Skip to content

ci: pin public repo to hosted runners; slim rust builds - #3056

Merged
goastler merged 10 commits into
mainfrom
ci/rust-build-slimming
Aug 19, 2026
Merged

goastler merged 10 commits into
mainfrom
ci/rust-build-slimming

Conversation

@goastler

@goastler goastler commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

Two CI changes.

1. Pin this repo to GitHub-hosted runners

Replaces the vars.GH_RUNNER indirection with a hardcoded runs-on: ubuntu-latest in all 14 workflows that used it, and drops the variable entirely from this repo. Each site carries a comment explaining why, matching the precedent already in android-webview.yml.

Why

  • This repo is public. Routing jobs through vars.GH_RUNNER means a fork PR can land on the self-hosted fleet, executing arbitrary contributor code on hardware we own. Worse than the immediate execution: a self-hosted runner is persistent, so an attacker can leave something behind — a poisoned cargo/npm cache, a modified toolchain, cron — that later runs inside trusted jobs. That converts a drive-by fork PR into a foothold in the release pipeline. GitHub's own guidance is to use self-hosted runners with private repositories only.
  • It costs nothing to stay hosted. Standard GitHub-hosted runners are free and unlimited on public repositories — macOS and Windows included; the per-minute macOS/Windows rates in the pricing tables are the private-repo card. Only larger runners are billed, and those are billed on public repos too. So the usual "self-hosted saves money on expensive OSes" argument does not apply to a public repo at all.

The one macos-15 job was already hardcoded and is unaffected.

Note for review: the self-hosted capacity labels encoded a per-job size (2c/4g/20d … 4c/8g/40d). Hardcoding to ubuntu-latest gives every job 4 cores / 16 GB, which is at or above what each job asked for on CPU and RAM, but the largest jobs previously requested 40 GB of disk against ~14 GB free on a standard hosted runner. If any of those hit disk pressure, the free_disk_space_* composite actions are the lever, not a larger runner.

2. Slim Rust builds in CI

  • CARGO_INCREMENTAL=0 — incremental artifacts are useless in CI (cold target dir each run) and inflate cache size.
  • CARGO_PROFILE_DEV_DEBUG=line-tables-only — keeps backtraces useful without full debug info.

Companion PRs: https://github.com/prosopo/captcha-private/pull/4152, https://github.com/prosopo/Protect/pull/474, prosopo/github_actions#7

Ref: https://docs.github.com/en/billing/reference/actions-runner-pricing

This repository is public, so routing jobs through vars.GH_RUNNER risks a
fork PR executing arbitrary contributor code on the self-hosted fleet, and
persisting there to poison later trusted jobs. Standard GitHub-hosted
runners are free and unlimited on public repos, so there is no cost reason
to take that risk.
@goastler
goastler force-pushed the ci/rust-build-slimming branch from 1c1a52c to 13175a5 Compare August 13, 2026 16:20
@goastler goastler changed the title ci: slim rust builds in CI ci: pin public repo to hosted runners; slim rust builds Aug 13, 2026
@goastler
goastler marked this pull request as ready for review August 19, 2026 15:38
# Conflicts:
#	packages/native-ja4/Cargo.toml
#	packages/native-merkle/Cargo.toml
publish_release and create_release_pr both run npm run build, which compiles
the native-ja4 and native-merkle napi crates, so they want the same cargo
settings as the test and lint workflows.
@goastler
goastler merged commit 03c2d2c into main Aug 19, 2026
6 checks passed
@goastler
goastler deleted the ci/rust-build-slimming branch August 19, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant