Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/actions/install-cargo-component/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: Install cargo-component
description: Install cargo-component using a precompiled binary (taiki-e/install-action).

# Replaces ad-hoc `cargo install cargo-component --locked || true` calls. The
# precompiled-binary path takes a few seconds vs. several minutes for a source
# install, and we no longer swallow install failures.

runs:
using: composite
steps:
- name: Install cargo-component
uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
with:
tool: cargo-component

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To ensure build reproducibility and avoid unexpected CI failures when a new version of cargo-component is released, consider pinning the tool to a specific version (e.g., cargo-component@0.20.0). This aligns with the project's practice of using --locked for deterministic builds, as seen in the local setup scripts. Without a version specifier, install-action will fetch the latest available version, which may introduce non-deterministic behavior in the build process.

References
  1. When applying a best practice, such as using --locked for reproducible builds, it should be applied consistently across the codebase. Pinning tool versions in CI is the equivalent best practice for binary installers to ensure a deterministic environment.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in #2566 — the composite action now pins to cargo-component@0.21.1 (latest stable as of 2026-04-07) and includes a comment about bump cadence via dependabot's cargo-component* group. Commit: 86d4419. (This PR is being closed in favor of #2566 — see PR description.)

44 changes: 38 additions & 6 deletions .github/workflows/code_style.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,39 @@
name: Code Style
on:
pull_request:
paths-ignore:
- 'README.md'
- 'CHANGELOG.md'
- 'CONTRIBUTING.md'
- 'CLAUDE.md'
- 'AGENTS.md'
- 'COVERAGE_PLAN.md'
- 'FEATURE_PARITY.md'
- 'LICENSE-*'
- '*.png'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- 'docs/**'
# Pushes to main/staging refresh the rust-cache entries that PR jobs
# restore from. PR jobs themselves are restore-only (see `save-if`
# on the rust-cache steps below).
push:
branches:
- main
- staging
paths-ignore:
- 'README.md'
- 'CHANGELOG.md'
- 'CONTRIBUTING.md'
- 'CLAUDE.md'
- 'AGENTS.md'
- 'COVERAGE_PLAN.md'
- 'FEATURE_PARITY.md'
- 'LICENSE-*'
- '*.png'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- 'docs/**'

permissions:
contents: read
Expand Down Expand Up @@ -94,7 +120,13 @@ jobs:

clippy-windows:
name: Clippy Windows (${{ matrix.name }})
if: github.base_ref == 'main'
# Mirror the Linux clippy gating: PR to main runs the full matrix for
# Windows-specific feature coverage, push to main/staging runs only the
# all-features leg to warm the shared cache (which `windows-build`
# used to fill before it was removed from test.yml).
if: >
(github.event_name == 'pull_request' && github.base_ref == 'main') ||
(github.event_name == 'push' && matrix.name == 'all-features')
runs-on: windows-latest
strategy:
fail-fast: false
Expand All @@ -117,11 +149,11 @@ jobs:
components: clippy
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
# Share the per-variant Windows target cache with test.yml's
# windows-build job. That job runs on `push` to main (where save-if
# allows writes), so clippy-windows — which only runs on main PRs —
# can restore from a warm cache instead of cold-building every time.
key: windows-${{ matrix.name }}
# Single shared slot for all three Windows clippy legs. Mirrors the
# Linux clippy `shared-key: clippy` pattern: --all-features is a
# superset, so restoring from whichever variant saved last beats
# storing three near-duplicate Windows target/ caches.
shared-key: clippy-windows
save-if: ${{ github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging') }}

Copilot AI Apr 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clippy-windows-extra shares shared-key: build-windows with the Clippy Windows (all-features) job and is allowed to save on push. Because cache keys are immutable, a subset leg can win and block the all-features job from refreshing the slot, reducing cache usefulness for future PRs. Recommend making clippy-windows-extra restore-only and letting only the all-features Windows job save the shared slot on pushes.

Suggested change
save-if: ${{ github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging') }}
save-if: false

Copilot uses AI. Check for mistakes.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved in #2566. clippy-windows-extra doesn't exist in the merged result — clippy-windows keeps its per-leg key: windows-${{ matrix.name }} shared with windows-build, so each variant has its own slot and there's no race. (This PR is being closed in favor of #2566.)

- name: Check lints
run: cargo clippy --all --benches --tests --examples ${{ matrix.flags }} -- -D warnings
Expand Down
10 changes: 2 additions & 8 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -86,10 +86,7 @@ jobs:
uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # cargo-llvm-cov

- name: Install cargo-component
run: |
if ! command -v cargo-component >/dev/null 2>&1; then
cargo install cargo-component --locked
fi
uses: ./.github/actions/install-cargo-component

- name: Build WASM channels (for integration tests)
run: ./scripts/build-wasm-extensions.sh --channels
Expand Down Expand Up @@ -150,10 +147,7 @@ jobs:
uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # cargo-llvm-cov

- name: Install cargo-component
run: |
if ! command -v cargo-component >/dev/null 2>&1; then
cargo install cargo-component --locked
fi
uses: ./.github/actions/install-cargo-component

- name: Build WASM channels
run: ./scripts/build-wasm-extensions.sh --channels
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -279,9 +279,9 @@ jobs:
persist-credentials: false
submodules: recursive
- name: Install Rust toolchain + wasm target
run: |
rustup target add wasm32-wasip2
cargo install cargo-component --locked || true
run: rustup target add wasm32-wasip2
- name: Install cargo-component
uses: ./.github/actions/install-cargo-component
- uses: swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: wasm-extensions
Expand Down
69 changes: 33 additions & 36 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,35 @@ on:
pull_request:
branches:
- main
paths-ignore:
- 'README.md'
- 'CHANGELOG.md'
- 'CONTRIBUTING.md'
- 'CLAUDE.md'
- 'AGENTS.md'
- 'COVERAGE_PLAN.md'
- 'FEATURE_PARITY.md'
- 'LICENSE-*'
- '*.png'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- 'docs/**'
push:
branches:
- main
paths-ignore:
- 'README.md'
- 'CHANGELOG.md'
- 'CONTRIBUTING.md'
- 'CLAUDE.md'
- 'AGENTS.md'
- 'COVERAGE_PLAN.md'
- 'FEATURE_PARITY.md'
- 'LICENSE-*'
- '*.png'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- 'docs/**'

permissions:
contents: read
Expand Down Expand Up @@ -49,7 +75,7 @@ jobs:
key: ${{ matrix.name }}
save-if: ${{ github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging') }}
- name: Install cargo-component
run: cargo install cargo-component --locked || true
uses: ./.github/actions/install-cargo-component
- name: Build WASM channels (for integration tests)
run: ./scripts/build-wasm-extensions.sh --channels
- name: Run Tests
Expand Down Expand Up @@ -109,37 +135,6 @@ jobs:
timeout --signal=INT --kill-after=30s 10m \
cargo test --manifest-path channels-src/telegram/Cargo.toml -- --nocapture

windows-build:
name: Windows Build (${{ matrix.name }})
if: >
github.event_name != 'pull_request' ||
github.base_ref != 'staging'
runs-on: windows-latest
strategy:
fail-fast: false
matrix:
include:
- name: all-features
flags: "--no-default-features --features postgres,libsql,html-to-markdown,bedrock,import"
- name: default
flags: ""
- name: libsql-only
flags: "--no-default-features --features libsql"
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
ref: ${{ inputs.ref || github.sha }}
persist-credentials: false
- name: Install Rust
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: windows-${{ matrix.name }}
save-if: ${{ github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging') }}
- name: Check compilation
run: cargo check --all --benches --tests --examples ${{ matrix.flags }}

wasm-wit-compat:
name: WASM WIT Compatibility
if: >
Expand All @@ -162,7 +157,7 @@ jobs:
key: wasm-extensions
save-if: ${{ github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging') }}
- name: Install cargo-component
run: cargo install cargo-component --locked || true
uses: ./.github/actions/install-cargo-component
- name: Build all WASM extensions against current WIT
run: ./scripts/build-wasm-extensions.sh
- name: Instantiation test (host linker compatibility)
Expand Down Expand Up @@ -224,7 +219,10 @@ jobs:
name: Run Tests
runs-on: ubuntu-latest
if: always()
needs: [tests, heavy-integration-tests, telegram-tests, wasm-wit-compat, docker-build, windows-build, version-check, bench-compile]
# Windows compilation is covered by the clippy-windows job in
# code_style.yml (clippy implies cargo check), so no Windows job is needed
# here.
needs: [tests, heavy-integration-tests, telegram-tests, wasm-wit-compat, docker-build, version-check, bench-compile]
Comment on lines +222 to +225

Copilot AI Apr 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow drops windows-build based on Windows compilation being covered by code_style.yml’s clippy job, but test.yml is also used as a reusable workflow (e.g. via staging-ci.yml), which does not run code_style.yml. As a result, those callers will lose any Windows compile signal entirely. If that coverage is still desired for batch/staging runs, consider adding a Windows leg back under workflow_call, or have the caller workflow also invoke the relevant Windows lint/check workflow.

Copilot uses AI. Check for mistakes.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch. Resolved in #2566 by keeping windows-build (with #2566's dynamic matrix: SLIM=1 leg on PRs, FULL=3 legs on push and workflow_call from staging-ci.yml). So scheduled batches and direct callers retain full Windows compile signal. (This PR is being closed in favor of #2566.)

steps:
- run: |
# Unit tests must always pass
Expand All @@ -237,12 +235,11 @@ jobs:
exit 1
fi
# Gated jobs: must pass on promotion PRs / push, skipped on developer PRs
for job in telegram-tests wasm-wit-compat docker-build windows-build version-check bench-compile; do
for job in telegram-tests wasm-wit-compat docker-build version-check bench-compile; do
case "$job" in
telegram-tests) result="${{ needs.telegram-tests.result }}" ;;
wasm-wit-compat) result="${{ needs.wasm-wit-compat.result }}" ;;
docker-build) result="${{ needs.docker-build.result }}" ;;
windows-build) result="${{ needs.windows-build.result }}" ;;
version-check) result="${{ needs.version-check.result }}" ;;
bench-compile) result="${{ needs.bench-compile.result }}" ;;
esac
Expand Down
Loading