Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/ci-guards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,10 @@ jobs:
if: ${{ matrix.group == 'ci' }}
run: python3 tests/test_ci_canonical_build_root.py

- name: Validate seeded macOS checkout
if: ${{ matrix.group == 'ci' }}
run: python3 tests/test_ci_git_seed.py

- name: Run canonical CMUX CI guard profile
if: ${{ matrix.group == 'ci' }}
run: |
Expand Down
102 changes: 102 additions & 0 deletions .github/workflows/ci-macos.yml
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,21 @@ jobs:
echo "CMUX_HOSTED_SOURCE_PREP_STARTED=$now"
} >> "$GITHUB_ENV"

# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- name: Clear stale git locks (self-hosted reused workspace)
shell: bash
run: |
Expand All @@ -213,6 +228,12 @@ jobs:
submodules: recursive
persist-credentials: false

# A seeded repository that checkout cannot use (a submodule moved to
# another URL) must not fail the retry the same way.
- name: Discard the git object seed after a failed checkout
if: steps.checkout.outcome == 'failure'
run: rm -rf "$GITHUB_WORKSPACE/.git"

# WarpBuild can lose GitHub DNS on an otherwise healthy runner. Retry the
# checkout once only after that action fails; healthy jobs still perform
# one checkout, and a second failure remains a hard failure with evidence.
Expand Down Expand Up @@ -1171,6 +1192,21 @@ jobs:
;;
esac

# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- name: Clear stale git locks (self-hosted reused workspace)
shell: bash
run: |
Expand All @@ -1190,6 +1226,12 @@ jobs:
with:
persist-credentials: false

# A seeded repository that checkout cannot use (a submodule moved to
# another URL) must not fail the retry the same way.
- name: Discard the git object seed after a failed checkout
if: steps.checkout.outcome == 'failure'
run: rm -rf "$GITHUB_WORKSPACE/.git"

# WarpBuild can lose GitHub DNS on an otherwise healthy runner. Retry the
# checkout once only after that action fails; healthy jobs still perform
# one checkout, and a second failure remains a hard failure with evidence.
Expand Down Expand Up @@ -2079,6 +2121,21 @@ jobs:
;;
esac

# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- name: Clear stale git locks (self-hosted reused workspace)
shell: bash
run: |
Expand Down Expand Up @@ -2310,6 +2367,21 @@ jobs:
CMUX_CI_HELPER_XCODE_APP: ${{ vars.CMUX_CI_HELPER_XCODE_APP_MACOS_15 }}
CMUX_CI_REQUIRED_MACOS_SDK_MAJOR: "26"
steps:
# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- name: Clear stale git locks (self-hosted reused workspace)
shell: bash
run: |
Expand All @@ -2323,13 +2395,28 @@ jobs:
fi

- name: Checkout
id: checkout
continue-on-error: true
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
# Depth 2 reaches the parent this commit was built on, which is what
# "Select package tests" diffs against.
fetch-depth: 2

# A seeded repository that checkout cannot use (a submodule moved to
# another URL) must not fail the retry the same way.
- name: Discard the git object seed after a failed checkout
if: steps.checkout.outcome == 'failure'
run: rm -rf "$GITHUB_WORKSPACE/.git"

- name: Retry checkout without the git object seed
if: steps.checkout.outcome == 'failure'
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
fetch-depth: 2

- name: Select package tests
id: select
env:
Expand Down Expand Up @@ -2808,6 +2895,21 @@ jobs:
;;
esac

# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- name: Clear stale git locks (self-hosted reused workspace)
shell: bash
run: |
Expand Down
19 changes: 17 additions & 2 deletions .github/workflows/cli-pipe-regressions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,20 +34,35 @@ jobs:
# restore needs this set here.
CI_CACHE_R2_PUBLIC_URL: ${{ vars.CI_CACHE_R2_PUBLIC_URL || 'https://ci-cache.cmux.com' }}
steps:
# Start from main's git objects, so checkout fetches only what changed
# since then instead of the whole tree and its submodules
# (scripts/ci/git-seed.sh). The script is read at this commit over HTTPS
# because nothing is checked out yet. A miss leaves the workspace empty
# and checkout clones as before.
- name: Restore git object seed
continue-on-error: true
timeout-minutes: 3
run: |
set -euo pipefail
script="$RUNNER_TEMP/git-seed.sh"
curl --fail --silent --show-error --location --connect-timeout 10 --max-time 30 \
-o "$script" "https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/scripts/ci/git-seed.sh"
bash "$script" restore "$GITHUB_WORKSPACE"

- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Initialize local Swift package dependency
run: git submodule update --init --depth 1 vendor/bonsplit
run: scripts/ci/git-seed.sh update-submodules "$GITHUB_WORKSPACE" vendor/bonsplit

- name: Select Xcode
run: ./scripts/select-ci-xcode.sh

- name: Initialize Ghostty and download its binary framework
run: |
set -euo pipefail
git submodule update --init --depth 1 ghostty
scripts/ci/git-seed.sh update-submodules "$GITHUB_WORKSPACE" ghostty
./scripts/download-prebuilt-ghosttykit.sh

- name: Install Rust toolchain
Expand Down
16 changes: 16 additions & 0 deletions .github/workflows/seed-derived-data.yml
Original file line number Diff line number Diff line change
Expand Up @@ -336,6 +336,22 @@ jobs:
retention-days: 3
compression-level: 0

# macOS jobs start their checkout from these objects, so a pull request
# fetches only what changed since this main commit instead of the whole
# tree and its submodules (scripts/ci/git-seed.sh). A failure costs them
# the head start, never this seed.
- name: Save git object seed
id: git-seed
if: github.ref == 'refs/heads/main'
continue-on-error: true
timeout-minutes: 5
env:
AWS_ACCESS_KEY_ID: ${{ secrets.CI_CACHE_R2_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.CI_CACHE_R2_SECRET_ACCESS_KEY }}
CI_CACHE_R2_ENDPOINT: ${{ format('https://{0}.r2.cloudflarestorage.com', secrets.CI_CACHE_R2_ACCOUNT_ID) }}
CI_CACHE_R2_BUCKET: ${{ vars.CI_CACHE_R2_BUCKET }}
run: scripts/ci/git-seed.sh save "$GITHUB_WORKSPACE"

- name: Summarize
if: always()
env:
Expand Down
2 changes: 2 additions & 0 deletions scripts/ci/detect_ci_change_areas.py
Original file line number Diff line number Diff line change
Expand Up @@ -630,6 +630,8 @@ def is_guard_only_test(path: str, references: Optional[tuple[frozenset[str], fro
# What restore-app-host-test-product.sh itself runs.
"scripts/ci/app_host_test_products.py",
"scripts/ci/canonical-build-root.sh",
# Seeds the checkout of both CLI lanes and initializes cli-pipe's submodules.
"scripts/ci/git-seed.sh",
})

CLI_LANE_INPUT_PREFIXES = (
Expand Down
Loading
Loading