From 2418944dd65a0c8f697f2b102d353f8c603f6bac Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 9 Oct 2026 17:30:43 +0000 Subject: [PATCH 1/5] Run 2 of 4 Gradle hosted Windows cells on PRs Each matching PR ran the 43-test hosted Gradle suite on Windows four times, once per Gradle line, at 28-42 min a cell: about 70% of the workflow's Windows minutes and its wall clock. Keep the oldest (6.9.4) and newest (9.8.0) lines on PRs and leave 7.6.6 and 8.14.3 hosted on Windows to the nightly and manual runs. ci.yml's e2e still runs hosted on all four lines on ubuntu on every PR and in the merge queue. Fixes #1300. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01VrgiQoDwt3vjxG2zNfZBAA --- .github/workflows/gradle-compatibility.yml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/.github/workflows/gradle-compatibility.yml b/.github/workflows/gradle-compatibility.yml index b8196642c..6bc58055c 100644 --- a/.github/workflows/gradle-compatibility.yml +++ b/.github/workflows/gradle-compatibility.yml @@ -42,7 +42,9 @@ name: Gradle patch compatibility # the same suites, filters, Gradle lines and JDKs on ubuntu on every PR and # in the merge queue. The ubuntu `extras` run on a PR only when it touches # Gradle code (`changes` below); every other PR gets them from the nightly -# (#1177). Windows cells run on every PR that matches `paths:`. +# (#1177). Windows cells run on every PR that matches `paths:`, except +# hosted on the middle Gradle lines (7.6.6, 8.14.3), which run nightly: a PR +# runs hosted on Windows on 6.9.4 and 9.8.0 only (#1300). on: pull_request: @@ -235,6 +237,16 @@ jobs: - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} # ci.yml's `e2e` runs these ubuntu cells on every PR (#1177). - os: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || '' }} + # Windows hosted on a PR: only the oldest (6.9.4) and newest (9.8.0) + # lines. The middle two are ~40 min each, 40% of a PR run's Windows + # minutes; they run nightly, and ci.yml's `e2e` runs hosted on all + # four lines on ubuntu on every PR (#1300). + - os: ${{ github.event_name == 'pull_request' && 'windows-latest' || '' }} + gradle: '7.6.6' + mode: hosted + - os: ${{ github.event_name == 'pull_request' && 'windows-latest' || '' }} + gradle: '8.14.3' + mode: hosted runs-on: ${{ matrix.os }} timeout-minutes: 60 steps: &cell-steps From bc3d7f60bafb8b44fc43e1c63da3772794b0fc7a Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 9 Oct 2026 17:42:24 +0000 Subject: [PATCH 2/5] Port #1301's minimist repin to unblock CI hosted-e2e (and the other live minimist suites) fail on every head: production now serves minimist@1.2.2 patch 642d7f02 while the tests pin 80630680 (#1293). This is #1301's change, applied verbatim; it becomes a no-op once #1301 lands. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01VrgiQoDwt3vjxG2zNfZBAA --- .../tests/e2e_hosted_production.rs | 4 +-- crates/socket-patch-cli/tests/e2e_npm.rs | 6 ++-- .../socket-patch-cli/tests/e2e_safety_pnpm.rs | 6 ++-- .../tests/e2e_vendored_production.rs | 4 +-- docs/testing/bun-compatibility.md | 2 +- scripts/backtest-bun.py | 2 +- scripts/backtest-vlt.py | 4 +-- scripts/tests/test_backtest_harnesses.py | 33 +++++++++++++++++++ 8 files changed, 47 insertions(+), 14 deletions(-) diff --git a/crates/socket-patch-cli/tests/e2e_hosted_production.rs b/crates/socket-patch-cli/tests/e2e_hosted_production.rs index 6c7ca6f07..f293592a0 100644 --- a/crates/socket-patch-cli/tests/e2e_hosted_production.rs +++ b/crates/socket-patch-cli/tests/e2e_hosted_production.rs @@ -33,7 +33,7 @@ //! //! | Ecosystem | PURL | Patch UUID | Advisory | //! |-----------|------|------------|----------| -//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h (CVE-2021-44906) | +//! | npm | `pkg:npm/minimist@1.2.2` | `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb` | GHSA-xvch-5gv4-984h (CVE-2021-44906) | //! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | GHSA-gm62-xv2j-4w53 &co | //! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_UUIDS`] (six today; the sixth merges three advisories) | GHSA-m42x-37p3-fv5w (CVE-2020-8162), GHSA-w749-p3v6-hccq (CVE-2022-21831), GHSA-9xrj-h377-fr87 (CVE-2026-33195), GHSA-r4mg-4433-c7g3 (CVE-2025-24293), GHSA-xr9x-r78c-5hrm (CVE-2026-66066) | //! @@ -123,7 +123,7 @@ const PATCH_HOST: &str = "patch.socket.dev"; const NPM_PURL: &str = "pkg:npm/minimist@1.2.2"; const NPM_NAME: &str = "minimist"; const NPM_VERSION: &str = "1.2.2"; -const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c"; +const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb"; const PYPI_PURL: &str = "pkg:pypi/urllib3@1.26.18"; const PYPI_NAME: &str = "urllib3"; diff --git a/crates/socket-patch-cli/tests/e2e_npm.rs b/crates/socket-patch-cli/tests/e2e_npm.rs index 63de6c636..4df29c4d7 100644 --- a/crates/socket-patch-cli/tests/e2e_npm.rs +++ b/crates/socket-patch-cli/tests/e2e_npm.rs @@ -1,7 +1,7 @@ //! End-to-end tests for the npm patch lifecycle. //! //! These tests exercise the full CLI against the real Socket API, using the -//! **minimist@1.2.2** patch (UUID `80630680-4da6-45f9-bba8-b888e0ffd58c`), +//! **minimist@1.2.2** patch (UUID `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`), //! which fixes CVE-2021-44906 (Prototype Pollution). //! //! # Prerequisites @@ -26,14 +26,14 @@ use common::cache_env; // Constants // --------------------------------------------------------------------------- -const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c"; +const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb"; const NPM_PURL: &str = "pkg:npm/minimist@1.2.2"; /// Git SHA-256 of the *unpatched* `index.js` shipped with minimist 1.2.2. const BEFORE_HASH: &str = "311f1e893e6eac502693fad8617dcf5353a043ccc0f7b4ba9fe385e838b67a10"; /// Git SHA-256 of the *patched* `index.js` after the security fix. -const AFTER_HASH: &str = "043f04d19e884aa5f8371428718d2a3f27a0d231afe77a2620ac6312f80aaa28"; +const AFTER_HASH: &str = "ec956dcafb886f14315570bf3981d44aa12c561716abb46eed8b067aaa1f6bdf"; // --------------------------------------------------------------------------- // Helpers diff --git a/crates/socket-patch-cli/tests/e2e_safety_pnpm.rs b/crates/socket-patch-cli/tests/e2e_safety_pnpm.rs index 783e7337a..e70b3511d 100644 --- a/crates/socket-patch-cli/tests/e2e_safety_pnpm.rs +++ b/crates/socket-patch-cli/tests/e2e_safety_pnpm.rs @@ -11,7 +11,7 @@ //! view and the store entry byte-identical. //! //! Fixture: minimist@1.2.2 + its Socket patch (UUID -//! `80630680-4da6-45f9-bba8-b888e0ffd58c`, CVE-2021-44906) — same +//! `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`, CVE-2021-44906) — same //! pair `e2e_npm.rs` uses, so the BEFORE/AFTER hashes are known. //! //! Network: yes (pnpm install + socket-patch get). Toolchain: pnpm. @@ -24,12 +24,12 @@ mod common; use common::{assert_run_ok, git_sha256_file, has_command, pnpm_run, write_package_json}; -const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c"; +const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb"; /// Git-SHA-256 of the *unpatched* `index.js` shipped with minimist 1.2.2. const BEFORE_HASH: &str = "311f1e893e6eac502693fad8617dcf5353a043ccc0f7b4ba9fe385e838b67a10"; /// Git-SHA-256 of the *patched* `index.js` after the security fix. -const AFTER_HASH: &str = "043f04d19e884aa5f8371428718d2a3f27a0d231afe77a2620ac6312f80aaa28"; +const AFTER_HASH: &str = "ec956dcafb886f14315570bf3981d44aa12c561716abb46eed8b067aaa1f6bdf"; // ── Setup helpers ───────────────────────────────────────────────────── diff --git a/crates/socket-patch-cli/tests/e2e_vendored_production.rs b/crates/socket-patch-cli/tests/e2e_vendored_production.rs index 51a34a20f..53f2f2d9c 100644 --- a/crates/socket-patch-cli/tests/e2e_vendored_production.rs +++ b/crates/socket-patch-cli/tests/e2e_vendored_production.rs @@ -49,7 +49,7 @@ //! //! | Ecosystem | PURL | Patch UUID | Marker in the patched bytes | //! |-----------|------|------------|-----------------------------| -//! | npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | `Socket Community Patch` header | +//! | npm | `pkg:npm/minimist@1.2.2` | `642d7f02-ebc1-4ab0-99e2-07f5dd8463cb` | `Socket Community Patch` header | //! | PyPI | `pkg:pypi/urllib3@1.26.18` | *any of three* (see [`PYPI_UUIDS`]) | `Socket Community Patch` header | //! | gem | `pkg:gem/activestorage@6.0.3` | *any of* [`GEM_PATCHES`] | `Socket Community Patch` header | //! @@ -137,7 +137,7 @@ const PROXY: &str = "https://patches-api.socket.dev"; const NPM_PURL: &str = "pkg:npm/minimist@1.2.2"; const NPM_NAME: &str = "minimist"; const NPM_VERSION: &str = "1.2.2"; -const NPM_UUID: &str = "80630680-4da6-45f9-bba8-b888e0ffd58c"; +const NPM_UUID: &str = "642d7f02-ebc1-4ab0-99e2-07f5dd8463cb"; const PYPI_PURL: &str = "pkg:pypi/urllib3@1.26.18"; const PYPI_NAME: &str = "urllib3"; diff --git a/docs/testing/bun-compatibility.md b/docs/testing/bun-compatibility.md index 26ef8e5d5..a65b4b96d 100644 --- a/docs/testing/bun-compatibility.md +++ b/docs/testing/bun-compatibility.md @@ -5,7 +5,7 @@ projects using text `bun.lock` or native binary `bun.lockb`. Real-Bun evidence b - **The native matrix** — `scripts/backtest-bun.py` runs real Bun releases against the public free Socket patch for `minimist@1.2.2` - (`80630680-4da6-45f9-bba8-b888e0ffd58c`) with the production CLI and patch + (`642d7f02-ebc1-4ab0-99e2-07f5dd8463cb`) with the production CLI and patch service, without a token or substitute service, and checks the INSTALLED bytes, lock stability, digest rejection and rollback on Linux, macOS and Windows ([workflow](../../.github/workflows/bun-compatibility.yml)). diff --git a/scripts/backtest-bun.py b/scripts/backtest-bun.py index 71020c4c8..8487c7b05 100644 --- a/scripts/backtest-bun.py +++ b/scripts/backtest-bun.py @@ -117,7 +117,7 @@ # former `vendored-detached` leg collapsed into `vendored`: same footprint. MODES = ['hosted', 'vendored'] PURL = 'pkg:npm/minimist@1.2.2' -UUID = '80630680-4da6-45f9-bba8-b888e0ffd58c' +UUID = '642d7f02-ebc1-4ab0-99e2-07f5dd8463cb' # The registry slot bun writes for a non-default registry: the full tarball URL. REGISTRY_SLOT = 'https://registry.npmjs.org/minimist/-/minimist-1.2.2.tgz' LOCAL_TUPLE_SPEC = f'minimist@.socket/vendor/npm/{UUID}/minimist-1.2.2.tgz' diff --git a/scripts/backtest-vlt.py b/scripts/backtest-vlt.py index 18ed56f9d..fb8533fa2 100644 --- a/scripts/backtest-vlt.py +++ b/scripts/backtest-vlt.py @@ -88,7 +88,7 @@ VERSIONS = ['0.0.0-16', '0.0.0-32', '1.0.0-rc.14', '1.0.0-rc.32', '1.0.4', '1.0.10', '1.2.0'] MODES = ['hosted', 'vendored', 'agent'] PURL = 'pkg:npm/minimist@1.2.2' -UUID = '80630680-4da6-45f9-bba8-b888e0ffd58c' +UUID = '642d7f02-ebc1-4ab0-99e2-07f5dd8463cb' NAME = 'minimist' VERSION = '1.2.2' TARGET = f'{NAME}@{VERSION}' @@ -1069,7 +1069,7 @@ def holds(self, root, lock_text, side): ok = True for copy_dir in self.copies(root, lock_text): for key, hashes in self.record['files'].items(): - path = copy_dir / key.split('/', 1)[1] + path = copy_dir / key.removeprefix('package/') digest = git_hash(path.read_bytes()) if path.is_file() else None details[str(path.relative_to(root))] = digest ok = ok and digest == hashes.get(f'{side}Hash') diff --git a/scripts/tests/test_backtest_harnesses.py b/scripts/tests/test_backtest_harnesses.py index bc2ee49dc..3ec7557aa 100644 --- a/scripts/tests/test_backtest_harnesses.py +++ b/scripts/tests/test_backtest_harnesses.py @@ -814,6 +814,39 @@ def test_shapes_are_depscan_capture_shapes(self): self.assertLessEqual(set(vlt.SHAPES), capture_names) +class VltInstalledBytesTests(unittest.TestCase): + def test_holds_checks_root_and_nested_files_with_optional_package_prefix(self): + contents = { + 'index.js': {'before': b'original entrypoint', 'after': b'patched entrypoint'}, + 'test/proto.js': {'before': b'original test', 'after': b'patched test'}, + } + for prefix in ('', 'package/'): + for side in ('before', 'after'): + with self.subTest(prefix=prefix, side=side), tempfile.TemporaryDirectory() as temp: + root = Path(temp) + package = root / 'node_modules' / 'minimist' + record = {'files': { + prefix + name: {s + 'Hash': vlt.git_hash(data) for s, data in sides.items()} + for name, sides in contents.items() + }} + cell = vlt.Cell({'out': root, 'record': record}, '1.2.0', 'vendored', 'direct') + expected = {} + for name, sides in contents.items(): + path = package / name + path.parent.mkdir(parents=True, exist_ok=True) + path.write_bytes(sides[side]) + expected[str(path.relative_to(root))] = vlt.git_hash(sides[side]) + self.assertEqual(cell.holds(root, '{}', side), (True, expected)) + other_side = 'after' if side == 'before' else 'before' + self.assertFalse(cell.holds(root, '{}', other_side)[0]) + + nested = package / 'test' / 'proto.js' + nested.write_bytes(b'corrupted') + self.assertFalse(cell.holds(root, '{}', side)[0]) + nested.unlink() + self.assertFalse(cell.holds(root, '{}', side)[0]) + + class VltConfigTests(unittest.TestCase): """write_vlt_json follows the DESIGN §8.3 per-era registry table.""" From 6fcaf8e9639cbde18a6b0946e3994758b4e02893 Mon Sep 17 00:00:00 2001 From: Mikola Lysenko Date: Fri, 9 Oct 2026 14:35:13 -0400 Subject: [PATCH 3/5] Run Linux CI jobs on Depot runners Merge-queue jobs wait for runners in the org's shared GitHub-hosted Linux pool, behind every PR run: in one merge_group run `clippy` waited 7.7 min to start while its Windows and macOS jobs started at once. Depot's runners don't count against that pool. Every Linux `runs-on` in ci.yml and the compatibility workflows now maps to depot-ubuntu-24.04-4 / depot-ubuntu-22.04-4 (4 vCPU, the size of GitHub's public-repo ubuntu-latest). Matrix values are unchanged, so job names, cache keys and scripts are unchanged too. Setting the repository variable DISABLE_DEPOT_RUNNERS=true falls back to GitHub-hosted runners, the same switch depscan uses. Release, publish, bench and the merge-queue helper workflows stay GitHub-hosted: npm provenance needs GitHub-hosted runners, bench timings should keep their baseline, and the helpers hold write tokens. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/bun-compatibility.yml | 6 +- .github/workflows/ci.yml | 69 +++++++++++--------- .github/workflows/composer-compatibility.yml | 6 +- .github/workflows/go-compatibility.yml | 4 +- .github/workflows/gradle-compatibility.yml | 8 +-- .github/workflows/npm-compatibility.yml | 4 +- .github/workflows/pdm-compatibility.yml | 8 +-- .github/workflows/pipenv-compatibility.yml | 4 +- .github/workflows/pnpm-compatibility.yml | 4 +- .github/workflows/poetry-compatibility.yml | 4 +- .github/workflows/sbt-compatibility.yml | 10 +-- .github/workflows/vlt-compatibility.yml | 18 ++--- 12 files changed, 77 insertions(+), 68 deletions(-) diff --git a/.github/workflows/bun-compatibility.yml b/.github/workflows/bun-compatibility.yml index 7d04cd593..a16bb4a9c 100644 --- a/.github/workflows/bun-compatibility.yml +++ b/.github/workflows/bun-compatibility.yml @@ -116,7 +116,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: - name: Checkout @@ -174,7 +174,7 @@ jobs: - {os: windows-latest, bun: '1.0.36'} # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: - name: Checkout @@ -374,7 +374,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: - name: Checkout diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2b966b8d6..25c0b489c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -43,12 +43,21 @@ concurrency: group: ci-${{ github.event.pull_request.number || (github.event_name == 'push' && github.sha) || github.ref }}${{ github.event_name == 'schedule' && '-nightly' || '' }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} +# Linux jobs run on Depot's runners (depot-ubuntu-*-4: 4 vCPU, like GitHub's +# public-repo ubuntu-latest), which don't draw on the org's shared GitHub-hosted +# concurrency pool, where merge-queue jobs used to wait behind PR CI. Matrix +# values stay `ubuntu-latest`/`ubuntu-22.04`, so job names, cache keys and +# scripts are unchanged; only `runs-on` maps them. Kill switch: set the +# repository variable DISABLE_DEPOT_RUNNERS=true to fall back to GitHub-hosted +# runners (the same switch depscan uses). The compatibility workflows follow +# the same mapping. Release, publish and merge-queue workflows stay +# GitHub-hosted (provenance / write tokens). jobs: # Required independently of ci-ok so the merge queue sees a compile/lint # failure immediately. Expensive jobs also depend on this preflight. clippy: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 20 steps: - name: Checkout @@ -91,7 +100,7 @@ jobs: node-addon: if: github.event.pull_request.draft != true needs: clippy - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 30 steps: - name: Checkout @@ -125,7 +134,7 @@ jobs: # test harnesses. lint-ecosystems: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 10 steps: - name: Checkout @@ -217,7 +226,7 @@ jobs: # tag doesn't already exist. release-readiness: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -272,7 +281,7 @@ jobs: exclude: # macOS legs run on main, the merge queue and nightly, not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 50 env: VEXCTL_VERSION: v0.3.0 @@ -431,7 +440,7 @@ jobs: # queue already skips this job because each constituent PR ran it. if: github.event.pull_request.draft != true && github.event_name != 'merge_group' needs: clippy - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} strategy: fail-fast: false matrix: @@ -482,7 +491,7 @@ jobs: # numbers are report-only so contributors get visibility without flaky # CI when coverage shifts naturally with test edits. A failing TEST # fails the job: this is the Linux leg of `test`. - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 35 permissions: contents: read @@ -590,7 +599,7 @@ jobs: docker-base: if: github.event.pull_request.draft != true needs: clippy - runs-on: ubuntu-22.04 + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-22.04' || 'depot-ubuntu-22.04-4' }} timeout-minutes: 30 permissions: contents: read @@ -646,7 +655,7 @@ jobs: # container ships fails to load. ubuntu-22.04's older glibc is # the highest base that's forward-compatible with debian:12. needs: docker-base - runs-on: ubuntu-22.04 + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-22.04' || 'depot-ubuntu-22.04-4' }} # sbt's image bakes three JDKs and warm sbt / Mill / scala-cli caches. timeout-minutes: ${{ matrix.ecosystem == 'sbt' && 45 || 30 }} permissions: @@ -771,7 +780,7 @@ jobs: # single lcov.info. lcov(1) handles the union — same files are # summed line-by-line so a line covered by ANY test counts. needs: [coverage, coverage-docker] - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 15 permissions: contents: read @@ -834,7 +843,7 @@ jobs: dispatch-tests: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 10 steps: - name: Checkout @@ -876,7 +885,7 @@ jobs: fail-fast: false matrix: os: [ubuntu-latest] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 env: &e2e-build-env CARGO_PROFILE_DEV_DEBUG: '0' @@ -933,7 +942,7 @@ jobs: fail-fast: false matrix: os: [windows-latest] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 env: *e2e-build-env steps: *e2e-build-steps @@ -945,7 +954,7 @@ jobs: fail-fast: false matrix: os: [macos-latest] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 env: *e2e-build-env steps: *e2e-build-steps @@ -1269,7 +1278,7 @@ jobs: # deno; VEX must attest nothing), one leg per major. - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'deno:: --ignored', deno: '1.46.3'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'deno:: --ignored', deno: '2.9.7'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} # The real-toolchain capstones loop several releases per leg (pip, # pipenv) or bootstrap a tool from PyPI before the suite (poetry, pdm, # hatch), hence more than the 25 minutes the older legs needed. @@ -1775,7 +1784,7 @@ jobs: - {os: windows-latest, suite: e2e_redirect_pnpm_build, test_filter: '--ignored --skip pnpm_pinned_matrix'} - {os: windows-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.16', test_filter: '--ignored maven_reactor'} - {os: windows-latest, suite: e2e_vendor_jvm_build, jvm_tool: gradle, gradle: '8.14.3', java: '17', test_filter: '--ignored gradle_multi_project'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 env: *e2e-env steps: *e2e-steps @@ -1826,7 +1835,7 @@ jobs: - {os: macos-latest, suite: e2e_vendor_maven_build, jvm_tool: maven, maven: '3.9.16'} - {os: macos-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.16', test_filter: '--ignored maven_reactor'} - {os: macos-latest, suite: e2e_nuget_dotnet_build, dotnet: '8'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} # The real-toolchain capstones loop several releases per leg (pip, # pipenv) or bootstrap a tool from PyPI before the suite (poetry, pdm, # hatch), hence more than the 25 minutes the older legs needed. @@ -1877,7 +1886,7 @@ jobs: - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '7'} - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '8'} - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '9'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 # What .cargo/config.toml's [env] gives processes cargo launches; these # legs launch the test binaries themselves. @@ -1909,7 +1918,7 @@ jobs: # pull_request runs of its PR into main) run it too. if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' || github.head_ref == 'release/v5-prerelease' needs: docker-base - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: ${{ matrix.ecosystem == 'sbt' && 45 || 35 }} permissions: contents: read @@ -1995,7 +2004,7 @@ jobs: # Only wait for the clippy preflight. if: github.event.pull_request.draft != true needs: clippy - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 40 strategy: fail-fast: false @@ -2049,7 +2058,7 @@ jobs: - {os: ubuntu-latest, yarn: '4.1.0'} - {os: ubuntu-latest, yarn: '4.18.0'} - {os: windows-latest, yarn: '4.12.0'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: &yarn-berry-steps - name: Checkout @@ -2090,7 +2099,7 @@ jobs: # of the spread (4.6.0, 4.12.0 on ubuntu) is yarn-berry-full. include: - {os: macos-latest, yarn: '4.12.0'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: *yarn-berry-steps @@ -2105,7 +2114,7 @@ jobs: include: - {os: ubuntu-latest, yarn: '4.6.0'} - {os: ubuntu-latest, yarn: '4.12.0'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: *yarn-berry-steps @@ -2122,7 +2131,7 @@ jobs: # e2e-build only (its binaries; only the matching OS build is needed); # see yarn-classic-matrix on test/coverage. needs: [e2e-build] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 # What .cargo/config.toml's [env] gives processes cargo launches; these # legs launch the test binaries themselves. @@ -2201,7 +2210,7 @@ jobs: cargo-vex-matrix-windows: name: cargo ${{ matrix.toolchain }} lock-v${{ matrix.lock || 'own' }} (${{ matrix.os }}) needs: [e2e-build-windows] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 env: *e2e-env strategy: @@ -2217,7 +2226,7 @@ jobs: if: github.event_name != 'pull_request' name: cargo ${{ matrix.toolchain }} lock-v${{ matrix.lock || 'own' }} (${{ matrix.os }}) needs: [e2e-build-macos] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 # What .cargo/config.toml's [env] gives processes cargo launches; these # legs launch the test binaries themselves. @@ -2238,7 +2247,7 @@ jobs: # merge_group runs the pull_request tier: the queue gates on ci-ok. if: (github.event_name != 'pull_request' && github.event_name != 'merge_group') || github.head_ref == 'release/v5-prerelease' needs: [e2e-build] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 # What .cargo/config.toml's [env] gives processes cargo launches; these # legs launch the test binaries themselves. @@ -2278,7 +2287,7 @@ jobs: # Only wait for the clippy preflight. if: github.event.pull_request.draft != true needs: clippy - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 30 steps: - name: Checkout @@ -2342,7 +2351,7 @@ jobs: name: hosted-e2e # may be a required check; do not rename if: github.event.pull_request.draft != true needs: clippy - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} permissions: contents: read timeout-minutes: 30 @@ -2547,7 +2556,7 @@ jobs: name: ci-ok # registered as a required check; do not rename if: always() needs: [clippy, node-addon, lint-ecosystems, release-readiness, test, test-release, coverage, docker-base, coverage-docker, coverage-merge, dispatch-tests, e2e-build, e2e-build-windows, e2e-build-macos, e2e, e2e-windows, e2e-full, e2e-docker, yarn-classic-matrix, yarn-berry-e2e, yarn-berry-full, cargo-vex-matrix, cargo-vex-matrix-windows, cargo-vex-matrix-full, cargo-old-toolchains, hosted-e2e, e2e-macos, yarn-berry-e2e-macos, cargo-vex-matrix-macos] - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 5 steps: - name: Check every needed job diff --git a/.github/workflows/composer-compatibility.yml b/.github/workflows/composer-compatibility.yml index 62a8d7fec..feb82a6e0 100644 --- a/.github/workflows/composer-compatibility.yml +++ b/.github/workflows/composer-compatibility.yml @@ -130,7 +130,7 @@ jobs: - {os: windows-latest, composer: '2.2.30', php: '8.3', sha256: 8c2b4478b64f8f7cdf1574838fdb0033b29049ca821dad452db7a3dcfcdbffc2} - {os: windows-latest, composer: '2.9.8', php: '8.4', sha256: 59b2c50e10cafa0d8efc19ede9a326d782f096c674a26baf98cf042ce23de890} - {os: windows-latest, composer: '2.10.3', php: '8.5', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 steps: &native-steps - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -216,7 +216,7 @@ jobs: # all (#1210); 2.40.0 resolves the tap's formula aliases first. # Ubuntu and Windows keep the 2.10.3 / 8.5 cell. - {os: macos-latest, composer: '2.10.3', php: '8.4', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 steps: *native-steps @@ -226,7 +226,7 @@ jobs: # Composer 1, so 1.10.28 is covered by the native legs only. name: docker composer ${{ matrix.composer }} if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 35 strategy: fail-fast: false diff --git a/.github/workflows/go-compatibility.yml b/.github/workflows/go-compatibility.yml index 3066d36bd..d7f3333e2 100644 --- a/.github/workflows/go-compatibility.yml +++ b/.github/workflows/go-compatibility.yml @@ -78,7 +78,7 @@ jobs: matrix: os: [ubuntu-latest] go: ['1.18.10', '1.21.13', '1.24.13', '1.26.3'] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: &go-steps - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -118,6 +118,6 @@ jobs: # macOS-latest dyld refuses binaries without LC_UUID (Go < 1.24 # linkers; see ci.yml's vexctl step). go: ['1.24.13', '1.26.3'] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: *go-steps diff --git a/.github/workflows/gradle-compatibility.yml b/.github/workflows/gradle-compatibility.yml index b8196642c..38ab4faeb 100644 --- a/.github/workflows/gradle-compatibility.yml +++ b/.github/workflows/gradle-compatibility.yml @@ -110,7 +110,7 @@ jobs: # Whether this run needs the ubuntu `extras`: always off pull_request, and # on a PR only when it touches Gradle code. if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 5 outputs: gradle_core: ${{ steps.diff.outputs.gradle_core }} @@ -158,7 +158,7 @@ jobs: - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} # On a PR only the ubuntu `extras` use the ubuntu build. - os: ${{ github.event_name == 'pull_request' && needs.changes.outputs.gradle_core != 'true' && 'ubuntu-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 env: CARGO_PROFILE_DEV_DEBUG: '0' @@ -235,7 +235,7 @@ jobs: - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} # ci.yml's `e2e` runs these ubuntu cells on every PR (#1177). - os: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 steps: &cell-steps - name: Checkout @@ -423,7 +423,7 @@ jobs: # Only the suite that owns those tests: e2e_vendor_jvm_build has none, # and every landed suite a cell runs must run a test. - {os: ubuntu-latest, gradle: '8.14.3', java: '21', mode: vendor, label: real-central, real_central: '1', suites: 'e2e_vendor_gradle_build', test_filter: 'gradle_vendor_511 gradle_vendor_487'} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 continue-on-error: ${{ matrix.record_only == 'true' }} steps: *cell-steps diff --git a/.github/workflows/npm-compatibility.yml b/.github/workflows/npm-compatibility.yml index 9ef2ae22c..f7ad21e3d 100644 --- a/.github/workflows/npm-compatibility.yml +++ b/.github/workflows/npm-compatibility.yml @@ -74,7 +74,7 @@ concurrency: jobs: build: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 25 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -103,7 +103,7 @@ jobs: install-proof: needs: build - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 25 strategy: fail-fast: false diff --git a/.github/workflows/pdm-compatibility.yml b/.github/workflows/pdm-compatibility.yml index 05619435d..9ab38d3b9 100644 --- a/.github/workflows/pdm-compatibility.yml +++ b/.github/workflows/pdm-compatibility.yml @@ -85,7 +85,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -128,7 +128,7 @@ jobs: # every Windows cell skipped; backtest-pdm.py now fails such a cell. os: [ubuntu-latest] pdm: ['0.12.3', '1.15.5', '2.0.3', '2.1.5', '2.3.4', '2.6.1', '2.7.4', '2.8.2', '2.9.3', '2.10.4', '2.11.2', '2.17.3', '2.20.1', '2.22.4', '2.25.9', '2.29.2'] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: &native-steps - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -204,7 +204,7 @@ jobs: # The ends of the range and the 2.8 lock-format boundary. os: [macos-latest] pdm: ['0.12.3', '2.8.2', '2.29.2'] - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: *native-steps @@ -225,7 +225,7 @@ jobs: - {os: macos-latest, pdm: '2.29.2'} # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: # The binaries resolve fixtures through the build job's checkout path, diff --git a/.github/workflows/pipenv-compatibility.yml b/.github/workflows/pipenv-compatibility.yml index 27e07c721..cea9c0e5e 100644 --- a/.github/workflows/pipenv-compatibility.yml +++ b/.github/workflows/pipenv-compatibility.yml @@ -86,7 +86,7 @@ jobs: - os: ubuntu-latest versions: 2022.12.19 2026.8.0 shapes: crlf marker-excluded extras category - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 steps: &matrix-steps - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -153,6 +153,6 @@ jobs: - os: macos-latest versions: 2018.11.26 2022.12.19 2023.12.1 2026.8.0 shapes: direct - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 steps: *matrix-steps diff --git a/.github/workflows/pnpm-compatibility.yml b/.github/workflows/pnpm-compatibility.yml index 271117272..06bec0175 100644 --- a/.github/workflows/pnpm-compatibility.yml +++ b/.github/workflows/pnpm-compatibility.yml @@ -60,7 +60,7 @@ concurrency: jobs: build: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 20 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -97,7 +97,7 @@ jobs: # failed the whole run. Every version still runs; a failure names it. name: install-proof (node ${{ matrix.node }}) needs: build - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 30 strategy: fail-fast: false diff --git a/.github/workflows/poetry-compatibility.yml b/.github/workflows/poetry-compatibility.yml index 00be6232b..e1f40c991 100644 --- a/.github/workflows/poetry-compatibility.yml +++ b/.github/workflows/poetry-compatibility.yml @@ -69,7 +69,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -97,7 +97,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 diff --git a/.github/workflows/sbt-compatibility.yml b/.github/workflows/sbt-compatibility.yml index 26cc6c768..80726c17a 100644 --- a/.github/workflows/sbt-compatibility.yml +++ b/.github/workflows/sbt-compatibility.yml @@ -115,7 +115,7 @@ jobs: if: github.event.pull_request.draft != true # Builds the sbt image once (base image first: Dockerfile.sbt is # `FROM socket-patch-test-base:latest`) and hands it to every leg. - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 45 steps: - name: Checkout @@ -168,7 +168,7 @@ jobs: # rust container. Absolute paths are kept (`tar -P`): # the test binaries carry their compile-time paths, and every leg checks # out to the same workspace path. - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 40 steps: - name: Checkout @@ -194,7 +194,7 @@ jobs: docker: name: sbt ${{ matrix.sbt }} / jdk ${{ matrix.jdk }} / ${{ matrix.group }} needs: [image, linux-bins] - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 45 strategy: fail-fast: false @@ -257,7 +257,7 @@ jobs: # vendored (the versions the image installs). name: ${{ matrix.group }} ${{ matrix.version }} needs: [image, linux-bins] - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 45 strategy: fail-fast: false @@ -308,7 +308,7 @@ jobs: # The warm-seed step boots sbt once so the tests share its caches. name: sbt 1.13.0 ${{ matrix.suite }} / ${{ matrix.os }} if: github.event.pull_request.draft != true - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 60 strategy: fail-fast: false diff --git a/.github/workflows/vlt-compatibility.yml b/.github/workflows/vlt-compatibility.yml index 466404c65..43fbecb57 100644 --- a/.github/workflows/vlt-compatibility.yml +++ b/.github/workflows/vlt-compatibility.yml @@ -127,7 +127,7 @@ env: jobs: matrix-coverage: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 5 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -145,7 +145,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -254,7 +254,7 @@ jobs: - {os: windows-latest, vlt: '1.2.0', linker: auto, suites: e2e_safety_vlt} - {os: windows-latest, vlt: '1.2.0', linker: hardlink, suites: e2e_safety_vlt} - {os: ubuntu-latest, vlt: '1.2.0', linker: hardlink, cache_root: /dev/shm/vlt-e2e-cache, suites: e2e_safety_vlt} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 # The capstones resolve fixtures through the build job's checkout path, # which is the same on every runner of one OS. @@ -368,13 +368,13 @@ jobs: - {os: macos-latest, vlt: '1.2.0'} - {os: macos-latest, vlt: '1.2.0', linker: auto, suites: e2e_safety_vlt} - {os: macos-latest, vlt: '1.2.0', linker: hardlink, suites: e2e_safety_vlt} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: *install-proof-steps plan: if: github.event.pull_request.draft != true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 5 outputs: native: ${{ steps.plan.outputs.native }} @@ -406,7 +406,7 @@ jobs: # Each job runs its cells against the public patch service. max-parallel: 6 matrix: ${{ fromJSON(needs.plan.outputs.native) }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -470,7 +470,7 @@ jobs: lock-diff: needs: native if: ${{ !cancelled() }} - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 10 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -517,7 +517,7 @@ jobs: exclude: # macOS legs run on push to main (and nightly where scheduled), not per PR push. - os: ${{ github.event_name == 'pull_request' && 'macos-latest' || '' }} - runs-on: ${{ matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -586,7 +586,7 @@ jobs: # Advisory until the socket-patch release that adds vlt support (with the # forward-compatible ledger handling) is the latest published one. continue-on-error: true - runs-on: ubuntu-latest + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 20 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 From 4dc60414ed45d0d440489476adf58233b6d9d86d Mon Sep 17 00:00:00 2001 From: Mikola Lysenko Date: Fri, 9 Oct 2026 16:50:24 -0400 Subject: [PATCH 4/5] Cut CI to a lean per-package-manager gate The org is short on Actions runners, and every socket-patch PR, merge group and main push ran ~195 jobs, ~40 of them on GitHub-hosted Windows/macOS. Unless the repository variable CI_SCOPE is `full`, those events now run a lean gate of ~28 Linux jobs: - e2e keeps one targeted row per package manager (17 rows: npm, pnpm, bun, vlt, uv x2, poetry, pdm, hatch, pipenv, pip, composer, gem, maven, gradle 9.8.0, nuget, deno). The other 87 rows (older tool versions, sbt, rush, bun lockb, extra vlt eras and Gradle lines) move to e2e-extended, which shares e2e's env and steps. - yarn classic, yarn berry and the cargo VEX matrix run one current row each. - The Windows/macOS legs, test, test-release, the sbt Docker coverage slice, old cargo toolchains and the live-production hosted-e2e are skipped. Everything still runs nightly and on workflow_dispatch, and setting CI_SCOPE=full restores the previous gate without a commit. ci-ok treats skipped jobs as passing. The row-reading test helpers now read e2e-extended and the CI_SCOPE-switched matrices, so the coverage assertions still check every row. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/ci.yml | 268 +++++++++++++++------------- scripts/tests/test_ci_scheduling.py | 4 +- scripts/tests/test_ci_vlt_rows.py | 8 +- 3 files changed, 157 insertions(+), 123 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2de0d6fcd..610e115f5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -52,6 +52,13 @@ concurrency: # runners (the same switch depscan uses). The compatibility workflows follow # the same mapping. Release, publish and merge-queue workflows stay # GitHub-hosted (provenance / write tokens). +# LEAN SCOPE (temporary, while org runner capacity is constrained): unless +# the repository variable CI_SCOPE is `full`, pull_request, merge_group and +# push runs skip the Windows/macOS legs, the yarn and old-toolchain +# matrices, the sbt Docker coverage slice, test-release and the +# live-production hosted-e2e. They still run in the nightly schedule and +# on workflow_dispatch. Set CI_SCOPE=full to restore the old gate without +# a commit. ci-ok treats skipped jobs as passing. jobs: # Required independently of ci-ok so the merge queue sees a compile/lint # failure immediately. Expensive jobs also depend on this preflight. @@ -264,7 +271,7 @@ jobs: bash scripts/release-lint.sh --sync-only test: - if: github.event.pull_request.draft != true + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy # No ubuntu-latest leg: `coverage` runs this same `cargo test # --workspace` (debug, default features, plus Go and vexctl) on ubuntu, @@ -441,7 +448,7 @@ jobs: test-release: # Each PR and main push runs the complete release-mode suite. The merge # queue already skips this job because each constituent PR ran it. - if: github.event.pull_request.draft != true && github.event_name != 'merge_group' + if: (github.event.pull_request.draft != true && github.event_name != 'merge_group') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} strategy: @@ -601,7 +608,7 @@ jobs: # Dockerfile.base compiles the full-LTO release binary inside Docker, with # no cache. Build it once per run and hand the image to every docker leg. docker-base: - if: github.event.pull_request.draft != true + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-22.04' || 'depot-ubuntu-22.04-4' }} timeout-minutes: 30 @@ -658,6 +665,7 @@ jobs: # (glibc 2.36); a binary linked against a newer glibc than the # container ships fails to load. ubuntu-22.04's older glibc is # the highest base that's forward-compatible with debian:12. + if: (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: docker-base runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-22.04' || 'depot-ubuntu-22.04-4' }} # sbt's image bakes three JDKs and warm sbt / Mill / scala-cli caches. @@ -783,6 +791,7 @@ jobs: # Merge the host coverage and per-ecosystem docker coverage into a # single lcov.info. lcov(1) handles the union — same files are # summed line-by-line so a line covered by ANY test counts. + if: (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: [coverage, coverage-docker] runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 15 @@ -941,7 +950,7 @@ jobs: retention-days: 3 e2e-build-windows: - if: github.event.pull_request.draft != true + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy strategy: fail-fast: false @@ -953,7 +962,7 @@ jobs: steps: *e2e-build-steps e2e-build-macos: - if: github.event_name != 'pull_request' + if: (github.event_name != 'pull_request') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy strategy: fail-fast: false @@ -996,8 +1005,6 @@ jobs: # Both capstones share one leg per composer line: the setup is # identical and the run step loops over `suite`. - {os: ubuntu-latest, suite: e2e_vendor_composer_build e2e_redirect_composer_build, composer: '2'} - - {os: ubuntu-latest, suite: e2e_vendor_composer_build e2e_redirect_composer_build, composer: '2.2'} - - {os: ubuntu-latest, suite: e2e_vendor_composer_build e2e_redirect_composer_build, composer: '1'} # Real-bundler gem capstones, one leg per bundler era. Boundaries: # 1.17/2.1 merged GEM section, 2.2 separate sections, 2.5 last # pre-CHECKSUMS, 2.6 CHECKSUMS, 4.0.15/4.0.21 before/after the @@ -1006,12 +1013,6 @@ jobs: # (no boundary of its own) is in e2e-full. # Hosted and vendored share each era's leg (one Ruby + bundler # setup; the run step loops over `suite`). - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '1.17.3'} - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '2.1.4'} - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '2.2.33'} - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.3', bundler: '2.5.23'} - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.3', bundler: '2.6.9'} - - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.4', bundler: '4.0.15'} - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.4', bundler: '4.0.21'} # The live-API smoke suites (e2e_npm, e2e_pypi, e2e_gem, # e2e_scan) are intentionally NOT in the PR matrix — their @@ -1041,8 +1042,6 @@ jobs: # matrix entry is needed for them. e2e_safety_pnpm below needs a # real pnpm and is #[ignore]-gated; e2e_safety_cargo_build runs in # every cargo-vex-matrix leg (ubuntu, macOS and Windows). - - os: ubuntu-latest - suite: e2e_safety_pnpm # pnpm-on-Windows uses junctions for symlinks and copies # (not hardlinks) by default, so the CoW invariant holds # vacuously. Test still runs to verify apply doesn't error @@ -1065,8 +1064,6 @@ jobs: - os: ubuntu-latest suite: e2e_redirect_npm_build npm_required: '1' - - os: ubuntu-latest - suite: e2e_redirect_rush_sim # Hermetic real-bun capstones (wiremock patch service, real `bun # install`): hosted (`e2e_redirect_bun_build`), vendored # (`e2e_vendor_bun_build`) and the hosted⇄vendored takeover / @@ -1099,23 +1096,9 @@ jobs: suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun bun: '1.4.2' test_filter: --include-ignored - - os: ubuntu-latest - suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun - bun: '1.1.45' - test_filter: --include-ignored - - os: ubuntu-latest - suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun - bun: '1.2.23' - test_filter: --include-ignored - - os: ubuntu-latest - suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun - bun: '1.3.14' - test_filter: --include-ignored # The binary bun.lockb era (1.0 / 1.1 lines) through e2e_bun_lockb, # which reads the SOCKET_PATCH_BUN_LOCKB_* gates exported for it # below. - - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.0.36', test_filter: --include-ignored} - - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.1.45', test_filter: --include-ignored} # Bun >= 1.4 migrating a hosted workspace bun.lockb to bun.lock # (#803; its reader must be 1.4+) and a vendored one, then # reverting it (#784; skipped by the < 1.2 readers above), and a @@ -1124,8 +1107,6 @@ jobs: # 1.4.2 and 1.3.14 also run the isolated-linker vendored re-run # after a late dependent (#861); 1.3 re-hoists a frozen binary lock # and refuses one whose trees changed. - - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.4.2', test_filter: --include-ignored text_migration workspace_late_dependent binary_shared_bundled_record_hosted_pin_is_managed} - - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.3.14', test_filter: --include-ignored workspace_late_dependent} # Real-vlt capstones (DESIGN §8.4): wiremock patch service and a local # npm registry fed from npmjs, driven by the pinned vlt release # (`node vlt.js`, installed below from a sha512-checked `npm pack`). @@ -1137,31 +1118,10 @@ jobs: # 0.0.0-32, B rc.12/rc.14 (rc.14 legs reach public npm), C rc.32, # D 1.0.4/1.0.7, E 1.1.1, F 1.2.0. - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '0.0.0-16', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.4', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.1.1', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.4', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix, vlt_upgrade: '1.2.0'} # Linux `auto` hardlinks from the global store; every OS gets the # explicit hardlink linker. - - {os: ubuntu-latest, suite: e2e_safety_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_safety_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix, vlt_store_linker: 'hardlink'} # rc.12 gets the definite no-hook advisory; windows rc.14 runs the # legacy DepIDs on NTFS with pre-junction symlinks. - - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vlt, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.0-rc.12', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} - - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.7', test_filter: --include-ignored vlt_pinned_matrix} # The named corepack pnpm hosted legs (pnpm 7-11, get-uuid, # zero-touch, --trust-lockfile). `#[ignore]`d; the pinned matrix # inside the same suite runs in pnpm-compatibility.yml, hence the @@ -1173,13 +1133,7 @@ jobs: # re-resolves a transitive override / rejects a repointed # constraint under --locked; 0.5.5 keeps both). The other 0.N # lines and 0.5.3/0.5.6 are in e2e-full. - - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.1.45'} - - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.5.4'} - - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.5.5'} - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.12.17'} - - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.1.45', test_filter: --include-ignored} - - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.5.4', test_filter: --include-ignored} - - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.5.5', test_filter: --include-ignored} - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.12.17', test_filter: --include-ignored} # The Poetry / PDM / Hatch / Pipenv / pip / deno manifest-less VEX # capstones share ONE test binary (`e2e_vex_build`, a module per @@ -1190,33 +1144,19 @@ jobs: # unix-only). One leg per major / lock format: 1.0 (lock 1.0), # 1.1 (lock 1.1), 1.8 (lock 2.0), 2.0 (first lock 2.1 writer), # current. - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.0.10'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.1.15'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.8.5'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '2.0.1'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '2.4.3'} # Real PDM / Hatch capstones (wiremock Socket API that also serves # the hosted wheel; PyPI for the tool bootstrap + six). # PDM: lock 2 (1.4), refused 3.1 (1.15) and 4.2 (2.7), 4.3 (2.8), # the hishel<1 bootstrap window (2.25) and current. - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '1.4.5'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '1.15.5'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.7.4'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.8.2'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.25.9'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.29.2'} # Hatch: 1.0 (hatch.toml env vendoring refused, needs >= 1.2), # 1.2, the virtualenv<21 window (1.9, 1.14) and current. - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.0.0'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.2.1'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.9.7'} - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.14.2'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.18.1'} # Real Pipenv / pip capstones (mock patch server; the tools are # bootstrapped from PyPI). `pipenv:` / `pip:` hold one or more # space-separated releases the suite loops over. The middle # Pipenv releases are in e2e-full. - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pipenv:: --ignored', pipenv: '2022.12.19'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pipenv:: --ignored', pipenv: '2026.8.0'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pip:: --ignored', pip: '22 23 24 25 26'} # Real-Maven hosted + vendored capstones, one leg per Maven line: @@ -1226,17 +1166,7 @@ jobs: # the .mvn/checksums pin) and 3.9.4 (first that enforces it). # Lines that run both capstones run them in one leg (one Maven # install; the run step loops over `suite`). - - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '3.6.3'} - - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '3.8.9'} - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '3.9.16'} - - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '4.0.0-rc-6'} - - {os: ubuntu-latest, suite: e2e_redirect_maven_build, jvm_tool: maven, maven: '3.9.3'} - - {os: ubuntu-latest, suite: e2e_redirect_maven_build, jvm_tool: maven, maven: '3.9.4'} - - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.6.3', test_filter: '--ignored maven_reactor'} - - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.8.9', test_filter: '--ignored maven_reactor'} - - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.2', test_filter: '--ignored maven_reactor'} - - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.16', test_filter: '--ignored maven_reactor'} - - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '4.0.0-rc-6', test_filter: '--ignored maven_reactor'} # Real-Gradle capstones, PR tier: one leg per Gradle line x {agent + # hosted, vendor + multi-project} on ubuntu, each on its line's LTS # JDK. Every other OS x line x mode cell (and the JDK-ceiling, @@ -1254,36 +1184,17 @@ jobs: # `gradle_hosted_[b-p]` names, and a catch-all that `--skip`s # exactly those words, so a new test always lands in some leg # (test_ci_gradle_prefixes.py keeps the skip list in sync). - - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} - - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} - - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} - - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} - - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} - - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} - - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} - - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} # Real-sbt hosted (socket-patch.sbt) + vendored # (socket-patch-vendor.sbt) capstones on the current 1.x line. The # other sbt lines, JDK 21, the agent cells beyond coverage-docker's, # Mill, scala-cli and macOS / Windows are sbt-compatibility.yml. - - {os: ubuntu-latest, suite: e2e_sbt_build, jvm_tool: sbt, sbt: '1.13.0', test_filter: '--ignored --test-threads=1'} - - {os: ubuntu-latest, suite: e2e_sbt_vendor_build, jvm_tool: sbt, sbt: '1.13.0', test_filter: '--ignored --test-threads=1'} # Real .NET SDK capstones: hosted + vendored nuget, one leg per SDK # major (the suite pins the major through a sandbox global.json): # the oldest and newest here, 7-9 on ubuntu in e2e-full. - - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '6'} - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '10'} # Real deno negative capstone (no hosted/vendored wiring exists for # deno; VEX must attest nothing), one leg per major. - - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'deno:: --ignored', deno: '1.46.3'} - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'deno:: --ignored', deno: '2.9.7'} runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} # The real-toolchain capstones loop several releases per leg (pip, @@ -1763,7 +1674,127 @@ jobs: # Each OS consumes only its own build. A queued macOS runner must not # delay Linux or Windows, and a Windows compile must not delay Gradle. + # Every other e2e row (older tool versions, extra suites and Gradle/sbt + # lines). Same steps and environment as `e2e`; runs only when the + # repository variable CI_SCOPE is `full`, nightly, or on dispatch. See the + # LEAN SCOPE note at the top of `jobs:`. + e2e-extended: + if: (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') + needs: [e2e-build] + strategy: + fail-fast: false + matrix: + include: + - {os: ubuntu-latest, suite: e2e_vendor_composer_build e2e_redirect_composer_build, composer: '2.2'} + - {os: ubuntu-latest, suite: e2e_vendor_composer_build e2e_redirect_composer_build, composer: '1'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '1.17.3'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '2.1.4'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.1', bundler: '2.2.33'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.3', bundler: '2.5.23'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.3', bundler: '2.6.9'} + - {os: ubuntu-latest, suite: e2e_redirect_gem_build e2e_vendor_gem_build, ruby: '3.4', bundler: '4.0.15'} + - os: ubuntu-latest + suite: e2e_safety_pnpm + - os: ubuntu-latest + suite: e2e_redirect_rush_sim + - os: ubuntu-latest + suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun + bun: '1.1.45' + test_filter: --include-ignored + - os: ubuntu-latest + suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun + bun: '1.2.23' + test_filter: --include-ignored + - os: ubuntu-latest + suite: e2e_redirect_bun_build e2e_vendor_bun_build mode_migration_bun + bun: '1.3.14' + test_filter: --include-ignored + - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.0.36', test_filter: --include-ignored} + - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.1.45', test_filter: --include-ignored} + - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.4.2', test_filter: --include-ignored text_migration workspace_late_dependent binary_shared_bundled_record_hosted_pin_is_managed} + - {os: ubuntu-latest, suite: e2e_bun_lockb, bun: '1.3.14', test_filter: --include-ignored workspace_late_dependent} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '0.0.0-16', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.0.4', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_vlt_build, vlt: '1.1.1', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vendor_vlt_build, vlt: '1.0.4', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: mode_migration_vlt, vlt: '1.0.0-rc.14', test_filter: --include-ignored vlt_pinned_matrix, vlt_upgrade: '1.2.0'} + - {os: ubuntu-latest, suite: e2e_safety_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_safety_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix, vlt_store_linker: 'hardlink'} + - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.2.0', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vlt, vlt: '0.0.0-32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.0-rc.12', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.0-rc.32', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_vlt, vlt: '1.0.7', test_filter: --include-ignored vlt_pinned_matrix} + - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.1.45'} + - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.5.4'} + - {os: ubuntu-latest, suite: e2e_redirect_uv_build, uv: '0.5.5'} + - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.1.45', test_filter: --include-ignored} + - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.5.4', test_filter: --include-ignored} + - {os: ubuntu-latest, suite: e2e_vendor_pypi_build, uv: '0.5.5', test_filter: --include-ignored} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.0.10'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.1.15'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '1.8.5'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'poetry:: --ignored', poetry: '2.0.1'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '1.4.5'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '1.15.5'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.7.4'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.8.2'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pdm:: --ignored', pdm: '2.25.9'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.0.0'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.2.1'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.9.7'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'hatch:: --ignored', hatch: '1.14.2'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'pipenv:: --ignored', pipenv: '2022.12.19'} + - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '3.6.3'} + - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '3.8.9'} + - {os: ubuntu-latest, suite: e2e_redirect_maven_build e2e_vendor_maven_build, jvm_tool: maven, maven: '4.0.0-rc-6'} + - {os: ubuntu-latest, suite: e2e_redirect_maven_build, jvm_tool: maven, maven: '3.9.3'} + - {os: ubuntu-latest, suite: e2e_redirect_maven_build, jvm_tool: maven, maven: '3.9.4'} + - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.6.3', test_filter: '--ignored maven_reactor'} + - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.8.9', test_filter: '--ignored maven_reactor'} + - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.2', test_filter: '--ignored maven_reactor'} + - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '3.9.16', test_filter: '--ignored maven_reactor'} + - {os: ubuntu-latest, suite: e2e_vendor_jvm_build, jvm_tool: maven, maven: '4.0.0-rc-6', test_filter: '--ignored maven_reactor'} + - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} + - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '6.9.4', java: '11', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} + - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} + - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '7.6.6', java: '17', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} + - {os: ubuntu-latest, suite: 'e2e_gradle_discovery_build e2e_gradle_agent_build e2e_redirect_gradle_build', jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_agent_ gradle_hosted_3 gradle_hosted_4 gradle_hosted_5'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} + - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '8.14.3', java: '21', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_hosted_b gradle_hosted_c gradle_hosted_d gradle_hosted_e gradle_hosted_f gradle_hosted_l gradle_hosted_m gradle_hosted_n gradle_hosted_o gradle_hosted_p'} + - {os: ubuntu-latest, suite: e2e_redirect_gradle_build, jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_hosted_ --skip gradle_hosted_3 --skip gradle_hosted_4 --skip gradle_hosted_5 --skip gradle_hosted_b --skip gradle_hosted_c --skip gradle_hosted_d --skip gradle_hosted_e --skip gradle_hosted_f --skip gradle_hosted_l --skip gradle_hosted_m --skip gradle_hosted_n --skip gradle_hosted_o --skip gradle_hosted_p'} + - {os: ubuntu-latest, suite: 'e2e_vendor_gradle_build e2e_vendor_jvm_build', jvm_tool: gradle, gradle: '9.8.0', java: '21', test_filter: '--ignored gradle_vendor_ gradle_multi_project'} + - {os: ubuntu-latest, suite: e2e_sbt_build, jvm_tool: sbt, sbt: '1.13.0', test_filter: '--ignored --test-threads=1'} + - {os: ubuntu-latest, suite: e2e_sbt_vendor_build, jvm_tool: sbt, sbt: '1.13.0', test_filter: '--ignored --test-threads=1'} + - {os: ubuntu-latest, suite: e2e_nuget_dotnet_build, dotnet: '6'} + - {os: ubuntu-latest, suite: e2e_vex_build, test_filter: 'deno:: --ignored', deno: '1.46.3'} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} + # The real-toolchain capstones loop several releases per leg (pip, + # pipenv) or bootstrap a tool from PyPI before the suite (poetry, pdm, + # hatch), hence more than the 25 minutes the older legs needed. + timeout-minutes: 40 + # What .cargo/config.toml's [env] gives processes cargo launches; these + # legs launch the test binaries themselves. + env: *e2e-env + steps: *e2e-steps + e2e-windows: + if: (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: [e2e-build-windows] strategy: fail-fast: false @@ -1799,7 +1830,7 @@ jobs: # The macOS rows run on main, the merge queue and nightly, not on every # PR push, so PRs stop queueing on the small macOS runner pool. e2e-macos: - if: github.event_name != 'pull_request' + if: (github.event_name != 'pull_request') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') # These jobs consume e2e-build's binaries and can run alongside unit tests. needs: [e2e-build-macos] strategy: @@ -2019,7 +2050,8 @@ jobs: # 1.0.2 oldest 1.x; 1.6.0 last that installs nothing for a `file:` # tarball; 1.7.0 first vendored-capable; 1.9.4 last without the # `integrity` line; 1.10.1 first with it; 1.22.22 current. - release: ['1.0.2', '1.6.0', '1.7.0', '1.9.4', '1.10.1', '1.22.22'] + # LEAN SCOPE: the current release only, unless CI_SCOPE=full / nightly. + release: ${{ fromJSON((vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && '["1.0.2","1.6.0","1.7.0","1.9.4","1.10.1","1.22.22"]' || '["1.22.22"]') }} steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -2060,11 +2092,8 @@ jobs: # 4.0.2 bare-hex checksum writer (4.0.0-4.0.2), 4.1.0 first # `10c0/` writer, current, and 4.12.0 on macOS / Windows. The rest # of the spread (4.6.0, 4.12.0 on ubuntu) is yarn-berry-full. - include: - - {os: ubuntu-latest, yarn: '4.0.2'} - - {os: ubuntu-latest, yarn: '4.1.0'} - - {os: ubuntu-latest, yarn: '4.18.0'} - - {os: windows-latest, yarn: '4.12.0'} + # LEAN SCOPE: the newest Linux release only, unless CI_SCOPE=full / nightly. + include: ${{ fromJSON((vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && '[{"os":"ubuntu-latest","yarn":"4.0.2"},{"os":"ubuntu-latest","yarn":"4.1.0"},{"os":"ubuntu-latest","yarn":"4.18.0"},{"os":"windows-latest","yarn":"4.12.0"}]' || '[{"os":"ubuntu-latest","yarn":"4.18.0"}]') }} runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 30 steps: &yarn-berry-steps @@ -2096,7 +2125,7 @@ jobs: # nightly, not on every PR push, so PRs stop queueing on the small # macOS runner pool. yarn-berry-e2e-macos: - if: github.event_name != 'pull_request' + if: (github.event_name != 'pull_request') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') name: yarn-berry ${{ matrix.yarn }} (${{ matrix.os }}) needs: clippy strategy: @@ -2150,12 +2179,8 @@ jobs: strategy: fail-fast: false matrix: - include: - - {os: ubuntu-latest, toolchain: '1.93.1', lock: ''} - - {os: ubuntu-latest, toolchain: '1.93.1', lock: '1'} - - {os: ubuntu-latest, toolchain: stable, lock: '2'} - - {os: ubuntu-latest, toolchain: '1.82.0', lock: '3'} - - {os: ubuntu-latest, toolchain: '1.93.1', lock: '4'} + # LEAN SCOPE: lockfile v4 only, unless CI_SCOPE=full / nightly. + include: ${{ fromJSON((vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && '[{"os":"ubuntu-latest","toolchain":"1.93.1","lock":""},{"os":"ubuntu-latest","toolchain":"1.93.1","lock":"1"},{"os":"ubuntu-latest","toolchain":"stable","lock":"2"},{"os":"ubuntu-latest","toolchain":"1.82.0","lock":"3"},{"os":"ubuntu-latest","toolchain":"1.93.1","lock":"4"}]' || '[{"os":"ubuntu-latest","toolchain":"1.93.1","lock":"4"}]') }} steps: &cargo-vex-steps - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -2218,6 +2243,7 @@ jobs: cargo-vex-matrix-windows: name: cargo ${{ matrix.toolchain }} lock-v${{ matrix.lock || 'own' }} (${{ matrix.os }}) + if: (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: [e2e-build-windows] runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 40 @@ -2232,7 +2258,7 @@ jobs: # The macOS rows run on main, the merge queue and nightly, not per PR push. cargo-vex-matrix-macos: - if: github.event_name != 'pull_request' + if: (github.event_name != 'pull_request') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') name: cargo ${{ matrix.toolchain }} lock-v${{ matrix.lock || 'own' }} (${{ matrix.os }}) needs: [e2e-build-macos] runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} @@ -2294,7 +2320,7 @@ jobs: # Dropping that `needs` also dropped the draft skip it inherited, so # gate on draft here directly (push/merge_group/schedule still run). # Only wait for the clippy preflight. - if: github.event.pull_request.draft != true + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 30 @@ -2358,7 +2384,7 @@ jobs: # ---------------------------------------------------------------------- hosted-e2e: name: hosted-e2e # may be a required check; do not rename - if: github.event.pull_request.draft != true + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} permissions: @@ -2564,7 +2590,7 @@ jobs: ci-ok: name: ci-ok # registered as a required check; do not rename if: always() - needs: [clippy, node-addon, lint-ecosystems, release-readiness, test, test-release, coverage, docker-base, coverage-docker, coverage-merge, dispatch-tests, e2e-build, e2e-build-windows, e2e-build-macos, e2e, e2e-windows, e2e-full, e2e-docker, yarn-classic-matrix, yarn-berry-e2e, yarn-berry-full, cargo-vex-matrix, cargo-vex-matrix-windows, cargo-vex-matrix-full, cargo-old-toolchains, hosted-e2e, e2e-macos, yarn-berry-e2e-macos, cargo-vex-matrix-macos] + needs: [clippy, node-addon, lint-ecosystems, release-readiness, test, test-release, coverage, docker-base, coverage-docker, coverage-merge, dispatch-tests, e2e-build, e2e-build-windows, e2e-build-macos, e2e, e2e-windows, e2e-extended, e2e-full, e2e-docker, yarn-classic-matrix, yarn-berry-e2e, yarn-berry-full, cargo-vex-matrix, cargo-vex-matrix-windows, cargo-vex-matrix-full, cargo-old-toolchains, hosted-e2e, e2e-macos, yarn-berry-e2e-macos, cargo-vex-matrix-macos] runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} timeout-minutes: 5 steps: diff --git a/scripts/tests/test_ci_scheduling.py b/scripts/tests/test_ci_scheduling.py index 1a7b83e67..cc5f5644b 100644 --- a/scripts/tests/test_ci_scheduling.py +++ b/scripts/tests/test_ci_scheduling.py @@ -75,7 +75,9 @@ def test_os_builds_use_the_same_artifact_contract(self): for family in ("e2e", "cargo-vex-matrix"): self.assertIn("pattern: e2e-bin-${{ matrix.os }}*", "\n".join(JOBS[family])) for job in ("e2e-build-macos", "e2e-macos", "cargo-vex-matrix-macos", "yarn-berry-e2e-macos"): - self.assertIn(" if: github.event_name != 'pull_request'", JOBS[job]) + # Never on pull_request; lean scope also skips them (CI_SCOPE). + self.assertIn(" if: (github.event_name != 'pull_request') && (vars.CI_SCOPE == 'full'" + " || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch')", JOBS[job]) def test_row_reader_preserves_both_os_siblings(self): jobs = reader.jobs("""jobs: diff --git a/scripts/tests/test_ci_vlt_rows.py b/scripts/tests/test_ci_vlt_rows.py index 62d325099..c5e7872cd 100644 --- a/scripts/tests/test_ci_vlt_rows.py +++ b/scripts/tests/test_ci_vlt_rows.py @@ -4,6 +4,7 @@ subset they use (no PyYAML on the runners).""" import importlib.util +import json import re import unittest from pathlib import Path @@ -102,6 +103,11 @@ def jobs(text): def matrix_include(job_lines): """The `strategy.matrix.include` rows of a job (flow or block style).""" lines = [strip_comment(l) for l in job_lines] + scoped = next((l for l in job_lines if l.strip().startswith("include: ${{ fromJSON(")), None) + if scoped is not None: + # CI_SCOPE-switched rows: the first JSON literal is the full table. + literal = re.search(r"&& '(\[.*?\])'", scoped).group(1) + return [{k: str(v) for k, v in row.items()} for row in json.loads(literal)] at = next(i for i, l in enumerate(lines) if l.strip() == "include:") base = indent(lines[at]) rows, current, item_indent = [], None, None @@ -129,7 +135,7 @@ def matrix_include(job_lines): def job_rows(jobs_by_id, job): """All rows of a job family, including its independent OS siblings.""" rows = matrix_include(jobs_by_id[job]) - for os_name in ("windows", "macos"): + for os_name in ("windows", "macos", "extended"): sibling = f"{job}-{os_name}" if sibling in jobs_by_id: rows += matrix_include(jobs_by_id[sibling]) From 4455baa315df6b895b9c0e439e89bce3da75899b Mon Sep 17 00:00:00 2001 From: Mikola Lysenko Date: Fri, 9 Oct 2026 17:13:06 -0400 Subject: [PATCH 5/5] Address lean CI review; size up critical-path jobs Review feedback on the lean gate: - hosted-e2e is no longer CI_SCOPE-gated. It always runs again (one Linux job), so the production proof keeps its step-level HOSTED_E2E_DISABLED kill switch and BYPASSED banner as its only bypass. - docker-base still runs on release/v5-prerelease pull requests, so e2e-docker keeps its only full-LTO Docker run there. - ci-vlt-proof-suites.py only drops cells that the lean `e2e` job runs on every pull request. job_rows() gets `extended=False` for that; the bundle and coverage checks still read e2e-extended too. Speed: the lean run's critical path was coverage at 14.2 min on a 4-vCPU runner (e2e-build 4.8 min, clippy 1.7 min), and all three are compile-bound. clippy, coverage, e2e-build and test-release now run on 16-vCPU Depot runners (depot-ubuntu-24.04-16); DISABLE_DEPOT_RUNNERS still falls back to ubuntu-latest. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/ci.yml | 29 +++++++++++++++++------------ scripts/ci-vlt-proof-suites.py | 4 +++- scripts/tests/test_ci_e2e_tiers.py | 7 ++++++- scripts/tests/test_ci_vlt_rows.py | 9 ++++++--- 4 files changed, 32 insertions(+), 17 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 610e115f5..4a61d2694 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -49,22 +49,27 @@ concurrency: # values stay `ubuntu-latest`/`ubuntu-22.04`, so job names, cache keys and # scripts are unchanged; only `runs-on` maps them. Kill switch: set the # repository variable DISABLE_DEPOT_RUNNERS=true to fall back to GitHub-hosted -# runners (the same switch depscan uses). The compatibility workflows follow +# runners (the same switch depscan uses). The compile-bound critical-path +# jobs (clippy, coverage, e2e-build, test-release) use 16-vCPU Depot runners +# (depot-ubuntu-24.04-16). The compatibility workflows follow # the same mapping. Release, publish and merge-queue workflows stay # GitHub-hosted (provenance / write tokens). # LEAN SCOPE (temporary, while org runner capacity is constrained): unless # the repository variable CI_SCOPE is `full`, pull_request, merge_group and -# push runs skip the Windows/macOS legs, the yarn and old-toolchain -# matrices, the sbt Docker coverage slice, test-release and the -# live-production hosted-e2e. They still run in the nightly schedule and -# on workflow_dispatch. Set CI_SCOPE=full to restore the old gate without -# a commit. ci-ok treats skipped jobs as passing. +# push runs use one targeted e2e row per package manager (the rest are in +# e2e-extended), one row each of the yarn and cargo VEX matrices, and skip +# the Windows/macOS legs, test, test-release, old cargo toolchains and the +# sbt Docker coverage slice. Everything runs in the nightly schedule and on +# workflow_dispatch. Set CI_SCOPE=full to restore the old gate without a +# commit. ci-ok treats skipped jobs as passing. hosted-e2e is not scoped: +# it always runs, and its step-level HOSTED_E2E_DISABLED switch is the only +# bypass. jobs: # Required independently of ci-ok so the merge queue sees a compile/lint # failure immediately. Expensive jobs also depend on this preflight. clippy: if: github.event.pull_request.draft != true - runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-16' }} timeout-minutes: 20 steps: - name: Checkout @@ -450,7 +455,7 @@ jobs: # queue already skips this job because each constituent PR ran it. if: (github.event.pull_request.draft != true && github.event_name != 'merge_group') && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') needs: clippy - runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-16' }} strategy: fail-fast: false matrix: @@ -502,7 +507,7 @@ jobs: # numbers are report-only so contributors get visibility without flaky # CI when coverage shifts naturally with test edits. A failing TEST # fails the job: this is the Linux leg of `test`. - runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-16' }} timeout-minutes: 35 permissions: contents: read @@ -608,7 +613,7 @@ jobs: # Dockerfile.base compiles the full-LTO release binary inside Docker, with # no cache. Build it once per run and hand the image to every docker leg. docker-base: - if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') + if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' || github.head_ref == 'release/v5-prerelease') needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-22.04' || 'depot-ubuntu-22.04-4' }} timeout-minutes: 30 @@ -898,7 +903,7 @@ jobs: fail-fast: false matrix: os: [ubuntu-latest] - runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-4' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} + runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS != 'true' && (matrix.os == 'ubuntu-latest' && 'depot-ubuntu-24.04-16' || matrix.os == 'ubuntu-22.04' && 'depot-ubuntu-22.04-4') || matrix.os }} timeout-minutes: 45 env: &e2e-build-env CARGO_PROFILE_DEV_DEBUG: '0' @@ -2384,7 +2389,7 @@ jobs: # ---------------------------------------------------------------------- hosted-e2e: name: hosted-e2e # may be a required check; do not rename - if: (github.event.pull_request.draft != true) && (vars.CI_SCOPE == 'full' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') + if: github.event.pull_request.draft != true needs: clippy runs-on: ${{ vars.DISABLE_DEPOT_RUNNERS == 'true' && 'ubuntu-latest' || 'depot-ubuntu-24.04-4' }} permissions: diff --git a/scripts/ci-vlt-proof-suites.py b/scripts/ci-vlt-proof-suites.py index 6dbc5d138..0b1cf7340 100644 --- a/scripts/ci-vlt-proof-suites.py +++ b/scripts/ci-vlt-proof-suites.py @@ -39,7 +39,9 @@ def proof_upgrade(vlt, node): def ci_cells(text=None): reader = load_reader() - rows = reader.job_rows(reader.jobs(text if text is not None else CI.read_text(encoding="utf-8")), "e2e") + # Only rows that run on every pull request: e2e-extended is CI_SCOPE=full only. + rows = reader.job_rows(reader.jobs(text if text is not None else CI.read_text(encoding="utf-8")), "e2e", + extended=False) return {(r["suite"], r["os"], r["vlt"], r.get("vlt_store_linker", ""), r.get("vlt_upgrade", "")) for r in rows if r.get("vlt") and r.get("test_filter") == "--include-ignored vlt_pinned_matrix"} diff --git a/scripts/tests/test_ci_e2e_tiers.py b/scripts/tests/test_ci_e2e_tiers.py index c995384c0..d4323034a 100644 --- a/scripts/tests/test_ci_e2e_tiers.py +++ b/scripts/tests/test_ci_e2e_tiers.py @@ -329,7 +329,12 @@ def test_upgrade_rule_matches_the_install_step(self): def test_lv0_mode_migration_without_ci_upgrade_stays(self): self.assertIn("mode_migration_vlt", proof.remaining(self.suites, "windows-latest", "1.0.0-rc.14", text=TEXT)) - self.assertNotIn("mode_migration_vlt", proof.remaining(self.suites, "ubuntu-latest", "1.0.0-rc.14", text=TEXT)) + # Lean scope: the rc.14 Linux row is in e2e-extended, which pull + # requests skip, so the proof keeps it. Only rows of the lean `e2e` + # job (here: redirect on vlt 1.2.0) are left out. + self.assertIn("mode_migration_vlt", proof.remaining(self.suites, "ubuntu-latest", "1.0.0-rc.14", text=TEXT)) + self.assertNotIn("e2e_redirect_vlt_build", + proof.remaining(self.suites, "ubuntu-latest", "1.2.0", text=TEXT)) if __name__ == "__main__": diff --git a/scripts/tests/test_ci_vlt_rows.py b/scripts/tests/test_ci_vlt_rows.py index c5e7872cd..cf3dd15af 100644 --- a/scripts/tests/test_ci_vlt_rows.py +++ b/scripts/tests/test_ci_vlt_rows.py @@ -132,10 +132,13 @@ def matrix_include(job_lines): return rows -def job_rows(jobs_by_id, job): - """All rows of a job family, including its independent OS siblings.""" +def job_rows(jobs_by_id, job, extended=True): + """All rows of a job family, including its independent OS siblings. + + `extended=False` leaves out the `-extended` sibling, whose rows run only + with CI_SCOPE=full or nightly, not on every pull request.""" rows = matrix_include(jobs_by_id[job]) - for os_name in ("windows", "macos", "extended"): + for os_name in ("windows", "macos") + (("extended",) if extended else ()): sibling = f"{job}-{os_name}" if sibling in jobs_by_id: rows += matrix_include(jobs_by_id[sibling])