From 25e854c6bf50650254b171246b0b341a90e800a3 Mon Sep 17 00:00:00 2001 From: Karib0u Date: Sat, 3 Oct 2026 10:31:24 +0200 Subject: [PATCH 1/2] fix(ci): prevent atomic rules pin drift --- .github/workflows/ci.yml | 19 ++++++++++++++++++- .github/workflows/release.yml | 2 +- 2 files changed, 19 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0278dc1..3adb17e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,7 +16,7 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Update this commit deliberately when the rules repository's atomic suite changes. + # Keep this exact commit in sync with release.yml; CI checks both pins. RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: @@ -41,6 +41,23 @@ jobs: rustflags: "" - name: Check formatting run: cargo fmt --all -- --check + - name: Check atomic rules pins agree + run: | + python3 - <<'PY' + import re + from pathlib import Path + + pins = [] + for workflow in ("ci.yml", "release.yml"): + path = Path(".github/workflows") / workflow + matches = re.findall(r"^ RUSTINEL_RULES_REF: ([0-9a-f]{40})$", path.read_text(), re.MULTILINE) + if len(matches) != 1: + raise SystemExit(f"{path}: expected exactly one full commit SHA for RUSTINEL_RULES_REF") + pins.append(matches[0]) + if pins[0] != pins[1]: + raise SystemExit(f"Atomic rules pins differ: ci.yml={pins[0]}, release.yml={pins[1]}. Update both together.") + print(f"CI and release atomics use the same rules commit: {pins[0]}") + PY release-field-contract: name: Release Field Contract diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2117a26..b02dbbc 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,7 +7,7 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Update this commit deliberately when the rules repository's atomic suite changes. + # Keep this exact commit in sync with ci.yml; CI checks both pins. RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: From 4830a71604538703f02bc448368e3811c0b01825 Mon Sep 17 00:00:00 2001 From: Karib0u Date: Sat, 3 Oct 2026 10:34:49 +0200 Subject: [PATCH 2/2] fix(ci): share the atomic rules pin across workflows --- .github/atomic-rules-ref | 1 + .github/workflows/ci.yml | 45 +++++++++++++++++++---------------- .github/workflows/release.yml | 15 +++++++++--- 3 files changed, 37 insertions(+), 24 deletions(-) create mode 100644 .github/atomic-rules-ref diff --git a/.github/atomic-rules-ref b/.github/atomic-rules-ref new file mode 100644 index 0000000..4ec0452 --- /dev/null +++ b/.github/atomic-rules-ref @@ -0,0 +1 @@ +fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3adb17e..01eafa4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,8 +16,6 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Keep this exact commit in sync with release.yml; CI checks both pins. - RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read @@ -41,23 +39,6 @@ jobs: rustflags: "" - name: Check formatting run: cargo fmt --all -- --check - - name: Check atomic rules pins agree - run: | - python3 - <<'PY' - import re - from pathlib import Path - - pins = [] - for workflow in ("ci.yml", "release.yml"): - path = Path(".github/workflows") / workflow - matches = re.findall(r"^ RUSTINEL_RULES_REF: ([0-9a-f]{40})$", path.read_text(), re.MULTILINE) - if len(matches) != 1: - raise SystemExit(f"{path}: expected exactly one full commit SHA for RUSTINEL_RULES_REF") - pins.append(matches[0]) - if pins[0] != pins[1]: - raise SystemExit(f"Atomic rules pins differ: ci.yml={pins[0]}, release.yml={pins[1]}. Update both together.") - print(f"CI and release atomics use the same rules commit: {pins[0]}") - PY release-field-contract: name: Release Field Contract @@ -347,11 +328,22 @@ jobs: run: python tests\native_capture_contract.py --binary "$env:GITHUB_WORKSPACE\target\release\rustinel.exe" shell: pwsh + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false @@ -501,11 +493,22 @@ jobs: rm -f "$RUNNER_TEMP/cert.p12" "$RUNNER_TEMP/rustinel.provisionprofile" security delete-keychain "$RUNNER_TEMP/rustinel-signing.keychain-db" 2>/dev/null || true + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index b02dbbc..6922348 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,8 +7,6 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Keep this exact commit in sync with ci.yml; CI checks both pins. - RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read @@ -305,11 +303,22 @@ jobs: name: ${{ matrix.artifact }} path: release-artifact/ + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false