Repository navigation
issues: a panic is never an accident, the owner's rule as a track, not yet enforced; seven stale crafted-ELF clauses go - #665
3 commits merged into
Conversation
…rates
The owner decided a rule graded by what a panic costs: no panic at all at
an input boundary, no implicit panic in the kernel or the system services,
normal Rust for apps, ports, tests and tooling. He asked that it be
recorded, not done now. The track carries the rule, what holds today and
the five stages with their exits.
Measured for it:
- `rg -o '\.unwrap\(\)|\.expect\(' kernel/src | wc -l` is 157 (154 lines
by `rg -c`).
- `cargo clippy --target x86_64-unknown-none -- -W clippy::indexing_slicing
-W clippy::arithmetic_side_effects -W clippy::unwrap_used
-W clippy::expect_used -W clippy::panic -W clippy::unreachable
-W clippy::cast_possible_truncation --message-format=json`, in kernel/,
counted per lint code with jq: 2,008 findings in the kernel crate.
- `rustc -Z unstable-options --print target-spec-json` gives
`"panic-strategy": "abort"` for x86_64-unknown-none and
aarch64-unknown-none-softfloat. The no-panic README calls its attribute
"useless in code built with panic = abort", so a link proof has to come
from a host build.
- A scratch crate run under the seven lints drew no warning for `assert!`,
`copy_from_slice` or `split_at`. It drew one each for `a[3]` and `panic!`.
The brief expected `issues/` to hold the two crafted-ELF panics an overflow
check found, and it holds neither. The closed entry left the tracker at
fa2799d, yet seven comments still cite `issues/` for it, and the tree's
rule is to file that rather than fix it here. The second file records it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
|
Review of CI:
Shape: a numbered stage list is the form the tree's tracks already use (24 of the 80 BLOCKER
NOTE
REMOVE
SEND BACK |
…llow]; seven crafted-ELF clauses go Answers the review of 6b2eef1 on PR #665. The set covers every operation that can panic on input. Each lint name was checked against clippy 0.1.98 (48a229ceae) on a scratch crate under `#![deny(unknown_lints)]`. All fifteen drew a finding on their own form. A bogus `clippy::no_such_lint_control` was refused, and it was the only error (exit 101). The set adds these to PR #653's nine: - `string_slice`, because `indexing_slicing` drew nothing on `&s[1..]` and `string_slice` did; - `cast_possible_truncation`, which the owner names; - `disallowed_methods` naming `slice::split_at` and `slice::copy_from_slice`; - `disallowed_macros` naming `core::assert`, `assert_eq` and `assert_ne`. Each of those configured names fired. What the set does not see, measured: `a << b`, `a >> b`, `1u64 << b`, `a.pow(b)` and `a.abs()` drew no finding. Built with `-C overflow-checks=on`, the shift, the `pow` and the `abs` each exit 101: "attempt to shift left with overflow", "attempt to exponentiate with overflow", "attempt to negate with overflow". The gate: - `#![forbid(clippy::indexing_slicing)]` turns an inner `#[expect(…, reason)]` into E0453, and an inner `#![allow(…, reason)]` too. - With `allow_attributes` and `allow_attributes_without_reason` on, an outer `#[allow]` draws the first lint, with or without a reason. - A bare `#[allow]`, `#![allow]` or `#[expect]` draws the second. - An inner `#![allow(…, reason = …)]` draws neither. Stage 3's exit closes that hole with a `--ci host` step. clippy.toml: with a parent file listing `copy_from_slice` and a child listing `split_at`, the child crate drew only `split_at`. With the child's file removed, it drew only `copy_from_slice`. Only the nearest file is read. The count. `cargo clippy --target x86_64-unknown-none --message-format=json` ran in kernel/ with the set as `-W`. The two methods and three macros were added to a copy of the root clippy.toml, passed through CLIPPY_CONF_DIR. It exits 101 under the kernel's `-Dwarnings`. Counted by code with jq: - 992 arithmetic_side_effects - 408 indexing_slicing - 394 cast_possible_truncation - 208 disallowed_macros (200 assert, 8 assert_eq) - 109 expect_used - 60 panic - 39 disallowed_methods (all copy_from_slice) - 29 unwrap_used - 16 unreachable - 14 panic_in_result_fn - 5 string_slice That is 2,274. Beside them are 26 allow_attributes and 28 allow_attributes_without_reason. Seven clauses cited `issues/` for crafted-ELF panics that the tracker closed at fa2799d. They sat at Cargo.toml (two), bootloader/, kernel/ and userland/Cargo.toml, and src/build.rs (two). All are deleted, with the file that recorded them. None of the five files is a sysroot input. Also deleted, as REMOVEs: - the "seven crates" claim; - the boundary and service lists; - "where a reviewer sees it"; - the per-crate inventory; - the rg count; - the crafted-ELF history; - the microcode citation; - the constraint's provenance; - stage 5; - the mutation line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
|
Round 2: review of CI: Net lines (
Round-1 BLOCKERs
Round-1 NOTEs: all four are applied (stages 1, 2 and 4, and stage 5 is gone). BLOCKER
NOTE
REMOVE
SEND BACK |
…ill of a locked build, and the crate track yields to the no-panic track Answers issuecomment-5931861144 (review of dc45e23). BLOCKERs: - Firmware. The shipping terms are shared and the loading clause splits: a device's firmware is loaded only by its own driver through its IOMMU domain and never executes on the CPU; CPU microcode is loaded by the kernel. Root CLAUDE.md is 16076 bytes, main's 16077. - Panics. Stage 3's step refuses an #[expect] of the set over more than one finding. It lints a copy in which each #[expect] of the set is a #[deny] whose reason is its own file and line; rustc attaches that reason to every finding the attribute governs. It also refuses a copy with fewer findings than --force-warn of the set, which catches an #[expect] the copy missed, as one inside cfg_attr. The tier-2 row says the stop is spelled out at its site. - Kill order. src/CLAUDE.md:24 is true: bootstrap recreates stage2 without its cargo, and reassemble puts it back in the same process under the same hold (src/toolchain.rs). Root CLAUDE.md's bullet no longer orders a kill: an agent stops what it started, killing only by PID and waiting out a build that holds the global lock. - Conflicting tracks. #604's track yields and names #665's: an input boundary is a crate of its own, because tier 1 is forbidden per crate and a crate holding a tier-2 stop cannot forbid the set (E0453, c1 of issuecomment-5931382112). toyos-userbound, -dma, -pci, -acpi, -transport, -blockring and -dns say so at their roots, -ps2 decodes a device's wire, and the network crates read the network; no step moves them. Step 3 takes 345 tests, step 4 drops acpi from toyos-boot and drops toyos-block, step 5 drops netd's library, and the network track's stage 4 no longer conflicts. NOTEs: the ABI issue lists the SYS_DEBUG issue and the small-kernel track; the boot-start exit asks a host test of the mark and the choice and a metal row or, where none can, a guest test of the fatal boot, and its false sentence on refused_claim and pci_function_is_exclusive goes; step 3 checks declared_model_controls; step 1's grep excludes issues/; the Fit line carries the layout rule from step 3; stage 4 waits on the userland-lint issue, whose exit is a src/clippy.rs shape; compile-time assertions and nested arithmetic are constraints; the mixer's timing is re-measured. REMOVEs: ", which is the only question worth asking" and ", so this build system no longer has the flag" (four manifests). Measured with cargo 1.98.1, clippy 0.1.98 (48a229ceae), on scratch crates posted to the pull request: - The review's patch to c6 (an #[expect] on a fn over v[i] and "+ x * x", one on a trait over two indexes): git apply --check 0, cargo build 0, cargo clippy -p c6 0 with no warning; reverted, clean. - The copy of that c6, cargo clippy --message-format=json: 101, every one of 13 findings carries its attribute's reason: mod drivers 5, the inner #![expect] 2, the impl 2, the fn 2, the trait 2. The same under RUSTFLAGS="-D warnings". With #[warn] in place of #[deny] under -D warnings no finding carries its reason: two carry "`-D clippy::...` implied by `-D warnings`" and eleven nothing. - --force-warn of the two lints on c6: 0, 13 warnings, those under each #[expect] included, no unfulfilled_lint_expectations. - c15, every #[expect] over one site and one nested in another: clippy 0; its copy gives five reasons, one finding each. - c18, an #[expect] inside cfg_attr over two indexes: clippy 0; the copy 0 findings; --force-warn 2. - c16: x * x + y * y - 1 and (a + b) * (c + d) are one arithmetic_side_effects finding each; v[i][j] is two indexing_slicing. cargo rustc --lib -- -C overflow-checks=on --emit=mir: 0, one overflow assert per operator, no source spans. - c17 with c14's clippy.toml: disallowed_macros fires on const _: () = assert!(...), const { assert!(...) } and a run-time assert!; clippy::panic passes panic! in a const item and in an inline const block; cargo build 0. git grep -h -E 'const _: \(\) = assert!|const \{ assert!' -- kernel/src | wc -l: 41. - CARGO_PROFILE_DEV_OPT_LEVEL=<n> cargo test -p toyos-mixer, scratch target, twice per level, exit 0 each; libtest's "finished in" for 55 tests: 9.94 s and 9.99 s at 0, 1.00 s and 1.00 s at 2. - cargo test -p <package> -- --list, lines ending ": test", exit 0 each: pcid 6, proclife 34, sched with check 95, xhci 150, gicv3 8, cpuvuln 52 (345); bootmap 43, rootimage 21, blackbox 33, tco 13, quiesce 8 (118); elide 12, logstream 14; manifest 19, swap 7; fat32-check 67; desktop 95; inspect 21; symbols 9. Staying: dma 17, pci 75, ps2 24, userbound 34, acpi 52, transport 17, blockring 19, blockhold 9. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
63cb34a
This PR records the owner's no-panic rule as a track. The rule is decided, and nothing enforces it yet. It also deletes seven stale comment clauses. No code changes.
What changed
issues/kernel/a-panic-is-never-an-accident.mdis a newkind: track. It carries:#[expect(…, reason = "…")]whose reason names its invariant.48a229ceae):indexing_slicingandstring_slice. Slicing astrdraws only the second.arithmetic_side_effects.unwrap_usedandexpect_used.panic,unreachable,todo,unimplementedandpanic_in_result_fn.cast_possible_truncation. The owner names it, although a truncatingasdoes not panic. For tiers 1 to 3 this overrides the tree-wide rejection inissues/build/clippy-stage-two-is-lints-one-at-a-time.md, and the track says so.disallowed_methodsnamingslice::split_atandslice::copy_from_slice.disallowed_macrosnamingcore::assert,assert_eqandassert_ne.#[allow]or#[expect]is error E0453.clippy::allow_attributesandclippy::allow_attributes_without_reason.#[allow]therefore fails the gate. So does an#[expect]without a reason.allow_attributeschecks only outer attributes, so an inner#![allow(…, reason = …)]passes both lints. Stage 3's exit adds a--ci hoststep that refuses it.--ci host.src/clippy.rs.Seven crafted-ELF clauses are deleted. They sat at
Cargo.toml(two),bootloader/Cargo.toml,kernel/Cargo.toml,userland/Cargo.tomlandsrc/build.rs(two). Each citedissues/for two panics the tracker closed atfa2799ded. The issue file that recorded them is deleted too. None of the five files is a sysroot input.Evidence
Each item comes from a command that was run. The commit message has the full lists.
Lint names and coverage. A scratch crate ran under
#![deny(unknown_lints)]. All fifteen lints drew a finding on their own form. A bogusclippy::no_such_lint_controlwas refused, and it was the only error.What the set misses.
a << b,a >> b,a.pow(b)anda.abs()drew no finding. Built with-C overflow-checks=on, the shift, thepowand theabseach exit 101.The
forbidandallow_attributesbehaviour above was measured on the same scratch crate.clippy.toml. A child crate's own file replaces its parent's rather than adding to it. This was measured with a parent and a child that list different methods.Kernel count.
cargo clippy --target x86_64-unknown-noneran inkernel/with the set as warnings. It exited 101 under the kernel's-Dwarningsand reported 2,274 findings:arithmetic_side_effectsindexing_slicingcast_possible_truncationdisallowed_macrosexpect_usedpanicdisallowed_methodsunwrap_usedunreachablepanic_in_result_fnstring_sliceThis is one of
src/clippy.rs's ten kernel shapes: x86-64 with default features.Gates
cargo run -- --ci host: EXIT=0 ("Host: 56 step(s), all green"). It ran on the tree off469e9022except two wording edits to the track, made during the run; no host step reads the track.🤖 Generated with Claude Code
https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L