- Add scripts/ci-target-cache.ts to snapshot and restore Cargo target directories to S3 storage on omp-kata runners.
- Update .github/actions/build-native/action.yml to support target cache restoration, saving, and compiler launcher configurations.
- Add skip_validation input in GitHub workflow actions to bypass clippy and Rust test checks on release runs.
- Pinned to the same versions as .github/actions/ensure-cmake (cmake 4.1.2, ninja 1.13.1), which now no-ops on the preloaded image.
- Extended both reload smoke-test tool lists with cmake/ninja.
- Rolled out as omp-kata-runner:2026-07-24-113811.
- Added ensure-cmake action installing pinned cmake/ninja on omp-kata pods; audiopus_sys builds bundled libopus via CMake (Ninja for MSVC cross).
- Set CMAKE_POLICY_VERSION_MINIMUM=3.5 globally and in build-native.ts: the bundled opus tree declares cmake_minimum_required below 3.5, which CMake 4.x refuses.
- Dropped the -C target-cpu=native fallback for non-x64 native builds: it baked build-host CPU features into shipped darwin arm64 addons and trips ring 0.17's aarch64-apple const assertion.
The glibc floor input was applied to every linux row, suffixing musl cross-targets to invalid *-unknown-linux-musl.2.17 triples. Gate the floor on non-musl libc.
Fixes#3367
- Added a paths-ignore filter to the CI workflow to prevent unnecessary runs during vouch bookkeeping commits.
- Ensured that pushes affecting both vouch files and project code continue to trigger the full CI matrix.
- Added a GitHub Action workflow to manage user vouching through discussion comments.
- Created CONTRIBUTING.md to define the vouching policy and workflow for contributors.
- Updated README.md to include instructions on the required vouching process for pull requests.
- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
- Updated the bun-install action to retry `bun install --frozen-lockfile` when the first attempt fails.
- Added a fallback path that creates a temporary job-local cache directory and reruns install with `--cache-dir`.
- Emitted a warning to note the shared-store failure before the retry path is used.
- Detected the runner environment in CI by checking SCCACHE_BUCKET and exporting an on_infra output.
- Updated the workflow to use the local ensure-sccache action on self-hosted runners and mozilla-actions/sccache-action on GitHub-hosted runners.
Native linux-x64/arm64 builds moved onto the Ubuntu 24.04 (glibc 2.39)
omp-kata runner. The x64 addon was a plain host build that linked the
runner's glibc and failed to dlopen with `version 'GLIBC_2.39' not found`
on older distros; the arm64 cross-build floated up to GLIBC_2.30. Build
the shipped linux-gnu addons through cargo-zigbuild against a pinned 2.17
floor so they load on any glibc >= 2.17.
- build-native.ts: key the tree-sitter-just `-UNDEBUG` CFLAGS off the
bare triple (cargo-zigbuild strips the `.2.17` glibc suffix before
invoking cargo) and symlink the suffixed target dir napi 3.7.0 expects
to the bare dir cargo-zigbuild writes, so postBuild copyArtifact finds
the cdylib.
- build-native action: add a `glibc` input plus a resolve step deriving
the zigbuild cross_target (suffixed) and the rustup bare_target
(stripped); gate zig/cargo-zigbuild install on cross_target so the
host-arch x64 build still runs native Rust tests.
- ci.yml: GLIBC_FLOOR=2.17 fed to the linux-x64 and linux-arm64 native
jobs.
Re-tags 15.13.1, whose release failed at the linux-x64 binary smoke
before any publish step ran.