Skip to main content

Crate lgwks_deps

Crate lgwks_deps 

Source
Expand description

lgwks_deps owns dependency admission and enforces INV-DEP-EDGE-OWNED: every external dependency authored by a workspace package names its semantic owner, capability, source, requirement, allowed consumers, and allowed dependency kinds.

The rule in one line: if a library is not in core, it is not an approved dependency, and the code does not compile until a human has registered it in the semantic contract. Everything here exists to make the second half of that sentence mechanically true rather than a convention people remember.

§Enforcement boundary

The same lgwks-deps check command is an explicit first job in local and remote CI. It reads cargo metadata --no-deps, not the transitive lockfile closure, because only metadata preserves the package that authored an edge. Embedders call check_dependencies for the identical verdict.

§Fail-closed

A missing register, unparseable metadata, an unparseable register, and an unreadable lock file are all refusals. A gate that passes when it cannot find its own contract is a gate that reports success for the one condition it exists to catch. The only way to stand enforcement down is enforce = false under [policy] in the register itself: a reviewable diff carrying a human’s name, never an environment variable a build can set for itself.

§No name-based exemption

There is no package whose name alone escapes the audit. An edge is exempt only when Cargo’s own workspace_members list names its target, so an internal edge is exempt because it is this workspace’s code and not because of how it is spelled. A path or Git package that calls itself lgwks_std — or lgwks-std, which Cargo folds to the same name — is an ordinary external edge and must be approved like any other; the refusal keeps the source it came from so the two cannot be confused.

The gate is not gated by itself, but that is a consequence of the build graph rather than an exemption: the lgwks_deps → lgwks_std edge in this repository targets a workspace member, and a consumer that reaches a published lgwks_std declares a real registry edge, which the register must review. Building the checker and interpreting a subject’s metadata are different operations, so auditing a same-named package creates no cycle.

§Storefront

lgwks_deps is also the install-and-select surface for third-party engines: enable a storefront feature and import its engine through this crate. For example, bevy-app exposes lgwks_deps::bevy_app::App, bevy-time exposes lgwks_deps::bevy_time::Time, and bevy-state exposes Bevy’s state API. tokio is the async engine behind lgwks_bot::rt (use lgwks_deps::tokio::... only when bypassing the bot facade), and gpui is the GPU desktop UI. Capability features are default-off; scan, the gate-tool feature, is the default-on exception for cargo install CLI use. Library consumers take default-features = false plus exactly the engine they need so the Rust parser never rides along with a runtime edge.

Do NOT cargo add tokio / cargo add gpui directly: the gate refuses any second edge, and the facade (lgwks_bot::rt, lgwks_deps::tokio) is the single entry this workspace audits.

Re-exports§

pub use tokio;
pub use bevy_ecs;
pub use bevy_app;
pub use bevy_time;
pub use bevy_state;
pub use appcui;

Modules§

contract
The approval register: parsing and lookup for contract/APPROVED.toml. contract owns the human-approved dependency register and enforces INV-APPROVAL-IS-SEMANTIC: an entry is not an approval unless it says what the standard library cannot do. A name on a list is a whitelist; a name with a reason, a pin, an approver, a date, and a link to the evidence is a contract, and only the second one is admissible here.
invariants
The optional authored invariant register and its repository-aware validator. Authored invariant register and its refusal rules.
lock
The register: parsing and approval lookup for contract/APPROVED.toml. lock owns reading Cargo.lock and enforces INV-LOCK-RESOLVED-TRUTH: the gate audits the resolved graph, not the declared one, so a crate that arrives only as somebody else’s transitive dependency is still audited.
metadata
Cargo metadata edges: who authored which external dependency. Cargo metadata ingestion for direct dependency-edge admission.
process_group
Safe process-group existence observation for the supervised process facade. Non-mutating process-group observation through the dependency storefront.
scan
Rust source scan: the zero-gate detectors behind lgwks-deps scan (feature scan). scan owns the zero-gate source detectors and enforces INV-SCAN-ZERO: a file this workspace ships carries no silenced error, no unlogged error return, no lint allowance, no overlong try chain, and no paraphrase docstring.
vendor
Vendor-tree coverage: binding the lockfile to the shared vendor/ tree. vendor owns lockfile-to-tree coverage and enforces INV-VENDOR-SINGLE-TREE: every registry package a repo’s Cargo.lock resolves must be present in the single shared vendor tree with the exact bytes the lock pins, or the offline build it feeds is a lie.

Enums§

GateError
Why the gate could not reach a verdict. Every variant is a refusal, not a pass; see the fail-closed note on this module.
Refusal
One dependency the register does not admit.

Constants§

CONTRACT_PATH
Register location relative to the repository root.

Functions§

audit_direct
Audits authored direct dependency edges against semantic ownership.
check_dependencies
Audits the repository rooted at root, reading its lock file and register.
check_dependencies_against
Audits root against a register held elsewhere. This exists for the check --contract diagnosis path, where a repo is audited before it carries a register of its own. enforce never calls it: a build always reads the register committed beside the code it is building, so no build can be pointed at a more permissive contract than the one in its own tree.
check_invariants
Resolves the optional invariant register beside root against the repository.
repository_root
Walks up from start to the nearest directory holding a Cargo.lock.