Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
self-hosted-runner:
labels:
- amd64-mo-shanghai-8c16g
- amd64-mo-guangzhou-2xlarge16
- amd64-mo-guangzhou-2xlarge32
- amd64-mo-guangzhou-medium8
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/check-action-file.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ on:
- 'scripts/select_coverage_artifacts.py'
- 'scripts/test_select_coverage_artifacts.py'
- 'scripts/test_merge_trigger_tke_subject.py'
- 'scripts/*race_seed*.py'

permissions:
contents: read
Expand Down Expand Up @@ -79,6 +80,8 @@ jobs:
bash actions/restore-sca-analysis-cache/environment-hash.test.sh
- name: Test Go cache import contracts
run: python3 -m unittest discover -s actions/seed-go-caches -p 'test_*.py' -v
- name: Test race canary evidence contracts
run: python3 -m unittest discover -s scripts -p 'test_race_seed*.py' -v
- name: Guard deliberate workflow disablements
env:
ACTIONLINT: ${{ steps.install-actionlint.outputs.executable }}
Expand Down
114 changes: 114 additions & 0 deletions .github/workflows/race-seed-canary.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
name: Race seed canary

on:
workflow_call:
inputs:
ci_sha:
description: Same immutable CI commit as the reusable workflow reference
required: true
type: string
matrixone_sha:
description: Full SHA reachable from matrixorigin/matrixone main
required: true
type: string
image:
description: Builder repository@sha256 digest (never a mutable tag)
required: true
type: string
repetitions:
description: One smoke pair per cache state, or three measured pairs
type: string
default: '1'
secrets:
S3ENDPOINT:
required: true
S3REGION:
required: true
S3APIKEY:
required: true
S3APISECRET:
required: true
S3BUCKET:
required: true

permissions:
contents: read

concurrency:
group: race-seed-canary
cancel-in-progress: false

jobs:
plan:
if: github.repository == 'matrixorigin/matrixone' && github.ref == 'refs/heads/main' && github.event_name == 'workflow_dispatch'
runs-on: ubuntu-22.04
timeout-minutes: 5
outputs:
matrix: ${{ steps.plan.outputs.matrix }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: matrixorigin/CI
ref: ${{ inputs.ci_sha }}
persist-credentials: false
- id: plan
env:
GH_TOKEN: ${{ github.token }}
SOURCE_SHA: ${{ inputs.matrixone_sha }}
SEED_IMAGE: ${{ inputs.image }}
REPETITIONS: ${{ inputs.repetitions }}
CI_SHA: ${{ inputs.ci_sha }}
run: python3 scripts/race_seed_plan.py

warm-snapshot:
needs: plan
uses: ./.github/workflows/race-seed-sample.yaml
with:
ci_sha: ${{ inputs.ci_sha }}
matrixone_sha: ${{ inputs.matrixone_sha }}
image: ${{ inputs.image }}
name: warm-preparation
cache_state: prepare
seed: false
secrets: inherit

samples:
needs: [plan, warm-snapshot]
strategy:
fail-fast: false
max-parallel: 1
matrix: ${{ fromJSON(needs.plan.outputs.matrix) }}
uses: ./.github/workflows/race-seed-sample.yaml
with:
ci_sha: ${{ inputs.ci_sha }}
matrixone_sha: ${{ inputs.matrixone_sha }}
image: ${{ inputs.image }}
name: ${{ matrix.name }}
cache_state: ${{ matrix.cache_state }}
seed: ${{ matrix.seed }}
secrets: inherit

compare:
needs: [plan, warm-snapshot, samples]
if: ${{ always() && needs.plan.result == 'success' }}
runs-on: ubuntu-22.04
timeout-minutes: 10
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: matrixorigin/CI
ref: ${{ inputs.ci_sha }}
persist-credentials: false
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: race-*
path: results
- env:
CANARY_REPETITIONS: ${{ inputs.repetitions }}
run: python3 scripts/race_seed_canary.py --summarize results
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: always()
with:
name: comparison
path: results/comparison.json
if-no-files-found: warn
142 changes: 142 additions & 0 deletions .github/workflows/race-seed-sample.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,142 @@
name: Race seed measurement sample

on:
workflow_call:
inputs:
ci_sha:
required: true
type: string
matrixone_sha:
required: true
type: string
image:
required: true
type: string
name:
required: true
type: string
cache_state:
required: true
type: string
seed:
required: true
type: boolean
secrets:
S3ENDPOINT:
required: true
S3REGION:
required: true
S3APIKEY:
required: true
S3APISECRET:
required: true
S3BUCKET:
required: true

permissions:
contents: read

jobs:
sample:
# Verified ARC pool: ephemeral pod, emptyDir workspace, no shared cache mount.
runs-on: amd64-mo-shanghai-8c16g
environment: ci
timeout-minutes: 120
steps:
- name: Require the audited pool and MatrixOne caller before any checkout
id: runner_guard
env:
RUNNER_KIND: ${{ runner.environment }}
run: |
test "$RUNNER_KIND" = self-hosted
test "$GITHUB_REPOSITORY" = matrixorigin/matrixone
test "$GITHUB_WORKSPACE" = /home/runner/_work/matrixone/matrixone
case "$RUNNER_NAME" in amd64-mo-shanghai-8c16g-*-runner-*) ;; *) exit 1;; esac
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: matrixorigin/matrixone
ref: ${{ inputs.matrixone_sha }}
persist-credentials: false
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: matrixorigin/CI
ref: ${{ inputs.ci_sha }}
path: _canary
persist-credentials: false
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version-file: go.mod
cache: false
- uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4
with:
distribution: adopt
java-version: '8'
- name: Match the existing UT CMake setup
uses: ./_canary/actions/setup-cmake
- name: Match the Shanghai UT module proxy policy
shell: bash
run: |
set -euo pipefail
proxy='http://goproxy.goproxy.svc.cluster.local'
version="$(awk '$1 == "github.com/spf13/cobra" {print $2; exit}' go.mod)"
if test -n "$version" && curl --disable --fail --silent --connect-timeout 5 --max-time 30 "$proxy/github.com/spf13/cobra/@v/$version.info" >/dev/null; then
echo "GOPROXY=$proxy|https://goproxy.cn|direct" >> "$GITHUB_ENV"
fi
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
if: inputs.cache_state == 'warm'
with:
name: warm-snapshot
path: warm-snapshot
- name: Measure complete race suite
env:
SEED_IMAGE: ${{ inputs.image }}
SEED_FLAVOR: race
SEED_TRANSPORT: registry
ENABLE_SEED: ${{ inputs.seed }}
CACHE_STATE: ${{ inputs.cache_state }}
CANARY_RUNNER_LABEL: amd64-mo-shanghai-8c16g
CANARY_SOURCE_SHA: ${{ inputs.matrixone_sha }}
CANARY_CI_SHA: ${{ inputs.ci_sha }}
CANARY_UT_PARALLEL: ${{ vars.UT_PARALLEL || 6 }}
CANARY_UT_TIMEOUT: ${{ vars.UT_TIMEOUT || 40 }}
GOCACHE: /home/runner/.cache/mo-race-canary
GOMODCACHE: /home/runner/go/pkg/mod
UT_WORKDIR: /home/runner/_work/matrixone/matrixone
endpoint: ${{ secrets.S3ENDPOINT }}
region: ${{ secrets.S3REGION }}
apikey: ${{ secrets.S3APIKEY }}
apisecret: ${{ secrets.S3APISECRET }}
bucket: ${{ secrets.S3BUCKET }}
run: |
set -euo pipefail
args=()
if [[ "$ENABLE_SEED" == true ]]; then args+=(--seed); fi
case "$CACHE_STATE" in
cold) ;;
warm) args+=(--snapshot "$GITHUB_WORKSPACE/warm-snapshot");;
prepare) args+=(--export "$GITHUB_WORKSPACE/warm-snapshot");;
*) exit 1;;
esac
python3 _canary/scripts/race_seed_canary.py "${args[@]}"
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: ${{ always() && steps.runner_guard.outcome == 'success' }}
with:
name: ${{ inputs.name }}
path: _canary/canary-report/
retention-days: 7
if-no-files-found: error
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: ${{ always() && steps.runner_guard.outcome == 'success' }}
with:
name: diagnostics-${{ inputs.name }}
path: /home/runner/_work/matrixone/matrixone/ut-report/
retention-days: 7
if-no-files-found: warn
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: success() && inputs.cache_state == 'prepare'
with:
name: warm-snapshot
path: warm-snapshot/
compression-level: 0
retention-days: 1
if-no-files-found: error
8 changes: 8 additions & 0 deletions actions/seed-go-caches/action.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
name: Seed Go caches
description: Best-effort additive import from the trusted CI builder, preserving existing caches
inputs:
transport:
description: Acquisition backend; registry is opt-in and requires a pinned image
default: docker
image:
description: Optional trusted repository at an immutable sha256 digest for paired measurements
default: ''
flavor:
description: Producer warm flavor (race or coverage)
required: true
Expand All @@ -13,6 +19,8 @@ runs:
- name: Import trusted Go cache entries
shell: bash
env:
SEED_TRANSPORT: ${{ inputs.transport }}
SEED_IMAGE: ${{ inputs.image }}
SEED_FLAVOR: ${{ inputs.flavor }}
SEED_GENERATION: ${{ inputs.generation }}
run: python3 "$GITHUB_ACTION_PATH/seed.py"
Loading