From 93100f950ca49dfdbf5c08bbf90a0272377fe49d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 19 Aug 2026 05:11:34 -0700 Subject: [PATCH 1/7] ci: refresh pinned branch coverage nightly --- .github/workflows/ci.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5f6b69dd..9182e13c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -223,13 +223,13 @@ jobs: printf 'TEST_DATABASE_URL=host=localhost user=postgres password=ci_%s_%s dbname=psychometrics_commons_test\n' \ "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" >> "$GITHUB_ENV" - name: Install pinned nightly with LLVM tools - run: rustup toolchain install nightly-2026-08-01 --profile minimal --component llvm-tools-preview + run: rustup toolchain install nightly-2026-08-18 --profile minimal --component llvm-tools-preview - name: Install pinned cargo-llvm-cov - run: cargo +nightly-2026-08-01 install cargo-llvm-cov --locked --version "$CARGO_LLVM_COV_VERSION" + run: cargo +nightly-2026-08-18 install cargo-llvm-cov --locked --version "$CARGO_LLVM_COV_VERSION" - name: Verify cargo-llvm-cov version - run: cargo +nightly-2026-08-01 llvm-cov --version | grep -F "$CARGO_LLVM_COV_VERSION" + run: cargo +nightly-2026-08-18 llvm-cov --version | grep -F "$CARGO_LLVM_COV_VERSION" - name: Generate branch coverage - run: cargo +nightly-2026-08-01 llvm-cov --branch --json --summary-only --output-path coverage-branches.json + run: cargo +nightly-2026-08-18 llvm-cov --branch --json --summary-only --output-path coverage-branches.json - name: Enforce complete branch coverage run: python3 scripts/check_coverage.py coverage-branches.json --kind branches - name: Diagnose missing branch coverage @@ -252,7 +252,7 @@ jobs: f"{file_entry.get('filename')}" ) PY - cargo +nightly-2026-08-01 llvm-cov report --branch --lcov --output-path coverage-branches.lcov + cargo +nightly-2026-08-18 llvm-cov report --branch --lcov --output-path coverage-branches.lcov python3 - <<'PY' from pathlib import Path From 8e78e1e6332eda10d8417e3a38f4b01083e8c0ec Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 19 Aug 2026 05:12:17 -0700 Subject: [PATCH 2/7] test: lock Rust compiler freshness contracts --- tests/ci_contract.rs | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/tests/ci_contract.rs b/tests/ci_contract.rs index b56306ef..f623afd8 100644 --- a/tests/ci_contract.rs +++ b/tests/ci_contract.rs @@ -1,6 +1,8 @@ //! Integration tests for repository CI evidence semantics. const CI_WORKFLOW: &str = include_str!("../.github/workflows/ci.yml"); +const RUST_TOOLCHAIN: &str = include_str!("../rust-toolchain.toml"); +const DEPENDABOT: &str = include_str!("../.github/dependabot.yml"); #[test] fn every_checkout_is_bound_to_the_pull_request_head() { @@ -100,8 +102,20 @@ fn line_coverage_failure_diagnostic_emits_machine_readable_annotations() { #[test] fn branch_coverage_failure_diagnostic_uses_lcov_branch_records() { assert!(CI_WORKFLOW.contains( - "cargo +nightly-2026-08-01 llvm-cov report --branch --lcov --output-path coverage-branches.lcov" + "cargo +nightly-2026-08-18 llvm-cov report --branch --lcov --output-path coverage-branches.lcov" )); assert!(CI_WORKFLOW.contains("raw_line.startswith(\"BRDA:\")")); assert!(CI_WORKFLOW.contains("taken in {\"0\", \"-\"}")); } + +#[test] +fn rust_toolchains_are_exact_and_reviewably_updated() { + assert!(RUST_TOOLCHAIN.contains("channel = \"1.97.1\"")); + assert!(!RUST_TOOLCHAIN.contains("channel = \"stable\"")); + + assert_eq!(CI_WORKFLOW.matches("nightly-2026-08-18").count(), 5); + assert!(!CI_WORKFLOW.contains("nightly-2026-08-01")); + + assert!(DEPENDABOT.contains("package-ecosystem: \"rust-toolchain\"")); + assert!(DEPENDABOT.contains("interval: \"weekly\"")); +} From 4436e484185fc85761e99d8543a8c92ee4d58405 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 19 Aug 2026 05:12:31 -0700 Subject: [PATCH 3/7] ci: track the pinned Rust toolchain --- .github/dependabot.yml | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..d331df5f --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,7 @@ +version: 2 +updates: + - package-ecosystem: "rust-toolchain" + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 1 From 14ac3219f5785efddcee1b73cfc5110b56008ec2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 19 Aug 2026 05:12:52 -0700 Subject: [PATCH 4/7] docs: record Rust toolchain freshness policy --- docs/doctoring/rust-toolchain-freshness.md | 29 ++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 docs/doctoring/rust-toolchain-freshness.md diff --git a/docs/doctoring/rust-toolchain-freshness.md b/docs/doctoring/rust-toolchain-freshness.md new file mode 100644 index 00000000..6b2ea1ba --- /dev/null +++ b/docs/doctoring/rust-toolchain-freshness.md @@ -0,0 +1,29 @@ +# Rust toolchain freshness + +Psychometrics Commons uses Rust `1.97.1` as its exact stable compiler baseline. +The project does not use a floating `stable` channel: a compiler transition is a +reviewed change that must preserve formatting, compilation, Clippy, tests, +rustdoc, PostgreSQL integration, and exact production coverage on one unchanged +head. + +Branch coverage uses `cargo-llvm-cov` 0.8.6 with the reproducible +`nightly-2026-08-18` toolchain because upstream Rust branch coverage remains +unstable and nightly-only. Installation, tool verification, coverage generation, +and missing-branch diagnostics use the same date pin. Repository contract tests +reject both the predecessor `nightly-2026-08-01` value and inconsistent partial +updates. + +GitHub Dependabot monitors the root `rust-toolchain.toml` through the +`rust-toolchain` package ecosystem. Stable compiler upgrades therefore arrive as +reviewable pull requests rather than silently changing CI behavior. + +## References + +GitHub. (2026). *Dependabot supports updates for Rust toolchains*. GitHub +Changelog. https://github.blog/changelog/ + +Rust Project Developers. (2026, July 16). *Announcing Rust 1.97.1*. Rust Blog. +https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/ + +Taiki Endo and contributors. (2026). *cargo-llvm-cov* (Version 0.8.6) +[Computer software]. GitHub. https://github.com/taiki-e/cargo-llvm-cov From 6626510e92efbdf6bbbd07bc129b80cc6a462bf6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 20 Aug 2026 06:56:04 -0700 Subject: [PATCH 5/7] test(ci): pin each Rust toolchain command --- tests/ci_contract.rs | 24 +++++++++++++++++++++--- 1 file changed, 21 insertions(+), 3 deletions(-) diff --git a/tests/ci_contract.rs b/tests/ci_contract.rs index f623afd8..5941c823 100644 --- a/tests/ci_contract.rs +++ b/tests/ci_contract.rs @@ -110,12 +110,30 @@ fn branch_coverage_failure_diagnostic_uses_lcov_branch_records() { #[test] fn rust_toolchains_are_exact_and_reviewably_updated() { + const STABLE_QUALITY_INSTALL: &str = + "rustup toolchain install 1.97.1 --profile minimal --component clippy --component rustfmt"; + const STABLE_COVERAGE_INSTALL: &str = + "rustup toolchain install 1.97.1 --profile minimal --component llvm-tools-preview"; + const NIGHTLY_COVERAGE_INSTALL: &str = + "rustup toolchain install nightly-2026-08-18 --profile minimal --component llvm-tools-preview"; + const NIGHTLY_LLVM_COV_INSTALL: &str = + "cargo +nightly-2026-08-18 install cargo-llvm-cov --locked --version \"$CARGO_LLVM_COV_VERSION\""; + const NIGHTLY_LLVM_COV_VERSION: &str = + "cargo +nightly-2026-08-18 llvm-cov --version | grep -F \"$CARGO_LLVM_COV_VERSION\""; + const NIGHTLY_BRANCH_JSON: &str = + "cargo +nightly-2026-08-18 llvm-cov --branch --json --summary-only --output-path coverage-branches.json"; + assert!(RUST_TOOLCHAIN.contains("channel = \"1.97.1\"")); assert!(!RUST_TOOLCHAIN.contains("channel = \"stable\"")); - - assert_eq!(CI_WORKFLOW.matches("nightly-2026-08-18").count(), 5); + assert!(CI_WORKFLOW.contains(STABLE_QUALITY_INSTALL)); + assert!(CI_WORKFLOW.contains(STABLE_COVERAGE_INSTALL)); + assert!(CI_WORKFLOW.contains(NIGHTLY_COVERAGE_INSTALL)); + assert!(CI_WORKFLOW.contains(NIGHTLY_LLVM_COV_INSTALL)); + assert!(CI_WORKFLOW.contains(NIGHTLY_LLVM_COV_VERSION)); + assert!(CI_WORKFLOW.contains(NIGHTLY_BRANCH_JSON)); assert!(!CI_WORKFLOW.contains("nightly-2026-08-01")); assert!(DEPENDABOT.contains("package-ecosystem: \"rust-toolchain\"")); + assert!(DEPENDABOT.contains("directory: \"/\"")); assert!(DEPENDABOT.contains("interval: \"weekly\"")); -} +} \ No newline at end of file From bc71223730b28e723fd1823964dec3b713b96c13 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 20 Aug 2026 06:56:28 -0700 Subject: [PATCH 6/7] docs(ci): cite exact Dependabot toolchain release --- docs/doctoring/rust-toolchain-freshness.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/doctoring/rust-toolchain-freshness.md b/docs/doctoring/rust-toolchain-freshness.md index 6b2ea1ba..a8d5c9d6 100644 --- a/docs/doctoring/rust-toolchain-freshness.md +++ b/docs/doctoring/rust-toolchain-freshness.md @@ -19,11 +19,11 @@ reviewable pull requests rather than silently changing CI behavior. ## References -GitHub. (2026). *Dependabot supports updates for Rust toolchains*. GitHub -Changelog. https://github.blog/changelog/ +GitHub. (2025, August 19). *Dependabot now supports Rust toolchain updates*. +GitHub Changelog. https://github.blog/changelog/2025-08-19-dependabot-now-supports-rust-toolchain-updates/ Rust Project Developers. (2026, July 16). *Announcing Rust 1.97.1*. Rust Blog. https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/ Taiki Endo and contributors. (2026). *cargo-llvm-cov* (Version 0.8.6) -[Computer software]. GitHub. https://github.com/taiki-e/cargo-llvm-cov +[Computer software]. GitHub. https://github.com/taiki-e/cargo-llvm-cov \ No newline at end of file From 2d500c30f3a49ad186ebc8191ebfa70d4678aace Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 20 Aug 2026 08:36:20 -0700 Subject: [PATCH 7/7] style(ci): restore rustfmt trailing newline --- tests/ci_contract.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/ci_contract.rs b/tests/ci_contract.rs index 5941c823..6e8de03d 100644 --- a/tests/ci_contract.rs +++ b/tests/ci_contract.rs @@ -136,4 +136,4 @@ fn rust_toolchains_are_exact_and_reviewably_updated() { assert!(DEPENDABOT.contains("package-ecosystem: \"rust-toolchain\"")); assert!(DEPENDABOT.contains("directory: \"/\"")); assert!(DEPENDABOT.contains("interval: \"weekly\"")); -} \ No newline at end of file +}