Commit Graph
3 Commits
Author SHA1 Message Date
Metal AgentandClaude Opus 5 2aab0c4aab Stop compiling the GPL crate GPUI drags in behind the framework
Lumbridge is Apache-2.0, and decision 0023 quietly made it link
GPL-3.0-or-later. `crates/gpui/Cargo.toml` at the pinned revision carries
`ztracing.workspace = true` -- unconditional, not optional, not behind a
feature -- and `ztracing` is GPL-3.0-or-later, as are the `zlog` and
`ztracing_macro` it pulls. `sum_tree` asks for it too. The path is the ordinary
Linux build, not an `--all-features` artefact and not a dev-dependency:

    lumbridge -> gpui_platform -> gpui_linux -> gpui -> ztracing -> zlog
                                                                -> ztracing_macro

`cargo deny check licenses` failed on it, exit 4.

This is the second thing decision 0023 got wrong by reading the manifests of the
crates it added instead of resolving the graph; the first was believing there
were two Zed Git sources when there are five. Both were found by a gate that had
never been run.

There was no feature to turn off, so the choice was to relax the licence policy,
drop the framework, or stop compiling the crate. `ztracing` is now redirected by
a `[patch]` table at `crates/lumbridge-ztracing-shim`, a first-party
zero-dependency no-op under Apache-2.0. `zlog` and `ztracing_macro` were
reachable only through it and leave the lockfile with it.

The shim is small because the usage is: nine `#[instrument(skip_all)]` sites
across `gpui/src/svg_renderer.rs`, `sum_tree/src/sum_tree.rs` and
`sum_tree/src/cursor.rs`, and nothing else. Upstream's own crate compiles to
almost exactly this whenever the `ztracing` cfg is off, which is every build
that is not a Tracy profiling build, so no shipping behaviour is lost. It is a
proc-macro crate deliberately: such a crate can export nothing but proc macros,
so an upstream revision that starts using `ztracing::Span` or
`ztracing::info_span!` fails to compile and names the shim, rather than
resolving to something plausible.

`scripts/workspace-guard.sh` gained a third gate asserting, against Cargo.lock
rather than the manifest, that no `ztracing`, `zlog` or `ztracing_macro`
resolves to a Zed source and that the patch table is still present. `cargo deny`
already checks this, and the duplication is the point: `scripts/ci.sh`
downgrades a missing cargo-deny to a warning unless `LUMBRIDGE_CI_STRICT=1`, and
that is how the licence closure went ungated once already. A `[patch]` is an
unusually quiet thing to lose -- delete the table and everything still compiles,
still passes, and is GPL again.

Removing the three GPL rejections exposed a fourth that had been sitting beside
them and was never reported separately: `libbz2-rs-sys` under `bzip2-1.0.6`,
reached through async-compression <- http_client <- gpui. It is BSD-style and
permissive with no copyleft, and is allowed in `deny.toml` with that reasoning
written down. `cargo deny check licenses sources` is exit 0 for the first time.

The Git-source allowances in `deny.toml` are all still needed; the patched
crate's own source was `zed.git`, which `gpui` still requires.

Decision 0025 records the whole of it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
2026-09-01 14:02:59 -07:00
Metal AgentandClaude Opus 5 3cb5e1002c Name the closure's own context where the framework now demands one
Stage 4 of decision 0023, finished. The dependency swap itself compiled the
whole closure on the first attempt; what did not compile was `apps/lumbridge`,
and the entire API delta across a ten-month jump turned out to be three
signatures over 19 call sites.

`Window::focus` is now `focus(&mut self, handle: &FocusHandle, cx: &mut App)`
-- 16 sites. `flex_shrink()` takes the factor it used to assume, so it is
`flex_shrink(1.0)` -- 2 sites. `Application::new()` is gone with the rest of
the entry point, and is `gpui_platform::application()` -- 1 site. That is all
of it. Nothing else in the framework's surface moved under this product in ten
months.

The interesting failure was in the fix, not the framework. Adding `, cx` to
every `window.focus` site is right in a method that owns a `cx` parameter and
wrong inside `cx.listener(...)`, whose closure is handed its own context as a
fourth argument that this code discarded as `_`. One such site capturing the
outer `cx` produced 35 errors -- E0596, two E0521s, an E0500, thirty E0501s and
two E0524s -- none of which named the actual mistake, and all of which vanished
when the discarded parameter was given the name it should have had. Worth
recording: a borrow-checker avalanche after a dependency bump is far more
likely to be one wrong capture than a framework that changed its ownership
model.

No crate outside `apps/lumbridge` needed a single change, because none of them
imports a gpui type. That boundary was not designed for this and paid for
itself anyway.

`scripts/workspace-guard.sh` now asserts what it exists to assert. It compared
`gpui` against version 0.2.2 from the crates.io registry, which after the swap
was a guard that would have failed on the correct state of the tree. It now
checks that `gpui` and `gpui_platform` both carry
git+https://github.com/zed-industries/zed.git at rev ce48461e -- the same rev,
because the pair are one framework snapshot and a disagreement between them
would compile against two. Their versions (0.2.2 and 0.1.0) are deliberately
not asserted; neither has been bumped upstream in ten months and neither means
anything. Both failure modes were induced before being trusted: a wrong
expected rev fails on both packages, and a lockfile where only gpui_platform's
rev is altered fails on that package alone.

One thing to fix next, not here: `cargo deny check sources` now fails. Decision
0023 predicted the move would bring two Git sources; the resolved graph brings
four. wasm_thread (via gpui_web and scheduler) and xim-rs, which supplies
zed-xim, xim-ctext and xim-parser to gpui_linux, are both unallowed, and
zed-industries/scap is in the lockfile too. deny.toml is named in AGENTS.md as
a file a decision record governs, so it is left alone and reported rather than
edited underneath this commit.

The UI gate is green: workspace-guard, fmt, clippy with -D warnings over
--all-targets --all-features, and 79 tests passing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
2026-09-01 13:22:50 -07:00
Metal AgentandClaude Opus 5 9a29e8e335 Make the gate structural, and correct what it tells an agent
CI / rust-ui (push) Failing after 6m20s
CI / rust-headless (push) Successful in 6m38s
Three gates in this repository were decorative, and each was discovered by
being wrong rather than by failing.

A crate directory in neither members nor exclude is silently not built, which
is how lumbridge-devices shipped 1,127 lines that had never compiled.
scripts/workspace-guard.sh refuses that state, and asserts the gpui source
and version out of Cargo.lock rather than the manifest, because a manifest
states an intent while the lockfile states what would actually be compiled --
and a caret requirement accepts a version nobody reviewed. It needs no
compiler, so it runs first and in the headless job, which unlike the UI job
is not continue-on-error and can therefore actually fail a push.

deny.toml's source policy had never been executed: ci.sh ran `check
licenses` alone, and `check sources` failed immediately on the rev-pinned
buzz-sdk. The permitted Git sources are now named one by one and the check
runs, so a fourth is a decision rather than an accident.

cargo-deny and cargo-nextest being absent was a warning that let a run report
green having skipped the licence gate DISTRIBUTION.md depends on. Under
LUMBRIDGE_CI_STRICT=1 a missing tool now fails; locally it stays a warning so
a contributor is not blocked.

skills/lumbridge-development/SKILL.md told every agent that GPUI and Floem
live in spikes/ and that no framework may be selected until both pass the
hard gates. Decision 0017 settled that a month ago in the opposite direction.
The entry point an agent is meant to read was the least accurate document in
the repository.

Decision 0023 records where the GPUI dependency actually goes. Published gpui
has not been released since 2025-10-22, Zed's main still declares 0.2.2 with
no bump pending, the platform backends moved to crates that inherit
publish = false, gpui's own x11 and wayland features are now empty markers,
and 0.2.2 has no accesskit dependency at all -- so "published now, migrate
later" was never available. The adapter 0017 promised was never written and
the call sites grew from few to 147 against 20 identities, so the adapter is
written first, on 0.2.2, before the dependency moves.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
2026-09-01 12:51:25 -07:00