Skip to content

feat: Auto-track c2pa-rs's main branch - #309

Merged
scouten-adobe merged 1 commit into
mainfrom
track-c2pa-rs-main
Sep 9, 2026
Merged

scouten-adobe merged 1 commit into
mainfrom
track-c2pa-rs-main

Conversation

@scouten-adobe

Copy link
Copy Markdown
Collaborator

Switches main's c2pa dependency to a git dependency on c2pa-rs's main branch (currently an unpublished 0.91.0-dev version requirement that doesn't resolve at all -- crates.io's max is 0.90.20, so main is currently broken). A new scheduled workflow (track-c2pa-rs-main.yml) runs cargo update -p c2pa on weekday mornings and pushes directly to main if Cargo.lock changed.

Also commits the first real Cargo.lock for this repo -- the migration deliberately didn't carry the old workspace-relative one forward (it wasn't meaningful outside the workspace), so main has had none until now. This is what makes the cargo-lock job in #308 meaningful.

stable (and any future v0.* line) is untouched -- it keeps a real crates.io version dependency, required for crates.io publishing (git deps can't publish).

Verified locally: cargo check resolves and builds against the git dependency.

Part of restoring c2patool's post-cutover release infrastructure. Unblocks #308.

main's c2pa dependency switches from an unpublished version requirement
(0.91.0-dev, which currently doesn't resolve at all -- crates.io's max is
0.90.20) to a git dependency on c2pa-rs's main branch, so this repo's
main continuously integration-tests against upstream's latest
in-development code instead of only catching breaks once a new c2pa
version publishes.

New scheduled workflow keeps Cargo.lock fresh against that branch
(cargo update -p c2pa, committed directly to main if it changed) --
otherwise a committed Cargo.lock would just keep resolving to whatever
commit was current when it was last generated, defeating the point.

stable (and any v0.* line) is unaffected -- it keeps a real crates.io
version dependency, required for crates.io publishing.
@scouten-adobe
scouten-adobe marked this pull request as ready for review September 9, 2026 18:51
@scouten-adobe
scouten-adobe merged commit a0e129c into main Sep 9, 2026
2 of 3 checks passed
@scouten-adobe
scouten-adobe deleted the track-c2pa-rs-main branch September 9, 2026 19:57
scouten-adobe added a commit that referenced this pull request Sep 9, 2026
Actions has been off since the cutover, so none of this had ever
actually executed until now:

- deny.toml: add contentauth/c2pa-rs to allow-git. main's own c2pa git
  dependency (#309) is intentional, but cargo-deny's sources check
  denies unrecognized git sources by default.
- src/main.rs: fix a stale test-fixture path (../../cli/tests/... ->
  ../tests/...) left over from the pre-flattening workspace layout.
  Broke both cargo test and clippy --all-targets (which compiles tests).
- Cargo.toml: split the c2pa dependency by target. It hardcoded the
  openssl backend feature unconditionally, which can't compile for
  wasm32 (c2pa-rs's own openssl dependency is itself gated to
  not(target_arch = "wasm32")) -- the wasi target needs
  rust_native_crypto instead. Needed 'resolver = "3"' too: edition 2018
  defaults to resolver 1, which unifies a dependency's features across
  ALL targets in one pass instead of resolving per-target, so both
  backends were getting enabled simultaneously and colliding.
- ci.yml / beta-preflight.yml: drop the doc-tests job entirely --
  c2patool has no library target, so 'cargo test --doc' has nothing to
  test and errors outright ('no library targets found'). The
  docs-private job (cargo doc --document-private-items) is the
  meaningful internal-docs check for a binary crate; doc-tests never
  applied here.

All four verified locally: cargo test --bins (14 passed), clippy
--all-targets, cargo deny check (all ok), and cargo +nightly-2026-01-16
test --target wasm32-wasip2 --no-run (compiles clean).
scouten-adobe added a commit that referenced this pull request Sep 9, 2026
* ci: Restore full CI job set for the standalone repo

Migration only carried a tests-cli slice. Restores everything from
c2pa-rs's tier-1a.yml/beta-preflight.yml that still applies to a
single binary crate with no workspace and no backend-feature matrix:

- tests-cli, doc-tests, cargo-check, cargo-lock, clippy_check, cargo_fmt,
  cargo-deny, tests-wasi -- all adapted to drop the get-features job and
  its $FEATURES matrix (c2patool's own Cargo.toml hardcodes its c2pa
  backend feature already; it never selected one dynamically) and any
  --workspace flag (none survive in a single-crate repo).
- New docs-private job: cargo doc --document-private-items --no-deps,
  warnings denied. c2patool doesn't publish to docs.rs (binary, no public
  API), so docs_rs/docs_stable don't apply, but internal documentation
  (including private items) still needs to build cleanly.

Dropped entirely: get-features, tests-openssl, tests-rust-native-crypto,
tests-windows-arm-*, docs_rs, docs_stable, tests-wasm, tests-cross -- all
either SDK-only backend-matrix concerns or docs.rs-publish concerns that
don't apply to a binary crate.

NOTE: main's Cargo.toml currently depends on an unpublished c2pa
version (0.91.0-dev), so this CI cannot actually pass until that's fixed
(see the companion 'auto-track c2pa-rs main' PR).

* fix: Four real bugs surfaced by actually running CI for the first time

Actions has been off since the cutover, so none of this had ever
actually executed until now:

- deny.toml: add contentauth/c2pa-rs to allow-git. main's own c2pa git
  dependency (#309) is intentional, but cargo-deny's sources check
  denies unrecognized git sources by default.
- src/main.rs: fix a stale test-fixture path (../../cli/tests/... ->
  ../tests/...) left over from the pre-flattening workspace layout.
  Broke both cargo test and clippy --all-targets (which compiles tests).
- Cargo.toml: split the c2pa dependency by target. It hardcoded the
  openssl backend feature unconditionally, which can't compile for
  wasm32 (c2pa-rs's own openssl dependency is itself gated to
  not(target_arch = "wasm32")) -- the wasi target needs
  rust_native_crypto instead. Needed 'resolver = "3"' too: edition 2018
  defaults to resolver 1, which unifies a dependency's features across
  ALL targets in one pass instead of resolving per-target, so both
  backends were getting enabled simultaneously and colliding.
- ci.yml / beta-preflight.yml: drop the doc-tests job entirely --
  c2patool has no library target, so 'cargo test --doc' has nothing to
  test and errors outright ('no library targets found'). The
  docs-private job (cargo doc --document-private-items) is the
  meaningful internal-docs check for a binary crate; doc-tests never
  applied here.

All four verified locally: cargo test --bins (14 passed), clippy
--all-targets, cargo deny check (all ok), and cargo +nightly-2026-01-16
test --target wasm32-wasip2 --no-run (compiles clean).

* fix: Use a WASI-safe unique id in atomic_write_file

std::process::id() panics under WASI (no process-ID concept in that
sandbox) rather than erroring, which crashed the whole test binary
(SIGABRT) the moment atomic_write_file_writes_and_replaces ran under
tests-wasi. Switched to a nanosecond timestamp instead -- verified
locally against the actual wasm32-wasip2 target with wasmtime, all 13
unit tests + 0 integration tests pass.

* ci: Use CODECOV_ORG_TOKEN, matching the org-level secret naming convention

* fix: Include integration tests in code coverage

cargo llvm-cov --bins alone only measures the crate's own embedded unit
tests -- it excludes tests/integration.rs (38 tests) entirely, since
that's a separate [[test]] target, not a bin target. That was masking
most of the actual coverage: --bins alone reports 32%, matching what
was seen in the new repo; adding --tests brings it to 68-71% locally,
in line with the historical c2pa-rs figure for this code.

This flag scope already existed as-is in c2pa-rs's own tier-1a.yml
tests-cli job (not something the migration or this PR's restore
introduced) -- it just never surfaced as a problem there, likely
because Codecov's per-file report aggregates uploads from multiple
c2pa-rs CI jobs, only one of which is this narrowly-scoped one.

* ci: Test on Mac/Linux/Windows, not just Linux

c2patool ships a Mac/Linux/Windows binary as its core product and has
real per-OS code (the cfg(windows) windows-sys dependency), unlike the
SDK crate this repo split from -- there, cross-platform testing is a
separate, more expensive Tier 1B/2 concern deliberately kept out of the
fast per-PR gate (Tier 1A/ci.yml stays ubuntu-only there). That
trade-off doesn't apply here: there's no other tier picking up
cross-platform coverage for c2patool, so it needs to be in the direct
gate. Coverage collection/Codecov upload stays ubuntu-only to avoid
three redundant uploads for the same run.

Verified locally on macOS: cargo test --bins --tests, 38 passed.

* feat: Test MSRV (1.88.0) on every supported platform

Adds rust-version = "1.88.0" to Cargo.toml -- an explicit, cargo-
enforced claim, not just documentation -- and extends the Unit tests
matrix with rust_version: [stable, 1.88.0] alongside the existing OS
matrix (6 combinations total), matching how c2pa-rs's own tier-1b.yml
combines os + rust_version for its MSRV coverage. Coverage/Codecov
upload stays scoped to just the ubuntu+stable leg.

Found and fixed a real MSRV violation surfacing this: c2patool's own
resolved Cargo.lock pulled in aes 0.9.3 (transitively via lopdf, via
c2pa's "pdf" feature), which requires rustc 1.89 -- one version past
what's claimed. Pinned to 0.9.1 (0.9.0 is yanked; 0.8.x doesn't satisfy
lopdf's own aes requirement). Verified locally: cargo +1.88.0 check and
cargo +1.88.0 test --bins --tests both pass clean (38 tests), as does
the regular stable build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant