-
Notifications
You must be signed in to change notification settings - Fork 6
ci: fail release PR integrity on a lagging Cargo.lock #2312
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -14,7 +14,7 @@ new_repo() { | |
| git -C "$repo" config user.name "Release Guard Test" | ||
| git -C "$repo" config user.email "release-guard@example.com" | ||
| printf '[package]\nname = "fixture"\nversion = "0.1.0"\n' >"$repo/Cargo.toml" | ||
| printf 'version = 3\n' >"$repo/Cargo.lock" | ||
| printf 'version = 3\n\n[[package]]\nname = "fixture"\nversion = "0.1.0"\n' >"$repo/Cargo.lock" | ||
| printf '# Changelog\n' >"$repo/CHANGELOG.md" | ||
| printf '0.1.0\n' >"$repo/version.txt" | ||
| printf '{"version":"0.1.0"}\n' >"$repo/server.json" | ||
|
|
@@ -46,6 +46,7 @@ new_repo | |
| base=$(head_sha) | ||
| printf '\n## 0.2.0\n' >>"$repo/CHANGELOG.md" | ||
| printf '[package]\nname = "fixture"\nversion = "0.2.0"\n' >"$repo/Cargo.toml" | ||
| printf 'version = 3\n\n[[package]]\nname = "fixture"\nversion = "0.2.0"\n' >"$repo/Cargo.lock" | ||
| printf '0.2.0\n' >"$repo/version.txt" | ||
| printf '{"version":"0.2.0"}\n' >"$repo/server.json" | ||
| printf '{".":"0.2.0"}\n' >"$repo/.release-please-manifest.json" | ||
|
|
@@ -83,3 +84,28 @@ head=$(head_sha) | |
| run_guard "$head" "$head" --allow-extra-files | ||
| gate_expect_failure "tracked ignored files must fail even with extra-file approval" | ||
| gate_output_contains "tracked ignored file" "tracked.tmp" | ||
|
|
||
| # The master break after the 1.0.0-beta.56 release merge: the workspace | ||
| # version moved but the lock still recorded the inheriting members at beta.55. | ||
|
Comment on lines
+88
to
+89
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This comment anchors a durable regression test to a specific master incident and beta release, so it becomes stale release-history narration rather than explaining why the fixture matters. Rephrase it around the invariant that workspace-inherited versions must agree with their lock entries, leaving the incident provenance in commit history. AGENTS.md reference: AGENTS.md:L195-L197 Useful? React with 👍 / 👎. |
||
| write_workspace_release() { | ||
| local lock_version=$1 | ||
| mkdir -p "$repo/crates/tracedecay" "$repo/crates/tracedecay-api" | ||
| printf '[workspace]\nmembers = ["crates/tracedecay", "crates/tracedecay-api"]\n\n[workspace.package]\nversion = "1.0.0-beta.56"\n' >"$repo/Cargo.toml" | ||
| printf '[package]\nname = "tracedecay"\nversion.workspace = true\n' >"$repo/crates/tracedecay/Cargo.toml" | ||
| printf '[package]\nname = "tracedecay-api"\nversion = "0.1.0"\n' >"$repo/crates/tracedecay-api/Cargo.toml" | ||
| printf 'version = 4\n\n[[package]]\nname = "serde"\nversion = "1.0.0"\nsource = "registry+https://github.com/rust-lang/crates.io-index"\n\n[[package]]\nname = "tracedecay"\nversion = "%s"\n\n[[package]]\nname = "tracedecay-api"\nversion = "0.1.0"\n' "$lock_version" >"$repo/Cargo.lock" | ||
| commit_all "workspace release with lock at $lock_version" | ||
| } | ||
|
|
||
| new_repo | ||
| base=$(head_sha) | ||
| write_workspace_release 1.0.0-beta.55 | ||
| run_guard "$base" "$(head_sha)" --allow-extra-files | ||
| gate_expect_failure "a lock lagging the workspace version must fail" | ||
| gate_output_contains "lagging lock" "tracedecay: Cargo.toml 1.0.0-beta.56, Cargo.lock 1.0.0-beta.55" | ||
|
|
||
| new_repo | ||
| base=$(head_sha) | ||
| write_workspace_release 1.0.0-beta.56 | ||
| run_guard "$base" "$(head_sha)" --allow-extra-files | ||
| gate_expect_success "a lock synced to the workspace version" | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When the allow-listed root
Cargo.tomlchanges a dependency constraint, patch, or resolver setting such that the existing resolution is stale, this loop still succeeds as long as each local package retains the same version. The release integrity check can therefore approve a lockfile that Cargo must update, recreating the broken locked-build outcome it is intended to prevent; validate the checked-out manifests and lock through Cargo's resolver rather than a name/version source-shape scan.AGENTS.md reference: AGENTS.md:L172-L177
Useful? React with 👍 / 👎.