[INFO] fetching crate tirith-core 0.4.2...
[INFO] documenting tirith-core-0.4.2 against 1.99.0-beta.8 for beta-rustdoc-1.100
[INFO] extracting crate tirith-core 0.4.2 into /workspace/builds/worker-0-tc1/source
[INFO] started tweaking crates.io crate tirith-core 0.4.2
[INFO] removed 0 missing tests
[INFO] finished tweaking crates.io crate tirith-core 0.4.2
[INFO] tweaked toml for crates.io crate tirith-core 0.4.2 written to /workspace/builds/worker-0-tc1/source/Cargo.toml
[INFO] validating manifest of crates.io crate tirith-core 0.4.2 on toolchain 1.99.0-beta.8
[INFO] running `Command { std: CARGO_HOME="/workspace/cargo-home" RUSTUP_HOME="/workspace/rustup-home" "/workspace/cargo-home/bin/cargo" "+1.99.0-beta.8" "metadata" "--manifest-path" "Cargo.toml" "--no-deps", kill_on_drop: false }`
[INFO] crate crates.io crate tirith-core 0.4.2 already has a lockfile, it will not be regenerated
[INFO] running `Command { std: CARGO_HOME="/workspace/cargo-home" RUSTUP_HOME="/workspace/rustup-home" "/workspace/cargo-home/bin/cargo" "+1.99.0-beta.8" "fetch" "--manifest-path" "Cargo.toml", kill_on_drop: false }`
[INFO] [stderr]     Updating crates.io index
[INFO] [stderr]  Downloading crates ...
[INFO] [stderr]   Downloaded rangemap v1.7.1
[INFO] [stderr]   Downloaded hickory-resolver v0.24.4
[INFO] [stderr]   Downloaded landlock v0.4.5
[INFO] [stderr]   Downloaded extrasafe v0.5.1
[INFO] [stderr]   Downloaded clap v4.5.57
[INFO] [stderr]   Downloaded syscalls v0.6.18
[INFO] [stderr]   Downloaded seccompiler v0.4.0
[INFO] [stderr]   Downloaded clap_builder v4.5.57
[INFO] [stderr]   Downloaded hickory-proto v0.24.4
[INFO] [stderr]   Downloaded rust-mcp-schema v0.10.1
[INFO] [stderr]   Downloaded lopdf v0.34.0
[INFO] running `Command { std: "docker" "create" "-v" "/var/lib/crater-agent-workspace/builds/worker-0-tc1/source:/opt/rustwide/workdir:ro,Z" "-v" "/var/lib/crater-agent-workspace/builds/worker-0-tc1/target:/opt/rustwide/target:rw,Z" "-v" "/var/lib/crater-agent-workspace/cargo-home:/opt/rustwide/cargo-home:ro,Z" "-v" "/var/lib/crater-agent-workspace/rustup-home:/opt/rustwide/rustup-home:ro,Z" "-m" "1610612736" "--network" "none" "ghcr.io/rust-lang/crates-build-env/linux@sha256:77db811e55d90add9212f6832c23229e3de5f1c1f9905e8cb07319ea15df73ac" "sleep" "infinity", kill_on_drop: false }`
[INFO] [stdout] c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8
[INFO] running `Command { std: "docker" "start" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "inspect" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-w" "/opt/rustwide/workdir" "--user" "0:0" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8" "/opt/rustwide/cargo-home/bin/cargo" "+1.99.0-beta.8" "metadata" "--no-deps" "--format-version=1", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "inspect" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-e" "CARGO_INCREMENTAL=0" "-e" "RUST_BACKTRACE=full" "-e" "RUSTFLAGS=--cap-lints=warn" "-e" "RUSTDOCFLAGS=--cap-lints=warn" "-w" "/opt/rustwide/workdir" "--user" "0:0" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8" "/opt/rustwide/cargo-home/bin/cargo" "+1.99.0-beta.8" "doc" "--frozen" "--no-deps" "--document-private-items" "--message-format=json", kill_on_drop: false }`
[INFO] [stderr]    Compiling proc-macro2 v1.0.106
[INFO] [stderr]    Compiling serde_core v1.0.228
[INFO] [stderr]    Compiling zerocopy v0.8.39
[INFO] [stderr]     Checking socket2 v0.6.2
[INFO] [stderr]     Checking mio v1.1.1
[INFO] [stderr]     Checking hashbrown v0.16.1
[INFO] [stderr]    Compiling serde v1.0.228
[INFO] [stderr]     Checking futures-util v0.3.31
[INFO] [stderr]    Compiling zmij v1.0.19
[INFO] [stderr]     Checking crypto-common v0.1.7
[INFO] [stderr]    Compiling rustix v1.1.3
[INFO] [stderr]    Compiling crossbeam-epoch v0.9.20
[INFO] [stderr]     Checking ring v0.17.14
[INFO] [stderr]     Checking linux-raw-sys v0.11.0
[INFO] [stderr]     Checking digest v0.10.7
[INFO] [stderr]     Checking simd-adler32 v0.3.8
[INFO] [stderr]    Compiling memchr v2.7.6
[INFO] [stderr]    Compiling ahash v0.8.12
[INFO] [stderr]    Compiling toml_write v0.1.2
[INFO] [stderr]     Checking ryu v1.0.22
[INFO] [stderr]    Compiling winnow v0.7.14
[INFO] [stderr]     Checking regex-syntax v0.8.9
[INFO] [stderr]     Checking tinyvec v1.10.0
[INFO] [stderr]     Checking indexmap v2.13.0
[INFO] [stderr]    Compiling quote v1.0.44
[INFO] [stderr]    Compiling syn v2.0.114
[INFO] [stderr]    Compiling aho-corasick v1.1.4
[INFO] [stderr]     Checking miniz_oxide v0.8.9
[INFO] [stderr]     Checking crossbeam-deque v0.8.6
[INFO] [stderr]    Compiling thiserror v2.0.18
[INFO] [stderr]    Compiling thiserror v1.0.69
[INFO] [stderr]     Checking rustls-webpki v0.103.13
[INFO] [stderr]     Checking num-rational v0.4.2
[INFO] [stderr]    Compiling curve25519-dalek v4.1.3
[INFO] [stderr]     Checking num-iter v0.1.45
[INFO] [stderr]     Checking num-complex v0.4.6
[INFO] [stderr]     Checking borrow-or-share v0.2.4
[INFO] [stderr]    Compiling syscalls v0.6.18
[INFO] [stderr]     Checking rustls v0.23.36
[INFO] [stderr]     Checking data-encoding v2.11.0
[INFO] [stderr]     Checking bit-vec v0.8.0
[INFO] [stderr]    Compiling unicode-general-category v1.1.0
[INFO] [stderr]     Checking bit-set v0.8.0
[INFO] [stderr]     Checking flate2 v1.1.9
[INFO] [stderr]     Checking rayon-core v1.13.0
[INFO] [stderr]     Checking vsimd v0.8.0
[INFO] [stderr]     Checking num v0.4.3
[INFO] [stderr]     Checking outref v0.5.2
[INFO] [stderr]     Checking micromap v0.3.0
[INFO] [stderr]     Checking regex-automata v0.4.14
[INFO] [stderr]    Compiling zip v2.4.2
[INFO] [stderr]     Checking linked-hash-map v0.5.6
[INFO] [stderr]    Compiling object v0.39.1
[INFO] [stderr]    Compiling owo-colors v4.3.0
[INFO] [stderr]     Checking bumpalo v3.19.1
[INFO] [stderr]     Checking x11rb-protocol v0.13.2
[INFO] [stderr]     Checking lru-cache v0.1.2
[INFO] [stderr]     Checking time v0.3.37
[INFO] [stderr]     Checking fraction v0.15.4
[INFO] [stderr]     Checking serde_json v1.0.149
[INFO] [stderr]     Checking zopfli v0.8.3
[INFO] [stderr]     Checking rayon v1.11.0
[INFO] [stderr]     Checking uuid-simd v0.8.0
[INFO] [stderr]     Checking nom v7.1.3
[INFO] [stderr]     Checking sha2 v0.10.9
[INFO] [stderr]     Checking md-5 v0.10.6
[INFO] [stderr]     Checking seccompiler v0.4.0
[INFO] [stderr]     Checking csv-core v0.1.13
[INFO] [stderr]     Checking num-cmp v0.1.0
[INFO] [stderr]     Checking resolv-conf v0.7.6
[INFO] [stderr]     Checking bytecount v0.6.9
[INFO] [stderr]     Checking rangemap v1.7.1
[INFO] [stderr]     Checking home v0.5.11
[INFO] [stderr]     Checking etcetera v0.8.0
[INFO] [stderr]     Checking csv v1.4.0
[INFO] [stderr]     Checking extrasafe v0.5.1
[INFO] [stderr]     Checking unicode-normalization v0.1.25
[INFO] [stderr]     Checking uuid v1.20.0
[INFO] [stderr]     Checking is-terminal v0.4.17
[INFO] [stderr]     Checking unicode-script v0.5.8
[INFO] [stderr]     Checking regex v1.12.3
[INFO] [stderr]     Checking fancy-regex v0.18.0
[INFO] [stderr]    Compiling synstructure v0.13.2
[INFO] [stderr]    Compiling serde_derive v1.0.228
[INFO] [stderr]    Compiling zerofrom-derive v0.1.6
[INFO] [stderr]    Compiling yoke-derive v0.8.1
[INFO] [stderr]    Compiling displaydoc v0.2.5
[INFO] [stderr]    Compiling zerovec-derive v0.11.2
[INFO] [stderr]    Compiling tokio-macros v2.6.0
[INFO] [stderr]    Compiling tracing-attributes v0.1.31
[INFO] [stderr]    Compiling ref-cast-impl v1.0.25
[INFO] [stderr]    Compiling thiserror-impl v1.0.69
[INFO] [stderr]    Compiling thiserror-impl v2.0.18
[INFO] [stderr]    Compiling enum-as-inner v0.6.1
[INFO] [stderr]    Compiling curve25519-dalek-derive v0.1.1
[INFO] [stderr]     Checking ppv-lite86 v0.2.21
[INFO] [stderr]     Checking gethostname v1.1.0
[INFO] [stderr]    Compiling async-trait v0.1.89
[INFO] [stderr]    Compiling enumflags2_derive v0.7.12
[INFO] [stderr]     Checking x11rb v0.13.2
[INFO] [stderr]     Checking rand_chacha v0.3.1
[INFO] [stderr]     Checking tokio v1.49.0
[INFO] [stderr]     Checking ref-cast v1.0.25
[INFO] [stderr]     Checking enumflags2 v0.7.12
[INFO] [stderr]     Checking rand v0.8.7
[INFO] [stderr]     Checking tempfile v3.24.0
[INFO] [stderr]     Checking zerofrom v0.1.6
[INFO] [stderr]     Checking landlock v0.4.5
[INFO] [stderr]     Checking yoke v0.8.1
[INFO] [stderr]     Checking tracing v0.1.44
[INFO] [stderr]     Checking zerovec v0.11.5
[INFO] [stderr]     Checking zerotrie v0.2.3
[INFO] [stderr]     Checking arboard v3.6.1
[INFO] [stderr]     Checking ed25519-dalek v2.2.0
[INFO] [stderr]     Checking tinystr v0.8.2
[INFO] [stderr]     Checking potential_utf v0.1.4
[INFO] [stderr]     Checking icu_collections v2.1.1
[INFO] [stderr]     Checking icu_locale_core v2.1.1
[INFO] [stderr]     Checking icu_provider v2.1.1
[INFO] [stderr]     Checking icu_properties v2.1.2
[INFO] [stderr]     Checking icu_normalizer v2.1.1
[INFO] [stderr]     Checking toml_datetime v0.6.11
[INFO] [stderr]     Checking serde_spanned v0.6.9
[INFO] [stderr]     Checking fluent-uri v0.4.1
[INFO] [stderr]     Checking email_address v0.2.9
[INFO] [stderr]     Checking chrono v0.4.43
[INFO] [stderr]     Checking serde_urlencoded v0.7.1
[INFO] [stderr]     Checking rust-mcp-schema v0.10.1
[INFO] [stderr]     Checking serde_yaml v0.9.34+deprecated
[INFO] [stderr]     Checking toml_edit v0.22.27
[INFO] [stderr]     Checking idna_adapter v1.2.1
[INFO] [stderr]     Checking referencing v0.46.5
[INFO] [stderr]     Checking idna v1.1.0
[INFO] [stderr]     Checking url v2.5.8
[INFO] [stderr]     Checking lopdf v0.34.0
[INFO] [stderr]     Checking jsonschema v0.46.5
[INFO] [stderr]     Checking hyper v1.8.1
[INFO] [stderr]     Checking tower v0.5.3
[INFO] [stderr]     Checking tokio-rustls v0.26.4
[INFO] [stderr]     Checking hickory-proto v0.24.4
[INFO] [stderr]     Checking toml v0.8.23
[INFO] [stderr]     Checking tower-http v0.6.8
[INFO] [stderr]     Checking hyper-util v0.1.20
[INFO] [stderr]    Compiling tirith-core v0.4.2 (/opt/rustwide/workdir)
[INFO] [stderr]     Checking hyper-rustls v0.27.7
[INFO] [stderr]     Checking reqwest v0.12.28
[INFO] [stderr]     Checking hickory-resolver v0.24.4
[INFO] [stderr]  Documenting tirith-core v0.4.2 (/opt/rustwide/workdir)
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`ArchiveOutcome`]):
[INFO] [stdout]             ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout]   = note: `#[warn(rustdoc::broken_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveViolation`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * A **hard structural violation** ([`ArchiveViolation`]) means the archive is
[INFO] [stdout]                                               ^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveViolation` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome::Rejected`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             [`ArchiveOutcome::Rejected`]. The reader still continues best-effort to
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome::Accepted`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             buffer). The wheel is still [`ArchiveOutcome::Accepted`]; the gap records
[INFO] [stdout]                                          ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `read_wheel`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`read_wheel`] takes a `Read + Seek` handle, so the CLI can pass a no-follow
[INFO] [stdout]            ^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `read_wheel` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveLimits::max_member_uncompressed`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           A4 only does the PLUMBING: for a member within [`ArchiveLimits::max_member_uncompressed`]
[INFO] [stdout]                                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveLimits` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeMemberHandoff::Buffered`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           it decompresses into a bounded in-memory buffer (a [`NativeMemberHandoff::Buffered`])
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeMemberHandoff` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeMemberHandoff::Streaming`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           member it produces a [`NativeMemberHandoff::Streaming`] view (whole-member
[INFO] [stdout]                                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeMemberHandoff` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `MemberVisitor`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           gap. The handoffs are surfaced to a [`MemberVisitor`]; B7 implements the actual
[INFO] [stdout]                                                ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `MemberVisitor` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `parse_metadata_headers`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             single shared helper [`parse_metadata_headers`], also used by
[INFO] [stdout]                                   ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `parse_metadata_headers` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `WheelMetadata`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             shipping a native `.so` is a [`WheelMetadata`] signal a later analyzer
[INFO] [stdout]                                           ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `WheelMetadata` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_wheel_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * [`verify_wheel_record`] is STRICT. A wheel is a freshly-built artifact, so
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_wheel_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_installed_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * [`verify_installed_record`] is LAX, per the installed-packages
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_installed_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `FileVerification::Unverifiable`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             an empty hash OR size column makes a file [`FileVerification::Unverifiable`]
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `FileVerification` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `OwnershipIndex`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`OwnershipIndex`] is a DUPLICATE-AWARE multimap
[INFO] [stdout]            ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `OwnershipIndex` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `classify_magic`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`classify_magic`]) used when the principal parser declines a buffer or when we
[INFO] [stdout]             ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `classify_magic` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `triage_native`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`triage_native`] NEVER panics on any input. Every `object` call is fallible and
[INFO] [stdout]            ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `triage_native` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeCoverage::Partial`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           falls back to the magic classifier and is recorded [`NativeCoverage::Partial`].
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeCoverage` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeFactKind::NativeModulePresent`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`NativeModulePresent`]: NativeFactKind::NativeModulePresent
[INFO] [stdout]                                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeFactKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NativeFacts` links to private item `correlate_native`
[INFO] [stdout]    --> src/artifact/native.rs:319:38
[INFO] [stdout]     |
[INFO] [stdout] 319 | /// raw observations; correlation ([`correlate_native`]) decides what becomes a
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout]     = note: `#[warn(rustdoc::private_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `embedded_urls` links to private item `is_suspicious_url`
[INFO] [stdout]    --> src/artifact/native.rs:345:12
[INFO] [stdout]     |
[INFO] [stdout] 345 |     /// ([`is_suspicious_url`]) counts toward the danger leg.
[INFO] [stdout]     |            ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `has_runtime_launch`
[INFO] [stdout]    --> src/artifact/native.rs:353:51
[INFO] [stdout]     |
[INFO] [stdout] 353 |     /// (the name can appear in help text); see [`has_runtime_launch`].
[INFO] [stdout]     |                                                   ^^^^^^^^^^^^^^^^^^ no item named `has_runtime_launch` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_corroboration` links to private item `correlate_native`
[INFO] [stdout]    --> src/artifact/native.rs:444:55
[INFO] [stdout]     |
[INFO] [stdout] 444 |     /// * a known-malicious indicator (folded in by [`correlate_native`], not here).
[INFO] [stdout]     |                                                       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArtifactSetInspection`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           B5/B6/B7 analyzers) and over an [`ArtifactSetInspection`] for cross-distribution
[INFO] [stdout]                                            ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArtifactSetInspection` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `artifact_hash_indicator`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             DB-gated hash match (see [`artifact_hash_indicator`]).
[INFO] [stdout]                                       ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `artifact_hash_indicator` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InspectionSubject::Artifact`
[INFO] [stdout]    --> src/artifact/correlate.rs:341:44
[INFO] [stdout]     |
[INFO] [stdout] 341 | /// subject with EXACT bytes has one: an [`InspectionSubject::Artifact`], a
[INFO] [stdout]     |                                            ^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `InspectionSubject` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InspectionSubject::GenericArchive`
[INFO] [stdout]    --> src/artifact/correlate.rs:342:7
[INFO] [stdout]     |
[INFO] [stdout] 342 | /// [`InspectionSubject::GenericArchive`], or an [`InspectionSubject::InstalledFile`]
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `InspectionSubject` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InspectionSubject::InstalledFile`
[INFO] [stdout]    --> src/artifact/correlate.rs:342:52
[INFO] [stdout]     |
[INFO] [stdout] 342 | /// [`InspectionSubject::GenericArchive`], or an [`InspectionSubject::InstalledFile`]
[INFO] [stdout]     |                                                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `InspectionSubject` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InspectionSubject::InstalledDistribution`
[INFO] [stdout]    --> src/artifact/correlate.rs:343:27
[INFO] [stdout]     |
[INFO] [stdout] 343 | /// that was hashed. An [`InspectionSubject::InstalledDistribution`] has none (its
[INFO] [stdout]     |                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `InspectionSubject` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_file`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           # Single-artifact ([`inspect_artifact_file`])
[INFO] [stdout]                               ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_file` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ARTIFACT_MAX_FILE_SIZE`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           1. Open the file no-follow within [`ARTIFACT_MAX_FILE_SIZE`] (a wheel ceiling,
[INFO] [stdout]                                              ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ARTIFACT_MAX_FILE_SIZE` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_set`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           # Artifact-set ([`inspect_artifact_set`])
[INFO] [stdout]                            ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_set` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_set`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           script). [`inspect_artifact_set`] is the two-pass model required for criterion
[INFO] [stdout]                     ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_set` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `read_wheel`
[INFO] [stdout]   --> src/artifact/inspect.rs:69:32
[INFO] [stdout]    |
[INFO] [stdout] 69 | /// The visitor B8 passes to [`read_wheel`]: it records native handoffs (for B7) and
[INFO] [stdout]    |                                ^^^^^^^^^^ no item named `read_wheel` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `RuleId::WheelStructurallyRejected`
[INFO] [stdout]    --> src/artifact/inspect.rs:495:35
[INFO] [stdout]     |
[INFO] [stdout] 495 |     /// findings, a synthesized [`RuleId::WheelStructurallyRejected`] finding for
[INFO] [stdout]     |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `RuleId` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `RuleId::WheelStructurallyRejected`
[INFO] [stdout]    --> src/artifact/inspect.rs:556:17
[INFO] [stdout]     |
[INFO] [stdout] 556 | /// Build the [`RuleId::WheelStructurallyRejected`] finding for a member the
[INFO] [stdout]     |                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `RuleId` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Action::Block`
[INFO] [stdout]    --> src/artifact/inspect.rs:558:65
[INFO] [stdout]     |
[INFO] [stdout] 558 | /// violation detail strings. High severity, which derives to [`Action::Block`]
[INFO] [stdout]     |                                                                 ^^^^^^^^^^^^^ no item named `Action` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ingest_bytes`
[INFO] [stdout]    --> src/artifact/quarantine.rs:627:66
[INFO] [stdout]     |
[INFO] [stdout] 627 |     /// re-hashes before publishing, identical verification to [`ingest_bytes`].
[INFO] [stdout]     |                                                                  ^^^^^^^^^^^^ no item named `ingest_bytes` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `gc_unreferenced_blobs`
[INFO] [stdout]    --> src/artifact/quarantine.rs:729:40
[INFO] [stdout]     |
[INFO] [stdout] 729 |     /// Blobs are GC'd separately by [`gc_unreferenced_blobs`].
[INFO] [stdout]     |                                        ^^^^^^^^^^^^^^^^^^^^^ no item named `gc_unreferenced_blobs` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `materialize_blob`
[INFO] [stdout]     --> src/artifact/quarantine.rs:1094:42
[INFO] [stdout]      |
[INFO] [stdout] 1094 | /// Materialise artifacts into it with [`materialize_blob`]; the lease is released
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^ no item named `materialize_blob` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineStore::ingest_file`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           into the quarantine (D1's [`QuarantineStore::ingest_file`]), so the bytes that
[INFO] [stdout]                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineStore` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ResolverAllowances`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              future policy ([`ResolverAllowances`]) opts in. `uv pip compile --no-build`
[INFO] [stdout]                              ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ResolverAllowances` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `validate_requirement`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              own step); [`validate_requirement`] rejects the `-e` / `git+` / `file:` /
[INFO] [stdout]                          ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `validate_requirement` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `isolated_env`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              a scrubbed environment ([`isolated_env`]) that points every pip/uv config
[INFO] [stdout]                                       ^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `isolated_env` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `validate_index_url`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           6. **Credentials in an index URL refused.** [`validate_index_url`] rejects a
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `validate_index_url` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `resolve_tool`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              [`resolve_tool`] uses [`crate::trusted_child`] to canonicalize, reject
[INFO] [stdout]               ^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `resolve_tool` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ResolvedSet`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`ResolvedSet`], RE-MATERIALISES each approved blob into the install
[INFO] [stdout]            ^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ResolvedSet` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineTransaction::materialize_blob`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           pre-flight stat: [`QuarantineTransaction::materialize_blob`] streams the blob
[INFO] [stdout]                             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineTransaction` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineError::DigestMismatch`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`QuarantineError::DigestMismatch`] / [`QuarantineError::BlobNotFound`], which
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineError` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineError::BlobNotFound`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`QuarantineError::DigestMismatch`] / [`QuarantineError::BlobNotFound`], which
[INFO] [stdout]                                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineError` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `rebind_for_install`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              time. Right before the install runs, [`rebind_for_install`] reloads the
[INFO] [stdout]                                                    ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `rebind_for_install` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `approved_requirements_text`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           2. **Generate `approved.txt`.** [`approved_requirements_text`] emits one local,
[INFO] [stdout]                                            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `approved_requirements_text` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InstallCommand::pip_install_args`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           3. **The pip argv.** [`InstallCommand::pip_install_args`] is exactly the plan's
[INFO] [stdout]                                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `InstallCommand` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `build_install_spec`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           4. **The capsule spec.** [`build_install_spec`] is a locked-down, **deny-all
[INFO] [stdout]                                     ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `build_install_spec` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleSpec`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              network** [`CapsuleSpec`]: the install needs no outbound traffic once the
[INFO] [stdout]                         ^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `CapsuleSpec` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `rebind_for_install`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           post-extraction)". D4 owns the FIRST half: [`rebind_for_install`] guarantees the
[INFO] [stdout]                                                       ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `rebind_for_install` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_post_install_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`verify_post_install_record`] is that second half. Once the contained pip
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_post_install_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_installed_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           tree). [`verify_installed_record`] already flags both
[INFO] [stdout]                   ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_installed_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleSpec`
[INFO] [stdout]    --> src/artifact/install.rs:316:7
[INFO] [stdout]     |
[INFO] [stdout] 316 | /// [`CapsuleSpec`] is locked-down deny-all.
[INFO] [stdout]     |       ^^^^^^^^^^^ no item named `CapsuleSpec` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_installed_distributions` links to private item `post_install_site_packages`
[INFO] [stdout]    --> src/artifact/install.rs:894:58
[INFO] [stdout]     |
[INFO] [stdout] 894 | /// one's `(dist_info_dir, identity)`. Reuses the SAME [`post_install_site_packages`]
[INFO] [stdout]     |                                                          ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `locate_installed_dist_info`
[INFO] [stdout]    --> src/artifact/install.rs:897:35
[INFO] [stdout]     |
[INFO] [stdout] 897 | /// .dist-info` in each. Unlike [`locate_installed_dist_info`], this is name-agnostic:
[INFO] [stdout]     |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `locate_installed_dist_info` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::PureToNative`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * ships a compiled extension where there was none ([`ReleaseAnomalyKind::PureToNative`]),
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::StartupHookAdded`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`ReleaseAnomalyKind::StartupHookAdded`]),
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::JavaScriptVolumeJump`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`ReleaseAnomalyKind::JavaScriptVolumeJump`]),
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::IdentityChanged`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * changes the distribution IDENTITY it claims ([`ReleaseAnomalyKind::IdentityChanged`]),
[INFO] [stdout]                                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::NewExecutionCapability`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             did not have ([`ReleaseAnomalyKind::NewExecutionCapability`]).
[INFO] [stdout]                            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize_project_name_public` links to private item `archive::normalize_project_name`
[INFO] [stdout]    --> src/artifact/mod.rs:718:7
[INFO] [stdout]     |
[INFO] [stdout] 718 | /// [`archive::normalize_project_name`] so the normalization stays single-sourced.
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `prev_hash` links to private item `append_to_audit_log`
[INFO] [stdout]   --> src/audit.rs:98:11
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// [`append_to_audit_log`], never by the constructors.
[INFO] [stdout]    |           ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `read_last_line`
[INFO] [stdout]     --> src/audit.rs:1044:15
[INFO] [stdout]      |
[INFO] [stdout] 1044 | /// Same as [`read_last_line`] on an already-open handle. Persist holds an
[INFO] [stdout]      |               ^^^^^^^^^^^^^^ no item named `read_last_line` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `count_lines`
[INFO] [stdout]     --> src/audit.rs:1108:15
[INFO] [stdout]      |
[INFO] [stdout] 1108 | /// Same as [`count_lines`] on an already-open handle. Persist holds an
[INFO] [stdout]      |               ^^^^^^^^^^^ no item named `count_lines` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `audit_signing_available` links to private item `sign_canonical`
[INFO] [stdout]     --> src/audit.rs:1479:34
[INFO] [stdout]      |
[INFO] [stdout] 1479 | /// key, exactly like a single [`sign_canonical`] attempt would.
[INFO] [stdout]      |                                  ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `BufReader`
[INFO] [stdout]    --> src/audit_aggregator.rs:125:7
[INFO] [stdout]     |
[INFO] [stdout] 125 | /// [`BufReader`] so a large append-only log is never fully buffered. Result and
[INFO] [stdout]     |       ^^^^^^^^^ no item named `BufReader` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `export_csv` links to private item `csv_neutralize_formula`
[INFO] [stdout]    --> src/audit_aggregator.rs:580:42
[INFO] [stdout]     |
[INFO] [stdout] 580 | /// LibreOffice evaluate as a formula. [`csv_neutralize_formula`] tab-prefixes
[INFO] [stdout]     |                                          ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `export_csv` links to private item `csv_escape`
[INFO] [stdout]    --> src/audit_aggregator.rs:581:48
[INFO] [stdout]     |
[INFO] [stdout] 581 | /// such cells (the OWASP mitigation) before [`csv_escape`].
[INFO] [stdout]     |                                                ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AgentOrigin`
[INFO] [stdout]    --> src/audit_aggregator.rs:609:17
[INFO] [stdout]     |
[INFO] [stdout] 609 | /// Render an [`AgentOrigin`] for the CSV cell as `kind:payload` (so dashboards
[INFO] [stdout]     |                 ^^^^^^^^^^^ no item named `AgentOrigin` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_at` links to private item `crate::canary::StoreLock`
[INFO] [stdout]    --> src/baseline.rs:576:14
[INFO] [stdout]     |
[INFO] [stdout] 576 | /// shared [`crate::canary::StoreLock`] for the whole sequence — without it, a
[INFO] [stdout]     |              ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `browser_extensions` links to private item `read_install_classes`
[INFO] [stdout]   --> src/browser_extensions.rs:22:37
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!   there and nowhere else; see [`read_install_classes`] for why nothing else
[INFO] [stdout]    |                                     ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `browser_extensions` links to private item `read_install_classes`
[INFO] [stdout]   --> src/browser_extensions.rs:38:9
[INFO] [stdout]    |
[INFO] [stdout] 38 | //!   [`read_install_classes`]; no `serde_json::Value` from that file crosses its
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `SurfaceHashChanged` links to private item `compare_entry`
[INFO] [stdout]     --> src/browser_extensions.rs:3713:11
[INFO] [stdout]      |
[INFO] [stdout] 3713 |     /// [`compare_entry`]. It exists so that omission is a reported drift rather
[INFO] [stdout]      |           ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `fill_fallback_bytes`
[INFO] [stdout]    --> src/canary.rs:159:46
[INFO] [stdout]     |
[INFO] [stdout] 159 | /// per-call-VARYING pseudo-random suffix ([`fill_fallback_bytes`]) so generation
[INFO] [stdout]     |                                              ^^^^^^^^^^^^^^^^^^^ no item named `fill_fallback_bytes` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleCoverage::is_degraded`
[INFO] [stdout]   --> src/capsule/mod.rs:30:7
[INFO] [stdout]    |
[INFO] [stdout] 30 | //! [`CapsuleCoverage::is_degraded`] / the specific flags and **fails closed**
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ the struct `CapsuleCoverage` has no field or associated item named `is_degraded`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `LandlockSeccompCapsule`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`LandlockSeccompCapsule`] backend (which probes the running kernel and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `LandlockSeccompCapsule` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           reports honest [`CapsuleCoverage`]) and the [`apply_containment`] primitive
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           single-threaded, deserializes the [`CapsuleSpec`], calls [`apply_containment`],
[INFO] [stdout]                                                                     ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`apply_containment`] applies, in this exact order:
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `LandlockSeccompCapsule::available_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`LandlockSeccompCapsule::available_coverage`] probes for Landlock support and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `LandlockSeccompCapsule` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerCapsule`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           capsule: the [`AppContainerCapsule`] backend (which probes for AppContainer
[INFO] [stdout]                         ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerCapsule` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerProfile`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`AppContainerProfile`]), the Job Object resource ceilings
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerProfile` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `JobObjectLimits`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`JobObjectLimits`]), the ACL grant list ([`AclGrant`]), and the assembled
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `JobObjectLimits` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AclGrant`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`JobObjectLimits`]), the ACL grant list ([`AclGrant`]), and the assembled
[INFO] [stdout]                                                       ^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AclGrant` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `WindowsLaunchPlan`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`WindowsLaunchPlan`]. The `windows`-crate Win32 calls that *apply* the plan
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `WindowsLaunchPlan` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `derive_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           the Windows CI runner), and the honesty contract ([`derive_coverage`]) is
[INFO] [stdout]                                                              ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `derive_coverage` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `acl_grants`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`acl_grants`]) and grants nothing else. Before producing any ACE, the shared
[INFO] [stdout]               ^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `acl_grants` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `job_object_limits`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             process-count / open-files ceilings ([`job_object_limits`]). The child is
[INFO] [stdout]                                                   ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `job_object_limits` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerCapsule::available_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AppContainerCapsule::available_coverage`] probes for AppContainer support and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerCapsule` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NetworkPolicy`
[INFO] [stdout]    --> src/capsule/windows.rs:318:63
[INFO] [stdout]     |
[INFO] [stdout] 318 | /// capability list is empty in E4 regardless of the spec's [`NetworkPolicy`] (a
[INFO] [stdout]     |                                                               ^^^^^^^^^^^^^ no item named `NetworkPolicy` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/capsule/windows.rs:653:21
[INFO] [stdout]     |
[INFO] [stdout] 653 | /// program as argv[0]; `CreateProcessW` resolves the executable separately from
[INFO] [stdout]     |                     ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `MAX_DIFF_PATH_CHARS`
[INFO] [stdout]    --> src/capsule_project.rs:316:24
[INFO] [stdout]     |
[INFO] [stdout] 316 |     /// shortened to [`MAX_DIFF_PATH_CHARS`], so the diff is a sample.
[INFO] [stdout]     |                        ^^^^^^^^^^^^^^^^^^^ no item named `MAX_DIFF_PATH_CHARS` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `capsule_receipt` links to private item `crate::audit::log_capsule_run_receipt`
[INFO] [stdout]   --> src/capsule_receipt.rs:11:20
[INFO] [stdout]    |
[INFO] [stdout] 11 | //! entry point ([`crate::audit::log_capsule_run_receipt`]) is `pub(crate)`. A
[INFO] [stdout]    |                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `command_matches` links to private item `is_shell_significant_ws`
[INFO] [stdout]    --> src/command_card.rs:789:50
[INFO] [stdout]     |
[INFO] [stdout] 789 |     /// only shell-significant whitespace (see [`is_shell_significant_ws`])? NOT
[INFO] [stdout]     |                                                  ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Action::Block`
[INFO] [stdout]   --> src/commands_manifest.rs:11:20
[INFO] [stdout]    |
[INFO] [stdout] 11 | //!    → High (→ [`Action::Block`]), `action: warn` → Medium (→ Warn).
[INFO] [stdout]    |                    ^^^^^^^^^^^^^ no item named `Action` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `evaluate`
[INFO] [stdout]   --> src/commands_manifest.rs:18:48
[INFO] [stdout]    |
[INFO] [stdout] 18 | //! This is STRUCTURAL, not a runtime check: [`evaluate`] is handed an immutable
[INFO] [stdout]    |                                                ^^^^^^^^ no item named `evaluate` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `commands_manifest` links to private item `crate::command_card::is_shell_significant_ws`
[INFO] [stdout]   --> src/commands_manifest.rs:29:7
[INFO] [stdout]    |
[INFO] [stdout] 29 | //! [`crate::command_card::is_shell_significant_ws`]).
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_from_path` links to private item `MANIFEST_READ_CAP`
[INFO] [stdout]    --> src/commands_manifest.rs:225:43
[INFO] [stdout]     |
[INFO] [stdout] 225 |     /// (`O_NONBLOCK`, fstat, capped at [`MANIFEST_READ_CAP`]) instead of a plain
[INFO] [stdout]     |                                           ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `glob_match`
[INFO] [stdout]    --> src/commands_manifest.rs:623:7
[INFO] [stdout]     |
[INFO] [stdout] 623 | /// [`glob_match`] with the text already decoded (repo-0263: the hot path
[INFO] [stdout]     |       ^^^^^^^^^^ no item named `glob_match` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `context_detect` links to private item `run_with_timeout`
[INFO] [stdout]   --> src/context_detect.rs:12:43
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! Every external command goes through [`run_with_timeout`], which drains stdout
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `Timeout` links to private item `SHELL_OUT_TIMEOUT`
[INFO] [stdout]   --> src/context_detect.rs:98:34
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// The shell-out exceeded [`SHELL_OUT_TIMEOUT`]. The child was killed.
[INFO] [stdout]    |                                  ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `DeserializeSeed`
[INFO] [stdout]    --> src/custom_rule_dsl.rs:156:9
[INFO] [stdout]     |
[INFO] [stdout] 156 | /// A [`DeserializeSeed`] threading the nesting depth through the recursive
[INFO] [stdout]     |         ^^^^^^^^^^^^^^^ no item named `DeserializeSeed` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `build_dsl_backing`
[INFO] [stdout]    --> src/custom_rule_dsl.rs:368:42
[INFO] [stdout]     |
[INFO] [stdout] 368 | /// fact it references is populated by [`build_dsl_backing`] for that context.
[INFO] [stdout]     |                                          ^^^^^^^^^^^^^^^^^ no item named `build_dsl_backing` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `top_findings` links to private item `TOP_N`
[INFO] [stdout]   --> src/dashboard.rs:73:62
[INFO] [stdout]    |
[INFO] [stdout] 73 |     /// Top rule IDs by occurrence (descending), capped at [`TOP_N`].
[INFO] [stdout]    |                                                              ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `top_hosts` links to private item `TOP_N`
[INFO] [stdout]   --> src/dashboard.rs:75:59
[INFO] [stdout]    |
[INFO] [stdout] 75 |     /// Top hosts by occurrence (descending), capped at [`TOP_N`]. Best-effort,
[INFO] [stdout]    |                                                           ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Valid`
[INFO] [stdout]   --> src/dashboard.rs:84:38
[INFO] [stdout]    |
[INFO] [stdout] 84 | /// into [`PolicySummary::NoFile`]/[`Valid`] so `--json` carries them at the same
[INFO] [stdout]    |                                      ^^^^^ no item named `Valid` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `generate_serve_token` links to private item `SERVE_TOKEN_BYTES`
[INFO] [stdout]    --> src/dashboard.rs:527:66
[INFO] [stdout]     |
[INFO] [stdout] 527 | /// Generate a fresh ephemeral `tirith dashboard serve` token: [`SERVE_TOKEN_BYTES`]
[INFO] [stdout]     |                                                                  ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `deobfuscate` links to private item `crate::extract::strip_invisible`
[INFO] [stdout]   --> src/deobfuscate.rs:17:43
[INFO] [stdout]    |
[INFO] [stdout] 17 | //! Note: the invisible-strip step (via [`crate::extract::strip_invisible`]) drops
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `base64_truncated` links to private item `MAX_BASE64_VALIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:105:55
[INFO] [stdout]     |
[INFO] [stdout] 105 |     /// run exceeded the bounded validation window ([`MAX_BASE64_VALIDATE_LEN`]),
[INFO] [stdout]     |                                                       ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_encoded_blob` links to private item `MIN_BASE64_CANDIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:748:16
[INFO] [stdout]     |
[INFO] [stdout] 748 | /// at least [`MIN_BASE64_CANDIDATE_LEN`] chars OR a contiguous hex run whose
[INFO] [stdout]     |                ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_encoded_blob` links to private item `MIN_HEX_CANDIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:749:38
[INFO] [stdout]     |
[INFO] [stdout] 749 | /// even-length prefix is at least [`MIN_HEX_CANDIDATE_LEN`]. Used by the engine's
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `collapse_spaced_chars`
[INFO] [stdout]    --> src/deobfuscate.rs:779:38
[INFO] [stdout]     |
[INFO] [stdout] 779 | ///   one ASCII space (mirrors the [`collapse_spaced_chars`] trigger, via the shared
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `probe_spaced_run`
[INFO] [stdout]    --> src/deobfuscate.rs:780:9
[INFO] [stdout]     |
[INFO] [stdout] 780 | ///   [`probe_spaced_run`] helper);
[INFO] [stdout]     |         ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `leet_fold`
[INFO] [stdout]    --> src/deobfuscate.rs:784:7
[INFO] [stdout]     |
[INFO] [stdout] 784 | /// [`leet_fold`] substitutes those chars UNCONDITIONALLY: an earlier
[INFO] [stdout]     |       ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalized_forms_with_status` links to private item `recover_printable_text`
[INFO] [stdout]    --> src/deobfuscate.rs:845:48
[INFO] [stdout]     |
[INFO] [stdout] 845 | ///   yields recoverable printable text (via [`recover_printable_text`]), each with
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalized_forms_with_status` links to private item `DecodeBudget`
[INFO] [stdout]    --> src/deobfuscate.rs:857:67
[INFO] [stdout]     |
[INFO] [stdout] 857 | /// cumulative decoded bytes, per-run bytes, emitted forms; see [`DecodeBudget`]);
[INFO] [stdout]     |                                                                   ^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_manifests` links to private item `SKIP_DIRS`
[INFO] [stdout]    --> src/ecosystem_scan.rs:272:52
[INFO] [stdout]     |
[INFO] [stdout] 272 | /// [`MAX_WALK_DEPTH`] and [`MAX_WALK_ENTRIES`]. [`SKIP_DIRS`] are not
[INFO] [stdout]     |                                                    ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `npm_lock_integrity_index` links to private item `parse_package_lock`
[INFO] [stdout]    --> src/ecosystem_scan.rs:649:21
[INFO] [stdout]     |
[INFO] [stdout] 649 | /// Separate from [`parse_package_lock`] on purpose: that function answers "what
[INFO] [stdout]     |                     ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `slopsquat` links to private item `hallucinated_name_shape`
[INFO] [stdout]     --> src/ecosystem_scan.rs:1704:42
[INFO] [stdout]      |
[INFO] [stdout] 1704 | /// 2. AI-hallucinated name shape (see [`hallucinated_name_shape`]).
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `InstalledIntegrityReport` links to private item `InstalledIntegrityReport::correlated_findings`
[INFO] [stdout]     --> src/ecosystem_scan.rs:3365:7
[INFO] [stdout]      |
[INFO] [stdout] 3365 | /// [`InstalledIntegrityReport::correlated_findings`]. Serialized onto
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `native_findings` links to private item `InstalledIntegrityReport::native_correlated_findings`
[INFO] [stdout]     --> src/ecosystem_scan.rs:3421:11
[INFO] [stdout]      |
[INFO] [stdout] 3421 |     /// [`InstalledIntegrityReport::native_correlated_findings`].
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `custom_seeds` links to private item `OutputAnalyzerState::extra_injection_seeds`
[INFO] [stdout]    --> src/engine.rs:657:25
[INFO] [stdout]     |
[INFO] [stdout] 657 |     /// threaded into [`OutputAnalyzerState::extra_injection_seeds`] so the
[INFO] [stdout]     |                         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_exec_provenance_hot`
[INFO] [stdout]     --> src/engine.rs:2541:35
[INFO] [stdout]      |
[INFO] [stdout] 2541 | ///   `libc::access(W_OK)`; see [`check_exec_provenance_hot`]). The OTHER SEVEN
[INFO] [stdout]      |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_taint_hot`
[INFO] [stdout]     --> src/engine.rs:2557:20
[INFO] [stdout]      |
[INFO] [stdout] 2557 | ///   non-empty: [`check_taint_hot`] fires `ExecOfTaintedFile` /
[INFO] [stdout]      |                    ^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `apply_baseline`
[INFO] [stdout]     --> src/engine.rs:2559:46
[INFO] [stdout]      |
[INFO] [stdout] 2559 | /// * **M10 ch5 — baseline.** Opt-in (D2): [`apply_baseline`] runs post-tier-3,
[INFO] [stdout]      |                                              ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_command_card_hot`
[INFO] [stdout]     --> src/engine.rs:2563:42
[INFO] [stdout]      |
[INFO] [stdout] 2563 | /// * **M11 — cards/manifest/canary.** [`check_command_card_hot`] (ATTESTATION-
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_command_manifest_hot`
[INFO] [stdout]     --> src/engine.rs:2564:57
[INFO] [stdout]      |
[INFO] [stdout] 2564 | ///   ONLY — never changes another finding's action), [`check_command_manifest_hot`]
[INFO] [stdout]      |                                                         ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_canary_hot`
[INFO] [stdout]     --> src/engine.rs:2566:42
[INFO] [stdout]      |
[INFO] [stdout] 2566 | ///   never weaken an engine finding), [`check_canary_hot`] (Exec+Paste+output).
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `explain_var` links to private item `mask_assignment`
[INFO] [stdout]    --> src/env_guard.rs:645:48
[INFO] [stdout]     |
[INFO] [stdout] 645 | /// **The value is never read or printed** — [`mask_assignment`] replaces it
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `DELETE_COUNT_KEY` links to private item `mass_file_deletion`
[INFO] [stdout]    --> src/event_buffer.rs:725:56
[INFO] [stdout]     |
[INFO] [stdout] 725 | /// one delete command targeted (`rm a b c` -> "3"). [`mass_file_deletion`] sums
[INFO] [stdout]     |                                                        ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NON_BUILD_DELETE_COUNT_KEY` links to private item `mass_file_deletion`
[INFO] [stdout]    --> src/event_buffer.rs:733:68
[INFO] [stdout]     |
[INFO] [stdout] 733 | /// path with `crate::util_build_dirs::is_build_artifact_path`). [`mass_file_deletion`]
[INFO] [stdout]     |                                                                    ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NON_BUILD_DELETE_COUNT_KEY` links to private item `TypedEvent::non_build_delete_count`
[INFO] [stdout]    --> src/event_buffer.rs:738:22
[INFO] [stdout]     |
[INFO] [stdout] 738 | /// heuristic; see [`TypedEvent::non_build_delete_count`].
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `iac_plan` links to private item `run_terraform_show_json`
[INFO] [stdout]   --> src/iac_plan.rs:17:7
[INFO] [stdout]    |
[INFO] [stdout] 17 | //! [`run_terraform_show_json`] — the engine hot path consults
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ShellTimeoutOutcome::OutputLimitExceeded`
[INFO] [stdout]    --> src/iac_plan.rs:496:32
[INFO] [stdout]     |
[INFO] [stdout] 496 | /// [`MAX_PLAN_SIZE_BYTES`] ([`ShellTimeoutOutcome::OutputLimitExceeded`]), and the
[INFO] [stdout]     |                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `ShellTimeoutOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `MAX_REASON_BYTES` links to private item `FLAG_READ_CAP`
[INFO] [stdout]   --> src/incident.rs:95:7
[INFO] [stdout]    |
[INFO] [stdout] 95 | /// [`FLAG_READ_CAP`] guarantees a flag written by [`start_at`] always reads back
[INFO] [stdout]    |       ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `now` links to private item `current_user`
[INFO] [stdout]    --> src/incident.rs:115:64
[INFO] [stdout]     |
[INFO] [stdout] 115 |     /// (`reason` via [`MAX_REASON_BYTES`], `started_by` via [`current_user`]) so
[INFO] [stdout]     |                                                                ^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `now` links to private item `FLAG_READ_CAP`
[INFO] [stdout]    --> src/incident.rs:116:48
[INFO] [stdout]     |
[INFO] [stdout] 116 |     /// the serialized body can never exceed [`FLAG_READ_CAP`] — a flag written by
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `read_flag_at` links to private item `FLAG_READ_CAP`
[INFO] [stdout]    --> src/incident.rs:225:46
[INFO] [stdout]     |
[INFO] [stdout] 225 | /// rejects non-regular files, and caps at [`FLAG_READ_CAP`]. Mapping is fail-SAFE:
[INFO] [stdout]     |                                              ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `1`
[INFO] [stdout]   --> src/install_txn.rs:54:53
[INFO] [stdout]    |
[INFO] [stdout] 54 |     /// `pacman -S <pkg...>` — Arch / Manjaro. argv[1] is `-S` (Sync), encoded
[INFO] [stdout]    |                                                     ^ no item named `1` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]   --> src/install_txn.rs:69:42
[INFO] [stdout]    |
[INFO] [stdout] 69 |     /// The program name to invoke (argv[0]). One variant ↔ one program; `Apt`
[INFO] [stdout]    |                                          ^ no item named `0` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/install_txn.rs:160:14
[INFO] [stdout]     |
[INFO] [stdout] 160 |     /// argv[0] — the package-manager program.
[INFO] [stdout]     |              ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/install_txn.rs:834:64
[INFO] [stdout]     |
[INFO] [stdout] 834 | /// Build the real install argv: install subcommand after argv[0], then the
[INFO] [stdout]     |                                                                ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `IntentClass` links to private item `IntentClass::justifies`
[INFO] [stdout]    --> src/intent.rs:133:21
[INFO] [stdout]     |
[INFO] [stdout] 133 | /// justifies via [`IntentClass::justifies`].
[INFO] [stdout]     |                     ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `classify_intent` links to private item `IntentClass::ALL`
[INFO] [stdout]    --> src/intent.rs:352:7
[INFO] [stdout]     |
[INFO] [stdout] 352 | /// [`IntentClass::ALL`] order (first matching keyword per class).
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ToolCallResult`
[INFO] [stdout]   --> src/mcp/content.rs:15:60
[INFO] [stdout]    |
[INFO] [stdout] 15 | //! [`crate::mcp::output_filter`] over the round-tripped [`ToolCallResult`].
[INFO] [stdout]    |                                                            ^^^^^^^^^^^^^^ no item named `ToolCallResult` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `filter_tool_result` links to private item `should_downgrade_injection_block`
[INFO] [stdout]    --> src/mcp/output_filter.rs:545:7
[INFO] [stdout]     |
[INFO] [stdout] 545 | /// [`should_downgrade_injection_block`] for the exact gate. With the flag off
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `sanitize_text_into` links to private item `TerminalSanitizer`
[INFO] [stdout]     --> src/mcp/output_filter.rs:2068:41
[INFO] [stdout]      |
[INFO] [stdout] 2068 | /// callers; multi-leaf MCP paths use [`TerminalSanitizer`] directly.
[INFO] [stdout]      |                                         ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `Url` links to private item `redact_url_userinfo`
[INFO] [stdout]    --> src/mcp_lock.rs:188:37
[INFO] [stdout]     |
[INFO] [stdout] 188 |     /// verbatim with `None`. See [`redact_url_userinfo`].
[INFO] [stdout]     |                                     ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `content_hash` links to private item `hash_field`
[INFO] [stdout]    --> src/mcp_lock.rs:329:31
[INFO] [stdout]     |
[INFO] [stdout] 329 |     /// length-prefixed via [`hash_field`], not `\0`-joined — so `["a","b"]` and
[INFO] [stdout]     |                               ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_descriptor_hash` links to private item `hash_field`
[INFO] [stdout]    --> src/mcp_lock.rs:766:36
[INFO] [stdout]     |
[INFO] [stdout] 766 | /// Length-prefixed framing (via [`hash_field`]) so no two distinct lists collide.
[INFO] [stdout]     |                                    ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_descriptor_drift` links to private item `McpDescriptorChange::sort_key`
[INFO] [stdout]    --> src/mcp_lock.rs:872:7
[INFO] [stdout]     |
[INFO] [stdout] 872 | /// [`McpDescriptorChange::sort_key`].
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_mcp_configs` links to private item `discover_mcp_configs_full`
[INFO] [stdout]     --> src/mcp_lock.rs:1772:7
[INFO] [stdout]      |
[INFO] [stdout] 1772 | /// [`discover_mcp_configs_full`] for it.
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `build_inventory` links to private item `discover_mcp_configs_full`
[INFO] [stdout]     --> src/mcp_lock.rs:1919:35
[INFO] [stdout]      |
[INFO] [stdout] 1919 | /// Path-level rejections (from [`discover_mcp_configs_full`]) and file-level ones
[INFO] [stdout]      |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `McpServerDrift::env_changes`
[INFO] [stdout]     --> src/mcp_lock.rs:2900:11
[INFO] [stdout]      |
[INFO] [stdout] 2900 |     /// [`McpServerDrift::env_changes`].
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `McpServerDrift` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_drift` links to private item `McpDrift::sort_key`
[INFO] [stdout]     --> src/mcp_lock.rs:3046:29
[INFO] [stdout]      |
[INFO] [stdout] 3046 | /// The result is sorted ([`McpDrift::sort_key`]). Privacy: entries carry only
[INFO] [stdout]      |                             ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `resolve_shortened_url` links to private item `MAX_REDIRECTS`
[INFO] [stdout]   --> src/network/shorturl.rs:30:67
[INFO] [stdout]    |
[INFO] [stdout] 30 | /// `None` for a non-shortener, a network failure, a chain over [`MAX_REDIRECTS`],
[INFO] [stdout]    |                                                                   ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `resolve_shortened_url` links to private item `CACHE_TTL`
[INFO] [stdout]   --> src/network/shorturl.rs:32:30
[INFO] [stdout]    |
[INFO] [stdout] 32 | /// Results are cached for [`CACHE_TTL`].
[INFO] [stdout]    |                              ^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `from_basename` links to private item `launcher_basename`
[INFO] [stdout]   --> src/npm_command.rs:77:11
[INFO] [stdout]    |
[INFO] [stdout] 77 |     /// [`launcher_basename`] for that.
[INFO] [stdout]    |           ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `safe_suggestions` links to private item `redact_suggestion`
[INFO] [stdout]    --> src/output.rs:187:36
[INFO] [stdout]     |
[INFO] [stdout] 187 |     /// cross that contract. See [`redact_suggestion`].
[INFO] [stdout]     |                                    ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::registry_history::synthesize_transfer`
[INFO] [stdout]    --> src/package_risk.rs:241:20
[INFO] [stdout]     |
[INFO] [stdout] 241 |     /// lives in [`crate::registry_history::synthesize_transfer`], which sees the
[INFO] [stdout]     |                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `synthesize_transfer` in module `registry_history`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::registry_api::is_usable_repo_url`
[INFO] [stdout]    --> src/package_risk.rs:463:11
[INFO] [stdout]     |
[INFO] [stdout] 463 |     /// [`crate::registry_api::is_usable_repo_url`]).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `is_usable_repo_url` in module `registry_api`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `PolicyScope` links to private item `Policy::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:215:27
[INFO] [stdout]     |
[INFO] [stdout] 215 | /// tightening-only via [`Policy::sanitize_repo_scoped`]. Org/User/Remote/Default
[INFO] [stdout]     |                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `scope` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:297:11
[INFO] [stdout]     |
[INFO] [stdout] 297 |     /// [`Self::sanitize_repo_scoped`] (repo policies may only tighten).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `injection_seeds_custom` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:375:22
[INFO] [stdout]     |
[INFO] [stdout] 375 |     /// is KEPT by [`Self::sanitize_repo_scoped`] — never reset. Bad regexes are
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `mcp_redact_injection` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:396:47
[INFO] [stdout]     |
[INFO] [stdout] 396 |     /// default block), so this is RESET by [`Self::sanitize_repo_scoped`] — only
[INFO] [stdout]     |                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gateway_profile` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:558:19
[INFO] [stdout]     |
[INFO] [stdout] 558 |     /// KEPT by [`Self::sanitize_repo_scoped`] — a repo may opt in but can never
[INFO] [stdout]     |                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralized_fields` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:565:19
[INFO] [stdout]     |
[INFO] [stdout] 565 |     /// scoped, [`Self::sanitize_repo_scoped`] records here the YAML key name of
[INFO] [stdout]     |                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `require_complete` links to private item `Policy::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:1127:30
[INFO] [stdout]      |
[INFO] [stdout] 1127 |     /// it and it survives [`Policy::sanitize_repo_scoped`]. Default false.
[INFO] [stdout]      |                              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Self::discover_local_only`
[INFO] [stdout]     --> src/policy.rs:1313:7
[INFO] [stdout]      |
[INFO] [stdout] 1313 | /// [`Self::discover_local_only`] and, when it is `Some(Secure)`, fills any
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^ the enum `GatewayProfile` has no variant or associated item named `discover_local_only`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:1320:7
[INFO] [stdout]      |
[INFO] [stdout] 1320 | /// [`Self::sanitize_repo_scoped`] — a repo may opt INTO the secure profile but
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^^ the enum `GatewayProfile` has no variant or associated item named `sanitize_repo_scoped`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_local_only` links to private item `Self::discover_local`
[INFO] [stdout]     --> src/policy.rs:1653:12
[INFO] [stdout]      |
[INFO] [stdout] 1653 |     /// ([`Self::discover_local`]) + the incident override merge, but
[INFO] [stdout]      |            ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_trust_entries` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:2929:30
[INFO] [stdout]      |
[INFO] [stdout] 2929 |     /// `allowlist` field ([`Self::sanitize_repo_scoped`]) and the repo flat-
[INFO] [stdout]      |                              ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_org_lists` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:3029:11
[INFO] [stdout]      |
[INFO] [stdout] 3029 |     /// [`Self::sanitize_repo_scoped`]: the repo **blocklist** (a restriction) is
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `util::read_text_no_follow_capped`
[INFO] [stdout]     --> src/policy.rs:3668:23
[INFO] [stdout]      |
[INFO] [stdout] 3668 | /// F17 — reads via [`util::read_text_no_follow_capped`] so a symlinked label
[INFO] [stdout]      |                       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `util` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AttestationOutcome`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AttestationOutcome`] encodes exactly this: every non-`Verified` variant is a
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AttestationOutcome` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `bind_subject_digest`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           bundle's in-toto statement names a SUBJECT digest. [`bind_subject_digest`]
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `bind_subject_digest` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PublisherPolicy`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`PublisherPolicy`]): an unexpected repository or workflow is a
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `PublisherPolicy` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AttestationOutcome::PublisherNotAllowed`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AttestationOutcome::PublisherNotAllowed`]. An EMPTY allowlist means "no
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AttestationOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              dependency decision outside this slice. [`NpmVerificationState`]
[INFO] [stdout]                                                       ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState::PresentUnverified`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              therefore tops out at [`NpmVerificationState::PresentUnverified`] for a
[INFO] [stdout]                                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState::VerificationUnavailable`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              [`NpmVerificationState::VerificationUnavailable`] is the honest terminal
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NPM_AUDIT_SIGNATURES_CONTRACTS`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           So [`NPM_AUDIT_SIGNATURES_CONTRACTS`] is a fixed table: a version RANGE, the
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NPM_AUDIT_SIGNATURES_CONTRACTS` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmPartialReason::UnsupportedNpmVersion`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           outside every range returns [`NpmPartialReason::UnsupportedNpmVersion`]
[INFO] [stdout]                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmPartialReason` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NPM_CLEAN_IS_NOT_BENIGN_CAVEAT`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`NPM_CLEAN_IS_NOT_BENIGN_CAVEAT`] is part of the output, not decoration.
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NPM_CLEAN_IS_NOT_BENIGN_CAVEAT` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `bind_attested_subject`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`bind_attested_subject`] compares the sha512 subject digest inside an
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `bind_attested_subject` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmPackageStatus::Invalid`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           will install. That is the [`NpmPackageStatus::Invalid`] case that forces an
[INFO] [stdout]                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmPackageStatus` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `parse_npm_version` links to private item `MAX_VERSION_TEXT_BYTES`
[INFO] [stdout]    --> src/provenance/npm.rs:197:7
[INFO] [stdout]     |
[INFO] [stdout] 197 | /// [`MAX_VERSION_TEXT_BYTES`], or a first line that is not a plain numeric
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `capped` links to private item `MAX_TREE_DIRECTORIES`
[INFO] [stdout]    --> src/provenance/npm.rs:950:62
[INFO] [stdout]     |
[INFO] [stdout] 950 |     /// True when the walk hit [`MAX_INSTALLED_PACKAGES`], [`MAX_TREE_DIRECTORIES`],
[INFO] [stdout]     |                                                              ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `unaccounted_locations` links to private item `MAX_REPORTED_UNACCOUNTED`
[INFO] [stdout]     --> src/provenance/npm.rs:1473:21
[INFO] [stdout]      |
[INFO] [stdout] 1473 |     /// The first [`MAX_REPORTED_UNACCOUNTED`] unaccounted locations, for the
[INFO] [stdout]      |                     ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `ArtifactScanReceipt` links to private item `crate::audit::log_artifact_scan_receipt`
[INFO] [stdout]    --> src/receipt.rs:399:8
[INFO] [stdout]     |
[INFO] [stdout] 399 | /// ([`crate::audit::log_artifact_scan_receipt`]). The chain line carries the
[INFO] [stdout]     |        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `looks_secret_shaped` links to private item `SECRET_SHAPE_PATTERNS`
[INFO] [stdout]    --> src/redact.rs:387:62
[INFO] [stdout]     |
[INFO] [stdout] 387 | /// token (OpenAI / AWS / GitHub / Anthropic / Slack — see [`SECRET_SHAPE_PATTERNS`]),
[INFO] [stdout]     |                                                              ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `contains_supported_secret` links to private item `analyze_supported_secrets`
[INFO] [stdout]    --> src/redact.rs:954:47
[INFO] [stdout]     |
[INFO] [stdout] 954 | /// Security-sensitive internal callers use [`analyze_supported_secrets`] to
[INFO] [stdout]     |                                               ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `TooLarge` links to private item `MAX_RESPONSE_BYTES`
[INFO] [stdout]    --> src/registry_api.rs:116:33
[INFO] [stdout]     |
[INFO] [stdout] 116 |     /// The response exceeded [`MAX_RESPONSE_BYTES`].
[INFO] [stdout]     |                                 ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `explain_config_risks` links to private item `check_agent_instructions`
[INFO] [stdout]     --> src/rules/aifile.rs:1326:28
[INFO] [stdout]      |
[INFO] [stdout] 1326 | /// Pure parsing; reuses [`check_agent_instructions`] + the tool-use classifier
[INFO] [stdout]      |                            ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `check` links to private item `USER_AGENTS`
[INFO] [stdout]    --> src/rules/cloaking.rs:187:69
[INFO] [stdout]     |
[INFO] [stdout] 187 | /// preflight, request dispatch, and redirect follow. The ordered [`USER_AGENTS`]
[INFO] [stdout]     |                                                                     ^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `custom_rule_dsl::clause_has_tier1_invisible_predicate`
[INFO] [stdout]    --> src/rules/custom.rs:282:8
[INFO] [stdout]     |
[INFO] [stdout] 282 | /// ([`custom_rule_dsl::clause_has_tier1_invisible_predicate`]), and (c) would
[INFO] [stdout]     |        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `clause_has_tier1_invisible_predicate` in module `custom_rule_dsl`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `any_semantic_only_dsl_rules_for_context` links to private item `parse_contexts`
[INFO] [stdout]    --> src/rules/custom.rs:304:7
[INFO] [stdout]     |
[INFO] [stdout] 304 | /// [`parse_contexts`] / [`custom_rule_dsl::resolve_runtime_contexts`] keeps it in
[INFO] [stdout]     |       ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `any_semantic_only_dsl_rules`
[INFO] [stdout]    --> src/rules/custom.rs:328:22
[INFO] [stdout]     |
[INFO] [stdout] 328 | /// Consulted (via [`any_semantic_only_dsl_rules`]) to force past the fast-exit,
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `any_semantic_only_dsl_rules` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `exfil` links to private item `might_contain_exfil`
[INFO] [stdout]   --> src/rules/exfil.rs:35:26
[INFO] [stdout]    |
[INFO] [stdout] 35 | //! A cheap pre-check ([`might_contain_exfil`]) returns immediately for clean text
[INFO] [stdout]    |                          ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ScanContext::Paste`
[INFO] [stdout]   --> src/rules/paste_provenance.rs:13:45
[INFO] [stdout]    |
[INFO] [stdout] 13 | //! page. Fires from `engine::analyze` in [`ScanContext::Paste`] ONLY.
[INFO] [stdout]    |                                             ^^^^^^^^^^^^^^^^^^ no item named `ScanContext` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `CompiledSeeds` links to private item `SEEDS`
[INFO] [stdout]   --> src/rules/prompt_injection.rs:58:16
[INFO] [stdout]    |
[INFO] [stdout] 58 | /// built-in [`SEEDS`]. Produced by [`compile_seeds`] (e.g. from policy
[INFO] [stdout]    |                ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compile_seeds` links to private item `classify`
[INFO] [stdout]    --> src/rules/prompt_injection.rs:113:34
[INFO] [stdout]     |
[INFO] [stdout] 113 | /// placeholder-substitution + [`classify`] logic as the built-in corpus. Good
[INFO] [stdout]     |                                  ^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `workflow_artifacts::MAX_WORKFLOWS`
[INFO] [stdout]    --> src/scan.rs:498:15
[INFO] [stdout]     |
[INFO] [stdout] 498 | /// at most [`workflow_artifacts::MAX_WORKFLOWS`] workflows,
[INFO] [stdout]     |               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `workflow_artifacts` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `workflow_artifacts::MAX_TOTAL_WORKFLOW_BYTES`
[INFO] [stdout]    --> src/scan.rs:499:7
[INFO] [stdout]     |
[INFO] [stdout] 499 | /// [`workflow_artifacts::MAX_TOTAL_WORKFLOW_BYTES`] of aggregate YAML source, and
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `workflow_artifacts` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `workflow_artifacts::MAX_TOTAL_STEPS`
[INFO] [stdout]    --> src/scan.rs:500:7
[INFO] [stdout]     |
[INFO] [stdout] 500 | /// [`workflow_artifacts::MAX_TOTAL_STEPS`] modelled steps.
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `workflow_artifacts` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `RulePanic` links to private item `catch_panic_scanning`
[INFO] [stdout]     --> src/scan.rs:1474:20
[INFO] [stdout]      |
[INFO] [stdout] 1474 | /// panic hook + [`catch_panic_scanning`]). Retained for back-compat; the guarded
[INFO] [stdout]      |                    ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `typed_events` links to private item `MAX_TYPED_EVENTS`
[INFO] [stdout]   --> src/session_warnings.rs:75:39
[INFO] [stdout]    |
[INFO] [stdout] 75 |     /// Off the hot path; capped to [`MAX_TYPED_EVENTS`].
[INFO] [stdout]    |                                       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `surfaced_correlations` links to private item `MAX_SURFACED_CORRELATIONS`
[INFO] [stdout]   --> src/session_warnings.rs:87:49
[INFO] [stdout]    |
[INFO] [stdout] 87 |     /// aged out (see [`correlate_session`]). [`MAX_SURFACED_CORRELATIONS`] is only a
[INFO] [stdout]    |                                                 ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_outcome` links to private item `with_session_locked`
[INFO] [stdout]     --> src/session_warnings.rs:1061:50
[INFO] [stdout]      |
[INFO] [stdout] 1061 | /// for `tirith warnings --hidden`. Atomic via [`with_session_locked`]; never
[INFO] [stdout]      |                                                  ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `record_executed_typed_events`
[INFO] [stdout]     --> src/session_warnings.rs:1190:21
[INFO] [stdout]      |
[INFO] [stdout] 1190 | /// should prefer [`record_executed_typed_events`] so events are appended only after
[INFO] [stdout]      |                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `record_executed_typed_events` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_typed_event` links to private item `MAX_TYPED_EVENTS`
[INFO] [stdout]     --> src/session_warnings.rs:1193:7
[INFO] [stdout]      |
[INFO] [stdout] 1193 | /// [`MAX_TYPED_EVENTS`] (oldest dropped first).
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `server_redirect_decision` links to private item `SERVER_MAX_REDIRECTS`
[INFO] [stdout]    --> src/ssrf_guard.rs:211:36
[INFO] [stdout]     |
[INFO] [stdout] 211 | /// 1. The hop count stays under [`SERVER_MAX_REDIRECTS`] — `prior_hops` is the
[INFO] [stdout]     |                                    ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `8`
[INFO] [stdout]   --> src/threatdb.rs:87:34
[INFO] [stdout]    |
[INFO] [stdout] 87 | /// Fixed EOF footer size: magic[8] + trailer_offset u64 + trailer_length u64 +
[INFO] [stdout]    |                                  ^ no item named `8` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `resolve_primary_path`
[INFO] [stdout]     --> src/threatdb.rs:1475:11
[INFO] [stdout]      |
[INFO] [stdout] 1475 |     /// [`resolve_primary_path`], which prefers the v2 file when present and
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^ no item named `resolve_primary_path` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/trusted_child.rs:435:24
[INFO] [stdout]     |
[INFO] [stdout] 435 |     /// multicall argv[0] semantics (for example `cargo -> rustup`).
[INFO] [stdout]     |                        ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `is_public_addr` links to private item `classify_ip`
[INFO] [stdout]    --> src/url_validate.rs:271:7
[INFO] [stdout]     |
[INFO] [stdout] 271 | /// [`classify_ip`] is the single source of truth for the IANA special-purpose
[INFO] [stdout]     |       ^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `TrustedExecutable`
[INFO] [stdout]    --> src/util.rs:496:46
[INFO] [stdout]     |
[INFO] [stdout] 496 | /// string is gone: callers must resolve a [`TrustedExecutable`] first. Capture,
[INFO] [stdout]     |                                              ^^^^^^^^^^^^^^^^^ no item named `TrustedExecutable` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Constraint`
[INFO] [stdout]    --> src/version_intent.rs:301:40
[INFO] [stdout]     |
[INFO] [stdout] 301 |     /// A plain token is therefore a [`Constraint`] (matching resolves the real installed
[INFO] [stdout]     |                                        ^^^^^^^^^^ no item named `Constraint` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Exact`
[INFO] [stdout]    --> src/version_intent.rs:302:28
[INFO] [stdout]     |
[INFO] [stdout] 302 |     /// version), NOT an [`Exact`] pin. Only Cargo's `=` operator (`=1.0.0`) is an exact pin.
[INFO] [stdout]     |                            ^^^^^ no item named `Exact` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compare_pep440_public_versions` links to private item `canonical_pep440_version`
[INFO] [stdout]    --> src/version_intent.rs:897:23
[INFO] [stdout]     |
[INFO] [stdout] 897 | /// grammar used by [`canonical_pep440_version`], including epochs, pre-releases,
[INFO] [stdout]     |                       ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: redundant explicit link target
[INFO] [stdout]  --> src/intent.rs:8:16
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! [`RuleId`](crate::verdict::RuleId)), and `mismatches` (high-impact signals no
[INFO] [stdout]   |      --------  ^^^^^^^^^^^^^^^^^^^^^^ explicit target is redundant
[INFO] [stdout]   |      |
[INFO] [stdout]   |      because label contains path that resolves to same destination
[INFO] [stdout]   |
[INFO] [stdout]   = note: when a link's destination is not specified,
[INFO] [stdout]           the label is used to resolve intra-doc links
[INFO] [stdout]   = note: `#[warn(rustdoc::redundant_explicit_links)]` on by default
[INFO] [stdout] help: remove explicit link target
[INFO] [stdout]   |
[INFO] [stdout] 8 - //! [`RuleId`](crate::verdict::RuleId)), and `mismatches` (high-impact signals no
[INFO] [stdout] 8 + //! [`RuleId`]), and `mismatches` (high-impact signals no
[INFO] [stdout]   |
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]    --> src/policy.rs:413:54
[INFO] [stdout]     |
[INFO] [stdout] 413 |     /// URL of the centralized policy server (e.g., "https://policy.example.com").
[INFO] [stdout]     |                                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]     |
[INFO] [stdout]     = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout]     = note: `#[warn(rustdoc::bare_urls)]` on by default
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]     |
[INFO] [stdout] 413 |     /// URL of the centralized policy server (e.g., "<https://policy.example.com>").
[INFO] [stdout]     |                                                      +                          +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: redundant explicit link target
[INFO] [stdout]  --> src/registry_api.rs:8:23
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! [`ApiProvenance`](crate::package_risk::ApiProvenance) the factor model
[INFO] [stdout]   |      ---------------  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ explicit target is redundant
[INFO] [stdout]   |      |
[INFO] [stdout]   |      because label contains path that resolves to same destination
[INFO] [stdout]   |
[INFO] [stdout]   = note: when a link's destination is not specified,
[INFO] [stdout]           the label is used to resolve intra-doc links
[INFO] [stdout] help: remove explicit link target
[INFO] [stdout]   |
[INFO] [stdout] 8 - //! [`ApiProvenance`](crate::package_risk::ApiProvenance) the factor model
[INFO] [stdout] 8 + //! [`ApiProvenance`] the factor model
[INFO] [stdout]   |
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]  --> src/rules/credential.rs:9:5
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! https://github.com/sirwart/ripsecrets
[INFO] [stdout]   |     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   |
[INFO] [stdout]   = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! <https://github.com/sirwart/ripsecrets>
[INFO] [stdout]   |     +                                     +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]   --> src/rules/credential.rs:12:5
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! https://github.com/gitleaks/gitleaks
[INFO] [stdout]    |     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]    |
[INFO] [stdout]    = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! <https://github.com/gitleaks/gitleaks>
[INFO] [stdout]    |     +                                    +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `role`
[INFO] [stdout]  --> src/rules/prompt_injection.rs:7:22
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! markers ("act as <role>", "you are now", "DAN mode"). Both are High severity.
[INFO] [stdout]   |                      ^^^^^^
[INFO] [stdout]   |
[INFO] [stdout]   = note: `#[warn(rustdoc::invalid_html_tags)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]   --> src/style.rs:13:6
[INFO] [stdout]    |
[INFO] [stdout] 13 | /// (https://no-color.org/ — presence alone disables, even if empty) and TTY.
[INFO] [stdout]    |      ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]    |
[INFO] [stdout]    = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]    |
[INFO] [stdout] 13 | /// (<https://no-color.org/> — presence alone disables, even if empty) and TTY.
[INFO] [stdout]    |      +                     +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `role`
[INFO] [stdout]    --> src/verdict.rs:305:58
[INFO] [stdout]     |
[INFO] [stdout] 305 |     /// M7 ch5 — a prompt-injection seed phrase ("act as <role>", "you are now",
[INFO] [stdout]     |                                                          ^^^^^^
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `sensitive`
[INFO] [stdout]    --> src/verdict.rs:322:15
[INFO] [stdout]     |
[INFO] [stdout] 322 |     /// "read <sensitive path> … send/post/upload it" / "do not tell the user"
[INFO] [stdout]     |               ^^^^^^^^^^
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stderr]     Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 12s
[INFO] [stderr]    Generated /opt/rustwide/target/doc/tirith_core/index.html
[INFO] running `Command { std: "docker" "inspect" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-e" "CARGO_INCREMENTAL=0" "-e" "RUST_BACKTRACE=full" "-e" "RUSTFLAGS=--cap-lints=warn" "-e" "RUSTDOCFLAGS=--cap-lints=warn" "-e" "RUSTC_BOOTSTRAP=1" "-e" "DOCS_RS=1" "-w" "/opt/rustwide/workdir" "--user" "0:0" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8" "/opt/rustwide/cargo-home/bin/cargo" "+1.99.0-beta.8" "rustdoc" "--lib" "-Zrustdoc-map" "--config" "build.rustdocflags=[\"--cfg\", \"docsrs\", \"-Z\", \"unstable-options\", \"--document-private-items\"]" "--frozen" "--message-format=json", kill_on_drop: false }`
[INFO] [stderr]    Compiling proc-macro2 v1.0.106
[INFO] [stderr]    Compiling thiserror v1.0.69
[INFO] [stderr]    Compiling thiserror v2.0.18
[INFO] [stderr]    Compiling quote v1.0.44
[INFO] [stderr]    Compiling syn v2.0.114
[INFO] [stderr]    Compiling synstructure v0.13.2
[INFO] [stderr]    Compiling serde_derive v1.0.228
[INFO] [stderr]    Compiling zerofrom-derive v0.1.6
[INFO] [stderr]    Compiling yoke-derive v0.8.1
[INFO] [stderr]    Compiling displaydoc v0.2.5
[INFO] [stderr]    Compiling zerovec-derive v0.11.2
[INFO] [stderr]    Compiling tokio-macros v2.6.0
[INFO] [stderr]    Compiling tracing-attributes v0.1.31
[INFO] [stderr]    Compiling ref-cast-impl v1.0.25
[INFO] [stderr]    Compiling thiserror-impl v1.0.69
[INFO] [stderr]    Compiling thiserror-impl v2.0.18
[INFO] [stderr]    Compiling async-trait v0.1.89
[INFO] [stderr]    Compiling enum-as-inner v0.6.1
[INFO] [stderr]    Compiling curve25519-dalek-derive v0.1.1
[INFO] [stderr]    Compiling enumflags2_derive v0.7.12
[INFO] [stderr]     Checking enumflags2 v0.7.12
[INFO] [stderr]     Checking curve25519-dalek v4.1.3
[INFO] [stderr]     Checking tokio v1.49.0
[INFO] [stderr]     Checking ref-cast v1.0.25
[INFO] [stderr]     Checking zerofrom v0.1.6
[INFO] [stderr]     Checking yoke v0.8.1
[INFO] [stderr]     Checking tracing v0.1.44
[INFO] [stderr]     Checking ed25519-dalek v2.2.0
[INFO] [stderr]     Checking zerovec v0.11.5
[INFO] [stderr]     Checking zerotrie v0.2.3
[INFO] [stderr]     Checking zip v2.4.2
[INFO] [stderr]     Checking landlock v0.4.5
[INFO] [stderr]     Checking tinystr v0.8.2
[INFO] [stderr]     Checking potential_utf v0.1.4
[INFO] [stderr]     Checking icu_locale_core v2.1.1
[INFO] [stderr]     Checking icu_collections v2.1.1
[INFO] [stderr]     Checking serde v1.0.228
[INFO] [stderr]     Checking icu_provider v2.1.1
[INFO] [stderr]     Checking icu_properties v2.1.2
[INFO] [stderr]     Checking icu_normalizer v2.1.1
[INFO] [stderr]     Checking ahash v0.8.12
[INFO] [stderr]     Checking toml_datetime v0.6.11
[INFO] [stderr]     Checking serde_spanned v0.6.9
[INFO] [stderr]     Checking fluent-uri v0.4.1
[INFO] [stderr]     Checking email_address v0.2.9
[INFO] [stderr]     Checking chrono v0.4.43
[INFO] [stderr]     Checking serde_urlencoded v0.7.1
[INFO] [stderr]     Checking serde_yaml v0.9.34+deprecated
[INFO] [stderr]     Checking rust-mcp-schema v0.10.1
[INFO] [stderr]     Checking toml_edit v0.22.27
[INFO] [stderr]     Checking referencing v0.46.5
[INFO] [stderr]     Checking idna_adapter v1.2.1
[INFO] [stderr]     Checking lopdf v0.34.0
[INFO] [stderr]     Checking idna v1.1.0
[INFO] [stderr]     Checking url v2.5.8
[INFO] [stderr]     Checking jsonschema v0.46.5
[INFO] [stderr]     Checking hyper v1.8.1
[INFO] [stderr]     Checking tower v0.5.3
[INFO] [stderr]     Checking tokio-rustls v0.26.4
[INFO] [stderr]     Checking hickory-proto v0.24.4
[INFO] [stderr]     Checking toml v0.8.23
[INFO] [stderr]     Checking tower-http v0.6.8
[INFO] [stderr]     Checking hyper-util v0.1.20
[INFO] [stderr]    Compiling tirith-core v0.4.2 (/opt/rustwide/workdir)
[INFO] [stderr]     Checking hickory-resolver v0.24.4
[INFO] [stderr]     Checking hyper-rustls v0.27.7
[INFO] [stderr]     Checking reqwest v0.12.28
[INFO] [stderr]  Documenting tirith-core v0.4.2 (/opt/rustwide/workdir)
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`ArchiveOutcome`]):
[INFO] [stdout]             ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout]   = note: `#[warn(rustdoc::broken_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveViolation`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * A **hard structural violation** ([`ArchiveViolation`]) means the archive is
[INFO] [stdout]                                               ^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveViolation` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome::Rejected`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             [`ArchiveOutcome::Rejected`]. The reader still continues best-effort to
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveOutcome::Accepted`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             buffer). The wheel is still [`ArchiveOutcome::Accepted`]; the gap records
[INFO] [stdout]                                          ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `read_wheel`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`read_wheel`] takes a `Read + Seek` handle, so the CLI can pass a no-follow
[INFO] [stdout]            ^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `read_wheel` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArchiveLimits::max_member_uncompressed`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           A4 only does the PLUMBING: for a member within [`ArchiveLimits::max_member_uncompressed`]
[INFO] [stdout]                                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArchiveLimits` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeMemberHandoff::Buffered`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           it decompresses into a bounded in-memory buffer (a [`NativeMemberHandoff::Buffered`])
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeMemberHandoff` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeMemberHandoff::Streaming`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           member it produces a [`NativeMemberHandoff::Streaming`] view (whole-member
[INFO] [stdout]                                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeMemberHandoff` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `MemberVisitor`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           gap. The handoffs are surfaced to a [`MemberVisitor`]; B7 implements the actual
[INFO] [stdout]                                                ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `MemberVisitor` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `parse_metadata_headers`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             single shared helper [`parse_metadata_headers`], also used by
[INFO] [stdout]                                   ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `parse_metadata_headers` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `WheelMetadata`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             shipping a native `.so` is a [`WheelMetadata`] signal a later analyzer
[INFO] [stdout]                                           ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `WheelMetadata` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_wheel_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * [`verify_wheel_record`] is STRICT. A wheel is a freshly-built artifact, so
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_wheel_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_installed_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * [`verify_installed_record`] is LAX, per the installed-packages
[INFO] [stdout]              ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_installed_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `FileVerification::Unverifiable`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             an empty hash OR size column makes a file [`FileVerification::Unverifiable`]
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `FileVerification` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `OwnershipIndex`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`OwnershipIndex`] is a DUPLICATE-AWARE multimap
[INFO] [stdout]            ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `OwnershipIndex` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `classify_magic`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`classify_magic`]) used when the principal parser declines a buffer or when we
[INFO] [stdout]             ^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `classify_magic` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `triage_native`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`triage_native`] NEVER panics on any input. Every `object` call is fallible and
[INFO] [stdout]            ^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `triage_native` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeCoverage::Partial`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           falls back to the magic classifier and is recorded [`NativeCoverage::Partial`].
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeCoverage` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NativeFactKind::NativeModulePresent`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`NativeModulePresent`]: NativeFactKind::NativeModulePresent
[INFO] [stdout]                                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NativeFactKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NativeFacts` links to private item `correlate_native`
[INFO] [stdout]    --> src/artifact/native.rs:319:38
[INFO] [stdout]     |
[INFO] [stdout] 319 | /// raw observations; correlation ([`correlate_native`]) decides what becomes a
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout]     = note: `#[warn(rustdoc::private_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `embedded_urls` links to private item `is_suspicious_url`
[INFO] [stdout]    --> src/artifact/native.rs:345:12
[INFO] [stdout]     |
[INFO] [stdout] 345 |     /// ([`is_suspicious_url`]) counts toward the danger leg.
[INFO] [stdout]     |            ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `has_runtime_launch`
[INFO] [stdout]    --> src/artifact/native.rs:353:51
[INFO] [stdout]     |
[INFO] [stdout] 353 |     /// (the name can appear in help text); see [`has_runtime_launch`].
[INFO] [stdout]     |                                                   ^^^^^^^^^^^^^^^^^^ no item named `has_runtime_launch` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_corroboration` links to private item `correlate_native`
[INFO] [stdout]    --> src/artifact/native.rs:444:55
[INFO] [stdout]     |
[INFO] [stdout] 444 |     /// * a known-malicious indicator (folded in by [`correlate_native`], not here).
[INFO] [stdout]     |                                                       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ArtifactSetInspection`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           B5/B6/B7 analyzers) and over an [`ArtifactSetInspection`] for cross-distribution
[INFO] [stdout]                                            ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ArtifactSetInspection` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `artifact_hash_indicator`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             DB-gated hash match (see [`artifact_hash_indicator`]).
[INFO] [stdout]                                       ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `artifact_hash_indicator` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_file`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           # Single-artifact ([`inspect_artifact_file`])
[INFO] [stdout]                               ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_file` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ARTIFACT_MAX_FILE_SIZE`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           1. Open the file no-follow within [`ARTIFACT_MAX_FILE_SIZE`] (a wheel ceiling,
[INFO] [stdout]                                              ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ARTIFACT_MAX_FILE_SIZE` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_set`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           # Artifact-set ([`inspect_artifact_set`])
[INFO] [stdout]                            ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_set` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `inspect_artifact_set`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           script). [`inspect_artifact_set`] is the two-pass model required for criterion
[INFO] [stdout]                     ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `inspect_artifact_set` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `RuleId::WheelStructurallyRejected`
[INFO] [stdout]    --> src/artifact/inspect.rs:495:35
[INFO] [stdout]     |
[INFO] [stdout] 495 |     /// findings, a synthesized [`RuleId::WheelStructurallyRejected`] finding for
[INFO] [stdout]     |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `RuleId` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ingest_bytes`
[INFO] [stdout]    --> src/artifact/quarantine.rs:627:66
[INFO] [stdout]     |
[INFO] [stdout] 627 |     /// re-hashes before publishing, identical verification to [`ingest_bytes`].
[INFO] [stdout]     |                                                                  ^^^^^^^^^^^^ no item named `ingest_bytes` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `gc_unreferenced_blobs`
[INFO] [stdout]    --> src/artifact/quarantine.rs:729:40
[INFO] [stdout]     |
[INFO] [stdout] 729 |     /// Blobs are GC'd separately by [`gc_unreferenced_blobs`].
[INFO] [stdout]     |                                        ^^^^^^^^^^^^^^^^^^^^^ no item named `gc_unreferenced_blobs` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `materialize_blob`
[INFO] [stdout]     --> src/artifact/quarantine.rs:1094:42
[INFO] [stdout]      |
[INFO] [stdout] 1094 | /// Materialise artifacts into it with [`materialize_blob`]; the lease is released
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^ no item named `materialize_blob` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineStore::ingest_file`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           into the quarantine (D1's [`QuarantineStore::ingest_file`]), so the bytes that
[INFO] [stdout]                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineStore` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ResolverAllowances`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              future policy ([`ResolverAllowances`]) opts in. `uv pip compile --no-build`
[INFO] [stdout]                              ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ResolverAllowances` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `validate_requirement`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              own step); [`validate_requirement`] rejects the `-e` / `git+` / `file:` /
[INFO] [stdout]                          ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `validate_requirement` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `isolated_env`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              a scrubbed environment ([`isolated_env`]) that points every pip/uv config
[INFO] [stdout]                                       ^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `isolated_env` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `validate_index_url`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           6. **Credentials in an index URL refused.** [`validate_index_url`] rejects a
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `validate_index_url` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `resolve_tool`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              [`resolve_tool`] uses [`crate::trusted_child`] to canonicalize, reject
[INFO] [stdout]               ^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `resolve_tool` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ResolvedSet`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`ResolvedSet`], RE-MATERIALISES each approved blob into the install
[INFO] [stdout]            ^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ResolvedSet` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineTransaction::materialize_blob`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           pre-flight stat: [`QuarantineTransaction::materialize_blob`] streams the blob
[INFO] [stdout]                             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineTransaction` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineError::DigestMismatch`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`QuarantineError::DigestMismatch`] / [`QuarantineError::BlobNotFound`], which
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineError` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `QuarantineError::BlobNotFound`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`QuarantineError::DigestMismatch`] / [`QuarantineError::BlobNotFound`], which
[INFO] [stdout]                                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `QuarantineError` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `rebind_for_install`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              time. Right before the install runs, [`rebind_for_install`] reloads the
[INFO] [stdout]                                                    ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `rebind_for_install` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `approved_requirements_text`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           2. **Generate `approved.txt`.** [`approved_requirements_text`] emits one local,
[INFO] [stdout]                                            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `approved_requirements_text` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `InstallCommand::pip_install_args`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           3. **The pip argv.** [`InstallCommand::pip_install_args`] is exactly the plan's
[INFO] [stdout]                                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `InstallCommand` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `build_install_spec`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           4. **The capsule spec.** [`build_install_spec`] is a locked-down, **deny-all
[INFO] [stdout]                                     ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `build_install_spec` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleSpec`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              network** [`CapsuleSpec`]: the install needs no outbound traffic once the
[INFO] [stdout]                         ^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `CapsuleSpec` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `rebind_for_install`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           post-extraction)". D4 owns the FIRST half: [`rebind_for_install`] guarantees the
[INFO] [stdout]                                                       ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `rebind_for_install` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_post_install_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`verify_post_install_record`] is that second half. Once the contained pip
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_post_install_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `verify_installed_record`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           tree). [`verify_installed_record`] already flags both
[INFO] [stdout]                   ^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `verify_installed_record` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleSpec`
[INFO] [stdout]    --> src/artifact/install.rs:316:7
[INFO] [stdout]     |
[INFO] [stdout] 316 | /// [`CapsuleSpec`] is locked-down deny-all.
[INFO] [stdout]     |       ^^^^^^^^^^^ no item named `CapsuleSpec` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_installed_distributions` links to private item `post_install_site_packages`
[INFO] [stdout]    --> src/artifact/install.rs:894:58
[INFO] [stdout]     |
[INFO] [stdout] 894 | /// one's `(dist_info_dir, identity)`. Reuses the SAME [`post_install_site_packages`]
[INFO] [stdout]     |                                                          ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `locate_installed_dist_info`
[INFO] [stdout]    --> src/artifact/install.rs:897:35
[INFO] [stdout]     |
[INFO] [stdout] 897 | /// .dist-info` in each. Unlike [`locate_installed_dist_info`], this is name-agnostic:
[INFO] [stdout]     |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `locate_installed_dist_info` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::PureToNative`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * ships a compiled extension where there was none ([`ReleaseAnomalyKind::PureToNative`]),
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::StartupHookAdded`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`ReleaseAnomalyKind::StartupHookAdded`]),
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::JavaScriptVolumeJump`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`ReleaseAnomalyKind::JavaScriptVolumeJump`]),
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::IdentityChanged`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           * changes the distribution IDENTITY it claims ([`ReleaseAnomalyKind::IdentityChanged`]),
[INFO] [stdout]                                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ReleaseAnomalyKind::NewExecutionCapability`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             did not have ([`ReleaseAnomalyKind::NewExecutionCapability`]).
[INFO] [stdout]                            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `ReleaseAnomalyKind` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize_project_name_public` links to private item `archive::normalize_project_name`
[INFO] [stdout]    --> src/artifact/mod.rs:718:7
[INFO] [stdout]     |
[INFO] [stdout] 718 | /// [`archive::normalize_project_name`] so the normalization stays single-sourced.
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `prev_hash` links to private item `append_to_audit_log`
[INFO] [stdout]   --> src/audit.rs:98:11
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// [`append_to_audit_log`], never by the constructors.
[INFO] [stdout]    |           ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `audit_signing_available` links to private item `sign_canonical`
[INFO] [stdout]     --> src/audit.rs:1479:34
[INFO] [stdout]      |
[INFO] [stdout] 1479 | /// key, exactly like a single [`sign_canonical`] attempt would.
[INFO] [stdout]      |                                  ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `BufReader`
[INFO] [stdout]    --> src/audit_aggregator.rs:125:7
[INFO] [stdout]     |
[INFO] [stdout] 125 | /// [`BufReader`] so a large append-only log is never fully buffered. Result and
[INFO] [stdout]     |       ^^^^^^^^^ no item named `BufReader` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `export_csv` links to private item `csv_neutralize_formula`
[INFO] [stdout]    --> src/audit_aggregator.rs:580:42
[INFO] [stdout]     |
[INFO] [stdout] 580 | /// LibreOffice evaluate as a formula. [`csv_neutralize_formula`] tab-prefixes
[INFO] [stdout]     |                                          ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `export_csv` links to private item `csv_escape`
[INFO] [stdout]    --> src/audit_aggregator.rs:581:48
[INFO] [stdout]     |
[INFO] [stdout] 581 | /// such cells (the OWASP mitigation) before [`csv_escape`].
[INFO] [stdout]     |                                                ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_at` links to private item `crate::canary::StoreLock`
[INFO] [stdout]    --> src/baseline.rs:576:14
[INFO] [stdout]     |
[INFO] [stdout] 576 | /// shared [`crate::canary::StoreLock`] for the whole sequence — without it, a
[INFO] [stdout]     |              ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `browser_extensions` links to private item `read_install_classes`
[INFO] [stdout]   --> src/browser_extensions.rs:22:37
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!   there and nowhere else; see [`read_install_classes`] for why nothing else
[INFO] [stdout]    |                                     ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `browser_extensions` links to private item `read_install_classes`
[INFO] [stdout]   --> src/browser_extensions.rs:38:9
[INFO] [stdout]    |
[INFO] [stdout] 38 | //!   [`read_install_classes`]; no `serde_json::Value` from that file crosses its
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `SurfaceHashChanged` links to private item `compare_entry`
[INFO] [stdout]     --> src/browser_extensions.rs:3713:11
[INFO] [stdout]      |
[INFO] [stdout] 3713 |     /// [`compare_entry`]. It exists so that omission is a reported drift rather
[INFO] [stdout]      |           ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CapsuleCoverage::is_degraded`
[INFO] [stdout]   --> src/capsule/mod.rs:30:7
[INFO] [stdout]    |
[INFO] [stdout] 30 | //! [`CapsuleCoverage::is_degraded`] / the specific flags and **fails closed**
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ the struct `CapsuleCoverage` has no field or associated item named `is_degraded`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `LandlockSeccompCapsule`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`LandlockSeccompCapsule`] backend (which probes the running kernel and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `LandlockSeccompCapsule` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           reports honest [`CapsuleCoverage`]) and the [`apply_containment`] primitive
[INFO] [stdout]                                                        ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           single-threaded, deserializes the [`CapsuleSpec`], calls [`apply_containment`],
[INFO] [stdout]                                                                     ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `apply_containment`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`apply_containment`] applies, in this exact order:
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `apply_containment` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `LandlockSeccompCapsule::available_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`LandlockSeccompCapsule::available_coverage`] probes for Landlock support and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `LandlockSeccompCapsule` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerCapsule`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           capsule: the [`AppContainerCapsule`] backend (which probes for AppContainer
[INFO] [stdout]                         ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerCapsule` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerProfile`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`AppContainerProfile`]), the Job Object resource ceilings
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerProfile` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `JobObjectLimits`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`JobObjectLimits`]), the ACL grant list ([`AclGrant`]), and the assembled
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `JobObjectLimits` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AclGrant`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`JobObjectLimits`]), the ACL grant list ([`AclGrant`]), and the assembled
[INFO] [stdout]                                                       ^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AclGrant` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `WindowsLaunchPlan`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`WindowsLaunchPlan`]. The `windows`-crate Win32 calls that *apply* the plan
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `WindowsLaunchPlan` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `derive_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           the Windows CI runner), and the honesty contract ([`derive_coverage`]) is
[INFO] [stdout]                                                              ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `derive_coverage` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `acl_grants`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             ([`acl_grants`]) and grants nothing else. Before producing any ACE, the shared
[INFO] [stdout]               ^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `acl_grants` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `job_object_limits`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]             process-count / open-files ceilings ([`job_object_limits`]). The child is
[INFO] [stdout]                                                   ^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `job_object_limits` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AppContainerCapsule::available_coverage`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AppContainerCapsule::available_coverage`] probes for AppContainer support and
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AppContainerCapsule` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NetworkPolicy`
[INFO] [stdout]    --> src/capsule/windows.rs:318:63
[INFO] [stdout]     |
[INFO] [stdout] 318 | /// capability list is empty in E4 regardless of the spec's [`NetworkPolicy`] (a
[INFO] [stdout]     |                                                               ^^^^^^^^^^^^^ no item named `NetworkPolicy` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/capsule/windows.rs:653:21
[INFO] [stdout]     |
[INFO] [stdout] 653 | /// program as argv[0]; `CreateProcessW` resolves the executable separately from
[INFO] [stdout]     |                     ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `MAX_DIFF_PATH_CHARS`
[INFO] [stdout]    --> src/capsule_project.rs:316:24
[INFO] [stdout]     |
[INFO] [stdout] 316 |     /// shortened to [`MAX_DIFF_PATH_CHARS`], so the diff is a sample.
[INFO] [stdout]     |                        ^^^^^^^^^^^^^^^^^^^ no item named `MAX_DIFF_PATH_CHARS` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `capsule_receipt` links to private item `crate::audit::log_capsule_run_receipt`
[INFO] [stdout]   --> src/capsule_receipt.rs:11:20
[INFO] [stdout]    |
[INFO] [stdout] 11 | //! entry point ([`crate::audit::log_capsule_run_receipt`]) is `pub(crate)`. A
[INFO] [stdout]    |                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `command_matches` links to private item `is_shell_significant_ws`
[INFO] [stdout]    --> src/command_card.rs:789:50
[INFO] [stdout]     |
[INFO] [stdout] 789 |     /// only shell-significant whitespace (see [`is_shell_significant_ws`])? NOT
[INFO] [stdout]     |                                                  ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Action::Block`
[INFO] [stdout]   --> src/commands_manifest.rs:11:20
[INFO] [stdout]    |
[INFO] [stdout] 11 | //!    → High (→ [`Action::Block`]), `action: warn` → Medium (→ Warn).
[INFO] [stdout]    |                    ^^^^^^^^^^^^^ no item named `Action` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `evaluate`
[INFO] [stdout]   --> src/commands_manifest.rs:18:48
[INFO] [stdout]    |
[INFO] [stdout] 18 | //! This is STRUCTURAL, not a runtime check: [`evaluate`] is handed an immutable
[INFO] [stdout]    |                                                ^^^^^^^^ no item named `evaluate` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `commands_manifest` links to private item `crate::command_card::is_shell_significant_ws`
[INFO] [stdout]   --> src/commands_manifest.rs:29:7
[INFO] [stdout]    |
[INFO] [stdout] 29 | //! [`crate::command_card::is_shell_significant_ws`]).
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_from_path` links to private item `MANIFEST_READ_CAP`
[INFO] [stdout]    --> src/commands_manifest.rs:225:43
[INFO] [stdout]     |
[INFO] [stdout] 225 |     /// (`O_NONBLOCK`, fstat, capped at [`MANIFEST_READ_CAP`]) instead of a plain
[INFO] [stdout]     |                                           ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `context_detect` links to private item `run_with_timeout`
[INFO] [stdout]   --> src/context_detect.rs:12:43
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! Every external command goes through [`run_with_timeout`], which drains stdout
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `Timeout` links to private item `SHELL_OUT_TIMEOUT`
[INFO] [stdout]   --> src/context_detect.rs:98:34
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// The shell-out exceeded [`SHELL_OUT_TIMEOUT`]. The child was killed.
[INFO] [stdout]    |                                  ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `build_dsl_backing`
[INFO] [stdout]    --> src/custom_rule_dsl.rs:368:42
[INFO] [stdout]     |
[INFO] [stdout] 368 | /// fact it references is populated by [`build_dsl_backing`] for that context.
[INFO] [stdout]     |                                          ^^^^^^^^^^^^^^^^^ no item named `build_dsl_backing` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `top_findings` links to private item `TOP_N`
[INFO] [stdout]   --> src/dashboard.rs:73:62
[INFO] [stdout]    |
[INFO] [stdout] 73 |     /// Top rule IDs by occurrence (descending), capped at [`TOP_N`].
[INFO] [stdout]    |                                                              ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `top_hosts` links to private item `TOP_N`
[INFO] [stdout]   --> src/dashboard.rs:75:59
[INFO] [stdout]    |
[INFO] [stdout] 75 |     /// Top hosts by occurrence (descending), capped at [`TOP_N`]. Best-effort,
[INFO] [stdout]    |                                                           ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Valid`
[INFO] [stdout]   --> src/dashboard.rs:84:38
[INFO] [stdout]    |
[INFO] [stdout] 84 | /// into [`PolicySummary::NoFile`]/[`Valid`] so `--json` carries them at the same
[INFO] [stdout]    |                                      ^^^^^ no item named `Valid` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `generate_serve_token` links to private item `SERVE_TOKEN_BYTES`
[INFO] [stdout]    --> src/dashboard.rs:527:66
[INFO] [stdout]     |
[INFO] [stdout] 527 | /// Generate a fresh ephemeral `tirith dashboard serve` token: [`SERVE_TOKEN_BYTES`]
[INFO] [stdout]     |                                                                  ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `deobfuscate` links to private item `crate::extract::strip_invisible`
[INFO] [stdout]   --> src/deobfuscate.rs:17:43
[INFO] [stdout]    |
[INFO] [stdout] 17 | //! Note: the invisible-strip step (via [`crate::extract::strip_invisible`]) drops
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `base64_truncated` links to private item `MAX_BASE64_VALIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:105:55
[INFO] [stdout]     |
[INFO] [stdout] 105 |     /// run exceeded the bounded validation window ([`MAX_BASE64_VALIDATE_LEN`]),
[INFO] [stdout]     |                                                       ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_encoded_blob` links to private item `MIN_BASE64_CANDIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:748:16
[INFO] [stdout]     |
[INFO] [stdout] 748 | /// at least [`MIN_BASE64_CANDIDATE_LEN`] chars OR a contiguous hex run whose
[INFO] [stdout]     |                ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_encoded_blob` links to private item `MIN_HEX_CANDIDATE_LEN`
[INFO] [stdout]    --> src/deobfuscate.rs:749:38
[INFO] [stdout]     |
[INFO] [stdout] 749 | /// even-length prefix is at least [`MIN_HEX_CANDIDATE_LEN`]. Used by the engine's
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `collapse_spaced_chars`
[INFO] [stdout]    --> src/deobfuscate.rs:779:38
[INFO] [stdout]     |
[INFO] [stdout] 779 | ///   one ASCII space (mirrors the [`collapse_spaced_chars`] trigger, via the shared
[INFO] [stdout]     |                                      ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `probe_spaced_run`
[INFO] [stdout]    --> src/deobfuscate.rs:780:9
[INFO] [stdout]     |
[INFO] [stdout] 780 | ///   [`probe_spaced_run`] helper);
[INFO] [stdout]     |         ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `has_deobfuscation_candidate` links to private item `leet_fold`
[INFO] [stdout]    --> src/deobfuscate.rs:784:7
[INFO] [stdout]     |
[INFO] [stdout] 784 | /// [`leet_fold`] substitutes those chars UNCONDITIONALLY: an earlier
[INFO] [stdout]     |       ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalized_forms_with_status` links to private item `recover_printable_text`
[INFO] [stdout]    --> src/deobfuscate.rs:845:48
[INFO] [stdout]     |
[INFO] [stdout] 845 | ///   yields recoverable printable text (via [`recover_printable_text`]), each with
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalized_forms_with_status` links to private item `DecodeBudget`
[INFO] [stdout]    --> src/deobfuscate.rs:857:67
[INFO] [stdout]     |
[INFO] [stdout] 857 | /// cumulative decoded bytes, per-run bytes, emitted forms; see [`DecodeBudget`]);
[INFO] [stdout]     |                                                                   ^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_manifests` links to private item `SKIP_DIRS`
[INFO] [stdout]    --> src/ecosystem_scan.rs:272:52
[INFO] [stdout]     |
[INFO] [stdout] 272 | /// [`MAX_WALK_DEPTH`] and [`MAX_WALK_ENTRIES`]. [`SKIP_DIRS`] are not
[INFO] [stdout]     |                                                    ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `npm_lock_integrity_index` links to private item `parse_package_lock`
[INFO] [stdout]    --> src/ecosystem_scan.rs:649:21
[INFO] [stdout]     |
[INFO] [stdout] 649 | /// Separate from [`parse_package_lock`] on purpose: that function answers "what
[INFO] [stdout]     |                     ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `slopsquat` links to private item `hallucinated_name_shape`
[INFO] [stdout]     --> src/ecosystem_scan.rs:1704:42
[INFO] [stdout]      |
[INFO] [stdout] 1704 | /// 2. AI-hallucinated name shape (see [`hallucinated_name_shape`]).
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `InstalledIntegrityReport` links to private item `InstalledIntegrityReport::correlated_findings`
[INFO] [stdout]     --> src/ecosystem_scan.rs:3365:7
[INFO] [stdout]      |
[INFO] [stdout] 3365 | /// [`InstalledIntegrityReport::correlated_findings`]. Serialized onto
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `native_findings` links to private item `InstalledIntegrityReport::native_correlated_findings`
[INFO] [stdout]     --> src/ecosystem_scan.rs:3421:11
[INFO] [stdout]      |
[INFO] [stdout] 3421 |     /// [`InstalledIntegrityReport::native_correlated_findings`].
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `custom_seeds` links to private item `OutputAnalyzerState::extra_injection_seeds`
[INFO] [stdout]    --> src/engine.rs:657:25
[INFO] [stdout]     |
[INFO] [stdout] 657 |     /// threaded into [`OutputAnalyzerState::extra_injection_seeds`] so the
[INFO] [stdout]     |                         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_exec_provenance_hot`
[INFO] [stdout]     --> src/engine.rs:2541:35
[INFO] [stdout]      |
[INFO] [stdout] 2541 | ///   `libc::access(W_OK)`; see [`check_exec_provenance_hot`]). The OTHER SEVEN
[INFO] [stdout]      |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_taint_hot`
[INFO] [stdout]     --> src/engine.rs:2557:20
[INFO] [stdout]      |
[INFO] [stdout] 2557 | ///   non-empty: [`check_taint_hot`] fires `ExecOfTaintedFile` /
[INFO] [stdout]      |                    ^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `apply_baseline`
[INFO] [stdout]     --> src/engine.rs:2559:46
[INFO] [stdout]      |
[INFO] [stdout] 2559 | /// * **M10 ch5 — baseline.** Opt-in (D2): [`apply_baseline`] runs post-tier-3,
[INFO] [stdout]      |                                              ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_command_card_hot`
[INFO] [stdout]     --> src/engine.rs:2563:42
[INFO] [stdout]      |
[INFO] [stdout] 2563 | /// * **M11 — cards/manifest/canary.** [`check_command_card_hot`] (ATTESTATION-
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_command_manifest_hot`
[INFO] [stdout]     --> src/engine.rs:2564:57
[INFO] [stdout]      |
[INFO] [stdout] 2564 | ///   ONLY — never changes another finding's action), [`check_command_manifest_hot`]
[INFO] [stdout]      |                                                         ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `analyze` links to private item `check_canary_hot`
[INFO] [stdout]     --> src/engine.rs:2566:42
[INFO] [stdout]      |
[INFO] [stdout] 2566 | ///   never weaken an engine finding), [`check_canary_hot`] (Exec+Paste+output).
[INFO] [stdout]      |                                          ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `explain_var` links to private item `mask_assignment`
[INFO] [stdout]    --> src/env_guard.rs:645:48
[INFO] [stdout]     |
[INFO] [stdout] 645 | /// **The value is never read or printed** — [`mask_assignment`] replaces it
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `DELETE_COUNT_KEY` links to private item `mass_file_deletion`
[INFO] [stdout]    --> src/event_buffer.rs:725:56
[INFO] [stdout]     |
[INFO] [stdout] 725 | /// one delete command targeted (`rm a b c` -> "3"). [`mass_file_deletion`] sums
[INFO] [stdout]     |                                                        ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NON_BUILD_DELETE_COUNT_KEY` links to private item `mass_file_deletion`
[INFO] [stdout]    --> src/event_buffer.rs:733:68
[INFO] [stdout]     |
[INFO] [stdout] 733 | /// path with `crate::util_build_dirs::is_build_artifact_path`). [`mass_file_deletion`]
[INFO] [stdout]     |                                                                    ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `NON_BUILD_DELETE_COUNT_KEY` links to private item `TypedEvent::non_build_delete_count`
[INFO] [stdout]    --> src/event_buffer.rs:738:22
[INFO] [stdout]     |
[INFO] [stdout] 738 | /// heuristic; see [`TypedEvent::non_build_delete_count`].
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `iac_plan` links to private item `run_terraform_show_json`
[INFO] [stdout]   --> src/iac_plan.rs:17:7
[INFO] [stdout]    |
[INFO] [stdout] 17 | //! [`run_terraform_show_json`] — the engine hot path consults
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `MAX_REASON_BYTES` links to private item `FLAG_READ_CAP`
[INFO] [stdout]   --> src/incident.rs:95:7
[INFO] [stdout]    |
[INFO] [stdout] 95 | /// [`FLAG_READ_CAP`] guarantees a flag written by [`start_at`] always reads back
[INFO] [stdout]    |       ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `now` links to private item `current_user`
[INFO] [stdout]    --> src/incident.rs:115:64
[INFO] [stdout]     |
[INFO] [stdout] 115 |     /// (`reason` via [`MAX_REASON_BYTES`], `started_by` via [`current_user`]) so
[INFO] [stdout]     |                                                                ^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `now` links to private item `FLAG_READ_CAP`
[INFO] [stdout]    --> src/incident.rs:116:48
[INFO] [stdout]     |
[INFO] [stdout] 116 |     /// the serialized body can never exceed [`FLAG_READ_CAP`] — a flag written by
[INFO] [stdout]     |                                                ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `read_flag_at` links to private item `FLAG_READ_CAP`
[INFO] [stdout]    --> src/incident.rs:225:46
[INFO] [stdout]     |
[INFO] [stdout] 225 | /// rejects non-regular files, and caps at [`FLAG_READ_CAP`]. Mapping is fail-SAFE:
[INFO] [stdout]     |                                              ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `1`
[INFO] [stdout]   --> src/install_txn.rs:54:53
[INFO] [stdout]    |
[INFO] [stdout] 54 |     /// `pacman -S <pkg...>` — Arch / Manjaro. argv[1] is `-S` (Sync), encoded
[INFO] [stdout]    |                                                     ^ no item named `1` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]   --> src/install_txn.rs:69:42
[INFO] [stdout]    |
[INFO] [stdout] 69 |     /// The program name to invoke (argv[0]). One variant ↔ one program; `Apt`
[INFO] [stdout]    |                                          ^ no item named `0` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/install_txn.rs:160:14
[INFO] [stdout]     |
[INFO] [stdout] 160 |     /// argv[0] — the package-manager program.
[INFO] [stdout]     |              ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/install_txn.rs:834:64
[INFO] [stdout]     |
[INFO] [stdout] 834 | /// Build the real install argv: install subcommand after argv[0], then the
[INFO] [stdout]     |                                                                ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `IntentClass` links to private item `IntentClass::justifies`
[INFO] [stdout]    --> src/intent.rs:133:21
[INFO] [stdout]     |
[INFO] [stdout] 133 | /// justifies via [`IntentClass::justifies`].
[INFO] [stdout]     |                     ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `classify_intent` links to private item `IntentClass::ALL`
[INFO] [stdout]    --> src/intent.rs:352:7
[INFO] [stdout]     |
[INFO] [stdout] 352 | /// [`IntentClass::ALL`] order (first matching keyword per class).
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ToolCallResult`
[INFO] [stdout]   --> src/mcp/content.rs:15:60
[INFO] [stdout]    |
[INFO] [stdout] 15 | //! [`crate::mcp::output_filter`] over the round-tripped [`ToolCallResult`].
[INFO] [stdout]    |                                                            ^^^^^^^^^^^^^^ no item named `ToolCallResult` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `filter_tool_result` links to private item `should_downgrade_injection_block`
[INFO] [stdout]    --> src/mcp/output_filter.rs:545:7
[INFO] [stdout]     |
[INFO] [stdout] 545 | /// [`should_downgrade_injection_block`] for the exact gate. With the flag off
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `sanitize_text_into` links to private item `TerminalSanitizer`
[INFO] [stdout]     --> src/mcp/output_filter.rs:2068:41
[INFO] [stdout]      |
[INFO] [stdout] 2068 | /// callers; multi-leaf MCP paths use [`TerminalSanitizer`] directly.
[INFO] [stdout]      |                                         ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `Url` links to private item `redact_url_userinfo`
[INFO] [stdout]    --> src/mcp_lock.rs:188:37
[INFO] [stdout]     |
[INFO] [stdout] 188 |     /// verbatim with `None`. See [`redact_url_userinfo`].
[INFO] [stdout]     |                                     ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `content_hash` links to private item `hash_field`
[INFO] [stdout]    --> src/mcp_lock.rs:329:31
[INFO] [stdout]     |
[INFO] [stdout] 329 |     /// length-prefixed via [`hash_field`], not `\0`-joined — so `["a","b"]` and
[INFO] [stdout]     |                               ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_descriptor_hash` links to private item `hash_field`
[INFO] [stdout]    --> src/mcp_lock.rs:766:36
[INFO] [stdout]     |
[INFO] [stdout] 766 | /// Length-prefixed framing (via [`hash_field`]) so no two distinct lists collide.
[INFO] [stdout]     |                                    ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_descriptor_drift` links to private item `McpDescriptorChange::sort_key`
[INFO] [stdout]    --> src/mcp_lock.rs:872:7
[INFO] [stdout]     |
[INFO] [stdout] 872 | /// [`McpDescriptorChange::sort_key`].
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_mcp_configs` links to private item `discover_mcp_configs_full`
[INFO] [stdout]     --> src/mcp_lock.rs:1772:7
[INFO] [stdout]      |
[INFO] [stdout] 1772 | /// [`discover_mcp_configs_full`] for it.
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `build_inventory` links to private item `discover_mcp_configs_full`
[INFO] [stdout]     --> src/mcp_lock.rs:1919:35
[INFO] [stdout]      |
[INFO] [stdout] 1919 | /// Path-level rejections (from [`discover_mcp_configs_full`]) and file-level ones
[INFO] [stdout]      |                                   ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `McpServerDrift::env_changes`
[INFO] [stdout]     --> src/mcp_lock.rs:2900:11
[INFO] [stdout]      |
[INFO] [stdout] 2900 |     /// [`McpServerDrift::env_changes`].
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `McpServerDrift` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compute_drift` links to private item `McpDrift::sort_key`
[INFO] [stdout]     --> src/mcp_lock.rs:3046:29
[INFO] [stdout]      |
[INFO] [stdout] 3046 | /// The result is sorted ([`McpDrift::sort_key`]). Privacy: entries carry only
[INFO] [stdout]      |                             ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `resolve_shortened_url` links to private item `MAX_REDIRECTS`
[INFO] [stdout]   --> src/network/shorturl.rs:30:67
[INFO] [stdout]    |
[INFO] [stdout] 30 | /// `None` for a non-shortener, a network failure, a chain over [`MAX_REDIRECTS`],
[INFO] [stdout]    |                                                                   ^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `resolve_shortened_url` links to private item `CACHE_TTL`
[INFO] [stdout]   --> src/network/shorturl.rs:32:30
[INFO] [stdout]    |
[INFO] [stdout] 32 | /// Results are cached for [`CACHE_TTL`].
[INFO] [stdout]    |                              ^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `from_basename` links to private item `launcher_basename`
[INFO] [stdout]   --> src/npm_command.rs:77:11
[INFO] [stdout]    |
[INFO] [stdout] 77 |     /// [`launcher_basename`] for that.
[INFO] [stdout]    |           ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `safe_suggestions` links to private item `redact_suggestion`
[INFO] [stdout]    --> src/output.rs:187:36
[INFO] [stdout]     |
[INFO] [stdout] 187 |     /// cross that contract. See [`redact_suggestion`].
[INFO] [stdout]     |                                    ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::registry_history::synthesize_transfer`
[INFO] [stdout]    --> src/package_risk.rs:241:20
[INFO] [stdout]     |
[INFO] [stdout] 241 |     /// lives in [`crate::registry_history::synthesize_transfer`], which sees the
[INFO] [stdout]     |                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `synthesize_transfer` in module `registry_history`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::registry_api::is_usable_repo_url`
[INFO] [stdout]    --> src/package_risk.rs:463:11
[INFO] [stdout]     |
[INFO] [stdout] 463 |     /// [`crate::registry_api::is_usable_repo_url`]).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `is_usable_repo_url` in module `registry_api`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `PolicyScope` links to private item `Policy::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:215:27
[INFO] [stdout]     |
[INFO] [stdout] 215 | /// tightening-only via [`Policy::sanitize_repo_scoped`]. Org/User/Remote/Default
[INFO] [stdout]     |                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `scope` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:297:11
[INFO] [stdout]     |
[INFO] [stdout] 297 |     /// [`Self::sanitize_repo_scoped`] (repo policies may only tighten).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `injection_seeds_custom` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:375:22
[INFO] [stdout]     |
[INFO] [stdout] 375 |     /// is KEPT by [`Self::sanitize_repo_scoped`] — never reset. Bad regexes are
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `mcp_redact_injection` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:396:47
[INFO] [stdout]     |
[INFO] [stdout] 396 |     /// default block), so this is RESET by [`Self::sanitize_repo_scoped`] — only
[INFO] [stdout]     |                                               ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gateway_profile` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:558:19
[INFO] [stdout]     |
[INFO] [stdout] 558 |     /// KEPT by [`Self::sanitize_repo_scoped`] — a repo may opt in but can never
[INFO] [stdout]     |                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralized_fields` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]    --> src/policy.rs:565:19
[INFO] [stdout]     |
[INFO] [stdout] 565 |     /// scoped, [`Self::sanitize_repo_scoped`] records here the YAML key name of
[INFO] [stdout]     |                   ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `require_complete` links to private item `Policy::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:1127:30
[INFO] [stdout]      |
[INFO] [stdout] 1127 |     /// it and it survives [`Policy::sanitize_repo_scoped`]. Default false.
[INFO] [stdout]      |                              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Self::discover_local_only`
[INFO] [stdout]     --> src/policy.rs:1313:7
[INFO] [stdout]      |
[INFO] [stdout] 1313 | /// [`Self::discover_local_only`] and, when it is `Some(Secure)`, fills any
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^ the enum `GatewayProfile` has no variant or associated item named `discover_local_only`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:1320:7
[INFO] [stdout]      |
[INFO] [stdout] 1320 | /// [`Self::sanitize_repo_scoped`] — a repo may opt INTO the secure profile but
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^^^^^^^^^^^ the enum `GatewayProfile` has no variant or associated item named `sanitize_repo_scoped`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `discover_local_only` links to private item `Self::discover_local`
[INFO] [stdout]     --> src/policy.rs:1653:12
[INFO] [stdout]      |
[INFO] [stdout] 1653 |     /// ([`Self::discover_local`]) + the incident override merge, but
[INFO] [stdout]      |            ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_trust_entries` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:2929:30
[INFO] [stdout]      |
[INFO] [stdout] 2929 |     /// `allowlist` field ([`Self::sanitize_repo_scoped`]) and the repo flat-
[INFO] [stdout]      |                              ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_org_lists` links to private item `Self::sanitize_repo_scoped`
[INFO] [stdout]     --> src/policy.rs:3029:11
[INFO] [stdout]      |
[INFO] [stdout] 3029 |     /// [`Self::sanitize_repo_scoped`]: the repo **blocklist** (a restriction) is
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AttestationOutcome`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AttestationOutcome`] encodes exactly this: every non-`Verified` variant is a
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AttestationOutcome` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `bind_subject_digest`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           bundle's in-toto statement names a SUBJECT digest. [`bind_subject_digest`]
[INFO] [stdout]                                                               ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `bind_subject_digest` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PublisherPolicy`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           ([`PublisherPolicy`]): an unexpected repository or workflow is a
[INFO] [stdout]             ^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `PublisherPolicy` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `AttestationOutcome::PublisherNotAllowed`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`AttestationOutcome::PublisherNotAllowed`]. An EMPTY allowlist means "no
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `AttestationOutcome` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              dependency decision outside this slice. [`NpmVerificationState`]
[INFO] [stdout]                                                       ^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState::PresentUnverified`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              therefore tops out at [`NpmVerificationState::PresentUnverified`] for a
[INFO] [stdout]                                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmVerificationState::VerificationUnavailable`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]              [`NpmVerificationState::VerificationUnavailable`] is the honest terminal
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmVerificationState` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NPM_AUDIT_SIGNATURES_CONTRACTS`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           So [`NPM_AUDIT_SIGNATURES_CONTRACTS`] is a fixed table: a version RANGE, the
[INFO] [stdout]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NPM_AUDIT_SIGNATURES_CONTRACTS` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmPartialReason::UnsupportedNpmVersion`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           outside every range returns [`NpmPartialReason::UnsupportedNpmVersion`]
[INFO] [stdout]                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmPartialReason` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NPM_CLEAN_IS_NOT_BENIGN_CAVEAT`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`NPM_CLEAN_IS_NOT_BENIGN_CAVEAT`] is part of the output, not decoration.
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NPM_CLEAN_IS_NOT_BENIGN_CAVEAT` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `bind_attested_subject`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`bind_attested_subject`] compares the sha512 subject digest inside an
[INFO] [stdout]            ^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `bind_attested_subject` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `NpmPackageStatus::Invalid`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           will install. That is the [`NpmPackageStatus::Invalid`] case that forces an
[INFO] [stdout]                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `NpmPackageStatus` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `parse_npm_version` links to private item `MAX_VERSION_TEXT_BYTES`
[INFO] [stdout]    --> src/provenance/npm.rs:197:7
[INFO] [stdout]     |
[INFO] [stdout] 197 | /// [`MAX_VERSION_TEXT_BYTES`], or a first line that is not a plain numeric
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `capped` links to private item `MAX_TREE_DIRECTORIES`
[INFO] [stdout]    --> src/provenance/npm.rs:950:62
[INFO] [stdout]     |
[INFO] [stdout] 950 |     /// True when the walk hit [`MAX_INSTALLED_PACKAGES`], [`MAX_TREE_DIRECTORIES`],
[INFO] [stdout]     |                                                              ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `unaccounted_locations` links to private item `MAX_REPORTED_UNACCOUNTED`
[INFO] [stdout]     --> src/provenance/npm.rs:1473:21
[INFO] [stdout]      |
[INFO] [stdout] 1473 |     /// The first [`MAX_REPORTED_UNACCOUNTED`] unaccounted locations, for the
[INFO] [stdout]      |                     ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `ArtifactScanReceipt` links to private item `crate::audit::log_artifact_scan_receipt`
[INFO] [stdout]    --> src/receipt.rs:399:8
[INFO] [stdout]     |
[INFO] [stdout] 399 | /// ([`crate::audit::log_artifact_scan_receipt`]). The chain line carries the
[INFO] [stdout]     |        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `looks_secret_shaped` links to private item `SECRET_SHAPE_PATTERNS`
[INFO] [stdout]    --> src/redact.rs:387:62
[INFO] [stdout]     |
[INFO] [stdout] 387 | /// token (OpenAI / AWS / GitHub / Anthropic / Slack — see [`SECRET_SHAPE_PATTERNS`]),
[INFO] [stdout]     |                                                              ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `contains_supported_secret` links to private item `analyze_supported_secrets`
[INFO] [stdout]    --> src/redact.rs:954:47
[INFO] [stdout]     |
[INFO] [stdout] 954 | /// Security-sensitive internal callers use [`analyze_supported_secrets`] to
[INFO] [stdout]     |                                               ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `TooLarge` links to private item `MAX_RESPONSE_BYTES`
[INFO] [stdout]    --> src/registry_api.rs:116:33
[INFO] [stdout]     |
[INFO] [stdout] 116 |     /// The response exceeded [`MAX_RESPONSE_BYTES`].
[INFO] [stdout]     |                                 ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `explain_config_risks` links to private item `check_agent_instructions`
[INFO] [stdout]     --> src/rules/aifile.rs:1326:28
[INFO] [stdout]      |
[INFO] [stdout] 1326 | /// Pure parsing; reuses [`check_agent_instructions`] + the tool-use classifier
[INFO] [stdout]      |                            ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `check` links to private item `USER_AGENTS`
[INFO] [stdout]    --> src/rules/cloaking.rs:187:69
[INFO] [stdout]     |
[INFO] [stdout] 187 | /// preflight, request dispatch, and redirect follow. The ordered [`USER_AGENTS`]
[INFO] [stdout]     |                                                                     ^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `custom_rule_dsl::clause_has_tier1_invisible_predicate`
[INFO] [stdout]    --> src/rules/custom.rs:282:8
[INFO] [stdout]     |
[INFO] [stdout] 282 | /// ([`custom_rule_dsl::clause_has_tier1_invisible_predicate`]), and (c) would
[INFO] [stdout]     |        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `clause_has_tier1_invisible_predicate` in module `custom_rule_dsl`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `any_semantic_only_dsl_rules_for_context` links to private item `parse_contexts`
[INFO] [stdout]    --> src/rules/custom.rs:304:7
[INFO] [stdout]     |
[INFO] [stdout] 304 | /// [`parse_contexts`] / [`custom_rule_dsl::resolve_runtime_contexts`] keeps it in
[INFO] [stdout]     |       ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `exfil` links to private item `might_contain_exfil`
[INFO] [stdout]   --> src/rules/exfil.rs:35:26
[INFO] [stdout]    |
[INFO] [stdout] 35 | //! A cheap pre-check ([`might_contain_exfil`]) returns immediately for clean text
[INFO] [stdout]    |                          ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `ScanContext::Paste`
[INFO] [stdout]   --> src/rules/paste_provenance.rs:13:45
[INFO] [stdout]    |
[INFO] [stdout] 13 | //! page. Fires from `engine::analyze` in [`ScanContext::Paste`] ONLY.
[INFO] [stdout]    |                                             ^^^^^^^^^^^^^^^^^^ no item named `ScanContext` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `CompiledSeeds` links to private item `SEEDS`
[INFO] [stdout]   --> src/rules/prompt_injection.rs:58:16
[INFO] [stdout]    |
[INFO] [stdout] 58 | /// built-in [`SEEDS`]. Produced by [`compile_seeds`] (e.g. from policy
[INFO] [stdout]    |                ^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compile_seeds` links to private item `classify`
[INFO] [stdout]    --> src/rules/prompt_injection.rs:113:34
[INFO] [stdout]     |
[INFO] [stdout] 113 | /// placeholder-substitution + [`classify`] logic as the built-in corpus. Good
[INFO] [stdout]     |                                  ^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `RulePanic` links to private item `catch_panic_scanning`
[INFO] [stdout]     --> src/scan.rs:1474:20
[INFO] [stdout]      |
[INFO] [stdout] 1474 | /// panic hook + [`catch_panic_scanning`]). Retained for back-compat; the guarded
[INFO] [stdout]      |                    ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `typed_events` links to private item `MAX_TYPED_EVENTS`
[INFO] [stdout]   --> src/session_warnings.rs:75:39
[INFO] [stdout]    |
[INFO] [stdout] 75 |     /// Off the hot path; capped to [`MAX_TYPED_EVENTS`].
[INFO] [stdout]    |                                       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `surfaced_correlations` links to private item `MAX_SURFACED_CORRELATIONS`
[INFO] [stdout]   --> src/session_warnings.rs:87:49
[INFO] [stdout]    |
[INFO] [stdout] 87 |     /// aged out (see [`correlate_session`]). [`MAX_SURFACED_CORRELATIONS`] is only a
[INFO] [stdout]    |                                                 ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_outcome` links to private item `with_session_locked`
[INFO] [stdout]     --> src/session_warnings.rs:1061:50
[INFO] [stdout]      |
[INFO] [stdout] 1061 | /// for `tirith warnings --hidden`. Atomic via [`with_session_locked`]; never
[INFO] [stdout]      |                                                  ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `record_executed_typed_events`
[INFO] [stdout]     --> src/session_warnings.rs:1190:21
[INFO] [stdout]      |
[INFO] [stdout] 1190 | /// should prefer [`record_executed_typed_events`] so events are appended only after
[INFO] [stdout]      |                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `record_executed_typed_events` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record_typed_event` links to private item `MAX_TYPED_EVENTS`
[INFO] [stdout]     --> src/session_warnings.rs:1193:7
[INFO] [stdout]      |
[INFO] [stdout] 1193 | /// [`MAX_TYPED_EVENTS`] (oldest dropped first).
[INFO] [stdout]      |       ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]      |
[INFO] [stdout]      = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `server_redirect_decision` links to private item `SERVER_MAX_REDIRECTS`
[INFO] [stdout]    --> src/ssrf_guard.rs:211:36
[INFO] [stdout]     |
[INFO] [stdout] 211 | /// 1. The hop count stays under [`SERVER_MAX_REDIRECTS`] — `prior_hops` is the
[INFO] [stdout]     |                                    ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `resolve_primary_path`
[INFO] [stdout]     --> src/threatdb.rs:1475:11
[INFO] [stdout]      |
[INFO] [stdout] 1475 |     /// [`resolve_primary_path`], which prefers the v2 file when present and
[INFO] [stdout]      |           ^^^^^^^^^^^^^^^^^^^^ no item named `resolve_primary_path` in scope
[INFO] [stdout]      |
[INFO] [stdout]      = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `0`
[INFO] [stdout]    --> src/trusted_child.rs:435:24
[INFO] [stdout]     |
[INFO] [stdout] 435 |     /// multicall argv[0] semantics (for example `cargo -> rustup`).
[INFO] [stdout]     |                        ^ no item named `0` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `is_public_addr` links to private item `classify_ip`
[INFO] [stdout]    --> src/url_validate.rs:271:7
[INFO] [stdout]     |
[INFO] [stdout] 271 | /// [`classify_ip`] is the single source of truth for the IANA special-purpose
[INFO] [stdout]     |       ^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `TrustedExecutable`
[INFO] [stdout]    --> src/util.rs:496:46
[INFO] [stdout]     |
[INFO] [stdout] 496 | /// string is gone: callers must resolve a [`TrustedExecutable`] first. Capture,
[INFO] [stdout]     |                                              ^^^^^^^^^^^^^^^^^ no item named `TrustedExecutable` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Constraint`
[INFO] [stdout]    --> src/version_intent.rs:301:40
[INFO] [stdout]     |
[INFO] [stdout] 301 |     /// A plain token is therefore a [`Constraint`] (matching resolves the real installed
[INFO] [stdout]     |                                        ^^^^^^^^^^ no item named `Constraint` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Exact`
[INFO] [stdout]    --> src/version_intent.rs:302:28
[INFO] [stdout]     |
[INFO] [stdout] 302 |     /// version), NOT an [`Exact`] pin. Only Cargo's `=` operator (`=1.0.0`) is an exact pin.
[INFO] [stdout]     |                            ^^^^^ no item named `Exact` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `compare_pep440_public_versions` links to private item `canonical_pep440_version`
[INFO] [stdout]    --> src/version_intent.rs:897:23
[INFO] [stdout]     |
[INFO] [stdout] 897 | /// grammar used by [`canonical_pep440_version`], including epochs, pre-releases,
[INFO] [stdout]     |                       ^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: redundant explicit link target
[INFO] [stdout]  --> src/intent.rs:8:16
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! [`RuleId`](crate::verdict::RuleId)), and `mismatches` (high-impact signals no
[INFO] [stdout]   |      --------  ^^^^^^^^^^^^^^^^^^^^^^ explicit target is redundant
[INFO] [stdout]   |      |
[INFO] [stdout]   |      because label contains path that resolves to same destination
[INFO] [stdout]   |
[INFO] [stdout]   = note: when a link's destination is not specified,
[INFO] [stdout]           the label is used to resolve intra-doc links
[INFO] [stdout]   = note: `#[warn(rustdoc::redundant_explicit_links)]` on by default
[INFO] [stdout] help: remove explicit link target
[INFO] [stdout]   |
[INFO] [stdout] 8 - //! [`RuleId`](crate::verdict::RuleId)), and `mismatches` (high-impact signals no
[INFO] [stdout] 8 + //! [`RuleId`]), and `mismatches` (high-impact signals no
[INFO] [stdout]   |
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]    --> src/policy.rs:413:54
[INFO] [stdout]     |
[INFO] [stdout] 413 |     /// URL of the centralized policy server (e.g., "https://policy.example.com").
[INFO] [stdout]     |                                                      ^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]     |
[INFO] [stdout]     = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout]     = note: `#[warn(rustdoc::bare_urls)]` on by default
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]     |
[INFO] [stdout] 413 |     /// URL of the centralized policy server (e.g., "<https://policy.example.com>").
[INFO] [stdout]     |                                                      +                          +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: redundant explicit link target
[INFO] [stdout]  --> src/registry_api.rs:8:23
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! [`ApiProvenance`](crate::package_risk::ApiProvenance) the factor model
[INFO] [stdout]   |      ---------------  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ explicit target is redundant
[INFO] [stdout]   |      |
[INFO] [stdout]   |      because label contains path that resolves to same destination
[INFO] [stdout]   |
[INFO] [stdout]   = note: when a link's destination is not specified,
[INFO] [stdout]           the label is used to resolve intra-doc links
[INFO] [stdout] help: remove explicit link target
[INFO] [stdout]   |
[INFO] [stdout] 8 - //! [`ApiProvenance`](crate::package_risk::ApiProvenance) the factor model
[INFO] [stdout] 8 + //! [`ApiProvenance`] the factor model
[INFO] [stdout]   |
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]  --> src/rules/credential.rs:9:5
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! https://github.com/sirwart/ripsecrets
[INFO] [stdout]   |     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]   |
[INFO] [stdout]   = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! <https://github.com/sirwart/ripsecrets>
[INFO] [stdout]   |     +                                     +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]   --> src/rules/credential.rs:12:5
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! https://github.com/gitleaks/gitleaks
[INFO] [stdout]    |     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]    |
[INFO] [stdout]    = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! <https://github.com/gitleaks/gitleaks>
[INFO] [stdout]    |     +                                    +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `role`
[INFO] [stdout]  --> src/rules/prompt_injection.rs:7:22
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! markers ("act as <role>", "you are now", "DAN mode"). Both are High severity.
[INFO] [stdout]   |                      ^^^^^^
[INFO] [stdout]   |
[INFO] [stdout]   = note: `#[warn(rustdoc::invalid_html_tags)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: this URL is not a hyperlink
[INFO] [stdout]   --> src/style.rs:13:6
[INFO] [stdout]    |
[INFO] [stdout] 13 | /// (https://no-color.org/ — presence alone disables, even if empty) and TTY.
[INFO] [stdout]    |      ^^^^^^^^^^^^^^^^^^^^^
[INFO] [stdout]    |
[INFO] [stdout]    = note: bare URLs are not automatically turned into clickable links
[INFO] [stdout] help: use an automatic link instead
[INFO] [stdout]    |
[INFO] [stdout] 13 | /// (<https://no-color.org/> — presence alone disables, even if empty) and TTY.
[INFO] [stdout]    |      +                     +
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `role`
[INFO] [stdout]    --> src/verdict.rs:305:58
[INFO] [stdout]     |
[INFO] [stdout] 305 |     /// M7 ch5 — a prompt-injection seed phrase ("act as <role>", "you are now",
[INFO] [stdout]     |                                                          ^^^^^^
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unclosed HTML tag `sensitive`
[INFO] [stdout]    --> src/verdict.rs:322:15
[INFO] [stdout]     |
[INFO] [stdout] 322 |     /// "read <sensitive path> … send/post/upload it" / "do not tell the user"
[INFO] [stdout]     |               ^^^^^^^^^^
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stderr]     Finished `dev` profile [unoptimized + debuginfo] target(s) in 51.33s
[INFO] [stderr]    Generated /opt/rustwide/target/doc/tirith_core/index.html
[INFO] running `Command { std: "docker" "inspect" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "rm" "-f" "c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8", kill_on_drop: false }`
[INFO] [stdout] c4fa13515d301ba990bbe102297389e642ec14306fefa8c111abd9a825c73bb8
