Files
pnpm/.github/workflows/ci.yml
Zoltan KochanandClaude Opus 5 4d32532cc7 chore: install the Rust dependencies with pnpm (#14689)
* chore: install the Rust dependencies with pnpm

Turn on `cargo.enabled` so `pnpm install` installs the crates `Cargo.lock`
pins alongside the JavaScript dependencies. pnpm links the registry crates
into `.pnpm/crates/crates-io` and the git-sourced ones into
`.pnpm/crates/git`, then writes a source replacement block into
`.cargo/config.toml` that points Cargo at both.

The `node-semver` fork stays patched in. pnpm installs git-sourced crates
since pnpm/pnpm#14694, which shipped in the 12.4.1 the repository pins, so
enabling this no longer costs the fork's `<=` range and `Ord for Bound`
fixes.

Document the workflow, including the two things a contributor hits first:
`pnpm install` shells out to `cargo`, so it fails when `cargo` is off
`PATH`, and the generated block leaves the tracked `.cargo/config.toml`
modified after every install.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SDxJNVEeyUBb4pcepEpGcj

* ci: initialize Rust before pnpm installs dependencies

Every `pnpm install` now shells out to `cargo metadata`, and there is no
way to opt one out: `cargo.enabled` is read from `pnpm-workspace.yaml`
only, no CLI flag or `PNPM_CONFIG_*` variable overrides it, and `--filter`
does not narrow the Cargo half. So each job whose install runs gets the
pinned toolchain first. `pnpm/setup` installs unless told not to,
`pnpm/update` runs its own install, and `pnpm pipeline` installs before it
runs anything.

The step has to precede the install rather than follow it. The rustup
action ends with `git restore .`, which would otherwise wipe the source
replacement block back out of `.cargo/config.toml`.

Keep that block out of the two workflows that commit. It points at the
gitignored `.pnpm/crates`, so a commit carrying it would break every
Rust-only job and every checkout that has not installed. Both workflows
also decide whether to commit at all by reading `git status --porcelain`,
which the block would make non-empty on every run. Each discards it right
before that check: the release PR in a step of its own, the lockfile
update through the `post-update` command pnpm/update runs between its
install and its commit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SDxJNVEeyUBb4pcepEpGcj

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-10 21:17:43 +02:00

224 lines
8.2 KiB
YAML

name: TS CI
on:
# Run push CI only on the default branch. A branch that lives in this repo
# fires both a `push` and a `pull_request` event for the same commit, and
# both runs report the `TS CI / Success` context to that commit. Branch
# protection then sees two results for the required check, so a cancellation
# or flake on the push side (e.g. two pushes racing on the test.yml
# concurrency group) blocks the PR even when the pull_request run passed.
# Restricting push to `main` means PRs carry `TS CI / Success` only via
# their `pull_request` run (and the merge queue via `merge_group`); `main`
# is validated pre-merge by `merge_group` and re-checked post-merge here.
push:
branches:
- main
pull_request:
merge_group:
permissions:
contents: read # to fetch code (actions/checkout)
jobs:
changes:
name: TS CI / Detect Changes
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: read
pull-requests: read
outputs:
ts: ${{ steps.force.outputs.ts || steps.filter.outputs.ts }}
steps:
# In the merge queue the full suite must run: `TS CI / Compile & Lint`
# is itself a required check, and a skipped job never reports its
# context, which would leave the queue waiting forever. Forcing
# detection true also tests the merged result, which is the point of
# the queue.
- name: Force TS CI for merge queue
if: github.event_name == 'merge_group'
id: force
run: echo "ts=true" >> "$GITHUB_OUTPUT"
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: github.event_name != 'merge_group'
with:
persist-credentials: false
- uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
if: github.event_name != 'merge_group'
id: filter
with:
# The TypeScript pnpm stack lives under pnpm11/, plus the
# workspace-root tooling that drives its build/lint/test.
filters: |
ts:
- 'pnpm11/**'
- '.meta-updater/**'
- '__patches__/**'
- 'package.json'
- 'pnpm-workspace.yaml'
- 'pnpm-lock.yaml'
- '.pnpmfile.cjs'
- 'eslint.config.mjs'
- 'tsconfig.lint.json'
- 'cspell.json'
- '.github/workflows/ci.yml'
- '.github/workflows/test.yml'
- '.github/workflows/build-pnpr.yml'
- '.github/scripts/**'
compile-and-lint:
needs: changes
# Run only when TypeScript-relevant files changed. Every PR (same-repo or
# fork) is covered by its pull_request run, and push only fires on main, so
# there are no duplicate build jobs to guard against here.
if: ${{ !cancelled() && needs.changes.outputs.ts == 'true' }}
name: TS CI / Compile & Lint
runs-on: blacksmith-4vcpu-ubuntu-2404
steps:
- name: Checkout Commit
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize Rust before dependency installation
uses: $/.github/actions/rustup
with:
restore-cache: false
- name: Install pnpm
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
with:
install: false
- name: Test release publication scripts
run: |
.github/scripts/npm-package-publication-state.test.sh
.github/scripts/npm-staged-publication.test.sh
- name: Compile and lint TypeScript
run: pn pipeline ts-check --include-workspace-root --full --no-cache
- name: Package compiled artifacts
shell: bash
run: |
mapfile -d '' -t lib_dirs < <(find . -type d -name lib -not -path '*/node_modules/*' -print0)
mapfile -d '' -t tsbuildinfo_files < <(find . -name 'tsconfig.tsbuildinfo' -not -path '*/node_modules/*' -print0)
tar -czf compiled.tar.gz --exclude='node_modules' "${lib_dirs[@]}" "${tsbuildinfo_files[@]}" pnpm11/pnpm/dist
- name: Upload compiled artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: compiled-packages
path: compiled.tar.gz
retention-days: 1
# Build the pnpr binaries once per OS via a per-OS reusable workflow (not a
# single matrix job) so each platform's test jobs gate only on their own
# build. `needs` can only target a whole job, never an individual matrix
# leg, so a matrix build would make the ubuntu tests wait for the slower
# windows build and vice versa.
build-pnpr-linux:
needs: changes
if: ${{ !cancelled() && needs.changes.outputs.ts == 'true' }}
name: TS CI / Build pnpr
uses: $/.github/workflows/build-pnpr.yml
with:
os: blacksmith-8vcpu-ubuntu-2404
build-pnpr-windows:
needs: changes
if: ${{ !cancelled() && needs.changes.outputs.ts == 'true' }}
name: TS CI / Build pnpr
uses: $/.github/workflows/build-pnpr.yml
with:
os: blacksmith-8vcpu-windows-2025
test:
name: TS CI / Test / ${{ matrix.platform_label }}
needs: [compile-and-lint, build-pnpr-linux]
strategy:
fail-fast: false
matrix:
include:
- node: '22.13.0'
node_major: '22'
platform: blacksmith-8vcpu-ubuntu-2404
platform_label: ubuntu
test_chunk: '1'
test_chunk_total: '1'
- node: '24.0.0'
node_major: '24'
platform: blacksmith-8vcpu-ubuntu-2404
platform_label: ubuntu
test_chunk: '1'
test_chunk_total: '1'
garnet: true
- node: '26.8.2'
node_major: '26'
platform: blacksmith-8vcpu-ubuntu-2404
platform_label: ubuntu
test_chunk: '1'
test_chunk_total: '1'
uses: $/.github/workflows/test.yml
with:
node: ${{ matrix.node }}
node_major: ${{ matrix.node_major }}
platform: ${{ matrix.platform }}
test_chunk: ${{ matrix.test_chunk }}
test_chunk_total: ${{ matrix.test_chunk_total }}
garnet: ${{ matrix.garnet == true }}
secrets:
GARNET_API_TOKEN: ${{ secrets.GARNET_API_TOKEN }}
test-windows:
name: TS CI / Test / ${{ matrix.platform_label }}
needs: [compile-and-lint, build-pnpr-windows]
strategy:
fail-fast: false
matrix:
include:
- node: '22.13.0'
node_major: '22'
platform: blacksmith-8vcpu-windows-2025
platform_label: windows 1/3
test_chunk: '1'
test_chunk_total: '3'
- node: '22.13.0'
node_major: '22'
platform: blacksmith-8vcpu-windows-2025
platform_label: windows 2/3
test_chunk: '2'
test_chunk_total: '3'
- node: '22.13.0'
node_major: '22'
platform: blacksmith-8vcpu-windows-2025
platform_label: windows 3/3
test_chunk: '3'
test_chunk_total: '3'
uses: $/.github/workflows/test.yml
with:
node: ${{ matrix.node }}
node_major: ${{ matrix.node_major }}
platform: ${{ matrix.platform }}
test_chunk: ${{ matrix.test_chunk }}
test_chunk_total: ${{ matrix.test_chunk_total }}
# Single aggregate gate — the only TS CI context branch protection needs
# to require. Listing the individual jobs as required checks does not
# work: they skip on non-TypeScript PRs, and a matrix job skipped at the
# job level never expands its `${{ matrix.* }}` name, so the per-platform
# contexts it would report never appear and the PR blocks forever waiting
# for them. This job always runs (it reports under a static name in every
# state) and fails only if a dependency actually failed or was cancelled —
# skipped dependencies count as a pass.
success:
name: TS CI / Success
if: ${{ always() }}
needs:
- changes
- compile-and-lint
- build-pnpr-linux
- build-pnpr-windows
- test
- test-windows
runs-on: blacksmith-4vcpu-ubuntu-2404
steps:
- name: Fail if any dependency failed or was cancelled
if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
run: exit 1