You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If this PR changes Cargo.lock, the dependency-feed-check check passes (see docs/pull-requests.md)
📋 Issue Type
Bug fix
Feature
Task
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See docs/pull-requests.md.
If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See docs/pull-requests.md
for the steps.
Prepare mxc-sdk and its required internal crates for crates.io publication, validate publishing metadata in CI, derive dependency order from Cargo metadata, and add guarded private packaging and ESRP release infrastructure.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555
These artifacts are submitted to crates.io, but this argument asks Cargo to package for Mxc-Azure-Feed; Cargo uses the selected registry when generating package lockfiles for interdependent crates. That validates and prepares the archives under the private-feed assumption rather than the destination registry. The source replacement configured earlier already keeps dependency downloads on the private feed, so leave the package target at Cargo's default crates.io registry.
Validate publication against crates.io, not the private registry
This job is labeled as a crates.io publication check, but --registry Mxc-Azure-Feed makes Cargo validate a dry run for the internal registry instead. Registry-specific dependency and package checks can therefore pass here and still fail during the ESRP crates.io release. Keep the private source replacement for downloads, but omit this target-registry override so the dry run models crates.io.
This only checks that the ref starts with v; it never verifies that the tag version matches the packaged crate version. A run queued on a stale or mistyped tag such as v1.0.0 can therefore publish mxc-sdk-0.9.0.crate, leaving the crates.io release untraceable to its version tag. Compare the tag suffix with the SDK archive filename before starting any ESRP task.
This sequence has no recovery path after a partial release. If crate N fails after earlier immutable versions were accepted by crates.io, rerunning the tag starts at crate 1; the duplicate-version failure stops the job before it reaches crate N. Add an order-validated resume mechanism or make exact-version duplicates idempotent so a transient ESRP failure does not permanently strand the release.
Reject publish allowlists that omit crates.io
scripts/ci/Invoke-CratePackage.ps1:75
This only rejects publish = false; a crate restricted to another registry (for example, publish = ["internal"]) passes CI even though this pipeline publishes to crates.io. Treat any non-null allowlist that omits crates-io as non-publishable.
The production gate accepts any nonempty v* tag without checking it against the packaged crate version. A run queued from refs/tags/v1.0.0 can therefore publish the 0.9.0 archives, leaving misleading release provenance and consuming an immutable crates.io version under the wrong source tag. Derive the expected version from the packaged mxc-sdk-<version>.crate (or emitted package metadata) and require an exact refs/tags/v<version> match before the first ESRP task.
Require crates.io in the Cargo publish registry list
scripts/ci/Invoke-CratePackage.ps1:76
This only rejects publish = false; Cargo metadata also represents publish = ["some-private-registry"] as a nonempty list, so such a crate passes CI even though this pipeline cannot publish it to crates.io. When publish is non-null, require that the list contains crates-io.
Resolve the crate-consolidation conflicts and update the crates.io release flow to package, validate, and publish only mxc-sdk.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 433e5b70-c2bd-496d-9b8d-bd2085bb2706
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📖 Description
mxc-sdk, to crates.io through ESRP.refs/tags/v*tag before a production release.🔗 References
🔍 Validation
pwsh -NoProfile -File scripts/ci/Invoke-CratePackage.ps1 -ValidateOnly— passed.node scripts/versioning/check-rust-toolchain-sync.js— passed.pwsh -NoProfile -File scripts/ci/Invoke-CratePackage.ps1 -OutDir <temp>— passed and producedmxc-sdk-0.9.0.crate.cargo publish --dry-run --locked --manifest-path src/Cargo.toml -p mxc-sdk— passed, including compilation from the packaged crate.git diff origin/main...HEAD --check— passed.✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (see docs/pull-requests.md)📋 Issue Type
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(
MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHubActions build; it runs on merge to
main, and Microsoft reviewers with write access can trigger iton a PR with
/azp run. See docs/pull-requests.md.If the
dependency-feed-checkcheck fails on a new dependency, the crate must be added tothe feed before the PR can pass. See docs/pull-requests.md
for the steps.