diff --git a/.bazelrc b/.bazelrc index 2d969543e..2816269e3 100644 --- a/.bazelrc +++ b/.bazelrc @@ -43,6 +43,10 @@ build:ci --announce_rc build:ci --verbose_failures # Fail-fast inside one invocation; job-level matrix provides isolation. build:ci --keep_going=false +# Reuse sandbox trees between actions: the zig/xwin toolchains stage ~10k-file +# input trees per action, and rebuilding+async-deleting them for thousands of +# actions exhausts file descriptors on the kata pods (EMFILE in unix_jni). +build:ci --reuse_sandbox_directories # --- Remote cache ------------------------------------------------------------ # The bazel-remote endpoint is cluster-internal only; .github/actions/bazel-cache diff --git a/.github/actions/bazel-natives/action.yml b/.github/actions/bazel-natives/action.yml index 8250ed3f7..452683e16 100644 --- a/.github/actions/bazel-natives/action.yml +++ b/.github/actions/bazel-natives/action.yml @@ -30,5 +30,8 @@ runs: shell: bash run: | set -euo pipefail + # Raise-only fd guard: huge toolchain input trees exhaust low soft + # limits during sandbox setup. + if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi export OMP_BAZEL_RC="${{ steps.cache.outputs.rc }}" bun scripts/bazel-natives.ts ${{ inputs.targets }} --dest "${{ inputs.dest }}" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6fb022820..4bd12a312 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -137,7 +137,11 @@ jobs: with: scope: validation - name: Rust tests - run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/... + # The ulimit guard runs in the step that launches the bazel server + # (limits are per-process and the server persists across steps). + run: | + if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi + bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/... # Clippy scope mirrors `cargo clippy --workspace` (libraries only, no # test targets) plus the strict/default split: crates with # `[lints] workspace = true` get the workspace policy, the vendored @@ -154,7 +158,9 @@ jobs: run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/... - name: Warm native addon cache (main push) if: github.event_name != 'pull_request' - run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-all + run: | + if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi + bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-all test_workspace: name: Test TS workspace fast