Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Quality scorecard

Audit reopening (2026-09-05): the second-computer CLI handoff and new negative regressions revealed gaps outside the earlier test inventory. Scores and ceiling-completion statements below describe the previous campaign; they are not a current release approval. See the v12 release audit for reviewed scopes, corrections and gates that must pass before reconfirming those conclusions.

Rullst generates an evidence-bound quality scorecard for every push to main and every pull request. The report is attached to the corresponding Rust CI run as quality-scorecard-<commit SHA> and is also written to that run’s job summary.

The permanent source of a run score is therefore the commit plus its workflow run, not a mutable badge. The versioned expert-audit ceilings live in .github/quality-scorecard-policy.json; CI can reduce them when required evidence fails, but a green run cannot inflate them.

What the score measures

DimensionWeightEvidence
API and architecture20Audited explicitness, cohesion and public-boundary quality; awarded only while format/Clippy, feature and MSRV gates pass
Verification depth25Audited test depth constrained by the cross-platform all-feature workspace result
Security and failure design20Audited fail-closed/error/secret boundary constrained by Clippy and the applicable specialist gate
Documentation and DX15Audited user guidance, examples, feature/migration clarity and evidence links
Operations and release20Audited durability/live/recovery/release maturity constrained by feature, MSRV and specialist evidence

Specialist evidence includes database/Redis live matrices, AI evals, the threat minimum, release local-access negatives, provider matrices, the facade’s shared-local recovery composition, and Messaging’s wire/trace, encrypted SQLite and ORM outbox crash-replay cases. Failed, cancelled, or skipped applicable gates suppress the dimensions they prove; the report is still generated so a red push cannot hide its note.

Documentation/DX evidence also includes a Cargo-aware aggregation of the 52 public tutorials. It consumes the Markdown files directly during the normal all-feature doctest run, so a green workspace test proves the standalone Rust examples compile on that SHA; explicitly contextual fragments remain visible as ignored and do not count as compiled examples.

Grades use the following fixed bands: A+ 97–100, A 90–96, B 80–89, C 70–79, D 60–69, and F below 60.

The v12 RC quality objective is A (90) or better for every crate except rullst-iot, whose approved floor is B (80). A+ is an evidence threshold, not a value to assign by intent. This owner-approved gate is deliberately stricter than the earlier all-B floor and reopens bounded implementation work before the feature freeze. It does not pre-approve a commit: the exact SHA still earns each ceiling only when every constraining gate succeeds.

Current audited green-gate scores — 3 September 2026

These are the maximum current scores when every referenced Rust CI gate passes. They are not presumed results for a new commit; the exact per-SHA artifact applies the real gate outcomes and includes the full finding for every row. They are also not the highest scores that future repository-owned work can earn. Here, current audited score means the score supported by code and evidence already present; local campaign ceiling means a planning target that must still be earned. Keeping those columns separate prevents a desired score from being published as an achieved one.

CrateCurrent audited scoreGradePrincipal remaining evidence boundary
rullst-core96ADependency operations, distributed deployment and host authorization
rullst-orm96AOnline snapshot isolation, managed/PITR backup, vendor operations and application writer/tenant/key policy
rullst-security96ATrusted rollback checkpoints, external SIEM delivery, independent audit and certification
rullst-connect95ARemote-provider leases/reconciliation, key/directory/backup operations, multi-host refresh and provider conformance
rullst96AWhole-file recovery/backup operations, multi-host coordination and maturity inherited from opt-in domain crates
rullst-auth95AShared ceremonies, multi-host state, refresh workflow and normative WebAuthn conformance
rullst-mail95AAuthoritative malware/CDR inspection, multi-host operations and inbox/provider evidence
rullst-messaging96ARemote protocols/replication, full metadata encryption and provider operations
cargo-rullst95AProduction deployment, provider accounts and real-application acceptance
rullst-ai95AExact live-model results, non-compatible streaming/provider loops, durable audit receiver operations and external retrievers
rullst-studio94ADurable/OTLP storage, key operations and shared operator authorization
rullst-capital93ALive authorization, authoritative outbox/reconciliation and homologation
rullst-orm-macros95ACompiler/ecosystem compatibility beyond the tested matrix
rullst-nexus95AHost identity/domain policy, global/custom-route authorization, immutable audit delivery and production operations
rullst-macros94AReal browser/network ecosystems and host identity policy remain external
rullst-iot83BConcrete transport/hardware storage, flashing and bootloader evidence
Repository (equal-crate aggregate)94A1,509/1,600; exact score remains conditional on the SHA’s gates

Measured gap to the v12 quality gate

Every non-IoT crate now has an audited ceiling of A or better, while IoT meets its approved B exception. The gap to the required grade is therefore zero. This also closes the repository-owned ceiling campaign, but it does not authorize a release: the exact RC SHA must still make every conditioning gate green, including the dedicated facade composition job.

CrateCurrentGap to required gradeNext evidence cluster to audit
None0Every current audited ceiling meets its approved RC floor

Maximum-local v12 campaign

The release floor is not the stopping target. The table below records the provisional highest score that the current campaign can responsibly pursue with repository-owned implementation, deterministic fixtures, local services, CI and documentation. These targets do not alter the scorecard policy and must not appear as achieved scores until their evidence is implemented and green on the exact commit.

The campaign is scoped to the 15 non-IoT crates, v12 quality, and the historically promised [x] capabilities. IoT remains audited at its accepted 83/B evidence but is outside the remaining ceiling work. The campaign does not pull every open v13 idea into the RC. External provider acceptance, app-store/device testing, fiscal homologation, independent audit and production operation remain external even when a bounded implementation earns a high A.

All 15 active crates have now reached their audited local target: rullst-core, rullst-macros, rullst-orm-macros, rullst-messaging, rullst-capital, rullst-mail, rullst-auth, rullst-nexus, cargo-rullst, rullst-studio, rullst-orm, rullst-security, rullst-connect, rullst-ai, and the umbrella rullst facade.

CrateCurrent auditedProvisional local ceilingPoints remainingRepository-owned evidence clusterExternal boundary retained
rullst-core96/A96/A0Monotonic readiness/admission/drain, explicit supervisor shutdown and startup/concurrency/poisoned-state evidence complete for this campaignDependency operations, production topology, replica/load-balancer coordination and host domain authorization
rullst-orm96/A96/A0Authenticated bounded document recovery, fail-closed inventory semantics and real MongoDB → SurrealDB → MongoDB rehearsal complete for this campaignOnline snapshot isolation, managed/PITR backup, vendor operations and application writer/tenant/key policy
rullst-security96/A96/A0HMAC-chained local SIEM integrity, explicit key rotation and exact forgery/ordering/restart negatives complete for this campaignTrusted whole-tail checkpoints, external SIEM delivery/acknowledgement, independent audit, certification and real SOC operation
rullst-connect95/A95/A0Encrypted shared-local token state, immutable quota, transactional generation CAS, restart/contention/corruption evidence and public/facade integration complete for this campaignRemote-provider lease/reconciliation, key/directory/backup operations, multi-host replication, live-provider conformance and IdP operations
rullst96/A96/A0Six-subsystem shared-local SQLite composition, aggregate readiness, restart/idempotency, secret-exclusion and isolated corruption evidence complete for this campaignWhole-file backup/recovery operations, multi-host coordination and maturity inherited from external provider/device evidence
rullst-auth95/A95/A0Bounded shared local revocation/device lifecycle, restart and counter-CAS evidence complete for this campaignShared ceremonies, multi-host replication, refresh workflow and normative WebAuthn conformance
rullst-mail95/A95/A0Bounded inspection, durable shared-local suppression and minimized terminal observations complete for this campaignAuthoritative malware/CDR inspection, provider webhook conformance, multi-host operations, inbox placement, DNS reputation and live-provider acceptance
rullst-messaging96/A96/A0Encrypted local durability, canonical codec/trace and ORM outbox crash-replay contracts complete for this campaignRemote broker operation, replication, full metadata encryption and cloud acceptance
cargo-rullst95/A95/A0All 270 structural profiles, eight generated-test/runtime cases, seven public-CLI profiles covering all six blueprints plus polyglot axes, and v5/v6/v11 transactional upgrade/recovery fixtures complete for this campaignProduction deployment/account acceptance
rullst-ai95/A95/A0OpenAI-compatible SSE/cancellation, bounded authenticated audit export and static-dispatch adaptive evaluation with content-free reports complete the repository-owned campaignNon-compatible protocols need adapters; audit receiver operation, exact live-model behavior/results and corpus quality remain external
rullst-studio94/A94/A0Push-only authenticated trace ingestion, bounded query heuristics and metadata-only Memory/live-Redis inspection complete for this campaignDurable/OTLP storage, producer key operations, shared operator identity/RBAC/TLS and production topology
rullst-iot83/B83/B0Approved B exception retained outside the 15-crate ceiling campaignPhysical hardware, flashing/bootloader, broker/device interoperability and certification
rullst-capital93/A93/A0Signed-environment binding and bounded HMAC-chained local fiscal command audit/recovery complete the local targetLive gateway acceptance, authoritative multi-writer outbox/reconciliation and official fiscal homologation
rullst-orm-macros95/A95/A0Fail-closed structured parser, 24 exact UI diagnostics and generated runtime cross-evidence complete for this campaignCompiler/ecosystem compatibility beyond the tested matrix
rullst-nexus95/A95/A0Trusted-context tenant scope, transaction-coupled audit and bounded admin operation contracts complete for this campaignHost identity/domain policy, global/custom-route authorization, immutable audit delivery and production operation
rullst-macros94/A94/A0Bounded grammar/diagnostics, native server route, versioned Wasm transport, CSRF composition and generated-project evidence complete for this campaignReal compiler/browser/network ecosystem matrix and host identity policy beyond CI
Repository1,509/1,600 = 94.3 (rounded 94/A)1,509/1,600 = 94.3/A0Repository-owned ceiling campaign complete; the exact SHA gates remain authoritativeA+ remains outside this local planning ceiling

On this planning scale, 100% of the maximum-local v12 target is now backed by committed evidence and zero planning points remain. Awarding those points is still conditional on every applicable gate succeeding for the exact SHA; this completion is not a release decision or an external validation claim. rullst-iot is the only accepted campaign result below A; its approved B exception reflects missing physical/device evidence rather than lowering the release gate for the other 15 crates. This table must be re-audited whenever implementation reveals a stronger or weaker boundary.

The final point allocation may differ from these candidate clusters after code review. External provider acceptance, fiscal homologation, device testing, store publication, and independent audit must stay explicitly external even when enough repository-owned evidence exists to reach A.

What the score does not measure

The score is not:

  • feature completeness or roadmap percentage;
  • a claim that every crate has the same maturity;
  • provider acceptance, device/store validation, fiscal homologation, or a security/compliance certification;
  • a benchmark or proof that Rullst is better than another framework;
  • a substitute for the exact release gates on the candidate SHA.

Those questions belong to the capability status, the capability ledger, and the release evidence. Keeping these axes separate prevents a well-tested bounded foundation from being mistaken for a finished remote integration.

Interpreting changes between pushes

A score should change only when its evidence changes. The per-push review will call out:

  1. the previous and current SHA;
  2. repository score and changed crate rows;
  3. the exact gate responsible for a gain or loss;
  4. feature-completeness movement separately, when applicable.

No points are added for code volume, number of features, marketing claims, or raw test count alone.