Repository navigation
Adopt the Polonius-enabled nightly and retire the -Z directive - #577
Conversation
|
Warning Your free Security trial is over. An organization admin can activate billing to continue. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
Summary
WalkthroughThe repository now uses ChangesPolonius nightly migration
Poem
Merge Risk: 🟡 Moderate · up to The change updates the pinned compiler and build/test configuration, but the current head still has a bounded error-reporting defect that can mislabel malformed coverage data, along with two contradictory developer-guide statements about Kani and NLL compatibility. These should be corrected or explicitly accepted before merge. Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (2 errors, 4 warnings)
✅ Passed checks (14 passed)
Full details: Title checkExplanation The title accurately summarises the main change: adoption of the Polonius-enabled nightly toolchain and removal of the explicit -Z directive. No roadmap or issue reference is required by the supplied context. Full details: Description checkExplanation The description directly explains the toolchain update, removal of explicit Polonius configuration, contract-test changes, compatibility fixes, documentation updates, and validation results. It is clearly related to the changeset. Full details: Docstring CoverageExplanation Docstring coverage is 87.60% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 121 functions across 25 files. (4 skipped: 4 unsupported.) Full details: Testing (Overall)Explanation Strengthen the tests for the new Cargo artefact parser. Resolution Add focused parser tests for malformed and non- Full details: User-Facing DocumentationExplanation Pass the check. The changed source and registry installation behaviour is documented in Full details: Developer DocumentationExplanation The developer guide documents the new toolchain, Cargo layouts, response-file helpers, coverage boundaries, and binary locator. ADR-006 also records the change in a dated addendum. However, the PR directly edits accepted ADR-007 without an addendum: its Decision section now changes the source-build requirement from “the pinned nightly and the Polonius flag” to only “the pinned nightly”, and its Date remains 2026-08-05. This is a retroactive edit to an accepted ADR, which violates the check. Resolution Restore ADR-007's historical wording and append a dated addendum that records the new pinned-nightly-only source-build requirement and any related formatting or installation consequences. Keep the original decision text intact, and update the ADR date or addendum date according to the repository convention. Full details: Module-Level DocumentationExplanation Pass the check. Every changed Python module has a leading module docstring, including Full details: Testing (Unit And Behavioural)Explanation Fail: the pull request adds new command-line and helper behaviour without complete boundary and edge-case coverage. Resolution Add an end-to-end test for the documentation-coverage CLI or Full details: Testing (Property / Proof)Explanation The PR introduces range- and ordering-based invariants without property coverage for all new helpers. Resolution Add substantive property-based tests for the new invariants. Generate ordered Cargo artefact lists and assert that Full details: Testing (Compile-Time / Ui)Explanation Pass this check. The PR retains Rust-specific compile-time coverage through direct Full details: Unit ArchitectureExplanation The new Resolution Split the Cargo/Rustdoc process and generated-file adapter into a narrow Full details: Domain ArchitectureExplanation Fail this check because the new Resolution Move Rustdoc JSON decoding, payload-shape validation, and generated-file handling into a dedicated Cargo/Rustdoc adapter such as Full details: ObservabilityExplanation PASS — keep this check passed. The aggregate diff from main changes only test modules under Full details: Security And PrivacyExplanation No security or privacy failure is introduced. The aggregate diff adds no secret or credential values and does not change workflow permissions or token handling. New Cargo and Rustdoc subprocess calls use argument arrays without shell evaluation. JSON and TOML inputs use parsers. The direct-rustc helpers pass paths as arguments and reject newline-bearing response-file arguments. The environment-isolated Netsuke helper was moved without changing its existing behaviour. The new coverage-file path handling uses Full details: Performance And Resource UseExplanation No material performance or resource-use failure was introduced. The changed executable code is a documentation-coverage gate and test-support code, not a production hot path. Full details: Concurrency And StateExplanation Pass the concurrency and state check. The changed process paths are synchronous: Full details: Architectural Complexity And MaintainabilityExplanation Pass. Keep the new boundaries. The original Full details: Rust Compiler Lint IntegrityExplanation Pass the check. The PR adds no broad ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Your free Security trial is over. An organization admin can activate Security or dismiss this notice. Comment |
Reviewer's GuideMoves the pinned Rust toolchain to a Polonius-default nightly and removes all Sequence diagram for UI harness dependency discoverysequenceDiagram
participant Harness as UI test harness
participant Cargo as Cargo 1.99
participant Rustc as rustc fixture compiler
Harness->>Cargo: cargo metadata/build with JSON messages
Cargo-->>Harness: compiler-artifact loadable filenames
Harness->>Harness: profile_dir(executable_path)
Harness->>Rustc: Compile fixture with -L dependency=parent_directories
Rustc-->>Harness: Fixture result
Flow diagram for the toolchain contract safeguardflowchart TD
Start[Build configuration] --> Channel[Read pinned channel]
Channel --> ValidChannel{Dated nightly >= 2026-08-04?}
ValidChannel -- No --> Fail[Contract test fails]
ValidChannel -- Yes --> Scan[Scan Makefile, Cargo config, and workflows]
Scan --> Directive{-Zpolonius directive found?}
Directive -- Yes --> Fail
Directive -- No --> Pass[Policy accepted]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
d828eff to
f1923cd
Compare
f1923cd to
ae6ea6c
Compare
ae6ea6c to
15efb15
Compare
|
@coderabbitai Please investigate the cause of the following issue using codegraph exploration and research, identify a fix and provide an AI coding agent prompt for the fix: https://github.com/leynos/netsuke/actions/runs/32751351959/job/97508796453?pr=577 |
This comment was marked as resolved.
This comment was marked as resolved.
e67be8d to
1fafe72
Compare
There was a problem hiding this comment.
Sorry @leynos, your pull request is larger than the review limit of 150,000 diff characters
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1fafe729c4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@coderabbitai re:
Is it the case that Kani cannot be run with the 2026-08-23 nightly? |
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
|
@coderabbitai Please suggest a fix for this issue and supply a prompt for an AI coding agent to enable it to apply the fix. Include the file and symbol names indicated in the issue at the head of your response. Ensure that this is validated against the current version of the codegraph. If further refinement to address this finding would be deleterious, please supply a clear explanatory one to two paragraph markdown message in a code block that I can paste into the CodeScene web ui's diagnostic suppression function so this diagnostic can be silenced. Complex Conditionalscripts/doc_coverage_model.py: coverage_count What lead to degradation?coverage_count has 1 complex conditionals with 2 branches, threshold = 2 Why does this problem occur?A complex conditional is an expression inside a branch such as an if-statmeent which consists of multiple, logical operations. Example: if (x.started() && y.running()).Complex conditionals make the code even harder to read, and contribute to the Complex Method code smell. Encapsulate them. How to fix it?Apply the DECOMPOSE CONDITIONAL refactoring so that the complex conditional is encapsulated in a separate function with a good name that captures the business rule. Optionally, for simple expressions, introduce a new variable which holds the result of the complex conditional. Helpful refactoring examplesTo get a general understanding of what this code health issue looks like - and how it might be addressed - we have prepared some diffs for illustrative purposes. SAMPLE# complex_conditional.js
function messageReceived(message, timeReceived) {
- // Ignore all messages which aren't from known customers:
- if (!message.sender &&
- customers.getId(message.name) == null) {
+ // Refactoring #1: encapsulate the business rule in a
+ // function. A clear name replaces the need for the comment:
+ if (!knownCustomer(message)) {
log('spam received -- ignoring');
return;
}
- // Provide an auto-reply when outside business hours:
- if ((timeReceived.getHours() > 17) ||
- (timeReceived.getHours() < 8)) {
+ // Refactoring #2: encapsulate the business rule.
+ // Again, note how a clear function name replaces the
+ // need for a code comment:
+ if (outsideBusinessHours(timeReceived)) {
return autoReplyTo(message);
}
pingAgentFor(message);
+}
+
+function outsideBusinessHours(timeReceived) {
+ // Refactoring #3: replace magic numbers with
+ // symbols that communicate with the code reader:
+ const closingHour = 17;
+ const openingHour = 8;
+
+ const hours = timeReceived.getHours();
+
+ // Refactoring #4: simple conditional rules can
+ // be further clarified by introducing a variable:
+ const afterClosing = hours > closingHour;
+ const beforeOpening = hours < openingHour;
+
+ // Yeah -- look how clear the business rule is now!
+ return afterClosing || beforeOpening;
} |
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
Inject the Cargo and Rustdoc boundary into coverage orchestration, while keeping explicit process configuration and payload validation in its adapter. Expand parser and executable CLI coverage, and record the pinned-nightly requirement for cargo-binstall source fallbacks.
|
@coderabbitai Please suggest a fix for this issue and supply a prompt for an AI coding agent to enable it to apply the fix. Include the file and symbol names indicated in the issue at the head of your response. Ensure that this is validated against the current version of the codegraph. If further refinement to address this finding would be deleterious, please supply a clear explanatory one to two paragraph markdown message in a code block that I can paste into the CodeScene web ui's diagnostic suppression function so this diagnostic can be silenced. scripts/tests/test_doc_coverage.py Comment on file boundaries with canned responses so the script's own logic — target
discovery, aggregation, threshold exits, malformed-output handling, and
command-failure translation — is exercised without invoking Cargo at all.
``scripts/doc_coverage_cargo.py`` wraps ``cargo rustdoc --show-coverage`` and❌ New issue: Low Cohesion |
|
@coderabbitai Please suggest a fix for this issue and supply a prompt for an AI coding agent to enable it to apply the fix. Include the file and symbol names indicated in the issue at the head of your response. Ensure that this is validated against the current version of the codegraph. If further refinement to address this finding would be deleterious, please supply a clear explanatory one to two paragraph markdown message in a code block that I can paste into the CodeScene web ui's diagnostic suppression function so this diagnostic can be silenced. scripts/tests/test_doc_coverage.py Comment on file )
def test_main_rejects_invalid_coverage_counts(
script: types.ModuleType,
cargo: types.ModuleType,❌ New issue: Excess Number of Function Arguments |
|
@coderabbitai Please suggest a fix for this issue and supply a prompt for an AI coding agent to enable it to apply the fix. Include the file and symbol names indicated in the issue at the head of your response. Ensure that this is validated against the current version of the codegraph. If further refinement to address this finding would be deleterious, please supply a clear explanatory one to two paragraph markdown message in a code block that I can paste into the CodeScene web ui's diagnostic suppression function so this diagnostic can be silenced. scripts/tests/test_doc_coverage.py Comment on lines +975 to +976 runner: types.ModuleType,
cargo: types.ModuleType,❌ New issue: Excess Number of Function Arguments |
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
This comment was marked as resolved.
Reach the injected Cargo adapter through the already-loaded CLI runner so the invalid-payload test stays below the CodeScene parameter threshold.
|
@coderabbitai review |
|
Reuse the Cargo adapter held by the loaded CLI runner so the invalid-count coverage test remains below the CodeScene parameter threshold.
Separate the doc-coverage test suite by model, Cargo adapter, Cargo payload, runner, and CLI boundaries. Keep dynamic import ordering in shared fixtures and execute every focused module through `make doc-coverage-test`.
Keep the split test modules compliant with the repository Ruff policy without changing the production or CLI contracts.
Summary
This branch moves the pinned Rust toolchain from
nightly-2026-06-25tonightly-2026-08-13and removes every instruction that passed a-Zpoloniusdirective to Cargo. Nightlies dated 2026-08-04 and later run thePolonius alpha analysis by default, so the dated pin now carries the
borrow-checker requirement on its own and the directive is redundant.
The plumbing is removed wholesale rather than left inert. The directive is
being retired upstream, and a build that restates it is a build that can
silently drop it — the failure mode the old contract test existed to catch.
ADR-006's decision is unchanged; only the mechanism that implements it is.
Review walkthrough
Start with the two files that define the new policy:
— the bumped pin, and the comment explaining that the channel is now the
whole mechanism.
— the amended Decision section. It records what the retired plumbing was
and why it existed, so the removal reads as a supersession rather than a
gap.
Then the inverted contract, which is the safeguard against regression:
— the test no longer asserts the flag is present everywhere. It now
requires the pinned channel to be a dated nightly at or after 2026-08-04,
and fails if any build-configuration surface reintroduces a
-Zpoloniusdirective.
Then the removals themselves, which are mechanical:
.cargo/config.tomlis deleted; carrying the flag was its only purpose.—
POLONIUS_FLAGSis gone.kani-fulland the binary-build recipe now setno
RUSTFLAGSat all, so only the lint gates set it, and only to denywarnings.
and the four workflows'
with.rustflagsinputs.— the rewritten "Toolchain and borrow checker" section, and the
shared-action contract
below it.
Finish with the fallout the newer toolchain surfaced, which is the least
obvious part of the branch. Cargo 1.99 no longer creates
target/debug/deps/:it runs integration tests from
<profile>/build/<pkg>/<hash>/out/and givesevery crate its own directory.
—
profile_dirderives the profile directory from either executablelayout. This module is new only in the sense that it was split out of
test_support/src/netsuke.rs, which had grown past the module line cap.and
tests/command_env_ui_tests.rs
— both UI-fixture harnesses now collect the parent directory of every
loadable artefact Cargo reports. Note that this must accept proc-macro
dynamic libraries as well as rlibs: a shared
deps/directory used to pickproc macros up as a side effect, so an rlib-only filter went unnoticed
until each crate got its own directory, at which point dependents failed
with
E0463.Two clippy lints new to this nightly are fixed at the source rather than
suppressed:
assert_is_emptyintests/ir_tests.rs,
src/graph_view/tests.rs
and
src/status_timing_tests.rs,
and
chunks_exact_to_as_chunksinsrc/hex_property_tests.rs.
Validation
All four gates run on the bumped toolchain, sequentially, from a clean tree:
The Polonius default was verified empirically rather than taken from the
compiler's
-Z helptext, which still reportsdefault: no. The classicNLL problem case #3 — a conditional early return of a borrow from a map —
compiles with no flag on
nightly-2026-08-13and is rejected onnightly-2026-06-25.Notes
which for 0.67.0 is
nightly-2025-11-21— earlier than the Poloniusdefault. Under the retired flag,
make kani-fullpassed-Zpolonius=nextthrough
RUSTFLAGSand so got the analysis; it no longer does. This isharmless today because the tree has no
POLONIUS(...)-tagged sites, but itis a real gap. Both
docs/polonius.md
and the developers' guide record it, and say to move Kani forward rather
than reinstate the directive.
-Zpolonius=legacyis not an NLL fallback. It was checked: it acceptsthe same programs as the default. Classifying a new borrow-centric API
against NLL now means compiling it on a pre-2026-08-04 nightly, which
docs/polonius.md
states.
CHANGELOG.mdis unchanged. The repository follows Common Changelogand keeps no
Unreleasedsection; the existing Polonius entry sits underthe released
0.1.0-beta1heading and describes what that release did.Recording this change is left to the next release cut, when the version
heading exists.
RUSTFLAGScontract model was simplified. Every recipe that stillsets
RUSTFLAGSdoes so for one reason — to deny warnings whileconditionally preserving an inherited value — so the per-case
WarningPolicyandInheritancePolicyfields had no remaining variantsand were removed. A recipe needing a different policy will fail the
assertions rather than pass silently, which is the signal to reintroduce
them.
Summary by Sourcery
Adopt the newer Polonius-enabled nightly as the sole compiler-policy mechanism and remove the retired explicit directive from build configuration, CI, documentation, and tests.
Bug Fixes:
Enhancements:
CI:
Documentation:
Tests:
Chores:
References