Loading
Draft: ci: Fix BCHN functional tests and win64 test jobs; bump rustls-webpki and rand for RUSTSEC advisories
Branch:
ci-deps-fixesfrom the jQrgen/rostrum fork (6 commits on top of masterefda92ba). Does not touch thebitcoincashcrate bump in !459 (merged).
Why
Master's CI has been red since 15 Apr 2026 (pipeline 2455334744), and MR pipelines (e.g. !458 (merged)) fail for reasons that have nothing to do with the MRs themselves:
| Symptom | Root cause |
|---|---|
All test-qa-bchn-* jobs fail: RPC is disabled. This version of Bitcoin Cash Node is old and may be out of consensus with the network |
bitcoin-cash-node 28.0.1 has reached its built-in expiry date |
test-stable-{bch,nexa}-win64 fail: Library bcryptprimitives.dll ... not found, status c0000135 |
Since Rust 1.78, std on Windows imports ProcessPrng from bcryptprimitives.dll. Debian bookworm's Wine 8.0 doesn't provide it. Wine 9 and later do. |
test-qa-nexa-win64 fails: Path '' set in environment variable PROCESS_WRAPPER does not exist |
which wine64-stable finds nothing, because bookworm's wine64 package has no binary by that name |
lint-audit fails (the job that turns master red) |
RUSTSEC-2026-0098 and RUSTSEC-2026-0099 in rustls-webpki 0.103.10, plus advisories published since April (see change 6) |
Changes
- ci: Upgrade bitcoin-cash-node to 29.2.0 for functional tests. This is the current BCHN release. The version now lives in a
BCHN_VERSIONvariable, and the tarball is checked against aBCHN_SHA256taken from the signedSHA256SUMS.29.2.0.asc(good signatures from Calin Culianu and im_uname, and it matches GitHub's asset digest). I chose the upgrade overexpire=0so the tests run against the node version operators actually run, rather than switching off a safety check. 29.2.0 drops-excessiveblocksize, but the functional tests never pass it. - ci: Fix win64 test jobs by installing Wine from WineHQ. In
.win64_common,INSTALL_EMULATORnow installswine-stablepinned to11.0.0.0~bookworm-1from the WineHQ bookworm repo, following the official WineHQ Debian instructions (this needsdpkg --add-architecture i386). The cargo runner andPROCESS_WRAPPERnow use/opt/wine-stable/bin/wine. I also addedWINEDLLOVERRIDES=mscoree,mshtml=so creating the Wine prefix doesn't try to install mono/gecko without a display. Existingallow_failureflags are unchanged. - deps: Bump rustls-webpki to 0.103.13. This fixes RUSTSEC-2026-0098/0099 and also RUSTSEC-2026-0104 (a CRL-parsing panic). It's the lowest release that covers all three, and it doesn't pull in aws-lc updates.
- deps: Bump rand to patched releases (RUSTSEC-2026-0097): 0.8.5 to 0.8.6, 0.9.2 to 0.9.3, 0.10.0 to 0.10.1. Lockfile only. These are the patched versions, so no audit ignore is needed.
- Cargo.toml:
homepageandrepositorynow point tohttps://gitlab.com/nexa/rostrum. - deps: Update lockfile for advisories published since April. This goes beyond the original scope, and the commit can be dropped on its own. Without it,
lint-auditstill fails. All updates are semver-compatible and touch only the lockfile:- rustls 0.23.37 to 0.23.45 (RUSTSEC-2026-0285). This forces rustls-webpki 0.103.15 and aws-lc-rs 1.18.1 / aws-lc-sys 0.45.0.
- crossbeam-epoch 0.9.18 to 0.9.21 (RUSTSEC-2026-0204).
- rust_decimal 1.41.0 to 1.43.0. This removes rkyv 0.7.46 (RUSTSEC-2026-0235) from the lockfile; it was an optional dependency that never got built.
- anyhow 1.0.102 to 1.0.104 (RUSTSEC-2026-0190).
- Yanked chacha20 0.10.0 to 0.10.2, and spin 0.9.8 to 0.9.9.
Verification (local, on Debian 13 box, at branch head 2df0085)
| Check | Result |
|---|---|
cargo fmt --all -- --check |
pass |
cargo build --locked --features=bch (stable 1.99) |
pass (2 fetch_update deprecation warnings on 1.99, not caused by this branch) |
cargo build --release --locked --features=bch |
pass |
cargo test --locked --features=bch |
pass, 107 unit tests |
cargo test --locked --features=nexa |
pass, 97 unit tests |
cargo +1.88 test --locked --features=fail-on-warnings,bch (MSRV toolchain, warnings denied) |
pass |
cargo audit --ignore RUSTSEC-2023-0089 --ignore RUSTSEC-2024-0436 (the lint-audit command, cargo-audit 0.22.2) |
pass, 0 vulnerabilities. Master failed with 2 vulnerabilities in April, and more advisories have appeared since. |
cargo clippy -- -D warnings |
fails, but master fails the same way. On stable 1.99 the branch and master give the same 20 errors (new lints plus the fetch_update deprecation). On 1.88, uninlined_format_args fires about 180 times in untouched files. Master's lint-clippy passed in April with CI's toolchain, and this branch changes no Rust source. |
Functional tests, BCH: test/functional/test_runner.py -parallel=4 with BCHN 29.2.0 and the branch's release binary |
pass, 36/36 tests (3 disabled by the runner: idle_timeout, doslimit and shutdownonerror don't support BCHN/spawn), 300 s |
.gitlab-ci.yml |
parses as YAML; every extends target exists; every changed script/before_script line passes bash -n |
| Patch series | git am onto master reproduces the branch tree exactly |
Not verified / reviewer notes
- This MR's pipeline is the first real run of the CI changes. Locally I parsed the YAML and ran every
script/before_scriptline throughbash -n. - The Wine fix was checked locally: a Rust 1.88
x86_64-pc-windows-gnubinary that importsbcryptprimitives.dllruns under the WineHQ 11.0 bookworm build. Debian's Wine 8.0 package has nobcryptprimitives.dllat all. I didn't run the install steps in a bookworm container. - Installing WineHQ adds about 100 MB of i386 packages to the win64 test jobs.
APT_CACHE_DIRshould cache them. - Not run: the Nexa functional tests, the aarch64/win64 CI jobs, and GitLab's own CI lint (it needs an API token).
- On newer Rust (1.99),
src/doslimit.rswarns about the deprecatedAtomicI32::fetch_update(renamed totry_update). This is out of scope here, but it will tripfail-on-warnings/clippy -D warningsonce CI's toolchain moves forward.