Stop compiling the GPL crate GPUI drags in behind the framework
Lumbridge is Apache-2.0, and decision 0023 quietly made it link
GPL-3.0-or-later. `crates/gpui/Cargo.toml` at the pinned revision carries
`ztracing.workspace = true` -- unconditional, not optional, not behind a
feature -- and `ztracing` is GPL-3.0-or-later, as are the `zlog` and
`ztracing_macro` it pulls. `sum_tree` asks for it too. The path is the ordinary
Linux build, not an `--all-features` artefact and not a dev-dependency:
lumbridge -> gpui_platform -> gpui_linux -> gpui -> ztracing -> zlog
-> ztracing_macro
`cargo deny check licenses` failed on it, exit 4.
This is the second thing decision 0023 got wrong by reading the manifests of the
crates it added instead of resolving the graph; the first was believing there
were two Zed Git sources when there are five. Both were found by a gate that had
never been run.
There was no feature to turn off, so the choice was to relax the licence policy,
drop the framework, or stop compiling the crate. `ztracing` is now redirected by
a `[patch]` table at `crates/lumbridge-ztracing-shim`, a first-party
zero-dependency no-op under Apache-2.0. `zlog` and `ztracing_macro` were
reachable only through it and leave the lockfile with it.
The shim is small because the usage is: nine `#[instrument(skip_all)]` sites
across `gpui/src/svg_renderer.rs`, `sum_tree/src/sum_tree.rs` and
`sum_tree/src/cursor.rs`, and nothing else. Upstream's own crate compiles to
almost exactly this whenever the `ztracing` cfg is off, which is every build
that is not a Tracy profiling build, so no shipping behaviour is lost. It is a
proc-macro crate deliberately: such a crate can export nothing but proc macros,
so an upstream revision that starts using `ztracing::Span` or
`ztracing::info_span!` fails to compile and names the shim, rather than
resolving to something plausible.
`scripts/workspace-guard.sh` gained a third gate asserting, against Cargo.lock
rather than the manifest, that no `ztracing`, `zlog` or `ztracing_macro`
resolves to a Zed source and that the patch table is still present. `cargo deny`
already checks this, and the duplication is the point: `scripts/ci.sh`
downgrades a missing cargo-deny to a warning unless `LUMBRIDGE_CI_STRICT=1`, and
that is how the licence closure went ungated once already. A `[patch]` is an
unusually quiet thing to lose -- delete the table and everything still compiles,
still passes, and is GPL again.
Removing the three GPL rejections exposed a fourth that had been sitting beside
them and was never reported separately: `libbz2-rs-sys` under `bzip2-1.0.6`,
reached through async-compression <- http_client <- gpui. It is BSD-style and
permissive with no copyleft, and is allowed in `deny.toml` with that reasoning
written down. `cargo deny check licenses sources` is exit 0 for the first time.
The Git-source allowances in `deny.toml` are all still needed; the patched
crate's own source was `zed.git`, which `gpui` still requires.
Decision 0025 records the whole of it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
This commit is contained in:
co-authored by
Claude Opus 5
parent
3cb5e1002c
commit
2aab0c4aab
@@ -89,9 +89,22 @@ failure is unattributable:
|
||||
versions of new `clippy::pedantic` lints arrive as hard errors under
|
||||
`-D warnings`. Isolating this stage is what stops a lint avalanche being
|
||||
mistaken for a GPUI API break.
|
||||
3. **`deny.toml`.** Add `zed-industries/zed` and `zed-industries/font-kit` to
|
||||
`allow-git`. The second is not optional: `gpui_wgpu` reaches `font-kit`
|
||||
through a Git source, so the move brings two Git sources, not one.
|
||||
3. **`deny.toml`.** Add the Zed Git sources to `allow-git`. This record
|
||||
originally said there were two, `zed-industries/zed` and
|
||||
`zed-industries/font-kit`. **That was wrong: there are five.** The graph also
|
||||
carries `xim-rs` (X11 input methods, feeding `gpui_linux` -- the IME path,
|
||||
so load-bearing for a hard gate rather than incidental), `wasm_thread`
|
||||
(reached twice, through `gpui_web` and through `scheduler` <- `gpui`), and
|
||||
`scap`, which resolves in the lockfile without being reachable in this
|
||||
target's graph and so is named before some later platform's build finds it
|
||||
first.
|
||||
|
||||
The error is worth keeping visible rather than quietly corrected. It was made
|
||||
by reading the manifests of the two crates being added, which is exactly the
|
||||
reasoning that misses a transitive Git source; only resolving the graph
|
||||
answers the question. `cargo deny check sources` is what caught it, on the
|
||||
commit after the allowance was written -- which is the argument for running
|
||||
that check at all.
|
||||
4. **The dependency swap.** `gpui` and `gpui_platform` at the pinned rev;
|
||||
`wayland`/`x11` requested on `gpui_platform`, where they still mean
|
||||
something; and `Application::new()` — which does not exist at that revision —
|
||||
@@ -101,10 +114,21 @@ failure is unattributable:
|
||||
6. **The probe changes job**: it stops proving AccessKit exists and starts
|
||||
proving the next revision still compiles.
|
||||
|
||||
The renderer swap from blade to wgpu in stage 4 is the least characterised risk.
|
||||
`scripts/native-libs.sh` addresses one missing `libxkbcommon-x11` symlink and
|
||||
says nothing about a Vulkan or GL loader, and the Gitea job installs no wgpu
|
||||
dependency. Expect to learn something here.
|
||||
The renderer swap from blade to wgpu in stage 4 was called the least
|
||||
characterised risk here, and at build time it cost nothing: the whole closure
|
||||
compiled on the existing `libxkbcommon-x11` shim, with no Vulkan or GL loader
|
||||
problem and no new native dependency. That is not the same as the risk being
|
||||
disproven. Nothing in `cargo check`, `clippy`, or the test suite opens a window,
|
||||
so the renderer has still never run. The risk moved from build time to first
|
||||
launch; it did not go away.
|
||||
|
||||
The rest of stage 4 was smaller than expected. The entire API delta across the
|
||||
ten-month jump was three signatures over nineteen sites: `Window::focus` taking
|
||||
the `App` it used to reach through the window, `flex_shrink` taking the factor
|
||||
it used to assume, and `Application::new` becoming
|
||||
`gpui_platform::application()`. No crate outside `apps/lumbridge` needed any
|
||||
change, because none of them imports a gpui type -- the narrow boundary
|
||||
`ARCHITECTURE.md` insisted on is the reason this was an afternoon.
|
||||
|
||||
## What is knowingly still unmet
|
||||
|
||||
|
||||
Reference in New Issue
Block a user