From 4a6fb4fde1c94d3012a519b86f5682710aa9528d Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 5 Oct 2026 02:26:52 +0000 Subject: [PATCH] ci: install Rust with rustup instead of dtolnay/rust-toolchain Every job that needs Rust ran two steps: a bash one-liner pulling the channel out of rust-toolchain.toml, then dtolnay/rust-toolchain to install it. rustup ships on every GitHub-hosted runner and reads rust-toolchain.toml itself, so one step does both: rustup toolchain install --profile minimal --no-self-update installs the pinned channel plus the file's components (rustfmt, clippy), and every later cargo call in the checkout, src-tauri/ included, resolves to it. The release build adds `rustup target add "$RUST_TARGET"` for its matrix target. This drops a third-party action from the build path, which is also what was turning Lint (workflows) red: upstream moved its v1 tag, so the pin's version comment stopped matching (#741). With no pin there is nothing to drift or to re-review on each upstream push. Quantco/pixi-pack made the same change (Quantco/pixi-pack#340). Given up: the action's new retry on release-server checksum failures. That only bites while a Rust release is mid-publish. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg --- .github/workflows/ci.yml | 46 ++++++++++++----------------------- .github/workflows/release.yml | 39 +++++++++++------------------ mise.toml | 4 +-- rust-toolchain.toml | 2 +- 4 files changed, 32 insertions(+), 59 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 51971435..786d64e1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -228,17 +228,12 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Read pinned Rust version - id: rust-toolchain-file - # bash explicitly: the default shell on a Windows runner is PowerShell, - # where `$(...)` and `$GITHUB_OUTPUT` mean nothing, so the step passes - # having written no output — and the toolchain action then fails with - # "toolchain is a required input", eight steps from the real cause. + # rustup ships on GitHub-hosted runners and reads rust-toolchain.toml + # itself, so the version and components live in that one file and no + # third-party action sits between it and the build. + - name: Install Rust toolchain shell: bash - run: echo "channel=$(sed -n 's/^channel *= *"\(.*\)"/\1/p' rust-toolchain.toml)" >> "$GITHUB_OUTPUT" - - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 - with: - toolchain: ${{ steps.rust-toolchain-file.outputs.channel }} + run: rustup toolchain install --profile minimal --no-self-update - name: Install jq run: sudo apt-get install -y jq - name: Install cargo-audit @@ -294,18 +289,12 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Read pinned Rust version - id: rust-toolchain-file - # bash explicitly: the default shell on a Windows runner is PowerShell, - # where `$(...)` and `$GITHUB_OUTPUT` mean nothing, so the step passes - # having written no output — and the toolchain action then fails with - # "toolchain is a required input", eight steps from the real cause. + # rustup ships on GitHub-hosted runners and reads rust-toolchain.toml + # itself, so the version and components live in that one file and no + # third-party action sits between it and the build. + - name: Install Rust toolchain shell: bash - run: echo "channel=$(sed -n 's/^channel *= *"\(.*\)"/\1/p' rust-toolchain.toml)" >> "$GITHUB_OUTPUT" - - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 - with: - toolchain: ${{ steps.rust-toolchain-file.outputs.channel }} - components: rustfmt, clippy + run: rustup toolchain install --profile minimal --no-self-update - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 with: workspaces: src-tauri @@ -340,17 +329,12 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Read pinned Rust version - id: rust-toolchain-file - # bash explicitly: the default shell on a Windows runner is PowerShell, - # where `$(...)` and `$GITHUB_OUTPUT` mean nothing, so the step passes - # having written no output — and the toolchain action then fails with - # "toolchain is a required input", eight steps from the real cause. + # rustup ships on GitHub-hosted runners and reads rust-toolchain.toml + # itself, so the version and components live in that one file and no + # third-party action sits between it and the build. + - name: Install Rust toolchain shell: bash - run: echo "channel=$(sed -n 's/^channel *= *"\(.*\)"/\1/p' rust-toolchain.toml)" >> "$GITHUB_OUTPUT" - - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 - with: - toolchain: ${{ steps.rust-toolchain-file.outputs.channel }} + run: rustup toolchain install --profile minimal --no-self-update - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 with: workspaces: src-tauri diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 77e9f989..f322c087 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -83,17 +83,12 @@ jobs: steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Read pinned Rust version - id: rust-toolchain-file - # bash explicitly: the default shell on a Windows runner is PowerShell, - # where `$(...)` and `$GITHUB_OUTPUT` mean nothing, so the step passes - # having written no output — and the toolchain action then fails with - # "toolchain is a required input", eight steps from the real cause. + # rustup ships on GitHub-hosted runners and reads rust-toolchain.toml + # itself, so the version and components live in that one file and no + # third-party action sits between it and the build. + - name: Install Rust toolchain shell: bash - run: echo "channel=$(sed -n 's/^channel *= *"\(.*\)"/\1/p' rust-toolchain.toml)" >> "$GITHUB_OUTPUT" - - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 - with: - toolchain: ${{ steps.rust-toolchain-file.outputs.channel }} + run: rustup toolchain install --profile minimal --no-self-update - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 with: workspaces: src-tauri @@ -181,22 +176,16 @@ jobs: node-version-file: ".node-version" cache: "npm" - - name: Read pinned Rust version - id: rust-toolchain-file - # bash explicitly: the default shell on a Windows runner is PowerShell, - # where `$(...)` and `$GITHUB_OUTPUT` mean nothing, so the step passes - # having written no output — and the toolchain action then fails with - # "toolchain is a required input", eight steps from the real cause. - shell: bash - run: echo "channel=$(sed -n 's/^channel *= *"\(.*\)"/\1/p' rust-toolchain.toml)" >> "$GITHUB_OUTPUT" - + # From rust-toolchain.toml, so releases build on the same version CI + # tests against. rustup ships on GitHub-hosted runners and reads the + # file itself; bash, because the Windows default shell is PowerShell. - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 - with: - # From rust-toolchain.toml, so releases build on the same version - # CI tests against. - toolchain: ${{ steps.rust-toolchain-file.outputs.channel }} - targets: ${{ matrix.rust_target }} + shell: bash + env: + RUST_TARGET: ${{ matrix.rust_target }} + run: | + rustup toolchain install --profile minimal --no-self-update + rustup target add "$RUST_TARGET" - name: Rust cache uses: swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 diff --git a/mise.toml b/mise.toml index 54f3d4a9..ff970b11 100644 --- a/mise.toml +++ b/mise.toml @@ -2,8 +2,8 @@ # contributor runs before `just `. # # CI does NOT depend on mise — it reads .node-version and rust-toolchain.toml -# directly via actions/setup-node and dtolnay/rust-toolchain, so those two -# files stay the source of truth and nothing here can drift from them. +# directly via actions/setup-node and rustup, so those two files stay the +# source of truth and nothing here can drift from them. # # Note: mise can read those idiomatic files itself, but that is off by # default (idiomatic_version_file_enable_tools), so the versions are diff --git a/rust-toolchain.toml b/rust-toolchain.toml index cf5a3ab3..c4d89be3 100644 --- a/rust-toolchain.toml +++ b/rust-toolchain.toml @@ -1,6 +1,6 @@ # Single source of truth for the Rust toolchain. # -# Read natively by rustup, by dtolnay/rust-toolchain in CI, and by mise. +# Read natively by rustup (locally and in CI) and by mise. # Pinned to an exact version rather than "stable": SQLPilot is an # application, not a published library, so a reproducible build matters # more than a wide MSRV — and an unpinned toolchain means a new stable