Skip to content

ci: resolve the sibling sources outside the workspace - #21

Open
EnRaiha wants to merge 2 commits into
mainfrom
fix/ci-sibling-preflight
Open

EnRaiha wants to merge 2 commits into
mainfrom
fix/ci-sibling-preflight

Conversation

@EnRaiha

@EnRaiha EnRaiha commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Problem

CI fails on every run that reaches the sibling build, and the failure reads as the PR's own breakage. It is neither upstream churn nor the PR.

setup-workspace checks the siblings out under .ci-sources/, inside the Lite workspace. Cargo resolves a path dependency's workspace = true inheritance against the root manifest of the workspace it considers that dependency to be in — nested like that, Lite's root. nodedb-array asks its root for nodedb-wal, Lite's root defines none, and cargo metadata dies before a line of Lite compiles:

error: failed to load source for dependency `nodedb-array`
Caused by:
  unable to update .../.ci-sources/nodedb/nodedb-array
Caused by:
  error inheriting `nodedb-wal` from workspace root manifest's `workspace.dependencies.nodedb-wal`
Caused by:
  `dependency.nodedb-wal` was not found in `workspace.dependencies`

Reproduced on current main (Origin 4664c821, consistent by every other measure), so it is structural, not upstream churn. Cargo's own trace names the root it used:

find_root - is root /home/.../nodedb-lite/Cargo.toml

Fix

Fetch the siblings into $RUNNER_TEMP/ci-sources — outside the workspace tree, the layout local development uses (../nodedb). Cargo then walks up to the sibling's own root and the inheritance resolves. actions/checkout rejects a path: outside $GITHUB_WORKSPACE, so the refs are fetched with git; fetching a ref covers branches, tags and SHAs alike.

scripts/ensure-origin.sh needs no change: it locates the Origin root through cargo metadata, not a path literal.

Also in this PR

  • Preflight — parse both sibling workspaces after the patch table is written. A genuinely inconsistent Origin ref then fails with an annotation naming the ref, not a raw cargo error deep in the log.
  • Nightly schedule — the run-ci label gate keeps upstream churn out of PR runs, but then nothing reports it at all: the first run to see a broken Origin workspace is the next PR a maintainer labels.

CI status on this branch

Run: https://github.com/NodeDB-Lab/nodedb-lite/actions/runs/35733597625

The sibling setup passes. Every step that compiles or checks the workspace is green:

Job Steps Result
Lint & Check Set up workspace, fmt, clippy, wasm32 check, C header, ABI surface pass
WASM Set up workspace, Build WASM release pass

Three failures remain. All three are pre-existing on main and unrelated to this diff — CI never reached them before because it died in setup-workspace.

Evidence for the three remaining failures

1. cargo deny — unmaintained advisories

Job: Test Suite / Lint & Check → Dependency audit

error[unmaintained]: bitmaps is unmaintained
  ├ ID: RUSTSEC-2026-0247
  ├ Solution: No safe upgrade is available!
  ├ bitmaps v2.1.0
    ├── im v15.1.0
    │   └── loro-internal v1.16.2
    │       └── loro v1.13.9
    │           └── nodedb-array v0.5.0 → nodedb-lite v0.1.0
error[unmaintained]: im is unmaintained             (RUSTSEC-2026-0248)
error[unmaintained]: sized-chunks is unmaintained   (RUSTSEC-2026-0251)

advisories FAILED, bans ok, licenses ok, sources ok

loro, pulled by nodedb-array, brings in im → bitmaps / sized-chunks. All three advisories postdate the config, so this fails on a calendar rather than on a commit. Fix: a deny.toml [advisories] ignore with a rationale, or an upstream loro bump that drops im.

2. Interop build — libcurl4-openssl-dev missing

Job: Test Suite / Test → Run tests

error: failed to run custom build command for `rdkafka-sys v4.10.0+2.12.1`
      .../librdkafka/src/rdkafka_conf.c:60:10: fatal error: curl/curl.h: No such file or directory
ensure-origin: Origin build FAILED; failing the interop suite (Origin source is present, so this is a real error, not a skip)
Summary [155.704s] 0/1217 tests run: 0 passed, 6 skipped
error: setup script failed

ensure-origin.sh builds Origin with --all-features; rdkafka-sys compiles librdkafka from source and needs the libcurl headers. test.yml's "Install system deps" installs cmake, clang, libclang-dev, pkg-config, protobuf-compiler, perl — not libcurl4-openssl-dev. Because the setup script exits non-zero, nextest aborts before running any of the 1217 tests: one missing header hides the whole suite.

Fix: add libcurl4-openssl-dev to the apt list. libsasl2-dev, libssl-dev, zlib1g-dev may also be wanted by the same build — unconfirmed until curl resolves.

3. WASM node tests — array::create_put_slice_roundtrip FAIL

Job: WASM → Run WASM node tests
Source: nodedb-lite-wasm/tests/array.rs:69

Running tests/array.rs
running 1 test
test create_put_slice_roundtrip ... FAIL

---- create_put_slice_roundtrip output ----
    error output:
        panicked at library/std/src/sys/time/unsupported.rs:35:9:
        time not implemented on this platform
    JS exception that was thrown:
        RuntimeError: unreachable
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 filtered out
error: test failed, to rerun pass `--test array`

A wall-clock call (std::time) on wasm32-unknown-unknown, where std has no time source. A genuine Lite-vs-current-Origin failure in the wasm path, not a path issue. Fix: gate or replace the SystemTime/Instant caller for wasm.

Evidence for the fix itself

Check Result
Minimal repro, sibling workspace outside consumer tree resolves
Minimal repro, sibling workspace nested in consumer tree fails, same inheritance error
Real repos, relocated: nodedb@4664c821 + pagedb@e4a6902 cargo metadata exit 0, 602 packages, nodedb-wal/nodedb-array/pagedb all resolve from $RUNNER_TEMP/ci-sources
Fetch step (both repos) 5.4 s
Preflight + verify steps pass
actionlint on ci.yml, test.yml, wasm.yml clean

Notes

  • Scheduled-run failure notifications go to whoever last edited the cron line — re-save that line if you want them.
  • The preflight catches manifest-level inconsistency only. A genuine API break upstream still surfaces as a test failure; that is the suite's job.
  • No pin.

Copilot AI lite review requested due to automatic review settings September 22, 2026 13:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@EnRaiha EnRaiha added the run-ci Opt this PR into the full test suite; re-add to force a re-run label Sep 22, 2026
CI has failed on every run that reached the sibling build since the
Origin crates adopted `workspace = true` inheritance, and the failure
reads as the pull request's own breakage. It is neither upstream churn
nor the PR:

setup-workspace checks the siblings out under `.ci-sources/`, inside the
Lite workspace. Cargo resolves a path dependency's inherited fields
against the root manifest of the workspace it considers that dependency
to be in — nested like that, Lite's root. `nodedb-array` asks its root
for `nodedb-wal`, Lite's root defines none, and `cargo metadata` dies
before a line of Lite compiles:

    error inheriting `nodedb-wal` from workspace root manifest's
    `workspace.dependencies.nodedb-wal`

Outside the workspace tree — the layout local development uses,
`../nodedb` — cargo walks up to the sibling's own root and the
inheritance resolves. actions/checkout rejects a `path:` outside
$GITHUB_WORKSPACE, so fetch the refs with git into $RUNNER_TEMP.

With that fixed, make the remaining failure mode legible and early:

- Parse both sibling workspaces after the patch table is written, so a
  genuinely inconsistent Origin ref fails with an annotation naming the
  ref, not a raw cargo error deep in the log.
- Run the same suites nightly on main. The `run-ci` label gate keeps
  upstream churn out of PR runs, but then nothing reports it at all: the
  first run to see a broken Origin workspace is the next PR a maintainer
  labels.
@EnRaiha
EnRaiha force-pushed the fix/ci-sibling-preflight branch from bcd6e03 to c129a44 Compare September 22, 2026 13:27
@EnRaiha EnRaiha changed the title ci: report sibling-source breakage as upstream, and probe it nightly ci: resolve the sibling sources outside the workspace Sep 22, 2026
Two failures keep the suite from running at all.

The interop setup builds the Origin workspace with --all-features;
rdkafka-sys compiles librdkafka from source and needs the libcurl and
libsasl2 headers. Without them the setup script exits non-zero and
nextest never runs — 0 of 1217 tests. Origin's test.yml has installed
both since the interop suite landed; Lite's copy was missing them.

The dependency audit then fails on three advisory ignores the sibling
tree needs: loro-internal pulls im and its support crates, all archived
upstream with no fixed version. Origin's deny.toml already carries the
three with review-by dates; Lite's did not.

The advisory gate is copied from Origin's scripts/ci so the review-by
dates stay enforced on both sides.
@EnRaiha

EnRaiha commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Pushed one more commit onto this branch: the three fixes that keep the suite from running at all.

Fix Evidence
Interop build deps (libcurl4-openssl-dev libsasl2-dev) in both apt blocks Origin's test.yml:54,172 installs them; without them rdkafka-sys fails curl/curl.h, the setup script exits non-zero, and nextest reports 0/1217 tests
deny.toml mirrors the three loro advisory ignores Origin carries RUSTSEC-2026-0247/-0248/-0251, review-by dated; the audit stops failing on a calendar
The advisory-ignore gate is ported from Origin's scripts/ci/check_advisory_ignores.py verbatim copy on purpose, so the review-by dates stay enforced on both sides; --self-test passes locally

Closes #22 (the suite aborting before running) and #23 (the audit ignores).

Nothing else moved: the sibling-checkout fix from the original commit is unchanged, and the PR still needs a maintainer's run-ci label to prove the suite end to end — the failure I cannot clear myself is the one this PR removes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

run-ci Opt this PR into the full test suite; re-add to force a re-run

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants