Sign in

Predrag Gruevski

@predr.ag
1.9K followers 387 following 661 posts

Querying (Almost) Everything // Frontier Systems @ OpenAI // Author of cargo-semver-checks & Trustfall // predr.ag/blog // ex Kensho // MIT alum // hachyderm.io/@predrag // not from around here 🇲🇰 // he-him

PostsRepliesMedia
Reposted by Predrag Gruevski
Marco Ieni @ieni.dev · 12h
I’m now team leader of the Rust Infrastructure team! I’ll keep shipping, but I’ll also pay more attention to the load, health, and overall direction of the team.
https://rust-lang.org/governance/teams/infra/
3717
Reposted by Predrag Gruevski
The Rust Foundation @rustfoundation.org · 28/09/2026
Join Symposium Co-Creators @nikomatsakis.com & Jack Huey and @orhun.dev of @jetbrains.com on Oct 1 to talk about coding agents that write reliable, idiomatic Rust! Register: info.jetbrains.com/rustrover-li... Read more: rustfoundation.org/event/livest...
info.jetbrains.com
Live Webinar - Smarter Coding Agents for Rust with Symposium
Discover how Rust and AI can make each other better and how Symposium gives coding agents the crate-aware skills, tools and workflows they need to write more reliable Rust.
072
Reposted by Predrag Gruevski
rev. howard arson @theophite.bsky.social · 27/09/2026
yes, i am saying this. literally this. i am saying that you should not care about water for 16,000 people when "growing alfalfa for export in deserts with approximately zero precipitation" is literally orders of magnitude more water and vastly more pointless.
3198492
Predrag Gruevski @predr.ag · 21/09/2026
I keep saying, big SemVer is always hard at work adding more SemVer 😆 Little-known fact, I wrote a cargo-semver-checks equivalent for Python, and it could handle both positional and keyword arguments, including their "only / both" flavors. It was kind of amazing how many footguns were in there.
1101
Predrag Gruevski @predr.ag · 21/09/2026
This security issue, and ones yet to come, all require a team effort. I'm proud of Rustaceans' willingness to lead with urgency and repeatedly choose a "fall into the pit of success" approach. Knowing that the language, toolchain, and community have my back is why I love being here 🦀
060
Predrag Gruevski @predr.ag · 21/09/2026
In response, the Codex team and I have been working to equip the defenders with the best tools. On top of Codex for OSS with our latest models, we've also extended tens of thousands of dollars' worth of API credits to Rust's security professionals. As a start. There's more to be done.
180
Predrag Gruevski @predr.ag · 21/09/2026
Lately I've been doing Rust ecosystem security work. GPT-6 Astra is an extraordinary tool for detecting bugs, unsoundness, and security vulnerabilities. *Everything* is buggy, it turns out. blog.rust-lang.org/2026/09/21/g...
blog.rust-lang.org
GitHub Actions leaking secrets when Miri output is cached | Rust Blog
Empowering everyone to build reliable and efficient software.
181
Predrag Gruevski @predr.ag · 21/09/2026
GitHub Actions + Rust's Miri can leak your secrets in CI 🧵 If you run Miri in CI: - upgrade to the 2026-09-22 nightly - clear caches - rotate any secrets that the `cargo miri` CI job had access to GPT-6 Astra helped find this 🦀
GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing cache poisoning). Rust projects tend to speed up CI by caching binaries built by cargo install and sometimes the contents of target/.

PR CI can be triggered by anyone who can open PRs on your repository. GitHub requires maintainer approval for the first PR, but future PRs will rerun CI on every push. Anyone who has previously landed a change can trigger a CI run extracting information from cached target/ and then cover their tracks by pushing a second commit to the PR.

GitHub sometimes hides overwritten commits in its UI, making this kind of attack harder to detect. CI run logs and overwritten commits are also deleted after a few months.

When cargo miri is invoked, Miri needs to retain build-relevant environment variables between runs. The current code to do so achieves this by storing all environment variables to target/. This, of course, persists when target/ is cached.

If your environment contained secrets, these can now be accessed by PRs via the cache.
1389
Predrag Gruevski @predr.ag · 16/09/2026
Jokes aside, genuinely happy for you. Good luck in the new role!
110
Predrag Gruevski @predr.ag · 16/09/2026
If that's the only blocker I'm paging a hiring manager right now :)
120
Predrag Gruevski @predr.ag · 16/09/2026
We could! The pets API is pluggable, and my wife made a whole personalized collection of them pixelwood-adoption-center.malenagruevski.chatgpt.site
pixelwood-adoption-center.malenagruevski.chatgpt.site
Pixelwood Adoption Center
Meet, play with, and adopt a ChatGPT pet from a cozy retro pixel-art adoption center.
120
Predrag Gruevski @predr.ag · 16/09/2026
Congrats! But we have crab too, you could have called 😆
150
Predrag Gruevski @predr.ag · 16/09/2026
it's not devoops unless it has 9 5s of availability
020
Predrag Gruevski @predr.ag · 13/09/2026
I'm lazy and just make the agent make the representative local setup on its own when needed. I've got other things to do etc. YMMV of course.
000
Predrag Gruevski @predr.ag · 13/09/2026
A good agent (Sol, Astra, etc.) can do this on its own in my experience.
110
Predrag Gruevski @predr.ag · 13/09/2026
If this wouldn't burn all my GitHub Actions credits I totally would. Or is there a way to do it that won't do that? 👀
200
Predrag Gruevski @predr.ag · 13/09/2026
When this works perfectly 2-3 times in a row: - have it automatically open a PR with the fix - have it watch CI and trigger this automatically on flaky-looking failures You made an AI loop to eliminate flaky tests. Congratulations!
110
Predrag Gruevski @predr.ag · 13/09/2026
AI loops 101 in two posts: When CI fails with on a flaky test, send this to your agent: "a test failed in a flaky fashion, please figure out why and propose a pragmatic path forward: <CI link>"
220
Predrag Gruevski @predr.ag · 12/09/2026
I would have loved to, but sadly no. Flying the other way next week for a different event.
100
Predrag Gruevski @predr.ag · 12/09/2026
RustConf was great 🎉 Now Rust ➡️ Rest, at least for 36h or so. Then, Rust again 🦀
1150
Predrag Gruevski @predr.ag · 05/09/2026
My 2c: genuinely caring is brutal but it's also one's greatest strength. People who genuinely care about both people and quality are irreplaceable and in short supply. No amount of AI will fix that.
040
Predrag Gruevski @predr.ag · 05/09/2026
Easy yes. Improving them is a one-off that saves tokens for everyone, indefinitely.
0140
Predrag Gruevski @predr.ag · 01/09/2026
👀
000
Predrag Gruevski @predr.ag · 01/09/2026
New programming book arrived in the mail 👀 There's never been a better time to think deeply about the structure behind the code we cause to exist.
Logic for Programmers, a book by Hillel Wayne
1446
Predrag Gruevski @predr.ag · 28/08/2026
Also, I can confirm the hero was properly wined and dined, the two of us met up for dinner last night 😆
170
Predrag Gruevski @predr.ag · 28/08/2026
I have about half a dozen PRs with `[perf]` in the title if you'd like to see concrete examples. I have about 30 more things sitting in local branches, waiting for me to clean up the code and make a PR.
140
Predrag Gruevski @predr.ag · 28/08/2026
I got a shout out in the weekly post on next trait solver progress for an up to 7.5% speedup ... by deleting one unnecessary line of code 😆 There are absolutely more of these opportunities, and I've built a method for finding them at some scale. Need. More. Time. 😅
140
Predrag Gruevski @predr.ag · 28/08/2026
I use unit for true and never for false. Why would I write code that's false? Do I look like a liar?
150
Predrag Gruevski @predr.ag · 28/08/2026
This change by Noah Lev will probably save a zillion dollars in docs\.rs and CI jobs everywhere. Really nice work! noahlev.org/blog/2026/08...
noahlev.org
How I made Rustdoc 25% faster in one week - Noah Lev Bartell-Mangel
From a "weird bug" to massive speedups
1354
Predrag Gruevski @predr.ag · 27/08/2026
More good news: Jess Izen is stepping into an Engineer in Residence role with the Rust Foundation! She's done so much good work for the ecosystem already (see the post!) and I can't think of a better person to wear this hat 🦀 rustfoundation.org/media/welcom...
rustfoundation.org
Welcoming Jess Izen as Engineer in Residence at the Rust Foundation
The Rust Foundation is pleased to welcome Jess Izen (@jlizen) as our new Engineer in Residence. For the next year, Jess will work full time as part of the Foundation’s engineering team, taking directi...
0213
Predrag Gruevski @predr.ag · 26/08/2026
bummer! next time then
030
Predrag Gruevski @predr.ag · 26/08/2026
I would also read that! @mattkeeter.com I'll bring some `unsafe` to RustConf if you need help getting it out of Steve 🤣
150
Predrag Gruevski @predr.ag · 26/08/2026
The first batch of Rust maintainers in residence has been announced! A lot of Rust will get even more love and attention: clippy, rustup, rustdoc, Windows support, standard library, and compiler internals 💖🦀
0171
Reposted by Predrag Gruevski
The Rust Foundation @rustfoundation.org · 26/08/2026
Announcing the 1st cohort of Rust Maintainers in Residence! Thanks to contributions from Google, AWS, & OpenAI, the Rust Foundation and Rust Project have raised $350K to fund 6 contributors on Rustup, Clippy, compiler, stdlib, & rustdoc 🦀 Read announcement: rustfoundation.org/media/rust-p...
rustfoundation.org
Rust Project and Rust Foundation Announce First Maintainers in Residence
New program directs $350,000 toward maintainers supporting critical Rust infrastructure DOVER, Delaware, USA – August 26, 2026 – The Rust Project and Rust Foundation today announced the inaugural coho...
1286
Reposted by Predrag Gruevski
waffle .-. @waffle.pet · 25/08/2026
blog.ihatereality.space/0C-never-type/
blog.ihatereality.space
I stabilized never type | I hate reality
yeah
2122737
Predrag Gruevski @predr.ag · 23/08/2026
Yes, I would strongly support a mechanism like this being built upstream!
000
Predrag Gruevski @predr.ag · 23/08/2026
Np, happy to help! Please feel free to ping me with any follow-up questions too — security improvements help everyone so I'll do anything I can do to help.
011
Predrag Gruevski @predr.ag · 23/08/2026
I iterated on this with GPT-5.6 Sol to try to close as many gaps as I could. It came up with a lot of interesting ways to sneak changes in, and we then plugged everything we could. I've found it really helpful to have a "please do an adversarial review of this change" ability available on-demand!
260
Predrag Gruevski @predr.ag · 23/08/2026
Adding a build script now requires adding an exception line to a special file, including a hash and path to the build script. `[package] build = ..` values are banned under this policy, so all build scripts must be `build.rs` and therefore subject to the hash check. github.com/obi1kenobi/c...
github.com
Add a build-script policy with hashes for allowed build scripts. by obi1kenobi · Pull Request #1706 · obi1kenobi/cargo-semver-checks
Adding a build script anywhere in the repo requires registering an exception, which will make that change much more obvious during code review and will make it harder for malicious changes to &quot...
120
Predrag Gruevski @predr.ag · 23/08/2026
For the repos only. I'd be interested in similar functionality in cargo for deps though. My repos like cargo-semver-checks and trustfall-rustdoc-adapter have hundreds of test crates, with more added for ~every new lint. I want to make it maximally "loud" if a PR adds a build script in one of them.
110
Predrag Gruevski @predr.ag · 23/08/2026
I'm updating my Rust projects to harden them against supply chain attacks: - explicit allowlist of hashes for build scripts in the project - `min-publish-age` of 7 days for deps updates, using the nightly cargo feature - ensure no jobs that could run a build script have GH tokens
2430
Reposted by Predrag Gruevski
Pete 🙆‍♂️ @petelevasseur.com · 16/08/2026
super duper cool to have @nia.is.fckn.gay of Hexcat to the @sdv.eclipse.org's @rust-lang.org special interest group this tuesday! chattin bout "Stable allocators, one unsoundness at a time" it's at 7am PDT / 10am EDT / 6pm CEST / 11pm JST =) wanna join? `.ics` is below
screenshot showing Nia Deckers' chat this on August 18, 2026 for "Stable allocators, one unsoundness at a time"
1153
Predrag Gruevski @predr.ag · 16/08/2026
Rust CI now runs cargo-semver-checks to prevent accidental breakage in the standard library 🦀 If you're wondering why that's important and why it took 15kLoC+, this post is for you. predr.ag/blog/protect...
predr.ag
Protecting the Rust standard library from accidental breakage
How & why we're running cargo-semver-checks in Rust's CI
06011
Reposted by Predrag Gruevski
Steve Klabnik @steveklabnik.com · 14/08/2026
I am very happy to announce that I have gotten a paper accepted to PLSS 2026: LLMs as Collaborators in Language Specification and Design conf.researchr.org/details/spla...
conf.researchr.org
LLMs as Collaborators in Language Specification and Design (PLSS 2026) - SPLASH/ISSTA 2026
Workshop on Programming Language Standardization and Specification This workshop aims to foster cross-pollination between researchers and industry professionals with experience in programming language...
161979
Predrag Gruevski @predr.ag · 14/08/2026
no no I think you meant why doesn't rust simply *just* add comptime gotta pair up the load-bearing words so they don't get lonely
150
Predrag Gruevski @predr.ag · 08/08/2026
"You fixed something — your change made a program compile when it shouldn't have — and that's proof your API has a major breaking change" @lorilorusso.bsky.social interviewed me to understand how cargo-semver-checks will catch breakage in your traits and types www.youtube.com/watch?v=38h2...
youtube.com
RustWeek Interview: Predrag Gruevski, Maintainer of cargo-semver-checks
YouTube video by Rust Programming Language
050
Reposted by Predrag Gruevski
Michal Piotrowski 🦀 @practicalrs.bsky.social · 04/08/2026
blog.rust-lang.org/2026/08/04/e...
blog.rust-lang.org
Enabling the next iteration of the borrow checker on nightly | Rust Blog
Empowering everyone to build reliable and efficient software.
0144
Predrag Gruevski @predr.ag · 01/08/2026
With any luck, this is the cargo-semver-checks release that will start scanning the Rust standard library for breakage. Enjoy v0.50.0! What a fitting moment for a nice round number 🎉 Expect a blog post soon!
cargo-semver-checks v0.50.0 release notes.

- Support for rustdoc JSON v61 for the latest nightly Rust
- One new lint: `auto_trait_impl_added`
- Bugfix in `constructible_struct_adds_field` to properly account for existing `pub` but `#[doc(hidden)]` fields.
- Support for parsing rustdocflags from `.cargo/config.toml` and some minor bugfixes
- Thanks to @taiki-e for accepting our upstream patches and promptly releasing them in `cargo-config2` so we can use them!
0453
Predrag Gruevski @predr.ag · 01/08/2026
Every year, RustWeek and the All Hands meeting of the Rust Project are the most productive few days Rust ever gets. An unbelievable amount of stuff gets done. And now you can read all about it! blog.rust-lang.org/inside-rust/...
blog.rust-lang.org
All Hands 2026 retrospective | Inside Rust Blog
Want to follow along with Rust development? Curious how you might get involved? Take a look!
070
Predrag Gruevski @predr.ag · 31/07/2026
If you use the Trustfall query engine via Python, please upgrade to v0.3.2. In v0.1.6 - 0.3.1, using the exposed APIs in a sufficiently contrived manner could trigger use-after-free. Your code *probably didn't do this*, but I yanked the affected versions to be safe. github.com/obi1kenobi/t...
github.com
Fix unsound `Opaque` in Python bindings. by obi1kenobi · Pull Request #960 · obi1kenobi/trustfall
Python adapters that broke the API contract in copying contexts and returning them more than once could cause a use-after-free / double-free bug. With this fix, this is explicitly checked for and w...
050