Skip to content

feat(xcm): enable bridging on mainnet and fix runtime upgrade migrations - #2698

Merged
enddynayn merged 7 commits into
mainfrom
feat/xcm-coretime
Jul 21, 2026
Merged

enddynayn merged 7 commits into
mainfrom
feat/xcm-coretime

Conversation

@enddynayn

@enddynayn enddynayn commented Jul 21, 2026 •

Copy link
Copy Markdown
Collaborator

Goal

Adds Session and AuraExt v0 to v1 migrations, folds frequency-bridging into
the mainnet feature the same way testnet already does, and cleans up the
Makefile so mainnet and paseo targets are not misleading. Also drops
generate-lockfile from the deny CI job for now because core2 0.4.0 is
yanked upstream (paritytech/polkadot-sdk#11769).

@codecov

codecov Bot commented Jul 21, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Files with missing lines Coverage Δ
pallets/msa/src/offchain_storage.rs 83.83% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions github-actions Bot added the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@github-actions github-actions Bot removed the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
run: |
cargo install --force --locked cargo-deny@0.18.9
cargo generate-lockfile
# Use the committed Cargo.lock. `cargo generate-lockfile` fails because

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The vulnerable crates job was dying on cargo generate-lockfile, not on cargo deny itself.

That line has been around since when we first added the audit check in #520. Back then the job used cargo audit, and the usual setup was install the tool, generate a lockfile, then run the audit. That made more sense if you might not have a committed lockfile. We do commit Cargo.lock, and the job later moved to cargo deny, but it looks like the regenerate step just stayed.

What happens now is we re resolve the whole dependency graph from scratch, and crates.io will not let you pick a yanked version in that situation. core2 0.4.0 got yanked, and we still pull it in through cid 0.9 from polkadot sdk sc-network. So fresh lockfile generation fails even though our committed Cargo.lock still builds fine under --locked.

Writeup from polkadot-sdk here: paritytech/polkadot-sdk#11769

I took generate-lockfile out of this job for now so deny just checks the lockfile we already commit, which is what we actually build with. Once we bump polkadot sdk to a release that no longer needs yanked core2, we can put the regenerate step back if we still want it.

@enddynayn enddynayn changed the title Feat/xcm coretime feat(xcm): enable bridging on mainnet and fix runtime upgrade migrations Jul 21, 2026
@github-actions github-actions Bot added the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
…s deny ignores for the stuff still pinned by polkadot-sdk.
@github-actions github-actions Bot removed the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@github-actions github-actions Bot added the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@github-actions github-actions Bot removed the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@enddynayn
enddynayn requested a review from harry-evans July 21, 2026 21:07
@github-actions github-actions Bot added the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@enddynayn
enddynayn marked this pull request as ready for review July 21, 2026 21:24
Comment thread deny.toml
{ id = "RUSTSEC-2026-0088", reason = "Wasmtime advisory, pending update in polkadot-sdk." },
{ id = "RUSTSEC-2026-0089", reason = "Wasmtime advisory, pending update in polkadot-sdk." },
{ id = "RUSTSEC-2026-0091", reason = "Wasmtime advisory, pending update in polkadot-sdk." },
{ id = "RUSTSEC-2026-0092", reason = "Wasmtime advisory, pending update in polkadot-sdk." },

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Polkadot-sdk upgrades are going to matter soon.

@harry-evans harry-evans left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sbendar
sbendar self-requested a review July 21, 2026 22:25
@sbendar

sbendar commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

Codex didn't seem have anything significant to say.

@sbendar sbendar closed this Jul 21, 2026
@sbendar sbendar reopened this Jul 21, 2026
@github-actions github-actions Bot removed the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026

@sbendar sbendar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex didn't have anything significant to say.

@github-actions github-actions Bot added the metadata-changed Metadata has changed since the latest full release label Jul 21, 2026
@enddynayn
enddynayn merged commit e46351d into main Jul 21, 2026
65 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

metadata-changed Metadata has changed since the latest full release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants