Layer (b) — core/clippy.toml bans rand::random and rand::thread_rng crate-wide, each with a reason naming KEY-05 and pointing at the evidence doc. No CI change was needed: the Rust job already runs `cargo clippy --all-targets --all-features -- -D warnings` from core/, so a disallowed_methods hit is already a build failure. --all-targets covers tests deliberately — a fixture keeping the default is a template for the next production call site. Ordering was asserted before the file was written, not after: the residual count of unmigrated call sites is 0, so this cannot turn CI red for other agents on this shared tree. Layer (c) — core/deny.toml makes the rand major split change-detecting: global multiple-versions = "allow", a per-crate deny-multiple-versions for rand, and a dated grandfather skip pinning =0.9.2 exactly. The tree as it stands passes; a third version or a change to either member fails. Both gates were OBSERVED working, not assumed: - Reintroducing one banned call produced the disallowed_methods error with the reason text reaching the developer at the failure point; reverting returned the residual count to 0. - `cargo deny check bans` exits 0 as-is. Removing the grandfather entry made it exit 2 and print both dependency trees, independently confirming F-07's account of where each rand version comes from. Restored, it exits 0 again. Policy (checkpoint Task 5, human-approved): bans-only. The advisories gate is NOT enabled — it fails builds when a new CVE is published against an existing dep with no local change, which on a tree where several agents push continuously would block everyone at an arbitrary hour, with remediation often meaning a bump to an exactly-pinned crypto dependency. No break-glass procedure exists. F-07's advisory half stays OPEN and is recorded as such. cargo-deny is pinned to 0.20.2 and installed from crates.io rather than via EmbarkStudios/cargo-deny-action, because that action exposes no input to pin the tool version — an unpinned supply-chain checker would reintroduce, at the CI layer, the exact "backend fixed by configuration rather than stated" shape this plan exists to remove. crates.io is also the source vetted at the Task 5 legitimacy gate (EmbarkStudios, repo resolves, ~4.79M downloads). RECORDED HONESTLY: layer (b)'s gate is live but not yet EFFECTIVE. The tree carries 42 pre-existing clippy warnings — unused imports, dead code, ~39 style lints — that are already errors under -D warnings, so that CI step cannot pass today for reasons unrelated to KEY-05. Until a dedicated lint-clearing pass lands, a new banned RNG call would be one error among many rather than a distinctive build-stopper. Pre-existing and out of scope; clearing it right before an OTA would be poor sequencing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
60 lines
2.7 KiB
TOML
60 lines
2.7 KiB
TOML
# KEY-05 layer (c) — make the `rand` major-version split VISIBLE rather than silent.
|
|
#
|
|
# WHY
|
|
# F-07 / R-05 asked for exactly one thing: a rule that fails the build when the
|
|
# duplicate `rand` majors in this graph change, "so the split is visible rather
|
|
# than silent". Two majors coexist today and that is tolerated-and-recorded, not
|
|
# fixed — bumping is not casual on a tree that pins `bip39` and `bitcoin` exactly.
|
|
#
|
|
# The contract this file encodes:
|
|
# - the tree AS IT STANDS passes;
|
|
# - a THIRD `rand` version, or a change to either member of the current pair,
|
|
# FAILS.
|
|
#
|
|
# POLICY DECISION (checkpoint 10-06 Task 5, decided 2026-08-02)
|
|
# Selected: **bans-only**. The `advisories` section is deliberately NOT enabled.
|
|
# An advisories gate fails builds when a new CVE is published against an existing
|
|
# dependency, with no change to this repository — on a tree where several agents
|
|
# commit and push continuously, an unrelated upstream disclosure would block
|
|
# everyone at an arbitrary hour, and the remediation is often a dependency bump
|
|
# that is itself a phase-sized change. No break-glass procedure exists today.
|
|
# Consequence, recorded rather than glossed: F-07's advisory half stays OPEN.
|
|
#
|
|
# Tool legitimacy: cargo-deny is published by EmbarkStudios
|
|
# (github.com/EmbarkStudios/cargo-deny), ~4.79M all-time downloads. CI pins 0.20.2
|
|
# (published 2026-07-09).
|
|
|
|
[bans]
|
|
# Global default stays permissive: this repo has many legitimately-duplicated
|
|
# transitive crates, and turning them all into build failures is not what F-07
|
|
# asked for and would be a large, unrelated cleanup.
|
|
multiple-versions = "allow"
|
|
|
|
# ...but `rand` specifically is change-detecting.
|
|
[[bans.deny]]
|
|
name = "rand"
|
|
deny-multiple-versions = true
|
|
|
|
# Grandfather entry — dated 2026-08-02, per F-07.
|
|
#
|
|
# Tolerates the CURRENTLY KNOWN second major so the rule lands green instead of
|
|
# turning CI red on the day it ships. Anything outside this exact pair trips the
|
|
# rule above.
|
|
#
|
|
# rand 0.8.5 — direct dependency (core/archipelago/Cargo.toml), and also via
|
|
# archipelago-security, bip39 2.1.0, mainline, secp256k1,
|
|
# tungstenite 0.20.1
|
|
# rand 0.9.2 — transitive only, via totp-rs 5.7.0 and tungstenite 0.26.2
|
|
# (through nostr-sdk)
|
|
#
|
|
# WHEN THIS FIRES: do not widen the skip list reflexively. A third version means a
|
|
# new dependency brought its own `rand`; decide deliberately whether to accept it,
|
|
# and if so record where it comes from here, the same way these two are recorded.
|
|
[[bans.skip]]
|
|
name = "rand"
|
|
version = "=0.9.2"
|
|
|
|
# Deliberately empty: see the policy decision above. Re-enabling this is a policy
|
|
# change that needs a break-glass procedure agreed first, not a quiet edit.
|
|
# [advisories]
|