From c1c337c2a22b5dd9d9ccb504c186ffb4bb42ca32 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Mon, 28 Sep 2026 12:37:04 +0200 Subject: [PATCH] ci: no toolchain installs on the bare aarch64 (klokka) runner; builtin:checkout The aarch64 release leg runs on the klokka host. Gate the sccache / cargo-binstall / cargo-leptos installs to the ephemeral x86_64 container; on the bare runner check-and-fail instead (the sccache tarball was x86_64-only anyway, so it was both a host mutation and a wrong-arch binary). Switch checkout to v4 builtin:checkout (native Go, no Node/download) in all jobs. Co-Authored-By: Claude Opus 4.8 --- .gitea/workflows/release.yml | 37 ++++++++++++++++++++++++------------ 1 file changed, 25 insertions(+), 12 deletions(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 8a8ba87..4a35d8a 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -23,7 +23,7 @@ jobs: runs-on: ${{ matrix.runs-on }} steps: - - uses: actions/checkout@v4 + - uses: builtin:checkout - name: Install Rust stable uses: dtolnay/rust-toolchain@stable @@ -39,22 +39,35 @@ jobs: echo "RUSTC_WRAPPER=sccache" >> "$GITHUB_ENV" echo "SCCACHE_DIR=${{ matrix.sccache_dir }}" >> "$GITHUB_ENV" mkdir -p "${{ matrix.sccache_dir }}" - if ! command -v sccache >/dev/null 2>&1; then - V=0.8.2 - curl -sSL "https://github.com/mozilla/sccache/releases/download/v${V}/sccache-v${V}-x86_64-unknown-linux-musl.tar.gz" | tar -xz - sudo install -m0755 "sccache-v${V}-x86_64-unknown-linux-musl/sccache" /usr/local/bin/sccache + if command -v sccache >/dev/null 2>&1; then sccache --version; exit 0; fi + # Bare runners (aarch64 = klokka host) are pre-provisioned; CI must not + # install onto them (and this tarball is x86_64-only). Only the + # ephemeral x86_64 container installs; a bare host missing it fails loud. + if [ "${{ matrix.arch }}" != x86_64 ]; then + echo "::error::sccache missing on the bare ${{ matrix.arch }} runner — provision klokka; CI must not install on bare hosts"; exit 1 fi + V=0.8.2 + curl -sSL "https://github.com/mozilla/sccache/releases/download/v${V}/sccache-v${V}-x86_64-unknown-linux-musl.tar.gz" | tar -xz + sudo install -m0755 "sccache-v${V}-x86_64-unknown-linux-musl/sccache" /usr/local/bin/sccache sccache --version - name: Install cargo-binstall run: | - command -v cargo-binstall || \ - curl -L --proto '=https' --tlsv1.2 -sSf \ - https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh \ - | bash + if command -v cargo-binstall >/dev/null 2>&1; then exit 0; fi + if [ "${{ matrix.arch }}" != x86_64 ]; then + echo "::error::cargo-binstall missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1 + fi + curl -L --proto '=https' --tlsv1.2 -sSf \ + https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh \ + | bash - name: Install cargo-leptos - run: command -v cargo-leptos || cargo binstall cargo-leptos --locked --no-confirm + run: | + if command -v cargo-leptos >/dev/null 2>&1; then exit 0; fi + if [ "${{ matrix.arch }}" != x86_64 ]; then + echo "::error::cargo-leptos missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1 + fi + cargo binstall cargo-leptos --locked --no-confirm - name: Build run: cargo leptos build --release @@ -111,7 +124,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: builtin:checkout - name: Log in to Docker Hub run: echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u bendik --password-stdin @@ -128,7 +141,7 @@ jobs: runs-on: aarch64 steps: - - uses: actions/checkout@v4 + - uses: builtin:checkout - name: Compute checksums and update PKGBUILD run: |