What changed, and why it matters
This commit is a housekeeping change that moves shared code-quality rules from individual package configuration files into a single workspace-wide configuration. It does not change any program logic, fix a bug, or alter how the software behaves at runtime. One package also adds a warning to discourage risky indexing patterns, which is a preventive code-quality measure, not a security patch.
No security action required. Treat as a normal build-system refactoring commit.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit refactors Cargo lint configuration by introducing [workspace.lints] in the root Cargo.toml and replacing duplicated per-package [lints.rust] / [lints.clippy] sections in consensus_encoding/Cargo.toml and units/Cargo.toml with [lints] workspace = true. In units/src/lib.rs it adds #![warn(clippy::indexing_slicing)] because the workspace-level config does not include that lint. No executable code, APIs, dependencies, or cryptographic operations are modified.
Changed components
Cargo.tomlconsensus_encoding/Cargo.tomlunits/Cargo.tomlunits/src/lib.rsInspect captured patch +138 / −263
diff --git a/Cargo.toml b/Cargo.toml
index 336e2eab..e1efd3af 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -2,3 +2,135 @@
members = ["addresses", "base58", "bip158", "bitcoin", "chacha20_poly1305", "consensus_encoding", "crypto", "fuzz", "hashes", "internals", "io", "p2p", "primitives", "units"]
exclude = ["benches"]
resolver = "2"
+
+[workspace.lints.rust]
+unexpected_cfgs = { level = "deny", check-cfg = ['cfg(kani)'] }
+
+[workspace.lints.clippy]
+# Exclude lints we don't think are valuable.
+needless_question_mark = "allow" # https://github.com/rust-bitcoin/rust-bitcoin/pull/2134
+manual_range_contains = "allow" # More readable than clippy's format.
+# Exhaustive list of pedantic clippy lints
+assigning_clones = "warn"
+bool_to_int_with_if = "warn"
+borrow_as_ptr = "warn"
+case_sensitive_file_extension_comparisons = "warn"
+cast_lossless = "warn"
+cast_possible_truncation = "allow" # All casts should include a code comment (except test code).
+cast_possible_wrap = "allow" # Same as above re code comment.
+cast_precision_loss = "warn"
+cast_ptr_alignment = "warn"
+cast_sign_loss = "allow" # All casts should include a code comment (except in test code).
+checked_conversions = "warn"
+cloned_instead_of_copied = "warn"
+copy_iterator = "warn"
+default_trait_access = "warn"
+doc_link_with_quotes = "warn"
+doc_markdown = "warn"
+empty_enum = "warn"
+enum_glob_use = "warn"
+expl_impl_clone_on_copy = "warn"
+explicit_deref_methods = "warn"
+explicit_into_iter_loop = "warn"
+explicit_iter_loop = "warn"
+filter_map_next = "warn"
+flat_map_option = "warn"
+float_cmp = "allow" # Bitcoin floats are typically limited to 8 decimal places and we want them exact.
+fn_params_excessive_bools = "warn"
+from_iter_instead_of_collect = "warn"
+if_not_else = "warn"
+ignored_unit_patterns = "warn"
+implicit_clone = "warn"
+implicit_hasher = "warn"
+inconsistent_struct_constructor = "warn"
+index_refutable_slice = "warn"
+inefficient_to_string = "warn"
+inline_always = "warn"
+into_iter_without_iter = "warn"
+invalid_upcast_comparisons = "warn"
+items_after_statements = "warn"
+iter_filter_is_ok = "warn"
+iter_filter_is_some = "warn"
+iter_not_returning_iterator = "warn"
+iter_without_into_iter = "warn"
+large_digit_groups = "warn"
+large_futures = "warn"
+large_stack_arrays = "warn"
+large_types_passed_by_value = "warn"
+linkedlist = "warn"
+macro_use_imports = "warn"
+manual_assert = "warn"
+manual_instant_elapsed = "warn"
+manual_is_power_of_two = "warn"
+manual_is_variant_and = "warn"
+manual_let_else = "warn"
+manual_ok_or = "warn"
+manual_string_new = "warn"
+many_single_char_names = "warn"
+map_unwrap_or = "warn"
+match_bool = "allow" # Adds extra indentation and LOC.
+match_same_arms = "allow" # Collapses things that are conceptually unrelated to each other.
+match_wild_err_arm = "warn"
+match_wildcard_for_single_variants = "warn"
+maybe_infinite_iter = "warn"
+mismatching_type_param_order = "warn"
+missing_errors_doc = "warn"
+missing_fields_in_debug = "warn"
+missing_panics_doc = "warn"
+must_use_candidate = "allow" # Useful for audit but many false positives.
+mut_mut = "warn"
+naive_bytecount = "warn"
+needless_bitwise_bool = "warn"
+needless_continue = "warn"
+needless_for_each = "warn"
+needless_pass_by_value = "warn"
+needless_raw_string_hashes = "warn"
+no_effect_underscore_binding = "warn"
+no_mangle_with_rust_abi = "warn"
+option_as_ref_cloned = "warn"
+option_option = "warn"
+ptr_as_ptr = "warn"
+ptr_cast_constness = "warn"
+pub_underscore_fields = "warn"
+range_minus_one = "warn"
+range_plus_one = "warn"
+redundant_clone = "warn"
+redundant_closure_for_method_calls = "warn"
+redundant_else = "warn"
+ref_as_ptr = "warn"
+ref_binding_to_reference = "warn"
+ref_option = "warn"
+ref_option_ref = "warn"
+return_self_not_must_use = "warn"
+same_functions_in_if_condition = "warn"
+semicolon_if_nothing_returned = "warn"
+should_panic_without_expect = "warn"
+similar_names = "allow" # Too many (subjectively) false positives.
+single_char_pattern = "warn"
+single_match_else = "warn"
+stable_sort_primitive = "warn"
+str_split_at_newline = "warn"
+string_add_assign = "warn"
+struct_excessive_bools = "warn"
+struct_field_names = "allow" # dumb
+too_many_lines = "warn"
+transmute_ptr_to_ptr = "warn"
+trivially_copy_pass_by_ref = "warn"
+unchecked_duration_subtraction = "warn"
+unicode_not_nfc = "warn"
+uninlined_format_args = "allow" # This is a subjective style choice.
+unnecessary_box_returns = "warn"
+unnecessary_join = "warn"
+unnecessary_literal_bound = "warn"
+unnecessary_wraps = "warn"
+unnested_or_patterns = "warn"
+unreadable_literal = "warn"
+unsafe_derive_deserialize = "warn"
+unused_async = "warn"
+unused_self = "warn"
+use_self = "warn"
+used_underscore_binding = "warn"
+used_underscore_items = "warn"
+verbose_bit_mask = "warn"
+wildcard_imports = "warn"
+zero_sized_map_values = "warn"
diff --git a/consensus_encoding/Cargo.toml b/consensus_encoding/Cargo.toml
index 312cd583..31a5028e 100644
--- a/consensus_encoding/Cargo.toml
+++ b/consensus_encoding/Cargo.toml
@@ -31,134 +31,5 @@ rustdoc-args = ["--cfg", "docsrs"]
name = "encoder"
required-features = ["alloc"]
-[lints.rust]
-unexpected_cfgs = { level = "deny", check-cfg = [] }
-
-[lints.clippy]
-# Exclude lints we don't think are valuable.
-needless_question_mark = "allow" # https://github.com/rust-bitcoin/rust-bitcoin/pull/2134
-manual_range_contains = "allow" # More readable than clippy's format.
-# Exhaustive list of pedantic clippy lints
-assigning_clones = "warn"
-bool_to_int_with_if = "warn"
-borrow_as_ptr = "warn"
-case_sensitive_file_extension_comparisons = "warn"
-cast_lossless = "warn"
-cast_possible_truncation = "allow" # All casts should include a code comment (except test code).
-cast_possible_wrap = "allow" # Same as above re code comment.
-cast_precision_loss = "warn"
-cast_ptr_alignment = "warn"
-cast_sign_loss = "allow" # All casts should include a code comment (except in test code).
-checked_conversions = "warn"
-cloned_instead_of_copied = "warn"
-copy_iterator = "warn"
-default_trait_access = "warn"
-doc_link_with_quotes = "warn"
-doc_markdown = "warn"
-empty_enum = "warn"
-enum_glob_use = "warn"
-expl_impl_clone_on_copy = "warn"
-explicit_deref_methods = "warn"
-explicit_into_iter_loop = "warn"
-explicit_iter_loop = "warn"
-filter_map_next = "warn"
-flat_map_option = "warn"
-float_cmp = "allow" # Bitcoin floats are typically limited to 8 decimal places and we want them exact.
-fn_params_excessive_bools = "warn"
-from_iter_instead_of_collect = "warn"
-if_not_else = "warn"
-ignored_unit_patterns = "warn"
-implicit_clone = "warn"
-implicit_hasher = "warn"
-inconsistent_struct_constructor = "warn"
-index_refutable_slice = "warn"
-inefficient_to_string = "warn"
-inline_always = "warn"
-into_iter_without_iter = "warn"
-invalid_upcast_comparisons = "warn"
-items_after_statements = "warn"
-iter_filter_is_ok = "warn"
-iter_filter_is_some = "warn"
-iter_not_returning_iterator = "warn"
-iter_without_into_iter = "warn"
-large_digit_groups = "warn"
-large_futures = "warn"
-large_stack_arrays = "warn"
-large_types_passed_by_value = "warn"
-linkedlist = "warn"
-macro_use_imports = "warn"
-manual_assert = "warn"
-manual_instant_elapsed = "warn"
-manual_is_power_of_two = "warn"
-manual_is_variant_and = "warn"
-manual_let_else = "warn"
-manual_ok_or = "warn"
-manual_string_new = "warn"
-many_single_char_names = "warn"
-map_unwrap_or = "warn"
-match_bool = "allow" # Adds extra indentation and LOC.
-match_same_arms = "allow" # Collapses things that are conceptually unrelated to each other.
-match_wild_err_arm = "warn"
-match_wildcard_for_single_variants = "warn"
-maybe_infinite_iter = "warn"
-mismatching_type_param_order = "warn"
-missing_errors_doc = "warn"
-missing_fields_in_debug = "warn"
-missing_panics_doc = "warn"
-must_use_candidate = "allow" # Useful for audit but many false positives.
-mut_mut = "warn"
-naive_bytecount = "warn"
-needless_bitwise_bool = "warn"
-needless_continue = "warn"
-needless_for_each = "warn"
-needless_pass_by_value = "warn"
-needless_raw_string_hashes = "warn"
-no_effect_underscore_binding = "warn"
-no_mangle_with_rust_abi = "warn"
-option_as_ref_cloned = "warn"
-option_option = "warn"
-ptr_as_ptr = "warn"
-ptr_cast_constness = "warn"
-pub_underscore_fields = "warn"
-range_minus_one = "warn"
-range_plus_one = "warn"
-redundant_clone = "warn"
-redundant_closure_for_method_calls = "warn"
-redundant_else = "warn"
-ref_as_ptr = "warn"
-ref_binding_to_reference = "warn"
-ref_option = "warn"
-ref_option_ref = "warn"
-return_self_not_must_use = "warn"
-same_functions_in_if_condition = "warn"
-semicolon_if_nothing_returned = "warn"
-should_panic_without_expect = "warn"
-similar_names = "allow" # Too many (subjectively) false positives.
-single_char_pattern = "warn"
-single_match_else = "warn"
-stable_sort_primitive = "warn"
-str_split_at_newline = "warn"
-string_add_assign = "warn"
-struct_excessive_bools = "warn"
-struct_field_names = "allow" # dumb
-too_many_lines = "warn"
-transmute_ptr_to_ptr = "warn"
-trivially_copy_pass_by_ref = "warn"
-unchecked_duration_subtraction = "warn"
-unicode_not_nfc = "warn"
-uninlined_format_args = "allow" # This is a subjective style choice.
-unnecessary_box_returns = "warn"
-unnecessary_join = "warn"
-unnecessary_literal_bound = "warn"
-unnecessary_wraps = "warn"
-unnested_or_patterns = "warn"
-unreadable_literal = "warn"
-unsafe_derive_deserialize = "warn"
-unused_async = "warn"
-unused_self = "warn"
-use_self = "warn"
-used_underscore_binding = "warn"
-used_underscore_items = "warn"
-verbose_bit_mask = "warn"
-wildcard_imports = "warn"
-zero_sized_map_values = "warn"
+[lints]
+workspace = true
diff --git a/units/Cargo.toml b/units/Cargo.toml
index 1d6eac2a..9c255076 100644
--- a/units/Cargo.toml
+++ b/units/Cargo.toml
@@ -35,135 +35,5 @@ serde_json = "1.0.68"
all-features = true
rustdoc-args = ["--cfg", "docsrs"]
-[lints.rust]
-unexpected_cfgs = { level = "deny", check-cfg = ['cfg(kani)'] }
-
-[lints.clippy]
-# Exclude lints we don't think are valuable.
-needless_question_mark = "allow" # https://github.com/rust-bitcoin/rust-bitcoin/pull/2134
-manual_range_contains = "allow" # More readable than clippy's format.
-# Exhaustive list of pedantic clippy lints
-assigning_clones = "warn"
-bool_to_int_with_if = "warn"
-borrow_as_ptr = "warn"
-case_sensitive_file_extension_comparisons = "warn"
-cast_lossless = "warn"
-cast_possible_truncation = "allow" # All casts should include a code comment (except test code).
-cast_possible_wrap = "allow" # Same as above re code comment.
-cast_precision_loss = "warn"
-cast_ptr_alignment = "warn"
-cast_sign_loss = "allow" # All casts should include a code comment (except in test code).
-checked_conversions = "warn"
-cloned_instead_of_copied = "warn"
-copy_iterator = "warn"
-default_trait_access = "warn"
-doc_link_with_quotes = "warn"
-doc_markdown = "warn"
-empty_enum = "warn"
-enum_glob_use = "warn"
-expl_impl_clone_on_copy = "warn"
-explicit_deref_methods = "warn"
-explicit_into_iter_loop = "warn"
-explicit_iter_loop = "warn"
-filter_map_next = "warn"
-flat_map_option = "warn"
-float_cmp = "allow" # Bitcoin floats are typically limited to 8 decimal places and we want them exact.
-fn_params_excessive_bools = "warn"
-from_iter_instead_of_collect = "warn"
-if_not_else = "warn"
-ignored_unit_patterns = "warn"
-implicit_clone = "warn"
-implicit_hasher = "warn"
-inconsistent_struct_constructor = "warn"
-index_refutable_slice = "warn"
-inefficient_to_string = "warn"
-inline_always = "warn"
-into_iter_without_iter = "warn"
-invalid_upcast_comparisons = "warn"
-items_after_statements = "warn"
-iter_filter_is_ok = "warn"
-iter_filter_is_some = "warn"
-iter_not_returning_iterator = "warn"
-iter_without_into_iter = "warn"
-large_digit_groups = "warn"
-large_futures = "warn"
-large_stack_arrays = "warn"
-large_types_passed_by_value = "warn"
-linkedlist = "warn"
-macro_use_imports = "warn"
-manual_assert = "warn"
-manual_instant_elapsed = "warn"
-manual_is_power_of_two = "warn"
-manual_is_variant_and = "warn"
-manual_let_else = "warn"
-manual_ok_or = "warn"
-manual_string_new = "warn"
-many_single_char_names = "warn"
-map_unwrap_or = "warn"
-match_bool = "allow" # Adds extra indentation and LOC.
-indexing_slicing = "warn"
-match_same_arms = "allow" # Collapses things that are conceptually unrelated to each other.
-match_wild_err_arm = "warn"
-match_wildcard_for_single_variants = "warn"
-maybe_infinite_iter = "warn"
-mismatching_type_param_order = "warn"
-missing_errors_doc = "warn"
-missing_fields_in_debug = "warn"
-missing_panics_doc = "warn"
-must_use_candidate = "allow" # Useful for audit but many false positives.
-mut_mut = "warn"
-naive_bytecount = "warn"
-needless_bitwise_bool = "warn"
-needless_continue = "warn"
-needless_for_each = "warn"
-needless_pass_by_value = "warn"
-needless_raw_string_hashes = "warn"
-no_effect_underscore_binding = "warn"
-no_mangle_with_rust_abi = "warn"
-option_as_ref_cloned = "warn"
-option_option = "warn"
-ptr_as_ptr = "warn"
-ptr_cast_constness = "warn"
-pub_underscore_fields = "warn"
-range_minus_one = "warn"
-range_plus_one = "warn"
-redundant_clone = "warn"
-redundant_closure_for_method_calls = "warn"
-redundant_else = "warn"
-ref_as_ptr = "warn"
-ref_binding_to_reference = "warn"
-ref_option = "warn"
-ref_option_ref = "warn"
-return_self_not_must_use = "warn"
-same_functions_in_if_condition = "warn"
-semicolon_if_nothing_returned = "warn"
-should_panic_without_expect = "warn"
-similar_names = "allow" # Too many (subjectively) false positives.
-single_char_pattern = "warn"
-single_match_else = "warn"
-stable_sort_primitive = "warn"
-str_split_at_newline = "warn"
-string_add_assign = "warn"
-struct_excessive_bools = "warn"
-struct_field_names = "allow" # dumb
-too_many_lines = "warn"
-transmute_ptr_to_ptr = "warn"
-trivially_copy_pass_by_ref = "warn"
-unchecked_duration_subtraction = "warn"
-unicode_not_nfc = "warn"
-uninlined_format_args = "allow" # This is a subjective style choice.
-unnecessary_box_returns = "warn"
-unnecessary_join = "warn"
-unnecessary_literal_bound = "warn"
-unnecessary_wraps = "warn"
-unnested_or_patterns = "warn"
-unreadable_literal = "warn"
-unsafe_derive_deserialize = "warn"
-unused_async = "warn"
-unused_self = "warn"
-use_self = "warn"
-used_underscore_binding = "warn"
-used_underscore_items = "warn"
-verbose_bit_mask = "warn"
-wildcard_imports = "warn"
-zero_sized_map_values = "warn"
+[lints]
+workspace = true
diff --git a/units/src/lib.rs b/units/src/lib.rs
index 8c27b593..960c8e0c 100644
--- a/units/src/lib.rs
+++ b/units/src/lib.rs
@@ -25,6 +25,8 @@
#![doc(test(attr(warn(unused))))]
// Exclude lints we don't think are valuable.
#![allow(clippy::uninlined_format_args)] // Allow `format!("{}", x)` instead of enforcing `format!("{x}")`
+// Extra restriction lints.
+#![warn(clippy::indexing_slicing)] // Avoid implicit panics from indexing/slicing.
#[cfg(feature = "alloc")]
extern crate alloc;
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.