Skip to content

ci: skip platform builds and CI setup for quest and docs-only diffs - #4407

Merged
kixelated merged 1 commit into
mainfrom
claude/ci-performance-optimization-198c0f
Sep 28, 2026
Merged

kixelated merged 1 commit into
mainfrom
claude/ci-performance-optimization-198c0f

Conversation

@kixelated

Copy link
Copy Markdown
Collaborator

Problem

A quest-only PR (e.g. #4367) ran 7 checks, including Windows, macOS, and two OBS builds on the most expensive runners (10-13 min each). platform.yml was unfiltered on the assumption it finishes before check.yml, which doesn't hold for light diffs. Check and Test also spent ~90s each on disk cleanup and Rust cache restore, and Test ran ~75s of nix setup to test nothing.

Approach

  • platform.yml: path filter on rs/, cpp/, .cargo/, Cargo.{toml,lock}, rust-toolchain.toml, justfile, and itself, for both PR and push. 26 of the last 60 merged PRs would skip it.
  • platform.yml, android.yml: install just as a checksummed prebuilt binary (taiki-e/install-action) instead of cargo install (118-142s).
  • check.yml: a Scope step classifies the diff. When it touches only quest/, .claude/, or root *.md, Check skips disk cleanup and the Rust cache (still runs quest check and the Markdown lints), and Test skips all steps and reports green. doc/ is not in the light set because just js check builds js/wasm through cargo.

Quest-only PR after this: Check (~2 min) and Test (~15s). Platform doesn't run.

Impact

  • No public API or wire changes. CI only.
  • Platform is not a required check, so a path filter can't leave a PR pending. Check and Test (required) still always report.

Alternatives

  • Gate Platform with a changes job instead of paths:. Unnecessary since it isn't required.
  • Cache the nix dev shell closure (~75s of copying path per job). Larger change; left as a follow-up.

Follow-ups

  • Cache the nix store across runs to cut dev-shell setup in every Check/Test job.

(Written by Claude Opus 5.5)

🤖 Generated with Claude Code

Platform (Windows, macOS, and both OBS builds) now runs only when the Rust
workspace or the OBS plugin changes, and installs a prebuilt just instead of
compiling it. Check and Test skip disk cleanup and the Rust cache when the diff
touches only quests, .claude/, or root Markdown; Test skips entirely.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kixelated
kixelated marked this pull request as ready for review September 28, 2026 21:40
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T21:43:51.476643Z d169d9a Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5af3f56f-c664-43d6-94f4-320c0be2b07f

📥 Commits

Reviewing files that changed from the base of the PR and between 3ea7002 and d169d9a.

📒 Files selected for processing (3)
  • .github/workflows/android.yml
  • .github/workflows/check.yml
  • .github/workflows/platform.yml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review.


Walkthrough

The check and test jobs now use changed-path detection to conditionally run cleanup and build steps. The platform workflow filters pushes and pull requests by path. The Android workflow installs cargo-ndk with Cargo, while the Android, Windows, and macOS workflows install the pinned just version through an action.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to d169d

Quest-only changes retain their Check validation while skipping selected build setup. No actionable merge-blocking issue remains after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d169d

The changed-path gates leave the Check job running for light diffs and include the OBS build configuration in the Platform trigger. No introduced security failure was established, but branch enforcement and complete validation coverage could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected security-control surface is CI validation and runner execution, not a demonstrated change in production service authority. A skipped Platform run removes its Windows, macOS, and OBS validation for that diff.

Trust Boundaries and Controls

  • observed — PR-controlled changed paths select the Check/Test scope. Check retains contents-read and OIDC-token permissions and runs its check command regardless of the new build-scope output; the inspected Platform jobs use contents-read and disable checkout credential persistence.

Resilience and Maintainability Implications

  • inferred — A light-diff Test result can be green without executing tests by design. Check remains the active validation path for those PRs; whether protected branches enforce that path cannot be established from the repository evidence inspected.

Hardening Proposals

  • proposed — Confirm that branch rules enforce Check for PRs and restrict direct pushes where equivalent validation is required; periodically compare Platform's path list with its build inputs.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main CI change: skipping platform builds and CI setup for quest-only and documentation-only diffs.
Description check ✅ Passed The description is directly related to the workflow changes. It explains the problem, implementation, performance impact, scope, and follow-up work.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kixelated
kixelated merged commit c9028b0 into main Sep 28, 2026
4 of 8 checks passed
@kixelated
kixelated deleted the claude/ci-performance-optimization-198c0f branch September 28, 2026 21:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant