- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
- Updated bazel cache key generation with v2 schema version and streamlined remote cache usage.
- Added native-inputs composite action to centralize change detection and artifact caching.
- Added a scheduled workflow to warm the hosted bazel disk cache.
- Split the rust validation job and integrated prebuilt native addon caching into the CI pipeline.
- Enhance CI workflows to build and reuse native addon artifacts instead of recompiling.
- Update bazel cache actions with selective backend detection and separate remote and disk modes.
- Add `--source` CLI option to install prebuilt native targets without requiring Bazel.
- Increase Kata runner memory configuration from 12Gi to 24Gi.
Four levers on top of the green pipeline:
- kata jobs pass --remote_download_toplevel, so fully cache-hit builds
stay metadata-only instead of pulling every intermediate artifact from
bazel-remote (the bulk of the previous 6-minute TS-only main runs).
- the xwin MSVC splat caches its ~1GiB CDN payload on the runner-cache
PVC (OMP_XWIN_CACHE_DIR), instead of re-downloading per ephemeral pod.
- main-push rust jobs export their bazel disk cache to the GitHub cache
(once per lockfile change, shared linux scope). GitHub only shares
default-branch caches across PRs, and main runs on kata where
actions/cache never saved — so every fresh PR was building cold.
- TS-only pull requests skip Rust validation entirely (gh pr diff path
gate); their test jobs restore addons from the main-exported cache.
Export runs disable top-level-only downloading: remote hits would
otherwise export action entries whose blobs were never materialized.
The zig and xwin toolchains stage ~10k-file input trees per action;
building and async-deleting thousands of sandbox trees exhausted file
descriptors (EMFILE in unix_jni during sandbox setup). --reuse_sandbox_directories
under --config=ci removes the churn, with a raise-only ulimit guard in
the bazel-launching steps as belt and braces.
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
- Enhanced CI workflows and GitHub actions to support native artifact caching and parallel builds.
- Added composite actions and scripts for computing sources, finding artifacts, and managing caches.
- Updated infrastructure documentation and runner deployment scripts with revised resource limits.
- Add scripts/ci-target-cache.ts to snapshot and restore Cargo target directories to S3 storage on omp-kata runners.
- Update .github/actions/build-native/action.yml to support target cache restoration, saving, and compiler launcher configurations.
- Add skip_validation input in GitHub workflow actions to bypass clippy and Rust test checks on release runs.
- Added ensure-cmake action installing pinned cmake/ninja on omp-kata pods; audiopus_sys builds bundled libopus via CMake (Ninja for MSVC cross).
- Set CMAKE_POLICY_VERSION_MINIMUM=3.5 globally and in build-native.ts: the bundled opus tree declares cmake_minimum_required below 3.5, which CMake 4.x refuses.
- Dropped the -C target-cpu=native fallback for non-x64 native builds: it baked build-host CPU features into shipped darwin arm64 addons and trips ring 0.17's aarch64-apple const assertion.
The glibc floor input was applied to every linux row, suffixing musl cross-targets to invalid *-unknown-linux-musl.2.17 triples. Gate the floor on non-musl libc.
Fixes#3367
- Added a paths-ignore filter to the CI workflow to prevent unnecessary runs during vouch bookkeeping commits.
- Ensured that pushes affecting both vouch files and project code continue to trigger the full CI matrix.
- Added a GitHub Action workflow to manage user vouching through discussion comments.
- Created CONTRIBUTING.md to define the vouching policy and workflow for contributors.
- Updated README.md to include instructions on the required vouching process for pull requests.
- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
- Detected the runner environment in CI by checking SCCACHE_BUCKET and exporting an on_infra output.
- Updated the workflow to use the local ensure-sccache action on self-hosted runners and mozilla-actions/sccache-action on GitHub-hosted runners.
Native linux-x64/arm64 builds moved onto the Ubuntu 24.04 (glibc 2.39)
omp-kata runner. The x64 addon was a plain host build that linked the
runner's glibc and failed to dlopen with `version 'GLIBC_2.39' not found`
on older distros; the arm64 cross-build floated up to GLIBC_2.30. Build
the shipped linux-gnu addons through cargo-zigbuild against a pinned 2.17
floor so they load on any glibc >= 2.17.
- build-native.ts: key the tree-sitter-just `-UNDEBUG` CFLAGS off the
bare triple (cargo-zigbuild strips the `.2.17` glibc suffix before
invoking cargo) and symlink the suffixed target dir napi 3.7.0 expects
to the bare dir cargo-zigbuild writes, so postBuild copyArtifact finds
the cdylib.
- build-native action: add a `glibc` input plus a resolve step deriving
the zigbuild cross_target (suffixed) and the rustup bare_target
(stripped); gate zig/cargo-zigbuild install on cross_target so the
host-arch x64 build still runs native Rust tests.
- ci.yml: GLIBC_FLOOR=2.17 fed to the linux-x64 and linux-arm64 native
jobs.
Re-tags 15.13.1, whose release failed at the linux-x64 binary smoke
before any publish step ran.
- Updated bun-install action to set mounted cache mode and use PVC cache paths.
- Removed RustFS Bun restore/save and maintenance scripts, replacing them with mounted cache setup.
- Removed zstd from runner image installation and baked-tool verification checks.
- Updated infra docs to describe split caching with RustFS for sccache and PVC for Bun/Cargo.
Two issues caught in review on #2597:
1. `gh release list` in GitHub Actions requires GH_TOKEN. The release
notes step in `.github/workflows/ci.yml` had no env block, so gh would
exit non-zero and the script's silent fallback would re-strand the
silent-tag entries this change is meant to recover. Pass
`GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` to the step.
2. Silently degrading to legacy single-version output on gh failure is
itself the regression vector — a future token misconfig or gh outage
would lose data with no signal. `resolvePublishedFloorTag` now throws
on gh failure with an actionable hint ("pass GH_TOKEN in Actions; set
OMP_RELEASE_NOTES_FLOOR= locally to opt into legacy mode"). The
thrown error propagates out of `main` and exits non-zero, failing the
CI step loudly so the release is rebuilt with the fix.
The legitimate null path is preserved: `OMP_RELEASE_NOTES_FLOOR=`
(empty) still forces single-version mode, and a successful gh call with
no candidate < target still returns null (first-ever publish case).
Verified locally: hiding gh from PATH now exits 1 with the hint;
`OMP_RELEASE_NOTES_FLOOR=` with hidden gh still produces the legacy
84-bullet single-version output.
Refs #2596
- Added composite GitHub actions to ensure rust toolchains and cargo helpers.
- Added a kata-native build action with variant checks and platform artifact uploads.
- Reworked CI matrices to split native cross-platform jobs and gate releases accordingly.
- Updated runner bootstrap and image to preinstall pinned build tools for CI consistency.
- Updated the bun-install composite action to detect preinstalled Bun and only fetch it when missing.
- Added cache-backend detection and wiring so Bun dependencies use RustFS cache when SCCACHE credentials are present.
- Conditionally skipped rust-cache in build-native and CI jobs when shared sccache runners are available, relying on the existing RustFS/sccache layer instead.
- Updated CI dependency install flow to share bun cache orchestration across jobs.
- Added RustFS-backed bun cache restore/save script keyed by bun.lock hash.
Self-hosted omp-kata runners now inject a shared S3 (RustFS, in-cluster)
sccache backend via pod env (SCCACHE_BUCKET/ENDPOINT/REGION + AWS creds).
The Enable-sccache step branches on SCCACHE_BUCKET: when set, sccache reads
the S3 config from the inherited environment; otherwise GitHub-hosted
runners (macOS, ubuntu-arm) keep the GHA cache backend since they can't
reach the private RustFS.
- Renamed the coding-agent native job and bucket names from tooling to unit in CI.
- Removed test_coding_agent_fast from the release job dependency list and gating condition.
- Added a setup-system-deps action with preloaded-runner guards and apt fallbacks.
- Updated CI workflows to download Linux x64 native artifacts and gate on native job success.
- Renamed coding-agent fast mode to singleton in scripts and test partitioning logic.
- Added settings test-state begin/restore helpers with recursive cleanup in affected tests.
- Added a mode-based `ci-test-ts.ts` runner with `--dry-run` support.
- Partitioned coding-agent tests into fast/ui/runtime/native/heavy buckets and separated workspace/native runs.
- Added coding-agent bucket modes that fail CI when a target bucket has no matching tests.
- Updated CI scripts/workflow to run the new TS buckets, use `omp-kata`, and gate releases on them.
- Updated the CI workflow concurrency rules to treat `workflow_dispatch` like a release path, grouping those runs by SHA and disabling cancel-in-progress.
- Extended the `GhaEval` expression evaluator in `scripts/ci-concurrency.test.ts` to support `==`/`!=` and align falsy checks.
- Added a regression test covering tagged-main `workflow_dispatch` runs using the release-style concurrency behavior.
The workflow-wide concurrency group was `${{ github.workflow }}-${{ github.ref }}`
with `cancel-in-progress: true`, so the release-script's atomic
`refs/heads/main + v* tag` push shared the `CI-refs/heads/main` group with every
later main push. The newer run cancelled the older release run before
`release_binary` / `release_github` / `release_npm` could execute, and no
future run carried the tag at HEAD, so the tag stayed published-as-a-ref but
unreleased on GitHub and npm (v15.12.6 in the wild).
Release runs are now routed to a per-sha group with `cancel-in-progress: false`
when either:
* the push subject starts with `chore: bump version to ` (the release-script
commit convention from scripts/release.ts), or
* `github.ref` is a `v*` tag (workflow_dispatch recovery from a tag ref).
Other events keep the cheap branch-wide cancel-in-progress for PR/main churn.
release.ts's retry hint now uses the same release commit subject so manual
retries also land in the per-sha group.
Added scripts/ci-concurrency.test.ts: a regression test with a minimal GHA
expression evaluator that asserts the resolved group / cancel-in-progress for
auto-release pushes, retry pushes, tag-ref dispatches, plain main pushes, PRs,
distinct release shas, and a benign `revert: chore: bump version to ...`
follow-up.
Fixes#2564
The pi-coding-agent prepack (bundle-dist.ts) imports the pi-utils barrel,
which eagerly loads the pi-natives addon; release_npm never downloaded the
linux x64 .node artifacts, so the publish died in prepack. Mirror the
test job's download-artifact step (release runs always rebuild natives in
the same run, so the default run-id resolves).
- Renamed the gate and native jobs in CI for consistent release naming.
- Renamed reusable-artifact output keys for native lookup compatibility.
- Rewired release and test jobs to read tags, flags, and hashes from metadata outputs.
- Updated the `release_brew` job to depend on `release_github_verify` instead of `release-github`.
- Changed the job guard so the tap release now requires `release_github_verify` to report success before running.
- Updated the workflow comment to describe that tap publishing is gated by verified release binaries.
- Added macOS CI signing and notarization steps when APPLE_* secrets are configured.
- Added strict darwin verification checks to reject ad-hoc signatures and run smoke tests.
- Added Homebrew formula publishing from release assets with SHA-256 checksums.
- Added helper scripts for signing secret upload, entitlements, and release workflows.
- Removed `tags: ["v*"]` trigger; release now fires from the single atomic `main` push that carries the tag.
- Replaced `gate.skip` with `gate.is-release` and `gate.release-tag` so downstream jobs detect the tag via `git tag --points-at HEAD`.
- Passed `release-tag` explicitly to release steps (gh-release, curl, release notes) since `github.ref` is now `refs/heads/main`, not the tag.
- Fixed rust-cache key collision on macOS x64 by setting `RUSTFLAGS` (target-cpu) before cache restore and including the native source hash in the shared key.
- CI now enabled OIDC publishing in the build matrix, installed Node 24/npm, and added a per-target native addon publish step.
- The release script now accepts `--native-leaf <tag>` and publishes only the matching generated native leaf package.
- Native package generation gained optional tag filtering with validation of requested leaf tags for targeted release publishing.
- Added a workflow `gate` job that marks `main` pushes with a `v*` tag at `HEAD` as duplicate release runs.
- Conditioned native, lint/test, and install CI jobs on that gate so redundant build and publish work is skipped on duplicate tagged pushes.
- Updated `scripts/ci-release-publish.ts` to publish packed tarballs via `npm publish` after `bun pm pack`, handling already-published versions as a no-op.
- sccache silently skips caching when incremental compilation is enabled, making the wrapper a no-op.
- Applied fix to both the shared build-native action and the CI workflow setup step.
- Updated the build-native action to install cargo-zigbuild for non-MSVC targets and cargo-xwin with LLVM tooling for MSVC targets.
- Removed the fixed aarch64 linker variable and narrowed Rust test execution to skip duplicate macOS runs.
- Reworked CI matrices to build win32-x64 artifacts on ubuntu with x86_64-pc-windows-msvc and simplified smoke testing to skip those Windows binaries via matrix gating.