Repository navigation
Conversation
Rust pilot audit per Phase 4 plan. Found that the committed `Cargo.lock` (647 lines) was missing 31 crate entries that resolve from `[build-dependencies]` on `bindgen` 0.69 (`vmafx-sys`) and `cbindgen` 0.27 (`vmafx-tad`). Running `cargo build` from a clean checkout regenerated the lock (912 lines) with `bindgen`, `cbindgen`, `clang-sys`, `cexpr`, `nom`, `rustix`, the `windows-sys` 0.59 family, and their transitive deps. No version downgrades, no MSRV impact, `cargo audit` is clean (1099 advisories scanned, 0 hits). Build / test / lint gates verified green: - `cargo build` (dev + release) — 0 warnings - `cargo test` — 15 tests pass (9 bindgen layout, 1 Netflix golden integration gracefully skipped without YUV fixtures, 5 TAD unit tests) - `cargo clippy --all-targets -- -D warnings` — 0 findings - `cargo fmt --check` — clean - `cargo audit` — clean Rule for future Rust pilots captured in `docs/rebase-notes.md`: regenerate `Cargo.lock` in the same PR that adds a new `[build-dependencies]` entry. Refs ADR-0702 (vmafx-sys FFI), ADR-0707 (vmafx-tad cbindgen pilot).
This was referenced May 30, 2026
lusoris
marked this pull request as ready for review
May 31, 2026 13:20
lusoris
marked this pull request as draft
May 31, 2026 13:54
lusoris
marked this pull request as ready for review
May 31, 2026 13:58
Contributor
Author
|
Closing as part of marathon cleanup 2026-05-31 (150 PRs merged today). Content likely superseded by sibling merges. Reopen if specific finding still needs work; bigger PRs preferred going forward per session feedback. |
Contributor
Author
|
Closing per triage 2026-06-01: STALE-NOOP: Cargo.lock build-dep sync already on master (104 packages, 919 lines). Branch preserved. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase 4 Rust pilot audit per the language-modernization plan. Inspected
both Rust crates in tree (
vmafx-sysFFI bindings,vmafx-tadcbindgenpilot) for build health, clippy warnings, test coverage, formatting, and
security advisories. Found one real defect: the committed
Cargo.lockwas missing 31 build-dependency entries (
bindgen0.69 +cbindgen0.27and their transitives), which
cargo buildsilently regenerated on everyfresh checkout. Lockfile is now in sync; no version churn, no MSRV impact.
Type
chore— maintenance / cleanupfix—Cargo.lockdrift fixAudit findings
cargo build(dev + release)cargo testcargo clippy --all-targets -- -D warningscargo fmt --checkcargo auditCargo.lockintegrityChecklist
cargo build+cargo clippy+cargo test+cargo fmtgreen..c/.cpp/.cu/.hfiles added.Bug-status hygiene (ADR-0165)
Netflix golden-data gate (ADR-0024)
assertAlmostEqualvalue modified.Deep-dive deliverables (ADR-0108)
AGENTS.mdinvariant note — no rebase-sensitive invariants: lockfile resolution is deterministic from manifests.changelog.d/fixed/rust-pilot-audit-2026-05-30.md.docs/rebase-notes.mdentryrust-pilot-audit-2026-05-30.Reproducer
🤖 Generated with Claude Code