Skip to content

ci: run the Rust build, tests and audit on the consumed branch - #8

Merged
kalyazin merged 2 commits into
feat_write_protectionfrom
ci/rust-on-consumed-branch
Sep 30, 2026
Merged

kalyazin merged 2 commits into
feat_write_protectionfrom
ci/rust-on-consumed-branch

Conversation

@kalyazin

@kalyazin kalyazin commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

rust.yml filtered to main, so feat_write_protection — the branch this crate is consumed from, and now the default branch — had no build, test or cargo audit. The security workflows scan it; nothing built it. Both filters gain the branch rather than moving to it, so main keeps what it had.

Widening it exposed two things in the matrix, both settled by running it rather than by reading:

ubuntu-20.04 no longer schedules. GitHub retired the label in April 2025, and a job naming it does not fail — it sits queued indefinitely, so a required check computed from it never returns.

The leg's purpose is no longer reachable on hosted runners. It existed to exercise the userfaultfd syscall path, taken when /dev/userfaultfd is absent. ubuntu-22.04 now runs kernel 6.8 and ubuntu-latest runs 6.17 — both past 6.1, so both carry the device, and the port to 22.04 failed with OpenDevUserfaultfd(PermissionDenied) precisely because the device was there and the ACL step was still gated to ubuntu-latest. The matrix keeps two kernels, which is real coverage, and the comment now records that the syscall fallback has no hosted runner left to cover it rather than implying it is still tested.

The ubuntu-20.04 header install goes with the label: 22.04's own headers are new enough for the linux5_7 feature, so one step covers both runners.

Verified: all eleven checks green, both build legs and audit among them.

The filters named main only, so the branch this crate is consumed from had
no build, test or audit at all — and it is now the default branch, leaving
main with the build and nobody consuming it.

Signed-off-by: Nikita Kalyazin <nikita.kalyazin@e2b.dev>
@cursor

cursor Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Workflow-only changes; no application code, with reduced kernel-path coverage in CI only.

Overview
rust.yml only ran on main, so feat_write_protection never got cargo build, tests, or audit. Push and pull_request now include that branch alongside main.

The build matrix swaps retired ubuntu-20.04 for ubuntu-22.04. The old leg that exercised userfaultfd via syscall without /dev/userfaultfd is gone; both runners are documented as kernels past 6.1 with the device node. /dev/userfaultfd setup and linux5_7 tests run on every matrix row instead of only ubuntu-latest, and the ubuntu-20.04-only step that installed linux-headers-5.11.0-25-generic for those tests is removed.

Reviewed by Cursor Bugbot for commit b10ee6b. Bugbot is set up for automated code reviews on this repo. Configure here.

@cla-bot cla-bot Bot added the cla-signed label Sep 29, 2026
GitHub retired the label in April 2025, and a job naming it does not fail —
it sits queued, so a required check computed from it never returns.

ubuntu-22.04 carries the same 5.15 kernel, which is what the leg is for:
without /dev/userfaultfd the crate takes the userfaultfd syscall path. Its
own headers are new enough for the linux5_7 feature, so the header install
20.04 needed goes with it and one step now covers both runners.

Signed-off-by: Nikita Kalyazin <nikita.kalyazin@e2b.dev>
@kalyazin
kalyazin force-pushed the ci/rust-on-consumed-branch branch from 5dfb4a5 to b10ee6b Compare September 29, 2026 15:36
@kalyazin
kalyazin marked this pull request as ready for review September 29, 2026 15:43
@kalyazin
kalyazin merged commit 2a303a1 into feat_write_protection Sep 30, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants