Skip to content

fix(release): drop chicken-and-egg verify step from publish-to-crates-io.yml - #144

Merged
avrabe merged 1 commit into
mainfrom
release/v0.7.0-drop-publish-verify
May 25, 2026
Merged

avrabe merged 1 commit into
mainfrom
release/v0.7.0-drop-publish-verify

Conversation

@avrabe

@avrabe avrabe commented May 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Removes the ./publish verify step from .github/workflows/publish-to-crates-io.yml
  • Unblocks crates.io publishing on v0.7.0 (and every future version's first publish)
  • No replacement step needed: ./publish publish's 10-attempt retry loop + cargo publish's own metadata validation cover the same ground correctly

Root cause

cargo publish --dry-run -p <name> resolves dependencies through the public crates.io index, not the local workspace. For a first publish of v0.7.0 of an internally-coupled workspace, the dependents (synth-opt, synth-frontend, synth-synthesis, …) fail dry-run because synth-cfg / synth-core / etc. aren't on the registry at 0.7.0 yet. This is inherent to cargo's dry-run semantics, not a script bug per se — but it makes a pre-flight verify step structurally impossible for new-version publishes.

Evidence

The first run of publish-to-crates-io.yml on the (re-tagged) v0.7.0 commit 70f5fd2 failed in the verify step with:

error: failed to select a version for the requirement `synth-cfg = "^0.7.0"`
FAIL: synth-opt dry-run failed: exit status: 101

(run 26384884309)

What the publish step does that verify doesn't

  • cargo publish (without --dry-run) runs the same metadata + packaging checks before upload, so we don't lose validation.
  • ./publish publish has a curated dependency order + per-attempt retry, sleeping 40s between attempts to ride out crates.io index propagation as each leaf publishes.

Recovery

After merge: re-run publish-to-crates-io.yml via gh workflow run publish-to-crates-io.yml -f tag=v0.7.0 to actually publish the workspace.

Follow-up

If a fail-fast metadata pre-flight is wanted later, ./publish verify could be changed to use cargo package -p <name> (path deps, no registry hit). Tracked as a separate issue.

Test plan

  • CI green on this PR
  • After merge: workflow_dispatch publish-to-crates-io.yml on v0.7.0 tag, watch all 11 crates publish in order

The 'Verify all crates can publish' step runs `cargo publish --dry-run -p <name>`
for every workspace crate before any have been published. cargo's dry-run
resolves dependencies through the public crates.io index — so the moment
a dependent workspace crate is asked to dry-run, it requires every synth-*
dep to already exist on crates.io at the new version. For v0.7.0 (or any
first publish of a new version), that's impossible: synth-opt needs
synth-cfg ^0.7.0, synth-frontend needs synth-core ^0.7.0, etc., and the
registry has none of them at the new version yet.

This blocked publish-to-crates-io.yml on v0.7.0 entirely — verify failed,
the actual publish step never ran. The `./publish publish` helper already
has a 10-attempt retry loop with 40s sleeps specifically to ride out
crates.io index propagation as each leaf publishes, so the verify step
is functionally redundant. `cargo publish` (without --dry-run) also
performs the full metadata validation before uploading, so we don't lose
the safety check by removing the pre-flight.

After this lands, re-run publish-to-crates-io.yml via workflow_dispatch
on the v0.7.0 tag to publish the workspace to crates.io.

Recoverable variant: change `./publish verify` to use `cargo package -p`
(which uses path deps and doesn't hit the registry) if a fail-fast
metadata check is wanted. Tracked as a follow-up but not blocking v0.7.0.
@avrabe
avrabe merged commit 7136173 into main May 25, 2026
7 checks passed
@avrabe
avrabe deleted the release/v0.7.0-drop-publish-verify branch May 25, 2026 05:46
@codecov

codecov Bot commented May 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

avrabe added a commit that referenced this pull request May 30, 2026
… (#190)

`./publish verify` ran `cargo publish --dry-run -p <name>`, which resolves every
workspace dep through the public crates.io index — so on a first publish of a
new version the dependents always fail with the chicken-and-egg "dep not yet
published" error. That sank the v0.7.0 verify step; PR #144 dropped it entirely,
losing the fail-fast metadata/compile check.

Switch verify() to `cargo package -p <name>`: it resolves through the local path
deps (no chicken-and-egg), builds each .crate end-to-end, and catches the real
pre-flight surface — missing README/license, bad include/exclude, broken
metadata, code that doesn't compile. Verified `cargo package` resolves for all
11 CRATES_TO_PUBLISH on a clean workspace with no prior version on crates.io.

Restore the `./publish verify` step in publish-to-crates-io.yml ahead of the
publish step. (publish=false crates like synth-abi aren't in CRATES_TO_PUBLISH,
so the synth-wit-version quirk noted in #146 is not hit by the verify pass.)

Tooling only — scripts/publish.rs is not a published crate, so this merges to
main without a crates.io version bump.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
avrabe added a commit that referenced this pull request May 30, 2026
…192)

The verify step added in #146 (v0.11.6) runs `cargo package` per crate, which
resolves path-dep VERSION REQUIREMENTS (`synth-core = "^0.11.x"`) against the
crates.io index during upload prep — so on the FIRST publish of a new version,
every dependent crate fails with "failed to select a version for synth-core =
^0.11.x" (the deps aren't published yet). This is the SAME chicken-and-egg that
sank v0.7.0's `--dry-run` verify (#144); `cargo package` does NOT avoid it
(confirmed: it only passes when the version is already on crates.io). It blocked
the v0.11.7 crates.io publish.

Remove the step. Compile errors are caught by CI test/build (path deps, no
chicken-and-egg); `./publish publish` validates metadata as cargo's own
pre-upload check. Reopening #146 — the fail-fast it asked for is not achievable
with cargo package.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant