Repository navigation
Add CI and release automation for the Rust crate - #42
Merged
Merged
Conversation
The Rust crate had no CI, no release workflow, no tags, and no documented release process; every crates.io release was published by hand. That made it hard to tell which source a published version came from, and left 0.2.2 stranded when the prebuilt ONNX Runtime binaries for its pinned ort release candidate stopped being hosted. - Add a Rust CI workflow: build and test on Linux/macOS/Windows, rustfmt, clippy, an MSRV check, and a packaging check. - Add a release workflow triggered by rust-v* tags that verifies the tag matches Cargo.toml, tests, and publishes via crates.io Trusted Publishing. - Document the release process, including the manual fallback and the ort release-candidate risk, in rust/RELEASING.md. - Add rust/CHANGELOG.md. - Fix a clippy lint so CI can gate on warnings. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
tmathern
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What happened
The Rust crate has no CI, no release workflow, no tags, and no documented release process. Every crates.io release (0.1.0 through 0.2.2) was published by hand, with nothing recorded in git.
That's why
trustmark0.2.2 is currently unbuildable. It pinsort =2.0.0-rc.8, andort-sysdownloads prebuilt ONNX Runtime binaries from a pyke-hosted CDN at build time. Those binaries are gone for older release candidates. Nothing was yanked on crates.io, so there was no signal — the crate just stopped building.mainalready contains the fix (0.3.0,ortrc.12) but it was never released.What's here
Automation
.github/workflows/rust-ci.yml— build and test on Linux/macOS/Windows,rustfmt,clippywith-D warnings, an MSRV check that readsrust-versionfromCargo.toml, and acargo publish --dry-runpackaging check. Path-filtered torust/, and the ~230 MB of ONNX models are cached..github/workflows/rust-release.yml— triggered by arust-v*tag. Verifies the tag matchesrust/Cargo.toml, confirms the version isn't already on crates.io, tests, packages, publishes via crates.io Trusted Publishing (no stored token), and opens a GitHub release. Supports a manual dry run.Documentation
rust/RELEASING.md— the automated process, the manual fallback with exact commands, the one-time Trusted Publishing setup, and an explicit writeup of theortrelease-candidate risk so the next person recognizes this failure mode immediately.rust/CHANGELOG.md— entries for 0.1.0 through 0.3.0, reconstructed from commit history.rust/README.md— pointers to both.One code change
src/bits/bch.rs:repeat().take()→repeat_n(). A newerclippyflags this, and CI gates on warnings.Validation
Run locally against the full set of gates the CI workflow uses:
cargo fmt --all -- --check— cleanRUSTFLAGS="-D warnings" cargo clippy --workspace --all-targets --all-features— cleancargo test --workspace --locked— 24 tests + 1 doctest passcargo publish --dry-run --locked— packages successfullyBoth workflow files parse as valid YAML, and the shell logic in the release workflow (version extraction, MSRV extraction, published-version check) was executed locally and produces the expected results.
Follow-up needed
main.rust/RELEASING.mdhas the exact command sequence.adobe/trustmark, workflowrust-release.yml, environmentcrates-io. ACARGO_REGISTRY_TOKENsecret is a documented alternative.rust-v0.3.0at the release commit so the history isn't lost for this version either.