Repository navigation
Expand file tree
/
Copy pathclippy.toml
More file actions
37 lines (35 loc) · 2.98 KB
/
Copy pathclippy.toml
File metadata and controls
37 lines (35 loc) · 2.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
# Workspace-wide Clippy policy.
#
# Enforced by `cargo clippy` in CI (chutes-build, chutes-build-core,
# xai-grok-tools, xai-grok-pager). clippy uses the NEAREST clippy.toml with
# no merging, so this root file is the single source of settings for every
# crate in the workspace.
# TODO: remove after https://github.com/hyperium/tonic/issues/2253 fixed.
large-error-threshold = 256
# Ban raw canonicalize: on Windows it returns verbatim `\\?\C:\...` paths that
# break external tools, leak into prompts, and poison path-equality keys.
# `dunce::canonicalize` keeps the verbatim form for paths it cannot simplify
# (over 260 chars, device names), so containment checks there fail closed.
#
# Ban raw child-process spawning: an unenrolled child outlives the session that
# started it, while an enrolled one dies with its scope. Allow with a reason
# where a child is waited on or deliberately detached.
#
# HTTP clients must be built through xai-grok-extra-ca: a zero-config
# `Client::new()` silently drops the optional CHUTES_EXTRA_CA_BUNDLE
# roots. Builder paths stay allowed where the endpoint policy wraps them.
# Allow with a stated reason for generic helpers that receive a policy-built
# client, common-layer crates that cannot reach the policy crate, and
# loopback-only test fixtures where no custom CA applies.
disallowed-methods = [
{ path = "reqwest::Client::new", reason = "bypasses the extra-CA policy (CHUTES_EXTRA_CA_BUNDLE); build through xai_grok_extra_ca; localhost-only clients allow with a reason" },
{ path = "reqwest::blocking::Client::new", reason = "bypasses the extra-CA policy (CHUTES_EXTRA_CA_BUNDLE); build through xai_grok_extra_ca; localhost-only clients allow with a reason" },
{ path = "reqwest::ClientBuilder::build", reason = "use xai_grok_extra_ca::build_reqwest_client: it applies the extra-CA policy and survives a broken OS store; localhost/test clients allow with a reason" },
{ path = "reqwest::blocking::ClientBuilder::build", reason = "use xai_grok_extra_ca::build_blocking_reqwest_client: it applies the extra-CA policy and survives a broken OS store; localhost/test clients allow with a reason" },
{ path = "std::fs::canonicalize", reason = "returns \\\\?\\ verbatim paths on Windows; use dunce::canonicalize" },
{ path = "std::path::Path::canonicalize", reason = "returns \\\\?\\ verbatim paths on Windows; use dunce::canonicalize" },
{ path = "tokio::fs::canonicalize", reason = "returns \\\\?\\ verbatim paths on Windows; use xai_grok_tools::util::fs helpers or spawn_blocking + dunce::canonicalize" },
{ path = "std::process::Command::spawn", reason = "an unenrolled child outlives its session; use xai_tty_utils::ProcessScope::enroll_std" },
{ path = "tokio::process::Command::spawn", reason = "an unenrolled child outlives its session; use xai_tty_utils::ProcessScope::enroll" },
{ path = "portable_pty::SlavePty::spawn_command", reason = "an unenrolled pty child outlives its session; enroll the shell with xai_tty_utils::ProcessScope::enroll_terminal_pid" },
]