Files
oh-my-pi/.bazelrc
T
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00

68 lines
3.2 KiB
Plaintext

# Bazel build configuration for the pi-natives NAPI addon pipeline.
# Cross targets, ISA variants, and release codegen are encoded in the
# //:natives-* addon targets (bazel/defs.bzl transition), so a bare
# `bazel build //:natives-<target>` is always release-grade.
common --enable_platform_specific_config
# Hermetic-ish action env: no host env leaks into action keys. Build scripts
# that need host tools (cmake for audiopus_sys' bundled opus) get an explicit
# PATH through crate annotations in MODULE.bazel.
build --incompatible_strict_action_env
# NOTE: rust pipelined_compilation stays OFF: handing dependents rmeta-only
# crates breaks `rust_test(crate = ...)` harness compiles whose deps export
# macro_rules! ("can't find crate" at macro expansion).
# Keep rustc errors readable.
build --@rules_rust//rust/settings:error_format=human
# Generated toolchains carry target_settings requiring the nightly channel.
build --@rules_rust//rust/toolchain/channel=nightly
# --- Rust validation (replaces cargo clippy/nextest in CI) --------------------
# Mirrors cargo semantics: crates with `[lints] workspace = true` (pi-ast,
# pi-iso, pi-natives, pi-shell, pi-walker) get the strict workspace policy
# (clippy-strict; bazel/clippy.bazelrc is generated from Cargo.toml); everything
# else gets default clippy + -Dwarnings (clippy).
build:clippy --aspects=@rules_rust//rust:defs.bzl%rust_clippy_aspect
build:clippy --output_groups=+clippy_checks
build:clippy --@rules_rust//rust/settings:clippy_flag=-Dwarnings
build:clippy-strict --config=clippy
import %workspace%/bazel/clippy.bazelrc
# rustfmt check via aspect, against the workspace rustfmt.toml.
build:rustfmt --aspects=@rules_rust//rust:defs.bzl%rustfmt_aspect
build:rustfmt --output_groups=+rustfmt_checks
build:rustfmt --@rules_rust//rust/settings:rustfmt.toml=//:rustfmt.toml
test --test_output=errors
test --test_summary=terse
# --- CI base -----------------------------------------------------------------
build:ci --curses=no --color=yes --show_timestamps
build:ci --announce_rc
build:ci --verbose_failures
# Fail-fast inside one invocation; job-level matrix provides isolation.
build:ci --keep_going=false
# --- Remote cache ------------------------------------------------------------
# The bazel-remote endpoint is cluster-internal only; .github/actions/bazel-cache
# composes endpoint + credentials into an rc fragment on omp-kata pods.
# GitHub-hosted runners never use a remote cache (actions/cache-backed
# --disk_cache instead). These configs carry only the policy bits.
#
# cache-rw: trusted in-cluster writers (omp-kata pods).
build:cache-rw --remote_upload_local_results=true
build:cache-rw --remote_local_fallback
# cache-ro: read-only consumers (e.g. local dev via .bazelrc.user + VPN/tailnet).
build:cache-ro --remote_upload_local_results=false
build:cache-ro --remote_local_fallback
# Don't let a cache outage fail the build.
build:cache-rw --remote_retries=2
build:cache-ro --remote_retries=2
build:cache-rw --remote_timeout=60s
build:cache-ro --remote_timeout=60s
# --- Local development ---------------------------------------------------------
# Optional user overrides (remote cache endpoint, disk cache, etc.).
try-import %workspace%/.bazelrc.user