fix(ci): WaaV CI never ran — make the workflow valid and fix what its first run reports - #11
Merged
Merged
Conversation
GitHub expressions only take single-quoted strings. `join(needs.*.result, ",")` made the whole workflow invalid, so every CI run since e03826e failed in 0 s with a workflow file issue and no job ever ran. The value now arrives through env instead of being spliced into the script. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The rustfmt job never ran while ci.yml was invalid, so these 8 hunks landed unformatted. No code change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e runtime graph Every compiling job failed in webrtc-sys's build script: libva headers not found. A composite action now installs the builder stage's packages from gateway/Dockerfile and sets the same CC/CXX/ZSTD env, in all 9 jobs that compile the gateway. The musl cross-compile job could never pass: livekit links libwebrtc, a glibc C++ prebuilt, and the runners have no musl C++ compiler. It is replaced by the claim it stood for, that no openssl/native-tls crate is in the runtime dependency graph under any feature. ort-sys uses native-tls only as a build dependency, to download ONNX Runtime. Also: rust-cache keys may not contain commas, and one build matrix entry had three. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ort is built with load-dynamic, so core::onnx's unit tests panic without libonnxruntime.so, and build+unit never provisioned it. The download moves into .github/actions/onnxruntime, which build+unit, coverage and accuracy share. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The clippy job never ran while ci.yml was invalid. All 85 findings across lib, tests, benches and examples: - await_holding_lock (53): every one is a test env or serialisation lock, deliberately held across the test body's awaits. Each #[tokio::test] owns its runtime and thread, so a blocked lock() cannot deadlock the guard's holder. Allowed for test builds only, with the reason recorded; production code is still linted. - chunks_exact(2) over PCM16 -> as_chunks::<2>(); % -> is_multiple_of; (n + d - 1) / d -> div_ceil; a Default for TTSProvider; the 320-byte STTResult is boxed in the observer queue event; orphaned doc comments, a needless lifetime, an explicit loop counter, redundant matches. - The aligned_copy bench ignored copy_from_slice's Result; a failed copy would have benchmarked nothing, so it now fails loudly. The release image builds with rust 1.96; every API used predates it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
deny.toml used `wildcard-dependencies`, which cargo-deny no longer accepts (`wildcards`), so the config failed to load before any check. Fixed by upgrading: anyhow 1.0.104 (unsound), crossbeam-epoch 0.9.21, h2 0.4.19, rtrb 0.3.5, rustls 0.23.45, quinn-proto 0.11.18, cxx 1.0.202, event-listener 5.4.2, memmap2 0.9.11, and the yanked chacha20, der and spin. object_store 0.12 -> 0.14.2 for quick-xml 0.41 (get() moved to ObjectStoreExt). The AWS SDK crates drop their default `rustls` feature: it only adds the legacy hyper-0.14 connector (rustls 0.21, h2 0.3, rustls-webpki 0.101), and with BehaviorVersion::latest(), which every call site passes, the SDK already uses default-https-client. Recorded as ignores with reasons (deny.toml; mirrored in gateway/.cargo/audit.toml for cargo audit): tonic 0.11's h2 0.3 and rustls-webpki 0.102, pinned by google-api-proto for the Google Speech client; tract-nnef's NNEF parser, which WaaV never feeds (the fixed tract caps time < 0.3.42 and would bring back RUSTSEC-2026-0009); five unmaintained crates with no upgrade. CDLA-Permissive-2.0 (the webpki-roots CA bundle) is an allowed licence. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The codebase writes British English, but locale was en-us. Domain terms, language codes, deliberate misspellings the tests feed to the code, and opaque ids are allow-listed in labelled groups. Agent-run transcripts under inferv2/REVIEW/*.json are excluded. The gate still catches recieve, adress and seperate. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
It has no checkout, so the workflow-wide working-directory (gateway) does not exist and bash could not start. All ten required results were success. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
WaaV CI has not run a single job since
e03826e(2026-06-03).ci.ymlwas invalid, so every run onmainand on every PR failed in 0 s with "workflow file issue". This PR makes the workflow valid, then fixes what the jobs report on their first real run. Every problem below was already onmain; none comes from a feature branch.1. The workflow never ran
ci.yml:386hadjoin(needs.*.result, ","). GitHub expressions accept only single-quoted strings. The value now reaches the script throughenv:.2. Nothing that compiles the gateway could build
livekit's
webrtc-syspanics in its build script without the libva headers. A composite action,.github/actions/native-deps, installs the builder-stage packages fromgateway/Dockerfileand sets the sameCC/CXX/ZSTD_SYS_USE_PKG_CONFIG. All 9 compiling jobs use it..github/actions/onnxruntimeprovisions ONNX Runtime.ortuses load-dynamic, socore::onnx's unit tests panicked without it in theturn-ensemblebuilds. It replaces the two copies of that step in coverage and accuracy.The rust-cache key for the build matrix contained commas, which rust-cache rejects.
3. The musl job could never pass →
no-opensslThe gateway links livekit's libwebrtc, a glibc C++ prebuilt, so it has never built for musl. The runners have no musl C++ compiler either. The job is replaced by the claim it stood for, from the README: no openssl or native-tls crate in the runtime dependency graph, under
--all-featuresand--no-default-features.ort-syspulls in native-tls only as a build dependency, to download ONNX Runtime. I confirmed the check fails when build edges are included.4. clippy
-D warnings(rust 1.98.1): 85 findings across lib, tests, benches and examplesawait_holding_lock: all in test code, and all on deliberate env or serialisation locks such ascore::net::test_env_lock. That's a process-wide stdMutexwhich serialises env-var-mutating tests and is deliberately held across awaits. Each#[tokio::test]has its own runtime and thread, so the deadlock this lint guards against can't happen. There's onecfg_attr(test, allow(...))inlib.rs, plus a crate-level allow in the three integration-test crates that do the same, each with the reason written down. Production code is still linted.as_chunks::<2>()for PCM16 decoding;is_multiple_ofanddiv_ceil;DefaultforTTSProvider;STTResultin the observer queue event (every queued event shrinks to about 80 bytes);aligned_copybench ignoredcopy_from_slice'sResult, and now fails loudly instead of benchmarking nothing.The release image builds with 1.96, and all of these APIs are older than that.
5. supply-chain
deny.tomlusedwildcard-dependencies, a key current cargo-deny rejects (it'swildcardsnow). So the config failed to load before any check ran.17 findings fixed by upgrades (14 advisories and 3 yanked crates):
cargo audit);The AWS SDK crates no longer enable their default
rustlsfeature. That feature only adds the legacy hyper-0.14 connector, and withBehaviorVersion::latest(), which every call site passes, the SDK already usesdefault-https-client.12 recorded as ignores, each with its reason, in
deny.toml, and mirrored ingateway/.cargo/audit.tomlforcargo audit:google-api-proto. The only peer is Google's endpoint. They leave with a move togoogleapis-tonic-*.timebelow 0.3.42, which would bring back RUSTSEC-2026-0009.Licence:
CDLA-Permissive-2.0is allowed. It's the Mozilla CA bundle inwebpki-roots.typos: 1845 findings, almost all false positives.
localewasen-us; it's nowen.inferv2/REVIEWare excluded.recieve,adressandseperate.6. rustfmt
8 hunks in
plugin-api/src/lib.rs.7. The merge gate itself
With all ten required results
success,requiredstill failed. It has no checkout, so the workflow-wideworking-directory: gatewaydoesn't exist and bash couldn't start. It now runs from the workspace root.Follow-ups (not in this PR)
google-api-proto/tonic 0.11. That clears the last h2 0.3 and rustls-webpki 0.102.Test plan
actionlint .github/workflows/ci.yml: clean.typos --config _typos.toml: clean, and it still catches real typos.cargo deny --all-features check advisories bans licenses sources: all ok.cargo clippy --locked --keep-going --all-targets --features dag-routing,turn-ensemble,noise-filter,openapi -- -D warnings: clean on rustc 1.98.1, in a bookworm container with the CI env.cargo test --lib(full features, ONNX Runtime provisioned): 7005 passed. Integration set: 56 passed.openapi_drift: 3 passed.cargo audit --deny warnings: clean.🤖 Generated with Claude Code