diff --git a/.github/workflows/bindgen.yml b/.github/workflows/bindgen.yml index d4f8438..d545e98 100644 --- a/.github/workflows/bindgen.yml +++ b/.github/workflows/bindgen.yml @@ -10,6 +10,7 @@ permissions: env: CARGO_TERM_COLOR: always + LLVM_VERSION: "20.1.6" jobs: bindgen: @@ -41,6 +42,19 @@ jobs: - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - name: Install pinned LLVM + uses: KyleMayes/install-llvm-action@ebc0426251bc40c7cd31162802432c68818ab8f0 # v2.0.9 + with: + version: ${{ env.LLVM_VERSION }} + directory: ${{ runner.temp }}/llvm + + - name: Select pinned libclang + shell: pwsh + run: | + $libraryDir = if ($IsWindows) { "bin" } else { "lib" } + $libclangPath = Join-Path $env:LLVM_PATH $libraryDir + echo "LIBCLANG_PATH=$libclangPath" >> $env:GITHUB_ENV + - name: Generate bindings shell: pwsh run: | diff --git a/symcrypt-bindgen/README.md b/symcrypt-bindgen/README.md index 8152653..94b9e16 100644 --- a/symcrypt-bindgen/README.md +++ b/symcrypt-bindgen/README.md @@ -5,6 +5,12 @@ own raw bindings. ## Updating Bindings +Use the exact LLVM version specified by `LLVM_VERSION` in +[the Bindgen workflow](../.github/workflows/bindgen.yml). All four CI targets use this version. +Set `LIBCLANG_PATH` to that LLVM installation's `bin` directory on Windows or `lib` directory +on Linux, and put its `bin` directory first on `PATH`. Pinning the bindgen crate alone does +not pin the libclang library it loads. + To create new bindings, run the following command: ```powershell