Skip to content

fix(ci): make develop CI green — benchmark find caps, cargo-audit --locked - #3861

Open
kylehgc wants to merge 3 commits into
rtk-ai:developfrom
kylehgc:submit/ci-green
Open

kylehgc wants to merge 3 commits into
rtk-ai:developfrom
kylehgc:submit/ci-green

Conversation

@kylehgc

@kylehgc kylehgc commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Fixes #3860. Two CI-only changes, one commit each, that make develop CI green again.

scripts/benchmark.sh: count find names only

Since #3854 rtk find --max N ends with a ... (N filtered) disclosure note and a [see remaining: tail -n +1 <tee log>] pointer. count_find_names / count_find_total counted every word on those lines as a name, so the find --max 10/100 cap checks read 19 and 109 names. Both counters now skip the two lines, anchored to their exact shapes (find_cmd.rs filtered_hint, tee.rs force_tee_tail_hint), next to the existing +N more / ext: skips.

Verified against a develop build in this repo, feeding rtk find '*' --max N through the two functions before / after:

--max 10   names 19 → 10    total 494 → 485
--max 100  names 109 → 100  total 485 → 485

Edge shapes checked: ... (1000+ filtered) (the FILTERED_CAP form) is skipped; tee disabled means no pointer line and nothing to skip; a real entry named ... (odd) name still counts. The --max cap itself is honoured (+475 more after 10 names); the counters were the bug, not find.

.github/workflows/ci.yml: cargo install cargo-audit --locked

tinyvec 1.13.0 (published 2026-09-03) does not compile under an unlocked resolve, so a cache miss on the Security Scan job now dies before the audit runs. --locked uses cargo-audit's own lockfile (tinyvec 1.11.0). Verified locally: unlocked exits 101 with the same error, locked installs cargo-audit 0.22.2. The advisory database is fetched at run time, so a locked build cannot make the audit stale.

Not changed

The golangci-lint benchmark row on the same runs is a separate failure (Go 1.27 on the runner) and is not touched here. release.yml has two more unlocked cargo install steps with the same exposure; left for a separate change.

cargo install cargo-audit resolves tinyvec 1.13.0 (released 2026-09-03), which fails to compile ("cannot find macro vec in this scope"), so the Security Scan job dies before the audit runs. --locked uses cargo-audit's own lockfile, which pins a tinyvec that builds. Verified locally: unlocked reproduces the error, locked installs cargo-audit 0.22.2.
…e pointer

Since upstream's find started disclosing hidden and gitignored matches (765b270, 68dc719), rtk find --max N ends with a "... (N filtered)" note and a "[see remaining: tail -n +1 <tee log>]" pointer. The benchmark's count_find_names/count_find_total awk counted every word on those two lines as a name, so the --max 10 cap read as 19 names and --max 100 as 109, and both cap checks failed on develop (fork run 33812431685; upstream develop fails the same two checks). Skip both lines in both counters. Locally in this repo: 19/109 -> 10/100 names, total 494 -> 485.
@kylehgc

kylehgc commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Rebased by merge (append-only) onto current develop. The benchmark half of this PR is now superseded by #3863 (d952a6b), which skips the same ... (N filtered) and [see remaining: ...] lines in count_find_names / count_find_total, so scripts/benchmark.sh is back to upstream's file here.

What remains is the single line from the original description:

run: cargo install cargo-audit --locked

cargo install cargo-audit without --locked resolves cargo-audit's dependencies fresh on every CI run; the tinyvec 1.11.0 release broke the build of the unlocked tree and turned the security job red on develop with no change to this repository. --locked pins cargo-audit to its own shipped Cargo.lock, which is what its README recommends and what the fix in fork CI has run green on since 2026-09-03.

Happy to retitle to fix(ci): install cargo-audit with --locked if you'd like the title to match the trimmed scope.

…t half

The benchmark find-count half (a990b99) is superseded by d952a6b (rtk-ai#3863),
which skips the same disclosure-note and tee-pointer lines; scripts/benchmark.sh
is upstream's again. What remains is the single ci.yml line:
`cargo install cargo-audit --locked`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

develop CI red since #3854: benchmark find --max caps count the disclosure note; cargo-audit install breaks on tinyvec 1.13.0

1 participant