fix(ci): reused sandbox trees to stop fd exhaustion on kata pods

The zig and xwin toolchains stage ~10k-file input trees per action;
building and async-deleting thousands of sandbox trees exhausted file
descriptors (EMFILE in unix_jni during sandbox setup). --reuse_sandbox_directories
under --config=ci removes the churn, with a raise-only ulimit guard in
the bazel-launching steps as belt and braces.
This commit is contained in:
can1357
2026-07-27 12:48:57 +02:00
parent 02c50eb6f3
commit 4fd3662114
3 changed files with 15 additions and 2 deletions
+3
View File
@@ -30,5 +30,8 @@ runs:
shell: bash
run: |
set -euo pipefail
# Raise-only fd guard: huge toolchain input trees exhaust low soft
# limits during sandbox setup.
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
export OMP_BAZEL_RC="${{ steps.cache.outputs.rc }}"
bun scripts/bazel-natives.ts ${{ inputs.targets }} --dest "${{ inputs.dest }}"
+8 -2
View File
@@ -137,7 +137,11 @@ jobs:
with:
scope: validation
- name: Rust tests
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/...
# The ulimit guard runs in the step that launches the bazel server
# (limits are per-process and the server persists across steps).
run: |
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/...
# Clippy scope mirrors `cargo clippy --workspace` (libraries only, no
# test targets) plus the strict/default split: crates with
# `[lints] workspace = true` get the workspace policy, the vendored
@@ -154,7 +158,9 @@ jobs:
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
- name: Warm native addon cache (main push)
if: github.event_name != 'pull_request'
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-all
run: |
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-all
test_workspace:
name: Test TS workspace fast