Conversation
Track the nine-crate Rust workspace (rover-core, rover-tasks, rover-store, rover-access, rover-agents, rover-source, rover-execution, rover-tui and rover-cli) with its lockfile, the pinned 1.88.0 MSRV toolchain file and the .cargo build config. The workspace forbids unsafe code and warns on clippy pedantic lints. Build output lives under the ignored /target/ directory. The Go binary remains the Rover product; this workspace is an unreleased port that is gated by docs/design/RUST_PARITY_PLAN.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Track ADR-0001 through ADR-0027 for the Rust port together with the Go to Rust state migration guide, compatibility baseline, dependency audit, parity plan, upstream feature matrix and the upstream source audit that records the Herdr manifest provenance. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/rust_dependency_audit.py checks every locked crates.io package against its SPDX expression and the exact license/notice files bundled under licenses/third-party, and emits a CycloneDX SBOM of the packages active on the supported targets. licenses/upstream/herdr holds the Apache-2.0 license for the reused Herdr detection manifests, whose hashes scripts/test_herdr_manifest_audit.py checks against the upstream audit. .gitattributes marks the bundled notices and Herdr manifests -text. Nine upstream notices use CRLF and THIRD_PARTY_NOTICES.md pins their exact SHA-256, so any EOL normalisation (for example core.autocrlf=input) would store LF blobs and make the audit fail on every fresh clone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add CARGO-overridable make targets: rust-fmt-check, rust-clippy (--all-targets, -D warnings), rust-test, rust-deps-check (script unit tests plus the locked license/notice audit), the aggregate rust-check, rust-sbom and rust-notices. CI installs the pinned 1.88.0 toolchain with clippy and rustfmt, fetches the locked dependencies and runs rust-check and rust-sbom. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Per product direction Rover ships no SDK clients. Delete sdk/, the sdk-test make target and the three SDK CI steps, drop the SDK package version checks from TestVersionSurfaces and add TestSDKSourceTreeRemoved so the tree cannot silently return. Historical plans and audit reports gain a banner saying their sdk/ citations describe removed code. The SDK clients were never published to a package registry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…odel Record what the Rust workspace implements so far (store, importer, source capture, execution, PTY sessions and the attached TUI), the Rust TUI file browser/editor, saved-command and briefing-draft trust boundaries in the security model, and the Unreleased rover-execution changes in the changelog. Go remains the authoritative product. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both the Go product and the Rust preview built an executable called `rover` with different `tui` keymaps and state roots, so a `cargo install --path crates/rover-cli` or a stray PATH entry silently replaced the product binary and bug reports could not tell them apart. The Rust binary is now `rover-rs`; its usage and error prefix say so, and `rover-rs --version` prints the crate version labelled as an unreleased Rust port preview that is not the Rover product binary. The parity plan records that the `rover` name moves only at cutover (P-164). tests/cli_identity.rs covers the version banner and usage text. Refs: F067 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/rust_dependency_audit.py invoked a literal `cargo`, so `make rust-check CARGO='cargo +1.88.0'` applied the pinned toolchain only to fmt/clippy/test and the audit relied on rust-toolchain.toml happening to resolve `cargo`. The script now splits the CARGO environment variable (default `cargo`), rejects an empty or malformed value, and the Makefile passes CARGO to the check, SBOM and notice-refresh invocations. Refs: F073 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Rust fmt/clippy/test/audit steps ran first inside the single 20 minute Go job with no cache, so a cold Rust build (bundled SQLite, alacritty_terminal, ratatui) risked the timeout and any Rust failure hid every Go result. source-validation now has a `go` job with the unchanged Go gates and a separate `rust` job with its own 30 minute limit and a SHA-pinned Swatinem/rust-cache v2.9.2 for ~/.cargo and target/rust-1.88.0 that only main saves. The trailing comment no longer says hosted execution is pending. docs/CI.md documents both jobs, the Rust steps and what each checks, and corrects the package count to 24 (21 with tests). Refs: F069, F072 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
make rust-sbom wrote bin/rover-rust-sbom.cdx.json and the runner then discarded it, so the step was only a smoke test. Upload it with the SHA-pinned actions/upload-artifact v7.0.1 (fail if missing, 30-day retention). Releases still ship only the Go binaries and their SBOM; the Rust preview is not released, so its SBOM is not a release asset. Refs: F073 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Releases published sha256 checksums from the same origin as the binaries, which only detects transport corruption: a replaced binary-plus-checksums pair was indistinguishable from a genuine one. The release job now requests id-token/attestations write and runs the SHA-pinned actions/attest-build-provenance v4.2.2 over bin/checksums.txt, so each binary and the SBOM gets a keyless Sigstore-signed provenance statement tied to the workflow run, commit and repository. No long-lived signing key is stored or injected. docs/CI.md documents `gh attestation verify`, and TestReleaseWorkflowAttestsProvenance keeps the step, its permissions and its position between checksums and publishing. Refs: F258 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
README opened with a ~100 line paragraph that mixed store internals, the unreleased Rust port and a Ctrl-B keybinding manual, and documented `rover agent session` commands and TUI keys that only the Rust preview has; the installed Go `rover` rejects them. It also said Linux was required, called the 0.2.0-alpha.1 report "Current validation", and claimed no public repo, hosted CI or release existed. - README now leads with what Rover is, install-from-source steps, one platform matrix (Linux validated in hosted CI; macOS observed when built with cgo, cross-built darwin binaries have a stub store; Windows unsupported), the quickstart and the existing Go usage. A short "Rust port (preview, not the product)" section points to the new docs/RUST_PREVIEW.md, which holds the rover-rs build steps, state location, TUI key table, agent session commands and gaps. - docs/validation/v0.0.1/REPORT.md records the hosted CI run for the v0.0.1 tag (go1.27.1 from setup-go 'stable', steps and results) and the later main run; README labels the 0.2.0-alpha.1 report historical. - STATUS keeps the Rust progress narrative in its own section, states that Rover does not build, test or support Windows (portable-pty's ConPTY backend is not a Rover capability), reframes the increment log as history (A-H shipped in v0.0.1, I is unreleased, make sdk-test no longer exists) and replaces "no hosted workflow was run" and "Linux validation pending" with the hosted CI facts. Refs: F064, F065, F066, F070, F071, F074, F275, F276 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SECURITY, SUPPORT and GOVERNANCE still described an unpublished "source bundle" with no public repository, hosted issue queue or intake channel, while GrayCodeAI/rover is public with issues enabled, a v0.0.1 release and green hosted CI. - SECURITY: report privately to security@graycodeai.com; say plainly that GitHub private vulnerability reporting is not enabled yet (the API reports enabled=false) and will become the second channel; no SLA; explain release provenance verification. - SUPPORT: public repo, source-only v0.0.1 tag, no package-manager listing or SLA, GitHub issues for problems, hello@graycodeai.com for anything else, and why `go install` is not a documented path. - GOVERNANCE: maintainers are the GrayCodeAI organization owners. Refs: F065, F275 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`make manifest-check` only printed "SOURCE_MANIFEST.json is stale", so a contributor had to diff 400+ entries by hand to learn that, say, only CHANGELOG.md drifted. --check now lists up to 20 missing, no-longer- tracked and changed paths plus any version change, and reports a missing or unparsable manifest separately. manifest-check runs the new unit tests first. Refs: F063 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CI now enforces `make rust-check` on Rust 1.88.0 (fmt, clippy pedantic lints as errors, tests, license audit), but CONTRIBUTING, ROADMAP and AGENTS.md never mentioned Rust, cargo or rustup, and CONTRIBUTING still said CI definitions were not evidence of any hosted run. CONTRIBUTING lists the toolchain install command, when to run rust-check and rust-notices, and the `make manifest` step that CI enforces. ROADMAP gains a Rust port section pointing to the parity plan and ADR index. AGENTS.md tells coding agents which gates to run and that the Rust preview is unreleased. Refs: F072, F075 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs/design/README.md was titled "Historical design reference" and told readers not to treat anything in the folder as current, yet the folder now holds 27 accepted Rust ADRs and the active parity plan. It is now an index: current decisions and plans (with what each covers and a note that ADR commands run as `rover-rs` until cutover) and, separately, the historical ten-layer master plan. The Rust preview page also says the Go state importer is a store API, not yet a CLI command. Refs: F075 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Three tracked research notes cited sdk/ paths, rover_client and passing `make sdk-test` runs as current evidence with no marker, so their relative links were dead and they contradicted the SDK removal. Each now opens with a historical-snapshot banner, research_notes/README.md explains how to read all seven dated notes, and the report's command block labels `make sdk-test` historical instead of current. Refs: F068 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs/ARCHITECTURE.md still listed a "Python CLI client" among Rover's interfaces after the SDK trees were deleted; the diagram now shows the remote CLI client that does exist. docs/SOURCES.md described the tree as an upgrade of 0.1.0-alpha.1 without saying that line was renumbered to the public 0.0.1 release. Refs: F276 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nges Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`make manifest-check` (run by CI and the release workflow) failed on main because CHANGELOG.md had changed after the last regeneration, and it would have failed again once the Rust workspace, notices and ADRs were tracked. Regenerated with `make manifest`: 628 entries (62 crates/, 320 licenses/, 35 docs/design/, no sdk/), version 0.0.1. Refs: F062, F063 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The first hosted `rust` job failed `make rust-clippy` on ubuntu-24.04:
three clippy pedantic lints (similar_names, question_mark,
inefficient_to_string) sit in `cfg(target_os = "linux")` code in
rover-execution's PTY foreground-process sampler, which macOS clippy
never compiles. Rename the `pgid` parameter to `foreground_group`,
replace a `let ... else { return None }` with `?` (same semantics in an
Option-returning function), and build the start-time String from the
dereferenced &str. Behaviour is unchanged.
Verified locally with
`cargo +1.88.0 clippy --workspace --all-targets --locked --offline
--target x86_64-unknown-linux-gnu -- -D warnings`, which reproduces the
three CI errors on the old code and passes on the new code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t fix Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The first green hosted run of the split workflow (run 36279833786) finished the rust job in 1 min 22 s with no cache (clippy build 27.6 s, test build 31.4 s, 319 Linux tests) and the go job in 2 min 40 s. SOURCE_MANIFEST.json regenerated for the doc change. Refs: F069 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR puts the owner's uncommitted Rover work under version control and makes the release story true.
The owner's work included the whole Rust port workspace (9 crates, 27 ADRs, license notices and audit scripts, all previously untracked), the SDK removal, and the Rust CI/Make gates. It is committed here in coherent commits: workspace, design docs, audit tooling, Rust gates, SDK removal, docs. The findings are fixed on top, and
SOURCE_MANIFEST.jsonis regenerated withmake manifest.Defect found and fixed in the owner's work: nine upstream license notices use CRLF, and
licenses/THIRD_PARTY_NOTICES.mdpins their exact SHA-256. With the globalcore.autocrlf=input, git stored them as LF blobs. A fresh clone, CI included, would then have failedrust_dependency_audit.py --check: the stored blob hashed to378f…, the pinned digest is29c9…. The new.gitattributesmarkslicenses/**and the Herdr manifests-text. A fresh clone now passes the audit. I also dropped the owner'ssdk/exclusion ingenerate_source_manifest.py, which does nothing once the deletion is committed.Second defect, found by this PR's first hosted run: the new
rustjob failedmake rust-clippyon ubuntu-24.04. Three pedantic lints (similar_names,question_mark,inefficient_to_string) sit incfg(target_os = "linux")code inrover-execution/src/pty.rs, which macOS clippy never compiles. They are fixed in9a7b8acwith no behaviour change.To reproduce locally, I ran
cargo +1.88.0 clippy --workspace --all-targets --locked --offline --target x86_64-unknown-linux-gnu -- -D warnings, with lint-only stubCC/ARfor the bundled SQLite build script. It shows the same three errors on the old code and passes on the new code.Main behaviour changes:
rover-rs. Before, both the Go product and the Rust preview built a binary calledrover, so one could replace the other onPATH.rover-rs --versionlabels itself as an unreleased preview.go(unchanged gates, 20 min) andrust(30 min, SHA-pinnedSwatinem/rust-cache, onlymainsaves the cache). The Rust SBOM is uploaded as a run artifact.actions/attest-build-provenance, SHA-pinned) for every checksummed asset. No long-lived key is involved.docs/RUST_PREVIEW.md;docs/validation/v0.0.1/REPORT.mdrecords the tag's hosted CI run;Findings addressed
target/stays ignored. CRLF blob defect fixed as described above. A fresh clone passesmanifest-check,version-check, the script tests, the license audit androver doctor --verify.make manifest(628 entries, nosdk/).--checknow lists the missing, untracked and changed paths, with unit tests.agent sessionand the Ctrl-B keys live indocs/RUST_PREVIEW.mdunderrover-rs, with build steps.security@graycodeai.com.enabled:false).rover): the Rust binary is renamed torover-rs. It has a preview--versionand a newtests/cli_identity.rs. The parity plan (P-164) records that the name changes only at cutover.sdk/, plusresearch_notes/README.md. The report'smake sdk-testline is now labelled historical. The other 4 notes' "SDK" hits are about other projects.goandrustjobs, with the cache and a separate timeout. Measured on this PR (run 36279833786): therustjob took 1 min 22 s from a cold cache (319 Linux tests) and thegojob 2 min 40 s. The numbers are recorded indocs/CI.md.portable-ptyand is not a Rover capability.docs/validation/v0.0.1/REPORT.mdcovers tag run 35097554082. That run'ssetup-go 'stable'resolved to go1.27.1, and the report cites the log.docs/CI.mdgains the Rust rows and the correct count: 24 packages, 21 with tests.CARGO): the SBOM is uploaded as an artifact. The audit script readsCARGOviashlex(with tests), and the Makefile passes it through. The Rust SBOM is deliberately not a release asset, because releases ship only Go binaries.docs/design/README.mdcalled the folder historical): it is now an index. Current ADRs and plans are listed apart from the historical master plan, and ROADMAP has a Rust-port section.TestReleaseWorkflowAttestsProvenanceguards the step, its permissions and its order; a mutation check confirmed the test fails when the step is removed.docs/CI.mddocumentsgh attestation verify.docs/ARCHITECTURE.mdno longer lists a Python client,docs/SOURCES.mdprovenance is fixed, and STATUS marks themake sdk-testresults as historical.Not reproduced / deferred
Verification
All commands below ran from the branch checkout on darwin/arm64 (go1.26.6, cargo 1.88.0) with a clean tree at
f31320b. After the lint fix,make rust-checkandmake manifest-checkwere re-run at43eea4a: both exit 0, 317 tests passed.make checkokmake raceokmake version-checkmake manifest-checkmake rust-check CARGO='cargo +1.88.0'-D warnings, 317 cargo tests passed / 0 failed, 19 script tests OK, "Rust dependency licenses and bundled notices match Cargo.lock."GOFLAGS=-buildvcs=false make demoGOFLAGS=-buildvcs=false make demo-extendedmake fuzzmake rust-sbom CARGO='cargo +1.88.0'actionlint .github/workflows/*.yml9a7b8ac; the 3 CI errors reproduce on the previous codegit cloneof the branchmanifest-check,version-check, script tests and license audit pass;rover doctor --verify --json→"verified": trueBaseline on the owner's uncommitted tree before any change:
make manifest-checkfailed ("SOURCE_MANIFEST.json is stale").make rust-checkpassed with 315 tests.Not run locally:
make vulncheck(needs network) andmake cross-build. The hostedgojob runs both.Hosted CI on this PR:
f31320b,gopassed andrustfailed: 3 Linux-only clippy lints, fixed in9a7b8ac.43eea4a, both jobs passed on the push and pull_request runs (36279833786, 36279837334). Therustjob ran 319 cargo tests with 0 failures, the 19 script tests, the license audit, and the SBOM artifact upload.39026d4(a docs-only change recording those timings), both jobs passed on the push and pull_request runs (36280024936, 36280027435).Follow-ups
gh api -X PUT repos/GrayCodeAI/rover/private-vulnerability-reporting), then change SECURITY.md to list it as live.rustjob duration after the first cache save onmain.cargo checkjob only if Windows support is pursued (parity task P-156).gh attestation verifyon one asset.0.1.0while Rover is0.0.1. Align them when the Rust port is first released. Also considerpublish = falseon the workspace crates.security@graycodeai.comandhello@graycodeai.commailboxes are monitored.🤖 Generated with Claude Code