From c6cdee28c9395ad62b363e90e410212ad975b324 Mon Sep 17 00:00:00 2001 From: AKolenda Date: Fri, 2 Oct 2026 00:31:37 -0600 Subject: [PATCH 1/2] ci(pr-automation): compare APIs using locked dependencies --- .github/PR_AUTOMATION.md | 2 ++ .github/workflows/pr-automation.yml | 30 ++++++++++++++++++++++++----- 2 files changed, 27 insertions(+), 5 deletions(-) diff --git a/.github/PR_AUTOMATION.md b/.github/PR_AUTOMATION.md index 199298629..256828eb3 100644 --- a/.github/PR_AUTOMATION.md +++ b/.github/PR_AUTOMATION.md @@ -194,6 +194,8 @@ Risk labels express required maintainer scrutiny: | `risk/unknown` | No valid classification was available. | `cargo-semver-checks` incompatibility forces `risk/high`. +The API check builds baseline and head rustdoc JSON with `cargo rustdoc --locked`, +so both builds use their committed dependency versions before comparison. A model-suspected breaking change promotes `risk/low` to `risk/medium`. Path rules can add `scope/core`, `scope/web`, `scope/ffi`, and `scope/tooling`. The classifier controls `scope/cross-cutting`, `kind/technical-debt`, and documentation-only classification. diff --git a/.github/workflows/pr-automation.yml b/.github/workflows/pr-automation.yml index 70c16b622..4c2dd71e5 100644 --- a/.github/workflows/pr-automation.yml +++ b/.github/workflows/pr-automation.yml @@ -403,11 +403,31 @@ jobs: CARGO_HOME="$semver_cargo" \ CARGO_TARGET_DIR="$semver_target" \ PATH="$rust_bin_dir:$PATH" \ - "$semver_bin" \ - --package ironrdp \ - --only-explicit-features \ - --features "$CARGO_SEMVER_CHECKS_FEATURES" \ - --baseline-rev "$BASE_SHA" + RUSTC_BOOTSTRAP=1 \ + RUSTDOCFLAGS="-Z unstable-options --document-private-items --document-hidden-items --output-format=json --cap-lints=allow" \ + HEAD_SHA="$HEAD_SHA" \ + BASE_SHA="$BASE_SHA" \ + SEMVER_BIN="$semver_bin" \ + SEMVER_FEATURES="$CARGO_SEMVER_CHECKS_FEATURES" \ + bash -euo pipefail -c ' + # cargo-semver-checks normally resolves a new dependency graph in a + # placeholder crate. Build rustdoc ourselves so both revisions use + # their committed lockfiles, just like the ordinary CI build. + artifact_root="$CARGO_TARGET_DIR" + for revision in baseline current; do + if [[ "$revision" == baseline ]]; then + git checkout --detach "$BASE_SHA" + else + git checkout --detach "$HEAD_SHA" + fi + export CARGO_TARGET_DIR="$artifact_root/$revision" + cargo rustdoc --locked --package ironrdp --lib \ + --no-default-features --features "$SEMVER_FEATURES" + done + "$SEMVER_BIN" \ + --current-rustdoc "$artifact_root/current/doc/ironrdp.json" \ + --baseline-rustdoc "$artifact_root/baseline/doc/ironrdp.json" + ' status=$? set -e case "$status" in From 3f0d8c48ac13be945d6a96fe06fe1df359ebf484 Mon Sep 17 00:00:00 2001 From: AKolenda Date: Fri, 9 Oct 2026 23:19:30 -0600 Subject: [PATCH 2/2] ci(pr-automation): flatten the locked rustdoc build loop Build each revision through a small helper called once per SHA and pass the artifact root explicitly instead of capturing CARGO_TARGET_DIR before overwriting it. --- .github/workflows/pr-automation.yml | 24 ++++++++++-------------- 1 file changed, 10 insertions(+), 14 deletions(-) diff --git a/.github/workflows/pr-automation.yml b/.github/workflows/pr-automation.yml index 4c2dd71e5..c36a2ac58 100644 --- a/.github/workflows/pr-automation.yml +++ b/.github/workflows/pr-automation.yml @@ -401,7 +401,6 @@ jobs: sudo -u nobody env -i \ HOME="$semver_home" \ CARGO_HOME="$semver_cargo" \ - CARGO_TARGET_DIR="$semver_target" \ PATH="$rust_bin_dir:$PATH" \ RUSTC_BOOTSTRAP=1 \ RUSTDOCFLAGS="-Z unstable-options --document-private-items --document-hidden-items --output-format=json --cap-lints=allow" \ @@ -409,24 +408,21 @@ jobs: BASE_SHA="$BASE_SHA" \ SEMVER_BIN="$semver_bin" \ SEMVER_FEATURES="$CARGO_SEMVER_CHECKS_FEATURES" \ + SEMVER_ARTIFACT_ROOT="$semver_target" \ bash -euo pipefail -c ' # cargo-semver-checks normally resolves a new dependency graph in a # placeholder crate. Build rustdoc ourselves so both revisions use # their committed lockfiles, just like the ordinary CI build. - artifact_root="$CARGO_TARGET_DIR" - for revision in baseline current; do - if [[ "$revision" == baseline ]]; then - git checkout --detach "$BASE_SHA" - else - git checkout --detach "$HEAD_SHA" - fi - export CARGO_TARGET_DIR="$artifact_root/$revision" - cargo rustdoc --locked --package ironrdp --lib \ - --no-default-features --features "$SEMVER_FEATURES" - done + build_rustdoc() { + git checkout --detach "$2" + CARGO_TARGET_DIR="$SEMVER_ARTIFACT_ROOT/$1" cargo rustdoc --locked \ + --package ironrdp --lib --no-default-features --features "$SEMVER_FEATURES" + } + build_rustdoc baseline "$BASE_SHA" + build_rustdoc current "$HEAD_SHA" "$SEMVER_BIN" \ - --current-rustdoc "$artifact_root/current/doc/ironrdp.json" \ - --baseline-rustdoc "$artifact_root/baseline/doc/ironrdp.json" + --current-rustdoc "$SEMVER_ARTIFACT_ROOT/current/doc/ironrdp.json" \ + --baseline-rustdoc "$SEMVER_ARTIFACT_ROOT/baseline/doc/ironrdp.json" ' status=$? set -e