Files
ngit-grasp/.ngit/act/workflows/rust_ci.yaml
T
DanConwayDev 2b93d25fdd ci: publish release tags to crates.io from Nostr CI
Crates.io publication is a manual release step even though Nostr CI already validates tagged commits. Publish after the existing lint, formatting and test steps succeed, using a repository-scoped CARGO_REGISTRY_TOKEN secret only in the publication step.

Require a push event on a v-prefixed tag and an exact manifest-version match. Use Cargo package verification and --locked against the explicit crates-io registry. Only ngit-grasp is selected; grasp-audit remains unpublished.

This assumes the coordinator has the scoped token configured and the tagged commit contains this workflow. It does not change archive/NIP-82 publication, stable promotion, documentation sync or registry versions; no live crate was uploaded during development.

Validated workflow syntax with actionlint, matching/mismatched tag and missing-secret cases with an intercepted publish command, Cargo packaging without upload, cargo fmt --all -- --check, and git diff --cached --check.
2026-09-12 06:41:52 +00:00

82 lines
3.8 KiB
YAML

# Docs-only pushes are skipped: a push runs only when at least one changed
# file falls outside the ignore list, so mixed code+docs pushes still run.
# Tag pushes always run regardless of path filters, and pull_request stays
# unfiltered because ngit-ci does not evaluate PR path filters yet (filtered
# PR triggers would run unconditionally anyway).
on:
push:
paths-ignore:
- "docs/**"
- "**/*.md"
- "work/**"
pull_request:
name: Rust CI
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Restore Nix store cache
continue-on-error: true
uses: nix-community/cache-nix-action@v7
with:
primary-key: nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
restore-prefixes-first-match: nix-${{ runner.os }}-
# cache-nix-action requires a token even with purge disabled;
# github.token is empty under ngit-ci, so any non-empty value works.
token: unused
- name: Restore Rust build cache
continue-on-error: true
uses: actions/cache@v4
with:
path: |
~/.cargo/git
~/.cargo/registry
target
key: rust-${{ runner.os }}-${{ hashFiles('**/Cargo.toml', 'Cargo.lock', 'flake.lock') }}
restore-keys: |
rust-${{ runner.os }}-
# The suite must be hermetic with respect to ambient git configuration,
# so CI always runs it under a deliberately hostile global config: a
# failing pre-commit hook delivered via both core.hooksPath and
# init.templateDir, plus the settings that have bitten before. The
# settings target test-side git only: the relay never runs `git commit`,
# so its server-side operations are unaffected except for
# init.defaultBranch, which is exactly the regression being guarded.
# (The hermetic helpers make the tests themselves config-blind, so this
# single run also covers hosts where these settings are unset.)
- name: Install hostile git configuration
run: |
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
git config --global init.defaultBranch main
git config --global core.hooksPath /tmp/hostile-git/hooks
git config --global init.templateDir /tmp/hostile-git/template
git config --global commit.gpgsign true
git config --global core.autocrlf true
- run: nix develop --command cargo fmt --all -- --check
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
- run: nix develop --command cargo test --locked
- run: nix develop --command cargo test -p grasp-audit --locked
- name: Publish release tag to crates.io
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: |
set -euo pipefail
version="$(nix eval --impure --raw --expr '(builtins.fromTOML (builtins.readFile ./Cargo.toml)).package.version')"
if [[ "$GITHUB_REF" != "refs/tags/v$version" ]]; then
echo "release tag must match Cargo.toml version v$version" >&2
exit 1
fi
: "${CARGO_REGISTRY_TOKEN:?Configure the repository CARGO_REGISTRY_TOKEN secret in ngit-ci}"
nix develop --command cargo publish --locked --registry crates-io --package ngit-grasp