Skip to content

Import Udon and Bento into the Zakura Common workspace - #523

Merged
ebfull merged 8 commits into
mainfrom
import-udon
Sep 28, 2026
Merged

ebfull merged 8 commits into
mainfrom
import-udon

Conversation

@ebfull

@ebfull ebfull commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Import the Udon and Bento crates from https://github.com/tachyon-zcash/udon at commit 586329a8c94fe042e7ec264b61bfd632888828cb, as unpublished, independently versioned workspace members:

  • zakura-udon: Pasta field and curve arithmetic with allocation-free FFTs, plus MSM, polynomial, and incremental execution machinery, and fixed Poseidon parameters and consumer traits behind features.
  • zakura-bento: facade for compile-time arithmetic, addition chains, and checked POD storage and embedding.
  • zakura-bento-core / zakura-bento-macros: implementation crates behind the facade.

The commit sequence:

  1. Stop vetting zakura-address and zakura-transparent as crates.io crates — fills a pre-existing gap: every other workspace member already sets audit-as-crates-io = false.
  2. Modernize benchmark and profiling dev-dependencies — criterion 0.5 in bellman, halo2_gadgets, orchard, pasta_curves, and sinsemilla; pprof 0.15 (which manages its own inferno) replacing the pinned pprof/inferno pairs; drops halo2_proofs' unused dashmap dev-dependency. This clears the criterion 0.4 and old pprof trees (clap 3, nix, memmap2, symbolic 8/10, …) out of Cargo.lock, with matching supply-chain exemption updates.
  3. Exclude unpublished workspace members from changelog tooling — members with publish = false need no CHANGELOG.md, cannot be named in fragments, and are excluded from release assembly; the policy is documented in the guidelines and the release skill.
  4. Import Udon and Bento into the Zakura Common workspace — the crates, workspace registration, README, and supply-chain policies plus exemptions for the dependencies they introduce (proc-macro-crate, toml_edit, toml_parser, winnow, and imported toml_datetime audits).
  5. Add Udon and Bento CI coverage — changes-filter and check-group wiring plus jobs adapted from the upstream repository's CI: feature-combination clippy and doc checks, native x86_64/aarch64 release tests across both sqrt-table sizes, compiler and artifact consumer tests, benchmark smoke tests, Miri checks of the unsafe storage paths, and target portability contracts.

All four imported crates are publish = false at version 0.1.0 and stay outside the coordinated release: version bumps, changelog assembly, and publishing are unaffected. cargo metadata --locked, cargo vet check --locked, and ./scripts/changelog.py check pass at every commit in the sequence.

🤖 Generated with Claude Code

ebfull and others added 6 commits September 28, 2026 10:03
Every other workspace member carries an `audit-as-crates-io = false`
policy so cargo-vet treats the vendored sources as first-party rather
than as the crates.io release of the same name. These two members were
missing the policy; add it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Bump criterion to 0.5 in bellman, halo2_gadgets, orchard,
pasta_curves, and sinsemilla, and replace the pinned pprof 0.8/0.11
and inferno pairs in halo2_gadgets and orchard with pprof 0.15, which
manages its own inferno. Drop halo2_proofs' dashmap dev-dependency,
which nothing references.

This clears the criterion 0.4 and old pprof dependency trees (clap 3,
nix, memmap2, symbolic 8/10, and friends) out of Cargo.lock. Update
the supply-chain data to match: drop exemptions for packages that left
the lockfile, cover the newer ahash, inferno, quick-xml, hashbrown,
and indexmap trees that pprof 0.15 pulls in, and import audits for
getrandom 0.3 and the wasip2/wit-bindgen publishers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Teach workspace_changelogs() to skip members that set publish = false
(directly, as an empty registry list, or inherited from the
workspace). Unpublished members need no CHANGELOG.md, cannot be named
in fragments, and are excluded from release assembly, while explicit
registry lists remain publishable. Document the policy in the
changelog guidelines and the release skill: unpublished members
version independently of the coordinated Common release.

This prepares for importing Udon and Bento, which stay unpublished.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Add four unpublished, independently versioned members, imported
from https://github.com/tachyon-zcash/udon at commit
586329a8c94fe042e7ec264b61bfd632888828cb:

- udon (zakura-udon): Pasta field and curve arithmetic with
  allocation-free FFTs, plus MSM, polynomial, and incremental
  execution machinery, and fixed Poseidon parameters and consumer
  traits behind features.
- bento (zakura-bento): facade for compile-time arithmetic, addition
  chains, and checked POD storage and embedding.
- bento-core and bento-macros: implementation crates behind the
  facade.

Register them in the workspace members and [workspace.dependencies]
tables and describe them in the README. Add supply-chain policies for
the new members and exemptions for the dependencies they introduce
(proc-macro-crate, toml_edit, toml_parser, winnow), along with
imported toml_datetime audits.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Wire the new crates into the changes filter, the handled-members
drift list, and the shared stable/MSRV check groups. Add jobs adapted
from the upstream udon repository's CI: feature-combination clippy and doc
checks, native-architecture release tests on x86_64 and aarch64
across both sqrt-table sizes, compiler and artifact consumer tests,
benchmark smoke tests, Miri checks of the unsafe storage paths, and
target portability contracts. The formatting job now also validates
the standalone test fixtures with the new check_udon_fixtures.py
script, and test-success gates on all of the new jobs.

Also expand $PACKAGES through an array in the existing no-std build
step instead of relying on unquoted word splitting.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The PR imports unpublished crates and changes dev-dependencies, CI,
and tooling only, so the fragment records an explicit exclusion.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​proc-macro-crate@​3.5.09910093100100

View full report

ebfull and others added 2 commits September 28, 2026 10:43
The setup-rust-toolchain action exports CARGO_BUILD_WARNINGS=deny by
default. The Bento and Udon compile-test harnesses run nested Cargo
builds of generated consumer crates that inherit the ambient
environment, and their success cases assume default warning behavior;
a fixture's intentionally unused type alias failed the Arithmetic
matrix on every platform. Set build-warnings to the empty string on
the jobs whose tests spawn nested builds, matching the upstream CI,
which never denies warnings globally.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Rust 1.98 Clippy adds chunks_exact_to_as_chunks, which fires on 29
constant-size chunks_exact and chunks_exact_mut kernel sites in the
Udon library and two bench modules (the upstream toolchain pin is
1.91, so its CI never saw the lint). Most sites have no
machine-applicable fix, so migrating to as_chunks is upstream work
rather than an import-time rewrite. Allow the lint at the crate and
bench-module roots, paired with unknown_lints because the pinned
1.97.1 Clippy predates the lint name; drop that pairing once the pin
reaches 1.98.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ebfull
ebfull marked this pull request as ready for review September 28, 2026 18:20
@v12-auditor

v12-auditor Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Note

Complete: Audit complete. V12 did not find any issues that need review.

Open the full results here.

Analyzed 164 files, diff 8d397d0...95fa3cc.

@ebfull
ebfull merged commit b15cb47 into main Sep 28, 2026
90 checks passed
@ebfull
ebfull deleted the import-udon branch September 28, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant