# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. # SPDX-License-Identifier: Apache-2.0 # Rust check, lint, and format tasks ["perf:seccomp"] description = "Compare native and sandbox-filtered TCP socket performance" run = "cargo run --release -p openshell-sandbox --features perf-harness --bin openshell-seccomp-perf --" ["rust:check"] description = "Check all Rust crates for errors" depends = ["rust:lockfiles:check"] run = [ "cargo check --workspace", "cargo check -p openshell-sandbox --all-targets --features perf-harness", ] run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 check native" hide = true ["rust:lockfiles:check"] description = "Verify all tracked Cargo lockfiles are current" run = "tasks/scripts/check-cargo-lockfiles.sh" run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/check-cargo-lockfiles.ps1" hide = true ["rust:lint"] description = "Lint Rust code with Clippy (deny warnings)" depends = ["rust:lockfiles:check"] run = [ "cargo clippy --workspace --all-targets -- -D warnings", "cargo clippy -p openshell-sandbox --all-targets --features perf-harness -- -D warnings", "cargo clippy --manifest-path e2e/rust/Cargo.toml --all-targets -- -D warnings", "cargo clippy --manifest-path examples/governance-interceptor/Cargo.toml --all-targets -- -D warnings", "cargo clippy --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all-targets -- -D warnings", ] run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 lint native" hide = true ["rust:format"] description = "Format Rust code" run = [ "cargo fmt --all", "cargo fmt --manifest-path e2e/rust/Cargo.toml --all", "cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all", "cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all", ] hide = true ["rust:format:check"] description = "Check Rust formatting" run = [ "cargo fmt --all -- --check", "cargo fmt --manifest-path e2e/rust/Cargo.toml --all -- --check", "cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all -- --check", "cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all -- --check", ] hide = true ["rust:deny"] description = "Check dependencies for all cargo-deny rules" run = "cargo deny check" ["rust:deny:policy"] description = "Check dependencies for license violations, bans, and source restrictions" run = "cargo deny check licenses bans sources" ["rust:verify:telemetry-off"] description = "Verify telemetry emission code is compiled out with --no-default-features" run = [ # Positive control: the default (telemetry-on) gateway must contain the # markers, so the absent checks below can never become silently vacuous. "cargo build -p openshell-gateway --bin openshell-gateway", "tasks/scripts/verify-telemetry-compiled-out.sh present target/debug/openshell-gateway", # Guard: telemetry-free builds must contain no telemetry markers. Built # through the `defaults-without-telemetry` alias, which is how the docs tell # operators to produce these artifacts. "cargo build -p openshell-gateway --bin openshell-gateway --no-default-features --features defaults-without-telemetry", "tasks/scripts/verify-telemetry-compiled-out.sh absent target/debug/openshell-gateway", "cargo build -p openshell-supervisor --bin openshell-supervisor --no-default-features --features defaults-without-telemetry", "tasks/scripts/verify-telemetry-compiled-out.sh absent target/debug/openshell-supervisor", ] ["rust:verify:defaults-without-telemetry"] description = "Verify the defaults-without-telemetry feature alias matches default minus telemetry and cannot be used additively" run = "tasks/scripts/verify-defaults-without-telemetry.sh" ["rust:verify:system-ca-roots"] description = "Verify system CA roots build mode compiles and excludes bundled Mozilla root crates" run = [ # Check that the supervisor compiles cleanly in system CA roots mode (all # defaults except bundled-ca-roots). "cargo check -p openshell-supervisor --all-targets --no-default-features --features system-ca-roots", # Guard: webpki-roots must not appear in the dependency graph. "bash -c 'if cargo tree -p openshell-supervisor -i webpki-roots --no-default-features --features system-ca-roots 2>/dev/null | grep -q webpki-roots; then echo \"ERROR: webpki-roots found in system CA roots build\" >&2; exit 1; fi'", # Guard: webpki-root-certs must not appear either (webpki-roots re-exports it). "bash -c 'if cargo tree -p openshell-supervisor -i webpki-root-certs --no-default-features --features system-ca-roots 2>/dev/null | grep -q webpki-root-certs; then echo \"ERROR: webpki-root-certs found in system CA roots build\" >&2; exit 1; fi'", ]