Skip to content

ci(pr-automation): compare APIs using locked dependencies - #2071

Open
AKolenda wants to merge 1 commit into
Devolutions:masterfrom
AKolenda:fix/pr-semver-locked-dependencies
Open

AKolenda wants to merge 1 commit into
Devolutions:masterfrom
AKolenda:fix/pr-semver-locked-dependencies

Conversation

@AKolenda

@AKolenda AKolenda commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

The public API compatibility job currently fails before comparing APIs because cargo-semver-checks resolves a fresh dependency graph in its placeholder crate. This selects picky-krb 0.12.5, whose new GssApiMessageError variant breaks sspi 0.21.3; ordinary CI succeeds using the committed lockfile's picky-krb 0.12.4.

Build baseline and head rustdoc JSON with cargo rustdoc --locked, then compare those artifacts with the existing pinned cargo-semver-checks binary. Both revisions retain their own locked dependencies. The existing unprivileged nobody execution, cleared environment, tool checksum, feature selection, and compatibility exit-code handling remain in place.

This fixes a shared automation failure affecting #2009, #2010, #2012, #2013, #2014 and #2016. Example failed job: https://github.com/Devolutions/IronRDP/actions/runs/36972417921/job/110729084933. Because this is a pull_request_target workflow, the repair takes effect for other PRs after it lands on the base branch.

Validation:

  • Real IronRDP cargo rustdoc --locked build with the full workflow feature set passed; the pinned comparator parsed and compared the resulting JSON.
  • Extracted workflow fixtures: unchanged API exits 0, removed root function exits 100, stale lockfile exits 101 without modifying the lockfile.
  • YAML parsing, Bash syntax checks, and git diff --check passed.
  • Fixture execution used the exact cleared-environment inner script as the current user; local sudo requires a password, so the unchanged nobody boundary was inspected rather than executed locally.

The comparator's existing inability to detect some changes through dependency re-exports reproduces with both its placeholder mode and this JSON mode; that separate limitation is unchanged.

Copilot AI lite review requested due to automatic review settings October 2, 2026 06:34
@AKolenda
AKolenda requested review from a team as code owners October 2, 2026 06:34
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

The account paying for this security review has reached its Codex usage limits. The payer can check the Codex usage dashboard. For personal accounts, using credits requires enabling “Use credits for security reviews” in Code review settings. If you do not manage the paying account, contact this repository's admins.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues remain.

Review effort: Lite
Findings: None

What changed in this PR

Updates PR automation to compare public APIs using rustdoc artifacts generated with each revision’s locked dependencies.

Changes:

  • Builds baseline and head rustdoc JSON with cargo rustdoc --locked.
  • Compares artifacts using the pinned semver checker.
  • Documents the locked-dependency workflow.
File Summary
.github/​workflows/​pr-automation.yml Builds and compares locked rustdoc artifacts.
.github/​PR_AUTOMATION.md Documents the updated compatibility check.

This branch was successfully deployed

1 active deployment
llm-providers — 2455b399 Deployed Oct 2, 2026 by AKolenda via Classify pull request #1579
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation-failed Exact-head automated classification or review failed or was unavailable risk/unknown Risk could not be determined automatically; needs maintainer-level scrutiny scope/tooling Build, CI, release, or developer tooling size/XS Size: up to 49 counted lines and 2 files

Development

Successfully merging this pull request may close these issues.

2 participants