Skip to content

issues: a panic is never an accident, the owner's rule as a track, not yet enforced; seven stale crafted-ELF clauses go - #665

Merged
3 commits merged into
mainfrom
wt/toyos-nopanic
Oct 1, 2026
Merged

3 commits merged into
mainfrom
wt/toyos-nopanic

Conversation

@Japabu

@Japabu Japabu commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

This PR records the owner's no-panic rule as a track. The rule is decided, and nothing enforces it yet. It also deletes seven stale comment clauses. No code changes.

What changed

issues/kernel/a-panic-is-never-an-accident.md is a new kind: track. It carries:

  • The tiers as the owner drew them.
    • Tier 1, input boundaries: no panic at all.
    • Tier 2, the kernel: no implicit panic. A deliberate stop is an #[expect(…, reason = "…")] whose reason names its invariant.
    • Tier 3, system services: the same rule as the kernel.
    • Tier 4: normal Rust.
  • The set. It covers every operation that can panic on input, and each name was checked against clippy 0.1.98 (48a229ceae):
    • indexing_slicing and string_slice. Slicing a str draws only the second.
    • arithmetic_side_effects.
    • unwrap_used and expect_used.
    • panic, unreachable, todo, unimplemented and panic_in_result_fn.
    • cast_possible_truncation. The owner names it, although a truncating as does not panic. For tiers 1 to 3 this overrides the tree-wide rejection in issues/build/clippy-stage-two-is-lints-one-at-a-time.md, and the track says so.
    • disallowed_methods naming slice::split_at and slice::copy_from_slice.
    • disallowed_macros naming core::assert, assert_eq and assert_ne.
  • How each stage's gate fails.
    • Tier 1 forbids the set, so an inner #[allow] or #[expect] is error E0453.
    • The kernel and the services deny the set and forbid clippy::allow_attributes and clippy::allow_attributes_without_reason.
    • A bare #[allow] therefore fails the gate. So does an #[expect] without a reason.
    • allow_attributes checks only outer attributes, so an inner #![allow(…, reason = …)] passes both lints. Stage 3's exit adds a --ci host step that refuses it.
  • Four stages, each with an exit a gate can fail.
    • Stage 1's first exit is one declaration of the set.
    • Stage 2's link-proof exit is a step of --ci host.
    • Stage 4's first exit is a userland shape in src/clippy.rs.

Seven crafted-ELF clauses are deleted. They sat at Cargo.toml (two), bootloader/Cargo.toml, kernel/Cargo.toml, userland/Cargo.toml and src/build.rs (two). Each cited issues/ for two panics the tracker closed at fa2799ded. The issue file that recorded them is deleted too. None of the five files is a sysroot input.

Evidence

Each item comes from a command that was run. The commit message has the full lists.

  • Lint names and coverage. A scratch crate ran under #![deny(unknown_lints)]. All fifteen lints drew a finding on their own form. A bogus clippy::no_such_lint_control was refused, and it was the only error.

  • What the set misses. a << b, a >> b, a.pow(b) and a.abs() drew no finding. Built with -C overflow-checks=on, the shift, the pow and the abs each exit 101.

  • The forbid and allow_attributes behaviour above was measured on the same scratch crate.

  • clippy.toml. A child crate's own file replaces its parent's rather than adding to it. This was measured with a parent and a child that list different methods.

  • Kernel count. cargo clippy --target x86_64-unknown-none ran in kernel/ with the set as warnings. It exited 101 under the kernel's -Dwarnings and reported 2,274 findings:

    • 992 arithmetic_side_effects
    • 408 indexing_slicing
    • 394 cast_possible_truncation
    • 208 disallowed_macros
    • 109 expect_used
    • 60 panic
    • 39 disallowed_methods
    • 29 unwrap_used
    • 16 unreachable
    • 14 panic_in_result_fn
    • 5 string_slice

    This is one of src/clippy.rs's ten kernel shapes: x86-64 with default features.

Gates

  • cargo run -- --ci host: EXIT=0 ("Host: 56 step(s), all green"). It ran on the tree of f469e9022 except two wording edits to the track, made during the run; no host step reads the track.

🤖 Generated with Claude Code

https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L

…rates

The owner decided a rule graded by what a panic costs: no panic at all at
an input boundary, no implicit panic in the kernel or the system services,
normal Rust for apps, ports, tests and tooling. He asked that it be
recorded, not done now. The track carries the rule, what holds today and
the five stages with their exits.

Measured for it:
- `rg -o '\.unwrap\(\)|\.expect\(' kernel/src | wc -l` is 157 (154 lines
  by `rg -c`).
- `cargo clippy --target x86_64-unknown-none -- -W clippy::indexing_slicing
  -W clippy::arithmetic_side_effects -W clippy::unwrap_used
  -W clippy::expect_used -W clippy::panic -W clippy::unreachable
  -W clippy::cast_possible_truncation --message-format=json`, in kernel/,
  counted per lint code with jq: 2,008 findings in the kernel crate.
- `rustc -Z unstable-options --print target-spec-json` gives
  `"panic-strategy": "abort"` for x86_64-unknown-none and
  aarch64-unknown-none-softfloat. The no-panic README calls its attribute
  "useless in code built with panic = abort", so a link proof has to come
  from a host build.
- A scratch crate run under the seven lints drew no warning for `assert!`,
  `copy_from_slice` or `split_at`. It drew one each for `a[3]` and `panic!`.

The brief expected `issues/` to hold the two crafted-ELF panics an overflow
check found, and it holds neither. The closed entry left the tracker at
fa2799d, yet seven comments still cite `issues/` for it, and the tree's
rule is to file that rather than fix it here. The second file records it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
@Japabu
Japabu marked this pull request as ready for review October 1, 2026 07:18
@Japabu

Japabu commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Review of 6b2eef15d against .claude/agents/reviewer.md and issues/README.md.

CI: host passed at 6b2eef15d (run 36829602301; gh run watch --exit-status exit 0, gh pr checks 665 exit 0). The branch adds no tests and targets no hardware.
Net lines (git diff --shortstat origin/main...6b2eef15d): +86 −0 across 2 files. Production 0, tests 0, issues/ +86.
Numbers I reproduced:

  • 157 occurrences on 154 lines: git grep -o -E '\.unwrap\(\)|\.expect\(' 6b2eef15d -- kernel/src | wc -l gives 157, and the per-file -c sum gives 154.
  • The seven-lint breakdown sums to 2,008. I did not re-run it, because a clippy run is a build.
  • overflow-checks = true is at Cargo.toml:254, kernel/Cargo.toml:387 and userland/Cargo.toml:85.
  • Both kernel targets print "panic-strategy": "abort" (RUSTC_BOOTSTRAP=1 rustc -Z unstable-options --print target-spec-json --target <t>, exit 0).
  • The no-panic README caveat at 9a0b1097 reads as quoted.
  • The issues/ grep exits 1 at 1e4d3e0ec and at origin/main.
  • da3f56573 is the commit that rewrote the seven citations.

Shape: a numbered stage list is the form the tree's tracks already use (24 of the 80 kind: track files carry one). The stage exits are what is wrong, not the list.

BLOCKER

  • issues/kernel/a-panic-is-never-an-accident.md:14-15 — The lint set is not the owner's "panicking forms".
    • It adds truncating casts. A truncating as never panics, and issues/build/clippy-stage-two-is-lints-one-at-a-time.md records cast_possible_truncation as rejected, so the tracker would give both answers.
    • It leaves out clippy::todo, clippy::unimplemented and clippy::panic_in_result_fn. PR toyos-microcode: Intel microcode update files validated and matched to a CPU, pure, and no input can panic it; the kernel step's design in its issue #653 already denies all three (76031de27:toyos-microcode/src/lib.rs:23-33).
    • The table drops the owner's "where the build allows" from the link proof.
    • "or a named invariant" adds a second kind of deliberate stop to tier 2, and no gate checks it.
    • Fix: record the owner's set. Unless the owner named casts, the 394 cast findings leave the count too.
  • issues/kernel/a-panic-is-never-an-accident.md:56-58,62-63 — The exits can pass while the rule fails.
    • "Denying the lints" still admits any #[allow], with or without a reason. toyos-transport/src/queue.rs:21 is one today.
    • Mutation that passes stage 3's exit as written: put #![deny(<the set>)] in kernel/src/main.rs and #[allow(clippy::arithmetic_side_effects, clippy::indexing_slicing)] on mod drivers; (kernel/src/main.rs:26). cargo run -- --clippy stays green and the rule is false.
    • Tier 1's exit should be forbid, as six of the seven crates already use. An inner #[allow] or #[expect] cannot override it.
    • Tier 2's exit should be deny with clippy::allow_attributes and clippy::allow_attributes_without_reason forbidden, so a deliberate stop is an #[expect(…, reason = …)] or nothing.
  • issues/build/seven-comments-cite-crafted-elf-panics-no-issue-holds.md — The branch adds 17 lines to keep seven false clauses it can delete.
    • Delete the crafted-ELF clause in this PR at Cargo.toml:210-211 and :231-232, bootloader/Cargo.toml:45-46, kernel/Cargo.toml:376-377, userland/Cargo.toml:69-70, and src/build.rs:408-411 and :635-637.
    • Then drop this file and the track's :35-39.
    • None of these five files is a sysroot input (src/sysroot.rs:54-59), so the deletion rebuilds no toolchain.
    • Stale prose is deleted, and these clauses are chronology the comment rule already bars.

NOTE

  • issues/kernel/a-panic-is-never-an-accident.md:66 — Stage 5 has no exit a gate can fail. Once the attributes land, the rule lives where it is enforced, and reviewer.md's "Edges" already holds the kernel half. Delete the stage.
  • issues/kernel/a-panic-is-never-an-accident.md:59-61 — Stage 2's "a host build that refuses to link" is measured once and then rots unless it is a step of cargo run -- --ci host. Say so in the exit.
  • issues/kernel/a-panic-is-never-an-accident.md:64-65 — Stage 4 waits on a clippy for the toyos toolchain that no issue owns (src/clippy.rs:7-8). Its first exit is a userland shape in src/clippy.rs.
  • issues/kernel/a-panic-is-never-an-accident.md:56-58 — The set is already copied into seven crate roots, and PR toyos-microcode: Intel microcode update files validated and matched to a CPU, pure, and no input can panic it; the kernel step's design in its issue #653 carries a different nine. Stage 1's exit should name one declaration of the set that every tier-1 crate reads.

REMOVE

  • issues/kernel/a-panic-is-never-an-accident.md:7, :9-10 and the PR title — "seven crates enforce it" is false by the file's own :25: none denies unreachable and none carries the proof. toyos-microcode: Intel microcode update files validated and matched to a CPU, pure, and no input can panic it; the kernel step's design in its issue #653 landing also moves the count.
  • :14 — The parenthetical list of input boundaries is the implementer's, written into the owner's row.
  • :16 — The service list rots when the next service lands. userland/ already answers it.
  • :15 — "where a reviewer sees it".
  • :20-25 — The per-crate lint inventory: the crate roots answer it, and "one #[allow] at queue.rs:21" misses :69 and :79.
  • :26-28 — The rg count and its rg -c aside: the clippy count at :28-32 is the compiled measure of the same calls, and the aside exists only to correct the brief.
  • :33-39 — The overflow-check provenance and crafted-ELF history. At most this clause stays: [profile.toyos] sets overflow-checks, so arithmetic is a panicking form.
  • :40-42 — It cites toyos-microcode/src/lib.rs, which only open PR toyos-microcode: Intel microcode update files validated and matched to a CPU, pure, and no input can panic it; the kernel step's design in its issue #653 holds, and it is already false at that PR's head 76031de27: nine lints are denied there, and the table is read through split_first_chunk at :243.
  • :45-47 — From "on a crate holding" on is provenance. The commit message already carries it.
  • :68-69 — The "Mutation" line: a track has nothing to mutate, and the stage exits are the gates.
  • PR body — "twelve kernel shapes" is wrong (src/clippy.rs has ten). The "Unsure" section and the first-person note on where the file lives would become main's merge record.

SEND BACK

Japabu and others added 2 commits October 1, 2026 09:37
…llow]; seven crafted-ELF clauses go

Answers the review of 6b2eef1 on PR #665.

The set covers every operation that can panic on input. Each lint name was
checked against clippy 0.1.98 (48a229ceae) on a scratch crate under
`#![deny(unknown_lints)]`. All fifteen drew a finding on their own form. A
bogus `clippy::no_such_lint_control` was refused, and it was the only
error (exit 101). The set adds these to PR #653's nine:
- `string_slice`, because `indexing_slicing` drew nothing on `&s[1..]` and
  `string_slice` did;
- `cast_possible_truncation`, which the owner names;
- `disallowed_methods` naming `slice::split_at` and `slice::copy_from_slice`;
- `disallowed_macros` naming `core::assert`, `assert_eq` and `assert_ne`.
Each of those configured names fired.

What the set does not see, measured: `a << b`, `a >> b`, `1u64 << b`,
`a.pow(b)` and `a.abs()` drew no finding. Built with
`-C overflow-checks=on`, the shift, the `pow` and the `abs` each exit 101:
"attempt to shift left with overflow", "attempt to exponentiate with
overflow", "attempt to negate with overflow".

The gate:
- `#![forbid(clippy::indexing_slicing)]` turns an inner
  `#[expect(…, reason)]` into E0453, and an inner `#![allow(…, reason)]` too.
- With `allow_attributes` and `allow_attributes_without_reason` on, an outer
  `#[allow]` draws the first lint, with or without a reason.
- A bare `#[allow]`, `#![allow]` or `#[expect]` draws the second.
- An inner `#![allow(…, reason = …)]` draws neither. Stage 3's exit closes
  that hole with a `--ci host` step.

clippy.toml: with a parent file listing `copy_from_slice` and a child
listing `split_at`, the child crate drew only `split_at`. With the child's
file removed, it drew only `copy_from_slice`. Only the nearest file is read.

The count. `cargo clippy --target x86_64-unknown-none
--message-format=json` ran in kernel/ with the set as `-W`. The two
methods and three macros were added to a copy of the root clippy.toml,
passed through CLIPPY_CONF_DIR. It exits 101 under the kernel's
`-Dwarnings`. Counted by code with jq:
- 992 arithmetic_side_effects
- 408 indexing_slicing
- 394 cast_possible_truncation
- 208 disallowed_macros (200 assert, 8 assert_eq)
- 109 expect_used
- 60 panic
- 39 disallowed_methods (all copy_from_slice)
- 29 unwrap_used
- 16 unreachable
- 14 panic_in_result_fn
- 5 string_slice
That is 2,274. Beside them are 26 allow_attributes and 28
allow_attributes_without_reason.

Seven clauses cited `issues/` for crafted-ELF panics that the tracker
closed at fa2799d. They sat at Cargo.toml (two), bootloader/, kernel/ and
userland/Cargo.toml, and src/build.rs (two). All are deleted, with the file
that recorded them. None of the five files is a sysroot input.

Also deleted, as REMOVEs:
- the "seven crates" claim;
- the boundary and service lists;
- "where a reviewer sees it";
- the per-crate inventory;
- the rg count;
- the crafted-ELF history;
- the microcode citation;
- the constraint's provenance;
- stage 5;
- the mutation line.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
@Japabu Japabu changed the title issues: a panic is never an accident — the owner's graded no-panic rule, decided and enforced in seven crates issues: a panic is never an accident, the owner's rule as a track, not yet enforced; seven stale crafted-ELF clauses go Oct 1, 2026
@Japabu

Japabu commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Round 2: review of f469e9022 against .claude/agents/reviewer.md, judged against round 1 (#665 (comment)).

CI: host passed at f469e9022 (run 36832634087; gh run watch --exit-status exited 0, and gh pr checks 665 exited 0). The branch adds no tests and targets no hardware.

Net lines (git diff --numstat origin/main...f469e9022): +79 −21.

  • Production: +11 −21, all of it comments.
  • Tests: 0.
  • issues/: +68.

Round-1 BLOCKERs

  • 1, the lint set — OPEN on one point.
    • Closed: :21-23 now names todo, unimplemented and panic_in_result_fn. :11 carries "where the build allows". :12 has a single kind of deliberate stop.
    • Open: the owner approved "lossy casts", but :24 records cast_possible_truncation alone.
    • cast_precision_loss is lossy by its name. cast_sign_loss and cast_possible_wrap change the value silently, and silent change is the reason the ruling gives for keeping truncating casts.
    • Fix: name all three beside truncation and re-measure the kernel count. Otherwise the orchestrator confirms with the owner that "lossy" meant truncation only, and :24 says so.
  • 2, the exits pass while the rule fails — OPEN.
    • Closed: the named mutation, an #[allow] on mod drivers;, now fails :63-64, because allow_attributes is forbidden there. The evidence is the scratch-crate measurement in f469e9022's message.
    • Open: the same mutation written as an #[expect] still passes. Put #[expect(clippy::arithmetic_side_effects, clippy::indexing_slicing, reason = "drivers")] on kernel/src/main.rs:26 (mod drivers;), or #![expect(…, reason = "…")] at the top of any module file.
    • That passes every gate :62-66 names, because the module's first finding fulfils the expect. Tier 2's "no implicit panic" is then false for the whole module.
    • Fix: the --ci host step at :65 also refuses an #[expect] of the set on a mod, on an impl, and as an inner #![expect]. Then one expect covers one stop, as :12 says.
  • 3, the seven clauses — CLOSED.
    • All seven are gone from the five files in the diff.
    • The second issue file does not appear in git diff origin/main...f469e9022.
    • git grep 'seven-comments-cite-crafted-elf' f469e9022 exits 1.

Round-1 NOTEs: all four are applied (stages 1, 2 and 4, and stage 5 is gone).
Round-1 REMOVEs: all are applied. The overflow clause stays at :19-20 in the form round 1 allowed.

BLOCKER

  • issues/kernel/a-panic-is-never-an-accident.md:62-66 — Stage 3 ends at kernel/src/main.rs alone, but the kernel links 25 more crates.
    • kernel/Cargo.toml:390-414 links 25 toyos crates whose code runs in the kernel, among them toyos-sched, toyos-pcid, toyos-dma, toyos-userbound and toyos-quiesce.
    • A crate-root attribute in main.rs reaches none of them. The 2,274 at :33-35 counts the kernel package alone.
    • Mutation: stage 3 lands as written while toyos-sched keeps an unchecked +. cargo run -- --clippy stays green, and tier 2 is false.
    • Fix: stage 3 also ends with every crate kernel/Cargo.toml links, unless stage 1 already forbids the set in it.

NOTE

  • :24-26 — Per the orchestrator's ruling, say why truncating casts are in the set: a truncating as degrades silently, and CLAUDE.md's "Fail fast" forbids silent degradation. "The owner names it" is not a reason.
  • :56-57 and issues/design-debt/elf-domain-lint-line-not-yet-added.md — The track's treatment of the ELF issue is not right.
    • That issue's exit, "every site inside it is checked or carries a one-clause #[allow]", contradicts its own #![forbid] on lib.rs (E0453), whether or not this track exists.
    • issues/README.md, "Filing one", bars this branch from editing a file the orchestrator holds.
    • So the clause in the track goes. The holder deletes "or carries a one-clause #[allow]" from that exit and makes toyos-elf an area of stage 1, since its "…" is this set.
  • :53-54 — Measure which mechanism "one declaration" is before promising it.
    • Cargo's [lints] applies to every target, so a forbid there reaches #[cfg(test)] code. Tier 4 frees test code, and the crates today exempt it with cfg_attr(not(test), …) (toyos-transport/src/lib.rs:26-27).
    • A kernel-module area cannot read a [lints] table at all.
  • :27-29 — The set names split_at and copy_from_slice but not split_at_mut and clone_from_slice, which panic on the same length mismatch.
  • PR body — The scratch-crate claims stand on no command, exit code or log in the body: forbid gives E0453, allow_attributes checks outer attributes only, string_slice, and shift, pow and abs. Stage 3's extra step rests on the outer-only claim.
  • :7, :31 — The track says plainly that the rule is decided and not yet enforced. At 63 body lines it is about a screen, and the REMOVEs below shorten it.

REMOVE

  • :16 — "every name checked against clippy 0.1.98 (48a229ceae)". It is provenance, the commit carries it, and it rots at the next toolchain bump.
  • :12 — "A type that makes the broken state unrepresentable is preferred over any stop." and "(fail fast)". Both restate CLAUDE.md.
  • :31-32 — Everything after "No crate carries the set.". It becomes false when toyos-microcode: Intel microcode update files validated and matched to a CPU, pure, and no input can panic it; the kernel step's design in its issue #653 lands: toyos-microcode/src/lib.rs at origin/wt/toyos-ucode denies panic_in_result_fn, todo and unimplemented.
  • :56-57 — ", the #[allow] in issues/design-debt/elf-domain-lint-line-not-yet-added.md's exit too". It narrates another issue's defect, and it rots when that issue is fixed.
  • PR body — "It covers every operation that can panic on input". The track's own :38-40 says otherwise.
  • PR body — "The issue file that recorded them is deleted too." main never carried that file, so the merge deletes none.
  • PR body, Gates — "except two wording edits to the track, made during the run; no host step reads the track". That is chronology, and CI at f469e9022 is the measurement.
  • PR body, "What changed" — The tier, set and stage bullets restate the track, which is the record.

SEND BACK

Japabu added a commit that referenced this pull request Oct 1, 2026
…ill of a locked build, and the crate track yields to the no-panic track

Answers issuecomment-5931861144 (review of dc45e23).

BLOCKERs:
- Firmware. The shipping terms are shared and the loading clause splits:
  a device's firmware is loaded only by its own driver through its IOMMU
  domain and never executes on the CPU; CPU microcode is loaded by the
  kernel. Root CLAUDE.md is 16076 bytes, main's 16077.
- Panics. Stage 3's step refuses an #[expect] of the set over more than
  one finding. It lints a copy in which each #[expect] of the set is a
  #[deny] whose reason is its own file and line; rustc attaches that
  reason to every finding the attribute governs. It also refuses a copy
  with fewer findings than --force-warn of the set, which catches an
  #[expect] the copy missed, as one inside cfg_attr. The tier-2 row says
  the stop is spelled out at its site.
- Kill order. src/CLAUDE.md:24 is true: bootstrap recreates stage2
  without its cargo, and reassemble puts it back in the same process
  under the same hold (src/toolchain.rs). Root CLAUDE.md's bullet no
  longer orders a kill: an agent stops what it started, killing only by
  PID and waiting out a build that holds the global lock.
- Conflicting tracks. #604's track yields and names #665's: an input
  boundary is a crate of its own, because tier 1 is forbidden per crate
  and a crate holding a tier-2 stop cannot forbid the set (E0453, c1 of
  issuecomment-5931382112). toyos-userbound, -dma, -pci, -acpi,
  -transport, -blockring and -dns say so at their roots, -ps2 decodes a
  device's wire, and the network crates read the network; no step moves
  them. Step 3 takes 345 tests, step 4 drops acpi from toyos-boot and
  drops toyos-block, step 5 drops netd's library, and the network
  track's stage 4 no longer conflicts.

NOTEs: the ABI issue lists the SYS_DEBUG issue and the small-kernel
track; the boot-start exit asks a host test of the mark and the choice
and a metal row or, where none can, a guest test of the fatal boot, and
its false sentence on refused_claim and pci_function_is_exclusive goes;
step 3 checks declared_model_controls; step 1's grep excludes issues/;
the Fit line carries the layout rule from step 3; stage 4 waits on the
userland-lint issue, whose exit is a src/clippy.rs shape; compile-time
assertions and nested arithmetic are constraints; the mixer's timing is
re-measured.

REMOVEs: ", which is the only question worth asking" and ", so this
build system no longer has the flag" (four manifests).

Measured with cargo 1.98.1, clippy 0.1.98 (48a229ceae), on scratch
crates posted to the pull request:
- The review's patch to c6 (an #[expect] on a fn over v[i] and
  "+ x * x", one on a trait over two indexes): git apply --check 0,
  cargo build 0, cargo clippy -p c6 0 with no warning; reverted, clean.
- The copy of that c6, cargo clippy --message-format=json: 101, every
  one of 13 findings carries its attribute's reason: mod drivers 5, the
  inner #![expect] 2, the impl 2, the fn 2, the trait 2. The same under
  RUSTFLAGS="-D warnings". With #[warn] in place of #[deny] under
  -D warnings no finding carries its reason: two carry "`-D clippy::...`
  implied by `-D warnings`" and eleven nothing.
- --force-warn of the two lints on c6: 0, 13 warnings, those under each
  #[expect] included, no unfulfilled_lint_expectations.
- c15, every #[expect] over one site and one nested in another: clippy 0;
  its copy gives five reasons, one finding each.
- c18, an #[expect] inside cfg_attr over two indexes: clippy 0; the copy
  0 findings; --force-warn 2.
- c16: x * x + y * y - 1 and (a + b) * (c + d) are one
  arithmetic_side_effects finding each; v[i][j] is two indexing_slicing.
  cargo rustc --lib -- -C overflow-checks=on --emit=mir: 0, one overflow
  assert per operator, no source spans.
- c17 with c14's clippy.toml: disallowed_macros fires on
  const _: () = assert!(...), const { assert!(...) } and a run-time
  assert!; clippy::panic passes panic! in a const item and in an inline
  const block; cargo build 0.
  git grep -h -E 'const _: \(\) = assert!|const \{ assert!' -- kernel/src
  | wc -l: 41.
- CARGO_PROFILE_DEV_OPT_LEVEL=<n> cargo test -p toyos-mixer, scratch
  target, twice per level, exit 0 each; libtest's "finished in" for 55
  tests: 9.94 s and 9.99 s at 0, 1.00 s and 1.00 s at 2.
- cargo test -p <package> -- --list, lines ending ": test", exit 0
  each: pcid 6, proclife 34, sched with check 95, xhci 150, gicv3 8,
  cpuvuln 52 (345); bootmap 43, rootimage 21, blackbox 33, tco 13,
  quiesce 8 (118); elide 12, logstream 14; manifest 19, swap 7;
  fat32-check 67; desktop 95; inspect 21; symbols 9. Staying: dma 17,
  pci 75, ps2 24, userbound 34, acpi 52, transport 17, blockring 19,
  blockhold 9.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
@github-merge-queue github-merge-queue Bot closed this pull request by merging all changes into main in 63cb34a Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant