Repository navigation
ci: send compile admission to the owned Mac that kept a build of its merge base #14396
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,84 @@ | ||
| name: CI owned warm labels | ||
| run-name: owned-warm-labels-${{ github.event.workflow_run.id }}-${{ github.event.workflow_run.run_attempt }} | ||
|
|
||
| # A compile admission on an owned Mac keeps its DerivedData, and uploads the | ||
| # main commits that build starts from cheaply (owned-warm-keys-<run>-<attempt>, | ||
| # ci-macos.yml). When the CI run completes, this labels the runner that ran it | ||
| # glaeda-warm-<sha12> for each, and takes those labels off the other runners of | ||
| # its pool, so pr_runner_pool.py can send a later admission merging onto one of | ||
| # them to that Mac (warm affinity). scripts/ci/owned_warm_labels.py has the | ||
| # rules. | ||
| # | ||
| # Changing runner labels needs the org route App with administration: write, | ||
| # so it is triggered by workflow_run and its code comes from main: a pull | ||
| # request cannot change it. It trusts only the keys from the artifact; the | ||
| # runner comes from the jobs API. Off unless CI_OWNED_WARM_LABELS is 1. It only | ||
| # makes API requests, so it runs on a GitHub-hosted runner rather than holding | ||
| # a slot in CI's Linux pool. | ||
| on: | ||
| workflow_run: | ||
| workflows: [CI] | ||
| types: [completed] | ||
|
|
||
| permissions: {} | ||
|
|
||
| env: | ||
| # Renaming the source workflow silently stops every `workflow_run` consumer | ||
| # of it; tests/test_ci_workflow_run_sources.py derives the expected name from | ||
| # this path. The script confirms the run's own `path` again before acting. | ||
| SOURCE_WORKFLOW_PATHS: .github/workflows/ci.yml | ||
|
|
||
| concurrency: | ||
| group: owned-warm-labels-${{ github.event.workflow_run.id }}-${{ github.event.workflow_run.run_attempt }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| label: | ||
| name: Label the owned Mac that kept this run's build | ||
| if: ${{ vars.CI_OWNED_WARM_LABELS == '1' && vars.GLAEDA_ROUTE_APP_ID != '' && github.event.workflow_run.head_repository.full_name == github.repository }} | ||
| runs-on: ubuntu-24.04 # github-hosted-required: only calls the Actions API; keeps CI's Linux pool free | ||
| timeout-minutes: 5 | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| steps: | ||
| # Most runs have no warm keys (no owned Mac, or no warm-keys yet); the | ||
| # download then fails and every step after it is skipped. | ||
| - name: Download the warm keys | ||
| id: keys | ||
| continue-on-error: true | ||
| uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 | ||
| with: | ||
| name: owned-warm-keys-${{ github.event.workflow_run.id }}-${{ github.event.workflow_run.run_attempt }} | ||
| run-id: ${{ github.event.workflow_run.id }} | ||
| github-token: ${{ github.token }} | ||
| path: ${{ runner.temp }}/owned-warm-keys | ||
|
|
||
| - name: Checkout trusted labeler | ||
| if: steps.keys.outcome == 'success' | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| with: | ||
| ref: main | ||
| persist-credentials: false | ||
|
|
||
| - name: Mint the runner labeling token | ||
| id: route-token | ||
| if: steps.keys.outcome == 'success' | ||
| continue-on-error: true | ||
| timeout-minutes: 1 | ||
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | ||
| with: | ||
| app-id: ${{ vars.GLAEDA_ROUTE_APP_ID }} | ||
| private-key: ${{ secrets.GLAEDA_ROUTE_APP_KEY }} | ||
| permission-administration: write | ||
|
|
||
| - name: Label the runner | ||
| if: steps.keys.outcome == 'success' && steps.route-token.outputs.token != '' | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| ROUTE_TOKEN: ${{ steps.route-token.outputs.token }} | ||
| RUN_ID: ${{ github.event.workflow_run.id }} | ||
| RUN_ATTEMPT: ${{ github.event.workflow_run.run_attempt }} | ||
| RUN_PATH: ${{ github.event.workflow_run.path }} | ||
| KEYS_FILE: ${{ runner.temp }}/owned-warm-keys/warm-keys.json | ||
| run: python3 scripts/ci/owned_warm_labels.py |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: manaflow-ai/cmux
Length of output: 8280
The warm-affinity workflow is inoperative at this head.
When an owned admission has a non-empty fingerprint,
.github/workflows/ci-macos.ymlcalls the checked-inscripts/ci/owned_build_state.py. That script has nowarm-keysdispatch branch, so the workflow exits before settingpathand uploads no artifact. Without that artifact,ci-owned-warm-labels.ymlcannot create warm labels. Enablement therefore cannot provide warm affinity for normal owned admissions.Add the producer implementation, or do not advertise or enable warm affinity until that implementation is present.
🤖 Prompt for AI Agents