Skip to main content

Module release_github_source

Module release_github_source 

Source
Expand description

Resolve the dev toolchain from GitHub releases instead of crates.io.

release snapshot pins every package to the newest dev version on crates.io. On 2026-09-08 crates.io locked the account that publishes every Greentic crate, and from then on every dev build still attached its archives to a GitHub release while none of them reached the index — so the dev channel froze on the versions it pinned the day before, with fixes merged and built and unreachable through gtc install.

--source github-releases reads the same builds from where they actually landed. For each toolchain package it picks the newest release in the dev lane whose archives are complete, and records each archive’s URL and sha256 as the package’s artifacts, which gtc installs directly instead of going through cargo binstall.

Two things crates.io used to do for us have to be done here instead:

  • Yanking. A GitHub release cannot be yanked. The 2026-09-06 worm rewrote branch tips with look-alike commits (LOCAL committer, a .vscode/tasks.json dropper, JavaScript posing as public/fonts/fa-solid-* files), and CI built releases from some of them. So the commit a release was tagged at must carry GitHub’s own verified committer and none of those files. A release that fails that check is REFUSED, never skipped: quietly falling back to an older build would publish a channel nobody chose.
  • Lane filtering. Only plain MAJOR.MINOR.RUN versions in the release’s own lane count. greentic-pack also tags v1.2.0-research.N in the same minor, and those are not dev builds.

Structs§

CommitProvenance
Where the commit a release is tagged at came from.
GithubDevReleaseSource
Production source: the GitHub REST API, with the ambient token when one is available (these repositories are public; the token lifts the rate limit).
RepoRelease
One GitHub release, reduced to what resolution needs.
RepoReleaseAsset
ResolvedDevPackage
A package resolved from its GitHub release.

Traits§

DevReleaseSource
Reads releases and commit provenance. Injected so resolution is testable without the network.

Functions§

resolve_dev_package
Pick the release to pin for one package and name its archives.
snapshot_manifest_from_github_releases
Build a dev-channel manifest for gtc release from GitHub releases.