fix(cargo): resolve inherited workspace dependency identity - #3734
oleksii-tumanov wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Adds support for Cargo workspace-inherited dependencies (dep.workspace = true) in introspect_cargo: it resolves each such member dep against [workspace.dependencies], applies any package rename from the shared spec, and only emits an edge when the shared spec has a path (resolved relative to the workspace root) that resolves to the same manifest as the matched crate. Non-path shared deps (registry, git, version), a workspace value that isn't literally true, missing/mismatched paths, and malformed or absent [workspace.dependencies] tables are all skipped rather than treated as local. Covers virtual and root-package workspaces plus root-package targets via a large parametrized test suite.
No blocking issues surfaced. 1 lower-confidence candidate did not survive cross-model review.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 207 functions depend on the 28 functions this change touches.
Health — this change adds coupling hotspots:
- new:
dispatch_command()— 2 callers, 125 callees - new:
introspect_cargo()— 15 callers, 3 callees - new:
test_poisoned_manifest_is_healed()— 0 callers, 6 callees
Verification — 207 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 33 function(s) in the blast radius were not formally verified this run
Test selection
Test selection
1 of 290 test file(s) selected (0%) via static blast radius.
tests/test_cargo_introspect.py— impact, changed-test
Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.
· 3 more finding(s) on lines outside this diff (see the check run).
|
Shipped in v0.9.66 (on PyPI). Cherry-picked with authorship preserved so it shows under your GitHub contributions. Thanks @oleksii-tumanov! |
What does this PR do?
Fixes #3733.
Resolve an inherited Cargo dependency through its root
[workspace.dependencies]declaration, including
packagerenames. A shared alias such asdb.workspace = truenow links to the actual
internal-storagecrate.The inherited path must identify that workspace member. Registry/git dependencies
and unresolved declarations stay unlinked even when an alias matches a local crate.
Direct dependencies and manifest discovery are unchanged.
Type of change
How was this tested?
The fixture was also checked with
cargo metadata --no-deps --offline.Ruff, all five skillgen checks, and
graphify update . --no-clusterpassed.Tests cover virtual/root-package workspaces, shared aliases, direct-dependency
precedence, root-relative paths, and external/unresolved name collisions.
Graphify-specific checklist