Skip to content

ci: stop E2E from saving an unresolved Swift package cache - #14632

Merged
teamleaderleo merged 2 commits into
mainfrom
ci-spm-offline-resolve
Sep 25, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
ci-spm-offline-resolve

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

E2E build job 108069926979 (run 36134675453, blacksmith-12vcpu-macos-26) restored an exact spm-03e341ca... hit, then its offline resolve failed after 44 s with "no versions of 'iroh-ffi' match the requirement 1.0.2-cmux.7.ios17.3" and it resolved online for another 86 s.

Cause

test-e2e.yml restored the spm- cache with actions/cache, which also saves on an exact-key miss. canonical-resolve copies the checkout to /private/tmp/cmux-ci/src and resolves there, so the workspace .ci-source-packages that the post step saved was still the fallback restore of the previous Package.resolved. nightly.yml already avoids this by collecting the resolved copy before saving; E2E did not.

After 4a0bd3a moved iroh-ffi to 1.0.2-cmux.7.ios17.3, an E2E run saved the old iroh-ffi clone (no new tag) under the new exact key in the GitHub store. Every later exact hit then tried the offline resolve, which cannot fetch, and fell back.

Frequency

Successful E2E build jobs today on Blacksmith (all read the GitHub store):

Job Key Offline resolve Resolve total
108002501389 (08:36Z) old spm-4c27 ok 112 s
108015710751 (09:36Z) old spm-4c27 ok 116 s
108040802311 (10:57Z) new spm-03e3 failed, 38 s 80 s
108069926979 (12:53Z) new spm-03e3 failed, 44 s 130 s

2 of 2 exact hits since the lockfile change failed offline. Even the "working" GitHub-store entry took about 2 minutes, since it holds no resolved state. Owned minis are unaffected (kept package state, about 10 s).

Fix

  • test-e2e.yml, test-macos-suite.yml and perf-activation.yml restore the spm- cache read-only through ./.github/actions/cache-restore, from the store nightly.yml seeds with the resolved copy (R2 by default), the same way compile admission already does. Each step sets CI_CACHE_R2_PUBLIC_URL, without which r2-cache.sh silently reports a miss.
  • tests/test_ci_pull_request_caches_are_read_only.py now fails any workflow other than nightly.yml that saves an spm- .ci-source-packages cache, or reads one other than through cache-restore with an r2 backend and CI_CACHE_R2_PUBLIC_URL set. It fails on the old workflows with all three findings and passes now.

No layout bump: the R2 seeds are written from the resolved copy and were never affected. Until nightly seeds the new key, E2E takes the prefix fallback and resolves normally, with no failed offline attempt.

Verification

  • python3 tests/test_ci_pull_request_caches_are_read_only.py (fails before on test-e2e, test-macos-suite, perf-activation; passes after)
  • python3 tests/test_ci_manual_macos_package_cache.py, tests/test_seed_derived_data.py, tests/test_ci_change_areas.py, tests/test_ci_reusable_workflow_permissions.py, tests/test_ci_cache_restore_receipt.py
  • actionlint on the three workflows

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

CI workflows no longer save a Swift package cache they only restore. Previously actions/cache saved on an exact-key miss, storing a fallback restore of the previous Package.resolved under the new exact key, so after the iroh-ffi version bump every exact hit failed the offline resolve and fell back to fetching remotes.

  • E2E, the macOS suite, and perf-activation now restore the spm- cache read-only via ./.github/actions/cache-restore, from the resolved copy nightly.yml seeds, with an r2 backend and CI_CACHE_R2_PUBLIC_URL set (a missing public URL silently reports a miss).
  • A new test guard fails any workflow other than nightly.yml that saves an spm- .ci-source-packages cache, or reads one from a store nightly does not seed without an r2 backend and the public URL.

Written for commit 6981afa. Summary will update on new commits.

Review in cubic

test-e2e.yml restored the `spm-` cache with actions/cache, which also saves
on an exact-key miss. canonical-resolve resolves in the canonical root, so
the workspace `.ci-source-packages` it saved was still the fallback restore
of the previous Package.resolved. After 4a0bd3a moved iroh-ffi to
1.0.2-cmux.7.ios17.3, that stale clone sat under the new exact key, so every
exact hit ran an offline resolve that could not find the new tag (38-44 s),
then resolved online (40-86 s).

E2E, the manual macOS suite and perf-activation now restore only, through
cache-restore, from the seed nightly.yml saves after collecting the resolved
copy. The read-only guard now fails any workflow other than nightly.yml that
saves an `spm-` `.ci-source-packages` cache or reads it from a store nightly
does not seed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

r2-cache.sh treats an unset CI_CACHE_R2_PUBLIC_URL as a miss, and none of
the three switched workflows set it where the restore runs. The guard now
also requires an r2 backend and the URL at step, job or workflow level for
every `spm-` `.ci-source-packages` reader.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cursor

cursor Bot commented Sep 25, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo
teamleaderleo merged commit be46dba into main Sep 25, 2026
18 of 20 checks passed
@teamleaderleo
teamleaderleo deleted the ci-spm-offline-resolve branch September 25, 2026 13:15
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 6981afa7a6, merged 2026-09-25 13:15:52 UTC

  • Not verified at merge: ci-status (not reported), Web complexity (in progress)
  • Verified: web-validation, Fast static checks, receipt-contract, Testbox broker trust boundary
  • Skipped by policy: web-build, web-database-tests, web-tests
  • Full suite: runs on main after merge.

Labeled merged-unverified: if main breaks near this merge, look here first.

@github-actions github-actions Bot added the merged-unverified A judging check was not green at merge; see the merge receipt comment label Sep 25, 2026
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
60d8ac1 Land ejc3's isolated defaults test from manaflow-ai#12598 (manaflow-ai#14504)
e926f24 fix: resolve the terminal Copy guard through the Command-aware keyboard layout (manaflow-ai#10872) (manaflow-ai#13015)
0df2946 Fix startup-race crash in v2RefreshKnownRefs against a half-restored session (manaflow-ai#2751) (manaflow-ai#9627)
611eeac ci(e2e): queue E2E runs for the owned pool within CI_PR_POOL_QUEUE_ROUNDS (manaflow-ai#14640)
27b8cbc ci: seed the Swift package cache from main pushes (manaflow-ai#14638)
be46dba ci: stop E2E from saving an unresolved Swift package cache (manaflow-ai#14632)
2486e99 ci: run-e2e.sh --wait asks glaeda-gh instead of polling GitHub (manaflow-ai#14622)
088034b ci(ios): queue test-ios runs for the owned pool within CI_PR_POOL_QUEUE_ROUNDS (manaflow-ai#14630)

# Conflicts:
#	.github/workflows/main-regression-bisect.yml
#	.github/workflows/perf-activation.yml
#	.github/workflows/seed-derived-data.yml
#	.github/workflows/test-e2e.yml
#	.github/workflows/test-ios.yml
#	.github/workflows/test-macos-suite.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merged-unverified A judging check was not green at merge; see the merge receipt comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant