Skip to content

Build RedDB sidecar from pinned source when needed - #100

Merged
filipeforattini merged 2 commits into
mainfrom
agent/reddb-source-sidecar
Jun 26, 2026
Merged

filipeforattini merged 2 commits into
mainfrom
agent/reddb-source-sidecar

Conversation

@filipeforattini

@filipeforattini filipeforattini commented Jun 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add REDDB_SOURCE_REF support to release preflight and release-fast
  • build the embedded red sidecar from a pinned RedDB source commit when full upstream assets are not available
  • pin the main release workflow to fix(migrations): align native migration contracts reddb#1473 merge commit so migration contract fixes are included in shipped red-request bundles

Validation

  • node --check scripts/sync-reddb.mjs scripts/check-reddb-release-assets.mjs
  • source-ref preflight against fb6dd5b00737ac5c093d838875c8ddb7eed4f874
  • release-asset preflight against RedDB v1.15.0
  • fake cargo sync-reddb test for linux and windows target output names
  • pnpm exec prettier --check changed workflow/script files
  • git diff --check
  • pre-commit hook: pnpm -r check passed after building @red-request/core and @red-request/engine

Note: a real local RedDB release build was attempted but blocked behind another long-running local cargo process in the RedDB workspace. The PR CI/release-fast path is the authoritative validation for the source-build workflow.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features

    • Release workflows can now build the RedDB sidecar from a pinned source revision when provided.
    • Added support for handling Windows builds more reliably, including the correct executable naming.
  • Bug Fixes

    • Improved release prechecks so source-based builds skip unnecessary asset checks and fail cleanly if the requested revision can’t be found.
    • Made local and cross-platform build detection more resilient when reporting the built version.

@coderabbitai

coderabbitai Bot commented Jun 26, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@filipeforattini, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 52 minutes and 58 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f09eac99-7e99-4095-89c5-d85a776f549c

📥 Commits

Reviewing files that changed from the base of the PR and between 6094dd2 and f8abb9f.

📒 Files selected for processing (2)
  • .github/workflows/release-fast.yml
  • .github/workflows/release.yml
📝 Walkthrough

Walkthrough

Release workflows and the RedDB sync helper now accept an optional source ref. When it is set, the jobs resolve the commit, check out reddb-io/reddb, build the sidecar from source, and adjust target, executable, and version handling for cross-platform builds.

Changes

RedDB source-ref release path

Layer / File(s) Summary
Dispatch and preflight gating
.github/workflows/release-fast.yml, .github/workflows/release.yml, scripts/check-reddb-release-assets.mjs
redb_source_ref / REDDB_SOURCE_REF are added to the release entry points, and the preflight script exits early after resolving the pinned RedDB commit when that ref is present.
Source checkout and cache workspace
.github/workflows/release-fast.yml, .github/workflows/release.yml
The RedDB repository is conditionally checked out into .red/tmp/reddb-source, and the Rust cache workspace list includes that checkout when source builds are enabled.
RedDB sync script portability
scripts/sync-reddb.mjs
The sync script derives the target triple, handles Windows extensions, streams Cargo JSON output through a temp file, and updates artifact copying and version probing for cross-built binaries.
Conditional sidecar provisioning
.github/workflows/release-fast.yml, .github/workflows/release.yml
The workflows branch between pnpm reddb:sync from the checked-out source and the existing download-based RedDB sidecar provisioning path.

Sequence Diagram(s)

sequenceDiagram
  participant Workflow as GitHub Actions workflow
  participant Check as scripts/check-reddb-release-assets.mjs
  participant GitHubAPI as GitHub API
  participant Checkout as RedDB source checkout step
  participant Sync as scripts/sync-reddb.mjs
  participant Cargo as cargo

  Workflow->>Check: run preflight with REDDB_SOURCE_REF
  Check->>GitHubAPI: resolve source commit SHA
  GitHubAPI-->>Check: commit lookup result
  Check-->>Workflow: exit(0) when source build is enabled
  Workflow->>Checkout: checkout reddb-io/reddb at REDDB_SOURCE_REF
  Workflow->>Sync: pnpm reddb:sync
  Sync->>Cargo: cargo build --message-format=json
  Cargo-->>Sync: compiler-artifact JSON
  Sync-->>Workflow: copy red-${triple}${ext} to sidecar path
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

  • reddb-io/red-request#59: Also touches scripts/check-reddb-release-assets.mjs; this PR extends that preflight with source-ref handling.
  • reddb-io/red-request#66: Also updates the release workflow preflight and RedDB asset selection logic; this PR adds the source-build branch.

Poem

(\/)
( •
•) I sniffed a ref and found a spark,
/ >🍃 then hopped from source into the dark.
I twitched my nose at JSON streams,
and built bright binaries from bunny dreams.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: building the RedDB sidecar from a pinned source ref when release assets are unavailable.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/reddb-source-sidecar

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release-fast.yml:
- Around line 60-73: The release workflow adds new third-party action references
by tag, which should be pinned to immutable commit SHAs. Update the actions used
in the Checkout RedDB source step and the Rust cache step to specific commit
hashes instead of version tags, and keep the existing workflow structure and
behavior unchanged.
- Around line 10-13: The release workflow input for reddb_source_ref is allowed
to be a branch or tag, but the checkout step still uses the raw value and can
build a different RedDB revision than the validation step resolved. Update the
workflow so the job only accepts or propagates the resolved full SHA from
check-reddb-release-assets.mjs, and ensure the checkout/build path uses that
resolved commit instead of the original input. Use the reddb_source_ref input
and the check-reddb-release-assets.mjs resolution flow as the key symbols to
locate the affected logic.

In @.github/workflows/release.yml:
- Around line 155-168: The release workflow currently adds new third-party
actions by tag, which should be pinned to immutable commit SHAs. Update the
Checkout RedDB source step using actions/checkout and the cache step using
swatinem/rust-cache so both references are locked to specific commit hashes
rather than version tags, keeping the existing step names and configuration
intact.

In `@scripts/sync-reddb.mjs`:
- Around line 122-128: The version fallback in sync-reddb.mjs is too broad
because sh(dest, ["version"]) failures are being ignored unconditionally. Update
the builtVersion logic to check whether the target triple matches the host
triple before suppressing the error, and only use the red built for ${triple}
fallback for true cross-builds. If the target and host match, rethrow the
version error so native release-matrix builds do not silently package a broken
sidecar. Use the existing triple and dest version flow to locate the change.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a18ee864-ff94-4409-8126-75d150745175

📥 Commits

Reviewing files that changed from the base of the PR and between 6528712 and 6094dd2.

📒 Files selected for processing (4)
  • .github/workflows/release-fast.yml
  • .github/workflows/release.yml
  • scripts/check-reddb-release-assets.mjs
  • scripts/sync-reddb.mjs

Comment on lines +10 to +13
reddb_source_ref:
description: "Optional RedDB source commit/ref to build instead of downloading release assets"
required: false
default: ""

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Require REDDB_SOURCE_REF to be a full SHA.

check-reddb-release-assets.mjs resolves the ref, but Line 65 still checks out the raw input. If someone passes a branch or movable tag, this job can build a different RedDB revision than the one validation reported.

Suggested fix
+      - name: Validate pinned RedDB source ref
+        if: env.REDDB_SOURCE_REF != ''
+        shell: bash
+        run: |
+          [[ "${REDDB_SOURCE_REF}" =~ ^[0-9a-f]{40}$ ]] || {
+            echo "::error::REDDB_SOURCE_REF must be a full 40-character commit SHA"
+            exit 1
+          }
+
       - name: Checkout RedDB source
         if: env.REDDB_SOURCE_REF != ''
         uses: actions/checkout@v7
         with:
           repository: reddb-io/reddb
           ref: ${{ env.REDDB_SOURCE_REF }}

Also applies to: 24-24, 60-67

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-fast.yml around lines 10 - 13, The release
workflow input for reddb_source_ref is allowed to be a branch or tag, but the
checkout step still uses the raw value and can build a different RedDB revision
than the validation step resolved. Update the workflow so the job only accepts
or propagates the resolved full SHA from check-reddb-release-assets.mjs, and
ensure the checkout/build path uses that resolved commit instead of the original
input. Use the reddb_source_ref input and the check-reddb-release-assets.mjs
resolution flow as the key symbols to locate the affected logic.

Comment on lines +60 to +73
- name: Checkout RedDB source
if: env.REDDB_SOURCE_REF != ''
uses: actions/checkout@v7
with:
repository: reddb-io/reddb
ref: ${{ env.REDDB_SOURCE_REF }}
path: .red/tmp/reddb-source
persist-credentials: false

- uses: swatinem/rust-cache@v2
with:
workspaces: "apps/desktop/src-tauri -> target"
workspaces: |
apps/desktop/src-tauri -> target
.red/tmp/reddb-source -> target

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Pin the added workflow actions to commit SHAs.

Line 62 and Line 69 introduce new action references by tag. That violates the blanket policy from zizmor and leaves the release path open to upstream tag retargeting.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 62-62: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 69-69: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-fast.yml around lines 60 - 73, The release
workflow adds new third-party action references by tag, which should be pinned
to immutable commit SHAs. Update the actions used in the Checkout RedDB source
step and the Rust cache step to specific commit hashes instead of version tags,
and keep the existing workflow structure and behavior unchanged.

Source: Linters/SAST tools

Comment on lines +155 to +168
- name: Checkout RedDB source
if: env.REDDB_SOURCE_REF != ''
uses: actions/checkout@v7
with:
repository: reddb-io/reddb
ref: ${{ env.REDDB_SOURCE_REF }}
path: .red/tmp/reddb-source
persist-credentials: false

- uses: swatinem/rust-cache@v2
with:
workspaces: "apps/desktop/src-tauri -> target"
workspaces: |
apps/desktop/src-tauri -> target
.red/tmp/reddb-source -> target

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Pin the added workflow actions to commit SHAs.

Line 157 and Line 164 add new action refs by tag. That violates the blanket policy and weakens the release workflow against upstream tag retargeting.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 157-157: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 164-164: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release.yml around lines 155 - 168, The release workflow
currently adds new third-party actions by tag, which should be pinned to
immutable commit SHAs. Update the Checkout RedDB source step using
actions/checkout and the cache step using swatinem/rust-cache so both references
are locked to specific commit hashes rather than version tags, keeping the
existing step names and configuration intact.

Source: Linters/SAST tools

Comment thread scripts/sync-reddb.mjs
Comment on lines +122 to +128
let builtVersion = `red built for ${triple}`;
try {
builtVersion = sh(dest, ["version"]).trim();
} catch {
// Cross-built binaries may not run on the build host; the release matrix builds native
// targets, so this is only a local-dev fallback.
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Only suppress version failures for actual cross-builds.

The release matrix builds native targets, so swallowing every dest version failure can package a broken sidecar. Compare the target with the host triple and rethrow when they match.

🐛 Proposed fix
+function rustHostTriple() {
+  const hostLine = sh("rustc", ["-vV"])
+    .split("\n")
+    .find((l) => l.startsWith("host:"));
+  return hostLine?.split(/\s+/)[1];
+}
+
 // Target triple Tauri uses to resolve the sidecar (e.g. x86_64-unknown-linux-gnu).
 // CI passes REDDB_TARGET from the release matrix; local dev falls back to the host.
 function targetTriple() {
   if (process.env.REDDB_TARGET) return process.env.REDDB_TARGET;
-  const hostLine = sh("rustc", ["-vV"])
-    .split("\n")
-    .find((l) => l.startsWith("host:"));
-  return hostLine?.split(/\s+/)[1];
+  return rustHostTriple();
 }
 const triple = targetTriple();
+const hostTriple = rustHostTriple();
 let builtVersion = `red built for ${triple}`;
 try {
   builtVersion = sh(dest, ["version"]).trim();
-} catch {
+} catch (err) {
+  if (hostTriple === triple) throw err;
   // Cross-built binaries may not run on the build host; the release matrix builds native
   // targets, so this is only a local-dev fallback.
 }
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
let builtVersion = `red built for ${triple}`;
try {
builtVersion = sh(dest, ["version"]).trim();
} catch {
// Cross-built binaries may not run on the build host; the release matrix builds native
// targets, so this is only a local-dev fallback.
}
let builtVersion = `red built for ${triple}`;
try {
builtVersion = sh(dest, ["version"]).trim();
} catch (err) {
if (hostTriple === triple) throw err;
// Cross-built binaries may not run on the build host; the release matrix builds native
// targets, so this is only a local-dev fallback.
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/sync-reddb.mjs` around lines 122 - 128, The version fallback in
sync-reddb.mjs is too broad because sh(dest, ["version"]) failures are being
ignored unconditionally. Update the builtVersion logic to check whether the
target triple matches the host triple before suppressing the error, and only use
the red built for ${triple} fallback for true cross-builds. If the target and
host match, rethrow the version error so native release-matrix builds do not
silently package a broken sidecar. Use the existing triple and dest version flow
to locate the change.

@filipeforattini
filipeforattini merged commit 3155f59 into main Jun 26, 2026
4 checks passed
@filipeforattini
filipeforattini deleted the agent/reddb-source-sidecar branch June 26, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant