Add Rust coding rules catalogue aligned with the SCRC MISRA C++ cross-reference (draft) - #3262
dcalavrezo-qorix wants to merge 4 commits into
Conversation
Add a draft rulebook of 43 Rust coding rules under docs/contribute/development/rust/coding_rules, derived from the 69 MISRA C++:2023 guidelines that the MISRust study (Molz et al., arXiv:2605.23490v2) retains as relevant for Rust, plus three S-CORE supplements for dependencies, foreign interfaces and verification governance. The section contains an overview with adoption rules, the generated rule catalogue, an applicability register covering all 179 MISRA C++ guidelines with the unchanged MISRust classification and the S-CORE disposition, and a page on per-rule verification evidence and deviation records. Each page is a document need realizing the Software Development Plan, matching the existing C++ MISRA mapping page. Rule text and metadata live in _assets/rules.json; the catalogue and the compact mapping table are generated by tools/render_rust_coding_rules.py, which also validates the mapping. The catalogue is positioned as a rule-by-rule gap review that supplements the lint profile in score_rust_policies. It does not change the CERT-style stance of the Rust coding guidelines page and binds a component only after adoption through its Software Development Plan. No CI check is enabled. MISRust paper and dataset are CC-BY-4.0 and are attributed in the pages, the source manifest and NOTICE. MISRA guidelines are cited by number, kind and category only; no MISRA text is reproduced. Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
|
Documentation preview for this pull request is available at: |
|
Only as question: Is this on top of rustc and clippy rules ? See https://eclipse-score.github.io/score/main/contribute/development/rust/coding_guidelines.html |
Make the Safety-Critical Rust Consortium's MISRA C++:2023 cross-reference (safety-critical-rust-coding-guidelines PR #1226, commit 9e81abd4) the primary applicability reference for the draft rulebook. MISRust remains a secondary reference; its C1-C6 class is kept per guideline for traceability, and where the two disagree the SCRC verdict is followed. The applicability register gains the SCRC verdict (safe, unsafe, not applicable), the related MISRA C:2025 guideline and the SCRC guideline link per row. Dispositions are derived from the SCRC verdict: 83 applicable guidelines map to S-CORE rules, 9 are queued for rule assignment, 82 not-applicable guidelines are excluded, and 5 are retained beyond the SCRC verdict with a stated reason. Both open groups are rendered as a review queue on the applicability page. Rule source IDs are adjusted accordingly: 19 guidelines SCRC marks applicable are attached to fitting rules, 14 guidelines SCRC marks not applicable are detached, and SCR-RUST-010 becomes a supplement without a MISRA C++ source. Rule text is unchanged. The render script validates the register against the pinned SCRC counts and derives each disposition from the verdict and rule links. Attribution, source manifest and NOTICE name the SCRC cross-reference (CC-BY-4.0 documentation, unmerged at time of use) alongside MISRust. Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The moderate validation gap and two documentation clarity nits remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Adds a draft catalogue of 43 Rust coding rules aligned with the pinned SCRC MISRA C++ cross-reference, including applicability data, attribution, documentation, and generation tooling.
Changes:
- Adds rule definitions, applicability registers, and a generated review queue.
- Adds rendering and validation tooling with pinned source metadata.
- Integrates the draft catalogue into Rust development documentation.
| File | Summary | Review note |
|---|---|---|
tools/render_rust_coding_rules.py |
Renders and validates catalogue artifacts. | moderate (3 votes): Validation checks aggregate counts but not each pinned guideline record or artifact metadata. |
NOTICE |
Adds third-party attribution. | — |
docs/contribute/development/rust/index.rst |
Links the new rules section. | — |
docs/contribute/development/rust/coding_rules/verification_and_deviations.rst |
Defines verification and rollout guidance. | — |
docs/contribute/development/rust/coding_rules/rules.rst |
Contains the generated rule catalogue. | — |
docs/contribute/development/rust/coding_rules/index.rst |
Provides overview and adoption guidance. | — |
docs/contribute/development/rust/coding_rules/applicability.rst |
Documents applicability and traceability. | nit (1 vote): scrc_guideline is described as a link, but only opaque IDs are stored and rendered. |
docs/contribute/development/rust/coding_rules/_assets/sources.json |
Records pinned sources. | — |
docs/contribute/development/rust/coding_rules/_assets/rules.json |
Stores rule definitions. | nit (3 votes): Correct the incomplete grammar around as being legal in safe Rust. |
docs/contribute/development/rust/coding_rules/_assets/review_queue.csv |
Stores the generated review queue. | — |
docs/contribute/development/rust/coding_rules/_assets/applicability.csv |
Stores applicability mappings. | — |
docs/contribute/development/rust/coding_rules/_assets/applicability_summary.csv |
Stores the generated mapping summary. | — |
docs/contribute/development/rust/coding_guidelines.rst |
References and links the draft catalogue. | — |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
PLeVasseur
left a comment
There was a problem hiding this comment.
Hi @dcalavrezo-qorix -- I had an AI review this. I then reviewed the review.
Please take a look at the feedback and consider how to proceed for each.
Follow up on the first review round of the Rust coding rules draft. Label the SCRC MISRA C++ cross-reference as a working reference and its per-guideline result as a draft SCRC assessment, in the overview, the applicability page, the register columns and the rendered source lists. The retained-source label now shows both decisions: the SCRC draft assessment and S-CORE's choice to retain the guideline. Link the three draft SCRC coding guidelines that exist at the pinned revision (7.0.4 shift-count bounds, 8.2.2 numeric uses of as, 8.2.10 recursion) from the rules that build on them, SCR-RUST-026, -016 and -022, and qualify the statement that the catalogue supplies rule text where none exists yet. Guideline URLs live in the source manifest and the render script rejects unknown SCRC guideline IDs. Correct the rule counts to 39 interpretations and four supplements, and say that the rules link, rather than cover, 83 of the 92 guidelines the SCRC draft assesses as applicable. Explain how S-CORE assigns Required and Advisory, and add a level rationale to the seven rules whose level differs from the category of every MISRA C++ source: SCR-RUST-003, -005, -009, -011, -024, -033 and -034. Add the compliant/non-compliant example pairs proposed in review to SCR-RUST-006, -007, -012, -023, -033, -034, -037 and -040, rendered from a new optional example field in the rule data. Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>
Rule text. Make the obligations explicit that review asked for: language specification reference and unstable-feature assessment (001); fixed-outcome conditions, the 0.1.1 object scope and Drop effects, with an example pair (003); the 0.1.2 discard convention and a contract-based definition of a critical Result (004); shared numerical contracts (005); the 6.7.1/6.7.2 scope adaptation and a first-party static mut ban with reviewed exceptions (008); nested block comments and cfg-parked code (009); closures capturing raw pointers and raw use-after-move (015); bool/char numeric uses and the char-cast restriction as an S-CORE addition (016); checked-downcast coverage limits (019); owning values from raw pointers (020); no C-variadic definitions (021); const fn recursion in constant contexts (022); when a conditional effect is acceptable (024); copy validity versus later typed use and byte comparison as an adaptation of 24.5.2 (025); the explicit shift bound and the arithmetic policy as an S-CORE extension (026); all production if/else-if chains (027); the raw-pointer-only scope of 11.3.2 (030); MaybeUninit container versus payload (031); borrowed-to-owned conversions and self-aliasing move emulation (035); panic-free versus panic-contained, destructor panics, catch_unwind limits, indirect termination calls and panic payload contents (036); functions preferred over macros with stated exceptions (038); and unwinding, nonlocal transfers, signals, errno, locale and returned-storage obligations from the linked MISRA C++ sources, plus the remaining MISRA C Addendum 6 work (042). Remove the exported-array sentence from 010. Sources. Move 18.5.1 from 004 to 036 and 042, and 6.0.3 from 011 to 013. Mark 6.4.2, 7.11.1, 19.2.3 and 21.6.4 not applicable, following the SCRC draft; 017 becomes an S-CORE adaptation without a MISRA C++ source and 014's method-resolution policy an S-CORE addition. 19.0.1 remains the only guideline retained beyond the SCRC draft, now justified by the cfg-name typo hazard. Register. Replace MISRust class labels in notes with the required Rust behavior, drop stale follow-up text on settled exclusions, record the SCRC authors' doubt about the safe classification of 4.1.3 and 7.0.1, name supertrait_item_shadowing for 6.4.2, and add a same-name rebinding example pair to 014. Tooling. Narrow the check message to what is verified and add --upstream, which compares every register row and the file hash with a local copy of the pinned SCRC mapping. Describe the differences analysis as a contributor's working notes. Fix the grammar in 016. Signed-off-by: Dan Calavrezo <195309321+dcalavrezo-qorix@users.noreply.github.com>


Improvement
Description
Adds a draft rulebook of 43 Rust coding rules under
docs/contribute/development/rust/coding_rules/, proposing S-CORE rule text for the MISRA C++:2023 guidelines that the Safety-Critical Rust Consortium's own cross-reference (safety-critical-rust-coding-guidelines PR #1226, pinned at commit9e81abd4) marks as applicable to safe or unsafe Rust.The new section contains:
_assets/rules.json. Each rule has a stableSCR-RUST-NNNidentifier, its MISRA C++ source IDs with the SCRC verdict, the obligation, the enforcement candidates (rustc, Clippy, CodeQL, review) and the known coverage limits.Each page is a
documentneed realizingwp__sw_development_plan, matching the existing C++ MISRA mapping page.tools/render_rust_coding_rules.pyregenerates the catalogue, the mapping table and the review queue, and validates the register against the pinned SCRC verdicts (--check).Sources and positioning
doc__rust_coding_guidelines. It is a gap review against thescore_rust_policieslint profile, binds a component only after adoption through its Software Development Plan, and the rule text is offered as candidate input to the SCRC guidelines, which currently cover 3 of the 92 applicable MISRA C++ guidelines. Everything isdraft; no CI check is enabled.Licensing
NOTICE.Verification
bazel run //:docs_check: build succeeded, 0 warnings, all needs validbazel run //:copyright.check: 0 files without headerbazel test //:format.check: 3/3 passedpython3 tools/render_rust_coding_rules.py --check: generated files currentRelated ticket
No improvement ticket exists yet; to be created and linked before the PR leaves draft.