Skip to content

ci: workflow hygiene for the ci-lint precheck (zackees/ci.yml#91) - #378

Merged
zackees merged 1 commit into
mainfrom
m2-41-hygiene
Sep 29, 2026
Merged

zackees merged 1 commit into
mainfrom
m2-41-hygiene

Conversation

@zackees

@zackees zackees commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Closes zackees/ci.yml#91 (workflow hygiene, part of zackees/ci.yml#37 / #52, round M2-41).

Changes

  • RUN-001: every ubuntu-latest -> ubuntu-24.04 (dylints, macOS-x64 guest host, auto-release, release). The release symbolizer workers all built on ubuntu-latest, so runs-on is now literal and the matrix drops its os key.
  • WF-001: timeout-minutes on the 8 jobs that lacked one (dylints 45, release validate 120, symbolizer 60, crates publish 60, others 10-15).
  • WF-002: release.yml gets its own kernal-api-release-call-<tag> concurrency group. It does not reuse the caller's kernal-api-release group, because a called workflow that shares its caller's group waits on the caller forever.
  • SEC-002: every workflow now defaults to contents: read + actions: read. Each job that ends with "Cancel the run" grants itself actions: write. release-assets grants itself contents: write, and the auto-release release call passes both writes down to release.yml. All grants are listed in ci.toml [allow].permissions.
  • SEC-001: secrets: inherit is replaced by the one secret release.yml now declares (PYPI_API_TOKEN).
  • TAG-003: pull_request.types gains edited.
  • CT-006: [workspace.metadata.soldr].targets matches ci.toml [platforms]. Soldr reads it only for soldr lint cross-target Clippy, which this repository's CI does not run.
  • REL-002: .gitignore now uses target.soldr-* unanchored.
  • ci-lint is pinned at zackees/ci.yml@78506e7 (ci.toml linter + the checkout step).
  • The CI guard tests that asserted the old shapes (ubuntu-latest, types list, workflow-level actions: write) now assert the new ones.

Evidence: ci_lint precheck --local at 78506e7 (before = origin/main, after = this branch)

rule before after
RUN-001 violation / needs_review 9 / 3 0 / 2 (matrix builder/os in ci.yml build/test)
WF-001 8 0
WF-002 1 0
SEC-002 8 1 (see below)
TAG-003 1 0
CT-006 1 0
REL-002 1 0
SEC-001 2 2 (the PyPI token, moved to explicit references)
total findings 985 956

Local: uv run --no-project -m unittest ci.test_native_proof ci.test_native_proof_jobs ci.test_macos_x64_guest ci.test_ci_modes ci.test_release_ci_gate ci.test_nextest_config ci.test_deny_warnings ci.test_target_features ci.test_cache_policy ci.test_prune_obsolete_cook_caches passes (126 tests OK), and so do ci/test_auto_release.py, test_crate_release.py, test_check_release_process_substrate.py and test_release_package_features.py.

Not done / remaining

  • SEC-001 x2: PYPI_API_TOKEN. Switching to PyPI trusted publishing (OIDC) needs PyPI-side configuration by the owner.
  • SEC-002 x1: publish-crates id-token: write. This is crates.io trusted publishing, which is already OIDC. ci-lint only allows id-token on a job named publish with environment: pypi, so this is filed as a ci-lint issue.
  • TOOL-002 x1: the reqwest/gzip feature-unification step is documented as unable to run --locked.
  • RUST-013: the version: 0.9.23 pin moves with the wrapper in the kernal-api: route setup-soldr/setup-uv through a wrapper with plan-driven saves ci.yml#92 PR.
  • The release workflows (auto-release/release) cannot run from a PR, so their permission changes are verified only by reading them and by the guard tests (unverified in a live release).

- Pin every runner label (ubuntu-latest -> ubuntu-24.04); the release
  symbolizer workers all build on Linux, so their runs-on is literal.
- timeout-minutes on every job; release.yml gets its own per-tag
  concurrency group (not the caller's, which would deadlock).
- Read-only workflow permissions; jobs that cancel the run or publish grant
  themselves actions/contents/id-token writes, listed in ci.toml's
  [allow].permissions. auto-release passes the release call its writes.
- secrets: inherit -> the one PYPI_API_TOKEN release.yml declares.
- pull_request.types gains 'edited' (TAG-003).
- [workspace.metadata.soldr].targets mirrors ci.toml [platforms] (CT-006).
- .gitignore: target.soldr-* unanchored (REL-002).
- ci-lint pinned at zackees/ci.yml@78506e7.
@zackees zackees added the ci-full Run the complete release-equivalent CI matrix on this PR SHA label Sep 29, 2026
@zackees
zackees merged commit 92446a5 into main Sep 29, 2026
14 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-full Run the complete release-equivalent CI matrix on this PR SHA

Projects

None yet

Development

Successfully merging this pull request may close these issues.

kernal-api: workflow hygiene findings from ci-lint precheck

1 participant