build(rust): pin all product and release lanes to 1.97.1 - #944
seonghobae wants to merge 89 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
#1258 adds a new valid Fresh live evidence from #970 I am not adding a second concurrent Do not treat the default merge-ref behavior as exact-head GREEN/RED, and do not fix it with a no-op trigger, force-push, destructive rebase, synthetic status, or required-gate weakening. |
|
Fresh exact-head authority on
These two successes are genuine evidence for the current two-parent/#1176-stacked head, but they do not make the PR GREEN. Keep Draft; no predecessor-evidence transfer, no blind rerun/no-op wake commit, and no protected reconciliation until #1176 reaches protected ancestry and the remaining exact-head gates settle. |
Canonical Rust-toolchain / generic-CI owner
Status: OPEN / Draft / do not merge.
develop@314ddeae7b775a4957594b599358c8255617eb2e8fe6b6d99c009527ef0bcba419e6f6debdb23c23agent/rust-toolchain-refresh-2026-08-19db0b7709f48161ca74ff6402ee5f75e136fea40cbolt-performance-chart-export-13223013812255847379Every source movement invalidates predecessor check/review evidence.
Rust 1.97.1 contract
BandScope pins repository-owned Rust execution to
1.97.1without widening crate MSRV. Rootrust-toolchain.toml, Dependabot update discovery, executable policy verification, ordinary CI, release preflight, dependency audit, and Windows/macOS amd64/arm64 packaging must share that exact reviewed compiler identity. The dedicated verifier rejects floatingstable, cross-job evidence borrowing, and failure-masked shell evidence.Predecessor
407c93773cf0403d3f32e3ddbd77f754b85bae61repaired release preflight, the consolidated security backstop, four native packaging lanes, and the Rust-contract verifier.6fb5d8e64351ff63ec9ba23143fdfa012602c68ethen fixed the supply-chain verifier's stalecargo +stable auditexpectation tocargo +1.97.1 audit; immediate child10e369ec1e58da1ae6c132e7c33e80f6d6683b81restored the final newline accidentally removed by the whole-file write.Fresh exact-source RCA on predecessor
10e369ec...Hosted repository CI
35942960875is terminal FAILURE, whilebuild-baseline 35942960738,SAST Semgrep 35942960776, andsbom 35942960729are terminal SUCCESS. Security and CodeQL were nonterminal when the source moved.The failed
ci / build-and-testjob received a runner and checked out exact source10e369ec1e58da1ae6c132e7c33e80f6d6683b81. Runtime/toolchain setup, numeric extension build, quickcheck, docs/security/supply-chain/bootstrap/Rust policy checks, andruff checkpassed. Failure occurred only atruff format --check src tests, which reportedtests/test_supply_chain_policy.pywould be reformatted.That file is not owned by this Rust/toolchain lane. #1176 is the canonical one-file Ruff owner and changes the exact failing assertion from the protected multi-line form to the pinned formatter's one-line form without product/assertion semantics change. Therefore the hosted RED is a valid prerequisite finding, not a Rust 1.97.1 semantic defect.
Non-force prerequisite adoption
Ordinary two-parent descendant
db0b7709f48161ca74ff6402ee5f75e136fea40chas parents10e369ec1e58da1ae6c132e7c33e80f6d6683b81and #1176 exact8fe6b6d99c009527ef0bcba419e6f6debdb23c23. Its tree adopts #1176's exact blob6a085394442846aa68b63ebcd5cfe546747a65b0forservices/analysis-engine/tests/test_supply_chain_policy.py; no formatter implementation was copied or re-authored here.The branch advanced with a normal fast-forward update and the PR base is retargeted to #1176, so the active #944 diff remains only its 16 Rust/CI-owned paths. Fresh compare from #1176 to
db0b770...is ahead-only and contains those 16 paths, with no formatter file.This is Draft stacking, not acceptance of an unreleased dependency. #1176 must still reach protected ancestry through its central CodeQL/admission prerequisites. After #1176 integrates, this PR must ordinary/non-force reconcile to the new protected
developand reacquire exact-head/base evidence.Current-head evidence
A fresh workflow generation now exists for exact
db0b7709f48161ca74ff6402ee5f75e136fea40c:sbom 35978965029: queuedCodeQL PR 35978964008: pendingbuild-baseline 35978963826: queuedci 35978963877: queuedSAST Semgrep 35978963867: queuedSecurity Scan 35978963795: queuedNo predecessor success transfers to this head. Queued/pending is not GREEN and no current-head independent non-author approval exists.
#944 owns repository Rust-toolchain and generic CI source identity only. It does not own the #1176 formatter delta, product UI, MIR/scientific acceptance, Project Persistence, Resource Admission, Score Storage, Distribution signing/notarization policy, or central
.githubrequired-workflow implementation.Keep Draft until #1176 reaches protected ancestry, this lane is reconciled to protected
develop, one unchanged exact head has every applicable build/CI/security/SAST/SBOM/supply-chain/CodeQL gate terminal-success, all valid findings are resolved, and a qualifying independent non-author current-head approval exists.No self-approval, bypass, synthetic status, source-neutral wake commit, blind rerun, gate weakening, force-push, destructive rebase, duplicate formatter owner, or predecessor-evidence promotion.