diff --git a/.github/workflows/ci-docs-only.yml b/.github/workflows/ci-docs-only.yml index 6cb41278f..ecd4419a7 100644 --- a/.github/workflows/ci-docs-only.yml +++ b/.github/workflows/ci-docs-only.yml @@ -12,18 +12,20 @@ # See the License for the specific language governing permissions and # limitations under the License. -# Companion to ci.yml for the required "Test and Lint" status check. +# Companion to ci.yml for the required "Test and Lint" and "Quick Checks" +# status checks. # # ci.yml skips docs-only pull requests via paths-ignore, but the branch -# ruleset requires a check named "Test and Lint" — without this workflow a -# docs-only PR would wait on that check forever. This workflow triggers on -# exactly the paths ci.yml ignores and reports an instant success under the -# same job name. Mixed PRs trigger both workflows and the real check still -# gates: a required check with any failing run blocks the merge. +# ruleset requires checks named "Test and Lint" and "Quick Checks" — without +# this workflow a docs-only PR would wait on those checks forever. This +# workflow triggers on exactly the paths ci.yml ignores and reports success +# under the same job names. Mixed PRs trigger both workflows and the real +# checks still gate: a required check with any failing run blocks the merge. # https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/troubleshooting-required-status-checks#handling-skipped-but-required-checks # # Keep the paths list below in sync with the pull_request paths-ignore list -# in ci.yml. +# in ci.yml, and keep the quick-checks steps below byte-identical to the +# quick-checks job in ci.yml (see the comment on that job). name: Continuous Integration (docs only) @@ -52,9 +54,63 @@ permissions: contents: read jobs: + # Deliberately NOT a bare `echo`. Once "Quick Checks" becomes a required + # check, ci.yml gates every expensive job behind it, so a mixed PR reports + # two check runs with this name: the real one (45-51s) and this companion. + # GitHub has no written contract for how it picks between same-named + # required check runs ("latest wins" vs "any failure blocks"), so instead of + # relying on ordering we make both runs execute the same commands against + # the same merge ref — their conclusions are then necessarily identical and + # the choice does not matter. Keep these steps byte-identical to the + # quick-checks job in ci.yml (a guard script that asserts this, and the paths + # sync below, is tracked in rustfs/backlog#1603). + # + # For a genuinely docs-only PR this adds no strictness (no code changed, so + # fmt and the guards always pass) and costs ~50s of ubuntu-latest. + quick-checks: + name: Quick Checks + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Checkout repository + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + + - name: Install ripgrep + run: sudo apt-get update && sudo apt-get install -y ripgrep + + - name: Install Rust toolchain + uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable + with: + components: rustfmt + + - name: Check code formatting + run: cargo fmt --all --check + + - name: Check unsafe code allowances + run: ./scripts/check_unsafe_code_allowances.sh + + - name: Check layered dependencies + run: ./scripts/check_layer_dependencies.sh + + - name: Check architecture migration rules + run: ./scripts/check_architecture_migration_rules.sh + + - name: Check tokio io-uring feature guard + run: ./scripts/check_no_tokio_io_uring.sh + + - name: Check extension schema boundaries + run: ./scripts/check_extension_schema_boundaries.sh + + - name: Check body-cache whitelist guard + run: ./scripts/check_body_cache_whitelist.sh + + - name: Check no planning docs committed + run: ./scripts/check_no_planning_docs.sh + test-and-lint: name: Test and Lint runs-on: ubuntu-latest + timeout-minutes: 10 steps: - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 184771d4e..096a9cffd 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -448,6 +448,13 @@ jobs: uring-integration: name: io_uring Integration (real) + # The pull_request trigger includes `closed` purely so the concurrency + # group cancels in-flight runs of a closed PR; every other job opts out of + # that run with this guard (or is skipped through its `needs` chain). This + # job had neither, so each closed/merged PR really ran the whole io_uring + # suite (measured 4m17s / 7m19s / 7m31s on runs 30678272341 / 30678117601 / + # 30662728539) and kept the cancellation run in progress for minutes. + if: github.event_name != 'pull_request' || github.event.action != 'closed' # GitHub-hosted ubuntu-latest runs a recent kernel with io_uring and, unlike # a container, applies no seccomp filter that would block io_uring_setup — so # the probe succeeds and the tests exercise the real UringBackend/FdCache/ @@ -746,7 +753,13 @@ jobs: # evaluates ILM within ~2s of the due time, well inside the poll window. s3-lifecycle-behavior-tests: name: S3 Lifecycle Behavior Tests - needs: [ build-rustfs-debug-binary ] + # Also gated on e2e-tests, matching s3-implemented-tests: when the e2e smoke + # suite is already red this lane cannot tell us anything new, and it holds a + # sm-standard-4 for up to 30 minutes doing so. Both lanes only download the + # prebuilt debug binary (no cargo build), and s3-implemented-tests — which + # already waits on e2e-tests — finishes later anyway, so a green PR's total + # wall clock is unchanged. + needs: [ build-rustfs-debug-binary, e2e-tests ] runs-on: sm-standard-4 timeout-minutes: 30 steps: