Repository navigation
ci(release): one cached Linux build and non-blocking reproducibility - #73
leoisadev1 wants to merge 4 commits into
Conversation
Stop the Linux release path from rebuilding twice from cold. Publish from a single cached build, move compare.py to a dispatch-only reproducibility workflow, and switch Tenki jobs to GitHub-hosted runners. Fixes CNV-47. Co-authored-by: Leo <leoisadev1@users.noreply.github.com>
| key=$(mktemp) | ||
| chmod 600 "$key" | ||
| bun run update:keygen "$key" |
There was a problem hiding this comment.
🔴 Linux reproducibility fails before building
Every Linux reproducibility dispatch fails when update:keygen receives the existing file created by mktemp. Its exclusive file creation rejects that path, so neither rebuild runs.
Learn more
The Linux reproducibility job needs one temporary Ed25519 seed shared by both builds. mktemp creates a file, while keygen writes its seed with flag: "wx", which rejects any existing file. The first key generation exits before either build starts. The release Linux workflow removes its placeholder before invoking the same command.
Example: Dispatch with platform=linux. mktemp creates /tmp/tmp.example; update:keygen /tmp/tmp.example fails with EEXIST. No artifacts reach the comparison.
Recommended fix: Remove the placeholder before calling update:keygen, as in Prepare external update seed, while keeping the generated seed outside the checkout.
| key=$(mktemp) | |
| chmod 600 "$key" | |
| bun run update:keygen "$key" | |
| key=$(mktemp) | |
| chmod 600 "$key" | |
| rm "$key" | |
| bun run update:keygen "$key" |
Was this helpful? React with 👍 or 👎 to provide feedback.
| function Invoke-UnsignedWindows($Destination) { | ||
| if (Test-Path packaging/out/windows) { Remove-Item -Recurse -Force packaging/out/windows } | ||
| ./packaging/windows/build.ps1 -VerificationOnly | ||
| ./packaging/windows/installer.ps1 | ||
| New-Item -ItemType Directory -Force $Destination | Out-Null | ||
| Copy-Item packaging/out/windows/*.msi $Destination | ||
| } | ||
| Invoke-UnsignedWindows packaging/out/windows-a | ||
| Invoke-UnsignedWindows packaging/out/windows-b |
There was a problem hiding this comment.
|
The first PR run sat on apt-get install ffmpeg for 40+ minutes on ubuntu-24.04. Bound each attempt and retry so a stuck mirror cannot hold the job. Co-authored-by: Leo <leoisadev1@users.noreply.github.com>
update:keygen refuses an existing mktemp file, so Linux compare never ran. Also queue the umbrella Release instead of cancelling a live publish on a same-version push, drop prefix cache restores that can leave stale pinned downloads, and wipe target/ between Windows compare builds. Co-authored-by: Leo <leoisadev1@users.noreply.github.com>
Leo's Tenki sponsorship means runner cost is not the problem. Put CI, Release preflight/publish and version-packages back on the same Tenki labels as main, restore actionlint.yaml, and drop the GitHub-hosted apt retry. The single cached Linux build and dispatch-only reproducibility workflow stay. Co-authored-by: Leo <leoisadev1@users.noreply.github.com>
Fixes CNV-47
Summary
Linux release CI was spending ~2.5h on two cold full builds, then
compare.pyfailed the job and skippedlinux-release-review. That blocking double-build is gone from the publish path. Runners are unchanged from main (Tenki for CI / umbrella Release / version-packages; GitHub-hosted for the platform release jobs).packaging/.cacheinputs, and the container Cargotargetat$RUNNER_TEMP/convt-linux-compile(outside the checkout so it cannot enter the source tarball).Release reproducibility) isworkflow_dispatchonly — no schedule. It rebuilds twice from cold, runscompare.pyon Linux, and compares unsigned Mac/Windows artifacts. It fails only itself and still uploads both trees when the compare fails. It uses the same runners as the platform release jobs (ubuntu-24.04,macos-15,windows-latest).group= workflow + ref + version). The umbrellaReleasequeues (cancel-in-progress: false) so a same-version desktop/Cargo.lockpush cannot abort a live publish. No auto-retry.source-audit.json,release-manifest.json,update-manifest.json, artifact namelinux-release-review,SOURCE_DATE_EPOCH, signing, package contents.Mac and Windows never had a double-build gate on the release path. They now get rust-cache / bun cache, and Mac/Windows unsigned pairs are in the dispatch-only repro workflow.
Do not dispatch, cancel, or rerun Build release linux / Release on
main. This PR does not merge.Evidence
python3 -m unittest discover -s scripts/release -p 'test_*.py' -v— 27 tests, OK (test_workflows.py: one Linux build, dispatch-only repro, artifact names preserved; no assertion that runners must be free).python3 -m unittest discover -s packaging/release -p 'test_*.py'— OK. AppImage runtime skip lives inappimage.shso the hash-pinnedappimage-source-build.pyrecipe is unchanged.PR CI 37686580423 is green on the restored Tenki labels (Release scripts 6s, Web 3m, Linux rust ~1m, Windows rust ~4m, macOS rust ~5m).
Review follow-up kept from
4ee2c0f:rms themktempplaceholder beforeupdate:keygen(wxrefuses an existing file).Releasequeues instead of cancelling.restore-keysthat can restore a stalepdfium.tgz).target/before each build.publish(contents: write).Cold vs warm timings (estimated; dry-run dispatch on this branch was not started):
rebuild-linux-source.sh/rebuild-cli.shstill compile CLI/app from empty caches insiderelease-linux.shMerge Danger
Door: two-way for workflows. After merge, the next Linux release on main is one cached build and will not run
compare.py. Byte drift will not fail publish; catch it by dispatchingRelease reproducibility.Blast radius: GitHub Actions only, plus
appimage.shcache-hit skip (runtime still verified againstruntime_sha256) and docs. No signing, no package payload, nocompare.pylogic, no published v0.2.0 assets. Compile cache is$RUNNER_TEMP/convt-linux-compile— not in the frozen tree.source.pyalready dropstarget/and.cache(#64/#65). Runners match main.Runners
Unchanged from main.
Optional: faster Tenki sizes
Not switched in this PR. From Tenki runner sizes:
tenki-standard-large-8c-16g(8c/16G)tenki-standard-large-plus-16c-32g(16c/32G)cargo testof the workspace. Tenki’s own guide puts Rust compiles on large or large-plus. Roughly 20–40% wall-clock if the suite is CPU-bound.tenki-macos-26-medium(6c/16G)tenki-macos-26-large(8c/32G)publishtenki-standard-large-8c-16gtenki-standard-large-plus-16c-32gcargo fetch+ manifest work; little to gain.preflight/ CI Web / Version packagestenki-standard-medium-4c-8gLinux release itself stays on GitHub-hosted
ubuntu-24.04(Tenki’s crates.io proxy breaks the offline build container). A bigger Tenki box would not apply there unless that proxy issue is solved. The remaining Linux floor after cache is the empty-cache source proofs, which more cores help only a little.