diff --git a/.config/e2e-full-selection.txt b/.config/e2e-full-selection.txt index 611d1816a..eb0c8f9db 100644 --- a/.config/e2e-full-selection.txt +++ b/.config/e2e-full-selection.txt @@ -1,2 +1,2 @@ sha256-darwin=9e9687ded961aa4e619a15def6e1ee0a5153be05423d009ee7a58126624c83e7 -sha256-linux=7633342a1d5bfc265bdeba59f3c373c937031dc446c3f6db31360bb8c666de12 +sha256-linux=364666693c2bf258997643c9d87e07e7b7501e58175f190d201d53c81946eb20 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dac48357e..8d7134b5b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -259,9 +259,6 @@ jobs: } > artifacts/test-and-lint/doctest-diagnostics.txt exit "${status}" - - name: Check offline enrollment E2E root boundary - run: ./scripts/check_offline_enrollment_e2e.sh - - name: Upload test reports and diagnostics if: always() uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 @@ -296,6 +293,37 @@ jobs: - name: Run rebalance/decommission migration proofs run: ./scripts/check_migration_gate_count.sh + # This gate builds into a fresh target directory to isolate the E2E root. + # Give its cold build a separate budget from workspace tests and migration proofs. + offline-enrollment-e2e: + name: Offline Enrollment E2E Root Boundary + if: needs.classify-changes.outputs.mode == 'full' && (github.event_name != 'pull_request' || github.event.action != 'closed') + needs: [ quick-checks, classify-changes ] + runs-on: sm-standard-4 + timeout-minutes: 60 + env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" + steps: + - name: Checkout repository + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false + + - name: Setup Rust environment + uses: ./.github/actions/setup + with: + rust-version: stable + cache-shared-key: ci-dev + cache-save-if: 'false' + install-build-packaging-tools: 'false' + install-test-tools: 'false' + + - name: Protect Connect test home + run: chmod go-w "$(realpath "$HOME")" + + - name: Check offline enrollment E2E root boundary + run: ./scripts/check_offline_enrollment_e2e.sh + # Dedicated serial lane for the ILM / lifecycle integration tests. These tests # drive the object layer through process-global singletons (the GLOBAL_ENV # ECStore, the global tier-config manager, background-expiry workers) and bind @@ -1190,6 +1218,7 @@ jobs: - typos - quick-checks - test-and-lint + - offline-enrollment-e2e - test-ilm-integration-serial - test-and-lint-rio-v2 - connect-short-credential-boundary @@ -1223,6 +1252,7 @@ jobs: - typos - quick-checks - test-and-lint + - offline-enrollment-e2e - test-ilm-integration-serial - test-and-lint-rio-v2 - test-and-lint-protocols diff --git a/scripts/ci_gate.py b/scripts/ci_gate.py index 74442691f..e22eeec02 100644 --- a/scripts/ci_gate.py +++ b/scripts/ci_gate.py @@ -14,7 +14,7 @@ import unittest ROOT = Path(__file__).resolve().parent.parent ALWAYS_JOBS = ("classify-changes", "typos", "quick-checks") CODE_JOBS = ( - "test-and-lint", "test-ilm-integration-serial", "test-and-lint-rio-v2", + "test-and-lint", "offline-enrollment-e2e", "test-ilm-integration-serial", "test-and-lint-rio-v2", "connect-short-credential-boundary", "test-and-lint-protocols", "build-rustfs-debug-binary", "uring-integration", "e2e-tests", "s3-implemented-tests", "s3-lifecycle-behavior-tests",