From c51c877fa354ef86cc49bd39ecad74659c4e5272 Mon Sep 17 00:00:00 2001 From: John Vandenberg Date: Mon, 13 Jul 2026 09:24:22 +0800 Subject: [PATCH] Use cargo:open --- .github/actions/install-mise-tools/action.yaml | 7 +++++++ .mise/config.toml | 1 + CLAUDE.md | 15 +++++++++++++++ Dockerfile.nanoserver | 5 +++-- Dockerfile.windows | 3 ++- config/conftest/policy/mise/mise.rego | 8 +++++++- .../mise-cargo-backend-allowlist.schema.json | 1 + utilities/cli/src/deployment_types/mise.rs | 4 ++++ .../output/facility-security-scenario/mise.toml | 3 +++ 9 files changed, 43 insertions(+), 4 deletions(-) diff --git a/.github/actions/install-mise-tools/action.yaml b/.github/actions/install-mise-tools/action.yaml index f18d88a2..81ad4ae2 100644 --- a/.github/actions/install-mise-tools/action.yaml +++ b/.github/actions/install-mise-tools/action.yaml @@ -26,6 +26,13 @@ inputs: runs: using: composite steps: + # No cargo: tool installs on the Windows lane right now -- cargo-binstall fails to execute there (os error 193). + # open-o2's opener isn't needed in CI, so skip cargo:open rather than let the install fail. + - name: Skip cargo:open on Windows + if: runner.os == 'Windows' + shell: bash --noprofile --norc -euo pipefail {0} + run: echo "MISE_DISABLE_TOOLS=cargo:open" >> "$GITHUB_ENV" + - name: Install mise binary uses: ./.github/actions/install-mise with: diff --git a/.mise/config.toml b/.mise/config.toml index b41ba60d..e7a534d7 100644 --- a/.mise/config.toml +++ b/.mise/config.toml @@ -63,6 +63,7 @@ action-validator = { version = "latest", os = ["linux", "macos"] } ast-grep = "latest" cargo-binstall = "latest" "cargo:cargo-expand" = { version = "latest", os = ["linux", "macos"] } +"cargo:open" = "latest" "cargo:wasm-opt" = { version = "latest", os = ["linux", "macos"] } "github:nextest-rs/nextest" = "latest" taplo = "latest" diff --git a/CLAUDE.md b/CLAUDE.md index efa38702..7ea517cc 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -614,6 +614,21 @@ If no msvc prebuilt exists either, use a different backend (aqua/github/http, or pattern), or os-scope the tool off Windows and provide coverage another way (as `dart-typegen` does via `http:dart-typegen`). +As of mise 2026.7.1 the `cargo:` backend is broken on the Windows lane in a further way: `cargo-binstall` itself +fails to execute, so the source-build fallbacks above never even get a chance. `cargo:open` (a low-dep pure-Rust +opener with no prebuilt anywhere) surfaced it: + + mise ERROR Failed to install cargo:open@latest: failed to execute command: \shims\cargo-binstall + -y open@5.3.6 --locked --root \installs\cargo-open\5.3.6: %1 is not a valid Win32 application. (os error 193) + +os error 193 is ERROR_BAD_EXE_FORMAT -- the staged cargo-binstall is not a runnable Win32 image (a mise +install-path / shim fault, not an `open`-specific one), so right now no `cargo:` tool installs on Windows at all. +Until mise fixes it, keep new `cargo:` tools off the Windows lane -- os-scope them to `["linux", "macos"]` where +Windows never needs them, or add the tool to `MISE_DISABLE_TOOLS` on every Windows surface that runs `mise install`. +The `install-mise-tools` composite action sets it for the CI jobs, and the Windows Dockerfiles carry it in their own +`MISE_DISABLE_TOOLS`. `cargo:open` takes the latter route: its open-o2 opener is a known Windows gap until the +backend works again. + ## Adding a new `upstream-cache` entry When upstream has no prebuilt binary for a platform we target (the case the "Tools must work on every OS" rule diff --git a/Dockerfile.nanoserver b/Dockerfile.nanoserver index 0d3de215..d8066d8e 100644 --- a/Dockerfile.nanoserver +++ b/Dockerfile.nanoserver @@ -328,12 +328,13 @@ RUN (if exist C:\token\gh_token set /p GITHUB_TOKEN= Re let _previous: Option = root.insert("tasks".to_string(), Value::Table(tasks)); + let mut tools = Table::new(); + let _previous: Option = tools.insert("cargo:open".to_string(), Value::String("latest".to_string())); + let _previous: Option = root.insert("tools".to_string(), Value::Table(tools)); + let content = toml::to_string(&Value::Table(root))?; fs::write(&output_path, content)?; diff --git a/verification/local/output/facility-security-scenario/mise.toml b/verification/local/output/facility-security-scenario/mise.toml index fdd728a1..6fe2ea06 100644 --- a/verification/local/output/facility-security-scenario/mise.toml +++ b/verification/local/output/facility-security-scenario/mise.toml @@ -26,3 +26,6 @@ cargo run [tasks.ws-server.env] OTLP_AUTH_PASSWORD = "1234" OTLP_AUTH_USERNAME = "root@example.com" + +[tools] +"cargo:open" = "latest"