| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |/ |
|
| |
|
|
|
|
|
| |
My efforts to fix it by flailing with CC versions have not been
successful.
We need CI passing so we can continue to do other work.
|
| |
|
|
|
| |
(This is what we do in all the other CI tests when we want to
cargo-install something.)
|
| |
|
|
|
|
|
| |
With the introduction of FFI, we ship generated header files
that we need to keep up-to-date. This CI test double-checks
that the generated files match those that we would generate from
cbindgen.
|
| |
|
|
| |
This enables us to test "restricted discovery" mode in shadow.
|
| |
|
|
|
|
|
|
| |
Relative directory reference here is incorrect since we changed
directories. Move this line to before the directory-change.
Looks like this was broken in c4e1d0c582164e17e0226af754a08692da5efb29,
but only surfaces on a cache miss of the tgen build.
|
| |
|
|
|
|
|
|
| |
The -latest jobs don't actually have artifacts. But:
In the -latest jobs this can cause errors due to duplication: the
artifacts from the -recent jobs in the same pipeline result in EEXIST
errors.
|
| |
|
|
|
| |
This will let us make the artifact processing only happen when we want
to save artifacts.
|
| |
|
|
| |
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2275#note_3054040
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
We replace uses of `amd64/rust:bookworm` in the `recent-*` jobs.
We add new latest-* jobs which
* aren't used for artifacts
* occur later in the pipeline
* only run on main, since we don't want them to block MRs
This is done with templates, to reuse the script parts.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Replace almost all the open-coded occurrences of `amd64/rust:bookworm`.
This rewinds us to Rust 1.79.
We can update after
https://github.com/rustsec/rustsec/issues/1217
is fixed upstream.
We're going to handle the rust-latest-* jobs specially.
There are still a few other images that look, from the name, like they
might be uncontrolled inputs into our CI, but they don't look risky.
Let's leave them for now.
|
| |
|
|
| |
So far only used by the cargo-audit job.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This avoids CI failures like this
https://gitlab.torproject.org/nickm/arti/-/jobs/617654
arising from situations like this
cargo-audit install fails with rust 1.80
https://github.com/rustsec/rustsec/issues/1217
error[E0282]: type annotations needed for Box<_>
https://github.com/time-rs/time/issues/693
IMO we should pin many of the other images too but I suspect that may
be controversial. I'm hoping that pinning this one to get CI working
is uncontroversial (perhaps only on a temporary basis).
The other way to solve this would be to remove --locked which IMO is
going in the wrong direction, by exposing us to more rather than fewer
uncontrolled inputs from our upstreams.
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
Without this, maint/shebang is broken.
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
And delete our old version of the script.
|
| |
|
|
| |
We're about to switch to a version that doesn't support this.
|
| |
|
|
|
|
|
|
| |
* Change all in-tree reference
* Delete our copy of script, which now lives
in the rust-maint-common subtree.
* Leave a symlink behind, so that old git hooks that people
(IMO possibly unwisely) installed, still work.
|
| | |
|
| |
|
|
| |
What a palaver.
|
| | |
|
| |\
| |
| |
| |
| |
| |
| | |
CI: Split build-repro job
Closes #1478
See merge request tpo/core/arti!2252
|
| | |
| |
| |
| |
| | |
As suggested here:
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2252#note_3046205
|
| | |
| |
| |
| |
| | |
This will allow the elements to run in parallel, hopefully speeding
things up (but using no fewer resources).
|
| | | |
|
| |/ |
|
| |
|
|
|
|
|
| |
Broken docs keep slipping in because we test this only with nightly,
where we allow failures.
Currently nightly is broken; see #1467. I'm not addressing that here yet.
|
| |
|
|
|
|
| |
Hopefully this will not be too slow.
Fixes #1472.
|
| |
|
|
| |
This reverts commit a6801c10584558316ff38f354167812d0c697549.
|
| |\
| |
| |
| |
| | |
Disable macos build tests
See merge request tpo/core/arti!2226
|
| | | |
|
| |/
|
|
|
| |
Ideally we'd tolerate situations with unaccepted ownership requests,
but that information doesn't seem to be public.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
I think that the effect of this will be as follows:
* MR branches will never run this, so when the crate ownership
is wrong, development can continue.
* When a new crate is first published, it will transition from
"ignored" to "complaining". This will happen on the first
CI run on main after "cargo publish" is run. But it *won't*
happen on the CI run on the publication tag.
The intent is that we discover a failure to `git add` while the
release technician who published the new crate is still around.
|
| |
|
|
|
|
|
|
| |
cf https://gitlab.torproject.org/tpo/tpa/team/-/issues/41621, it's
possible to unexpectedly run on a container for a different architecture
than the one requested. This can result in subtle and difficult to debug
issues, e.g. when unexpectedly running in the i386 variant of a
container instead of the expected amd64 variant.
|
| |
|
|
|
|
|
|
| |
Images with multi-arch manifests suffer from subtle caching issues
that can result in running an image with a different arch than intended.
See https://gitlab.torproject.org/tpo/tpa/team/-/issues/41621.
We can avoid this issue by using single-arch manifests where available.
|
| |
|
|
|
| |
This includes a fix for a (rare) panic-causing race condition, and misc
other additions and improvements.
|
| |
|
|
|
|
|
| |
Consultation with a nearby Python expert, on another topic, revealed
that without --strict, mypy turns most of its stuff off by default.
Sadly (?) this bureaucracy didn't find any bugs.
|
| |\
| |
| |
| |
| | |
CI: Move cargo clean section to after_script.
See merge request tpo/core/arti!2159
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Part of arti#1410.
The idea here is to consolidate `cargo clean` in an after_script
section we call everywhere, rather than have it be in one that we
can forget to copy.
We can't call `cargo clean` unconditionally, though, since some of
our jobs don't install cargo. So we make sure it's there.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Provide and run script for making/checking link blocks in CHANGELOG.md
Closes #1388
See merge request tpo/core/arti!2126
|
| | | | |
|
| | | | |
|
| | | | |
|
| | |/
|/| |
|