Skip to content

Add licensing, spelling, and unsafe-documentation gates - #7

Merged
P4suta merged 2 commits into
mainfrom
agent/add-licensing-and-unsafe-documentation-gates
Aug 3, 2026
Merged

P4suta merged 2 commits into
mainfrom
agent/add-licensing-and-unsafe-documentation-gates

Conversation

@P4suta

@P4suta P4suta commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Closes the two baseline gaps that separated this repository from its siblings. Both turned up real findings rather than just adding ceremony.

Licensing and spelling

  • Add REUSE.toml and LICENSES/, reaching REUSE 3.3 compliance at 58/58 files. This was the only one of the four Windows crates with no REUSE metadata at all. Annotations are path-based rather than per-file SPDX headers — matching windows-spawn — so no source file needed touching.
  • Add _typos.toml and run both tools in a new required Licensing and spelling job. The spell-check found one real misspelling in a CI helper test label (unparseable → unparsable); the helper self-test still passes.
  • Ship REUSE.toml and LICENSES/ in the package, as the siblings do.

Unsafe documentation

Deny clippy::undocumented_unsafe_blocks workspace-wide. CONTRIBUTING.md already required a specific safety justification on every unsafe block, and ADR 0003 confines unsafe to src/sys.rs — but nothing enforced either.

Fifteen blocks had no justification:

  • Two in production code — RmCancelCurrentTask and RmEndSession, where the argument is that the ended guard serializes the call and the upgraded Arc keeps the session alive across it.
  • Thirteen in the hardening tests that deliberately fabricate malformed RM_FILTER_INFO records with out-of-bounds and misaligned strFilename pointers and unterminated strings. That is precisely where the invariants most needed writing down: the reader has to be able to tell "this pointer is bogus on purpose, and the parser must reject it without dereferencing" from an actual defect.

Verification

fmt, clippy -D warnings (with the new lint), test --workspace --all-targets --all-features, test --doc, typos, reuse lint, cargo deny check, and the Dependabot policy self-test all pass locally. cargo package --list confirms the new licensing files ship.

Does not touch #4.

Closes the two baseline gaps that separated this repository from its
siblings, both of which turned up real findings.

Licensing and spelling:

- Add REUSE.toml and LICENSES/, reaching REUSE 3.3 compliance at 58/58
  files. This was the only one of the four Windows crates with no REUSE
  metadata at all. Annotations are path-based rather than per-file SPDX
  headers, matching windows-spawn, so no source file needed touching.
- Add _typos.toml and run both tools in a new required CI job. The
  spell-check found one real misspelling in a CI helper test label.
- Ship REUSE.toml and LICENSES/ in the package, as the siblings do.

Unsafe documentation:

- Deny clippy::undocumented_unsafe_blocks workspace-wide. CONTRIBUTING
  already required a specific safety justification on every unsafe block
  and ADR 0003 confines unsafe to src/sys.rs, but nothing checked it.
- Fifteen blocks had no justification. Two were production code
  (RmCancelCurrentTask and RmEndSession, where the argument is that the
  `ended` guard serializes the call and keeps the session alive). The
  other thirteen were the hardening tests that deliberately fabricate
  malformed RM_FILTER_INFO records with out-of-bounds and misaligned
  pointers -- precisely where the invariants most needed writing down.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@P4suta
P4suta enabled auto-merge (squash) August 3, 2026 11:40
fsfe/reuse-action and crate-ci/typos are not on this repository's Actions
allowlist, so the CI workflow failed at startup rather than running. The
allowlist is a deliberate security control, so install both tools directly
rather than widening it; taiki-e/install-action is already allowed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@P4suta
P4suta merged commit 891c690 into main Aug 3, 2026
26 checks passed
@P4suta
P4suta deleted the agent/add-licensing-and-unsafe-documentation-gates branch August 3, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant