Skip to content

chore: track the Rust workspace preview and make release docs truthful - #2

Open
Patel230 wants to merge 23 commits into
mainfrom
chore/rust-workspace-release-truth
Open

Patel230 wants to merge 23 commits into
mainfrom
chore/rust-workspace-release-truth

Conversation

@Patel230

@Patel230 Patel230 commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR puts the owner's uncommitted Rover work under version control and makes the release story true.

The owner's work included the whole Rust port workspace (9 crates, 27 ADRs, license notices and audit scripts, all previously untracked), the SDK removal, and the Rust CI/Make gates. It is committed here in coherent commits: workspace, design docs, audit tooling, Rust gates, SDK removal, docs. The findings are fixed on top, and SOURCE_MANIFEST.json is regenerated with make manifest.

Defect found and fixed in the owner's work: nine upstream license notices use CRLF, and licenses/THIRD_PARTY_NOTICES.md pins their exact SHA-256. With the global core.autocrlf=input, git stored them as LF blobs. A fresh clone, CI included, would then have failed rust_dependency_audit.py --check: the stored blob hashed to 378f…, the pinned digest is 29c9…. The new .gitattributes marks licenses/** and the Herdr manifests -text. A fresh clone now passes the audit. I also dropped the owner's sdk/ exclusion in generate_source_manifest.py, which does nothing once the deletion is committed.

Second defect, found by this PR's first hosted run: the new rust job failed make rust-clippy on ubuntu-24.04. Three pedantic lints (similar_names, question_mark, inefficient_to_string) sit in cfg(target_os = "linux") code in rover-execution/src/pty.rs, which macOS clippy never compiles. They are fixed in 9a7b8ac with no behaviour change.

To reproduce locally, I ran cargo +1.88.0 clippy --workspace --all-targets --locked --offline --target x86_64-unknown-linux-gnu -- -D warnings, with lint-only stub CC/AR for the bundled SQLite build script. It shows the same three errors on the old code and passes on the new code.

Main behaviour changes:

  • The Rust preview binary is now rover-rs. Before, both the Go product and the Rust preview built a binary called rover, so one could replace the other on PATH. rover-rs --version labels itself as an unreleased preview.
  • CI has two independent jobs: go (unchanged gates, 20 min) and rust (30 min, SHA-pinned Swatinem/rust-cache, only main saves the cache). The Rust SBOM is uploaded as a run artifact.
  • The release workflow adds keyless GitHub build-provenance attestations (actions/attest-build-provenance, SHA-pinned) for every checksummed asset. No long-lived key is involved.
  • README is rebuilt around the Go product:
    • install from source, one platform matrix, then the quickstart;
    • the Rust keybinding manual moved to docs/RUST_PREVIEW.md;
    • docs/validation/v0.0.1/REPORT.md records the tag's hosted CI run;
    • SECURITY, SUPPORT and GOVERNANCE describe the public repo as it actually is.

Findings addressed

  • F062 (Rust workspace untracked): all 421 untracked paths are committed. target/ stays ignored. CRLF blob defect fixed as described above. A fresh clone passes manifest-check, version-check, the script tests, the license audit and rover doctor --verify.
  • F063 (stale manifest): regenerated with make manifest (628 entries, no sdk/). --check now lists the missing, untracked and changed paths, with unit tests.
  • F064 (README documented Rust-only commands and keys): the README documents only the Go product. agent session and the Ctrl-B keys live in docs/RUST_PREVIEW.md under rover-rs, with build steps.
  • F065 / F275 (docs denied the public repo, CI and release):
    • README, STATUS, SECURITY, SUPPORT and GOVERNANCE now state the observed facts: public repo, hosted CI, source-only v0.0.1 release.
    • Security reports go to security@graycodeai.com.
    • SECURITY.md says plainly that GitHub private vulnerability reporting is not enabled yet (the API returns enabled:false).
  • F066 (97-line README paragraph): README is restructured, and STATUS holds the Rust progress narrative without the keybinding manual.
  • F067 (two binaries named rover): the Rust binary is renamed to rover-rs. It has a preview --version and a new tests/cli_identity.rs. The parity plan (P-164) records that the name changes only at cutover.
  • F068 (research notes cite removed SDKs): banners on the 3 notes that cite Rover's sdk/, plus research_notes/README.md. The report's make sdk-test line is now labelled historical. The other 4 notes' "SDK" hits are about other projects.
  • F069 (cold Rust build inside the single 20-min job): split into go and rust jobs, with the cache and a separate timeout. Measured on this PR (run 36279833786): the rust job took 1 min 22 s from a cold cache (319 Linux tests) and the go job 2 min 40 s. The numbers are recorded in docs/CI.md.
  • F070 (Windows ConPTY claim): STATUS and RUST_PREVIEW now say Rover does not build, test or support Windows. The ConPTY backend comes from portable-pty and is not a Rover capability.
  • F071 ("Current validation" pointed at 0.2.0-alpha.1):
    • README relabels that report as historical.
    • The new docs/validation/v0.0.1/REPORT.md covers tag run 35097554082. That run's setup-go 'stable' resolved to go1.27.1, and the report cites the log.
  • F072 (unverified → confirmed; Rust gates undocumented, package count wrong):
    • docs/CI.md gains the Rust rows and the correct count: 24 packages, 21 with tests.
    • CONTRIBUTING, ROADMAP and AGENTS.md document the Rust toolchain and gates.
  • F073 (unverified → confirmed; SBOM discarded, audit ignored CARGO): the SBOM is uploaded as an artifact. The audit script reads CARGO via shlex (with tests), and the Makefile passes it through. The Rust SBOM is deliberately not a release asset, because releases ship only Go binaries.
  • F074 (platform statements disagreed): README has one matrix. Linux is validated in CI. macOS is observed and needs a from-source cgo build (cross-built darwin binaries have a stub store). Windows is unsupported. STATUS now cites the CI runs.
  • F075 (docs/design/README.md called the folder historical): it is now an index. Current ADRs and plans are listed apart from the historical master plan, and ROADMAP has a Rust-port section.
  • F258 (unverified → confirmed; no release provenance): release assets get provenance attestations. TestReleaseWorkflowAttestsProvenance guards the step, its permissions and its order; a mutation check confirmed the test fails when the step is removed. docs/CI.md documents gh attestation verify.
  • F276 (unverified → confirmed; docs still name the SDK client): docs/ARCHITECTURE.md no longer lists a Python client, docs/SOURCES.md provenance is fixed, and STATUS marks the make sdk-test results as historical.

Not reproduced / deferred

  • F065 (part): I did not enable GitHub private vulnerability reporting. That is a repository-settings change for the owner, so SECURITY.md describes the current state.
  • F070 (part): I did not add a Windows CI job, because I cannot verify a Windows build from this macOS host. I took the documentation fix instead (the finding's second option).
  • F258 (part): the attestation step runs only when the owner dispatches a release, so it has not run yet.

Verification

All commands below ran from the branch checkout on darwin/arm64 (go1.26.6, cargo 1.88.0) with a clean tree at f31320b. After the lint fix, make rust-check and make manifest-check were re-run at 43eea4a: both exit 0, 317 tests passed.

Command Result
make check exit 0; 21 packages ok
make race exit 0; 21 packages ok
make version-check exit 0
make manifest-check exit 0 (4 new unit tests plus the check)
make rust-check CARGO='cargo +1.88.0' exit 0: fmt, clippy -D warnings, 317 cargo tests passed / 0 failed, 19 script tests OK, "Rust dependency licenses and bundled notices match Cargo.lock."
GOFLAGS=-buildvcs=false make demo exit 0; "12 smoke scenarios passed"
GOFLAGS=-buildvcs=false make demo-extended exit 0; "16 extended CLI scenarios passed"
make fuzz exit 0; 5 fuzzers
make rust-sbom CARGO='cargo +1.88.0' "Wrote 180 Rust SBOM components"
actionlint .github/workflows/*.yml exit 0
Linux-target clippy (stub C tools, see Summary) exit 0 after 9a7b8ac; the 3 CI errors reproduce on the previous code
Fresh git clone of the branch manifest-check, version-check, script tests and license audit pass; rover doctor --verify --json → "verified": true

Baseline on the owner's uncommitted tree before any change: make manifest-check failed ("SOURCE_MANIFEST.json is stale"). make rust-check passed with 315 tests.

Not run locally: make vulncheck (needs network) and make cross-build. The hosted go job runs both.

Hosted CI on this PR:

  • At f31320b, go passed and rust failed: 3 Linux-only clippy lints, fixed in 9a7b8ac.
  • At 43eea4a, both jobs passed on the push and pull_request runs (36279833786, 36279837334). The rust job ran 319 cargo tests with 0 failures, the 19 script tests, the license audit, and the SBOM artifact upload.
  • At the final head 39026d4 (a docs-only change recording those timings), both jobs passed on the push and pull_request runs (36280024936, 36280027435).

Follow-ups

  1. Owner: enable private vulnerability reporting (gh api -X PUT repos/GrayCodeAI/rover/private-vulnerability-reporting), then change SECURITY.md to list it as live.
  2. Optionally record the warm-cache rust job duration after the first cache save on main.
  3. Add a Windows cargo check job only if Windows support is pursued (parity task P-156).
  4. The next release dispatch exercises the attestation step; confirm gh attestation verify on one asset.
  5. The Rust crates are version 0.1.0 while Rover is 0.0.1. Align them when the Rust port is first released. Also consider publish = false on the workspace crates.
  6. Confirm the security@graycodeai.com and hello@graycodeai.com mailboxes are monitored.

🤖 Generated with Claude Code

Patel230 and others added 23 commits September 27, 2026 04:41
Track the nine-crate Rust workspace (rover-core, rover-tasks, rover-store,
rover-access, rover-agents, rover-source, rover-execution, rover-tui and
rover-cli) with its lockfile, the pinned 1.88.0 MSRV toolchain file and the
.cargo build config. The workspace forbids unsafe code and warns on clippy
pedantic lints. Build output lives under the ignored /target/ directory.

The Go binary remains the Rover product; this workspace is an unreleased
port that is gated by docs/design/RUST_PARITY_PLAN.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Track ADR-0001 through ADR-0027 for the Rust port together with the Go to
Rust state migration guide, compatibility baseline, dependency audit,
parity plan, upstream feature matrix and the upstream source audit that
records the Herdr manifest provenance.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/rust_dependency_audit.py checks every locked crates.io package
against its SPDX expression and the exact license/notice files bundled
under licenses/third-party, and emits a CycloneDX SBOM of the packages
active on the supported targets. licenses/upstream/herdr holds the
Apache-2.0 license for the reused Herdr detection manifests, whose hashes
scripts/test_herdr_manifest_audit.py checks against the upstream audit.

.gitattributes marks the bundled notices and Herdr manifests -text. Nine
upstream notices use CRLF and THIRD_PARTY_NOTICES.md pins their exact
SHA-256, so any EOL normalisation (for example core.autocrlf=input) would
store LF blobs and make the audit fail on every fresh clone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add CARGO-overridable make targets: rust-fmt-check, rust-clippy
(--all-targets, -D warnings), rust-test, rust-deps-check (script unit
tests plus the locked license/notice audit), the aggregate rust-check,
rust-sbom and rust-notices. CI installs the pinned 1.88.0 toolchain with
clippy and rustfmt, fetches the locked dependencies and runs rust-check
and rust-sbom.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Per product direction Rover ships no SDK clients. Delete sdk/, the
sdk-test make target and the three SDK CI steps, drop the SDK package
version checks from TestVersionSurfaces and add TestSDKSourceTreeRemoved
so the tree cannot silently return. Historical plans and audit reports
gain a banner saying their sdk/ citations describe removed code.

The SDK clients were never published to a package registry.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…odel

Record what the Rust workspace implements so far (store, importer,
source capture, execution, PTY sessions and the attached TUI), the
Rust TUI file browser/editor, saved-command and briefing-draft trust
boundaries in the security model, and the Unreleased rover-execution
changes in the changelog. Go remains the authoritative product.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both the Go product and the Rust preview built an executable called
`rover` with different `tui` keymaps and state roots, so a
`cargo install --path crates/rover-cli` or a stray PATH entry silently
replaced the product binary and bug reports could not tell them apart.

The Rust binary is now `rover-rs`; its usage and error prefix say so,
and `rover-rs --version` prints the crate version labelled as an
unreleased Rust port preview that is not the Rover product binary. The
parity plan records that the `rover` name moves only at cutover (P-164).
tests/cli_identity.rs covers the version banner and usage text.

Refs: F067
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/rust_dependency_audit.py invoked a literal `cargo`, so
`make rust-check CARGO='cargo +1.88.0'` applied the pinned toolchain only
to fmt/clippy/test and the audit relied on rust-toolchain.toml happening
to resolve `cargo`. The script now splits the CARGO environment variable
(default `cargo`), rejects an empty or malformed value, and the Makefile
passes CARGO to the check, SBOM and notice-refresh invocations.

Refs: F073
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Rust fmt/clippy/test/audit steps ran first inside the single 20
minute Go job with no cache, so a cold Rust build (bundled SQLite,
alacritty_terminal, ratatui) risked the timeout and any Rust failure hid
every Go result. source-validation now has a `go` job with the unchanged
Go gates and a separate `rust` job with its own 30 minute limit and a
SHA-pinned Swatinem/rust-cache v2.9.2 for ~/.cargo and target/rust-1.88.0
that only main saves. The trailing comment no longer says hosted
execution is pending.

docs/CI.md documents both jobs, the Rust steps and what each checks, and
corrects the package count to 24 (21 with tests).

Refs: F069, F072
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
make rust-sbom wrote bin/rover-rust-sbom.cdx.json and the runner then
discarded it, so the step was only a smoke test. Upload it with the
SHA-pinned actions/upload-artifact v7.0.1 (fail if missing, 30-day
retention). Releases still ship only the Go binaries and their SBOM; the
Rust preview is not released, so its SBOM is not a release asset.

Refs: F073
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Releases published sha256 checksums from the same origin as the
binaries, which only detects transport corruption: a replaced
binary-plus-checksums pair was indistinguishable from a genuine one.
The release job now requests id-token/attestations write and runs the
SHA-pinned actions/attest-build-provenance v4.2.2 over bin/checksums.txt,
so each binary and the SBOM gets a keyless Sigstore-signed provenance
statement tied to the workflow run, commit and repository. No long-lived
signing key is stored or injected.

docs/CI.md documents `gh attestation verify`, and
TestReleaseWorkflowAttestsProvenance keeps the step, its permissions and
its position between checksums and publishing.

Refs: F258
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
README opened with a ~100 line paragraph that mixed store internals, the
unreleased Rust port and a Ctrl-B keybinding manual, and documented
`rover agent session` commands and TUI keys that only the Rust preview
has; the installed Go `rover` rejects them. It also said Linux was
required, called the 0.2.0-alpha.1 report "Current validation", and
claimed no public repo, hosted CI or release existed.

- README now leads with what Rover is, install-from-source steps, one
  platform matrix (Linux validated in hosted CI; macOS observed when
  built with cgo, cross-built darwin binaries have a stub store; Windows
  unsupported), the quickstart and the existing Go usage. A short "Rust
  port (preview, not the product)" section points to the new
  docs/RUST_PREVIEW.md, which holds the rover-rs build steps, state
  location, TUI key table, agent session commands and gaps.
- docs/validation/v0.0.1/REPORT.md records the hosted CI run for the
  v0.0.1 tag (go1.27.1 from setup-go 'stable', steps and results) and
  the later main run; README labels the 0.2.0-alpha.1 report historical.
- STATUS keeps the Rust progress narrative in its own section, states
  that Rover does not build, test or support Windows (portable-pty's
  ConPTY backend is not a Rover capability), reframes the increment log
  as history (A-H shipped in v0.0.1, I is unreleased, make sdk-test no
  longer exists) and replaces "no hosted workflow was run" and "Linux
  validation pending" with the hosted CI facts.

Refs: F064, F065, F066, F070, F071, F074, F275, F276
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SECURITY, SUPPORT and GOVERNANCE still described an unpublished "source
bundle" with no public repository, hosted issue queue or intake channel,
while GrayCodeAI/rover is public with issues enabled, a v0.0.1 release
and green hosted CI.

- SECURITY: report privately to security@graycodeai.com; say plainly that
  GitHub private vulnerability reporting is not enabled yet (the API
  reports enabled=false) and will become the second channel; no SLA;
  explain release provenance verification.
- SUPPORT: public repo, source-only v0.0.1 tag, no package-manager
  listing or SLA, GitHub issues for problems, hello@graycodeai.com for
  anything else, and why `go install` is not a documented path.
- GOVERNANCE: maintainers are the GrayCodeAI organization owners.

Refs: F065, F275
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`make manifest-check` only printed "SOURCE_MANIFEST.json is stale", so a
contributor had to diff 400+ entries by hand to learn that, say, only
CHANGELOG.md drifted. --check now lists up to 20 missing, no-longer-
tracked and changed paths plus any version change, and reports a missing
or unparsable manifest separately. manifest-check runs the new unit tests
first.

Refs: F063
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CI now enforces `make rust-check` on Rust 1.88.0 (fmt, clippy pedantic
lints as errors, tests, license audit), but CONTRIBUTING, ROADMAP and
AGENTS.md never mentioned Rust, cargo or rustup, and CONTRIBUTING still
said CI definitions were not evidence of any hosted run.

CONTRIBUTING lists the toolchain install command, when to run
rust-check and rust-notices, and the `make manifest` step that CI
enforces. ROADMAP gains a Rust port section pointing to the parity plan
and ADR index. AGENTS.md tells coding agents which gates to run and that
the Rust preview is unreleased.

Refs: F072, F075
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs/design/README.md was titled "Historical design reference" and told
readers not to treat anything in the folder as current, yet the folder
now holds 27 accepted Rust ADRs and the active parity plan. It is now an
index: current decisions and plans (with what each covers and a note
that ADR commands run as `rover-rs` until cutover) and, separately, the
historical ten-layer master plan. The Rust preview page also says the Go
state importer is a store API, not yet a CLI command.

Refs: F075
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Three tracked research notes cited sdk/ paths, rover_client and passing
`make sdk-test` runs as current evidence with no marker, so their
relative links were dead and they contradicted the SDK removal. Each now
opens with a historical-snapshot banner, research_notes/README.md
explains how to read all seven dated notes, and the report's command
block labels `make sdk-test` historical instead of current.

Refs: F068
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs/ARCHITECTURE.md still listed a "Python CLI client" among Rover's
interfaces after the SDK trees were deleted; the diagram now shows the
remote CLI client that does exist. docs/SOURCES.md described the tree as
an upgrade of 0.1.0-alpha.1 without saying that line was renumbered to
the public 0.0.1 release.

Refs: F276
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nges

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`make manifest-check` (run by CI and the release workflow) failed on main
because CHANGELOG.md had changed after the last regeneration, and it
would have failed again once the Rust workspace, notices and ADRs were
tracked. Regenerated with `make manifest`: 628 entries (62 crates/,
320 licenses/, 35 docs/design/, no sdk/), version 0.0.1.

Refs: F062, F063
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The first hosted `rust` job failed `make rust-clippy` on ubuntu-24.04:
three clippy pedantic lints (similar_names, question_mark,
inefficient_to_string) sit in `cfg(target_os = "linux")` code in
rover-execution's PTY foreground-process sampler, which macOS clippy
never compiles. Rename the `pgid` parameter to `foreground_group`,
replace a `let ... else { return None }` with `?` (same semantics in an
Option-returning function), and build the start-time String from the
dereferenced &str. Behaviour is unchanged.

Verified locally with
`cargo +1.88.0 clippy --workspace --all-targets --locked --offline
--target x86_64-unknown-linux-gnu -- -D warnings`, which reproduces the
three CI errors on the old code and passes on the new code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t fix

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The first green hosted run of the split workflow (run 36279833786)
finished the rust job in 1 min 22 s with no cache (clippy build 27.6 s,
test build 31.4 s, 319 Linux tests) and the go job in 2 min 40 s.
SOURCE_MANIFEST.json regenerated for the doc change.

Refs: F069
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant