diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b7f1146..073e3f7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -30,6 +30,18 @@ jobs: fi echo "clean" + - name: Fail if a crate root lacks #![forbid(unsafe_code)] + run: | + set -euo pipefail + status=0 + while IFS= read -r root; do + if ! grep -q '^#!\[forbid(unsafe_code)\]' "$root"; then + echo "::error file=$root::crate root is missing #![forbid(unsafe_code)]" + status=1 + fi + done < <(find . -path ./target -prune -o \( -path '*/src/lib.rs' -o -path '*/src/main.rs' -o -path '*/src/bin/*.rs' -o -name build.rs \) -print) + exit $status + dependency-policy: name: Dependency licenses & sources (cargo-deny) runs-on: ubuntu-latest diff --git a/fasterhenry-cli/build.rs b/fasterhenry-cli/build.rs index 6d0dafd..34852fa 100644 --- a/fasterhenry-cli/build.rs +++ b/fasterhenry-cli/build.rs @@ -1,6 +1,8 @@ // Bakes the source revision into `--version` via FASTERHENRY_GIT_DESCRIBE. // Falls back to "unknown" where git is absent (a crates.io tarball build), // so the version string stays deterministic there. +#![forbid(unsafe_code)] + use std::process::Command; fn describe() -> String { diff --git a/fasterhenry-cli/src/lib.rs b/fasterhenry-cli/src/lib.rs index 4520474..1809f79 100644 --- a/fasterhenry-cli/src/lib.rs +++ b/fasterhenry-cli/src/lib.rs @@ -4,6 +4,8 @@ //! The binary logic lives in this library so the tests can drive it without //! spawning a process; `src/main.rs` is a thin wrapper. +#![forbid(unsafe_code)] + pub mod cli; pub mod inp; pub mod mat; diff --git a/fasterhenry-cli/src/main.rs b/fasterhenry-cli/src/main.rs index be87555..6078b8b 100644 --- a/fasterhenry-cli/src/main.rs +++ b/fasterhenry-cli/src/main.rs @@ -5,6 +5,8 @@ //! the explicit `fasterhenry run `, which writes //! one only when `--zc-mat` asks for it. See `--help`. +#![forbid(unsafe_code)] + use fasterhenry_cli::cli::{Invocation, RunArgs}; use fasterhenry_cli::inp::ParseOptions; use fasterhenry_cli::spice::write_spice_subckt;