# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 64 → 67 (+3.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 86 → 86 (+0.0)
- Architecture 100 → 98 (-1.6)
- Maturity 61 → 65 (+4.5)
- Readiness 68 → 64 (-4.2)
- Security 55 → 62 (+7.5)

## Resolved (11)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High IaC: DS-0029 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- High IaC: DS-0029 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- High IaC: WD-DOCKER-0001 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: DS-0013 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (container/ubuntu24-cuda13-llvm19/Dockerfile)
- Off-boarding risk: anonymized user #1

## New (42)

- High IaC: DS-0029 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- High IaC: DS-0029 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- High IaC: WD-DOCKER-0001 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent API for retrieving version information. `CublasContext` and `CudnnContext` return a tuple `(u32, u32, u32)` directly. `Context` and `UnownedContext` return a `CudaResult` wrapping an opaque or unspecified type (likely requiring further calls). `CudaApiVersion` uses a builder-like or accessor pattern (`get`, `major`, `minor`). This forces users to handle versioning differently depending on which context or API they are querying.
- Inconsistent handling of stream context. `CublasContext` has a `with_stream` method that takes a closure, suggesting a scoped stream execution, but also has `set_stream` (implied by Cudnn having it, though Cublas doesn't explicitly list `set_stream` in the provided snippet, it has `with_stream`). More critically, `CudnnContext` has `set_stream` but no `with_stream`. This creates an inconsistency in how users manage stream scope: one library encourages scoped execution via closures, the other uses imperative state setting.
- Inconsistent resource management pattern: Some types use a static method `drop(ctx: Self)` (Cublas, Cudnn, Context, Event, ArrayObject) while others rely on standard Rust `Drop` trait or do not expose a manual drop method in the signature list. While `drop` as a static method is a valid pattern for explicit resource release, the inconsistency lies in the fact that `CudaBuilder` and `GpuBuffer`/`GpuBox` do not show a `drop` method, implying reliance on RAII, whereas the context/event types require explicit manual cleanup. This mixes RAII and manual memory management paradigms without a clear, consistent boundary.
- Low cohesion: Builder (LCOM4 4) (crates/rustc_codegen_nvvm/src/builder.rs)
- Low cohesion: CodegenCx (LCOM4 14) (crates/rustc_codegen_nvvm/src/context.rs)
- Low cohesion: CudaBuilder (LCOM4 15) (crates/cuda_builder/src/lib.rs)
- Low cohesion: CudnnContext (LCOM4 4) (crates/cudnn/src/context.rs)
- Medium IaC: DS-0013 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (container/ubuntu24-cuda13-llvm21/Dockerfile)
- Off the main sequence: blastoff
- Off the main sequence: cust_raw
- Off-boarding risk: anonymized user #1
- Outdated: anyhow
- …and 22 more

## Changes since last survey

- 9 commits — 5 feature/other, 4 fixes

## By area

- .github/workflows — 3 commits
- crates/cuda_std — 3 commits
- crates/rustc_codegen_nvvm — 1 commit
- guide/src — 1 commit
- tests/compiletests — 1 commit

## Notable commits

- fix: ci: fix digest artifact pattern matching llvm21 image digests
- fix: fix(atomic): use system memory scope for SystemAtomic types
- fix: fix(nvvm): cast bit-counting intrinsic results back to the return width
- fix: fix(warp): fix float casting in warp_match_any/warp_match_all
- change: Grant Pages deploy artifact read permission
- change: Point LLVM 21 prebuilt URLs at the upstream release
- change: Upgrade modern backend to LLVM 21.1.8 and CUDA 13.3
- change: docs(guide): warn that the default NvvmArch fails silently on pre-Turing GPUs
- change: mark warp_shuffle_64/128/16/8 as gpu_only
