export: public tree rebuilt from 201a801 #89
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ci | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| # Two reasons, and the second one was an accident that earned its keep. | |
| # | |
| # The stated one: the advisory database moves without anyone committing here, | |
| # so `deny` has to run on a clock -- otherwise a fresh RUSTSEC entry stays | |
| # unseen until the next unrelated pull request. | |
| # | |
| # The one found in practice (2026-08-17): the schedule runs the WHOLE | |
| # workflow, so the suite is executed weekly against a commit nobody touched. | |
| # That is the only thing in this project that can catch a flaky test after | |
| # the fact -- a push-triggered run tests a change, and a change that passes | |
| # once looks settled. The first scheduled run ever found a repair from the | |
| # night before that had swapped one race for a subtler one. Keep it whole; | |
| # narrowing this to the `deny` job would save minutes and lose that. | |
| schedule: | |
| - cron: "17 5 * * 1" | |
| # A red scheduled run needs a second opinion, and asking for one should not | |
| # require an empty commit. Without this, the only way to re-test the exact | |
| # commit the cron tripped on is to push something -- which changes the thing | |
| # under test. (Found the hard way on 2026-08-17.) | |
| workflow_dispatch: | |
| env: | |
| CARGO_TERM_COLOR: always | |
| # The public test suite compiles 400+ test binaries; with debuginfo the | |
| # target tree outgrows the 14 GB a hosted runner has free (W13: the run | |
| # died on ENOSPC in the middle of the build). Tests do not need line info. | |
| CARGO_PROFILE_DEV_DEBUG: 0 | |
| CARGO_PROFILE_TEST_DEBUG: 0 | |
| jobs: | |
| linux: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: Swatinem/rust-cache@v2 | |
| - name: fmt | |
| run: cargo fmt --check | |
| - name: clippy | |
| run: cargo clippy --workspace --all-targets -- -D warnings | |
| - name: test | |
| run: cargo test --workspace | |
| windows: | |
| runs-on: windows-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: Swatinem/rust-cache@v2 | |
| - name: check | |
| run: cargo check --workspace | |
| # The rules that used to live only in a document and in somebody's memory. | |
| gates: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: Swatinem/rust-cache@v2 | |
| # Two frozen function bodies in crates/meclaw-colony/src/colony.rs, | |
| # byte-compared against their reference under .github/fixtures/. | |
| - name: corridor byte gates | |
| run: .github/gates/corridor_byte_gates.sh | |
| # CONTRIBUTING bans unwrap()/expect() outside tests. The clippy lints for | |
| # it are allow-by-default, so `-D warnings` above never saw them. This | |
| # pins the existing count per package and fails when it grows. | |
| - name: unwrap/expect budget | |
| run: python3 .github/gates/unwrap_budget.py | |
| # GH #234 -- two gates USED to stand here: `build_librarian_seed.py | |
| # --check` (GH #205) and `build_builder_hive.py --check` (GH #217), | |
| # guarding the two committed trees that are generated. Do not put them | |
| # back. Both generators live under workshop/, which is not part of this | |
| # tree and is not meant to be, so the steps could not pass here -- they | |
| # failed on a missing file, which says nothing about whether the artifacts | |
| # drifted. | |
| # | |
| # They now run where their sources are: as R11 of the release gate, in the | |
| # tree that has workshop/, before an export is built. The shipped Rust | |
| # twins (librarian_seed_corpus.rs, builder_hive_template_tree.rs) cover | |
| # this clone and skip when no generator is present -- which here is | |
| # always, so a green run of theirs asserts nothing about the corpus. That | |
| # is intentional: the assertion belongs to the tree that can make it. | |
| deny: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # Deterministic half: a verdict that depends only on this commit's | |
| # Cargo.lock and deny.toml. Blocking. | |
| - name: bans, licenses, sources | |
| uses: EmbarkStudios/cargo-deny-action@v2 | |
| with: | |
| command: check bans licenses sources | |
| # Time-dependent half: RUSTSEC advisories and crates.io yank state change | |
| # under a commit that never moved, so a red here is a report, not a | |
| # verdict on the pull request. It is deliberately not blocking; the | |
| # advisories standing open today are tracked in GH #127 (GH #115 is | |
| # where the split was decided). | |
| - name: advisories (reporting only) | |
| continue-on-error: true | |
| uses: EmbarkStudios/cargo-deny-action@v2 | |
| with: | |
| command: check advisories |