Files
ngit-grasp/.ngit/act/workflows/rust_ci.yaml
T
DanConwayDev 7f7530664b ci: pass placeholder token to cache-nix-action
cache-nix-action@v7 reads its token input as required in both restore
and save; its github.token default is empty under ngit-ci (no
GITHUB_TOKEN is injected), so both phases threw "Input required and not
supplied: token" and, hidden by continue-on-error, the Nix store cache
never restored or saved. Any non-empty value satisfies the check and is
never transmitted while purge (default off) stays disabled.

Validation: matches the fix applied to ngit-ci's own workflows and its
documented snippet; the next push-triggered run should show the
restore/save steps succeeding instead of failing fast.
2026-08-19 18:26:10 +00:00

69 lines
3.1 KiB
YAML

# Docs-only pushes are skipped: a push runs only when at least one changed
# file falls outside the ignore list, so mixed code+docs pushes still run.
# Tag pushes always run regardless of path filters, and pull_request stays
# unfiltered because ngit-ci does not evaluate PR path filters yet (filtered
# PR triggers would run unconditionally anyway).
on:
push:
paths-ignore:
- "docs/**"
- "**/*.md"
- "work/**"
pull_request:
name: Rust CI
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Restore Nix store cache
continue-on-error: true
uses: nix-community/cache-nix-action@v7
with:
primary-key: nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
restore-prefixes-first-match: nix-${{ runner.os }}-
# cache-nix-action requires a token even with purge disabled;
# github.token is empty under ngit-ci, so any non-empty value works.
token: unused
- name: Restore Rust build cache
continue-on-error: true
uses: actions/cache@v4
with:
path: |
~/.cargo/git
~/.cargo/registry
target
key: rust-${{ runner.os }}-${{ hashFiles('**/Cargo.toml', 'Cargo.lock', 'flake.lock') }}
restore-keys: |
rust-${{ runner.os }}-
# The suite must be hermetic with respect to ambient git configuration,
# so CI always runs it under a deliberately hostile global config: a
# failing pre-commit hook delivered via both core.hooksPath and
# init.templateDir, plus the settings that have bitten before. The
# settings target test-side git only: the relay never runs `git commit`,
# so its server-side operations are unaffected except for
# init.defaultBranch, which is exactly the regression being guarded.
# (The hermetic helpers make the tests themselves config-blind, so this
# single run also covers hosts where these settings are unset.)
- name: Install hostile git configuration
run: |
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
git config --global init.defaultBranch main
git config --global core.hooksPath /tmp/hostile-git/hooks
git config --global init.templateDir /tmp/hostile-git/template
git config --global commit.gpgsign true
git config --global core.autocrlf true
- run: nix develop --command cargo fmt --all -- --check
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
- run: nix develop --command cargo test --locked
- run: nix develop --command cargo test -p grasp-audit --locked