ci(rust): harden sccache setup and scope-contract pins after #559 review - #566
Conversation
|
Warning Review limit reached
Next review available in: 52 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 64c10f71ac
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
64c10f7 to
5e7d40e
Compare
- sccache-action steps are continue-on-error with an explicit fallback that unsets RUSTC_WRAPPER, so a flaky action cannot block the merge-gate path (the concern behind 92991a3's removal). - Contract test now pins the rust_fast_gates scope condition inside its job block, requires sccache wiring in BOTH heavy jobs, and adds negative pins so moved work (fmt/shellcheck/shell suites) cannot silently reappear in the heavy rust job. Refs #558
Second-round review: the earlier pins were file-wide counts with a leaky awk block and no positive placement assertions. Now each job block is extracted exactly, sccache presence is asserted per job, suite placement is pinned both directions (including the market-recorder suite's home in the heavy job), and a mutation test (recorder moved back to fast gates) proves the pins fail. Refs #558
a8caa2e to
0a045dc
Compare
Replace the homegrown sccache setup (apt/cargo install plus actions/cache on ~/.cache/sccache, whose research-image primary key embedded github.sha and could never hit) with the #559/#566 pattern in every job that compiles Rust on the runner: - mozilla-actions/sccache-action@v0.0.10 with continue-on-error and a fallback step that unsets RUSTC_WRAPPER/SCCACHE_GHA_ENABLED - job env RUSTC_WRAPPER=sccache and SCCACHE_GHA_ENABLED=true - Swatinem/rust-cache keys dimensioned on rustc version, sccache version, and Cargo.lock - ${SCCACHE_PATH:-sccache} --show-stats || true evidence steps The acr-publish publish matrix compiles inside docker buildx, so the host-side wrapper does not apply there and that job is unchanged. No test semantics, job conditions, or gating changed. Refs #567
#570) * ci(rust): backfill sccache-action pattern onto ploy-ci and acr-publish Replace the homegrown sccache setup (apt/cargo install plus actions/cache on ~/.cache/sccache, whose research-image primary key embedded github.sha and could never hit) with the #559/#566 pattern in every job that compiles Rust on the runner: - mozilla-actions/sccache-action@v0.0.10 with continue-on-error and a fallback step that unsets RUSTC_WRAPPER/SCCACHE_GHA_ENABLED - job env RUSTC_WRAPPER=sccache and SCCACHE_GHA_ENABLED=true - Swatinem/rust-cache keys dimensioned on rustc version, sccache version, and Cargo.lock - ${SCCACHE_PATH:-sccache} --show-stats || true evidence steps The acr-publish publish matrix compiles inside docker buildx, so the host-side wrapper does not apply there and that job is unchanged. No test semantics, job conditions, or gating changed. Refs #567 * ci(rust): tolerate missing sccache binary in cache dimension steps CodeRabbit P1 on #570: when sccache setup fails (the case continue-on-error tolerates), the unconditional version lookup would fail the job. Mirrors the ci.yml fix. Refs #567 --------- Co-authored-by: Sonic Shih <sonic.shih@mandonothing.com>
Change contract
Two hardening items from the post-#559 review:
Setup sccachesteps arecontinue-on-errorwith an explicit fallback step that unsetsRUSTC_WRAPPER/SCCACHE_GHA_ENABLEDif the action fails — a flaky action can no longer block the merge-gate path (the concern that made 92991a3 remove it in July). Stats steps tolerate a missing binary.,ci/rust,scope condition checked inside the rust_fast_gates block. A mutation test (recorder moved back to fast gates) proves the pins fail.Out of scope
Dependency / merge order
Stacks on #559 and #564 (both merged).
Focused validation
.github/scripts/test-select-rust-ci-scope.shPASS with the strengthened pinsRollout / rollback impact
CI-only; a flaky sccache setup now degrades to an uncached build instead of a red gate. Rollback = revert.
Issue relationship
Refs #558