Skip to content

Update remaining dependencies #8230

Update remaining dependencies

Update remaining dependencies #8230

Workflow file for this run

name: Rust
on:
push:
branches:
- main
pull_request:
workflow_dispatch:
merge_group:
concurrency:
group: rust-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
# Not needed in CI, should make things a bit faster
CARGO_INCREMENTAL: 0
CARGO_TERM_COLOR: always
# Build smaller artifacts to avoid running out of space in CI and make it a bit faster
RUSTFLAGS: -C strip=symbols
RUST_BACKTRACE: full
# If a property test fails, we want to shrink it as much as possible to find the minimal failing
# case. This only happens on test failure, so it's not a big deal if it's slow.
PROPTEST_MAX_SHRINK_ITERS: 100000
# Default is 256, but we want PRs to check more cases, so they fail in CI before we merge them.
# For slow tests, this can be reduced using `#[property_test(config = "ProptestConfig { .. }")]`.
PROPTEST_CASES: 10000
PROPTEST_MAX_GLOBAL_REJECTS: 100000
# Run faster benchmark checks in CI
BENCHMARK_TYPE: check
VERBOSE: true
jobs:
cargo-fmt:
name: cargo-fmt (Linux x86-64)
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: cargo fmt
run: cargo fmt --all -- --check
cargo-clippy:
name: cargo-clippy (${{ strategy.job-index == 0 && 'Linux x86-64' || (strategy.job-index == 1 && 'Windows x86-64' || 'macOS arm64') }})
strategy:
matrix:
os: ["ubuntu-22.04", "windows-2022", "macos-26"]
runs-on: ${{ matrix.os }}
steps:
# Enable the sccache runs-on S3 backend for Linux runners, to cache C/C++ and Rust.
# On GitHub-hosted or fork runners, the runs-on action is ignored.
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: ${{ runner.os == 'Linux' && 's3' || '' }}
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: runner.os == 'Linux' && github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
# On macOS, we need a proper Clang version, not Apple's custom version without wasm32 support
- name: Install LLVM and Clang for macOS
uses: KyleMayes/install-llvm-action@ebc0426251bc40c7cd31162802432c68818ab8f0 # v2.0.9
with:
env: true
version: 17
if: runner.os == 'macOS'
# Because macOS, see https://andreasfertig.blog/2021/02/clang-and-gcc-on-macos-catalina-finding-the-include-paths/
- name: Configure C compiler macOS
run: |
echo "SDKROOT=$(xcrun --show-sdk-path)" >> $GITHUB_ENV
if: runner.os == 'macOS'
- name: Install glibtoolize (macOS)
run: brew install libtool
if: runner.os == 'macOS'
# We cache protoc because it sometimes fails to download, but cache is too slow on Windows.
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
# We don't have an easy way to clear old tool versions, but there aren't many tools
# (or versions), so just reset when we upgrade the compiler.
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
if: runner.os != 'Windows'
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
# Needed for hwloc
- name: Install automake (macOS)
run: brew install automake
if: runner.os == 'macOS'
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# We don't need to cache anything more than the crate packages and bare git clones.
# <https://doc.rust-lang.org/cargo/guide/cargo-home.html#caching-the-cargo-home-in-ci>
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
# Reset stored crates when any direct dependency versions change, so we aren't storing
# outdated versions. Currently this happens every 1-3 weeks.
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
- name: Configure compiled deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# Clippy has no build artifacts, so we can save the whole target directory
path: './target'
# There's no point in restoring deps from older compiler versions, because they won't be
# used. To stop the cache from growing too large, we also reset it whenever any direct
# dependency version changes.
# TODO: we might be able to share clippy and check-individually caches
key: ${{ runner.os }}-${{ github.job }}-target-${{ hashFiles('./Cargo.toml') }}-${{ hashFiles('./rust-toolchain.toml') }}
# Windows caching is very slow, and we already have sccache on Linux
if: runner.os == 'macOS' && false
# Checks benchmark code style and syntax (but clippy does not do code generation checks)
- name: cargo clippy
run: |
cargo -Zgitoxide -Zgit clippy --locked --all-targets --features runtime-benchmarks -- -D warnings
cargo-runtime-build:
name: cargo-runtime-build (Linux x86-64)
# If clippy and tests pass on all OSes, it is unlikely that a runtime build will pass on Linux, but fail on other OSes.
runs-on: ubuntu-22.04
steps:
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: 's3'
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
- name: build subspace-runtime
run: |
cargo -Zgitoxide -Zgit build --locked --package subspace-runtime
- name: build evm-domain-runtime
run: |
cargo -Zgitoxide -Zgit build --locked --package evm-domain-runtime
- name: build auto-id-domain-runtime
run: |
cargo -Zgitoxide -Zgit build --locked --package auto-id-domain-runtime
cargo-test:
name: cargo-test (${{ strategy.job-index == 0 && 'Linux x86-64' || (strategy.job-index == 1 && 'Windows x86-64' || 'macOS arm64') }})
strategy:
matrix:
os: ["ubuntu-22.04", "windows-2022", "macos-26"]
runs-on: ${{ matrix.os }}
# Don't use the full 6 hours if a test hangs
timeout-minutes: 120
steps:
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: ${{ runner.os == 'Linux' && 's3' || '' }}
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: runner.os == 'Linux' && github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
# On macOS, we need a proper Clang version, not Apple's custom version without wasm32 support
- name: Install LLVM and Clang for macOS
uses: KyleMayes/install-llvm-action@ebc0426251bc40c7cd31162802432c68818ab8f0 # v2.0.9
with:
env: true
version: 17
if: runner.os == 'macOS'
# Because macOS, see https://andreasfertig.blog/2021/02/clang-and-gcc-on-macos-catalina-finding-the-include-paths/
- name: Configure C compiler macOS
run: |
echo "SDKROOT=$(xcrun --show-sdk-path)" >> $GITHUB_ENV
if: runner.os == 'macOS'
- name: Install glibtoolize (macOS)
run: brew install libtool
if: runner.os == 'macOS'
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
if: runner.os != 'Windows'
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
# Needed for hwloc
- name: Install automake (macOS)
run: brew install automake
if: runner.os == 'macOS'
- name: Install cargo-nextest
uses: taiki-e/install-action@7a79fe8c3a13344501c80d99cae481c1c9085912 # 2.81.10
with:
tool: cargo-nextest
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
# Disable PDB generation on Windows to avoid LNK1318 PDB size limits with large test binaries
# (wasmtime 35+ makes domain_client_operator test binary exceed PDB page count limits)
# /DEBUG:NONE tells the MSVC linker to skip PDB file creation entirely
- name: Configure Windows linker
run: echo "RUSTFLAGS=$env:RUSTFLAGS -C debuginfo=0 -C link-arg=/DEBUG:NONE" >> $env:GITHUB_ENV
if: runner.os == 'Windows'
# Software Vulkan (lavapipe) so the wgpu byte-identity test runs on the GPU-less runners;
# macOS uses the runner's native Metal adapter and needs nothing here.
- name: Install Vulkan runtime (Linux)
run: |
sudo apt-get update
sudo apt-get install --no-install-recommends --yes mesa-vulkan-drivers
if: runner.os == 'Linux'
- name: Install Vulkan runtime (Windows)
run: |
& {
# See https://vulkan.lunarg.com/sdk/home for updates
$sdkVersion = "1.4.341.0"
if ("${{ runner.arch }}" -eq "ARM64") {
$arch = "ARM64"
$urlPath = "warm"
$archDir = ""
$expectedHash = "4a350fbeec743683494f746e9cf7e2052494ca9ae618931afc2abb8985e072b0"
} else {
$arch = "X64"
$urlPath = "windows"
# The archive also contains 32-bit loader in `x86`, which can't be used by 64-bit tests
$archDir = "x64\"
$expectedHash = "20571dcc8292b80a47d68bbbfa4094d87044041f50f4e2e1f326a01e3732b226"
}
$url = "https://sdk.lunarg.com/sdk/download/$sdkVersion/$urlPath/VulkanRT-$arch-$sdkVersion-Components.zip"
Invoke-WebRequest -Uri $url -OutFile VulkanRT.zip
$actualHash = (Get-FileHash VulkanRT.zip -Algorithm SHA256).Hash.ToLower()
if ($actualHash -ne $expectedHash.ToLower()) {
throw "SHA256 mismatch: expected $expectedHash, got $actualHash"
}
7z e VulkanRT.zip -o"${{ runner.temp }}\vulkan" "VulkanRT-$arch-$sdkVersion-Components\${archDir}vulkan-1.dll"
if ($LASTEXITCODE -ne 0) {
throw "Failed to extract Vulkan loader"
}
Remove-Item VulkanRT.zip
$vulkanPath = "${{ runner.temp }}\vulkan"
"$vulkanPath" >> $env:GITHUB_PATH
}
& {
# See https://github.com/mmozeiko/build-mesa/releases for updates
$version = "26.0.5"
if ("${{ runner.arch }}" -eq "ARM64") {
$arch = "arm64"
$archJson = "aarch64"
$expectedHash = "6980c51ce19cff6318d001d05a5fbd9c53cff64d29ea04b5e0285a09b6fe7ae4"
} else {
$arch = "x64"
$archJson = "x86_64"
$expectedHash = "289b283fd13a0029d0226d9695807e62343bb25da2499545bb5f973c97146262"
}
$url = "https://github.com/mmozeiko/build-mesa/releases/download/$version/mesa-lavapipe-$arch-$version.7z"
Invoke-WebRequest -Uri $url -OutFile mesa-lavapipe.7z
$actualHash = (Get-FileHash mesa-lavapipe.7z -Algorithm SHA256).Hash.ToLower()
if ($actualHash -ne $expectedHash.ToLower()) {
throw "SHA256 mismatch: expected $expectedHash, got $actualHash"
}
7z x mesa-lavapipe.7z -o"${{ runner.temp }}\mesa"
if ($LASTEXITCODE -ne 0) {
throw "Failed to extract lavapipe"
}
Remove-Item mesa-lavapipe.7z
$mesaPath = "${{ runner.temp }}\mesa"
"$mesaPath" >> $env:GITHUB_PATH
$icdPath = "$mesaPath\lvp_icd.$archJson.json"
New-Item -Path "HKLM:\SOFTWARE\Khronos\Vulkan\Drivers" -Force| Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Khronos\Vulkan\Drivers" -Name $icdPath -Value 0 -Type DWord
}
if: runner.os == 'Windows'
- name: cargo nextest run --locked
run: |
cargo -Zgitoxide -Zgit nextest run --locked
# Checks benchmark code generation, and runs each benchmark once.
# Fails if code generation fails, benchmarks panic, or generated weights are not valid Rust.
check-runtime-benchmarks:
name: check-runtime-benchmarks (Linux x86-64)
# We always run benchmarks on our Linux reference machine
runs-on: ubuntu-22.04
# Don't use the full 6 hours if a benchmark hangs
timeout-minutes: 120
steps:
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: 's3'
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
- name: runtime-benchmark.sh check
run: |
scripts/runtime-benchmark.sh
staking-fuzzer-test:
name: staking-fuzzer-test (Linux x86-64)
# Fuzzing is most efficient on Linux, it doesn't matter if it fails on other OSes.
# Our runs-on instances don't have the required packages
runs-on: ubuntu-22.04
# Don't use the full 6 hours if fuzzing hangs
timeout-minutes: 120
env:
AFL_SKIP_CPUFREQ: 1
AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES: 1
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Apt update
run: sudo apt-get update
- name: install dependencies
run: sudo apt install -y protobuf-compiler binutils-dev coreutils
- name: install ziggy
run: cargo install --locked --force ziggy@1.3.5 cargo-afl@0.17.0 honggfuzz@0.5.58 grcov@0.10.5
- name: test fuzzer
run: scripts/run-fuzzer.sh
# This job checks all crates individually, including no_std and other featureless builds.
# We need to check crates individually for missing features, because cargo does feature
# unification, which hides missing features when crates are built together.
cargo-check-individually:
name: cargo-check-individually (Linux x86-64)
# If clippy and tests pass on all OSes, it is unlikely that a crate build will pass on Linux but fail on other OSes.
runs-on: ubuntu-22.04
steps:
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: 's3'
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
- name: check all crates individually
run: |
scripts/check-crates-individually.sh
# This job checks for incorrectly added dependencies, or dependencies that were made unused by code changes.
cargo-unused-deps:
name: cargo-unused-deps (Linux x86-64)
# We need to use Linux to check GPU dependencies (or Windows, but it's slow)
runs-on: ubuntu-22.04
steps:
- uses: runs-on/action@d141ef83eb66d096ce8afc767e09115a65c63b60 # v2.1.2
with:
sccache: 's3'
- uses: mozilla-actions/sccache-action@9e7fa8a12102821edf02ca5dbea1acd0f89a2696 # v0.0.10
if: github.repository_owner == 'autonomys'
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Configure tool cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
id: tool-cache
with:
path: '~/**/_tool'
key: ${{ runner.os }}-tool-${{ hashFiles('./rust-toolchain.toml') }}
- name: Install Protoc
uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Install cargo-udeps
uses: taiki-e/install-action@7a79fe8c3a13344501c80d99cae481c1c9085912 # 2.81.10
with:
tool: cargo-udeps
- name: Configure source deps cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-cargo-${{ hashFiles('./Cargo.toml') }}
# If this check fails, check the new dependency is actually needed. If it is, try adding any
# new features to MOST_FEATURES in the script. If that doesn't work, add an exception to the
# crate:
# <https://github.com/est31/cargo-udeps?tab=readme-ov-file#ignoring-some-of-the-dependencies>
- name: check for unused dependencies
run: |
./scripts/find-unused-deps.sh
rust-all:
# Hack for buggy GitHub Actions behavior with skipped checks: https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/collaborating-on-repositories-with-code-quality-features/troubleshooting-required-status-checks#handling-skipped-but-required-checks
if: ${{ always() }}
runs-on: ubuntu-24.04
needs:
- cargo-fmt
- cargo-clippy
- cargo-runtime-build
- cargo-test
- check-runtime-benchmarks
- cargo-check-individually
- cargo-unused-deps
- staking-fuzzer-test
steps:
- name: Check job statuses
# Another hack is to actually check the status of the dependencies or else it'll fall through
run: |
echo "Checking statuses..."
[[ "${{ needs.cargo-fmt.result }}" == "success" ]] || exit 1
[[ "${{ needs.cargo-clippy.result }}" == "success" ]] || exit 1
[[ "${{ needs.cargo-runtime-build.result }}" == "success" ]] || exit 1
[[ "${{ needs.cargo-test.result }}" == "success" ]] || exit 1
[[ "${{ needs.check-runtime-benchmarks.result }}" == "success" ]] || exit 1
[[ "${{ needs.cargo-check-individually.result }}" == "success" ]] || exit 1
[[ "${{ needs.cargo-unused-deps.result }}" == "success" ]] || exit 1
[[ "${{ needs.staking-fuzzer-test.result }}" == "success" ]] || exit 1