Repository navigation
feat(xcm): enable bridging on mainnet and fix runtime upgrade migrations - #2698
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests.
🚀 New features to boost your workflow:
|
| run: | | ||
| cargo install --force --locked cargo-deny@0.18.9 | ||
| cargo generate-lockfile | ||
| # Use the committed Cargo.lock. `cargo generate-lockfile` fails because |
There was a problem hiding this comment.
The vulnerable crates job was dying on cargo generate-lockfile, not on cargo deny itself.
That line has been around since when we first added the audit check in #520. Back then the job used cargo audit, and the usual setup was install the tool, generate a lockfile, then run the audit. That made more sense if you might not have a committed lockfile. We do commit Cargo.lock, and the job later moved to cargo deny, but it looks like the regenerate step just stayed.
What happens now is we re resolve the whole dependency graph from scratch, and crates.io will not let you pick a yanked version in that situation. core2 0.4.0 got yanked, and we still pull it in through cid 0.9 from polkadot sdk sc-network. So fresh lockfile generation fails even though our committed Cargo.lock still builds fine under --locked.
Writeup from polkadot-sdk here: paritytech/polkadot-sdk#11769
I took generate-lockfile out of this job for now so deny just checks the lockfile we already commit, which is what we actually build with. Once we bump polkadot sdk to a release that no longer needs yanked core2, we can put the regenerate step back if we still want it.
…s deny ignores for the stuff still pinned by polkadot-sdk.
| { id = "RUSTSEC-2026-0088", reason = "Wasmtime advisory, pending update in polkadot-sdk." }, | ||
| { id = "RUSTSEC-2026-0089", reason = "Wasmtime advisory, pending update in polkadot-sdk." }, | ||
| { id = "RUSTSEC-2026-0091", reason = "Wasmtime advisory, pending update in polkadot-sdk." }, | ||
| { id = "RUSTSEC-2026-0092", reason = "Wasmtime advisory, pending update in polkadot-sdk." }, |
There was a problem hiding this comment.
Polkadot-sdk upgrades are going to matter soon.
|
Codex didn't seem have anything significant to say. |
sbendar
left a comment
There was a problem hiding this comment.
Codex didn't have anything significant to say.
Goal
Adds Session and AuraExt v0 to v1 migrations, folds frequency-bridging into
the mainnet feature the same way testnet already does, and cleans up the
Makefile so mainnet and paseo targets are not misleading. Also drops
generate-lockfile from the deny CI job for now because core2 0.4.0 is
yanked upstream (paritytech/polkadot-sdk#11769).