name: PR Check — Rust # Rust half of the former check.yml (split in #232). # # Only runs when Rust actually changes. On this repo roughly 1 PR in 40 touches # src-tauri/, and the runner has capacity 1 — jobs queue instead of running in # parallel, so every minute spent here is a minute the next PR waits. # # No `branches:` filter on purpose. `branches: [main]` never matched a PR # stacked on top of another feature branch, which is what /autopilot produces: # 4 of the 5 PRs in the feature-gating milestone ran no CI at all. on: pull_request: paths: - 'src-tauri/**' - '.forgejo/workflows/check-rust.yml' # Cancel obsolete runs (e.g. on force-push) so only the latest commit runs. # Distinct from the frontend group: a shared group would make the two # workflows cancel each other on a PR that touches both. concurrency: group: ci-rust-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: rust: runs-on: ubuntu container: ubuntu:22.04 env: PATH: /root/.cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin CARGO_TERM_COLOR: always # Nothing persists between runs (see the caching note below), so # incremental artifacts get written and never reused — pure overhead. # Test debug info is dead weight here for the same reason. CARGO_INCREMENTAL: 0 CARGO_PROFILE_TEST_DEBUG: 0 steps: - name: Install system dependencies, Node.js and Rust run: | apt-get update apt-get install -y --no-install-recommends \ curl wget git ca-certificates build-essential pkg-config \ libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev libssl-dev \ libdbus-1-dev # Node.js is required by actions/checkout and taiki-e/install-action # (they are JavaScript actions and need `node` in the container PATH). curl -fsSL https://deb.nodesource.com/setup_20.x | bash - apt-get install -y nodejs # Rust toolchain curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain stable --profile minimal node --version rustc --version cargo --version - name: Checkout uses: https://github.com/actions/checkout@v4 # No actions/cache step here, deliberately. The job container cannot # reach the runner's cache server (#234): the restore times out into a # miss AND the save times out, so the cache cost ~7 min per run and # returned nothing. Bring caching back through Swatinem/rust-cache once # #234 is fixed — not before, it shares the same backend. - name: cargo check run: cargo check --manifest-path src-tauri/Cargo.toml --all-targets - name: cargo test run: cargo test --manifest-path src-tauri/Cargo.toml --all-targets # Prebuilt binary. `cargo install --locked cargo-audit` recompiled the # tool from source on every single run (~4m40s). No continue-on-error: # a tooling failure should fail the job rather than be swallowed. - name: Install cargo-audit uses: https://github.com/taiki-e/install-action@v2 with: tool: cargo-audit # Advisories are informational — they can land on unrelated crates and # would otherwise stall unrelated work — so the step is non-blocking. # It no longer hides real failures behind `|| true` though. Daily # RustSec coverage outside Rust PRs lives in audit.yml. - name: cargo audit continue-on-error: true run: cargo audit --file src-tauri/Cargo.lock