Development Workflow
Daily loop
devenv shell
cargo build --all-features
cargo test
lint:all
verify:docs
verify:security
test:idl
Formatting and linting
- Rust and markdown formatting are enforced through
dprint. - Clippy runs with strict workspace lint settings, including the
pina_lintscrate that holds every Pina lint. security:pina-lintruns every registered Pina lint over all example programs and secure security fixtures. It builds the workspacepina_lint_driverand runs cargo with it asRUSTC_WORKSPACE_WRAPPER.- The Security Lints reference documents each rule, compliant patterns, and heuristic limitations.
Reusable documentation blocks
- Template providers live in
templates/*.t.md. - Prefer updating the shared provider block first when the same guidance appears in the README, crate readmes, and mdBook.
- Run
docs:syncafter changing provider blocks to refresh all consumer blocks. - Run
docs:check(orverify:docs) in CI to ensure docs stay synchronized.
Dependency/tooling updates
update:deps
Codama/IDL workflow
# Generate IDLs and clients for all examples.
codama:idl:all
# Generate Rust + CPI + JS + Dart clients.
codama:clients:generate
# Generate one project's configured clients.
pina generate
# Run the complete generation and validation pipeline.
codama:test
# Run IDL fixture drift + validation checks used by CI.
test:idl
# Run Quasar SVM generated-client e2e checks alongside LiteSVM.
pnpm run test:quasar-svm
Dependency security
security:denyruns policy checks (license allow-list, source restrictions, dependency bans). CI exposes it as the dedicatedcargo-denyjob.security:auditruns RustSec vulnerability checks overCargo.lock.security:zizmoraudits GitHub Actions workflows and composite actions for security anti-patterns. CI exposes it as the dedicatedzizmorjob.verify:securityruns all of the checks above.
Coverage
Generate coverage locally for Pina’s runtime, CLI, Codama renderer, and profile codec fixtures:
coverage:all
This produces an LCOV report at target/coverage/lcov.info.
Bit-precise verification
Kani proves bounded safety and correctness properties over Pina’s parsers, lamport arithmetic, resize planning, fixed PinaPod validation, CPI metadata, and compact account layouts. Compact coverage includes size checks, valid initialization, patch preflight, grow and shrink ordering, and rejected updates that leave bytes and lamports unchanged:
# Fast proofs intended for every pull request.
devenv --profile kani shell -- test:kani:quick
# Heavier compact patch and layout state-machine proofs.
devenv --profile kani shell -- test:kani:compact
# Every proof harness.
devenv --profile kani shell -- test:kani
Kani is provided by the pinned ifiokjr/nixpkgs devenv input. Compact proofs use explicit unwind bounds. A successful result applies to the capacities and operation sequences encoded by each proof.
For experimental Solana-VM coverage collection (non-blocking), run:
coverage:vm:experimental
Changesets
Any code changes in crates/ or examples/ should include a file in .changeset/ describing impact and release type.