Skip to content

Add Rust coding rules catalogue aligned with the SCRC MISRA C++ cross-reference (draft) - #3262

Draft
dcalavrezo-qorix wants to merge 4 commits into
mainfrom
docs/rust-coding-rules
Draft

dcalavrezo-qorix wants to merge 4 commits into
mainfrom
docs/rust-coding-rules

Conversation

@dcalavrezo-qorix

@dcalavrezo-qorix dcalavrezo-qorix commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Improvement

Description

Adds a draft rulebook of 43 Rust coding rules under docs/contribute/development/rust/coding_rules/, proposing S-CORE rule text for the MISRA C++:2023 guidelines that the Safety-Critical Rust Consortium's own cross-reference (safety-critical-rust-coding-guidelines PR #1226, pinned at commit 9e81abd4) marks as applicable to safe or unsafe Rust.

The new section contains:

  • Overview with attribution, the relation to the existing Rust coding guidelines, the adoption rules and the Required/Advisory level semantics.
  • Rule catalogue, generated from _assets/rules.json. Each rule has a stable SCR-RUST-NNN identifier, its MISRA C++ source IDs with the SCRC verdict, the obligation, the enforcement candidates (rustc, Clippy, CodeQL, review) and the known coverage limits.
  • Applicability register covering all 179 MISRA C++:2023 guidelines with the SCRC verdict, related MISRA C:2025 guideline, SCRC guideline link, the MISRust class as secondary traceability, and the S-CORE disposition. A review queue lists the 9 applicable guidelines without a rule yet and the 5 guidelines retained beyond the SCRC verdict.
  • Verification and deviations describing the per-rule coverage record, checker validation, deviation records and a staged rollout.

Each page is a document need realizing wp__sw_development_plan, matching the existing C++ MISRA mapping page. tools/render_rust_coding_rules.py regenerates the catalogue, the mapping table and the review queue, and validates the register against the pinned SCRC verdicts (--check).

Sources and positioning

  • Primary: SCRC MISRA C++:2023 cross-reference (54 safe, 38 unsafe, 87 not applicable). Still an open PR under weekly subcommittee review; the pinned revision is recorded in the source manifest and must be re-aligned when it changes.
  • Secondary: MISRust (Molz et al., RWTH Aachen, arXiv:2605.23490v2). Where it disagrees with SCRC, SCRC is followed. The SCRC's own differences analysis is linked.
  • The catalogue does not change the CERT-style stance in doc__rust_coding_guidelines. It is a gap review against the score_rust_policies lint profile, binds a component only after adoption through its Software Development Plan, and the rule text is offered as candidate input to the SCRC guidelines, which currently cover 3 of the 92 applicable MISRA C++ guidelines. Everything is draft; no CI check is enabled.

Licensing

  • SCRC cross-reference: CC-BY-4.0 (documentation per repository COPYRIGHT). Verdicts, MISRA C references and guideline links reproduced unchanged; rationale text not copied. Attributed in the pages, source manifest and NOTICE.
  • MISRust paper and dataset: CC-BY-4.0, attributed likewise; classifications reproduced unchanged.
  • MISRA C++:2023 and MISRA C:2025 Addendum 6 are cited by guideline number, kind and category only. No MISRA text is reproduced or redistributed.
  • Committers: please confirm whether the CC-BY-4.0 content needs an Eclipse IP review entry before merge.

Verification

  • bazel run //:docs_check: build succeeded, 0 warnings, all needs valid
  • bazel run //:copyright.check: 0 files without header
  • bazel test //:format.check: 3/3 passed
  • python3 tools/render_rust_coding_rules.py --check: generated files current

Related ticket

No improvement ticket exists yet; to be created and linked before the PR leaves draft.

Add a draft rulebook of 43 Rust coding rules under
docs/contribute/development/rust/coding_rules, derived from the 69
MISRA C++:2023 guidelines that the MISRust study (Molz et al.,
arXiv:2605.23490v2) retains as relevant for Rust, plus three S-CORE
supplements for dependencies, foreign interfaces and verification
governance.

The section contains an overview with adoption rules, the generated
rule catalogue, an applicability register covering all 179 MISRA C++
guidelines with the unchanged MISRust classification and the S-CORE
disposition, and a page on per-rule verification evidence and
deviation records. Each page is a document need realizing the
Software Development Plan, matching the existing C++ MISRA mapping
page.

Rule text and metadata live in _assets/rules.json; the catalogue and
the compact mapping table are generated by
tools/render_rust_coding_rules.py, which also validates the mapping.

The catalogue is positioned as a rule-by-rule gap review that
supplements the lint profile in score_rust_policies. It does not
change the CERT-style stance of the Rust coding guidelines page and
binds a component only after adoption through its Software
Development Plan. No CI check is enabled.

MISRust paper and dataset are CC-BY-4.0 and are attributed in the
pages, the source manifest and NOTICE. MISRA guidelines are cited by
number, kind and category only; no MISRA text is reproduced.

Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Documentation preview for this pull request is available at:
pr-3262: https://eclipse-score.github.io/score/pr-3262/

@RolandJentschETAS

Copy link
Copy Markdown
Contributor

Only as question: Is this on top of rustc and clippy rules ? See https://eclipse-score.github.io/score/main/contribute/development/rust/coding_guidelines.html

Make the Safety-Critical Rust Consortium's MISRA C++:2023 cross-reference
(safety-critical-rust-coding-guidelines PR #1226, commit 9e81abd4) the
primary applicability reference for the draft rulebook. MISRust remains
a secondary reference; its C1-C6 class is kept per guideline for
traceability, and where the two disagree the SCRC verdict is followed.

The applicability register gains the SCRC verdict (safe, unsafe, not
applicable), the related MISRA C:2025 guideline and the SCRC guideline
link per row. Dispositions are derived from the SCRC verdict: 83
applicable guidelines map to S-CORE rules, 9 are queued for rule
assignment, 82 not-applicable guidelines are excluded, and 5 are
retained beyond the SCRC verdict with a stated reason. Both open groups
are rendered as a review queue on the applicability page.

Rule source IDs are adjusted accordingly: 19 guidelines SCRC marks
applicable are attached to fitting rules, 14 guidelines SCRC marks not
applicable are detached, and SCR-RUST-010 becomes a supplement without a
MISRA C++ source. Rule text is unchanged. The render script validates the
register against the pinned SCRC counts and derives each disposition from
the verdict and rule links.

Attribution, source manifest and NOTICE name the SCRC cross-reference
(CC-BY-4.0 documentation, unmerged at time of use) alongside MISRust.

Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
@dcalavrezo-qorix dcalavrezo-qorix changed the title Add MISRA-derived Rust coding rules catalogue as draft Add Rust coding rules catalogue aligned with the SCRC MISRA C++ cross-reference (draft) Sep 18, 2026
@FScholPer
FScholPer requested a lite review from Copilot September 23, 2026 07:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The moderate validation gap and two documentation clarity nits remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds a draft catalogue of 43 Rust coding rules aligned with the pinned SCRC MISRA C++ cross-reference, including applicability data, attribution, documentation, and generation tooling.

Changes:

  • Adds rule definitions, applicability registers, and a generated review queue.
  • Adds rendering and validation tooling with pinned source metadata.
  • Integrates the draft catalogue into Rust development documentation.
File Summary Review note
tools/​render_rust_coding_rules.py Renders and validates catalogue artifacts. moderate (3 votes): Validation checks aggregate counts but not each pinned guideline record or artifact metadata.
NOTICE Adds third-party attribution. —
docs/​contribute/​development/​rust/​index.rst Links the new rules section. —
docs/​contribute/​development/​rust/​coding_rules/​verification_and_deviations.rst Defines verification and rollout guidance. —
docs/​contribute/​development/​rust/​coding_rules/​rules.rst Contains the generated rule catalogue. —
docs/​contribute/​development/​rust/​coding_rules/​index.rst Provides overview and adoption guidance. —
docs/​contribute/​development/​rust/​coding_rules/​applicability.rst Documents applicability and traceability. nit (1 vote): scrc_guideline is described as a link, but only opaque IDs are stored and rendered.
docs/​contribute/​development/​rust/​coding_rules/​_assets/​sources.json Records pinned sources. —
docs/​contribute/​development/​rust/​coding_rules/​_assets/​rules.json Stores rule definitions. nit (3 votes): Correct the incomplete grammar around as being legal in safe Rust.
docs/​contribute/​development/​rust/​coding_rules/​_assets/​review_queue.csv Stores the generated review queue. —
docs/​contribute/​development/​rust/​coding_rules/​_assets/​applicability.csv Stores applicability mappings. —
docs/​contribute/​development/​rust/​coding_rules/​_assets/​applicability_summary.csv Stores the generated mapping summary. —
docs/​contribute/​development/​rust/​coding_guidelines.rst References and links the draft catalogue. —

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tools/render_rust_coding_rules.py Outdated
Comment thread docs/contribute/development/rust/coding_rules/_assets/rules.json Outdated

@PLeVasseur PLeVasseur left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @dcalavrezo-qorix -- I had an AI review this. I then reviewed the review.

Please take a look at the feedback and consider how to proceed for each.

Comment thread docs/contribute/development/rust/coding_rules/index.rst Outdated
Comment thread docs/contribute/development/rust/coding_rules/index.rst Outdated
Comment thread docs/contribute/development/rust/coding_rules/index.rst Outdated
Comment thread docs/contribute/development/rust/coding_rules/index.rst Outdated
Comment thread docs/contribute/development/rust/coding_rules/index.rst
Comment thread docs/contribute/development/rust/coding_rules/rules.rst
Comment thread docs/contribute/development/rust/coding_rules/rules.rst
Comment thread docs/contribute/development/rust/coding_rules/rules.rst
Comment thread docs/contribute/development/rust/coding_rules/rules.rst
Comment thread docs/contribute/development/rust/coding_rules/rules.rst
Follow up on the first review round of the Rust coding rules draft.

Label the SCRC MISRA C++ cross-reference as a working reference and its
per-guideline result as a draft SCRC assessment, in the overview, the
applicability page, the register columns and the rendered source lists.
The retained-source label now shows both decisions: the SCRC draft
assessment and S-CORE's choice to retain the guideline.

Link the three draft SCRC coding guidelines that exist at the pinned
revision (7.0.4 shift-count bounds, 8.2.2 numeric uses of as, 8.2.10
recursion) from the rules that build on them, SCR-RUST-026, -016 and
-022, and qualify the statement that the catalogue supplies rule text
where none exists yet. Guideline URLs live in the source manifest and
the render script rejects unknown SCRC guideline IDs.

Correct the rule counts to 39 interpretations and four supplements, and
say that the rules link, rather than cover, 83 of the 92 guidelines the
SCRC draft assesses as applicable.

Explain how S-CORE assigns Required and Advisory, and add a level
rationale to the seven rules whose level differs from the category of
every MISRA C++ source: SCR-RUST-003, -005, -009, -011, -024, -033 and
-034.

Add the compliant/non-compliant example pairs proposed in review to
SCR-RUST-006, -007, -012, -023, -033, -034, -037 and -040, rendered from
a new optional example field in the rule data.

Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
Rule text. Make the obligations explicit that review asked for:
language specification reference and unstable-feature assessment (001);
fixed-outcome conditions, the 0.1.1 object scope and Drop effects, with
an example pair (003); the 0.1.2 discard convention and a contract-based
definition of a critical Result (004); shared numerical contracts (005);
the 6.7.1/6.7.2 scope adaptation and a first-party static mut ban with
reviewed exceptions (008); nested block comments and cfg-parked code
(009); closures capturing raw pointers and raw use-after-move (015);
bool/char numeric uses and the char-cast restriction as an S-CORE
addition (016); checked-downcast coverage limits (019); owning values
from raw pointers (020); no C-variadic definitions (021); const fn
recursion in constant contexts (022); when a conditional effect is
acceptable (024); copy validity versus later typed use and byte
comparison as an adaptation of 24.5.2 (025); the explicit shift bound
and the arithmetic policy as an S-CORE extension (026); all production
if/else-if chains (027); the raw-pointer-only scope of 11.3.2 (030);
MaybeUninit container versus payload (031); borrowed-to-owned
conversions and self-aliasing move emulation (035); panic-free versus
panic-contained, destructor panics, catch_unwind limits, indirect
termination calls and panic payload contents (036); functions preferred
over macros with stated exceptions (038); and unwinding, nonlocal
transfers, signals, errno, locale and returned-storage obligations from
the linked MISRA C++ sources, plus the remaining MISRA C Addendum 6 work
(042). Remove the exported-array sentence from 010.

Sources. Move 18.5.1 from 004 to 036 and 042, and 6.0.3 from 011 to 013.
Mark 6.4.2, 7.11.1, 19.2.3 and 21.6.4 not applicable, following the SCRC
draft; 017 becomes an S-CORE adaptation without a MISRA C++ source and
014's method-resolution policy an S-CORE addition. 19.0.1 remains the
only guideline retained beyond the SCRC draft, now justified by the
cfg-name typo hazard.

Register. Replace MISRust class labels in notes with the required Rust
behavior, drop stale follow-up text on settled exclusions, record the
SCRC authors' doubt about the safe classification of 4.1.3 and 7.0.1,
name supertrait_item_shadowing for 6.4.2, and add a same-name
rebinding example pair to 014.

Tooling. Narrow the check message to what is verified and add
--upstream, which compares every register row and the file hash with a
local copy of the pinned SCRC mapping. Describe the differences analysis
as a contributor's working notes. Fix the grammar in 016.

Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog
Status: No status

Development

Successfully merging this pull request may close these issues.

4 participants