Skip to content

ci: seed the Swift package cache from main pushes - #14638

Merged
teamleaderleo merged 2 commits into
mainfrom
ci-spm-seed-on-main
Sep 25, 2026
Merged

teamleaderleo merged 2 commits into
mainfrom
ci-spm-seed-on-main

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Follow-up to #14632. Only nightly.yml saves the spm- package seed, and only on an exact-key miss. After a Package.resolved change, every reader takes the prefix fallback and resolves online until the next nightly, which can be up to a day away.

Change

seed-derived-data.yml runs on every main push. It already restores spm-<hash> from R2 and runs canonical-resolve. On an exact-key miss, and only on main, two steps now run directly after "Resolve Swift packages":

  • Collect resolved Swift packages: rsync ${CMUX_CI_CANONICAL_ROOT:-/private/tmp/cmux-ci}/src/.ci-source-packages back into .ci-source-packages (as nightly.yml does), then sanitize it.
  • Save Swift packages: cache-save to the same store and key as nightly.yml.

Both are continue-on-error, and they sit right after resolve, so a concurrency cancel of the long build cannot lose them. R2 saves are write-once per key (If-None-Match: * in r2-cache.sh), so matrix legs that race here are harmless. The first leg to finish resolving wins.

tests/test_ci_pull_request_caches_are_read_only.py allows only this writer. It asserts that the writer:

  • runs on the main ref only
  • saves only on an exact-key miss
  • copies the canonical resolved packages and sanitizes them
  • uses the same store, key and path as nightly.yml
  • runs only after a successful collect
  • does not fail the seed
  • sits directly after resolve

Verification

  • python3 tests/test_ci_pull_request_caches_are_read_only.py passes. Mutations fail it: dropping the main-ref condition, and replacing the rsync.
  • tests/test_seed_derived_data.py, tests/test_ci_workflow_guards_are_wired.py, tests/test_ci_swiftpm_manifest_cache.sh
  • actionlint on seed-derived-data.yml

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Seeds the Swift package cache from main pushes so a Package.resolved change gets a fresh seed immediately instead of waiting up to a day for the nightly job.

  • On an exact-key miss, seed-derived-data.yml now copies the resolved packages from the canonical root back into the workspace, sanitizes them, and saves them under the same spm- key and store nightly.yml uses.
  • The new collect and save steps sit directly after resolve and are continue-on-error, so they run before a cancel can cut them off and never fail the seed.
  • The read-only guard now permits this one writer and asserts its conditions: main ref only, exact-key miss only, canonical resolved source, matching store and key, and placement right after resolve.

Written for commit 674e19a. Summary will update on new commits.

Review in cubic

seed-derived-data.yml already restores the `spm-` cache from R2 and runs
canonical-resolve on every main push. On an exact-key miss it now copies the
resolved packages from the canonical root back into the workspace, sanitizes
them and saves them to R2 under the exact key, right after resolve and
without failing the seed. A Package.resolved change gets a correct package
seed from the next main push instead of the next nightly.

The read-only guard allows this one writer and pins its conditions: main
ref, exact-key miss, the canonical resolved copy as the source, the same
store and key as nightly.yml, and placement directly after resolve.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 289e81cc-fc17-487a-83fa-4743d2f7f526

📥 Commits

Reviewing files that changed from the base of the PR and between be46dba and 03aaac3.

📒 Files selected for processing (2)
  • .github/workflows/seed-derived-data.yml
  • tests/test_ci_pull_request_caches_are_read_only.py
 ______________________________________________
< Looking for trouble in all the right places. >
 ----------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@teamleaderleo
teamleaderleo merged commit 27b8cbc into main Sep 25, 2026
10 of 13 checks passed
@teamleaderleo
teamleaderleo deleted the ci-spm-seed-on-main branch September 25, 2026 13:22
@github-actions

Copy link
Copy Markdown
Contributor

Merge receipt for 674e19ad0b, merged 2026-09-25 13:22:04 UTC

  • Not verified at merge: ci-status (not reported), Web complexity (in progress), web-validation (in progress), receipt-contract (in progress), Testbox broker trust boundary (in progress)
  • Skipped by policy: web-build, web-database-tests, web-tests
  • Full suite: runs on main after merge.

Labeled merged-unverified: if main breaks near this merge, look here first.

@github-actions github-actions Bot added the merged-unverified A judging check was not green at merge; see the merge receipt comment label Sep 25, 2026
rustybret pushed a commit to rustybret/bmux that referenced this pull request Sep 25, 2026
60d8ac1 Land ejc3's isolated defaults test from manaflow-ai#12598 (manaflow-ai#14504)
e926f24 fix: resolve the terminal Copy guard through the Command-aware keyboard layout (manaflow-ai#10872) (manaflow-ai#13015)
0df2946 Fix startup-race crash in v2RefreshKnownRefs against a half-restored session (manaflow-ai#2751) (manaflow-ai#9627)
611eeac ci(e2e): queue E2E runs for the owned pool within CI_PR_POOL_QUEUE_ROUNDS (manaflow-ai#14640)
27b8cbc ci: seed the Swift package cache from main pushes (manaflow-ai#14638)
be46dba ci: stop E2E from saving an unresolved Swift package cache (manaflow-ai#14632)
2486e99 ci: run-e2e.sh --wait asks glaeda-gh instead of polling GitHub (manaflow-ai#14622)
088034b ci(ios): queue test-ios runs for the owned pool within CI_PR_POOL_QUEUE_ROUNDS (manaflow-ai#14630)

# Conflicts:
#	.github/workflows/main-regression-bisect.yml
#	.github/workflows/perf-activation.yml
#	.github/workflows/seed-derived-data.yml
#	.github/workflows/test-e2e.yml
#	.github/workflows/test-ios.yml
#	.github/workflows/test-macos-suite.yml
teamleaderleo added a commit that referenced this pull request Sep 25, 2026
#14638 taught the read-only guard to inspect seed-derived-data.yml, but
test_ci_cache_restore_receipt.py runs that guard in a fixture that copied only
ci.yml, ci-macos.yml and nightly.yml, so receipt-contract failed on main with
FileNotFoundError for seed-derived-data.yml. The fixture now copies the whole
.github tree the guard globs, and the contract also runs when
seed-derived-data.yml changes.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merged-unverified A judging check was not green at merge; see the merge receipt comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant