Skip to content

fix(ci): restore standalone BDK builds (SFT-8127) - #8

Closed
Jacksper13 wants to merge 2 commits into
foundation-dev-0.0.1from
jack/sft-8127-bdk-ci-compatibility
Closed

Jacksper13 wants to merge 2 commits into
foundation-dev-0.0.1from
jack/sft-8127-bdk-ci-compatibility

Conversation

@Jacksper13

@Jacksper13 Jacksper13 commented Sep 16, 2026 •

Copy link
Copy Markdown

Summary

Restore the standalone build and fix the existing CI failures exposed by documentation-only PR #7.

  • Align the wallet and example dependencies so they supply the serialization implementations that Wallet::Update already requires. Keep the existing BDK crate versions and serialization support without introducing a broader BDK upgrade.
  • Commit a Cargo-generated, version-3 lockfile and use --locked in CI. Preserve both Rust 1.63 and 1.85 checks, with compatible dependency selections and documented lockfile regeneration.
  • Keep the WASM Clang 14 setup on Ubuntu 22.04, remove the unused LLVM repository-key download, and bound package operations to five minutes with network timeouts/retries. Build/test jobs have a 20-minute limit instead of a six-hour default.
  • Replace deprecated keypair conversions in the signer and its PSBT test with the equivalent existing From conversion, and add a nonempty wallet-update serialization roundtrip regression test.
  • Select only the needed Esplora features in each example. The blocking example uses the existing native-TLS option, removing minreq's obsolete rustls 0.21/webpki 0.101 dependency and its three audit failures. The async example retains its native-TLS backend without pulling in an unused blocking backend.

Scope

No changes to wallet formats, signing policy, or SECURITY.md. All example backends stay enabled and share the same BDK types. The blocking Esplora example now uses platform trust roots/native TLS instead of bundled webpki roots; certificate/hostname verification remains enabled. This is confined to the example, not a change to downstream applications' TLS selection. Dependency metadata/lockfile changes account for most of the diff; the lockfile is generated by Cargo, not hand-edited.

Instead of relying on whichever transitive versions resolve on a given day, CI uses the committed dependency graph. Library consumers still resolve dependencies in their own workspace, so this does not globally pin downstream applications.

Validation

  • No local tests, builds, or analyzers were run, as requested.
  • Local work was limited to source inspection, Cargo dependency-lock generation, Rust formatting, and git diff --check.
  • At head 345b47e1, CI passed: the Rust 1.63/1.85 feature matrix, no-std, WASM, all four examples, Clippy, formatting, and the new serialization regression.
  • Coverage passed, and the dependency audit passed. The corresponding push workflows also passed.
  • Coveralls reports 85.06% line coverage and 100% changed-line coverage. It has no successful coverage build for the base commit, so it cannot calculate a coverage delta or regressions against the base.

Dependency follow-ups

The audit's informational warnings remain visible; no advisories are suppressed. bincode (persisted file-store format), adler (backtrace), and rustls-pemfile (HTTP dependency) are reported as unmaintained. Migrating these is outside this build-repair PR.

anyhow also has an informational downcast_mut unsoundness warning (RUSTSEC-2026-0190). There are no calls to that operation in this wallet, its examples, or the selected BDK dependencies. The patched 1.0.103 requires Rust 1.68, versus the wallet's declared 1.63 test baseline. It is a development/example dependency here; updating the MSRV or backporting that fix needs a separate compatibility decision, not an advisory ignore.

SFT-8127

Use the matching Foundation BDK serialization revision across the wallet and examples. Lock compatible dependency versions without removing Rust 1.63 coverage, and bound package installation so mirror failures cannot consume six hours. Preserve Update serialization and cover it with a nonempty roundtrip fixture. Tests, builds, and Clippy are delegated to CI; local verification is limited to formatting, dependency-lock generation, and diff checks.
@coveralls

coveralls commented Sep 16, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 35088715832

Warning

No base build found for commit 646fc24 on foundation-dev-0.0.1.
Coverage changes can't be calculated without a base build.
If a base build is processing, this comment will update automatically when it completes.

Coverage: 85.061%

Details

  • Patch coverage: 1 of 1 lines across 1 file are fully covered (100%).

Uncovered Changes

No uncovered changes found.

Coverage Regressions

Requires a base build to compare against. How to fix this →


Coverage Stats

Coverage Status
Relevant Lines: 7484
Covered Lines: 6366
Line Coverage: 85.06%
Coverage Strength: 3332.25 hits per line

💛 - Coveralls

@Jacksper13 Jacksper13 closed this Sep 16, 2026
@Jacksper13
Jacksper13 deleted the jack/sft-8127-bdk-ci-compatibility branch September 16, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants