ci: workflow hygiene for the ci-lint precheck (zackees/ci.yml#91) - #378
Merged
Merged
Conversation
- Pin every runner label (ubuntu-latest -> ubuntu-24.04); the release symbolizer workers all build on Linux, so their runs-on is literal. - timeout-minutes on every job; release.yml gets its own per-tag concurrency group (not the caller's, which would deadlock). - Read-only workflow permissions; jobs that cancel the run or publish grant themselves actions/contents/id-token writes, listed in ci.toml's [allow].permissions. auto-release passes the release call its writes. - secrets: inherit -> the one PYPI_API_TOKEN release.yml declares. - pull_request.types gains 'edited' (TAG-003). - [workspace.metadata.soldr].targets mirrors ci.toml [platforms] (CT-006). - .gitignore: target.soldr-* unanchored (REL-002). - ci-lint pinned at zackees/ci.yml@78506e7.
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes zackees/ci.yml#91 (workflow hygiene, part of zackees/ci.yml#37 / #52, round M2-41).
Changes
ubuntu-latest->ubuntu-24.04(dylints, macOS-x64 guest host, auto-release, release). The release symbolizer workers all built onubuntu-latest, soruns-onis now literal and the matrix drops itsoskey.timeout-minuteson the 8 jobs that lacked one (dylints 45, release validate 120, symbolizer 60, crates publish 60, others 10-15).kernal-api-release-call-<tag>concurrency group. It does not reuse the caller'skernal-api-releasegroup, because a called workflow that shares its caller's group waits on the caller forever.contents: read+actions: read. Each job that ends with "Cancel the run" grants itselfactions: write.release-assetsgrants itselfcontents: write, and the auto-releasereleasecall passes both writes down to release.yml. All grants are listed in ci.toml[allow].permissions.secrets: inheritis replaced by the one secret release.yml now declares (PYPI_API_TOKEN).pull_request.typesgainsedited.[workspace.metadata.soldr].targetsmatches ci.toml[platforms]. Soldr reads it only forsoldr lintcross-target Clippy, which this repository's CI does not run..gitignorenow usestarget.soldr-*unanchored.zackees/ci.yml@78506e7(ci.tomllinter+ the checkout step).ubuntu-latest, types list, workflow-levelactions: write) now assert the new ones.Evidence:
ci_lint precheck --localat 78506e7 (before = origin/main, after = this branch)builder/osin ci.yml build/test)Local:
uv run --no-project -m unittest ci.test_native_proof ci.test_native_proof_jobs ci.test_macos_x64_guest ci.test_ci_modes ci.test_release_ci_gate ci.test_nextest_config ci.test_deny_warnings ci.test_target_features ci.test_cache_policy ci.test_prune_obsolete_cook_cachespasses (126 tests OK), and so doci/test_auto_release.py,test_crate_release.py,test_check_release_process_substrate.pyandtest_release_package_features.py.Not done / remaining
PYPI_API_TOKEN. Switching to PyPI trusted publishing (OIDC) needs PyPI-side configuration by the owner.publish-cratesid-token: write. This is crates.io trusted publishing, which is already OIDC. ci-lint only allows id-token on a job namedpublishwithenvironment: pypi, so this is filed as a ci-lint issue.--locked.version: 0.9.23pin moves with the wrapper in the kernal-api: route setup-soldr/setup-uv through a wrapper with plan-driven saves ci.yml#92 PR.