From 8924181a571486d50be442d155a3c1fac97ebb6b Mon Sep 17 00:00:00 2001 From: matejsemancik Date: Wed, 7 Oct 2026 13:46:00 +0200 Subject: [PATCH 1/3] ci(ios-kmp): cache Kotlin/Native library caches in PR checks Debug framework links build a native cache for every library dependency in ~/.konan/.../klib/cache. Self-hosted runners start from a fresh VM, so every PR check rebuilt them: ~4 of the ~4m40s link in uniapp-kmp (Compose Multiplatform), against 28s with the caches present. The new opt-in `kotlin_native_cache` input caches only those library caches (~340 MB), keyed on libs.versions.toml without a restore-keys fallback so outdated library versions do not accumulate. The compiler distribution and LLVM (~16s to download) are left out: restoring them would cost about as much as it saves. --- .github/workflows/ios-kmp-selfhosted-test.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.github/workflows/ios-kmp-selfhosted-test.yml b/.github/workflows/ios-kmp-selfhosted-test.yml index aa32f9a..c7ac754 100644 --- a/.github/workflows/ios-kmp-selfhosted-test.yml +++ b/.github/workflows/ios-kmp-selfhosted-test.yml @@ -46,6 +46,11 @@ on: description: "Path to directory containing Fastfile. If not specified, uses iosApp. Example: iosApp/appA" type: string required: false + kotlin_native_cache: + description: "Whether to cache the Kotlin/Native compiler caches of library dependencies (~/.konan/.../klib/cache) between runs. A debug framework link on a fresh runner otherwise rebuilds them every time, which can take several minutes for large dependency graphs like Compose Multiplatform." + type: boolean + required: false + default: false secrets: GRADLE_CACHE_ENCRYPTION_KEY: @@ -74,6 +79,16 @@ jobs: uses: gradle/actions/setup-gradle@v5 with: cache-encryption-key: ${{ secrets.GRADLE_CACHE_ENCRYPTION_KEY }} + # Only the caches of library dependencies (`*-user*`) are built during the link; the compiler, + # platform klibs and their caches come with the Kotlin/Native distribution. Library caches live in + # per-version folders, so the key changes with libs.versions.toml and has no restore-keys fallback: + # a partial restore would carry outdated library versions into every new cache. + - name: Cache Kotlin/Native library caches + if: ${{ inputs.kotlin_native_cache }} + uses: actions/cache@v6 + with: + path: ~/.konan/kotlin-native-prebuilt-*/klib/cache/*-user* + key: konan-klib-cache-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/libs.versions.toml') }} - name: Build KMP Package if: ${{ inputs.kmp_swift_package_integration }} env: From 89bdadb975da987d506919bc15934859c72d8466 Mon Sep 17 00:00:00 2001 From: matejsemancik Date: Wed, 7 Oct 2026 15:41:25 +0200 Subject: [PATCH 2/3] Flip kotlin_native_cache to true --- .github/workflows/ios-kmp-selfhosted-test.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ios-kmp-selfhosted-test.yml b/.github/workflows/ios-kmp-selfhosted-test.yml index c7ac754..f3beb5f 100644 --- a/.github/workflows/ios-kmp-selfhosted-test.yml +++ b/.github/workflows/ios-kmp-selfhosted-test.yml @@ -50,7 +50,7 @@ on: description: "Whether to cache the Kotlin/Native compiler caches of library dependencies (~/.konan/.../klib/cache) between runs. A debug framework link on a fresh runner otherwise rebuilds them every time, which can take several minutes for large dependency graphs like Compose Multiplatform." type: boolean required: false - default: false + default: true secrets: GRADLE_CACHE_ENCRYPTION_KEY: From 9d90ef18cd45a0ce27c48d9c13f47d958bf1bc0f Mon Sep 17 00:00:00 2001 From: matejsemancik Date: Wed, 7 Oct 2026 15:45:31 +0200 Subject: [PATCH 3/3] docs(claude): never mention internal projects in this public repository --- CLAUDE.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/CLAUDE.md b/CLAUDE.md index 7968b0c..e8d8820 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -137,6 +137,9 @@ All iOS actions support: ## Important Conventions +### Public Repository +This repository is public and open source. Never mention internal or client projects (repository names, app names, bundle IDs, ticket keys), internal discussions or decisions, or private infrastructure details anywhere they end up public: code, comments, commit messages, PR titles and descriptions, issues and release notes. Describe the situation generically instead, e.g. "a Compose Multiplatform project with ~130 library dependencies" rather than the project's name. + ### Secrets Management - iOS workflows require App Store Connect API keys and Match password - Android workflows require keystore passwords and Google Play service account JSON