Import Udon and Bento into the Zakura Common workspace - #523
Merged
Merged
Conversation
Every other workspace member carries an `audit-as-crates-io = false` policy so cargo-vet treats the vendored sources as first-party rather than as the crates.io release of the same name. These two members were missing the policy; add it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Bump criterion to 0.5 in bellman, halo2_gadgets, orchard, pasta_curves, and sinsemilla, and replace the pinned pprof 0.8/0.11 and inferno pairs in halo2_gadgets and orchard with pprof 0.15, which manages its own inferno. Drop halo2_proofs' dashmap dev-dependency, which nothing references. This clears the criterion 0.4 and old pprof dependency trees (clap 3, nix, memmap2, symbolic 8/10, and friends) out of Cargo.lock. Update the supply-chain data to match: drop exemptions for packages that left the lockfile, cover the newer ahash, inferno, quick-xml, hashbrown, and indexmap trees that pprof 0.15 pulls in, and import audits for getrandom 0.3 and the wasip2/wit-bindgen publishers. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Teach workspace_changelogs() to skip members that set publish = false (directly, as an empty registry list, or inherited from the workspace). Unpublished members need no CHANGELOG.md, cannot be named in fragments, and are excluded from release assembly, while explicit registry lists remain publishable. Document the policy in the changelog guidelines and the release skill: unpublished members version independently of the coordinated Common release. This prepares for importing Udon and Bento, which stay unpublished. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Add four unpublished, independently versioned members, imported from https://github.com/tachyon-zcash/udon at commit 586329a8c94fe042e7ec264b61bfd632888828cb: - udon (zakura-udon): Pasta field and curve arithmetic with allocation-free FFTs, plus MSM, polynomial, and incremental execution machinery, and fixed Poseidon parameters and consumer traits behind features. - bento (zakura-bento): facade for compile-time arithmetic, addition chains, and checked POD storage and embedding. - bento-core and bento-macros: implementation crates behind the facade. Register them in the workspace members and [workspace.dependencies] tables and describe them in the README. Add supply-chain policies for the new members and exemptions for the dependencies they introduce (proc-macro-crate, toml_edit, toml_parser, winnow), along with imported toml_datetime audits. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Wire the new crates into the changes filter, the handled-members drift list, and the shared stable/MSRV check groups. Add jobs adapted from the upstream udon repository's CI: feature-combination clippy and doc checks, native-architecture release tests on x86_64 and aarch64 across both sqrt-table sizes, compiler and artifact consumer tests, benchmark smoke tests, Miri checks of the unsafe storage paths, and target portability contracts. The formatting job now also validates the standalone test fixtures with the new check_udon_fixtures.py script, and test-success gates on all of the new jobs. Also expand $PACKAGES through an array in the existing no-std build step instead of relying on unquoted word splitting. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The PR imports unpublished crates and changes dev-dependencies, CI, and tooling only, so the fragment records an explicit exclusion. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
The setup-rust-toolchain action exports CARGO_BUILD_WARNINGS=deny by default. The Bento and Udon compile-test harnesses run nested Cargo builds of generated consumer crates that inherit the ambient environment, and their success cases assume default warning behavior; a fixture's intentionally unused type alias failed the Arithmetic matrix on every platform. Set build-warnings to the empty string on the jobs whose tests spawn nested builds, matching the upstream CI, which never denies warnings globally. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Rust 1.98 Clippy adds chunks_exact_to_as_chunks, which fires on 29 constant-size chunks_exact and chunks_exact_mut kernel sites in the Udon library and two bench modules (the upstream toolchain pin is 1.91, so its CI never saw the lint). Most sites have no machine-applicable fix, so migrating to as_chunks is upstream work rather than an import-time rewrite. Allow the lint at the crate and bench-module roots, paired with unknown_lints because the pinned 1.97.1 Clippy predates the lint name; drop that pairing once the pin reaches 1.98. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ebfull
marked this pull request as ready for review
September 28, 2026 18:20
|
Note Complete: Audit complete. V12 did not find any issues that need review. Open the full results here. Analyzed 164 files, diff |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Import the Udon and Bento crates from https://github.com/tachyon-zcash/udon at commit 586329a8c94fe042e7ec264b61bfd632888828cb, as unpublished, independently versioned workspace members:
zakura-udon: Pasta field and curve arithmetic with allocation-free FFTs, plus MSM, polynomial, and incremental execution machinery, and fixed Poseidon parameters and consumer traits behind features.zakura-bento: facade for compile-time arithmetic, addition chains, and checked POD storage and embedding.zakura-bento-core/zakura-bento-macros: implementation crates behind the facade.The commit sequence:
audit-as-crates-io = false.Cargo.lock, with matching supply-chain exemption updates.publish = falseneed noCHANGELOG.md, cannot be named in fragments, and are excluded from release assembly; the policy is documented in the guidelines and the release skill.All four imported crates are
publish = falseat version 0.1.0 and stay outside the coordinated release: version bumps, changelog assembly, and publishing are unaffected.cargo metadata --locked,cargo vet check --locked, and./scripts/changelog.py checkpass at every commit in the sequence.🤖 Generated with Claude Code