diff --git a/.github/actions/install-node-dependencies/action.yml b/.github/actions/install-node-dependencies/action.yml index 6aecef6e152..146d83debca 100644 --- a/.github/actions/install-node-dependencies/action.yml +++ b/.github/actions/install-node-dependencies/action.yml @@ -2,6 +2,10 @@ name: Install Node dependencies description: Installs the Node toolchain and repository dependencies for CI jobs, with optional Electron archive caching. inputs: + cache-pnpm-verification: + description: Restore pnpm's policy-checked lockfile verification record on Linux. + required: false + default: 'true' native-runtime: description: Native runtime to prepare after the script-free install (none, node, or electron). required: false @@ -24,6 +28,15 @@ inputs: default: 'false' outputs: + verification-cache-hit: + description: Whether pnpm's verification record was restored. + value: ${{ steps.verification-cache-restore.outputs.cache-hit }} + verification-cache-path: + description: The small pnpm-owned verification record, without registry metadata. + value: ${{ steps.verification-cache.outputs.path }} + verification-cache-key: + description: Exact verification record key, also used by the isolated PR benchmark. + value: ${{ steps.verification-cache.outputs.key }} node-version: description: Resolved Node.js version used for the install. value: ${{ steps.requested-node.outputs.node-version || steps.default-node.outputs.node-version }} @@ -86,6 +99,25 @@ runs: path: ${{ steps.pnpm-store.outputs.path }} key: node-cache-${{ runner.os }}-${{ steps.pnpm-store.outputs.arch }}-pnpm-${{ hashFiles(inputs.cache-dependency-path) }} + - name: Resolve pnpm verification cache + id: verification-cache + if: runner.os == 'Linux' && inputs.cache-pnpm-verification == 'true' + shell: bash + env: + POLICY_HASH: ${{ hashFiles('pnpm-lock.yaml', 'pnpm-workspace.yaml', '.npmrc') }} + run: | + printf 'path=%s/lockfile-verified.jsonl\n' "$(pnpm cache path)" >> "$GITHUB_OUTPUT" + printf 'key=pnpm-verification-v1-%s-%s-%s-%s\n' "$RUNNER_OS" "$RUNNER_ARCH" "$(pnpm --version)" "$POLICY_HASH" >> "$GITHUB_OUTPUT" + + - name: Restore pnpm verification record + id: verification-cache-restore + if: steps.verification-cache.outputs.key != '' + continue-on-error: true + uses: actions/cache/restore@v5 + with: + path: ${{ steps.verification-cache.outputs.path }} + key: ${{ steps.verification-cache.outputs.key }} + - name: Validate native runtime shell: bash env: @@ -120,6 +152,15 @@ runs: git -C "$GITHUB_WORKSPACE" diff --exit-code -- package.json pnpm-lock.yaml pnpm-workspace.yaml fi + # pnpm checks the cached record's policy and validity; never bypass verification. + - name: Save pnpm verification record on main + if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request' && steps.verification-cache.outputs.key != '' && steps.verification-cache-restore.outputs.cache-hit != 'true' + continue-on-error: true + uses: actions/cache/save@v5 + with: + path: ${{ steps.verification-cache.outputs.path }} + key: ${{ steps.verification-cache.outputs.key }} + - name: Resolve Electron package cache id: electron-package-cache if: inputs.native-runtime == 'electron' || inputs.cache-electron-package == 'true' diff --git a/.github/workflows/ci-pnpm-verification-pilot.yml b/.github/workflows/ci-pnpm-verification-pilot.yml new file mode 100644 index 00000000000..2a35a52fcd0 --- /dev/null +++ b/.github/workflows/ci-pnpm-verification-pilot.yml @@ -0,0 +1,65 @@ +name: pnpm verification cache pilot + +on: + pull_request: + paths: ['.github/workflows/ci-pnpm-verification-pilot.yml'] + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: pnpm-verification-pilot-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +env: + ORCA_BACKGROUND_LAUNCH: '1' + +jobs: + seed: + strategy: + matrix: + runner: [ubuntu-latest, ubuntu-24.04-arm] + runs-on: ${{ matrix.runner }} + timeout-minutes: 15 + steps: + - uses: actions/checkout@v6 + with: + persist-credentials: false + - uses: ./.github/actions/install-node-dependencies + id: deps + # PR caches are scoped to the PR merge ref; main never restores them. + - uses: actions/cache/save@v5 + if: steps.deps.outputs.verification-cache-hit != 'true' + with: + path: ${{ steps.deps.outputs.verification-cache-path }} + key: ${{ steps.deps.outputs.verification-cache-key }} + + measure: + needs: seed + name: measure ${{ matrix.runner }} sample ${{ matrix.sample }} cache ${{ matrix.cache }} + strategy: + fail-fast: false + max-parallel: 4 + matrix: + runner: [ubuntu-latest, ubuntu-24.04-arm] + sample: [1, 2, 3] + cache: ['false', 'true'] + runs-on: ${{ matrix.runner }} + timeout-minutes: 15 + steps: + - uses: actions/checkout@v6 + with: + persist-credentials: false + - uses: ./.github/actions/install-node-dependencies + id: deps + with: + cache-pnpm-verification: ${{ matrix.cache }} + - name: Validate treatment and frozen install + env: + CACHE_ENABLED: ${{ matrix.cache }} + CACHE_HIT: ${{ steps.deps.outputs.verification-cache-hit }} + run: | + if [ "$CACHE_ENABLED" = true ]; then test "$CACHE_HIT" = true; fi + git diff --exit-code -- package.json pnpm-lock.yaml pnpm-workspace.yaml + node -e "require.resolve('vitest'); require.resolve('electron')" diff --git a/config/scripts/ci-dependency-download-cache.test.mjs b/config/scripts/ci-dependency-download-cache.test.mjs index fad103d8fa6..0f615fd3712 100644 --- a/config/scripts/ci-dependency-download-cache.test.mjs +++ b/config/scripts/ci-dependency-download-cache.test.mjs @@ -48,7 +48,11 @@ describe('CI dependency download caches', () => { action.runs.steps.findIndex((step) => step.name === 'Install dependencies') ) const saves = action.runs.steps.filter((step) => step.uses === 'actions/cache/save@v5') - expect(saves).toEqual([]) + expect(saves).toHaveLength(1) + expect(saves[0].name).toBe('Save pnpm verification record on main') + expect(saves[0].if).toContain("github.ref == 'refs/heads/main'") + expect(saves[0].if).toContain("github.event_name != 'pull_request'") + expect(saves[0].with.path).toBe('${{ steps.verification-cache.outputs.path }}') }) it('restores Windows packaging downloads from the release cache without a PR upload', () => { diff --git a/config/scripts/mobile-release-shell-switch-workflow.test.mjs b/config/scripts/mobile-release-shell-switch-workflow.test.mjs index 28b94945cc2..40cc20a95ba 100644 --- a/config/scripts/mobile-release-shell-switch-workflow.test.mjs +++ b/config/scripts/mobile-release-shell-switch-workflow.test.mjs @@ -120,6 +120,8 @@ const BUNDLER_CACHE_PATHS = ['metro-cache', '.expo', 'node_modules/.cache'] const REVIEWED_COMPUTED_PATHS = [ '${{ steps.electron-package-cache.outputs.cache-root }}', '${{ steps.pnpm-store.outputs.path }}', + // Only pnpm's lockfile-verified.jsonl record, never Metro transforms. + '${{ steps.verification-cache.outputs.path }}', "${{ github.event_name != 'pull_request' && 'pnpm' || '' }} store" ]