Repository navigation
chore(publish): verify with cargo package, not cargo publish --dry-run (#146) - #548
Merged
Merged
Conversation
#146) `scripts/publish.rs::verify` already used `cargo package` per-crate, but that still hits the crates.io chicken-and-egg for dependent crates on a first publish of a new version: cargo verifies each packaged crate outside the workspace, downloads its deps from the index, and fails when the new version isn't published yet. Empirically confirmed at an unpublished 0.99.0 — this is why PR #192 removed the CI verify step. Fix: package the whole publishable set in ONE `cargo package -p a -p b …` invocation. Cargo writes every member to target/package/*.crate first, then verify-builds each against those local tarballs at the new version, never touching the index. Confirmed at 0.99.0: dependents (synth-synthesis etc.) compile against the just-packaged deps with nothing on crates.io. Full verify build retained (no --no-verify), so non-compiling code is still caught. Also: - Add synth-backend-aarch64 to CRATES_TO_PUBLISH. It is a hard, always-on dep of synth-cli (#538) but was never published — publish would (and the restored verify does) fail on synth-cli's unresolved dep. The restored fail-fast check is exactly what surfaced this latent gap. - Restore the `./publish verify` pre-flight step in publish-to-crates-io.yml and rewrite the now-false comment (it asserted cargo package cannot avoid the chicken-and-egg; it can, when the whole set is packaged together). - Update docs/release-process.md: describe the token-free verify pre-flight and add synth-backend-aarch64 to the published-crate table. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #146.
Problem
./publish verifyis meant to be a fail-fast, index-free "does each publishable crate build a valid package" pre-flight before crates.io publish. The original step usedcargo publish --dry-run, which resolves every path-dep version requirement against the crates.io index — so on the FIRST publish of any new version, dependents fail with the chicken-and-egg "failed to select a version for synth-core = ^x.y" (deps aren't on the registry yet). That sank the v0.7.0 verify step (dropped in #144).scripts/publish.rs::verifyhad already been switched to a per-cratecargo package -p <name>loop (PR #190), but that has the same problem: cargo verify-builds each packaged crate outside the workspace, downloads its deps from the index, and fails when the new version isn't published. PR #192 then removed the CI verify step, concluding cargo package couldn't avoid the chicken-and-egg.Empirical finding
I bumped the whole workspace to an unpublished
0.99.0and tested:cargo package -p synth-synthesis(per-crate) → fails:failed to select a version for the requirement synth-cfg = "^0.99.0" … location searched: crates.io index.cargo package -p synth-cfg -p synth-core -p synth-opt -p synth-synthesis(one invocation) → succeeds:Verifying synth-synthesis v0.99.0→Compiling synth-opt v0.99.0/Compiling synth-core v0.99.0(its deps) →Finished, with noDownloaded synth-*from crates.io.Packaging the whole set together makes cargo write every member to
target/package/*.cratefirst, then verify-build each against those local tarballs at the new version — the index is never consulted for inter-member deps. Full verify build is retained (no--no-verify), so non-compiling code is still caught. This satisfies the issue's falsification ("must pass on a clean workspace with no prior version on crates.io").Changes
scripts/publish.rs—verify()now packages the entire publishable set in onecargo package -p a -p b …invocation instead of once per crate.scripts/publish.rs— addsynth-backend-aarch64toCRATES_TO_PUBLISH. It is a hard, always-on dep of synth-cli (Feature challenge: add an aarch64 (host-native) backend so output runs and debugs natively on arm64 dev machines #538) that was never published;./publish publishwould fail on synth-cli's unresolved dep, and the restored verify is what surfaced this latent gap..github/workflows/publish-to-crates-io.yml— restore the./publish verifypre-flight step and rewrite the now-incorrect comment.docs/release-process.md— describe the token-free verify pre-flight; add synth-backend-aarch64 to the published-crate table.Trade-off to note for reviewers
The restored verify step full-builds the publishable set on the publish runner (ubuntu-latest), which includes synth-verify's
static-link-z3C++ build. That runner already builds z3 duringcargo publish -p synth-verify, so this is added time (z3 built twice) rather than a new failure mode; the smithy-runner disk exhaustion (#306) does not apply to ubuntu-latest. If the extra build time is unwanted, the alternative is--no-verify(packaging/metadata check only, relying on the CI Test job for compile coverage) — flagged here rather than chosen silently.Validation
rustc --edition 2024 scripts/publish.rscompiles clean;rustfmt --checkpasses.cargo fmt/clippyare unaffected.🤖 Generated with Claude Code