feat(#3245): gate rustdoc in nix flake check, and clear the workspace

Nothing in the gate read doc-comments: clippy doesn't check intra-doc
links, cargo test doesn't, and no check built docs. So a [`Foo`] pointing
at a renamed, moved or deleted item rendered as plain text and had no
discoverer but a human happening to read the comment.

That matters here more than in most repos, because the convention is to
put a thing's authoritative description in one doc-comment and point at
it from everywhere else -- the design leans on the pointers being real,
and a dangling link is worse than no link since it names something and
sends the reader looking.

Adds `docs-rustdoc` to nix/checks.nix: craneLib.cargoDoc over
--workspace --no-deps --document-private-items, denying six rustdoc
lints. Listed explicitly rather than -D warnings so a new lint appearing
upstream cannot red the build on a class nobody has triaged.

--document-private-items is load-bearing rather than thoroughness for
its own sake: most of this workspace's doc-comments live on private
items and //! module headers, so without it rustdoc checks a small
fraction of the links and the gate sits green while the rot continues.

Then fixes every error it reports, 40 to 0 across nine crates. The
classes differ and so do the fixes:

- public item, wrong scope -> qualify. Node and Node::parent are both
  public; the link failed only because scheduler.rs does not import
  Node. Six sites become [`crate::Node::parent`].
- private item -> downgrade to backticks. Nothing was made public to
  satisfy a lint; changing API surface to appease a doc check would be
  the tail wagging the dog.
- genuinely dead -> [`JobBuilder::insert_into`] names a method that does
  not exist. Insertion is Scheduler::insert_job.
- prose that looks like markup -> argv[0] parsed as a link, and
  <args>/<hex>/<name> parsed as HTML tags.

Note for future fixes: pub(crate) resolves in an intra-doc link, a plain
private fn in a binary crate does not (wait_for_nodes resolved,
connect_hint did not, same crate, same shape).

The check does not ride the clippy/test artifact cache. It takes
cargoArtifacts, but rustdoc needs its own flavour of dependency
metadata, which cargo build does not produce, so a --no-deps docs build
still compiles dependencies it never documents. Measured at 6m47s cold;
that reasoning is recorded in the check's own comment so the next reader
does not re-derive it.

Verified by running the check's exact command against the pre-cleanup
tree first: 40 errors, build failed. A gate that cannot fail is not
evidence, and building it before the cleanup makes that proof free.
This commit is contained in:
atlas 2026-08-14 02:15:32 +02:00 committed by mara
commit be3411e180
20 changed files with 88 additions and 41 deletions

View file

@ -678,7 +678,7 @@ impl Bus {
}
/// The effective context window for `model`: the API-reported window if a
/// turn has completed ([`api_context_window`]), else the per-model default
/// turn has completed (`api_context_window`), else the per-model default
/// ([`context_window_tokens`]). Single accessor so the state + dashboard
/// endpoints agree by construction.
#[must_use]

View file

@ -34,7 +34,7 @@ const REMINDER_BATCH_LIMIT: u64 = 100;
const POLL_INTERVAL: Duration = Duration::from_secs(5);
/// Same cap the broker used to enforce on `send`/`ask`/`remind` bodies
/// ([`hive-c0re::agent_config::limits::MESSAGE_MAX_BYTES`], not
/// (`hive-c0re`'s `agent_config::limits::MESSAGE_MAX_BYTES`, not
/// reachable from here — hive-agent doesn't depend on hive-c0re).
/// Duplicated rather than shared: this is the last remaining reminder
/// caller of that constant once the c0re-side store is deleted (commit 6).

View file

@ -7,7 +7,7 @@
//!
//! The sqlite event log stores raw (un-enriched) events — the DB never needs
//! migration when the enrichment logic changes. Enrichment is applied at
//! SSE-emit time in [`crate::web_ui::stream`] so both the live tail
//! SSE-emit time in `crate::web_ui::stream` so both the live tail
//! (`events/stream`) and the history replay (`events/history`) endpoints
//! deliver the same enriched shape.
//!

View file

@ -292,7 +292,7 @@ enum SigintOutcome {
/// directly (`Command::new(program).spawn()`, no shell in between), so the
/// harness is always the immediate parent of any claude turn it started —
/// scanning `/proc/*/status` for `PPid: <our own pid>` plus `/proc/*/cmdline`
/// for an argv[0] of `claude` finds *that* specific process without needing
/// for an `argv[0]` of `claude` finds *that* specific process without needing
/// the driver to surface its pid through any extra plumbing. Distinguishes
/// the harness's own tracked turn from an unrelated `claude` someone is
/// running interactively in the same container (a manually shelled-in
@ -301,7 +301,7 @@ enum SigintOutcome {
/// **Matches on `cmdline`, not `status`'s `Name:` field.** The nixpkgs
/// `claude-code` package wraps its real binary (`wrapProgram`-style: the
/// executable on `PATH` is a thin `exec -a claude .../.claude-wrapped ...`
/// shim) — `exec -a` only overrides argv[0] as the process itself/`cmdline`
/// shim) — `exec -a` only overrides `argv[0]` as the process itself/`cmdline`
/// see it, not the kernel's own `comm` (what `status`'s `Name:` line
/// reports, set from the executed binary's own basename at `execve` time).
/// So `Name:` shows `.claude-wrapped`, not `claude`, on a wrapped package —