From 70314b6c60d8180237d66baf372d7f5dfd4ea1d8 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Fri, 4 Sep 2026 01:08:16 +0200 Subject: [PATCH] ci: stop routing CI's cargo through the sandbox wrapper The kernel test step added in #153 fails on every PR: error: rustup could not choose a version of cargo to run, because one wasn't specified explicitly, and no default is configured ops/cargo.sh unconditionally redirects RUSTUP_HOME to $HOME/.relayflows-toolchain/rustup. On a runner that directory is empty, so the rustup shim has no toolchain to resolve. It passed locally only because every command in that verification had RUSTUP_TOOLCHAIN=stable in front of it, and the workflow was written without it -- so the evidence behind #153 was not the command #153 shipped. The wrapper exists for a cloud sandbox, where the propagated tree drops files over a per-file size cap and a toolchain must be obtainable per step. A GitHub runner has neither constraint, and dtolnay/rust-toolchain has already installed a default toolchain into the standard home. Use plain cargo, as the adjacent release build already does and as its passing runs demonstrate. The SDK step has the same problem through npm test -> test:prep, so expand npm test to its constituents and drop test:prep. Its only real output is the relayflowd binary live-kernel.test.ts execs, and this job has already built one: point RELAYFLOWD_BIN at the release binary instead of compiling a second debug copy through a wrapper that cannot run here. test:prep's chmod of the preflight CLI fixtures is kept inline. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR Session-Id: c228933d-4f94-4d83-9a9a-daf3c83b94f1 --- .github/workflows/cloud-runtime-artifact.yml | 45 +++++++++++++++----- 1 file changed, 35 insertions(+), 10 deletions(-) diff --git a/.github/workflows/cloud-runtime-artifact.yml b/.github/workflows/cloud-runtime-artifact.yml index 8b3f8701f..484897c94 100644 --- a/.github/workflows/cloud-runtime-artifact.yml +++ b/.github/workflows/cloud-runtime-artifact.yml @@ -50,11 +50,21 @@ jobs: # opposite contracts that both passed because neither was ever executed. # # The toolchain and the build are already paid for above; this adds the - # test run and nothing else. Invoked through ops/cargo.sh, as the repo - # does everywhere else, so the target directory stays outside the tree. + # test run and nothing else. + # + # Plain `cargo`, NOT ops/cargo.sh. That wrapper unconditionally redirects + # RUSTUP_HOME to $HOME/.relayflows-toolchain/rustup, which on a runner is + # empty, so the rustup shim has nothing to choose: + # error: rustup could not choose a version of cargo to run, because one + # wasn't specified explicitly, and no default is configured + # The wrapper exists for a cloud sandbox, where the propagated tree drops + # files over a size cap; a GitHub runner has neither that constraint nor + # that tree, and dtolnay/rust-toolchain has already installed a default + # toolchain into the standard home. Matching the build step above is both + # simpler and the configuration that is known to work here. - name: Test kernel working-directory: kernel - run: sh ../ops/cargo.sh test --workspace + run: cargo test --workspace - name: Install SDK dependencies run: npm ci --prefix sdk @@ -66,13 +76,28 @@ jobs: # added to any other file never runs, which is how ~22 of ~26 SDK # test files were uncovered. # - # `npm test` is the repo's own entry point and a strict superset of - # what this step used to do: - # test:prep && typecheck && build && typecheck:tests && vitest run - # test:prep builds the relayflowd binary that tests/live-kernel.test.ts - # execs, and the build it runs is why a bare `vitest run` is wrong - # here -- several files fail at collection without sdk/dist. - npm test + # This is `npm test` expanded, minus test:prep. `npm test` is + # test:prep && typecheck && build && typecheck:tests && vitest run, + # and test:prep shells out to ops/cargo.sh -- which fails on a runner + # for the reason given on the kernel step above. Its only purpose is + # to produce the relayflowd binary that tests/live-kernel.test.ts + # execs, and this job has already built one: the release binary from + # the build step. Point RELAYFLOWD_BIN at it rather than compiling a + # second, debug copy through a wrapper that cannot run here. + # + # The build is still required: several test files fail at collection + # without sdk/dist, which is why a bare `vitest run` is not enough. + # test:prep's other half, kept: it re-asserts the executable bit on the + # preflight CLI fixtures. They are committed 100755 so actions/checkout + # already restores them, but the guard is one line and the failure it + # prevents is an opaque EACCES deep inside a preflight test. + ( [ ! -d ../testdata/preflight ] || \ + find ../testdata/preflight -name '*-cli' -type f -exec chmod +x {} + ) + npm run typecheck + npm run build + npm run typecheck:tests + RELAYFLOWD_BIN="$GITHUB_WORKSPACE/kernel/target/release/relayflowd" \ + ./node_modules/.bin/vitest run - name: Build standalone flows CLI run: |