Skip to content

ci: parallelize selected PR checks and simplify contributor docs - #379

Merged
thomasklemm merged 18 commits into
rubys:mainfrom
thomasklemm:thomasklemm/pr-ci-parallelism
Oct 3, 2026
Merged

thomasklemm merged 18 commits into
rubys:mainfrom
thomasklemm:thomasklemm/pr-ci-parallelism

Conversation

@thomasklemm

@thomasklemm thomasklemm commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Reduce PR feedback latency without dropping coverage or running every target unnecessarily. At the same time, replace the historical development/CI documentation sprawl with concise contributor guidance and executable contracts owned by the code.

Changes

  • Start selected producers and comparisons when their inputs are ready, rather than after Unit. Build a same-run debug compiler independently for Campfire consumers.
  • Split all integration targets across three bounded Unit shards, retaining library/binary tests, the debug bench gate, failure propagation, and complete target coverage. Run the three Campfire GC comparisons concurrently; allow all seven selected extra comparisons to start in parallel.
  • Preserve change-based job selection. Unlabeled drafts retain the fixture/Unit floor; ci:full also expands drafts. Keep publication permissions and gates separate from PR validation.
  • Reuse compiled gems for archive smoke while still extracting fresh archives and executing every README command. Key uv's download cache to the emitted Python dependency template instead of nonexistent repository manifests.
  • Standardize active Node workflows and generated prerequisites on Node 24; update compatible Actions. Centralize CI MRI selection and the local Ruby minimum, leaving JRuby and exact reproduction pins separate.
  • Isolate both Active Storage roots for parallel interpreted Campfire files, with unchanged Ruby launch arguments, identity, environment, and deterministic results. Keep Spinel execution serial and fall back to serial when mount isolation is unavailable.
  • Simplify and reorganize contributor documentation. Development guidance owns the local loop; the CI handbook explains coverage, results, and publication boundaries. Remove redundant internal prose specifications and keep implementation contracts beside their owners.

Verification and limits

The previous exact-head hosted run completed successfully in 12:17, with no failed underlying steps. Both independent Thermos reviews and their follow-up checks found the material review findings resolved.

The subsequent seven-way comparison fan-out, uv cache-key correction, and integration of current canonical main have passed local combined checks. Their fresh hosted run is still pending; the owner explicitly requested merging before it completes, with post-merge verification to follow.

Known limits:

  • The under-ten-minute goal and lower aggregate runner usage are not yet demonstrated.
  • Hosted runners refuse the current unprivileged mount probe, so Campfire correctly uses the serial fallback there; local parallel timings are not a hosted speedup claim.
  • The latest stable Swift setup action still declares Node 20 and emits the runner's migration warning. No stable Node-24 replacement exists yet; do not downgrade Node or adopt an unreleased action just to silence it.
  • The hosted ci:full label-event test remains a follow-up. Compiler/modeling warnings and platform-dependent Campfire floors were not suppressed or blindly regenerated.

Integration

Includes the unchanged documentation foundation from #351. Current canonical main was merged into this branch, preserving contributor commits; the Spinel guide retains both upstream asset/OCRAN guidance and the Node 24 prerequisite. GitHub also marked #351 as merged automatically when its unchanged head became part of canonical main; no manual closure or branch deletion was performed.

No release, deployment, or manual Full validation dispatch is included.

thomasklemm and others added 12 commits October 3, 2026 12:18
Organize development guidance by task and replace the historical CI reuse document with a concise contributor-facing CI entry. Keep implementation details with their workflows and tests, correct stale claims, and update navigation.

Remove workflow assertions tied to documentation wording while retaining behavioral CI checks and source-reference validation.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Partition all integration targets across three bounded unit shards, with library/bin tests and the debug bench gate on shard zero. Produce the same-run debug compiler independently for selected Campfire consumers and remove unit-success barriers from independent lanes. Required gates still include unit and compiler outcomes.

Keep targeted routing, drafts and execution-receipt controls intact. Contract-test-only edits no longer select every target; changed CI implementations and mixed ownership still expand normally.

Workflow/fixture/reference contracts pass. Actual shard 1 and 2 runs pass; shard 0 exposes the unchanged date-dependent Sydney now_offset assertion, independently reproduced without the runner. No test result is suppressed.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Run up to four extra target comparisons and six archive smokes at once,
without changing the planner, selected checks, or failure handling.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Keep all three collector modes, their unique result keys, and advisory
failure reporting. Missing, cancelled, or failed mode evidence must not
produce a completed validation result.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Run ruby-lane files in parallel, one process per file, with a private
tmp/storage bind-mount so Active Storage writes do not collide. Keep
$0, cwd and file-list order. Spinel runs stay serial on the shared
sqlite file, and a box without unshare falls back to the old loop.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a1028c-d068-7428-803e-a7f2eaec32c7
Call run_test for the default secret, capture one combined stream, and
mount with the real uid after dropping inherited and ambient capabilities.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a1028c-d068-7428-803e-a7f2eaec32c7
Keep test-only fallback controls out of the production harness. Exercise
real concurrent storage collisions, ordinary uid/capabilities, missing and
refused namespace tools, and a worker mount failing after a successful
probe. Include these regressions in the default Cargo unit coverage.

On the pinned Campfire emit, serial and parallel tallies/failure logs are
byte-identical: 401/405 tests, 68/69 files, two skips. Parent-orb timing is
100.86 seconds serial and 15.00 seconds at eight jobs; hosted timing remains
to be measured.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Preserve the documentation foundation and separate optimization commits.

Co-Authored-By: Amp <amp@ampcode.com>
Active TypeScript, Playwright, and browser jobs now install Node 24,
the current LTS. The emitted package types follow that pin. Node 20
ABI 115 has no better-sqlite3 12.11.1 prebuild, so compare installs
were compiling the native module; Node 24 ABI 137 uses the published
linux-x64 prebuild. Doctor now treats Node below 24 as missing for
the typescript target.

Bump actions whose latest stable majors keep the inputs these jobs
use: checkout v7, setup-node v7, cache v6, upload-artifact v7,
setup-java v6, setup-dotnet v6, setup-go v7, and setup-python v7.
Gradle setup stays on v5. v6 extracts caching into a proprietary
component and changes its license. Floating majors that are already
current, and astral-sh/setup-uv@v7, stay put: v8 stopped publishing
a moving major tag.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a102d0-ead8-754c-8160-0bd23f9dffb6
Keep README smoke execution on a fresh extraction. Reuse setup-ruby installed gems through a post-setup BUNDLE_PATH, including lockless JRuby archives. Finish the uv update and simplify Node requirement checks and regression coverage.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Exercise workflow shell commands rather than freezing the export spelling. A missing MRI lock must not prevent preparation for setup-ruby.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e395ed96-05fb-4939-b668-c43da1462fb0
📥 Commits

Reviewing files that changed from the base of the PR and between 71a5ee5 and 85f1a6e.

📒 Files selected for processing (14)
  • .github/workflows/ci.yml
  • .ruby-version
  • bin/rh
  • docs/ci/README.md
  • docs/development/README.md
  • docs/guide/targets.md
  • scripts/campfire-suite
  • scripts/ci-plan.py
  • src/project.rs
  • tests/ci_campfire_optimization_test.py
  • tests/ci_plan_test.py
  • tests/ci_policy_workflow.rs
  • tests/ci_toolchain_workflow.rs
  • tests/rh_verify_test.rb
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/project.rs
  • docs/guide/targets.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

CI now shards unit tests, builds a shared debug binary for Campfire jobs, and updates job concurrency and caching. Campfire Ruby runs can use isolated parallel workers. Tool checks and generated instructions require Node.js 24. Contributor and CI documentation has been reorganized.

Changes

CI and Contributor Workflow

Layer / File(s) Summary
Unit sharding and shared binary
.github/workflows/ci.yml, scripts/ci-unit-tests.py, scripts/ci-plan.py, tests/ci_unit_tests_test.py, tests/ci_plan_test.py, tests/ci_policy_workflow.rs, tests/workflow_yaml_parses.rs
Unit integration targets run in three shards, with library and binary tests limited to shard 0. A separate build-roundhouse job publishes the debug binary used by Campfire consumers. CI selection and result checks cover the updated job plan.
CI lanes and action updates
.github/workflows/ci.yml, .github/workflows/release.yml, tests/ci_policy_workflow.rs, tests/workflow_yaml_parses.rs
The workflows update action versions, job dependencies, and matrix concurrency. Ruby and JRuby archive smoke jobs prepare and reuse Bundler dependencies.
Isolated Campfire Ruby runs
scripts/campfire-suite, tests/ci_campfire_optimization_test.py, tests/ci_policy_workflow.rs
Ruby test files run in parallel only when namespace and bind-mount checks succeed. Workers use separate storage paths, and results are tallied in file order. Tests cover isolation and serial fallback.
Node.js 24 minimum and smoke counts
bin/rh, src/emit/typescript/package.rs, src/project.rs, scripts/smoke, scripts/campfire-archive-files, docs/guide/*, tests/ci_smoke_test.py, tests/ci_policy_workflow.rs
doctor checks installed versions against minimum requirements. Node.js 24 is the minimum for the Node prerequisite, emitted Node types, and generated project instructions. Smoke parsing accepts two Node test pass-summary formats.
Contributor documentation and references
AGENTS.md, DEVELOPMENT.md, README.md, docs/README.md, docs/ci/*, docs/development/*, docs/data/*, docs/guide/*, docs/pipeline/*, docs/env-gates.md, docs/ci-reuse.md, scripts/ci-reuse.py, tests/docs_references.rs
Contributor setup and task guides are added or reorganized. CI and verification documentation describes coverage selection and evidence limits. Links and documentation reference checks are updated.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 85f1a

No actionable regression remains from this review. The GC reporting issue predates the change, so it does not prevent this PR from merging after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 85f1a

Earlier execution and parallel workers retain the inspected validation and publication controls. No introduced security vulnerability was established. Risk remains low rather than minimal because interruption handling and some affected surfaces are not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected authority changes are bounded to validation runners, their artifacts, and the local caller's execution context. Storage isolation is not a general sandbox: workers retain the application's working tree, launch environment, and access outside the two mounted storage roots.

Trust Boundaries and Controls

  • observed — Publication requests are restricted to the canonical repository, main branch, and scheduled or manually dispatched full caller. Earlier producer execution does not remove the compact validation gate or grant deployment permissions to PR validation.
  • observed — The existing publication policy permits failed extra-target results to be exposed as reproduction evidence, not successful validation certification, after archive-byte verification. Campfire conformance remains in the required compact floor. This policy predates the PR and is not an introduced concern.

Resilience and Maintainability Implications

  • observed — Isolation failure does not silently enable unisolated parallel execution, and absent worker status cannot produce a passing file row. These controls preserve failure visibility despite tolerated worker-command failures.

Hardening Proposals

  • proposed — Make worker cancellation and join-before-cleanup ownership explicit, and validate parent-only and process-group interruption. Document exclusive ownership of a reused emit, or enforce it if independent concurrent invocations are intended. These address unresolved lifecycle coverage, not an established vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.36% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 67 functions across 14 files. (7 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main CI parallelization work and the contributor documentation changes.
Full details: Docstring Coverage

Explanation

Docstring coverage is 28.36% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 67 functions across 14 files. (7 skipped: 7 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

thomasklemm and others added 6 commits October 3, 2026 18:58
The unit job already runs tests/ci_campfire_optimization_test.py, which
preloads scripts/campfire-test-bcrypt.rb. Without the gem those tests
fail on a clean runner; a machine that already has bcrypt hides it.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Unlabeled drafts retain fixture and unit coverage. Labeled drafts run the full non-publishing matrix; removing the label returns to the small floor.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Keep TAP recognition and the 21-test execution floor. Pin asymmetric pass/total counts, zero execution, both sides of the floor, and failing README blocks. The actual failing hosted TypeScript archive passes the full model/controller and browser smoke after this change.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Use one workflow MRI selector and a local minimum read by doctor. Keep JRuby and exact repro pins separate. Isolate both Active Storage roots without changing the serial Ruby launch contract, and test actual overlapping service writes across default, test, and production environments.

Name the draft floor independently of the baseline ordering and derive unit shard coordinates from the matrix strategy. Group SDK-selection contracts separately from CI execution policy.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
…deps

Remove the four-job matrix bottleneck without selecting additional work. Keep uv dependency downloads cached, but invalidate using the Python manifest template that exists before generation instead of unmatched default manifest globs.

Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
Preserve upstream contributor commits and OCRAN/asset guidance while retaining the Node24 prerequisite. Resolve only the documentation overlap.

Co-Authored-By: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-01a10180-9342-76c1-a249-6ab6602d9657
@thomasklemm thomasklemm changed the title ci: start selected checks earlier, shard units, and move to Node 24 ci: parallelize selected PR checks and simplify contributor docs Oct 3, 2026
@thomasklemm
thomasklemm merged commit 26365fa into rubys:main Oct 3, 2026
32 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant