diff --git a/infra/build-server/lib.sh b/infra/build-server/lib.sh index a5b14cf7..5083439d 100755 --- a/infra/build-server/lib.sh +++ b/infra/build-server/lib.sh @@ -43,15 +43,19 @@ bs_rsync() { rsync -e "$BS_SSH_CMD" "$@"; } # the two sides' rustc must agree (the box is pinned by provision.sh RUST_TOOLCHAIN; the Mac runs rustup's stable): # a different compiler gives different bytes and, across a minor version, different lints and errors +# the pin (main, 7 October 2026): rust-toolchain.toml at the worktree root (and the fork's own copy) names the channel; the Mac's +# rustc AS RESOLVED IN THE CRATE DIR (rustup reads the file), the box's rustc and the pin must agree, else the build is refused +bs_pin() { sed -n 's/^channel *= *"\([^"]*\)".*/\1/p' "${1:-$BS_WT_ROOT}/rust-toolchain.toml" 2>/dev/null | head -1; } bs_toolchain_check() { - local mac box - mac=$("${CARGO_HOME:-$HOME/.cargo}/bin/rustc" --version 2>/dev/null | awk '{ print $2 }') + local mac box pin + pin=$(bs_pin "$BS_WT_ROOT"); [ -n "$pin" ] || pin=$(bs_pin "$BS_TOP") + mac=$(cd "${BS_CRATE:-.}" && "${CARGO_HOME:-$HOME/.cargo}/bin/rustc" --version 2>/dev/null | awk '{ print $2 }') box=$(bs_ssh '. /etc/profile.d/igneum-build.sh; rustc --version' 2>/dev/null | awk '{ print $2 }') [ -n "$box" ] || bs_die "cannot read rustc on $BS_HOST (is it provisioned? infra/build-server/run-from-mac.sh)" - if [ "$mac" != "$box" ]; then - if [ "${IGNEUM_TOOLCHAIN_MISMATCH:-}" = ok ]; then bs_log "WARNING: rustc $mac on the Mac, $box on the box (IGNEUM_TOOLCHAIN_MISMATCH=ok)" - else bs_die "rustc $mac on the Mac, $box on the box; re-provision with RUST_TOOLCHAIN=$mac or set IGNEUM_TOOLCHAIN_MISMATCH=ok"; fi - else bs_log "rustc $box on both sides"; fi + if [ -n "$pin" ] && { [ "$mac" != "$pin" ] || [ "$box" != "$pin" ]; } || [ "$mac" != "$box" ]; then + if [ "${IGNEUM_TOOLCHAIN_MISMATCH:-}" = ok ]; then bs_log "WARNING: pin ${pin:-none}, rustc $mac on the Mac, $box on the box (IGNEUM_TOOLCHAIN_MISMATCH=ok)" + else bs_die "toolchain mismatch: rust-toolchain.toml pins ${pin:-nothing}, the Mac resolves rustc $mac in $BS_CRATE, the box runs $box; align the pin (one commit), 'rustup toolchain install $pin' on the Mac, 'RUST_TOOLCHAIN=$pin infra/build-server/run-from-mac.sh ' for the box, or set IGNEUM_TOOLCHAIN_MISMATCH=ok"; fi + else bs_log "rustc $box on both sides${pin:+ (pinned $pin by rust-toolchain.toml)}"; fi } # Where am I? Sets BS_KIND (node = a worktree of the fork under vendor/; repo = a crate of the igneum repo), BS_TOP (the git diff --git a/infra/build-server/provision.sh b/infra/build-server/provision.sh index bfa06b91..eb010bd0 100755 --- a/infra/build-server/provision.sh +++ b/infra/build-server/provision.sh @@ -18,9 +18,9 @@ # directory per agent worktree, sshd key-only, ufw with 22 and the seed p2p ports. # # Settings (environment, all optional): -# RUST_TOOLCHAIN 1.99.0 the Mac's `rustc --version` on 6 October 2026. Neither the repo nor the fork carries a -# rust-toolchain file (checked 6 October 2026), so the pin lives here; the fork's Cargo.toml says -# rust-version 1.91.0. tools/build-remote.sh compares the two sides and refuses a mismatch. +# RUST_TOOLCHAIN 1.99.0 the channel of rust-toolchain.toml at the repo root (run-from-mac.sh passes it; one file pins +# the Mac, the box, the PCs and CI since 7 October 2026). tools/build-remote.sh refuses a build +# when the pin, the Mac's rustc or the box's rustc differ. # SCCACHE_GB 100 the local disk cache at /srv/sccache # SCCACHE_VERSION (unset) a `cargo install sccache --version` pin; unset = the newest on crates.io # NODE_MAJOR 22 diff --git a/infra/build-server/run-from-mac.sh b/infra/build-server/run-from-mac.sh index f36fe94f..eeb94ea0 100755 --- a/infra/build-server/run-from-mac.sh +++ b/infra/build-server/run-from-mac.sh @@ -23,6 +23,8 @@ BS_TOOL=run-from-mac IP="${1:-}"; shift || true [ -n "$IP" ] || bs_die "usage: run-from-mac.sh [--wire-only]" WIRE_ONLY=0; [ "${1:-}" = --wire-only ] && WIRE_ONLY=1 +# the toolchain pin travels from rust-toolchain.toml unless RUST_TOOLCHAIN is set by hand (one file pins every side, 7 Oct 2026) +[ -n "${RUST_TOOLCHAIN:-}" ] || RUST_TOOLCHAIN=$(sed -n 's/^channel *= *"\([^"]*\)".*/\1/p' "$REPO/rust-toolchain.toml" 2>/dev/null | head -1); export RUST_TOOLCHAIN PASS="" # a string, not an array: bash 3.2 (the Mac) treats an empty array as unbound under set -u for v in MODE RUST_TOOLCHAIN SCCACHE_GB SCCACHE_VERSION NODE_MAJOR SLOTS P2P_PORTS BOX_HOSTNAME SSH_PUBKEY; do [ -n "${!v:-}" ] && PASS="$PASS $v=$(printf '%q' "${!v}")" diff --git a/rust-toolchain.toml b/rust-toolchain.toml new file mode 100644 index 00000000..08b4a599 --- /dev/null +++ b/rust-toolchain.toml @@ -0,0 +1,7 @@ +# One pin for every side (main, 7 October 2026): the Mac, igneum-build-1 (provision.sh RUST_TOOLCHAIN reads this), the PCs and CI. +# rustup resolves the nearest rust-toolchain.toml walking up from the crate, so the fork worktrees under vendor/ are covered by +# this file and carry their own copy for the fork's standalone checkout. lib.sh bs_toolchain_check refuses a build when the pin, +# the Mac's rustc or the box's rustc differ. Bump here and in vendor/igneum-node/rust-toolchain.toml in one commit each. +[toolchain] +channel = "1.99.0" +targets = ["x86_64-pc-windows-gnu", "x86_64-unknown-linux-gnu"]