Uh oh!
There was an error while loading. Please reload this page.
ci: Include root pubspec.yaml in pub cache key - #189826
Conversation
The `pub package cache` step in composite-flutter-setup keys its cache on a hash of the pubspec.yaml files found under dev/, examples/, and packages/, but omits the root workspace pubspec.yaml. The root pubspec pins the versions of all transitive dependencies, so a pub roll that only touches the root, leaves the hash, and therefore the hash key, unchanged. This is exactly what happens on pub package rolls like flutter#189760. When that happens the cache still hits and restores a stale pubspec.lock over the freshly checked-out one. At that point, the following `flutter update-packages` then fails when run with `--enforce-lockfile`, since the lock file we just restored from cache no longer matches the pinned versions in the checked-out root pubspec.yaml, which breaks the Tree Analyze step tree-wide until the cache is manually invalidated. We now include the root pubspec.yaml in the hash so that a packages only roll changes the cache key, forcing a fresh package resolve rather than restoring a stale lock. Fixes: flutter#189825
There was a problem hiding this comment.
Code Review
This pull request updates the GitHub Action composite-flutter-setup to include the root pubspec.yaml file when generating the stable hash for dependency caching. Feedback was provided to correct a typo in the updated comment, which incorrectly refers to pubspec.yaml as package.yaml.
Uh oh!
There was an error while loading. Please reload this page.
| # Generate a stable hash for github caching from the pubspec.yaml | ||
| # files that drive dependency resolution. Includes the root | ||
| # pubspec.yaml and all pubspec.yaml files from dev/examples/packages. | ||
| find pubspec.yaml dev examples packages -name "pubspec.yaml" -print0 | sort -z | xargs -0 cat | sha256sum >> "$RUNNER_TEMP/pub_deps_sha" |
There was a problem hiding this comment.
Hash only tracked pubspec.yaml files in the tree and their contents... its faster because the objects are already in the git db:
git ls-tree HEAD -- $(git ls-files '*/pubspec.yaml') | git hash-object --stdin
Updated the method for generating a stable hash for GitHub caching from pubspec.yaml files to use git commands for improved accuracy.
jtmcdole
left a comment
There was a problem hiding this comment.
my approval isn't enough since I made the last commit.
Uh oh!
There was an error while loading. Please reload this page.
flutter/flutter@1ac2e82...2a2a79d 2026-07-22 21270878+elliette@users.noreply.github.com Clear cached directional focus history on a non-directional focus request (flutter/flutter#187957) 2026-07-22 chris@bracken.jp ci: Include root pubspec.yaml in pub cache key (flutter/flutter#189826) 2026-07-22 6655696+guidezpl@users.noreply.github.com Remove codecov badge from README (flutter/flutter#189728) 2026-07-22 116356835+AbdeMohlbi@users.noreply.github.com Clean android engine/embedding tests (flutter/flutter#189276) 2026-07-22 50643541+Mairramer@users.noreply.github.com Add barrierBuilder support to showDialog and showGeneralDialog (flutter/flutter#187992) 2026-07-22 matt.boetger@gmail.com Fix Mockito dynamic agent loading warnings in Robolectric tests (flutter/flutter#189804) 2026-07-22 chris@bracken.jp [iOS] Remove dead RasterThreadMerger plumbing from platform views (flutter/flutter#189753) 2026-07-22 737941+loic-sharma@users.noreply.github.com Add OverlayPortal.overlayChildLayoutBuilder sample (flutter/flutter#188930) 2026-07-22 katelovett@google.com Automate recurring tasks via workflows - localizations (flutter/flutter#189750) 2026-07-21 chris@bracken.jp [iOS] Remove dead parameters and no-op overrides (flutter/flutter#189754) 2026-07-21 chris@bracken.jp [iOS] Inject DisplayLinkManager into FlutterViewController (flutter/flutter#189764) 2026-07-21 46920873+gabrimatic@users.noreply.github.com Support custom BoxBorder animation in BoxDecoration (flutter/flutter#186348) 2026-07-21 chingjun@google.com Rename CpuArch.x86_64 to CpuArch.x64 (flutter/flutter#189478) 2026-07-21 engine-flutter-autoroll@skia.org Roll Skia from 569534e9fa59 to 5e183e5aeac5 (3 revisions) (flutter/flutter#189795) 2026-07-21 engine-flutter-autoroll@skia.org Roll Dart SDK from 3b2f5ad7718d to 1e65011ee004 (4 revisions) (flutter/flutter#189791) 2026-07-21 jacksongardner@google.com Run delete-bot-branches.yaml on `pull_request_target` instead of `pull_request` so that we can access secrets. (flutter/flutter#189793) 2026-07-21 jmccandless@google.com Batch release directory correction (flutter/flutter#189738) 2026-07-21 brackenavaron@gmail.com [flutter_test][Test cross imports] Move TestWidgetsApp to flutter_test (flutter/flutter#189435) 2026-07-21 brunocorona.alcantar@gmail.com Fix null-deref/double-dispose in StretchingOverscrollIndicator (#189589) (flutter/flutter#189667) 2026-07-21 engine-flutter-autoroll@skia.org Roll Packages from 611899b to 8260a1e (10 revisions) (flutter/flutter#189782) 2026-07-21 chris@bracken.jp [iOS] Inject DisplayLinkManager into FlutterMetalLayer (flutter/flutter#189752) 2026-07-21 jason-simmons@users.noreply.github.com Derive the SkImage size used by ImageEncodingImpeller::ConvertDlImageToSkImage from the size of the underlying texture, not the size of the DlImage (flutter/flutter#189739) If this roll has caused a breakage, revert this CL and stop the roller using the controls here: https://autoroll.skia.org/r/flutter-packages Please CC bmparr@google.com,stuartmorgan@google.com on the revert to ensure that a human is aware of the problem. To file a bug in Packages: https://github.com/flutter/flutter/issues/new/choose To report a problem with the AutoRoller itself, please file a bug: https://issues.skia.org/issues/new?component=1389291&template=1850622 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+doc/main/autoroll/README.md
…r#12272) flutter/flutter@1ac2e82...2a2a79d 2026-07-22 21270878+elliette@users.noreply.github.com Clear cached directional focus history on a non-directional focus request (flutter/flutter#187957) 2026-07-22 chris@bracken.jp ci: Include root pubspec.yaml in pub cache key (flutter/flutter#189826) 2026-07-22 6655696+guidezpl@users.noreply.github.com Remove codecov badge from README (flutter/flutter#189728) 2026-07-22 116356835+AbdeMohlbi@users.noreply.github.com Clean android engine/embedding tests (flutter/flutter#189276) 2026-07-22 50643541+Mairramer@users.noreply.github.com Add barrierBuilder support to showDialog and showGeneralDialog (flutter/flutter#187992) 2026-07-22 matt.boetger@gmail.com Fix Mockito dynamic agent loading warnings in Robolectric tests (flutter/flutter#189804) 2026-07-22 chris@bracken.jp [iOS] Remove dead RasterThreadMerger plumbing from platform views (flutter/flutter#189753) 2026-07-22 737941+loic-sharma@users.noreply.github.com Add OverlayPortal.overlayChildLayoutBuilder sample (flutter/flutter#188930) 2026-07-22 katelovett@google.com Automate recurring tasks via workflows - localizations (flutter/flutter#189750) 2026-07-21 chris@bracken.jp [iOS] Remove dead parameters and no-op overrides (flutter/flutter#189754) 2026-07-21 chris@bracken.jp [iOS] Inject DisplayLinkManager into FlutterViewController (flutter/flutter#189764) 2026-07-21 46920873+gabrimatic@users.noreply.github.com Support custom BoxBorder animation in BoxDecoration (flutter/flutter#186348) 2026-07-21 chingjun@google.com Rename CpuArch.x86_64 to CpuArch.x64 (flutter/flutter#189478) 2026-07-21 engine-flutter-autoroll@skia.org Roll Skia from 569534e9fa59 to 5e183e5aeac5 (3 revisions) (flutter/flutter#189795) 2026-07-21 engine-flutter-autoroll@skia.org Roll Dart SDK from 3b2f5ad7718d to 1e65011ee004 (4 revisions) (flutter/flutter#189791) 2026-07-21 jacksongardner@google.com Run delete-bot-branches.yaml on `pull_request_target` instead of `pull_request` so that we can access secrets. (flutter/flutter#189793) 2026-07-21 jmccandless@google.com Batch release directory correction (flutter/flutter#189738) 2026-07-21 brackenavaron@gmail.com [flutter_test][Test cross imports] Move TestWidgetsApp to flutter_test (flutter/flutter#189435) 2026-07-21 brunocorona.alcantar@gmail.com Fix null-deref/double-dispose in StretchingOverscrollIndicator (#189589) (flutter/flutter#189667) 2026-07-21 engine-flutter-autoroll@skia.org Roll Packages from 611899b to 8260a1e (10 revisions) (flutter/flutter#189782) 2026-07-21 chris@bracken.jp [iOS] Inject DisplayLinkManager into FlutterMetalLayer (flutter/flutter#189752) 2026-07-21 jason-simmons@users.noreply.github.com Derive the SkImage size used by ImageEncodingImpeller::ConvertDlImageToSkImage from the size of the underlying texture, not the size of the DlImage (flutter/flutter#189739) If this roll has caused a breakage, revert this CL and stop the roller using the controls here: https://autoroll.skia.org/r/flutter-packages Please CC bmparr@google.com,stuartmorgan@google.com on the revert to ensure that a human is aware of the problem. To file a bug in Packages: https://github.com/flutter/flutter/issues/new/choose To report a problem with the AutoRoller itself, please file a bug: https://issues.skia.org/issues/new?component=1389291&template=1850622 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+doc/main/autoroll/README.md
The
pub package cachestep in composite-flutter-setup keys its cache on a hash of the pubspec.yaml files found under dev/, examples/, and packages/, but omits the root workspace pubspec.yaml. The root pubspec pins the versions of all transitive dependencies, so a pub roll that only touches the root, leaves the hash, and therefore the hash key, unchanged. This is exactly what happens on pub package rolls like #189760.When that happens the cache still hits and restores a stale pubspec.lock over the freshly checked-out one. At that point, the following
flutter update-packagesthen fails when run with--enforce-lockfile, since the lock file we just restored from cache no longer matches the pinned versions in the checked-out root pubspec.yaml, which breaks the Tree Analyze step tree-wide until the cache is manually invalidated.We now include the root pubspec.yaml in the hash so that a packages only roll changes the cache key, forcing a fresh package resolve rather than restoring a stale lock.
Fixes: #189825
Pre-launch Checklist
///).If you need help, consider asking for advice on the #hackers-new channel on Discord.
If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.
Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the
gemini-code-assistbot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.