Skip to content

fix(ci): WaaV CI never ran — make the workflow valid and fix what its first run reports - #11

Merged
dittops merged 8 commits into
mainfrom
fix/ci-workflow-expression
Sep 27, 2026
Merged

dittops merged 8 commits into
mainfrom
fix/ci-workflow-expression

Conversation

@dittops

@dittops dittops commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

WaaV CI has not run a single job since e03826e (2026-06-03). ci.yml was invalid, so every run on main and on every PR failed in 0 s with "workflow file issue". This PR makes the workflow valid, then fixes what the jobs report on their first real run. Every problem below was already on main; none comes from a feature branch.

1. The workflow never ran

ci.yml:386 had join(needs.*.result, ","). GitHub expressions accept only single-quoted strings. The value now reaches the script through env:.

2. Nothing that compiles the gateway could build

livekit's webrtc-sys panics in its build script without the libva headers. A composite action, .github/actions/native-deps, installs the builder-stage packages from gateway/Dockerfile and sets the same CC/CXX/ZSTD_SYS_USE_PKG_CONFIG. All 9 compiling jobs use it.

.github/actions/onnxruntime provisions ONNX Runtime. ort uses load-dynamic, so core::onnx's unit tests panicked without it in the turn-ensemble builds. It replaces the two copies of that step in coverage and accuracy.

The rust-cache key for the build matrix contained commas, which rust-cache rejects.

3. The musl job could never pass → no-openssl

The gateway links livekit's libwebrtc, a glibc C++ prebuilt, so it has never built for musl. The runners have no musl C++ compiler either. The job is replaced by the claim it stood for, from the README: no openssl or native-tls crate in the runtime dependency graph, under --all-features and --no-default-features. ort-sys pulls in native-tls only as a build dependency, to download ONNX Runtime. I confirmed the check fails when build edges are included.

4. clippy -D warnings (rust 1.98.1): 85 findings across lib, tests, benches and examples

  • 53 × await_holding_lock: all in test code, and all on deliberate env or serialisation locks such as core::net::test_env_lock. That's a process-wide std Mutex which serialises env-var-mutating tests and is deliberately held across awaits. Each #[tokio::test] has its own runtime and thread, so the deadlock this lint guards against can't happen. There's one cfg_attr(test, allow(...)) in lib.rs, plus a crate-level allow in the three integration-test crates that do the same, each with the reason written down. Production code is still linted.
  • 32 fixed in code:
    • as_chunks::<2>() for PCM16 decoding;
    • is_multiple_of and div_ceil;
    • a Default for TTSProvider;
    • boxing the 320-byte STTResult in the observer queue event (every queued event shrinks to about 80 bytes);
    • orphaned doc comments, a needless lifetime and an explicit loop counter;
    • the aligned_copy bench ignored copy_from_slice's Result, and now fails loudly instead of benchmarking nothing.

The release image builds with 1.96, and all of these APIs are older than that.

5. supply-chain

  • deny.toml used wildcard-dependencies, a key current cargo-deny rejects (it's wildcards now). So the config failed to load before any check ran.

  • 17 findings fixed by upgrades (14 advisories and 3 yanked crates):

    • anyhow 1.0.104 (unsound);
    • crossbeam-epoch 0.9.21;
    • h2 0.4.19;
    • rtrb 0.3.5;
    • rustls 0.23.45;
    • quinn-proto 0.11.18;
    • cxx 1.0.202, event-listener 5.4.2 and memmap2 0.9.11 (all unsound, found by cargo audit);
    • quick-xml 0.41, via object_store 0.12 → 0.14.2;
    • rustls-webpki 0.101 ×3, gone with the AWS SDK's legacy connector (h2 0.3 leaves that path too, but stays via tonic; see below);
    • yanked chacha20, der and spin.

    The AWS SDK crates no longer enable their default rustls feature. That feature only adds the legacy hyper-0.14 connector, and with BehaviorVersion::latest(), which every call site passes, the SDK already uses default-https-client.

  • 12 recorded as ignores, each with its reason, in deny.toml, and mirrored in gateway/.cargo/audit.toml for cargo audit:

    • tonic 0.11's h2 0.3 and rustls-webpki 0.102: pinned by google-api-proto. The only peer is Google's endpoint. They leave with a move to googleapis-tonic-*.
    • tract-nnef: WaaV never loads NNEF, only the compiled-in DeepFilterNet ONNX model. The fixed tract caps time below 0.3.42, which would bring back RUSTSEC-2026-0009.
    • 5 unmaintained crates with no upgrade.
  • Licence: CDLA-Permissive-2.0 is allowed. It's the Mozilla CA bundle in webpki-roots.

  • typos: 1845 findings, almost all false positives.

    • The codebase writes British English, but locale was en-us; it's now en.
    • Domain terms, language codes, deliberate test misspellings and opaque ids are allow-listed in labelled groups.
    • Agent-run JSON transcripts under inferv2/REVIEW are excluded.
    • I confirmed the gate still catches recieve, adress and seperate.

6. rustfmt

8 hunks in plugin-api/src/lib.rs.

7. The merge gate itself

With all ten required results success, required still failed. It has no checkout, so the workflow-wide working-directory: gateway doesn't exist and bash couldn't start. It now runs from the workspace root.

Follow-ups (not in this PR)

  • Move the Google Speech client off google-api-proto/tonic 0.11. That clears the last h2 0.3 and rustls-webpki 0.102.
  • tract 0.22+, once DeepFilterNet supports it.

Test plan

  • actionlint .github/workflows/ci.yml: clean.
  • typos --config _typos.toml: clean, and it still catches real typos.
  • cargo deny --all-features check advisories bans licenses sources: all ok.
  • cargo clippy --locked --keep-going --all-targets --features dag-routing,turn-ensemble,noise-filter,openapi -- -D warnings: clean on rustc 1.98.1, in a bookworm container with the CI env.
  • cargo test --lib (full features, ONNX Runtime provisioned): 7005 passed. Integration set: 56 passed. openapi_drift: 3 passed.
  • cargo audit --deny warnings: clean.
  • CI green on this PR: all 15 jobs, including server boot, VAD/turn accuracy and the merge gate, which had never run before. The live-provider e2e job is secret-gated and skipped on PRs.
  • WaaV#10 merged locally on top of this PR: clippy (all targets), deny, audit, typos, fmt and no-openssl are clean. 7018 unit, 56 integration and 3 openapi-drift tests pass. feat(gateway): rate limits, retries, breakers and fallback for Bud voice deployments #10 needs no changes, so merge this PR first.

🤖 Generated with Claude Code

dittops and others added 7 commits September 27, 2026 22:50
GitHub expressions only take single-quoted strings. `join(needs.*.result, ",")`
made the whole workflow invalid, so every CI run since e03826e failed in 0 s
with a workflow file issue and no job ever ran. The value now arrives through
env instead of being spliced into the script.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The rustfmt job never ran while ci.yml was invalid, so these 8 hunks
landed unformatted. No code change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e runtime graph

Every compiling job failed in webrtc-sys's build script: libva headers not
found. A composite action now installs the builder stage's packages from
gateway/Dockerfile and sets the same CC/CXX/ZSTD env, in all 9 jobs that
compile the gateway.

The musl cross-compile job could never pass: livekit links libwebrtc, a
glibc C++ prebuilt, and the runners have no musl C++ compiler. It is
replaced by the claim it stood for, that no openssl/native-tls crate is in
the runtime dependency graph under any feature. ort-sys uses native-tls
only as a build dependency, to download ONNX Runtime.

Also: rust-cache keys may not contain commas, and one build matrix entry
had three.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ort is built with load-dynamic, so core::onnx's unit tests panic without
libonnxruntime.so, and build+unit never provisioned it. The download moves
into .github/actions/onnxruntime, which build+unit, coverage and accuracy
share.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The clippy job never ran while ci.yml was invalid. All 85 findings across
lib, tests, benches and examples:

- await_holding_lock (53): every one is a test env or serialisation
  lock, deliberately held across the test body's awaits. Each
  #[tokio::test] owns its runtime and thread, so a blocked lock() cannot
  deadlock the guard's holder. Allowed for test builds only, with the
  reason recorded; production code is still linted.
- chunks_exact(2) over PCM16 -> as_chunks::<2>(); % -> is_multiple_of;
  (n + d - 1) / d -> div_ceil; a Default for TTSProvider; the 320-byte
  STTResult is boxed in the observer queue event; orphaned doc comments,
  a needless lifetime, an explicit loop counter, redundant matches.
- The aligned_copy bench ignored copy_from_slice's Result; a failed copy
  would have benchmarked nothing, so it now fails loudly.

The release image builds with rust 1.96; every API used predates it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
deny.toml used `wildcard-dependencies`, which cargo-deny no longer
accepts (`wildcards`), so the config failed to load before any check.

Fixed by upgrading: anyhow 1.0.104 (unsound), crossbeam-epoch 0.9.21,
h2 0.4.19, rtrb 0.3.5, rustls 0.23.45, quinn-proto 0.11.18, cxx 1.0.202,
event-listener 5.4.2, memmap2 0.9.11, and the yanked chacha20, der and
spin. object_store 0.12 -> 0.14.2 for quick-xml 0.41 (get() moved to
ObjectStoreExt). The AWS SDK crates drop their default `rustls` feature:
it only adds the legacy hyper-0.14 connector (rustls 0.21, h2 0.3,
rustls-webpki 0.101), and with BehaviorVersion::latest(), which every call
site passes, the SDK already uses default-https-client.

Recorded as ignores with reasons (deny.toml; mirrored in
gateway/.cargo/audit.toml for cargo audit): tonic 0.11's h2 0.3 and
rustls-webpki 0.102, pinned by google-api-proto for the Google Speech
client; tract-nnef's NNEF parser, which WaaV never feeds (the fixed tract
caps time < 0.3.42 and would bring back RUSTSEC-2026-0009); five
unmaintained crates with no upgrade. CDLA-Permissive-2.0 (the webpki-roots
CA bundle) is an allowed licence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The codebase writes British English, but locale was en-us. Domain terms,
language codes, deliberate misspellings the tests feed to the code, and
opaque ids are allow-listed in labelled groups. Agent-run transcripts
under inferv2/REVIEW/*.json are excluded. The gate still catches recieve,
adress and seperate.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dittops dittops changed the title fix(ci): the workflow never ran — single-quote the merge gate's string literal fix(ci): WaaV CI never ran — make the workflow valid and fix what its first run reports Sep 27, 2026
It has no checkout, so the workflow-wide working-directory (gateway) does
not exist and bash could not start. All ten required results were success.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dittops
dittops merged commit 3ad97af into main Sep 27, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant