Skip to content

build: pin the Rust toolchain to 1.94.1 - #28

Merged
anvanster merged 3 commits into
mainfrom
build/pin-rust-toolchain
Oct 6, 2026
Merged

anvanster merged 3 commits into
mainfrom
build/pin-rust-toolchain

Conversation

@anvanster

Copy link
Copy Markdown
Member

Intent

The developer is preparing to build and publish the CodeGraph 0.21.0 release across all platforms (darwin-arm64, darwin-x64, linux-x64 on SLES, linux-arm64 via Docker, win32-x64). They agreed to pin the Rust toolchain to 1.94.1 with a rust-toolchain.toml, so every build host and the arm64 container use the same compiler. Hosts had disagreed: SLES defaulted to 1.94.1, the Mac and Windows to 1.93.1, and the container to whatever was current stable. This change is that one-line toolchain pin, committed and run through the no-mistakes gate before the release build. Standing constraints: push only through the no-mistakes gate, never use em dashes, don't manually edit CHANGELOG.md or Cargo.lock, and merge no external PRs.

What Changed

  • Added rust-toolchain.toml, which pins rustc to 1.94.1 with the minimal profile, rustfmt and clippy, and the x86_64-apple-darwin target for the darwin-x64 cross-build. Every build host now uses the same compiler.
  • scripts/build-linux-arm64.sh now bootstraps rustup with --default-toolchain none, so the container installs the pinned toolchain from rust-toolchain.toml and no longer pulls current stable. Before building, the script runs rustc --version and exits with an error if the toolchain install failed.
  • The build-from-source notes in README.md and vscode/README.md now list rustup as the requirement and say it installs the pinned Rust version. They no longer say "Rust stable".

🤖 Generated with Claude Code

Risk Assessment

✅ Low: The change only adds a toolchain pin and makes a small bootstrap tweak to the arm64 build script. Both prior findings are fixed correctly: the darwin-x64 target is listed, the container installs no default toolchain, and rustc --version runs inside /src, where the pin triggers the 1.94.1 install and fails loudly if that install fails.

Testing

I drove the pin on two fresh, isolated rustup installs with no toolchains, mirroring how release hosts and the linux-arm64 container meet it. On the arm64 Mac the pin auto-installed only 1.94.1, with the x86_64-apple-darwin target. With that toolchain, the full darwin-x64 codegraph-server release cross-build succeeded and produced an x86_64 Mach-O binary that prints codegraph-server 0.21.0 under Rosetta. In an Ubuntu 20.04 arm64 container I replayed the script's --default-toolchain none bootstrap. No stable toolchain was installed. The new rustc --version line installed and printed 1.94.1 inside /src. Outside the pinned tree, rustc failed, which is the error the guard is there to catch. Every scenario passed.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
On a fresh host, running rustc/cargo in the repo resolves to the pinned 1.94.1 with clippy and rustfmt ✅ pass live darwin-fresh-rustup-x64-cross.log and linux-arm64-container-bootstrap.log: 'rustc 1.94.1 (e408947bf 2026-03-25)', active toolchain overridden by rust-toolchain.toml
darwin-x64 codegraph-server release binary cross-builds on the arm64 Mac with the pinned toolchain alone, without a manual rustup target add, and runs ✅ pass live darwin-x64-server-cross-build.log: Finished release, build exit=0, 'Mach-O 64-bit executable x86_64', 'codegraph-server 0.21.0'
linux-arm64 container bootstrap installs no stable toolchain, and the new rustc --version line in /src installs and prints 1.94.1 ✅ pass live linux-arm64-container-bootstrap.log: 'no installed toolchains' after bootstrap, then 'rustc 1.94.1' in /src
Adversarial: without the pin, the container's rustc --version fails and the build stops instead of using some other compiler ✅ pass live linux-arm64-container-bootstrap.log: in /tmp, rustup reports 'could not choose a version of rustc', so the guard's failure branch runs
Evidence: linux-arm64 container bootstrap transcript (installs none, pin picks 1.94.1, guard fires without pin)
debconf: delaying package configuration, since apt-utils is not installed
--- bootstrap exactly as scripts/build-linux-arm64.sh does ---
info: downloading installer
info: profile set to minimal
info: default host tuple is aarch64-unknown-linux-gnu
info: skipping toolchain installation
--- toolchains installed before entering /src ---
no installed toolchains
warn: no toolchain installed and no default toolchain set
help: run 'rustup default stable' to download the latest stable release of Rust and set it as your default toolchain.
--- adversarial: outside the repo, no pin -> guard must fire ---
error: rustup could not choose a version of rustc to run, because one wasn't specified explicitly, and no default is configured.
help: run 'rustup default stable' to download the latest stable release of Rust and set it as your default toolchain.
RUST TOOLCHAIN INSTALL FAILED (expected outside the repo)
--- inside /src (script line: rustc --version) ---
info: syncing channel updates for 1.94.1-aarch64-unknown-linux-gnu
info: latest update on 2026-03-26 for version 1.94.1 (e408947bf 2026-03-25)
info: downloading 6 components
warn: the missing active toolchain `1.94.1-aarch64-unknown-linux-gnu` has been auto-installed
warn: this might cause rustup commands to take longer time to finish than expected
info: you may opt out with `RUSTUP_AUTO_INSTALL=0` or `rustup set auto-install disable`
rustc 1.94.1 (e408947bf 2026-03-25)
cargo 1.94.1 (29ea6fb6a 2026-03-24)
--- toolchains after ---
1.94.1-aarch64-unknown-linux-gnu (active)
1.94.1-aarch64-unknown-linux-gnu (overridden by '/src/rust-toolchain.toml')
cargo-aarch64-unknown-linux-gnu
clippy-aarch64-unknown-linux-gnu
rust-std-aarch64-unknown-linux-gnu
rust-std-x86_64-apple-darwin
rustc-aarch64-unknown-linux-gnu
rustfmt-aarch64-unknown-linux-gnu
--- cargo check of a workspace crate with the pinned compiler ---
  thread 'main' (4666) panicked at /root/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/bindgen-0.72.1/lib.rs:616:27:
  Unable to find libclang: "couldn't find any valid shared libraries matching: ['libclang.so', 'libclang-*.so', 'libclang.so.*', 'libclang-*.so.*'], set the `LIBCLANG_PATH` environment variable to a path where one of these files can be found (invalid: [])"
  note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
exit=101
Evidence: Fresh rustup on arm64 Mac: pin auto-installs 1.94.1 + x86_64-apple-darwin
--- fresh, isolated rustup on the arm64 Mac (no toolchains, no default) ---
no installed toolchains
warn: no toolchain installed and no default toolchain set
help: run 'rustup default stable' to download the latest stable release of Rust and set it as your default toolchain.
--- in repo: rustc --version ---
info: syncing channel updates for 1.94.1-aarch64-apple-darwin
info: latest update on 2026-03-26 for version 1.94.1 (e408947bf 2026-03-25)
info: downloading 6 components
warn: the missing active toolchain `1.94.1-aarch64-apple-darwin` has been auto-installed
warn: this might cause rustup commands to take longer time to finish than expected
info: you may opt out with `RUSTUP_AUTO_INSTALL=0` or `rustup set auto-install disable`
rustc 1.94.1 (e408947bf 2026-03-25)
cargo 1.94.1 (29ea6fb6a 2026-03-24)
1.94.1-aarch64-apple-darwin (overridden by '~/.no-mistakes/worktrees/b8216ba13cd2/01M47FDH2N955PN02S5F19PYDT/rust-toolchain.toml')
--- installed targets for the pinned toolchain ---
aarch64-apple-darwin
x86_64-apple-darwin
--- darwin-x64 cross build (cargo build --release --target x86_64-apple-darwin) ---
   Compiling rocksdb v0.22.0
   Compiling codegraph-parser-api v0.2.1 (~/.no-mistakes/worktrees/b8216ba13cd2/01M47FDH2N955PN02S5F19PYDT/crates/codegraph-parser-api)
    Finished `release` profile [optimized] target(s) in 1m 42s
exit=
/tmp/nm-rust.IB0N/target/x86_64-apple-darwin/release/libcodegraph_parser_api.rlib: current ar archive
/tmp/nm-rust.IB0N/target/x86_64-apple-darwin/release/libcodegraph_parser_api.rlib
Evidence: darwin-x64 codegraph-server release cross build with rustc 1.94.1; x86_64 binary prints 0.21.0
--- rustc used: rustc 1.94.1 (e408947bf 2026-03-25) ---
--- cargo build --release --target x86_64-apple-darwin -p codegraph-server ---
    |    ^^^^^^^^^^^^^^^^^^^^^^^^^

warning: `codegraph-server` (lib) generated 13 warnings (run `cargo fix --lib -p codegraph-server` to apply 1 suggestion)
    Finished `release` profile [optimized] target(s) in 6m 50s
build exit=0
/tmp/nm-rust.IB0N/target/x86_64-apple-darwin/release/codegraph-server: Mach-O 64-bit executable x86_64
--- run x86_64 binary (Rosetta) ---
codegraph-server 0.21.0

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

🔧 **Review** - 2 issues found → auto-fixed ✅
  • ⚠️ rust-toolchain.toml:7 - The darwin-x64 engine is cross-compiled on the ARM Mac with cargo build --release --target x86_64-apple-darwin (per the release build notes). The pin makes rustup auto-install a fresh 1.94.1 toolchain with profile = "minimal", and that install only includes the host std. rustup does not auto-add extra targets. The x86_64-apple-darwin target the Mac added for 1.93.1 does not carry over to 1.94.1, so the darwin-x64 release build will fail with "can't find crate for core" / "target may not be installed" until someone runs rustup target add again. Fix: add targets = ["x86_64-apple-darwin"] to the [toolchain] table. rustup installs listed targets' std on every host, which is harmless, and this keeps the pin self-sufficient for every release artifact.
  • ℹ️ scripts/build-linux-arm64.sh:142 - The linux-arm64 container still bootstraps rustup with --default-toolchain stable. Once cargo runs in /src, the new rust-toolchain.toml overrides that and rustup downloads 1.94.1 as well, so every container build downloads two toolchains and the stable one is never used. Using --default-toolchain none here, so the pin alone decides the compiler, would remove the extra download and the misleading 'stable' in the build log. This is not a correctness problem: the pin still wins.

🔧 Fix applied.
✅ Re-checked - no issues remain.

✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
On a fresh host, running rustc/cargo in the repo resolves to the pinned 1.94.1 with clippy and rustfmt ✅ pass live darwin-fresh-rustup-x64-cross.log and linux-arm64-container-bootstrap.log: 'rustc 1.94.1 (e408947bf 2026-03-25)', active toolchain overridden by rust-toolchain.toml
darwin-x64 codegraph-server release binary cross-builds on the arm64 Mac with the pinned toolchain alone, without a manual rustup target add, and runs ✅ pass live darwin-x64-server-cross-build.log: Finished release, build exit=0, 'Mach-O 64-bit executable x86_64', 'codegraph-server 0.21.0'
linux-arm64 container bootstrap installs no stable toolchain, and the new rustc --version line in /src installs and prints 1.94.1 ✅ pass live linux-arm64-container-bootstrap.log: 'no installed toolchains' after bootstrap, then 'rustc 1.94.1' in /src
Adversarial: without the pin, the container's rustc --version fails and the build stops instead of using some other compiler ✅ pass live linux-arm64-container-bootstrap.log: in /tmp, rustup reports 'could not choose a version of rustc', so the guard's failure branch runs
  • docker run --platform linux/arm64 ubuntu:20.04: ran the script's rustup bootstrap (--default-toolchain none --profile minimal), checked rustup toolchain list (empty), ran rustc --version in /tmp (no pin) and in /src (pinned), then checked rustup show active-toolchain and rustup component list --installed
  • Fresh isolated RUSTUP_HOME/CARGO_HOME on the arm64 Mac, installed with --default-toolchain none: rustc --version, rustup show active-toolchain, rustup target list --installed in the worktree
  • cargo build --release --target x86_64-apple-darwin -p codegraph-parser-api with the fresh pinned toolchain
  • cargo build --release --target x86_64-apple-darwin -p codegraph-server with the fresh pinned toolchain, then file and arch -x86_64 codegraph-server --version
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

anvanster and others added 3 commits October 5, 2026 19:06
Release engines are built on four hosts plus a container that installs
its own Rust. Unpinned, they ran three different rustc versions. A
rust-toolchain.toml makes rustup on every host, and in the linux-arm64
container, use the same compiler.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017rVbt7rENTwXkdHt3Bpgb5
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔍 CodeGraph PR Review

4 files changed (+14/−3, 0 functions) · Risk: 🟢 low

Suggested reviewers

Andrey Vasilevsky (22 lines), anvanster (8 lines)

Suggested commit: fix(core): <describe the change> · 0 tests cover the changes
🤖 Generated by CodeGraph

@anvanster
anvanster merged commit 590c2ca into main Oct 6, 2026
1 check passed
@anvanster
anvanster deleted the build/pin-rust-toolchain branch October 6, 2026 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant