-
Notifications
You must be signed in to change notification settings - Fork 2
155 lines (144 loc) · 6.98 KB
/
Copy pathrhel-compatibility.yml
File metadata and controls
155 lines (144 loc) · 6.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
name: rhel-compatibility
# Proves the workspace builds with Red Hat's system-native Rust toolchain and
# no rustup, which is the enterprise consumption path. GitHub's ubuntu-latest
# runners are x86_64, so this runs native amd64 with no emulation -- that is
# what makes CI, rather than a developer laptop, the authoritative gate for the
# x86_64-specific linker configuration stripped below.
#
# Security note: this workflow interpolates no event data. The only variable is
# PROTOC_VERSION, a static literal passed via env:, plus GitHub's own
# GITHUB_WORKSPACE path. No untrusted input reaches any run: block.
on:
push:
branches: [main]
paths:
- '**/*.rs'
- '**/Cargo.toml'
- 'Cargo.lock'
- 'rust-toolchain.toml'
- '.cargo/config.toml'
- '.github/workflows/rhel-compatibility.yml'
pull_request:
paths:
- '**/*.rs'
- '**/Cargo.toml'
- 'Cargo.lock'
- 'rust-toolchain.toml'
- '.cargo/config.toml'
- '.github/workflows/rhel-compatibility.yml'
workflow_dispatch:
# Serialize per ref: this job builds a container and the whole workspace, so
# successive pushes to a PR would otherwise stack multi-minute runs. Matches
# the pattern used by ci.yml, release.yml, release-please.yml and
# npm-build-publish.yml.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
env:
# protoc is NOT available from any UBI repository -- see the "Install build
# prerequisites" step. Pinned to the version this workspace builds against
# locally (libprotoc 35.1).
PROTOC_VERSION: '35.1'
# sha256 of protoc-${PROTOC_VERSION}-linux-x86_64.zip. Upstream publishes no
# checksum file for its releases, so this is computed from the asset and
# pinned here. Refresh it alongside PROTOC_VERSION:
# curl -fsSLO https://github.com/protocolbuffers/protobuf/releases/download/vX.Y/protoc-X.Y-linux-x86_64.zip
# sha256sum protoc-X.Y-linux-x86_64.zip
PROTOC_SHA256: '6930ebf62bd4ea607b98fff052596c6ee564b9835b4ce172c75a3f53ae9d91b7'
jobs:
rhel-native:
name: RHEL rust-toolset (no rustup)
runs-on: ubuntu-latest
timeout-minutes: 45
container:
image: registry.access.redhat.com/ubi9/ubi:latest
steps:
# Probed 2026-09-04 against ubi9/ubi:latest. Findings that shape this
# step, all verified rather than assumed:
#
# This list is the empirically minimal set, verified end-to-end by
# `make check-rhel` on 2026-09-04. Probe findings against ubi9/ubi:latest:
#
# rust-toolset AVAILABLE (ubi-9-appstream-rpms), currently 1.92.0
# -- note it is a *rolling* stream, so it is ahead of
# the 1.88.0 that RHEL 9.7's notes document
# fontconfig-devel AVAILABLE -- plotters' font stack in hyperdb-mcp
# gcc, gcc-c++ AVAILABLE -- also plotters: freetype-sys compiles C
# and pathfinder_simd compiles C++. Nothing in this
# workspace's own code needs a C or C++ compiler.
# git AVAILABLE -- lets actions/checkout use git rather
# than falling back to a REST tarball
# unzip AVAILABLE (ubi-9-baseos-rpms), not preinstalled
# protobuf-compiler *** NOT AVAILABLE *** -- `dnf search protobuf`
# returns only protobuf-c and python3-protobuf, so
# there is no protoc binary. Fetched below instead.
# mold *** NOT AVAILABLE *** -- hence the RUSTFLAGS
# override in the build step.
#
# cmake and make are deliberately absent: they were required only by
# aws-lc-sys, which is no longer in the dependency graph now that both
# reqwest declarations use `rustls-no-provider` and let the workspace's
# ring provider apply.
#
# Note ubi-9-codeready-builder-rpms is already enabled by default, so
# enabling it is not an available fallback for the missing protoc.
- name: Install build prerequisites
run: |
dnf install -y rust-toolset fontconfig-devel git unzip gcc gcc-c++
dnf clean all
- name: Install protoc
# hyperdb-api-core/build.rs runs tonic_prost_build, which needs protoc.
# This is a standing M-OOBE deviation: a published crate should not
# require a tool beyond cargo and rustc. The durable fix is to generate
# the .rs files at publish time and vendor them into the crate; until
# then CI supplies protoc explicitly.
#
# The archive is unpacked into /usr/local as root, so its integrity is
# verified first. Version-pinning alone does not help here: a retagged
# or compromised release would still be accepted.
run: |
set -euo pipefail
ZIP="protoc-${PROTOC_VERSION}-linux-x86_64.zip"
curl -fsSLO "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOC_VERSION}/${ZIP}"
echo "${PROTOC_SHA256} ${ZIP}" | sha256sum -c -
unzip -q "${ZIP}" -d /usr/local
rm "${ZIP}"
protoc --version
- uses: actions/checkout@v7
- name: Prove this is the distro toolchain, not rustup
run: |
if command -v rustup >/dev/null 2>&1; then
echo "::error::rustup is present; this job must exercise the system toolchain only"
exit 1
fi
echo "cargo: $(command -v cargo)"
echo "rustc: $(command -v rustc)"
rustc --version
cargo --version
- name: cargo check with the system toolchain
# The repo's .cargo/config.toml pins linker = "clang" plus
# -fuse-ld=mold for x86_64-unknown-linux-gnu, and mold is not in any
# UBI repo. `cargo check` still links build scripts and proc-macro
# crates for the host, so this genuinely breaks the job.
#
# Both overrides are neutralized by environment rather than by editing
# the checkout. Note that `--config target.<triple>.rustflags=[]` does
# NOT work: cargo *joins* rustflags across config sources. The env var
# replaces them, which was verified directly.
#
# rust-toolchain.toml needs no handling at all: it is read only by
# rustup's proxy shims, and the step above asserts rustup is absent.
env:
RUSTFLAGS: ''
CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_LINKER: cc
run: |
set -euo pipefail
cargo check --workspace --locked --all-targets
# hyperdb-compile-check declares its own [workspace], so --workspace
# skips it -- yet release.yml publishes it, meaning the gate that
# proves "builds on Red Hat's toolchain with no rustup" would
# otherwise never cover a crate enterprise consumers can depend on.
cargo check --locked --all-targets \
--manifest-path hyperdb-compile-check/Cargo.toml