Skip to content
9 changes: 6 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -564,7 +564,8 @@ jobs:
needs.promote.result == 'success' &&
needs.trigger-upload.result == 'success' &&
needs.promote.outputs.promoted == 'true'
runs-on: *runner-4vcpu
# Mostly waiting on the ECS cutover after a dependency install: the smallest runner is enough.
runs-on: *runner-2vcpu
# Leave setup/promotion headroom above the 70-minute cutover poll.
timeout-minutes: 90
permissions:
Expand Down Expand Up @@ -992,6 +993,8 @@ jobs:
# Sigstore signs against the runner's OIDC identity; no key material is stored.
id-token: write
attestations: write
# Records each attestation against the image as an artifact storage record.
artifact-metadata: write
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -1031,7 +1034,7 @@ jobs:

- name: Attest SBOM
if: matrix.platform != 'index'
uses: actions/attest-sbom@c604332985a26aa8cf1bdc465b92731239ec6b9e # v4.1.0
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ${{ matrix.image }}
subject-digest: ${{ matrix.digest }}
Expand All @@ -1041,7 +1044,7 @@ jobs:
push-to-registry: true

- name: Attest build provenance
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ${{ matrix.image }}
subject-digest: ${{ matrix.digest }}
Expand Down
9 changes: 6 additions & 3 deletions .github/workflows/helm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,11 @@ on:
- 'scripts/generate-image-manifest.ts'
- 'package.json'

# Pull requests cancel a superseded run; pushes never do, so a newer push cannot cut off a chart
# publish already in flight.
concurrency:
group: helm-${{ github.ref }}
cancel-in-progress: true
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
Comment thread
waleedlatif1 marked this conversation as resolved.

permissions:
contents: read
Expand Down Expand Up @@ -260,7 +262,8 @@ jobs:
contents: read # Read the chart source.
packages: write # Push the chart, its signature, and its attestations to GHCR.
id-token: write # Sigstore signs against the runner's OIDC identity; no key material is stored.
attestations: write # Let actions/attest-build-provenance record the SLSA provenance.
attestations: write # Let actions/attest record the SLSA provenance.
artifact-metadata: write # And its artifact storage record.
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
with:
Expand Down Expand Up @@ -388,7 +391,7 @@ jobs:
# attestation with it, rather than only being retrievable from GitHub.
- name: Attest build provenance
if: steps.exists.outputs.already == 'false'
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ${{ steps.package.outputs.repository }}
subject-digest: ${{ steps.push.outputs.digest }}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ import {
type InMemoryStripe,
stripeClientMock,
} from '@sim/testing/mocks/stripe.mock'
import { sleep } from '@sim/utils/helpers'
import { generateId } from '@sim/utils/id'
import { type BetterAuthOptions, betterAuth } from 'better-auth'
import { createAuthMiddleware } from 'better-auth/api'
Expand Down Expand Up @@ -376,7 +377,11 @@ type TestTransaction = Parameters<Parameters<typeof testDatabase.transaction>[0]

/**
* Starts a transaction that takes its locks in `holdLocks`, then parks until released and runs
* `finish`. `untilBlocking` resolves once another backend is waiting on one of its locks.
* `finish`. `locked` resolves once those locks are held: start the contending work after it, or the
* contender can take the lock first and nothing ever waits on the parked transaction.
* `untilBlocking` resolves once another backend is waiting on one of its locks; if none does within
* the deadline it releases the transaction before throwing, so a failure never leaves it holding
* locks that the suite's teardown then waits on.
*/
function startParkedTransaction(
holdLocks: (tx: TestTransaction) => Promise<void>,
Expand All @@ -399,16 +404,18 @@ function startParkedTransaction(
})
async function untilBlocking() {
const pid = await holderPid
for (let attempt = 0; attempt < 200; attempt++) {
const deadline = Date.now() + 10_000
while (Date.now() < deadline) {
const [row] = await connection<{ blocked: number }[]>`
select count(*)::int as blocked from pg_stat_activity
where ${pid}::int = any(pg_blocking_pids(pid))`
if (row.blocked > 0) return
await new Promise<void>((resolve) => setImmediate(resolve))
await sleep(10)
}
release()
throw new Error('No transaction ever waited on the parked one')
}
return { done, release, untilBlocking }
return { done, release, locked: holderPid.then(() => undefined), untilBlocking }
}

describe('cancel_at_period_end sync', () => {
Expand Down Expand Up @@ -1037,6 +1044,7 @@ describe('Team activation', () => {
reason: 'admin-cancel-at-period-end',
})
})
await cancelling.locked
const activating = testDatabase.transaction((tx) =>
ensureTeamOrganizationForAcceptance({
billingOwnerUserId: owner.id,
Expand Down Expand Up @@ -1088,6 +1096,7 @@ describe('operator retry', () => {
})
}
)
await writing.locked
const requeuing = requeueFromAdminApi(pauseSync)
await writing.untilBlocking()
writing.release()
Expand Down Expand Up @@ -1129,6 +1138,7 @@ describe('operator retry', () => {
})
}
)
await writing.locked
const retrying = requestDashboardSubscriptionCancellation({
organizationId: org.organizationId,
operationId,
Expand Down
1 change: 1 addition & 0 deletions apps/sim/scripts/test-mobile-e2e.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1066,6 +1066,7 @@ try {
durationMs: 0,
error: getErrorMessage(error),
})
logger.error('FAIL suite setup', { error: getErrorMessage(error) })
} finally {
await check('fixtures are removed', undefined, async () => {
await sql.begin(async (tx) => {
Expand Down
Loading
Loading