rust-version: update flake.nix and open the PR; fix version checks - #100
Merged
Merged
Conversation
rust-version now detects the release channel from the pinned toolchain instead of taking it as an input, so a nightly pin can never be rewritten to a stable release or the other way round; beta pins are rejected. With `update-flake` it also rewrites the `sha256` of the fenix `fromToolchainFile` call in flake.nix. fenix fetches the release's channel manifest with `pkgs.fetchurl` at evaluation time, so the hash is that manifest's, computed with curl and openssl rather than Nix. Flake inputs are deliberately left alone. With `pr` it opens the pull request itself through create-pull-request, adding only the files it edited, so callers no longer wire that up. The PR uses GITHUB_TOKEN by default, so a maintainer approves its CI run. Also installs the channel before `rustup check` and anchors the channel line it parses, so a repository that pins a version or date no longer reads as up to date, and drops the stale cleanup step from the pre-`$/` checkout convention. rust-version-check compared versions as strings, which orders 1.100 before 1.99 and would have stopped reporting once the minor version reached three digits; it now sorts them as versions and anchors the same parse. The lint-workflows shellcheck helper also covers a repository that is itself an action, i.e. has action.yml at its root, and skips manifests without `runs.steps`. The test workflow exercises rust-version on an up-to-date pin, an outdated stable pin with a flake, an outdated nightly pin, and a beta pin.
… rust-version-check The toolchain parse piped `rustup show` through `grep rustc`, but rustup 1.28 reworked that output and no longer prints the rustc line, so the grep found nothing and pipefail failed the step. `rustc --version` under the `rust-toolchain.toml` override reports the pinned version directly. Nightlies were dated by the commit date rustc and `rustup check` report, which is the day before the nightly cut from it, so a dated pin read as one day older than it was and the "latest" date was one day behind the real latest. A dated pin now supplies its own date, and the latest date comes from the nightly channel manifest, the file the fenix hash is taken from. Only stable needs the channel installed for `rustup check`. rust-version-check is removed: rust-version covers the same check and can open the pull request itself. Its only remaining callers use the reusable workflow form that #89 already removed.
samuelburnham
marked this pull request as ready for review
October 1, 2026 20:09
samuelburnham
enabled auto-merge
October 1, 2026 20:09
The range opened at any `fromToolchainFile` mention and closed at the next
`}`. In a flake that also calls lean4-nix's `fromToolchainFile` on a
`${system}` line, that brace closed the range before the fenix block, so
its `sha256` was never rewritten and the action failed on ix, lean-ffi and
Blake3.lean. The range now opens at `fromToolchainFile {` and closes at the
`sha256` line itself.
arthurpaulino
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
rust-version now detects the release channel from the pinned toolchain instead of taking it as an input, so a nightly pin can never be rewritten to a stable release or the other way round; beta pins are rejected. With
update-flakeit also rewrites thesha256of the fenixfromToolchainFilecall in flake.nix. fenix fetches the release's channel manifest withpkgs.fetchurlat evaluation time, so the hash is that manifest's, computed with curl and openssl rather than Nix. Flake inputs are deliberately left alone. Withprit opens the pull request itself through create-pull-request, adding only the files it edited, so callers no longer wire that up. The PR uses GITHUB_TOKEN by default, so a maintainer approves its CI run.Also installs the channel before
rustup checkand anchors the channel line it parses, so a repository that pins a version or date no longer reads as up to date, and drops the stale cleanup step from the pre-$/checkout convention.rust-version-check compared versions as strings, which orders 1.100 before 1.99 and would have stopped reporting once the minor version reached three digits; it now sorts them as versions and anchors the same parse.
The lint-workflows shellcheck helper also covers a repository that is itself an action, i.e. has action.yml at its root, and skips manifests without
runs.steps.The test workflow exercises rust-version on an up-to-date pin, an outdated stable pin with a flake, an outdated nightly pin, and a beta pin.