ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks. - Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe. - Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
This commit is contained in:
@@ -4,13 +4,33 @@ name: Warm bazel disk cache
|
||||
# actions/cache entries created on the default branch. Bazel action keys do
|
||||
# not transfer across runner environments (a kata-produced disk cache misses
|
||||
# every action on ubuntu-22.04), so seed the disk cache from the same image
|
||||
# PR jobs run on. A warm run restores the exact-key archive, builds
|
||||
# incrementally, and saves nothing; a lockfile/config change misses, rebuilds,
|
||||
# and saves the new key.
|
||||
# PR jobs run on. Runs the full hosted action set — Rust validation (test,
|
||||
# clippy, rustfmt) plus the native addons — so one exact-key archive covers
|
||||
# both rust_validate and native_addons for this source generation. The v3
|
||||
# key embeds a crates/** source fingerprint, so a native change on main
|
||||
# means an exact miss: the build seeds from the previous generation via the
|
||||
# config-scoped prefix and the refreshed archive is saved. An exact hit
|
||||
# makes every invocation a cache replay and saves nothing.
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "23 */6 * * *"
|
||||
push:
|
||||
branches: [main]
|
||||
paths:
|
||||
- "packages/**"
|
||||
- "crates/**"
|
||||
- "scripts/**"
|
||||
- "bazel/**"
|
||||
- "MODULE.bazel"
|
||||
- "MODULE.bazel.lock"
|
||||
- "BUILD.bazel"
|
||||
- ".bazelrc"
|
||||
- ".bazelignore"
|
||||
- ".bazelversion"
|
||||
- "Cargo.toml"
|
||||
- "Cargo.lock"
|
||||
- "rust-toolchain.toml"
|
||||
- "rustfmt.toml"
|
||||
- ".github/**"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
@@ -30,10 +50,26 @@ jobs:
|
||||
uses: ./.github/actions/bazel-cache
|
||||
with:
|
||||
scope: linux
|
||||
- name: Build native addons
|
||||
# Invocation set mirrors the hosted CI jobs (rust_validate +
|
||||
# native_addons) so the saved archive serves both.
|
||||
- name: Rust tests
|
||||
run: |
|
||||
set -euo pipefail
|
||||
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
|
||||
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/...
|
||||
- name: Clippy (workspace lint policy on opted-in crates)
|
||||
run: |
|
||||
bazelisk query "kind('rust_library|rust_shared_library', //crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...)" \
|
||||
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy-strict --
|
||||
- name: Clippy (default lints elsewhere)
|
||||
run: |
|
||||
bazelisk query "kind('rust_library|rust_shared_library', //crates/... - (//crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...) - //crates/vendor/brush-core/... - //crates/vendor/brush-builtins/...)" \
|
||||
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy --
|
||||
- name: Rustfmt
|
||||
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
|
||||
- name: Build native addons
|
||||
run: |
|
||||
set -euo pipefail
|
||||
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build //:natives-linux-x64-baseline //:natives-linux-x64-modern
|
||||
- name: Save bazel disk cache
|
||||
if: steps.cache.outputs.save-needed == 'true'
|
||||
|
||||
@@ -9,12 +9,15 @@ on:
|
||||
- "scripts/**"
|
||||
- "bazel/**"
|
||||
- "MODULE.bazel"
|
||||
- "MODULE.bazel.lock"
|
||||
- "BUILD.bazel"
|
||||
- ".bazelrc"
|
||||
- ".bazelignore"
|
||||
- ".bazelversion"
|
||||
- "Cargo.toml"
|
||||
- "Cargo.lock"
|
||||
- "Cargo.Bazel.lock"
|
||||
- "rust-toolchain.toml"
|
||||
- "rustfmt.toml"
|
||||
- ".github/**"
|
||||
pull_request:
|
||||
branches: [main]
|
||||
@@ -24,12 +27,15 @@ on:
|
||||
- "scripts/**"
|
||||
- "bazel/**"
|
||||
- "MODULE.bazel"
|
||||
- "MODULE.bazel.lock"
|
||||
- "BUILD.bazel"
|
||||
- ".bazelrc"
|
||||
- ".bazelignore"
|
||||
- ".bazelversion"
|
||||
- "Cargo.toml"
|
||||
- "Cargo.lock"
|
||||
- "Cargo.Bazel.lock"
|
||||
- "rust-toolchain.toml"
|
||||
- "rustfmt.toml"
|
||||
- ".github/**"
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
@@ -160,6 +166,11 @@ jobs:
|
||||
- name: Rustfmt
|
||||
if: steps.inputs.outputs.rust == 'true'
|
||||
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
|
||||
# No disk-cache save here: native_addons saves this same key
|
||||
# concurrently, and an immutable archive can have only one producer
|
||||
# per key — a validation-only archive winning the race would
|
||||
# suppress the addon half on every later exact hit. Validation
|
||||
# actions are seeded by the main cache warmer's combined archive.
|
||||
|
||||
# Builds the native addons every downstream job installs. TS-only PRs
|
||||
# restore the prebuilt Linux x64 pair published by trusted main builds
|
||||
@@ -264,7 +275,10 @@ jobs:
|
||||
if: steps.decide.outputs.needed == 'true'
|
||||
shell: bash
|
||||
run: |
|
||||
summary=$(grep -E "INFO: [0-9]+ processes:" "$RUNNER_TEMP/bazel-build.log" | tail -1 || true)
|
||||
# Bazel runs with --color=yes (config=ci); strip ANSI before
|
||||
# matching — escapes split "INFO:" from the process count in
|
||||
# the raw log.
|
||||
summary=$(sed -E 's/\x1b\[[0-9;]*m//g' "$RUNNER_TEMP/bazel-build.log" | grep -E '[0-9]+ processes:' | tail -1 || true)
|
||||
echo "::notice title=Bazel build summary::${summary:-no process summary found}"
|
||||
- name: Save Bazel disk cache
|
||||
if: steps.cache.outputs.save-needed == 'true'
|
||||
|
||||
Reference in New Issue
Block a user