The product was spikes/gpui-shell: a cargo workspace of its own, named in the root manifest's exclude list. It inherited neither unsafe_code = "forbid" nor clippy pedantic, and ./scripts/ci.sh never compiled it. Every test written into it silently never ran, and apps/lumbridge was an eleven-line stub printing a version string. Four separate research passes over the sidebar, settings, devices, and theme work independently discovered they were about to write substantial new code into that directory. Graduating first means writing it once. - apps/lumbridge is the product; spikes/ui-shell-model becomes crates/lumbridge-ui-fixture and joins the workspace. - scripts/ci.sh takes --headless and --ui. The headless pass excludes the two UI crates by name, so a contributor changing lumbridge-core does not wait on a window toolkit, and a runner that cannot carry GPUI still gates everything else. A new crate is headless by default rather than silently joining the slow job. - scripts/native-libs.sh replaces the ad-hoc symlink in the launcher, and says which apt package actually fixes the problem instead of working around it silently. The stale libxcb/libxkbcommon symlinks in the old spike target directory are gone; only libxkbcommon-x11.so was ever needed. - deny.toml and cargo deny check licenses. spikes/README.md called GPUI's licence closure a hard gate and the scorecard scored it pending; graduation makes it the product's closure, so it is enforced rather than described. Two rejections were reviewed and allowed with the reasoning recorded in the file: webpki-roots under CDLA-Permissive-2.0 (Mozilla's CA store, data not code, reached through ureq) and libfuzzer-sys under NCSA (reached only under all-features via gpui's image decoder; no shipped build links it). Clippy pedantic across both crates is clean at -D warnings. render was 353 lines; render_sidebar, render_tabs, and render_root come out of it, which the sidebar rework needed anyway. The remaining over-length functions are single declarative element trees and carry per-function allows with reasons, not a blanket suppression. Decision 0017 records the two calls this forces: published gpui 0.2.2 behind an accessibility adapter rather than an unpinned Zed revision and an MSRV bump, and Floem frozen rather than maintained in parity or deleted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
58 lines
1.8 KiB
TOML
58 lines
1.8 KiB
TOML
# License policy for everything Lumbridge ships.
|
|
#
|
|
# Graduating the GPUI shell out of `spikes/` moved several hundred packages from
|
|
# a spike's dependency tree into the product's. `spikes/README.md` called GPUI's
|
|
# license closure "a hard gate" and the scorecard scored it `pending`; this is
|
|
# where that gate is enforced rather than described.
|
|
#
|
|
# cargo install cargo-deny && cargo deny check licenses
|
|
[graph]
|
|
all-features = true
|
|
|
|
[licenses]
|
|
# Permissive, plus two weak-copyleft licenses that are file-level and do not
|
|
# reach Lumbridge's own sources.
|
|
allow = [
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"BSL-1.0",
|
|
"CC0-1.0",
|
|
"ISC",
|
|
"MIT",
|
|
"MIT-0",
|
|
"MPL-2.0",
|
|
"Unicode-3.0",
|
|
"Unlicense",
|
|
"Zlib",
|
|
|
|
# Reviewed additions, each reached by exactly one path:
|
|
#
|
|
# CDLA-Permissive-2.0 is webpki-roots, which is Mozilla's CA root store —
|
|
# data, not code, under a permissive data licence with no copyleft and no
|
|
# attribution requirement on downstream distribution. It arrives through
|
|
# ureq, which the Claude usage endpoint needs (decision 0016).
|
|
"CDLA-Permissive-2.0",
|
|
# NCSA is libfuzzer-sys, a permissive BSD/MIT-style licence. It reaches the
|
|
# graph only as rav1e -> ravif -> image -> gpui and only under
|
|
# `all-features`; no shipped build links it. Allowed rather than excluded so
|
|
# the audit stays strict everywhere else.
|
|
"NCSA",
|
|
]
|
|
# A dependency whose license cannot be determined is not a licensing question to
|
|
# settle later; it is a blocker now.
|
|
unused-allowed-license = "allow"
|
|
confidence-threshold = 0.9
|
|
|
|
[bans]
|
|
multiple-versions = "allow"
|
|
|
|
[advisories]
|
|
yanked = "deny"
|
|
|
|
[sources]
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
|