Skip to content

Use owned strings for borrowed string values - #545

Open
leynos wants to merge 1 commit into
harden-lint-frontmatterfrom
harden-lint-string-ownership
Open

leynos wants to merge 1 commit into
harden-lint-frontmatterfrom
harden-lint-string-ownership

Conversation

@leynos

@leynos leynos commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

This source-fix layer replaces 336 measured str_to_string sites where borrowed string values need an owned String. It preserves the resulting values and prepares the code for the later denied Clippy baseline. The 33-file patch is one behaviour-preserving commit on top of PR #544, which repairs frontmatter bounds. Subsequent source-fix waves will handle the remaining measured lint sites; this PR does not enable final enforcement.

Review walkthrough

Validation

At commit d48ff7a8e4a9ebc409ab056cc7d7172abce4e526 on PR #544
168caf8f88a326f6a78bc83b1531efee100edaee, the single child commit
retains stable patch ID ba37eb624da23f0c055f7c490542e7b3f87cbefb
and a 1:1 range-diff. The parent added a separate
token-grouping test;
the child conversion remains unchanged.

All eight Make gates passed sequentially: make check-fmt, make lint,
make test, make typecheck, make markdownlint, make nixie,
make verus, and make verus-selftest. Captured logs are under
/tmp/pr545-restack-<gate>-d48ff7a.out. Local
cs delta 168caf8f88a326f6a78bc83b1531efee100edaee d48ff7a8e4a9ebc409ab056cc7d7172abce4e526
reported no issues.

CI run 35968706652
passed all six jobs on this exact head, including build-test and the Windows
atomic-write contract. Verus run 35968706628,
CodeScene result 7671172,
and Gecko also passed. Managed CodeRabbit request f89a98c9 remains
queued; the skipped automatic check is not a review.

Notes

The Phase-0 proposed-baseline Clippy measurement was a lower bound because root compilation stopped before all integration targets; those targets and Whitaker remain unmeasured under final enforcement. Existing gates pass under this layer's current configuration. This PR is a source-fix wave, so its green current-configuration gates do not assert final-baseline compliance.

References

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: df908be0-a484-4a51-a453-2236c68e264c

📥 Commits

Reviewing files that changed from the base of the PR and between 168caf8 and d48ff7a.

📒 Files selected for processing (33)
  • src/code_emphasis.rs
  • src/fences/attachment.rs
  • src/footnotes/renumber/definitions/tests.rs
  • src/footnotes/renumber/reorder/tests.rs
  • src/footnotes/renumber/tests.rs
  • src/footnotes/tests.rs
  • src/html.rs
  • src/html_tests.rs
  • src/io/replace.rs
  • src/io_line_ending_tests.rs
  • src/io_metrics_tests.rs
  • src/lists.rs
  • src/process/code_emphasis_tests.rs
  • src/process/tests.rs
  • src/reflow/tests/cell_parsing.rs
  • src/table/tests/mod.rs
  • src/table/tests/split_cells.rs
  • src/wrap/continuation.rs
  • src/wrap/continuation_tests.rs
  • src/wrap/inline/normalize.rs
  • src/wrap/inline/span_helper_coupling_tests.rs
  • src/wrap/inline/span_helper_props.rs
  • src/wrap/paragraph/pending.rs
  • src/wrap/paragraph_tests.rs
  • src/wrap/tests/inline_wrapping.rs
  • src/wrap/tests/link_ref_regex.rs
  • src/wrap/tests/link_reference_definitions.rs
  • src/wrap/tests/prefix.rs
  • src/wrap/tests/span_grouping_props.rs
  • src/wrap/tests/tail_deferral.rs
  • src/wrap/tests/thematic_break.rs
  • src/wrap/tests/token_grouping.rs
  • src/wrap/tokenize/parsing_tests.rs
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • leynos/netsuke (auto-detected)
  • leynos/df12-dylint-builds (auto-detected)
  • leynos/typos-config-builder (auto-detected)
  • leynos/falcon-correlate (auto-detected)
  • leynos/msgspec-crockford (auto-detected)
  • leynos/vk (auto-detected)
  • leynos/simulacat-core (auto-detected)
  • leynos/agent-template-python (auto-detected)
  • leynos/shared-actions (auto-detected)
  • leynos/cuprum (auto-detected)

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


Summary

  • Replace borrowed-string .to_string() conversions with .to_owned() across source code and tests.
  • Preserve existing conversion behaviour and test cases. This prepares the codebase for a later Clippy baseline; it does not enable final lint enforcement.

Validation

  • The PR description reports that all eight Make gates passed sequentially and all six CI jobs passed on the stated head.
  • Verus, CodeScene and Gecko also passed.
  • Final-baseline Clippy measurement remains incomplete for some integration targets and Whitaker.

Reviews

  • No substantive review findings were supplied.

Walkthrough

This change replaces to_string() with to_owned() in string conversions across implementation code and tests. The supplied summaries report no changes to inputs, expected values, assertions or processing behaviour.

Changes

String conversion updates

Layer / File(s) Summary
Text processing and table conversions
src/code_emphasis.rs, src/fences/attachment.rs, src/html*.rs, src/io/*, src/io_*tests.rs, src/lists.rs, src/process/*tests.rs, src/reflow/tests/*, src/table/tests/*
Implementation code and tests use to_owned() in place of to_string(). Inputs, expected values and assertions remain unchanged.
Footnote conversions
src/footnotes/*
Footnote tests, helpers and fixtures use to_owned() in place of to_string(). Test cases and assertions remain unchanged.
Wrapping conversions
src/wrap/*
Wrapping code and tests use to_owned() in place of to_string(). Continuation handling, test inputs and expected outputs remain unchanged.

Priority: ⬇️ Low

Change: Refactor

Merge Risk: ⚪ Minimal · up to d48ff

This change preserves the strings used by the application and its tests, with no identified user-facing behavior change. It is ready to merge subject to normal checks.

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: replacing borrowed-value string conversions with owned strings. No roadmap item or issue reference is required by the provided context.
Description check ✅ Passed The description directly explains the 336 behaviour-preserving conversions, the Clippy preparation, validation results, scope, and relationship to PR #544.
Docstring Coverage ✅ Passed Docstring coverage is 91.74% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 121 functions across 33 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Testing (Overall) ✅ Passed PASS — The pull request introduces no new functionality or behavioural change. The authoritative diff replaces borrowed-string conversions from .to_string() with .to_owned() and applies related fo…
User-Facing Documentation ✅ Passed Pass the documentation check. The PR changes only 33 Rust files. Production changes replace to_string() with to_owned() for borrowed string values, with no user-facing behaviour or public API chan…
Developer Documentation ✅ Passed Pass this check. The review-scoped diff changes only 33 Rust source files under src/. The production changes replace string conversion calls such as to_string() with to_owned() and do not change…
Module-Level Documentation ✅ Passed Pass the module-level documentation check. All 156 Rust source files have file-level //! documentation, including every changed file. The exact pull-request diff changes string-conversion methods an…
Testing (Unit And Behavioural) ✅ Passed Pass the check. The authoritative diff changes only borrowed-to-owned string conversion sites, with minor formatting in test fixtures; it does not change test markers, function counts, assertions, inp…
Testing (Property / Proof) ✅ Passed Pass. The authoritative diff changes 33 Rust files by replacing borrowed-string conversions such as to_string() with to_owned(), plus rustfmt line wrapping. Normalising these conversion names remo…
Testing (Compile-Time / Ui) ✅ Passed Pass this check. The PR changes only to_string()/str::to_string calls to to_owned() across 33 Rust files. The production replacements preserve String values and do not change public declaratio…
Unit Architecture ✅ Passed Mark this check PASS. The authoritative diff changes only to_string()/str::to_string conversions to to_owned(), plus formatting-only line wrapping. Production changes retain existing function si…
Domain Architecture ✅ Passed The PR changes only borrowed-string ownership calls from to_string() to to_owned() across 33 Rust files. The production hunks retain the same functions, control flow, and dependencies. The remaini…
Observability ✅ Passed Mark Observability as passed. The reviewed range changes only borrowed-string ownership calls from to_string() to to_owned(), plus test-fixture formatting. The production hunks preserve control fl…

A borrowed slice, now owned with care
The same text travels everywhere
Tests keep their values, lines and flow
While to_owned() takes the show
No output shifts; the strings stay so

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Reviewer's Guide

This source-fix wave mechanically replaces 336 measured .to_string() conversions of borrowed string values with .to_owned() across production and test code, preserving behavior while preparing the codebase for stricter Clippy ownership-lint enforcement. It does not enable final enforcement; the documented formatting, lint, type, documentation, verification, and test gates pass under the current configuration.

File-Level Changes

Change Details Files
Replace borrowed-string conversions with explicit owned-string conversions across production code.
  • Use .to_owned() for borrowed &str values converted into String in HTML conversion, fence handling, I/O, metrics, and wrapping paths.
  • Cover the measured ownership-lint sites without changing data flow or output semantics.
src/fences/attachment.rs
src/html.rs
src/io/replace.rs
src/io_metrics_tests.rs
src/wrap/continuation.rs
src/wrap/paragraph/pending.rs
Apply the same ownership-conversion cleanup throughout unit, integration, regression, and property-based tests.
  • Update test fixtures, expected values, helper mappers, and proptest strategies from .to_string() to .to_owned().
  • Preserve existing behavioral assertions for footnotes, tables, HTML, code emphasis, lists, wrapping, links, and reflow.
src/code_emphasis.rs
src/footnotes/renumber/definitions/tests.rs
src/footnotes/renumber/reorder/tests.rs
src/footnotes/renumber/tests.rs
src/footnotes/tests.rs
src/html_tests.rs
src/io_line_ending_tests.rs
src/lists.rs
src/process/code_emphasis_tests.rs
src/process/tests.rs
src/reflow/tests/cell_parsing.rs
src/table/tests/mod.rs
src/table/tests/split_cells.rs
src/wrap/continuation_tests.rs
src/wrap/inline/normalize.rs
src/wrap/inline/span_helper_coupling_tests.rs
src/wrap/inline/span_helper_props.rs
src/wrap/paragraph_tests.rs
src/wrap/tests/inline_wrapping.rs
src/wrap/tests/link_ref_regex.rs
src/wrap/tests/link_reference_definitions.rs
src/wrap/tests/prefix.rs
src/wrap/tests/span_grouping_props.rs
src/wrap/tests/tail_deferral.rs
src/wrap/tests/thematic_break.rs
src/wrap/tests/token_grouping.rs
src/wrap/tokenize/parsing_tests.rs

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

codescene-access[bot]

This comment was marked as outdated.

@leynos
leynos marked this pull request as ready for review September 24, 2026 00:46

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @leynos, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 14 hours and 3 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T00:48:34.843196Z 4a409d0 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Replace 336 measured `str_to_string` occurrences in the footnote,
table, process, wrap, and supporting source areas. Preserve the
resulting `String` values while satisfying the planned Clippy baseline.
@leynos
leynos force-pushed the harden-lint-string-ownership branch from 4a409d0 to d48ff7a Compare September 24, 2026 07:16
@leynos
leynos added this pull request to stack #557 September 24, 2026 16:15
@pandalump

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants