Skip to content

ci: fix the CI jobs that fail on every master run #40

ci: fix the CI jobs that fail on every master run

ci: fix the CI jobs that fail on every master run #40

Workflow file for this run

name: CI
# Quality gate for master. Runs the same checks contributors run locally
# (see the README "Contributing" section): formatting + clippy + crate-DAG
# cycles via `cargo xtask ci`, the workspace test suite, and the supply-chain
# gate (cargo-deny + cargo-audit). An extra `msrv` job enforces the 1.88 floor
# from ADR-0001.
on:
push:
branches: [master]
pull_request:
branches: [master]
# Least privilege: the workflow only reads repository contents.
permissions:
contents: read
# Cancel superseded runs for the same ref so re-pushes do not stack jobs.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
env:
CARGO_TERM_COLOR: always
# `RUSTC_WRAPPER: sccache` routes rustc through sccache and stores the cache in
# the GitHub Actions cache. It is set per job, only where
# `mozilla-actions/sccache-action` installs the binary: `cargo deny` runs
# `cargo metadata`, which invokes `rustc -vV`, so a wrapper without the binary
# fails the `deny` job.
jobs:
# fmt + clippy (-D warnings) + workspace DAG cycle check.
quality:
name: Format, lint & cycles
runs-on: ubuntu-latest
timeout-minutes: 15
env:
RUSTC_WRAPPER: sccache
SCCACHE_GHA_ENABLED: "true"
steps:
- uses: actions/checkout@v4
- name: Install stable toolchain (rustfmt + clippy)
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- name: Run sccache-cache
uses: mozilla-actions/sccache-action@v0.0.11
- uses: Swatinem/rust-cache@v2
- name: cargo xtask ci
run: cargo xtask ci
# Full workspace test suite. The default feature set needs no Docker; the
# Docker-backed `integration` feature is exercised separately in a later
# milestone (it requires a running daemon).
test:
name: Test (workspace)
runs-on: ubuntu-latest
timeout-minutes: 30
env:
RUSTC_WRAPPER: sccache
SCCACHE_GHA_ENABLED: "true"
steps:
- uses: actions/checkout@v4
- name: Install stable toolchain
uses: dtolnay/rust-toolchain@stable
- name: Run sccache-cache
uses: mozilla-actions/sccache-action@v0.0.11
- uses: Swatinem/rust-cache@v2
# The scaffold compile gate (`crates/rustasea-scaffold/tests/generated_compiles.rs`)
# runs `cargo check --offline` on every generated starter kit, and the
# WASM variants need crates that the host build never downloads. Fetch
# every locked crate, for every target, before the tests run.
- name: cargo fetch
run: cargo fetch
# `--no-fail-fast` reports every failing test in one run instead of
# stopping at the first failing test binary.
- name: cargo test
run: cargo test --workspace --no-fail-fast
# Supply-chain gate: license allow-list, advisory database, banned crates and
# source provenance (configuration in deny.toml).
deny:
name: cargo-deny
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- name: Install cargo-deny
uses: taiki-e/install-action@v2
with:
tool: cargo-deny
- name: cargo deny check
run: cargo deny check
# RustSec advisory scan. Required (not advisory): a known vulnerability must
# fail the build. Unpatchable advisories are allow-listed with a documented
# reason in deny.toml; cargo-audit reads .cargo/audit.toml when present.
audit:
name: cargo-audit
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- name: Install cargo-audit
uses: taiki-e/install-action@v2
with:
tool: cargo-audit
- name: cargo audit
run: cargo audit
# Enforce the MSRV floor (ADR-0001: rustc 1.88). CI otherwise runs stable;
# this job pins 1.88.0 so an accidental use of a newer API fails the build.
msrv:
name: MSRV (1.88.0)
runs-on: ubuntu-latest
timeout-minutes: 15
env:
RUSTC_WRAPPER: sccache
SCCACHE_GHA_ENABLED: "true"
steps:
- uses: actions/checkout@v4
- name: Install Rust 1.88.0
uses: dtolnay/rust-toolchain@1.88.0
- name: Run sccache-cache
uses: mozilla-actions/sccache-action@v0.0.11
- uses: Swatinem/rust-cache@v2
- name: cargo check (MSRV)
run: cargo check --workspace