-
Notifications
You must be signed in to change notification settings - Fork 2
6.3 Code Quality Licensing and Review Gates
Relevant source files
The following files were used as context for generating this wiki page:
This page documents the quality assurance framework, review gates, automated dependency checks, static analysis configurations, and licensing compliance standards enforced across the synaptic-wiring codebase. These guardrails ensure that public APIs remain stable, memory allocations stay bounded, dependencies remain secure and license-compliant, and code formatting adheres strictly to project standards before any change merges into main.
The REVIEW.md file defines the manual verification standards and review gates required for any pull request touching src/, Cargo.toml, or public APIs REVIEW.md:1-5.
The Minimum Supported Rust Version (MSRV) is pinned to 1.98.1. To prevent drift between build systems and CI pipelines, this version must be identical across:
-
Cargo.toml(rust-version) REVIEW.md:7-10 -
rust-toolchain.toml(channel) REVIEW.md:7-10 - The README MSRV badge/line REVIEW.md:7-10
-
.github/workflows/ci.yml(toolchain install, packaging job, andcargo-denyaction) REVIEW.md:7-10 -
.github/workflows/coverage.ymlREVIEW.md:11-13
The CI validate workflow automatically checks these pins and fails if any discrepancies occur (LIM-1042) REVIEW.md:14-15.
Cargo.toml defines four distinct [profile.*] blocks to optimize compile times, test execution speeds, release binaries, and profiler integration REVIEW.md:27-39.
| Profile | Command | Configuration Rationale |
|---|---|---|
dev |
cargo build / cargo run
|
opt-level = 0, full debug info, incremental compilation enabled for the fastest edit-compile loop REVIEW.md:35. |
test |
cargo test |
Inherits dev with opt-level = 1 to accelerate unit and property test suites while maintaining fast compile times REVIEW.md:36. |
release |
cargo build --release |
opt-level = 3, thin LTO, single codegen unit, stripped binaries tuned for crates.io distribution REVIEW.md:37. |
bench |
cargo bench |
Inherits release for realistic performance benchmarks, but sets strip = false to retain debug symbols for profiler analysis REVIEW.md:38. |
Changes to Cargo.toml metadata or file inclusions must be verified against packaging rules:
cargo package --locked --list
cargo package --lockedThe CI packaging job builds the unpacked .crate from a temporary directory to verify that excluded build artifacts or local tooling never leak into published crates REVIEW.md:50-56.
Before requesting a review or pushing changes to core mesh, topology, or neuromodulation modules, developers must execute:
cargo fmt --check
cargo test --locked
cargo clippy --all-features -- -D warningsgraph TD
A["DeveloperPush"] --> B["cargo fmt --check"]
B --> C["cargo test --locked"]
C --> D["cargo clippy --all-features -- -D warnings"]
D --> E["cargo package --locked"]
E --> F["HumanReviewGate"]
sub5["Sources"]
style sub5 fill:none,stroke:none
click sub5 "[REVIEW.md:60-76]()"
Figure 1: Local review gate execution sequence.
Sources: [REVIEW.md:1-140]()
The deny.toml configuration file governs cargo-deny, enforcing supply-chain security, vulnerability scanning, and license compliance across all dependencies deny.toml:1-4.
The [advisories] section queries RustSec advisory databases to immediately fail builds upon encountering vulnerable, unmaintained, or unsound transitive dependencies, and treats yanked crates as errors deny.toml:9-15.
To maintain compatibility with the project's dual MIT/Apache-2.0 license and the permissive licenses of its dependency tree, deny.toml defines a strict allowlist with a confidence threshold of 0.93 deny.toml:17-32. Allowed licenses include:
-
MITdeny.toml:23 -
Apache-2.0deny.toml:24 -
Apache-2.0 WITH LLVM-exceptiondeny.toml:25 -
Unicode-3.0(required by crates likeunicode-ident) deny.toml:21-26 -
BSD-2-ClauseandBSD-3-Clausedeny.toml:27-28 -
ISC,Zlib, andCC0-1.0deny.toml:29-32
- Multiple Versions: Warns when multiple versions of the same crate are pulled into the dependency graph deny.toml:35-36.
-
Wildcards: Prohibits wildcard dependency specifications (
*) deny.toml:37. -
Sources: Restricts registry lookups strictly to
https://github.com/rust-lang/crates.io-indexand blocks unknown git repositories or registries deny.toml:42-46.
graph TD
A["Cargo.lock"] --> B["cargo-deny check"]
B --> C["AdvisoriesScan"]
B --> D["LicenseComplianceScan"]
B --> E["SourceRestrictionScan"]
C --> F["FailOnUnsoundOrYanked"]
D --> G["ValidateAgainstAllowlist"]
E --> H["EnforceCratesIoIndex"]
sub6["Sources"]
style sub6 fill:none,stroke:none
click sub6 "[deny.toml:1-46]()"
Figure 2: cargo-deny validation pipeline.
Sources: [deny.toml:1-46]()
Static analysis tools provide automated feedback on code smells, complexity, and potential bugs, configured to respect the project's MSRV and testing harness.
Codacy static analysis is configured via .codacy.yml to suppress false positives and ignore paths that do not contain core library code .codacy.yml:1-3. Excluded paths comprise:
-
.github/workflows/**.codacy.yml:4-5 -
tests/propagate_into_alloc.rs(which implements a custom system-forwardingGlobalAllocspecifically designed to track heap allocations during zero-allocation propagation tests) .codacy.yml:6-7
DeepSource monitors repository health using version 1 of its configuration schema .deepsource.toml:1-2 with two active analyzers:
-
Rust Analyzer: Enabled with meta-parameter
msrv = "1.98.1"to ensure code idioms align with the compiler target .deepsource.toml:3-9. - Secrets Analyzer: Enabled to prevent accidental check-ins of API keys or credentials .deepsource.toml:10-12.
Sources: [.codacy.yml:1-8], [.deepsource.toml:1-12]()
The repository is dually licensed under the MIT License and the Apache License 2.0, permitting downstream consumers to select either terms.
-
MIT License:
LICENSE-MITestablishes copyright under Raul Montoya Cardenas and Limen-Neural contributors LICENSE-MIT:1-19. -
Apache-2.0 License:
LICENSE-APACHE-2.0outlines formal patent and copyright grants LICENSE-APACHE-2.0:1-137.
Repository assets such as docs/logo.png include embedded C2PA (Coalition for Content Provenance and Authenticity) metadata docs/logo.png:1-4. This metadata contains cryptographically signed SHA-256 hash boxes (c2pa.hash.boxes), action logs indicating AI generation parameters (Azure OpenAI Image Gen), and cryptographic assertion chains linking back to Microsoft Root Authorities docs/logo.png:3-4.
Sources: [LICENSE-MIT:1-19], [LICENSE-APACHE-2.0:1-137], [docs/logo.png:1-4]()
- 1. Overview
- 1.1. Getting Started & Public API
- 1.2. Release History and Versioning
- 2. Core Runtime: SynapticMesh
- 2.1. Propagation APIs and Tick Semantics
- 2.2. Spike Delay Buffer (Ring Buffer)
- 2.3. Core Types and Error Model
- 2.4. Checkpointing and Serde State Restoration
- 3. Topology Subsystem
- 3.1. SynapticGraph and CSR Representation
- 3.2. Topology Generators
- 3.3. Wiring Rules, Dale's Law and Delay Assignment
- 3.4. Topology Digest
- 4. Sparse Maps and Channel Routing
- 4.1. ChannelRouter and RouterConfig
- 4.2. Neuromodulation and Plasticity
- 4.3. SparseSynapticMap (CSR)
- 5. Testing, Benchmarks and Quality Gates
- 5.1. Propagation Contract Tests
- 5.2. Checkpoint Resume Property Suite
- 5.3. Benchmarks and Unit Test Module
- 6. Build, CI and Project Tooling
- 6.1. Cargo Manifest, Profiles and Dependencies
- 6.2. CI Workflows and Packaging Validation
- 6.3. Code Quality, Licensing and Review Gates
- 7. Glossary