Skip to content

Cut CI to a lean per-package-manager gate (+ #1353 Gradle Windows cells) - #1375

Merged
Mikola Lysenko (mikolalysenko) merged 9 commits into
mainfrom
ci/lean-scope
Oct 9, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 9 commits into
mainfrom
ci/lean-scope

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #1362 (Depot runners). Until #1362 merges, this diff includes its commits.

The org is short on Actions runners. Every socket-patch PR, merge group and main push ran about 195 jobs, about 40 of them on GitHub-hosted Windows/macOS. With this change, unless the repository variable CI_SCOPE is full, those events run a lean gate of about 28 Linux jobs. After #1362 those all run on Depot, which uses no GitHub-hosted runners.

Lean gate (PR, merge queue, push to main)

  • clippy, node-addon, lint-ecosystems, release-readiness, dispatch-tests, coverage (the Linux workspace tests) and e2e-build.
  • e2e: one targeted row per package manager, 17 rows instead of 104.
    • JS: npm, pnpm (redirect), bun 1.4.2, vlt 1.2.0.
    • Python: uv 0.12.17 (redirect and vendor), poetry 2.4.3, pdm 2.29.2, hatch 1.18.1, pipenv 2026.8.0, pip.
    • Others: composer 2, gem (ruby 3.4 / bundler 4.0.21), maven 3.9.16, gradle 9.8.0 (agent and hosted subset), nuget (dotnet 10), deno 2.9.7.
  • One current row each for yarn classic (1.22.22), yarn berry (4.18.0) and the cargo VEX matrix (lockfile v4).

Runs only with CI_SCOPE=full, nightly, or on workflow_dispatch

  • e2e-extended, the other 87 e2e rows: older tool versions, sbt, rush, bun lockb, the extra vlt eras and Gradle lines. It shares e2e's env and steps through YAML anchors.
  • The Windows/macOS legs (test, e2e-*-windows/macos, cargo-vex-matrix-*, yarn-berry-e2e-macos).
  • test-release, docker-base / coverage-docker / coverage-merge, cargo-old-toolchains.
  • The live-production hosted-e2e, which stalled the queue for 2.5 h today (Merge queue blocked: production no longer publishes free minimist@1.2.2 patch #1293).

ci-ok treats skipped jobs as passing, and the required checks (ci-ok, clippy) are unchanged. To restore the old gate, set CI_SCOPE=full; no commit is needed.

Also paused, in repo settings rather than this diff

  • The 11 *-compatibility.yml workflows, bench, the bughunt/ledger workflows, installer-drift and vlt-serve-watchdog are disabled.
  • The merge queue builds 1 group at a time.
  • These come back incrementally once CI is stable.

Verification

  • python3 -m unittest discover -s scripts/tests: 307 OK (1 skip). The row-reading helpers now include e2e-extended and the CI_SCOPE-switched fromJSON matrices, so the per-row coverage assertions still cover every row.
  • PyYAML parses the file. actionlint reports no new error kinds; the 13 extra findings are the existing optional-matrix-field warnings, now also reported for the new job.

🤖 Generated with Claude Code


Note

Medium Risk
PR/merge-queue coverage is materially narrower until nightly or CI_SCOPE=full, so regressions on older toolchains, Windows/macOS, docker coverage, or production hosted-e2e may not block merges.

Overview
Introduces a temporary lean CI gate for pull_request, merge_group, and push when the repo variable CI_SCOPE is not full. Nightly schedule and workflow_dispatch still run the full suite; setting CI_SCOPE=full restores the old gate without a code change. ci-ok continues to treat skipped jobs as success.

On lean runs, many expensive jobs are skipped entirely: Windows/macOS test, test-release, docker coverage (docker-base / coverage-docker / coverage-merge), cross-platform e2e builds and legs, hosted-e2e, cargo-old-toolchains, and trimmed yarn/cargo matrices (e.g. yarn classic 1.22.22 only, berry 4.18.0 on Linux, cargo VEX lock v4 only).

The e2e matrix is cut from ~104 rows to ~17—one current/boundary row per ecosystem (npm, pnpm, bun 1.4.2, vlt 1.2.0, uv/poetry/pdm/hatch/pipenv/pip, composer 2, gem, maven, gradle 9.8.0 subset, nuget, deno, etc.). Older tool versions, extra Gradle/sbt lines, rush, bun lockb, and the rest move to a new e2e-extended job (same *e2e-steps as e2e) that only runs under full scope / nightly / dispatch.

gradle-compatibility.yml drops Windows hosted cells for Gradle 7.6.6 and 8.14.3 on PRs (keeps 6.9.4 and 9.8.0); middle lines still run nightly and ubuntu PR coverage via e2e.

Unit tests in scripts/tests were updated for the new if: expressions, e2e-extended in row readers, and fromJSON CI_SCOPE matrix literals.

Reviewed by Cursor Bugbot for commit 1fcb4c8. Configure here.

Claude (claude) and others added 6 commits October 9, 2026 17:30
Each matching PR ran the 43-test hosted Gradle suite on Windows four
times, once per Gradle line, at 28-42 min a cell: about 70% of the
workflow's Windows minutes and its wall clock. Keep the oldest (6.9.4)
and newest (9.8.0) lines on PRs and leave 7.6.6 and 8.14.3 hosted on
Windows to the nightly and manual runs. ci.yml's e2e still runs hosted
on all four lines on ubuntu on every PR and in the merge queue.

Fixes #1300.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VrgiQoDwt3vjxG2zNfZBAA
hosted-e2e (and the other live minimist suites) fail on every head:
production now serves minimist@1.2.2 patch 642d7f02 while the tests
pin 80630680 (#1293). This is #1301's change, applied verbatim; it
becomes a no-op once #1301 lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VrgiQoDwt3vjxG2zNfZBAA
Merge-queue jobs wait for runners in the org's shared GitHub-hosted Linux
pool, behind every PR run: in one merge_group run `clippy` waited 7.7 min
to start while its Windows and macOS jobs started at once. Depot's runners
don't count against that pool.

Every Linux `runs-on` in ci.yml and the compatibility workflows now maps
to depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4 (4 vCPU, the size of
GitHub's public-repo ubuntu-latest). Matrix values are unchanged, so job
names, cache keys and scripts are unchanged too. Setting the repository
variable DISABLE_DEPOT_RUNNERS=true falls back to GitHub-hosted runners,
the same switch depscan uses.

Release, publish, bench and the merge-queue helper workflows stay
GitHub-hosted: npm provenance needs GitHub-hosted runners, bench timings
should keep their baseline, and the helpers hold write tokens.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	.github/workflows/vlt-compatibility.yml
The org is short on Actions runners, and every socket-patch PR, merge
group and main push ran ~195 jobs, ~40 of them on GitHub-hosted
Windows/macOS. Unless the repository variable CI_SCOPE is `full`, those
events now run a lean gate of ~28 Linux jobs:

- e2e keeps one targeted row per package manager (17 rows: npm, pnpm,
  bun, vlt, uv x2, poetry, pdm, hatch, pipenv, pip, composer, gem,
  maven, gradle 9.8.0, nuget, deno). The other 87 rows (older tool
  versions, sbt, rush, bun lockb, extra vlt eras and Gradle lines)
  move to e2e-extended, which shares e2e's env and steps.
- yarn classic, yarn berry and the cargo VEX matrix run one current
  row each.
- The Windows/macOS legs, test, test-release, the sbt Docker coverage
  slice, old cargo toolchains and the live-production hosted-e2e are
  skipped.

Everything still runs nightly and on workflow_dispatch, and setting
CI_SCOPE=full restores the previous gate without a commit. ci-ok
treats skipped jobs as passing. The row-reading test helpers now
read e2e-extended and the CI_SCOPE-switched matrices, so the coverage
assertions still check every row.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko Mikola Lysenko (mikolalysenko) added the ci-perf CI / merge-queue performance finding (profiler routine) label Oct 9, 2026
…ed' into ci/depot-linux-runners

# Conflicts:
#	.github/workflows/gradle-compatibility.yml
# Conflicts:
#	.github/workflows/ci.yml
#	.github/workflows/gradle-compatibility.yml
@mikolalysenko Mikola Lysenko (mikolalysenko) changed the title Cut CI to a lean per-package-manager gate Cut CI to a lean per-package-manager gate (+ #1353 Gradle Windows cells) Oct 9, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Update: #1362 (Depot runners) merged at 20:53Z, so this PR is now based on main. At the maintainer's request it also folds in #1353 (gradle-compatibility.yml: run 2 of 4 hosted Windows cells on PRs), with the Depot mapping re-applied; #1353 is closed. The diff is now 4 files: ci.yml, gradle-compatibility.yml and two script-test helpers. scripts/tests: 307 OK.

Comment thread .github/workflows/ci.yml Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issues.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 1fcb4c8. Configure here.

Comment thread .github/workflows/ci.yml Outdated
Comment thread scripts/tests/test_ci_vlt_rows.py Outdated
Review feedback on the lean gate:
- hosted-e2e is no longer CI_SCOPE-gated. It always runs again (one
  Linux job), so the production proof keeps its step-level
  HOSTED_E2E_DISABLED kill switch and BYPASSED banner as its only
  bypass.
- docker-base still runs on release/v5-prerelease pull requests, so
  e2e-docker keeps its only full-LTO Docker run there.
- ci-vlt-proof-suites.py only drops cells that the lean `e2e` job
  runs on every pull request. job_rows() gets `extended=False` for
  that; the bundle and coverage checks still read e2e-extended too.

Speed: the lean run's critical path was coverage at 14.2 min on a
4-vCPU runner (e2e-build 4.8 min, clippy 1.7 min), and all three are
compile-bound. clippy, coverage, e2e-build and test-release now run on
16-vCPU Depot runners (depot-ubuntu-24.04-16); DISABLE_DEPOT_RUNNERS
still falls back to ubuntu-latest.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit f84535b Oct 9, 2026
54 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the ci/lean-scope branch October 9, 2026 21:29
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 9, 2026
Main now runs PR, merge_group and push CI in the lean scope (#1375) on
Depot runners (#1362), and already carries this PR's Gradle Windows
change. Every conflicted workflow and test file takes main's version.
Only the pieces that still save minutes on that structure are re-applied.

Kept:
- Merge-queue verdict reuse on push to main. clippy runs
  scripts/ci-reuse-merge-group.py (actions: read), which looks for a
  successful merge_group run of ci.yml for the identical SHA from a
  gh-readonly-queue/main/ branch of this repository. When it finds one, the
  push run still compiles to refresh the main-only caches (cargo test
  --no-run in test, coverage under the llvm-cov env and
  cargo-old-toolchains; the e2e builders and node-addon build as before)
  but skips test steps and the test-only jobs the queue already ran: e2e,
  e2e-extended, e2e-windows, e2e-macos, the cargo-vex and yarn lean jobs and
  docker-base. Jobs the queue never runs (test-release, e2e-full,
  yarn-berry-full, cargo-vex-matrix-full) keep running, so the Linux e2e
  bundle still uploads. API errors, timeouts, bad payloads, missing
  evidence and direct pushes all fall back to the full run. hosted-e2e is
  left running on every push, as main's LEAN SCOPE note requires.
- Coverage summary from the existing LCOV export
  (scripts/ci-lcov-summary.py) instead of a second `cargo llvm-cov
  report --summary-only` pass over the instrumented objects. coverage is
  the critical-path job.
- Runtime-balanced Windows test shards (scripts/ci-test-shard.py with
  scripts/ci-test-durations.json) and the slimmer sbt warm-up for
  coverage-docker's blocking slice (Dockerfile.sbt SBT_WARM_TOOLS). Both
  only affect full-scope runs now.

Dropped:
- e2e row packing (ci-e2e-groups.py, ci-e2e-run.py, grouped e2e jobs,
  e2e-gradle-mid) and their tests: main split e2e into lean `e2e` and
  full-only `e2e-extended` instead.
- The Gradle compat changes (already on main via #1375).
- The ci-ok `!cancelled()` condition and the node-addon OS matrix: they
  don't apply cleanly to main's design and aren't needed for the savings
  above.
- The per-workflow Depot runs-on edits, which main landed in #1362.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-perf CI / merge-queue performance finding (profiler routine)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants