refactor(android): forbid unsafe workspace-wide, quarantine JNI in app (#91)
Addresses #91: the #90 posture (`deny(unsafe_code)` + three scattered `#![allow(unsafe_code)]` across solitaire_data and solitaire_engine) punched unsafe holes into otherwise-pure logic crates. Replace it by *reducing* the unsafe rather than relocating it, then forbidding it everywhere it can be forbidden. Changes: - solitaire_data: new safe `android_jni` bridge owning the cached `JavaVM` and activity `GlobalRef`; exposes `with_env` / `with_activity_env` so keystore/clipboard/safe-area never touch a raw handle. - keystore: drop the `JavaVM::from_raw` init path (now in the app) and replace the three `unsafe { JByteArray::from_raw(x.into_raw()) }` casts with the safe `JByteArray::from(JObject)` conversion jni 0.21 provides. - engine clipboard + safe_area: route through the bridge; remove their `#![allow(unsafe_code)]` and all `from_raw` calls. - solitaire_app: becomes the single owner of FFI unsafe. `android_main` reconstructs the raw `JavaVM` / activity once (it must, as the cdylib that exports `#[unsafe(no_mangle)]`) and registers the safe wrappers. It opts to its own `deny`-level lints with two scoped `#[allow(unsafe_code)]`. - workspace: `unsafe_code` is now `forbid`. Every crate except the app entry point is fully unsafe-free. Net: 7 unsafe sites across three crates collapse to 3 at the OS boundary in one crate. Verified with host `clippy --workspace -- -D warnings` and an `aarch64-linux-android` clippy build of solitaire_app (transitively engine + data); also fixed two latent android-only `collapsible_if` warnings surfaced in the keystore by the cross-target check. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
+7
-6
@@ -19,13 +19,14 @@ license = "MIT"
|
||||
rust-version = "1.95"
|
||||
|
||||
# Pedantic correctness lints applied across every member crate via
|
||||
# `[lints] workspace = true`. `unsafe_code` is "deny" rather than "forbid"
|
||||
# so the three Android JNI FFI modules can opt back in with a scoped
|
||||
# `#![allow(unsafe_code)]` — `forbid` cannot be locally overridden, which
|
||||
# would break the Android build. Pure crates (core, sync) carry no `unsafe`
|
||||
# and so remain effectively forbidden in practice.
|
||||
# `[lints] workspace = true`.
|
||||
[workspace.lints.rust]
|
||||
unsafe_code = "deny"
|
||||
# Workspace-wide ban on `unsafe`. The sole exception is `solitaire_app`,
|
||||
# which sets its own `deny`-level lints (see its Cargo.toml) because the
|
||||
# Android cdylib entry point must reconstruct raw JNI handles. Every other
|
||||
# crate reaches Android JNI through the safe `solitaire_data::android_jni`
|
||||
# bridge and stays fully unsafe-free.
|
||||
unsafe_code = "forbid"
|
||||
single_use_lifetimes = "warn"
|
||||
trivial_casts = "warn"
|
||||
unused_lifetimes = "warn"
|
||||
|
||||
Reference in New Issue
Block a user