Skip to content

6.3 Code Quality Licensing and Review Gates

Raul Cardenas Montoya edited this page Sep 19, 2026 · 1 revision

Code Quality, Licensing and Review Gates

Relevant source files

The following files were used as context for generating this wiki page:

This page documents the quality assurance framework, review gates, automated dependency checks, static analysis configurations, and licensing compliance standards enforced across the synaptic-wiring codebase. These guardrails ensure that public APIs remain stable, memory allocations stay bounded, dependencies remain secure and license-compliant, and code formatting adheres strictly to project standards before any change merges into main.


1. REVIEW.md Gates and the Human Quality Bar

The REVIEW.md file defines the manual verification standards and review gates required for any pull request touching src/, Cargo.toml, or public APIs REVIEW.md:1-5.

MSRV Pin Rule

The Minimum Supported Rust Version (MSRV) is pinned to 1.98.1. To prevent drift between build systems and CI pipelines, this version must be identical across:

The CI validate workflow automatically checks these pins and fails if any discrepancies occur (LIM-1042) REVIEW.md:14-15.

Build Profiles

Cargo.toml defines four distinct [profile.*] blocks to optimize compile times, test execution speeds, release binaries, and profiler integration REVIEW.md:27-39.

Profile Command Configuration Rationale
dev cargo build / cargo run opt-level = 0, full debug info, incremental compilation enabled for the fastest edit-compile loop REVIEW.md:35.
test cargo test Inherits dev with opt-level = 1 to accelerate unit and property test suites while maintaining fast compile times REVIEW.md:36.
release cargo build --release opt-level = 3, thin LTO, single codegen unit, stripped binaries tuned for crates.io distribution REVIEW.md:37.
bench cargo bench Inherits release for realistic performance benchmarks, but sets strip = false to retain debug symbols for profiler analysis REVIEW.md:38.

Packaging Validation

Changes to Cargo.toml metadata or file inclusions must be verified against packaging rules:

cargo package --locked --list
cargo package --locked

The CI packaging job builds the unpacked .crate from a temporary directory to verify that excluded build artifacts or local tooling never leak into published crates REVIEW.md:50-56.

Mandatory Local Commands

Before requesting a review or pushing changes to core mesh, topology, or neuromodulation modules, developers must execute:

cargo fmt --check
cargo test --locked
cargo clippy --all-features -- -D warnings

REVIEW.md:60-76

graph TD
    A["DeveloperPush"] --> B["cargo fmt --check"]
    B --> C["cargo test --locked"]
    C --> D["cargo clippy --all-features -- -D warnings"]
    D --> E["cargo package --locked"]
    E --> F["HumanReviewGate"]
    
    sub5["Sources"]
    style sub5 fill:none,stroke:none
    click sub5 "[REVIEW.md:60-76]()"
Loading

Figure 1: Local review gate execution sequence. Sources: [REVIEW.md:1-140]()


2. Dependency Security and Licensing Enforcement (cargo-deny)

The deny.toml configuration file governs cargo-deny, enforcing supply-chain security, vulnerability scanning, and license compliance across all dependencies deny.toml:1-4.

Advisories

The [advisories] section queries RustSec advisory databases to immediately fail builds upon encountering vulnerable, unmaintained, or unsound transitive dependencies, and treats yanked crates as errors deny.toml:9-15.

License Allowlist

To maintain compatibility with the project's dual MIT/Apache-2.0 license and the permissive licenses of its dependency tree, deny.toml defines a strict allowlist with a confidence threshold of 0.93 deny.toml:17-32. Allowed licenses include:

Bans and Sources

  • Multiple Versions: Warns when multiple versions of the same crate are pulled into the dependency graph deny.toml:35-36.
  • Wildcards: Prohibits wildcard dependency specifications (*) deny.toml:37.
  • Sources: Restricts registry lookups strictly to https://github.com/rust-lang/crates.io-index and blocks unknown git repositories or registries deny.toml:42-46.
graph TD
    A["Cargo.lock"] --> B["cargo-deny check"]
    B --> C["AdvisoriesScan"]
    B --> D["LicenseComplianceScan"]
    B --> E["SourceRestrictionScan"]
    
    C --> F["FailOnUnsoundOrYanked"]
    D --> G["ValidateAgainstAllowlist"]
    E --> H["EnforceCratesIoIndex"]

    sub6["Sources"]
    style sub6 fill:none,stroke:none
    click sub6 "[deny.toml:1-46]()"
Loading

Figure 2: cargo-deny validation pipeline. Sources: [deny.toml:1-46]()


3. Automated Static Analysis and Metrics

Static analysis tools provide automated feedback on code smells, complexity, and potential bugs, configured to respect the project's MSRV and testing harness.

Codacy Configuration (.codacy.yml)

Codacy static analysis is configured via .codacy.yml to suppress false positives and ignore paths that do not contain core library code .codacy.yml:1-3. Excluded paths comprise:

  • .github/workflows/** .codacy.yml:4-5
  • tests/propagate_into_alloc.rs (which implements a custom system-forwarding GlobalAlloc specifically designed to track heap allocations during zero-allocation propagation tests) .codacy.yml:6-7

DeepSource Configuration (.deepsource.toml)

DeepSource monitors repository health using version 1 of its configuration schema .deepsource.toml:1-2 with two active analyzers:

  1. Rust Analyzer: Enabled with meta-parameter msrv = "1.98.1" to ensure code idioms align with the compiler target .deepsource.toml:3-9.
  2. Secrets Analyzer: Enabled to prevent accidental check-ins of API keys or credentials .deepsource.toml:10-12.

Sources: [.codacy.yml:1-8], [.deepsource.toml:1-12]()


4. Licensing, Provenance and Repository Assets

Dual Licensing

The repository is dually licensed under the MIT License and the Apache License 2.0, permitting downstream consumers to select either terms.

  • MIT License: LICENSE-MIT establishes copyright under Raul Montoya Cardenas and Limen-Neural contributors LICENSE-MIT:1-19.
  • Apache-2.0 License: LICENSE-APACHE-2.0 outlines formal patent and copyright grants LICENSE-APACHE-2.0:1-137.

Documentation Assets and Provenance

Repository assets such as docs/logo.png include embedded C2PA (Coalition for Content Provenance and Authenticity) metadata docs/logo.png:1-4. This metadata contains cryptographically signed SHA-256 hash boxes (c2pa.hash.boxes), action logs indicating AI generation parameters (Azure OpenAI Image Gen), and cryptographic assertion chains linking back to Microsoft Root Authorities docs/logo.png:3-4.

Sources: [LICENSE-MIT:1-19], [LICENSE-APACHE-2.0:1-137], [docs/logo.png:1-4]()

Clone this wiki locally