Skip to content

rust-version: update flake.nix and open the PR; fix version checks - #100

Merged
samuelburnham merged 4 commits into
mainfrom
fix/rust-version-actions
Oct 2, 2026
Merged

samuelburnham merged 4 commits into
mainfrom
fix/rust-version-actions

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

rust-version now detects the release channel from the pinned toolchain instead of taking it as an input, so a nightly pin can never be rewritten to a stable release or the other way round; beta pins are rejected. With update-flake it also rewrites the sha256 of the fenix fromToolchainFile call in flake.nix. fenix fetches the release's channel manifest with pkgs.fetchurl at evaluation time, so the hash is that manifest's, computed with curl and openssl rather than Nix. Flake inputs are deliberately left alone. With pr it opens the pull request itself through create-pull-request, adding only the files it edited, so callers no longer wire that up. The PR uses GITHUB_TOKEN by default, so a maintainer approves its CI run.

Also installs the channel before rustup check and anchors the channel line it parses, so a repository that pins a version or date no longer reads as up to date, and drops the stale cleanup step from the pre-$/ checkout convention.

rust-version-check compared versions as strings, which orders 1.100 before 1.99 and would have stopped reporting once the minor version reached three digits; it now sorts them as versions and anchors the same parse.

The lint-workflows shellcheck helper also covers a repository that is itself an action, i.e. has action.yml at its root, and skips manifests without runs.steps.

The test workflow exercises rust-version on an up-to-date pin, an outdated stable pin with a flake, an outdated nightly pin, and a beta pin.

rust-version now detects the release channel from the pinned toolchain
instead of taking it as an input, so a nightly pin can never be rewritten
to a stable release or the other way round; beta pins are rejected. With
`update-flake` it also rewrites the `sha256` of the fenix
`fromToolchainFile` call in flake.nix. fenix fetches the release's channel
manifest with `pkgs.fetchurl` at evaluation time, so the hash is that
manifest's, computed with curl and openssl rather than Nix. Flake inputs
are deliberately left alone. With `pr` it opens the pull request itself
through create-pull-request, adding only the files it edited, so callers
no longer wire that up. The PR uses GITHUB_TOKEN by default, so a
maintainer approves its CI run.

Also installs the channel before `rustup check` and anchors the channel
line it parses, so a repository that pins a version or date no longer
reads as up to date, and drops the stale cleanup step from the pre-`$/`
checkout convention.

rust-version-check compared versions as strings, which orders 1.100 before
1.99 and would have stopped reporting once the minor version reached three
digits; it now sorts them as versions and anchors the same parse.

The lint-workflows shellcheck helper also covers a repository that is
itself an action, i.e. has action.yml at its root, and skips manifests
without `runs.steps`.

The test workflow exercises rust-version on an up-to-date pin, an outdated
stable pin with a flake, an outdated nightly pin, and a beta pin.
… rust-version-check

The toolchain parse piped `rustup show` through `grep rustc`, but rustup
1.28 reworked that output and no longer prints the rustc line, so the
grep found nothing and pipefail failed the step. `rustc --version` under
the `rust-toolchain.toml` override reports the pinned version directly.

Nightlies were dated by the commit date rustc and `rustup check` report,
which is the day before the nightly cut from it, so a dated pin read as
one day older than it was and the "latest" date was one day behind the
real latest. A dated pin now supplies its own date, and the latest date
comes from the nightly channel manifest, the file the fenix hash is
taken from. Only stable needs the channel installed for `rustup check`.

rust-version-check is removed: rust-version covers the same check and can
open the pull request itself. Its only remaining callers use the reusable
workflow form that #89 already removed.
@samuelburnham
samuelburnham marked this pull request as ready for review October 1, 2026 20:09
The range opened at any `fromToolchainFile` mention and closed at the next
`}`. In a flake that also calls lean4-nix's `fromToolchainFile` on a
`${system}` line, that brace closed the range before the fenix block, so
its `sha256` was never rewritten and the action failed on ix, lean-ffi and
Blake3.lean. The range now opens at `fromToolchainFile {` and closes at the
`sha256` line itself.
@samuelburnham
samuelburnham added this pull request to the merge queue Oct 2, 2026
@samuelburnham
samuelburnham merged commit 2a6b43b into main Oct 2, 2026
4 checks passed
@samuelburnham
samuelburnham deleted the fix/rust-version-actions branch October 2, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants