Skip to content

Enforce the contract crate's dependency rule, and the minimal build (#18 §D3/§D4) #112

Enforce the contract crate's dependency rule, and the minimal build (#18 §D3/§D4)

Enforce the contract crate's dependency rule, and the minimal build (#18 §D3/§D4) #112

Workflow file for this run

name: CI
on:
push:
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
env:
# Lint levels live in `[lints]` in Cargo.toml so local and CI runs agree;
# don't add a blanket RUSTFLAGS here.
CARGO_TERM_COLOR: always
jobs:
rust:
name: Rust
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
submodules: recursive
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- uses: Swatinem/rust-cache@v2
- name: Check formatting
run: cargo fmt --all -- --check
- name: Clippy
run: cargo clippy --all-targets --all-features -- -D warnings
- name: Build
run: cargo build --all-targets --all-features
- name: Test
run: cargo test --all-features
- name: Test default features
run: cargo test
# The adapter's `memory-git` feature gates the diff family, and the test
# that the family is *withheld* without it is `#[cfg(not(feature =
# "memory-git"))]`. Both the `--all-features` and default runs above
# compile that test out, so without this step it would be checked by
# nothing — a feature-gated test whose default fate is to be built by one
# job and executed by none.
#
# This is also the configuration that keeps the promise the feature
# exists for: no `git2` / `libgit2-sys` in the graph.
# `api/Cargo.toml` spells out this exact command in a comment and asks
# that the contract crate never link a storage engine, a native library,
# an HTTP client, or an async runtime. It was left as a comment, so
# nothing checked it — and a forbidden dependency arrives transitively,
# through a feature someone enabled two crates away, which is precisely
# the way nobody notices.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinymemory-api`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault. The
# manifest says so; this runs what it says.
- name: Assert the contract crate stays free of heavy dependencies
run: |
forbidden="$(cargo tree -p tinymemory-api -e normal,build --prefix none \
| grep -Ei 'rusqlite|libsqlite|git2|reqwest|regex|tokio' || true)"
if [ -n "$forbidden" ]; then
echo "tinymemory-api pulled in a dependency its manifest forbids:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what hosts compile against. It must stay free of" >&2
echo "storage engines, native libraries, HTTP clients and async runtimes." >&2
exit 1
fi
# The minimal build has to stay genuinely usable, not merely compile:
# a host that wants the ports wired and nothing retained must be able to
# bind the null driver without pulling an engine in behind it.
- name: Build and bind the minimal configuration
run: |
cargo build -p tinymemory --no-default-features
cargo test -p tinymemory --no-default-features --test null_provider
- name: Lint and test the adapter without its optional engine features
run: |
cargo clippy -p tinymemory-tinycortex --all-targets --no-default-features -- -D warnings
cargo test -p tinymemory-tinycortex --no-default-features
- name: Assert the default adapter build links no native git
run: |
linked="$(cargo tree -p tinymemory-tinycortex --no-default-features \
-e normal --prefix none | grep -cE '^(git2|libgit2-sys)' || true)"
if [ "$linked" -ne 0 ]; then
echo "the default adapter build linked $linked native-git crate(s);" >&2
echo "the memory-git feature exists to keep them out" >&2
exit 1
fi
# The module crate is its own workspace root (see the `exclude` note in the
# root Cargo.toml), so NONE of the steps above touch it: `--all-targets`,
# `--all-features` and `--workspace` all stop at the workspace boundary and
# exit 0 without having compiled a line of it.
#
# That silence is the hazard. A cdylib that fails to build is a release that
# cannot be cut, and it would be discovered at release time rather than on the
# PR that broke it. So it gets its own job with the same gates.
module:
name: Module (own workspace)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- uses: Swatinem/rust-cache@v2
- name: Check formatting
run: cargo fmt --manifest-path crates/tinymemory-module/Cargo.toml --all -- --check
- name: Clippy
run: >-
cargo clippy --manifest-path crates/tinymemory-module/Cargo.toml
--all-targets -- -D warnings
# `--locked`, matching how the release builds this crate. Without it, a
# stale `crates/tinymemory-module/Cargo.lock` — which is a *separate*
# lockfile from the root's, and easy to forget when the root version moves
# — passes here and then fails all eleven release bundle jobs, after the
# tag has already been pushed. That happened once; this is the guard.
- name: Build the cdylib
run: cargo build --locked --manifest-path crates/tinymemory-module/Cargo.toml --release
- name: Unit tests
run: cargo test --manifest-path crates/tinymemory-module/Cargo.toml --lib
# The loader E2E drives a real dlopen'ed module, and tinybus binds its
# broker tasks to the runtime that created them. The module is loaded once
# per process and never unloaded, so two such tests in one process leave the
# second talking to a dead broker and it HANGS rather than failing. Hence
# one process per test, with a timeout so a hang is a red build and not a
# six-hour job.
- name: Loader E2E (one process per test)
env:
TINYMEMORY_TEST_MODULE: >-
${{ github.workspace }}/crates/tinymemory-module/target/release/libtinymemory_module.so
run: |
set -euo pipefail
tests=$(
cargo test --manifest-path crates/tinymemory-module/Cargo.toml \
--test module_e2e -- --ignored --list \
| sed -n 's/^\(.*\): test$/\1/p'
)
if [ -z "$tests" ]; then
echo "No ignored E2E tests were found — the list step is broken." >&2
exit 1
fi
for test in $tests; do
echo "::group::$test"
timeout 300 cargo test --manifest-path crates/tinymemory-module/Cargo.toml \
--test module_e2e -- --ignored --exact "$test"
echo "::endgroup::"
done
docs:
name: Docs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- name: Build documentation
env:
RUSTDOCFLAGS: -D warnings
run: cargo doc --no-deps --all-features
msrv:
name: Minimum supported Rust version
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive
- name: Read rust-version from Cargo.toml
id: msrv
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "tinymemory") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "package.rust-version is not set in Cargo.toml" >&2
exit 1
fi
echo "version=$msrv" >> "$GITHUB_OUTPUT"
- uses: dtolnay/rust-toolchain@master
with:
toolchain: ${{ steps.msrv.outputs.version }}
- uses: Swatinem/rust-cache@v2
- name: Build with the declared MSRV
run: cargo build --all-targets --all-features
supply-chain:
name: Supply chain
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive
- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check all