perf(ci): cut warm CI time via download-skipping, splat reuse, PR gating

Four levers on top of the green pipeline:
- kata jobs pass --remote_download_toplevel, so fully cache-hit builds
  stay metadata-only instead of pulling every intermediate artifact from
  bazel-remote (the bulk of the previous 6-minute TS-only main runs).
- the xwin MSVC splat caches its ~1GiB CDN payload on the runner-cache
  PVC (OMP_XWIN_CACHE_DIR), instead of re-downloading per ephemeral pod.
- main-push rust jobs export their bazel disk cache to the GitHub cache
  (once per lockfile change, shared linux scope). GitHub only shares
  default-branch caches across PRs, and main runs on kata where
  actions/cache never saved — so every fresh PR was building cold.
- TS-only pull requests skip Rust validation entirely (gh pr diff path
  gate); their test jobs restore addons from the main-exported cache.

Export runs disable top-level-only downloading: remote hits would
otherwise export action entries whose blobs were never materialized.
This commit is contained in:
can1357
2026-07-27 14:31:24 +02:00
parent ae01a76136
commit a7abeff1b7
4 changed files with 114 additions and 23 deletions
+40 -12
View File
@@ -131,12 +131,37 @@ jobs:
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/bun-install
# TS-only PRs skip Rust validation entirely; addons for the TS test
# jobs come from the main-exported disk cache. Pushes always run.
- name: Detect Rust-affecting changes
id: changes
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
if [ "${{ github.event_name }}" != "pull_request" ]; then
echo "rust=true" >> "$GITHUB_OUTPUT"
exit 0
fi
if gh pr diff ${{ github.event.pull_request.number }} --name-only \
| grep -qE '^(crates/|Cargo\.(toml|lock)|Cargo\.Bazel\.lock|MODULE\.bazel|BUILD\.bazel|\.bazelrc|\.bazelversion|bazel/|rust-toolchain\.toml|rustfmt\.toml|scripts/bazel-natives|\.github/actions/bazel-|\.github/workflows/ci\.yml)'; then
echo "rust=true" >> "$GITHUB_OUTPUT"
else
echo "No Rust-affecting changes; skipping validation."
echo "rust=false" >> "$GITHUB_OUTPUT"
fi
- if: steps.changes.outputs.rust == 'true'
uses: ./.github/actions/bun-install
- id: cache
if: steps.changes.outputs.rust == 'true'
uses: ./.github/actions/bazel-cache
with:
scope: validation
scope: linux
# Main pushes export the disk cache PRs restore (once per
# lockfile change; no-op otherwise).
export: ${{ github.event_name != 'pull_request' }}
- name: Rust tests
if: steps.changes.outputs.rust == 'true'
# The ulimit guard runs in the step that launches the bazel server
# (limits are per-process and the server persists across steps).
run: |
@@ -147,14 +172,17 @@ jobs:
# `[lints] workspace = true` get the workspace policy, the vendored
# brush fork is exempt (same as run-rs-task.ts's cargo excludes).
- name: Clippy (workspace lint policy on opted-in crates)
if: steps.changes.outputs.rust == 'true'
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy-strict --
- name: Clippy (default lints elsewhere)
if: steps.changes.outputs.rust == 'true'
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/... - (//crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...) - //crates/vendor/brush-core/... - //crates/vendor/brush-builtins/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy --
- name: Rustfmt
if: steps.changes.outputs.rust == 'true'
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
- name: Warm native addon cache (main push)
if: github.event_name != 'pull_request'
@@ -175,7 +203,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test workspace packages and repo scripts (TS)
env:
OMP_TEST_CONCURRENCY: "4"
@@ -194,7 +222,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test coding-agent singleton/global-state bucket
# Keep global Settings/env/fake-timer tests serial; native addon
# artifacts are still available like every other coding-agent bucket.
@@ -213,7 +241,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test native/TUI/browser-ish packages (TS)
env:
OMP_TEST_CONCURRENCY: "4"
@@ -232,7 +260,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test coding-agent UI/TUI bucket
env:
OMP_TEST_CONCURRENCY: "2"
@@ -251,7 +279,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test coding-agent runtime bucket
# Runtime/session tests import native-backed barrels too; keep this
# separate for concurrency, not as a native-free guardrail.
@@ -272,7 +300,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Test coding-agent native/unit bucket
env:
OMP_TEST_CONCURRENCY: "4"
@@ -291,7 +319,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: CLI smoke test
run: bun run ci:test:smoke
@@ -307,7 +335,7 @@ jobs:
- uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Install method smoke tests
env:
OMP_INSTALL_TEST_SKIP_NATIVE_BUILD: "1"
@@ -421,7 +449,7 @@ jobs:
uses: ./.github/actions/bazel-natives
with:
targets: ${{ matrix.native_targets }}
cache-scope: release-${{ matrix.target_id }}
cache-scope: ${{ startsWith(matrix.target_id, 'darwin') && format('release-{0}', matrix.target_id) || 'linux' }}
- name: Build release binary
env:
RELEASE_TARGETS: ${{ matrix.target_id }}
@@ -588,7 +616,7 @@ jobs:
uses: ./.github/actions/bazel-natives
with:
targets: linux-x64-baseline linux-x64-modern
cache-scope: linux-x64-pair
cache-scope: linux
- name: Publish to npm
env:
# Fallback auth: setup-node wrote an .npmrc referencing