|
| 1 | +# Contributing to panic-attack |
| 2 | + |
| 3 | +Thank you for your interest in contributing to panic-attack! This |
| 4 | +document provides guidelines and information for contributors. |
| 5 | + |
| 6 | +## Code of Conduct |
| 7 | + |
| 8 | +This project follows the Contributor Covenant Code of Conduct. By |
| 9 | +participating, you are expected to uphold this code. Please report |
| 10 | +unacceptable behavior to |
| 11 | +[j.d.a.jewell@open.ac](j.d.a.jewell@open.ac).uk. |
| 12 | + |
| 13 | +## How to Contribute |
| 14 | + |
| 15 | +### Reporting Bugs |
| 16 | + |
| 17 | +Before creating bug reports, please check the existing issues to avoid |
| 18 | +duplicates. When creating a bug report, include: |
| 19 | + |
| 20 | +- **Clear title** describing the issue |
| 21 | + |
| 22 | +- **Detailed description** of the problem |
| 23 | + |
| 24 | +- **Steps to reproduce** the behavior |
| 25 | + |
| 26 | +- **Expected behavior** vs actual behavior |
| 27 | + |
| 28 | +- **Environment** (OS, Rust version, panic-attack version) |
| 29 | + |
| 30 | +- **Logs or error messages** if applicable |
| 31 | + |
| 32 | +### Suggesting Enhancements |
| 33 | + |
| 34 | +Enhancement suggestions are tracked as GitHub issues. When creating an |
| 35 | +enhancement suggestion: |
| 36 | + |
| 37 | +- **Use a clear and descriptive title** |
| 38 | + |
| 39 | +- **Provide a detailed description** of the proposed feature |
| 40 | + |
| 41 | +- **Explain why this enhancement would be useful** to most users |
| 42 | + |
| 43 | +- **List any alternatives** you’ve considered |
| 44 | + |
| 45 | +### Pull Requests |
| 46 | + |
| 47 | +1. **Fork the repository** and create your branch from `main` |
| 48 | + |
| 49 | +2. **Follow the coding standards** described below |
| 50 | + |
| 51 | +3. **Add tests** for any new functionality |
| 52 | + |
| 53 | +4. **Update documentation** including README, rustdoc, and examples |
| 54 | + |
| 55 | +5. **Ensure all tests pass** (`cargo` `test`) |
| 56 | + |
| 57 | +6. **Ensure zero warnings** (`cargo` `build` `--release`) |
| 58 | + |
| 59 | +7. **Run clippy** (`cargo` `clippy` `--` `-D` `warnings`) |
| 60 | + |
| 61 | +8. **Format code** (`cargo` `fmt`) |
| 62 | + |
| 63 | +9. **Write a clear commit message** following the project’s commit |
| 64 | + style |
| 65 | + |
| 66 | +## Development Setup |
| 67 | + |
| 68 | +### Prerequisites |
| 69 | + |
| 70 | +- Rust 1.85.0 or later (MSRV) |
| 71 | + |
| 72 | +- Cargo |
| 73 | + |
| 74 | +- Git |
| 75 | + |
| 76 | +- just (optional, for task automation) |
| 77 | + |
| 78 | +### Building |
| 79 | + |
| 80 | +``` bash |
| 81 | +git clone https://github.com/hyperpolymath/panic-attack.git |
| 82 | +cd panic-attack |
| 83 | +cargo build |
| 84 | +``` |
| 85 | + |
| 86 | +### Running Tests |
| 87 | + |
| 88 | +``` bash |
| 89 | +# Run all tests |
| 90 | +cargo test |
| 91 | + |
| 92 | +# Run readiness tests (machine-verifiable CRG grades) |
| 93 | +just readiness |
| 94 | + |
| 95 | +# Run readiness summary (pass/fail per grade) |
| 96 | +just readiness-summary |
| 97 | + |
| 98 | +# Run with verbose output |
| 99 | +cargo test -- --nocapture |
| 100 | + |
| 101 | +# Run specific test |
| 102 | +cargo test test_name |
| 103 | +``` |
| 104 | + |
| 105 | +### Running Locally |
| 106 | + |
| 107 | +``` bash |
| 108 | +cargo run -- assail ./examples/vulnerable_program.rs --verbose |
| 109 | +``` |
| 110 | + |
| 111 | +## Coding Standards |
| 112 | + |
| 113 | +### Rust Style |
| 114 | + |
| 115 | +- Follow the [Rust Style Guide](https://doc.rust-lang.org/1.0.0/style/) |
| 116 | + |
| 117 | +- Use `cargo` `fmt` for consistent formatting |
| 118 | + |
| 119 | +- Use `cargo` `clippy` to catch common mistakes |
| 120 | + |
| 121 | +- Maximum line length: 100 characters (flexible for readability) |
| 122 | + |
| 123 | +### Documentation |
| 124 | + |
| 125 | +- All public APIs must have rustdoc comments |
| 126 | + |
| 127 | +- Include examples in rustdoc where appropriate |
| 128 | + |
| 129 | +- Keep comments up-to-date with code changes |
| 130 | + |
| 131 | +- Use `//!` for module-level documentation |
| 132 | + |
| 133 | +- Use `///` for item-level documentation |
| 134 | + |
| 135 | +### Testing |
| 136 | + |
| 137 | +- Write unit tests for all non-trivial functions |
| 138 | + |
| 139 | +- Write integration tests for user-facing features |
| 140 | + |
| 141 | +- Aim for 80% code coverage |
| 142 | + |
| 143 | +- Test edge cases and error conditions |
| 144 | + |
| 145 | +- Use descriptive test names: |
| 146 | + `test_<what>_<condition>_<expected_result>` |
| 147 | + |
| 148 | +- Readiness tests use CRG grade prefixes: `readiness_d_`, |
| 149 | + `readiness_c_`, `readiness_b_` |
| 150 | + |
| 151 | +### Commit Messages |
| 152 | + |
| 153 | +Follow the Conventional Commits specification: |
| 154 | + |
| 155 | + <type>: <description> |
| 156 | + |
| 157 | + [optional body] |
| 158 | + |
| 159 | + [optional footer] |
| 160 | + |
| 161 | +Types: - `feat`: New feature - `fix`: Bug fix - `docs`: Documentation |
| 162 | +changes - `test`: Adding or updating tests - `refactor`: Code |
| 163 | +refactoring - `perf`: Performance improvements - `chore`: Maintenance |
| 164 | +tasks |
| 165 | + |
| 166 | +Example: |
| 167 | + |
| 168 | + feat: add Latin-1 fallback for non-UTF-8 files |
| 169 | + |
| 170 | + Implements encoding_rs fallback when UTF-8 decoding fails. |
| 171 | + Verbose mode logs skipped files. Fixes handling of vendored |
| 172 | + C files with non-ASCII author names. |
| 173 | + |
| 174 | + Closes #42 |
| 175 | + |
| 176 | +## Project Structure |
| 177 | + |
| 178 | + panic-attack/ |
| 179 | + ├── src/ |
| 180 | + │ ├── main.rs # CLI entry point (clap) — 20 subcommands |
| 181 | + │ ├── lib.rs # Library API |
| 182 | + │ ├── types.rs # Core types (49 languages, 25 categories) |
| 183 | + │ ├── assail/ # Static analysis engine |
| 184 | + │ │ ├── analyzer.rs # 49-language analyzer with per-file detection |
| 185 | + │ │ └── patterns.rs # Language-specific attack patterns |
| 186 | + │ ├── kanren/ # miniKanren-inspired logic engine |
| 187 | + │ │ ├── core.rs # Unification, substitution, fact DB |
| 188 | + │ │ ├── taint.rs # Source-to-sink taint analysis |
| 189 | + │ │ ├── crosslang.rs # FFI boundary vulnerability chains |
| 190 | + │ │ └── strategy.rs # Risk-weighted search prioritisation |
| 191 | + │ ├── attack/ # 6-axis stress testing |
| 192 | + │ │ ├── executor.rs # Attack execution engine |
| 193 | + │ │ └── strategies.rs # Per-axis attack strategies |
| 194 | + │ ├── signatures/ # Logic-based bug signature detection |
| 195 | + │ │ ├── engine.rs # SignatureEngine (use-after-free, deadlock, etc.) |
| 196 | + │ │ └── rules.rs # Detection rules |
| 197 | + │ ├── report/ # Report generation and output |
| 198 | + │ │ ├── generator.rs # AssaultReport builder |
| 199 | + │ │ └── formatter.rs # Output formatting (text, JSON, YAML, Nickel, SARIF) |
| 200 | + │ ├── assemblyline.rs # Batch scanning with rayon parallelism + BLAKE3 |
| 201 | + │ ├── notify.rs # Notification pipeline (markdown + GitHub issues) |
| 202 | + │ ├── attestation/ # Cryptographic attestation chain |
| 203 | + │ │ ├── intent.rs # Pre-execution commitment |
| 204 | + │ │ ├── evidence.rs # Rolling hash accumulator |
| 205 | + │ │ ├── seal.rs # Post-execution binding |
| 206 | + │ │ ├── chain.rs # Chain builder orchestration |
| 207 | + │ │ └── envelope.rs # A2ML envelope wrapper |
| 208 | + │ ├── ambush/ # Ambient stressors + DAW-style timeline |
| 209 | + │ ├── amuck/ # Mutation combinations |
| 210 | + │ ├── abduct/ # Isolation + time-skew |
| 211 | + │ ├── adjudicate/ # Campaign verdict aggregation |
| 212 | + │ ├── axial/ # Reaction observation |
| 213 | + │ ├── a2ml/ # AI manifest protocol |
| 214 | + │ ├── panll/ # PanLL event-chain export |
| 215 | + │ ├── storage/ # Filesystem + VerisimDB persistence |
| 216 | + │ ├── i18n/ # Multi-language support (ISO 639-1, 10 languages) |
| 217 | + │ └── diagnostics.rs # Self-check (version, fleet, attestation, panicbot) |
| 218 | + ├── tests/ # Integration + readiness tests |
| 219 | + ├── examples/ # Example programs |
| 220 | + ├── .machine_readable/ # SCM checkpoint files + bot directives |
| 221 | + └── .github/workflows/ # CI/CD workflows |
| 222 | + |
| 223 | +## RSR Compliance |
| 224 | + |
| 225 | +This project follows RSR (Reproducible Software Repositories) standards: |
| 226 | + |
| 227 | +### Critical Invariants |
| 228 | + |
| 229 | +1. **SCM files in .machine_readable/ only** - Never put STATE.scm, |
| 230 | + ECOSYSTEM.scm, or META.scm in the repository root |
| 231 | + |
| 232 | +2. **AI manifest required** - AI.a2ml must be present and up-to-date |
| 233 | + |
| 234 | +3. **License consistency** - All files must use MPL-2.0 (SPDX header) |
| 235 | + |
| 236 | +4. **Author attribution** - Jonathan D.A. Jewell |
| 237 | + [j.d.a.jewell@open.ac](j.d.a.jewell@open.ac).uk |
| 238 | + |
| 239 | +### Updating Checkpoint Files |
| 240 | + |
| 241 | +When making significant changes, update: - |
| 242 | +`.machine_readable/STATE.scm` - Current state, completion %, next |
| 243 | +actions - `.machine_readable/ECOSYSTEM.scm` - If adding new dependencies |
| 244 | +or integrations - `.machine_readable/META.scm` - If making architectural |
| 245 | +decisions (ADRs) |
| 246 | + |
| 247 | +## Release Process |
| 248 | + |
| 249 | +1. Update version in `Cargo.toml` |
| 250 | + |
| 251 | +2. Update `CHANGELOG.md` with changes since last release |
| 252 | + |
| 253 | +3. Update `.machine_readable/STATE.scm` with new version |
| 254 | + |
| 255 | +4. Run full test suite: `cargo` `test` |
| 256 | + |
| 257 | +5. Run readiness tests: `just` `readiness-summary` |
| 258 | + |
| 259 | +6. Create git tag: `git` `tag` `-a` `vX.Y.Z` `-m` `"Release` `vX.Y.Z"` |
| 260 | + |
| 261 | +7. Push tag: `git` `push` `origin` `vX.Y.Z` |
| 262 | + |
| 263 | +8. GitHub Actions will create the release |
| 264 | + |
| 265 | +## Getting Help |
| 266 | + |
| 267 | +- **Documentation**: See README.md and DESIGN.md |
| 268 | + |
| 269 | +- **Issues**: Check existing issues or create a new one |
| 270 | + |
| 271 | +- **Email**: [j.d.a.jewell@open.ac](j.d.a.jewell@open.ac).uk |
| 272 | + |
| 273 | +- **Roadmap**: See ROADMAP.md for future plans |
| 274 | + |
| 275 | +## License |
| 276 | + |
| 277 | +By contributing to panic-attack, you agree that your contributions will |
| 278 | +be licensed under the MPL-2.0 license. See the LICENSE file for details. |
| 279 | + |
| 280 | +## Recognition |
| 281 | + |
| 282 | +Contributors will be acknowledged in: - CHANGELOG.md for their specific |
| 283 | +contributions - GitHub contributors page - Release notes |
| 284 | + |
| 285 | +Thank you for contributing to panic-attack! |
0 commit comments