Skip to content

Commit 7fa7135

Browse files
Run pnpm install-proof as one job per Node runtime (#897)
* Run pnpm install-proof as one job per Node The pnpm install-proof matrix spawned 25 single-version jobs (one per pnpm/Node pair) whose real work is ~20 s each. Most of each job was runner setup, and any one leg that never got a runner left the run red: on 2026-10-05 20/28 pnpm runs failed, every failed leg checked being an ubuntu-latest job cancelled with no runner and no log. Group the legs by Node runtime (10, 16, 24): each job installs its pnpm versions, then runs both pinned suites per version in turn with a per-version TMPDIR so the shared cache sandbox starts empty, as it did on a fresh runner. Every pnpm/Node pair still runs on every PR and main push; a failure is reported per version via ::error. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uej6tnJfjRU8NCUz2jdDG4 * Route Gradle digests through utils::digest main has failed socket-patch-core's lib tests since Gradle support (#646) and the digest helpers (#865) both landed. The guard test production_digests_go_through_the_helpers flags three files #646 added that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and patch/sidecars/maven.rs. That breaks test, test-release and coverage on every open PR. Each inline sha1/sha256 call now goes through sha1_hex_of or sha256_hex_of, which compute the same lowercase hex. Behaviour is unchanged. Assisted-by: Claude Code:claude-opus-5-5 (cherry picked from commit 659ac2c) --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent 819c0f4 commit 7fa7135

1 file changed

Lines changed: 48 additions & 46 deletions

File tree

‎.github/workflows/pnpm-compatibility.yml‎

Lines changed: 48 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -68,39 +68,25 @@ jobs:
6868
retention-days: 7
6969

7070
install-proof:
71+
# One job per Node runtime; each walks its pnpm versions in turn. A leg
72+
# does ~20 s of work, so 25 single-version jobs spent most of their time
73+
# (and runner slots) on setup, and any one leg left waiting for a runner
74+
# failed the whole run. Every version still runs; a failure names it.
75+
name: install-proof (node ${{ matrix.node }})
7176
needs: build
7277
runs-on: ubuntu-latest
73-
timeout-minutes: 15
78+
timeout-minutes: 30
7479
strategy:
7580
fail-fast: false
7681
matrix:
7782
include:
7883
# 1.0.0 must explicitly refuse its non-durable shrinkwrap format.
79-
- {pnpm: '1.0.0', node: '10.24.1'}
80-
- {pnpm: '1.43.1', node: '10.24.1'}
81-
- {pnpm: '2.0.0', node: '10.24.1'}
82-
- {pnpm: '2.25.7', node: '10.24.1'}
83-
- {pnpm: '3.0.0', node: '10.24.1'}
84-
- {pnpm: '3.8.1', node: '10.24.1'}
85-
- {pnpm: '4.0.0', node: '16.20.2'}
86-
- {pnpm: '4.14.4', node: '16.20.2'}
87-
- {pnpm: '5.0.0', node: '16.20.2'}
88-
- {pnpm: '5.18.11', node: '16.20.2'}
89-
- {pnpm: '6.0.0', node: '16.20.2'}
90-
- {pnpm: '6.35.1', node: '16.20.2'}
91-
- {pnpm: '7.0.0', node: '16.20.2'}
92-
- {pnpm: '7.33.7', node: '16.20.2'}
93-
- {pnpm: '8.0.0', node: '16.20.2'}
94-
- {pnpm: '8.15.9', node: '16.20.2'}
95-
- {pnpm: '9.0.0', node: '24.11.1'}
96-
- {pnpm: '9.15.9', node: '24.11.1'}
97-
- {pnpm: '10.0.0', node: '24.11.1'}
98-
- {pnpm: '10.33.0', node: '24.11.1'}
99-
- {pnpm: '10.34.5', node: '24.11.1'}
100-
- {pnpm: '11.0.0', node: '24.11.1'}
101-
- {pnpm: '11.27.0', node: '24.11.1'}
102-
- {pnpm: '12.0.0', node: '24.11.1'}
103-
- {pnpm: '12.4.2', node: '24.11.1'}
84+
- node: '10.24.1'
85+
pnpm: 1.0.0 1.43.1 2.0.0 2.25.7 3.0.0 3.8.1
86+
- node: '16.20.2'
87+
pnpm: 4.0.0 4.14.4 5.0.0 5.18.11 6.0.0 6.35.1 7.0.0 7.33.7 8.0.0 8.15.9
88+
- node: '24.11.1'
89+
pnpm: 9.0.0 9.15.9 10.0.0 10.33.0 10.34.5 11.0.0 11.27.0 12.0.0 12.4.2
10490
steps:
10591
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
10692
with:
@@ -110,34 +96,50 @@ jobs:
11096
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
11197
with:
11298
node-version: '24.11.1'
113-
- name: Install the pinned package manager
99+
- name: Install the pinned package managers
114100
env:
115-
PNPM_TEST_VERSION: ${{ matrix.pnpm }}
101+
PNPM_TEST_VERSIONS: ${{ matrix.pnpm }}
116102
run: |
117-
npm install --prefix "$RUNNER_TEMP/pnpm-tool" --no-audit --no-fund "pnpm@$PNPM_TEST_VERSION"
118-
echo "SOCKET_PATCH_PNPM_E2E_BIN=$RUNNER_TEMP/pnpm-tool/node_modules/.bin/pnpm" >> "$GITHUB_ENV"
103+
for v in $PNPM_TEST_VERSIONS; do
104+
npm install --prefix "$RUNNER_TEMP/pnpm-$v" --no-audit --no-fund "pnpm@$v"
105+
done
119106
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
120107
with:
121108
node-version: ${{ matrix.node }}
122-
- name: Require installation, verified VEX, rollback and integrity rejection
109+
# Per version: installation, verified VEX, rollback and integrity
110+
# rejection, then the vendored lifecycle and manifest-less VEX (pnpm
111+
# >= 9: full vendored capstone; 7-8: the legacy lifecycle; 1-6:
112+
# vendoring refused, nothing attested). Each version gets its own
113+
# TMPDIR, so the suites' shared cache sandbox (cache_env::cache_root)
114+
# and fixtures start as empty as on a fresh runner.
115+
- name: Require every pinned pnpm to install, verify, roll back and vendor
123116
env:
124-
SOCKET_PATCH_PNPM_E2E_VERSION: ${{ matrix.pnpm }}
117+
PNPM_TEST_VERSIONS: ${{ matrix.pnpm }}
125118
SOCKET_PATCH_PNPM_E2E_REQUIRED: '1'
126119
SOCKET_NO_CONFIG: '1'
127120
SOCKET_NO_UPDATE_CHECK: '1'
128121
run: |
129-
chmod +x bin/socket-patch bin/pnpm-e2e
122+
chmod +x bin/socket-patch bin/pnpm-e2e bin/pnpm-vendor-e2e
130123
export SOCKET_PATCH_PNPM_E2E_SOCKET_BIN="$PWD/bin/socket-patch"
131-
bin/pnpm-e2e pnpm_pinned_matrix --ignored --nocapture
132-
- name: Require vendored lifecycle and manifest-less VEX
133-
# pnpm >= 9: full vendored capstone (vendor + get --mode vendored);
134-
# 7-8: the legacy lifecycle; 1-6: vendoring refused, nothing attested.
135-
env:
136-
SOCKET_PATCH_PNPM_E2E_VERSION: ${{ matrix.pnpm }}
137-
SOCKET_PATCH_PNPM_E2E_REQUIRED: '1'
138-
SOCKET_NO_CONFIG: '1'
139-
SOCKET_NO_UPDATE_CHECK: '1'
140-
run: |
141-
chmod +x bin/socket-patch bin/pnpm-vendor-e2e
142-
export SOCKET_PATCH_PNPM_E2E_SOCKET_BIN="$PWD/bin/socket-patch"
143-
bin/pnpm-vendor-e2e pnpm_pinned_matrix --ignored --nocapture
124+
failed=()
125+
for v in $PNPM_TEST_VERSIONS; do
126+
echo "::group::pnpm $v"
127+
if (
128+
export SOCKET_PATCH_PNPM_E2E_VERSION="$v"
129+
export SOCKET_PATCH_PNPM_E2E_BIN="$RUNNER_TEMP/pnpm-$v/node_modules/.bin/pnpm"
130+
export TMPDIR="$RUNNER_TEMP/tmp-$v"
131+
mkdir -p "$TMPDIR" &&
132+
bin/pnpm-e2e pnpm_pinned_matrix --ignored --nocapture &&
133+
bin/pnpm-vendor-e2e pnpm_pinned_matrix --ignored --nocapture
134+
); then
135+
echo "::endgroup::"
136+
else
137+
echo "::endgroup::"
138+
echo "::error title=pnpm $v::pnpm $v install-proof failed (expand its log group)"
139+
failed+=("$v")
140+
fi
141+
done
142+
if [ "${#failed[@]}" -ne 0 ]; then
143+
echo "Failed pnpm versions: ${failed[*]}"
144+
exit 1
145+
fi

0 commit comments

Comments
 (0)