Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
c855523
feat(rust): add the Rust port workspace preview
Patel230 Sep 26, 2026
abb6e56
docs(design): add Rust port ADRs and parity/migration plans
Patel230 Sep 26, 2026
032d0e8
build(rust): add dependency license audit, notice bundle and SBOM tool
Patel230 Sep 26, 2026
e88c7c0
ci(rust): gate the Rust workspace in Make and source-validation
Patel230 Sep 26, 2026
d0306c2
chore: remove the Python, TypeScript and Go SDK source trees
Patel230 Sep 26, 2026
9a68e64
docs: describe the Rust port preview in README, STATUS and security m…
Patel230 Sep 26, 2026
36acb82
fix(rust): name the preview binary rover-rs so it cannot shadow rover
Patel230 Sep 26, 2026
4537e02
fix(rust): run the dependency audit with the CARGO the Makefile uses
Patel230 Sep 26, 2026
d9c46b9
ci: run Go product and Rust preview gates as independent cached jobs
Patel230 Sep 26, 2026
e9716db
ci(rust): keep the generated Rust SBOM as a workflow artifact
Patel230 Sep 26, 2026
c0b9729
ci(release): attest build provenance for every released asset
Patel230 Sep 26, 2026
e8741d8
docs: restructure README and STATUS around the shipped Go product
Patel230 Sep 26, 2026
e79819b
docs: state the real publication, support and security intake status
Patel230 Sep 26, 2026
cf46240
fix(manifest): name the paths that make SOURCE_MANIFEST.json stale
Patel230 Sep 26, 2026
3f369f0
docs: document the Rust toolchain and gates for contributors
Patel230 Sep 26, 2026
4ddd5a8
docs(design): index current Rust ADRs apart from the historical plan
Patel230 Sep 26, 2026
079eaa3
docs: mark research notes that cite the removed SDKs as historical
Patel230 Sep 26, 2026
199c958
docs: drop the removed Python client from the architecture diagram
Patel230 Sep 26, 2026
bbd27e5
docs(changelog): record the Rust preview, CI, provenance and docs cha…
Patel230 Sep 26, 2026
f31320b
chore(manifest): regenerate SOURCE_MANIFEST.json for the tracked tree
Patel230 Sep 26, 2026
9a7b8ac
fix(rust): clear clippy pedantic lints in the Linux-only /proc reader
Patel230 Sep 26, 2026
43eea4a
chore(manifest): regenerate SOURCE_MANIFEST.json after the pty.rs lin…
Patel230 Sep 26, 2026
39026d4
docs(ci): record the measured cold-cache duration of both CI jobs
Patel230 Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 2 additions & 0 deletions .cargo/config.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
[build]
target-dir = "target/rust-1.88.0"
5 changes: 5 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Byte-exact files. scripts/rust_dependency_audit.py and
# scripts/test_herdr_manifest_audit.py verify these by SHA-256, so Git must
# never convert their line endings (some upstream notices use CRLF).
/licenses/** -text
/crates/rover-agents/src/herdr_manifests/** -text
48 changes: 39 additions & 9 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,10 @@ concurrency:
group: source-validation-${{ github.ref }}
cancel-in-progress: true
jobs:
linux:
# The Go binary is the Rover product. Its gates run in their own job so a
# Rust preview failure never hides Go results (and vice versa).
go:
name: go (linux/amd64)
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
Expand Down Expand Up @@ -38,15 +41,42 @@ jobs:
run: make demo
- name: Extended terminal, workflow and protocol scenarios
run: make demo-extended
- name: Python CLI client
run: make sdk-test
- name: TypeScript CLI client
run: node --test sdk/typescript/test/*.test.ts
- name: Go CLI client
run: go test ./sdk/go -count=1 -v
- name: Cross-compile for all supported platforms
run: make cross-build
- name: Vulnerability scanning
run: make vulncheck
# This validates Rover's own source. It is not an independently trusted Rover
# acceptance publisher for arbitrary candidate PRs. Hosted execution is pending.
# Unreleased Rust port preview (crates/, gated by docs/design/RUST_PARITY_PLAN.md).
rust:
name: rust preview (linux/amd64, 1.88.0)
runs-on: ubuntu-24.04
timeout-minutes: 30
env:
CARGO_TERM_COLOR: never
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Install pinned Rust MSRV toolchain
run: rustup toolchain install 1.88.0 --profile minimal --component clippy --component rustfmt
- name: Restore Rust build cache
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
# .cargo/config.toml sets target-dir = target/rust-1.88.0.
workspaces: '. -> target/rust-1.88.0'
# Only main writes the cache; branches and PRs restore from it.
save-if: ${{ github.ref == 'refs/heads/main' }}
- name: Fetch locked Rust dependencies
run: cargo +1.88.0 fetch --locked
- name: Format, lint, test, and audit Rust workspace
run: make rust-check CARGO='cargo +1.88.0'
- name: Generate Rust CycloneDX SBOM
run: make rust-sbom CARGO='cargo +1.88.0'
- name: Keep the Rust SBOM as a run artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: rover-rust-sbom
path: bin/rover-rust-sbom.cdx.json
if-no-files-found: error
retention-days: 30
# This validates Rover's own source on GitHub-hosted runners. It is not an
# independently trusted Rover acceptance publisher for arbitrary candidate PRs.
11 changes: 10 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@ on:
default: true
permissions:
contents: write
# Keyless (OIDC) Sigstore signing of build provenance; no long-lived key.
id-token: write
attestations: write
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
Expand Down Expand Up @@ -66,6 +69,10 @@ jobs:
run: |
cd bin
sha256sum rover rover-linux-amd64 rover-darwin-amd64 rover-darwin-arm64 rover-sbom.json > checksums.txt
- name: Attest build provenance for every checksummed asset
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-checksums: bin/checksums.txt
- name: Create release
uses: softprops/action-gh-release@8f7ab71908ac24848f30f6066c520d5ddf38a571 # v2
with:
Expand All @@ -83,4 +90,6 @@ jobs:
# This release workflow is opt-in (workflow_dispatch only). It does NOT run
# automatically on push or PR. Review the build artifacts and govulncheck
# results before publishing. Per project policy, no automatic credential upload,
# signing key injection, or deployment occurs.
# signing key injection, or deployment occurs. Provenance is signed keylessly
# with the run's short-lived OIDC identity (GitHub artifact attestations);
# verify a download with `gh attestation verify <file> --repo GrayCodeAI/rover`.
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# Binaries & build
/bin/
/target/
coverage.out
coverage.html
*.test
Expand Down
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,10 @@ agent-neutral full-platform scope. Do not describe the design reference as shipp

Before changing code, identify the relevant test and domain owner. Add regression tests
for acceptance/security changes. Run make check, make race, and make demo in an appropriate
owned environment. Report exact commands and limitations. Do not invent passing CI runs,
live provider tests, code-coverage metrics, or security certification.
owned environment; for Rust changes also run make rust-check CARGO='cargo +1.88.0'. Run
make manifest after changing tracked files. Report exact commands and limitations. Do not
invent passing CI runs, live provider tests, code-coverage metrics, or security certification.
The Go binary is the product; the Rust preview (crates/, binary rover-rs) is unreleased.

Do not weaken tests or required policy to make checks green. Keep schema changes explicit.
Never copy model assertions into evidence as observed facts. No automatic publication,
Expand Down
34 changes: 34 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,39 @@
# Changelog

## Unreleased

- Track the Rust port workspace (nine crates, Rust 1.88.0 MSRV) as an
unreleased preview. Its executable is `rover-rs`, not `rover`, so it cannot
shadow the Go product binary, and `rover-rs --version` labels it a preview.
Build and usage notes are in `docs/RUST_PREVIEW.md`.
- CI runs the Go product gates and the Rust preview gates as independent jobs.
The Rust job is cached and keeps its CycloneDX SBOM as a run artifact.
- The release workflow attests build provenance (GitHub artifact attestations,
keyless Sigstore signing) for every checksummed asset; verify with
`gh attestation verify`.
- `make manifest-check` names the paths that make `SOURCE_MANIFEST.json` stale.
The Rust dependency audit runs with the same `CARGO` as the Makefile.
`.gitattributes` keeps the hash-verified license notices byte-exact.
- README, STATUS, SECURITY, SUPPORT, and GOVERNANCE now describe the public
repository, hosted CI, the source-only `v0.0.1` release, and one platform
matrix. `docs/validation/v0.0.1/REPORT.md` records the tag's hosted CI run.
- Remove the Python, TypeScript, and Go SDK source trees and their CI/Make
targets per product direction. Historical validation records remain dated.
- `ProcessGroupIdentity` gains a `conflicting` field listing every equally
ranked candidate when the group is ambiguous (additive; empty otherwise). The
TUI now emits one `foreground_process` evidence entry per conflicting
candidate instead of a single generic message, so an operator can see which
agents disagreed rather than only that they did. Identity selection is
unchanged: an ambiguous group still resolves to unknown.
- `rover-execution`: `parse_nul_terminated_argv` and the `MAX_PROCESS_ARG_*`
bounds are now `cfg(target_os = "linux")`. They only ever served the Linux
`/proc` reader — the macOS backend deliberately reports unknown argv rather
than parse a lossy `ps` command line — so the wider gate left them dead on
macOS.
- `rover-execution`: reject a negative pid parsed out of `ps` output instead of
casting it to `u32`, and drop the unused `&self` from
`foreground_process_group_details_for`.

## 0.0.1

- Establish the current public release identity and fail-closed version checks.
Expand Down
28 changes: 20 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,14 +5,26 @@ terminal-first ten-layer scope, but do not claim unimplemented integrations work

## Local workflow

1. Build with Go, a C compiler, system SQLite development headers, and Git.
2. Run `make check`, `make race`, and `make demo` on owned fixtures.
3. Add a focused regression test before changing acceptance semantics.
4. Update STATUS and the acceptance mapping when a capability's guarantees change.
5. Inspect the diff for source/state/credential leakage and unchecked error paths.

CI definitions in this bundle are not evidence of a successful hosted run. Provide the
actual command, platform, toolchain, result, and limitations in a contribution.
1. Build the Go product with Go 1.26.6 or newer, a C compiler, system SQLite
development headers, and Git.
2. Run `make check`, `make race`, `make version-check`, and `make demo` on owned
fixtures.
3. Run `make manifest` after adding, removing, or editing tracked files, then
`make manifest-check`. CI fails when `SOURCE_MANIFEST.json` is stale.
4. When a change touches the Rust port (`crates/`, `Cargo.toml`, `Cargo.lock`,
`licenses/`, or `scripts/rust_*`), install the pinned toolchain with
`rustup toolchain install 1.88.0 --profile minimal --component clippy --component rustfmt`
and run `make rust-check CARGO='cargo +1.88.0'`. It runs `cargo fmt`, clippy
with the workspace's pedantic lints as errors, the workspace tests, the script
unit tests, and the locked license/notice audit. After a reviewed dependency
change, `make rust-notices CARGO='cargo +1.88.0'` refreshes the bundled notices.
5. Add a focused regression test before changing acceptance semantics.
6. Update STATUS and the acceptance mapping when a capability's guarantees change.
7. Inspect the diff for source/state/credential leakage and unchecked error paths.

A green hosted CI run ([docs/CI.md](docs/CI.md)) is necessary but not sufficient.
Provide the actual command, platform, toolchain, result, and limitations in a
contribution.

## Design discipline

Expand Down
Loading
Loading