Skip to content

chore(rust): sync Cargo.lock + Phase 4 Rust pilot audit (2026-05-30) - #323

Closed
lusoris wants to merge 1 commit into
masterfrom
chore/rust-pilot-audit-2026-05-30
Closed

lusoris wants to merge 1 commit into
masterfrom
chore/rust-pilot-audit-2026-05-30

Conversation

@lusoris

@lusoris lusoris commented May 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Phase 4 Rust pilot audit per the language-modernization plan. Inspected
both Rust crates in tree (vmafx-sys FFI bindings, vmafx-tad cbindgen
pilot) for build health, clippy warnings, test coverage, formatting, and
security advisories. Found one real defect: the committed Cargo.lock
was missing 31 build-dependency entries (bindgen 0.69 + cbindgen 0.27
and their transitives), which cargo build silently regenerated on every
fresh checkout. Lockfile is now in sync; no version churn, no MSRV impact.

Type

  • chore — maintenance / cleanup
  • fix — Cargo.lock drift fix

Audit findings

Gate Result
cargo build (dev + release) clean
cargo test 15 / 15 pass (Netflix integration test gracefully skips without YUV)
cargo clippy --all-targets -- -D warnings 0 findings
cargo fmt --check clean
cargo audit 0 advisories (1099 scanned)
Cargo.lock integrity drift — 31 missing build-dep crate entries (FIXED)

Checklist

  • Conventional Commits.
  • cargo build + cargo clippy + cargo test + cargo fmt green.
  • No .c / .cpp / .cu / .h files added.
  • No breaking change.

Bug-status hygiene (ADR-0165)

  • no state delta: pilot-audit chore — no bug opened, closed, or ruled out.

Netflix golden-data gate (ADR-0024)

  • No assertAlmostEqual value modified.
  • No Python-test files touched.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: mechanical audit (run cargo gates, refresh lockfile).
  • Decision matrix — no alternatives: only-one-way fix (regenerate Cargo.lock from cargo build).
  • AGENTS.md invariant note — no rebase-sensitive invariants: lockfile resolution is deterministic from manifests.
  • Reproducer / smoke-test command — see Reproducer.
  • CHANGELOG fragment — changelog.d/fixed/rust-pilot-audit-2026-05-30.md.
  • Rebase note — docs/rebase-notes.md entry rust-pilot-audit-2026-05-30.

Reproducer

# From a clean checkout of master:
cd $(git rev-parse --show-toplevel)
cargo build 2>&1 | tail -5
git diff --stat Cargo.lock    # BEFORE this PR: shows hundreds of additions
cargo clippy --all-targets -- -D warnings
cargo test
cargo fmt --check
cargo audit
# AFTER this PR: `git diff --stat Cargo.lock` is empty after cargo build.

🤖 Generated with Claude Code

Rust pilot audit per Phase 4 plan. Found that the committed
`Cargo.lock` (647 lines) was missing 31 crate entries that resolve
from `[build-dependencies]` on `bindgen` 0.69 (`vmafx-sys`) and
`cbindgen` 0.27 (`vmafx-tad`). Running `cargo build` from a clean
checkout regenerated the lock (912 lines) with `bindgen`, `cbindgen`,
`clang-sys`, `cexpr`, `nom`, `rustix`, the `windows-sys` 0.59 family,
and their transitive deps. No version downgrades, no MSRV impact,
`cargo audit` is clean (1099 advisories scanned, 0 hits).

Build / test / lint gates verified green:
- `cargo build` (dev + release) — 0 warnings
- `cargo test` — 15 tests pass (9 bindgen layout, 1 Netflix golden
  integration gracefully skipped without YUV fixtures, 5 TAD unit tests)
- `cargo clippy --all-targets -- -D warnings` — 0 findings
- `cargo fmt --check` — clean
- `cargo audit` — clean

Rule for future Rust pilots captured in `docs/rebase-notes.md`:
regenerate `Cargo.lock` in the same PR that adds a new
`[build-dependencies]` entry.

Refs ADR-0702 (vmafx-sys FFI), ADR-0707 (vmafx-tad cbindgen pilot).
@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:20
@lusoris
lusoris marked this pull request as draft May 31, 2026 13:54
@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:58
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Closing as part of marathon cleanup 2026-05-31 (150 PRs merged today). Content likely superseded by sibling merges. Reopen if specific finding still needs work; bigger PRs preferred going forward per session feedback.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the chore/rust-pilot-audit-2026-05-30 branch May 31, 2026 14:07
@lusoris
lusoris restored the chore/rust-pilot-audit-2026-05-30 branch May 31, 2026 18:40
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:49
@lusoris

lusoris commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Closing per triage 2026-06-01: STALE-NOOP: Cargo.lock build-dep sync already on master (104 packages, 919 lines). Branch preserved.

@lusoris lusoris closed this Jun 1, 2026
@lusoris
lusoris deleted the chore/rust-pilot-audit-2026-05-30 branch June 4, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant