Repository navigation
Cache the macOS vexctl build in the CI test job - #874
Merged
Mikola Lysenko (mikolalysenko) merged 2 commits intoOct 5, 2026
Merged
Conversation
The macOS `test` leg compiles vexctl (and all of sigstore/cosign) with `go install` on every run, because the v0.3.0 darwin release binaries lack LC_UUID. Over the last 39 macOS test jobs that step took a median 110s (max 168s), and it is the step's only network flake source: the sum.golang.org tile reads that the 5-attempt retry loop exists for. The binary depends only on the vexctl version, the Go toolchain that setup-go resolved and the runner OS/arch, so restore it from an actions/cache entry keyed on exactly those and skip the compile on a hit. Like the cargo cache, the entry is saved from main only. Linux and Windows keep downloading the sha256-pinned release binary; all three OSes now put the same $RUNNER_TEMP/vexctl-bin on PATH, and `vexctl version` runs on every path so a bad restore fails the step. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018DBLy7nL4ekAfds2AURvgc
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit c4924e6. Configure here.
Mikola Lysenko (mikolalysenko)
enabled auto-merge (squash)
October 5, 2026 18:14
Collaborator
Author
|
Burn-down agent: labeled Ready for review at
Generated by Claude Code |
Tanmay Singla (Tanmay182003)
approved these changes
Oct 5, 2026
Mikola Lysenko (mikolalysenko)
deleted the
ci-janitor/cache-macos-vexctl
branch
October 5, 2026 18:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Every CI run's
test (macos-latest)job compiles vexctl, including all of sigstore/cosign, withgo install github.com/openvex/vexctl@v0.3.0. It has to compile because the v0.3.0 darwin release binaries are built with go1.22.7, which emits noLC_UUID, and the macOS runner's dyld refuses to load them.testjobs,Install vexctltook a median of 110s (min 46s, max 168s, mean 106s). These timings come from the step timestamps inGET /actions/runs/<id>/jobsfor the most recent 40 completed CI runs. Main and PRs together see about 75 CI runs a day, so this is roughly 2 macOS runner-hours a day of rebuilding the same bytes.INTERNAL_ERRORstream resets there have failed otherwise-green runs. That is why the step already carries a 5-attempt retry with backoff (see the existing comment inci.yml).Root cause
The compiled binary is a pure function of the vexctl version, the Go toolchain that
setup-goresolved, and the runner OS/arch. Nothing cached it, so every run rebuilt it.Fix
Changes are to the
testjob in.github/workflows/ci.ymlonly:VEXCTL_VERSIONmoves to job-levelenv, so the cache key and the install step read the same value.actions/cache/restore(SHA-pinned to v5.1.0) on$RUNNER_TEMP/vexctl-bin. The key isvexctl-<version>-go<setup-go resolved version>-<os>-<arch>, so a Go patch bump or a vexctl bump rebuilds.go installon a cache hit. On a miss it compiles exactly as before (same 5-attempt retry), now withGOBIN=$RUNNER_TEMP/vexctl-bin. All three OSes now put the same directory onPATH, andvexctl versionruns on every path, so a bad restore fails the step loudly.The
coveragejob (Linux) is untouched. The cached binary is about 84 MB uncompressed, well inside the 10 GiB cache budget theCache cargocomment cares about.Proof
RUNNER_OS=macOS CACHE_HIT=truewith a stub binary in$RUNNER_TEMP/vexctl-binmakes the step skipgo install, run the restored binary, and write the directory to$GITHUB_PATH.$RUNNER_TEMP/vexctl-bin/vexctl,vexctl versionprints, and the directory lands on$GITHUB_PATH.e2ejob). None are in the edited range.scripts/tests/test_ci_e2e_tiers.py,test_ci_vlt_rows.pyandtest_release.pypass.Where tests run
No test moves or is removed.
tests/e2e_vex.rsstill gets a real vexctl on PATH on all three OSes, built from the same version with the same Go pin. The required-check nametest (macos-latest)is unchanged.🤖 Generated with Claude Code
https://claude.ai/code/session_018DBLy7nL4ekAfds2AURvgc
Generated by Claude Code
Note
Low Risk
Changes are limited to CI workflow steps for test tooling; application code and test selection are untouched.
Overview
The
testjob in.github/workflows/ci.ymlnow caches the macOSgo installof vexctl so PR runs can skip a ~110s compile and its sum.golang.org flake surface.VEXCTL_VERSIONmoves to job-levelenv, andsetup-gogets anidso the cache key includes the resolved Go version. Restore vexctl (macOS) restores$RUNNER_TEMP/vexctl-bin; on a hit, Install vexctl skipsgo installbut still runsvexctl versionand puts that directory onPATH. On a miss, macOS builds withGOBIN=$RUNNER_TEMP/vexctl-bin(same 5-attempt retry as before). Save vexctl (macOS) writes the cache only onmainafter a miss, matching the existing rust-cache policy. Linux/Windows still download the pinned release binaries unchanged.Reviewed by Cursor Bugbot for commit c4924e6. Configure here.
Generated by Claude Code