Repository navigation
Route Linux guard tests by owning group - #13585
Conversation
|
Warning Review limit reachedNext included review available in 39 seconds. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (9)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Post-merge integration regression to repair on current main: #13535 added the
Please land a small follow-up that assigns |
The Linux guard router kept a hand-written copy of every workflow-guard-tests step (STEP_OWNERS) and every path those steps run (PATH_OWNERS), and a test required the copy to equal the workflow. Two PRs that each passed alone could land a copy that disagreed with the workflow: #13535 added "Validate build graph health tooling" while #13585 introduced the copy, and every PR failed guards until #13609. Ownership now comes from the workflow. Each step's `if: ${{ matrix.group == '<group>' }}` names its group and each path its `run:` executes belongs to that group. The router reads ci-guards.yml with a small line scanner, because the changes job runs on bare python3 without PyYAML; a test holds the scanner to yaml.safe_load field by field. An unreadable workflow fails open to every group. STEP_OWNERS is gone, and PATH_OWNERS keeps only the 24 indirect inputs (imported scripts, the agent-chat working directory, the ghostty submodule, skill files). Routing is unchanged for every path the old tables knew. A step with an unknown group fails its own PR with the exact file to edit. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Summary
workflow-guard-testsstep and its directly executed inputslinux_guard_test_groupsroute and expand only those matrix groupslinux_guard_tests/Guard statusrequired-check contractOwnership / drift protection
scripts/ci/workflow_guard_groups.pyis the declarative source for:tests/test_ci_linux_guard_routing.pycompares that manifest back toci-guards.yml, so moving a step between groups or adding a direct guard executable requires an ownership update in the same change.Routing-policy files are also guarded in the caller before the PR-controlled detector runs; edits to the router, ownership manifest, reusable guard workflow, or routing contract tests emit the full group list.
Measurement: PR #13559
Measured from CI run 35683657111 (commit
39f90135), whose changed files are:.github/workflows/ios-testflight.ymlios/scripts/upload-testflight.shtests/test_ios_appstore_lane_identity.pyCurrent routing allocated all 11
workflow-guard-testsjobs. Their log spans sum to 315.021s = 5.25 runner-minutes.The new ownership route selects:
preflight(workflow policy + Python syntax)ci(repository reusable-workflow permission scan)release-ios(TestFlight/App Store guards)quality-determinism(test tree determinism scan)Using the same run's per-group durations, that is 110.555s = 1.84 runner-minutes, saving 204.466s = 3.41 runner-minutes (64.9%) and 7 of 11 allocations (63.6%).
The guard-test wall span in that run was about 37.39s. The selected four span about 37.18s on the same timestamps because
quality-determinismremains the critical parallel leg. This optimization removes unrelated runner work instead of shortening unrelated jobs.Whole-run allocation
Across all successful allocated jobs in CI run 35683657111, log spans sum to about 600.375s = 10.01 runner-minutes across 22 jobs. Removing the seven unrelated guard-test legs yields a same-run counterfactual of 395.909s = 6.60 runner-minutes across 15 jobs: the same 3.41 runner-minute saving, or about 34.1% of total allocated runner time for this case.
The workflow itself ran from 03:34:28Z to 03:36:25Z (117s wall clock). The removed guard-test legs were off the overall critical path, so the modeled wall clock remains about 117s; the gain is runner capacity and cost, not a synthetic critical-path speedup.
Required-check behavior
The reusable
workflow-guard-testsjob still runs whenlinux_guard_tests == 'true', andGuard statusstill requires its aggregate result to be successful. Only the matrix vector changes.This PR itself changes routing policy, so its own route intentionally fails open to all 11 groups; the narrow #13559 case is covered as a routing regression test.
Summary by cubic
Routes Linux
workflow-guard-testsjobs to expand only the matrix groups that own the changed files instead of always running the full 11-group matrix, cutting CI time without changing thelinux_guard_tests/Guard statusrequired-check contract.Routing and ownership
workflow_guard_groups.pydeclaratively maps every guard-test step and its directly executed inputs to an owning group.linux_guard_test_groupsinput rather than a hard-coded group list.Drift protection
ci-guards.yml, so moving a step between groups or adding a direct guard executable requires an ownership update in the same change.preflight,ci,release-ios, andquality-determinism; that case saves 3.41 runner-minutes (64.9%) and 7 of 11 allocations.Written for commit 6b96108. Summary will update on new commits.