Repository navigation
ci: record Cargo-Rail planning evidence - #49
Merged
Merged
Conversation
Add a "Planning evidence" job to the Check workflow. It runs on push to main and on manual dispatch. It records which workspace files the cargo.build and cargo.clippy work items read, and saves the record in the Actions cache under the commit it describes. Both plan jobs now install the stable toolchain, restore the evidence of the base commit, and pass it to the planner. A change that no compiler reads, such as a Markdown edit, then skips the Rust jobs. A cache miss only widens the plan. The evidence binds the Cargo environment. Move RUSTFLAGS from the Check workflow env to the jobs that install mold, so that the evidence job and both plan jobs see the same Cargo environment. The crate has no Rust tests, so route on cargo.build in place of cargo.test. Note in Cargo.toml that the cdylib has no Rust doctests.
Clippy evidence is always incomplete under Cargo-Rail 0.30.1. The clippy::cargo lints run cargo metadata, and the recorder cannot represent that run's target probe. Stop recording it, and stop installing the clippy component in the evidence and plan jobs. The planner fails when the evidence directory does not exist. Create the directory after the cache restore, so that a cache miss only widens the plan.
Remove the since inputs. The v10 Action already compares a push with its previous commit and a pull request with its merge base. Plan every work item on manual dispatch, because the planner cannot resolve HEAD~1 of a branch other than the default branch in a shallow clone. Do not persist checkout credentials in the plan and evidence jobs. Record the build with --locked. Keep only the workflows and the Cargo-Rail policy in the ci work item. Move .taplo.toml to a taplo work item that routes only the Format job. Remove the Makefile, because no CI job reads it.
The Format job runs taplo validate, which also checks pyproject.toml. A change to only pyproject.toml selects the python work item, so the Format job must route on it.
Cargo-Rail has no complete evidence for cargo.clippy, cargo.doc, or cargo.doctest, so jobs that route on them never skip. The crate has no doc or doctest cfg gates, and the Clippy job checks only the library. Route Clippy and Documentation on cargo.build, whose evidence covers the same compiler inputs. Remove the workflow_dispatch trigger from the Check workflow. Record evidence only on push. Plan every item on a scheduled or manual Quality run, and remove the event clauses from the Clippy condition. Restore evidence only on push and pull request events, because an empty base SHA makes the key match evidence of an unrelated commit. Give the plan and evidence jobs read-only contents permission. Remove the jq print, which could skip the save step. Add rust-cache to the evidence job. Make mold the default linker and delete the job-level RUSTFLAGS. .cargo/config.toml already sets the target CPU. Check TOML formatting with taplo fmt --check. Add pyproject.toml to the taplo item, and route Format on taplo in place of python.
maturin reads both files when it builds the wheel, so a change to either one must run the Python jobs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
The Rust jobs in this repository now skip changes that no compiler reads. Before this change, Cargo-Rail could not tell which files the crate compiles from, so a Markdown edit still required every Rust job.
A new
Planning evidencejob in the Check workflow builds the crate throughcargo rail plan evidence. The recorder notes each file that the compiler reads. The job saves the record in the Actions cache under the commit that it built. It runs on every push tomain. It never runs on pull requests, so it is not a required check.Both plan jobs restore the evidence of the base commit on push and pull request events and pass it to the planner. When no recorded input changed, the planner skips
cargo.build. A cache miss or a stale record only widens the plan, so the result is never less safe than today.Job routing
Cargo-Rail has no complete evidence for
cargo.clippy,cargo.doc, orcargo.doctest. Jobs that route on them never skip. The crate has nocfg(doc)orcfg(test)code, and the Clippy job checks only the library, so Clippy and Documentation read the same source files as the build. These jobs now route oncargo.build, whose evidence covers the same compiler inputs.Clippy evidence is not recorded, because Cargo-Rail 0.30.1 marks it incomplete when the
clippy::cargolints runcargo metadata.The crate has no Rust tests, and no job runs
cargo test. The jobs that compile the extension route oncargo.buildin place ofcargo.test. A note inCargo.tomlrecords that thecdylibcrate has no Rust doctests, because the Python tests cover the bindings.Work items
The
ciwork item now holds only the workflows and.config/rail.toml. A newtaplowork item holds.taplo.tomlandpyproject.toml, and routes the Format job. The Format job now runstaplo fmt --checkin place oftaplo validate. TheMakefileleavesci, because no CI job reads it. Thepythonwork item now also holdsReadme.mdandLICENSE, because maturin reads both files when it builds the wheel.Planner and job settings
The plan jobs no longer pass
since. The v10 Action already compares a push with its previous commit and a pull request with its merge base. A scheduled or manual Quality run plans every work item. The plan and evidence jobs have read-only contents permission and do not keep the checkout credentials.The evidence is valid only for the same Cargo configuration, which includes
RUSTFLAGSand theCARGO_*variables. The Check workflow setRUSTFLAGSwith-fuse-ld=moldfor every job. The jobs that install mold now make it the default linker, andRUSTFLAGSis gone..cargo/config.tomlalready sets the target CPU. The evidence job and both plan jobs now see the same Cargo environment.Cost
The evidence job compiles the crate on every push to
main. It uses the Rust cache, so a warm cache makes the run short.