Run pnpm install-proof as one job per Node runtime - #897
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
Conversation
The pnpm install-proof matrix spawned 25 single-version jobs (one per pnpm/Node pair) whose real work is ~20 s each. Most of each job was runner setup, and any one leg that never got a runner left the run red: on 2026-10-05 20/28 pnpm runs failed, every failed leg checked being an ubuntu-latest job cancelled with no runner and no log. Group the legs by Node runtime (10, 16, 24): each job installs its pnpm versions, then runs both pinned suites per version in turn with a per-version TMPDIR so the shared cache sandbox starts empty, as it did on a fresh runner. Every pnpm/Node pair still runs on every PR and main push; a failure is reported per version via ::error. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uej6tnJfjRU8NCUz2jdDG4
|
bugbot run Generated by Claude Code |
main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Assisted-by: Claude Code:claude-opus-5-5 (cherry picked from commit 659ac2c)
|
I cherry-picked #878's fix (659ac2c, Locally I ran the digest, gradle_cache, jvm_jar and sidecars lib tests: 67/67 pass. Generated by Claude Code |
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 58e901c. Configure here.
|
[agent] Ready for review at Generated by Claude Code |
Problem
pnpm hosted compatibilityis the reddest workflow in the repo right now. In the last 400 runs (2026-10-05 19:07–22:40 UTC), 20 of 28 completed pnpm runs failed (npm hosted/vendored, the next worst, was 16/28). I checked the failed install-proof legs, and none of them had a test failure. Each one was anubuntu-latestjob that was cancelled 15–18 min after it was queued, never got a runner, and has no log (the job-logs API returns 404):2.25.7,3.0.0,3.8.1,5.18.11,7.33.7,8.0.0,10.33.0,11.0.0,12.0.0,12.4.2). The other 15 passed, and their real work took ~20 s each.6.35.1,7.0.0) were cancelled with no runner. Every other leg passed.The workflow spawns 25 single-version jobs (one per pnpm/Node pair). Most of them do about 20 s of real work (the two 12.x legs take ~70 s); the rest is runner setup, and every job is billed as at least one full minute. A run fails if any one of its 25 jobs fails to get a runner, so the matrix is the workflow most exposed to runner shortage during busy agent push bursts. In the run above, legs waited up to 11 min just to start.
Root cause
The matrix runs one pnpm version per job, so 25 jobs compete for runners to do about 8 minutes of total work.
Fix
The install-proof job now runs one job per Node runtime (10.24.1, 16.20.2, 24.11.1), and each job loops over its pnpm versions:
pnpm-e2e pnpm_pinned_matrixand thenpnpm-vendor-e2e pnpm_pinned_matrix. The vendored suite still only runs if the hosted one passed, as the two separate steps did before.TMPDIR. That keeps the suites' shared cache sandbox (cache_env::cache_root()=$TMPDIR/socket-patch-test-caches-$USER:HOME,PNPM_HOME, the npm cache, XDG dirs) and every fixture tempdir as empty as they were on a fresh runner. No pnpm version sees another's cache or store.::error title=pnpm <v>::annotation and its own log group, and the step fails at the end listing every failed version.The
buildjob is unchanged.Also included: 58e901c is a
-xcherry-pick of #878 (Gradle digests throughutils::digest). TheCIworkflow'scoverage,testandtest-releasejobs are red onmainitself, onutils::digest::tests::production_digests_go_through_the_helpers(a semantic conflict between #646 and #865). Without that fix this PR couldn't go green. The commit becomes a no-op once #878 merges.Proof
origin/main's matrix with the expanded new matrix and got the same 25 pairs.actionlintis clean.pnpm-e2eandpnpm-vendor-e2ebinaries withPNPM_TEST_VERSIONS="9.15.9 10.33.0 0.0.0-missing". 9.15.9 and 10.33.0 passed both suites. The bogus version failed, got its::errorannotation, and the step exited 1 withFailed pnpm versions: 0.0.0-missing. Each version's cache sandbox was created under its own$RUNNER_TEMP/tmp-<v>/socket-patch-test-caches, and nothing was written to the shared/tmp.utils::digest,gradle_cache,jvm_jarandsidecarslib tests pass (67/67).rustfmt --checkis clean, and so is CI'scargo clippy --workspace --all-features -- -D warnings.Where each test still runs
Nothing moved and nothing was removed. All 25 pnpm/Node pairs still run on every PR that touches the workflow's paths and on every
mainpush, in the same workflow, now under 3 jobs.Note for the owner
The per-version check names
install-proof (<pnpm>, <node>)are replaced byinstall-proof (node 10.24.1),install-proof (node 16.20.2)andinstall-proof (node 24.11.1). If any of the old names is a required status check in branch protection, it needs updating.Related: #892 adds PR-run concurrency to this same workflow. The two changes touch different parts of the file and are complementary: #892 drops superseded runs, and this PR shrinks each run.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Uej6tnJfjRU8NCUz2jdDG4
Note
Low Risk
Changes are CI orchestration and digest helper consolidation with the same test matrix coverage; branch protection may need updated required check names for the three Node jobs.
Overview
pnpm hosted compatibility no longer fans out 25 install-proof matrix jobs (one per pinned pnpm). It runs three jobs—one per Node runtime (
10.24.1,16.20.2,24.11.1)—that install each group’s pnpm versions under a shared setup, then loop with per-versionTMPDIR, log groups, and::errorannotations. Hosted and vendored e2e (pnpm-e2ethenpnpm-vendor-e2e) run in one step per version; job timeout rises to 30 minutes.Gradle/JVM code routes SHA-1/SHA-256 hashing through
crate::utils::digest(sha1_hex_of,sha256_hex_of) ingradle_cache,jvm_jar, and Maven sidecars instead of inlinesha1/sha2+hex::encode(cherry-pick to unblock CI onproduction_digests_go_through_the_helpers).Reviewed by Cursor Bugbot for commit 58e901c. Configure here.
Generated by Claude Code