From 1020a71c7c32efbc2d8e1aea952afda6f44b30dd Mon Sep 17 00:00:00 2001 From: Albert Hui Date: Wed, 19 Aug 2026 06:43:14 +0000 Subject: [PATCH] chore(ci): delete the unsafe audit that cannot fail - run: cargo geiger 2>&1 || true continue-on-error: true `|| true` on the step and `continue-on-error` on the job: this check has never been capable of reporting anything. It is also a SIBLING of the shared-workflow call rather than a job inside it, so `ci / All checks` never reached it and branch protection never required it. Eighteen repos carried a byte-identical copy. Deleting rather than fixing, because a working exit code would not help. Where `unsafe_code = "forbid"` is in force, `unsafe` is a compile error, so a job asserting its absence still could not fail -- the same defect with a healthier appearance. The real control is now in the shared workflow: `Unsafe lint audit` asserts that every workspace member EFFECTIVELY forbids or denies `unsafe_code`, which is the part the compiler cannot tell you. A member with no `[lints]` table does not inherit workspace lints (inheritance is opt-in via `[lints] workspace = true`), and a member with its own `[lints]` table replaces inheritance rather than extending it. Either way it compiles with `unsafe` permitted while the workspace root still reads compliant. That check lives inside the gate, is required by branch protection, and found five unprotected published crates on its first run. A check that cannot fail is worse than no check: it reads as coverage that does not exist. --- .github/workflows/ci.yml | 21 --------------------- 1 file changed, 21 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b173abd..488950b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -44,24 +44,3 @@ jobs: # `coverage-gate: strict`. types.rs at 24% of lines is the largest gap. coverage-gate: floor coverage-floor: 60 - - # Reporting only — fuser and the FFI surface use unsafe by necessity. Review - # the output; a spike vs baseline warrants investigation. Repo-specific, so it - # stays here rather than moving into the shared workflow. Carried over - # verbatim, including the path-dep rewrite it needs to resolve fleet deps from - # crates.io. - geiger: - name: Unsafe Audit (cargo-geiger) - runs-on: ubuntu-latest - continue-on-error: true - steps: - - run: sudo apt-get update && sudo apt-get install -y libfuse3-dev pkg-config - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - name: Use crates.io for fleet deps (drop local path deps) - run: sed -i -E 's/, path = "[^"]*"//' Cargo.toml - - uses: dtolnay/rust-toolchain@stable - - uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2.7.8 - with: - cache-on-failure: true - - run: cargo install cargo-geiger --locked - - run: cargo geiger 2>&1 || true