Skip to content

ci: run the release's Linux gate alongside the other platforms - #240

Merged
martin-fleck-at merged 1 commit into
mainfrom
ci/gate-in-parallel-with-platforms
Sep 30, 2026
Merged

martin-fleck-at merged 1 commit into
mainfrom
ci/gate-in-parallel-with-platforms

Conversation

@martin-fleck-at

Copy link
Copy Markdown
Contributor

The release workflow ran its Windows and macOS gates first and its Linux gate afterwards, inside the publishing job, so every release waited for the slowest platform leg and then for the whole Linux gate on top. This change runs all three gates in parallel in one gate job and leaves the publishing job to install, build and publish, with needs: [changes, gate]. The gate step is CI's own line, npm run check on Linux and npm run check:platform elsewhere, and CI now reddens if the two workflows' gate commands differ.

What it costs

The publishing job no longer publishes the very build that was gated. It rebuilds the same commit from the same lockfile on a fresh runner, so the guarantee becomes "this commit passed the gate" rather than "these files passed it". Handing the gated build over as an artifact would not restore the stronger form anyway, because release.mjs stamps the version into the tree after the gate. In exchange, the one job holding id-token: write now runs only the install, the build and the publish, not the whole test suite.

Times

From the first release run under the layout this replaces (run 36698204577, today):

  • Windows leg 6 m 47 s, macOS leg 6 m 0 s, in parallel.
  • Publishing job: 1 m 17 s of setup, install and build, then the Linux gate at 3 m 35 s, then the publish.
  • Start to publish: 11 m 55 s.

Under this change the Linux gate runs next to Windows and finishes first: roughly 5 minutes, estimated from the same steps. Start to publish then becomes the Windows leg plus the publishing job's 1 m 17 s, about 8 m 20 s, which saves the 3 m 35 s the Linux gate took. That figure is an estimate from one run, not a measurement of the new layout.

How I know it works

As with the previous change to this file, the new jobs cannot run before merge: CI does not execute release.yml, and dispatching it would publish. The evidence is CI's guard step, run locally against mutated copies of release.yml. Each mutation reddens it with the message it should:

  • gate dropped from the publishing job's needs:: "publishing job 'release' does not need the gate job".
  • The needs: line moved off the publishing job onto another job: the same message. Finding the line anywhere in the file is not enough.
  • The gate weakened to npm run check:platform on every leg: fails, printing both commands.
  • The Full gate step deleted: fails with <no Full gate step>.
  • macOS dropped from the os: list: the environment comparison fails, naming both lists.

The guard reads the gate command out of both files rather than spelling it: Actions expands a ${{ … }} inside a run: script before bash sees it, so a literal copy of the line would have been compared as npm run check.


Follows #237, which gave the release gate its Windows and macOS legs.

- Gate every platform in one parallel job and leave the publishing job
  to build and publish, so the Linux gate no longer waits behind the
  slowest platform leg
- Run the gate command CI runs, and redden CI when the two differ
- Assert that the publishing job needs the gate job, in place of the
  line-order check that assumed both sat in one job
@martin-fleck-at
martin-fleck-at merged commit 071c0b8 into main Sep 30, 2026
7 checks passed
@martin-fleck-at
martin-fleck-at deleted the ci/gate-in-parallel-with-platforms branch September 30, 2026 10:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant