Expand description
lgwks_deps owns dependency admission and enforces
INV-DEP-EDGE-OWNED: every external dependency authored by a workspace
package names its semantic owner, capability, source, requirement, allowed
consumers, and allowed dependency kinds.
The rule in one line: if a library is not in core, it is not an approved
dependency, and the code does not compile until a human has registered it in
the semantic contract. Everything here exists to
make the second half of that sentence mechanically true rather than a
convention people remember.
§Enforcement boundary
The same lgwks-deps check command is an explicit first job in local and
remote CI. It reads cargo metadata --no-deps, not the transitive lockfile
closure, because only metadata preserves the package that authored an edge.
Embedders call check_dependencies for the identical verdict.
§Fail-closed
A missing register, unparseable metadata, an unparseable register, and an unreadable lock file are
all refusals. A gate that passes when it cannot find its own contract is a
gate that reports success for the one condition it exists to catch. The only
way to stand enforcement down is enforce = false under [policy] in the
register itself: a reviewable diff carrying a human’s name, never an
environment variable a build can set for itself.
§No name-based exemption
There is no package whose name alone escapes the audit. An edge is exempt
only when Cargo’s own workspace_members list names its target, so an
internal edge is exempt because it is this workspace’s code and not
because of how it is spelled. A path or Git package that calls itself
lgwks_std — or lgwks-std, which Cargo folds to the same name — is an
ordinary external edge and must be approved like any other; the refusal
keeps the source it came from so the two cannot be confused.
The gate is not gated by itself, but that is a consequence of the build
graph rather than an exemption: the lgwks_deps → lgwks_std edge in this
repository targets a workspace member, and a consumer that reaches a
published lgwks_std declares a real registry edge, which the register
must review. Building the checker and interpreting a subject’s metadata are
different operations, so auditing a same-named package creates no cycle.
§Storefront
lgwks_deps is also the install-and-select surface for third-party
engines: enable a storefront feature and import its engine through this
crate. For example, bevy-app exposes lgwks_deps::bevy_app::App,
bevy-time exposes lgwks_deps::bevy_time::Time, and bevy-state
exposes Bevy’s state API.
tokio is the async engine behind lgwks_bot::rt (use lgwks_deps::tokio::... only when bypassing the bot facade), and gpui is
the GPU desktop UI. Capability features are default-off; scan, the
gate-tool feature, is the default-on exception for cargo install CLI use.
Library consumers take default-features = false plus exactly the engine
they need so the Rust parser never rides along with a runtime edge.
Do NOT cargo add tokio / cargo add gpui directly: the gate refuses any
second edge, and the facade (lgwks_bot::rt, lgwks_deps::tokio) is the
single entry this workspace audits.
Re-exports§
pub use tokio;pub use bevy_ecs;pub use bevy_app;pub use bevy_time;pub use bevy_state;pub use appcui;
Modules§
- contract
- The approval register: parsing and lookup for
contract/APPROVED.toml.contractowns the human-approved dependency register and enforces INV-APPROVAL-IS-SEMANTIC: an entry is not an approval unless it says what the standard library cannot do. A name on a list is a whitelist; a name with a reason, a pin, an approver, a date, and a link to the evidence is a contract, and only the second one is admissible here. - invariants
- The optional authored invariant register and its repository-aware validator. Authored invariant register and its refusal rules.
- lock
- The register: parsing and approval lookup for
contract/APPROVED.toml.lockowns readingCargo.lockand enforces INV-LOCK-RESOLVED-TRUTH: the gate audits the resolved graph, not the declared one, so a crate that arrives only as somebody else’s transitive dependency is still audited. - metadata
- Cargo metadata edges: who authored which external dependency. Cargo metadata ingestion for direct dependency-edge admission.
- process_
group - Safe process-group existence observation for the supervised process facade. Non-mutating process-group observation through the dependency storefront.
- scan
- Rust source scan: the zero-gate detectors behind
lgwks-deps scan(featurescan).scanowns the zero-gate source detectors and enforces INV-SCAN-ZERO: a file this workspace ships carries no silenced error, no unlogged error return, no lint allowance, no overlong try chain, and no paraphrase docstring. - vendor
- Vendor-tree coverage: binding the lockfile to the shared
vendor/tree.vendorowns lockfile-to-tree coverage and enforces INV-VENDOR-SINGLE-TREE: every registry package a repo’sCargo.lockresolves must be present in the single shared vendor tree with the exact bytes the lock pins, or the offline build it feeds is a lie.
Enums§
- Gate
Error - Why the gate could not reach a verdict. Every variant is a refusal, not a pass; see the fail-closed note on this module.
- Refusal
- One dependency the register does not admit.
Constants§
- CONTRACT_
PATH - Register location relative to the repository root.
Functions§
- audit_
direct - Audits authored direct dependency edges against semantic ownership.
- check_
dependencies - Audits the repository rooted at
root, reading its lock file and register. - check_
dependencies_ against - Audits
rootagainst a register held elsewhere. This exists for thecheck --contractdiagnosis path, where a repo is audited before it carries a register of its own.enforcenever calls it: a build always reads the register committed beside the code it is building, so no build can be pointed at a more permissive contract than the one in its own tree. - check_
invariants - Resolves the optional invariant register beside
rootagainst the repository. - repository_
root - Walks up from
startto the nearest directory holding aCargo.lock.