Skip to content

ci: skip platform validation for unrelated pull request paths - #497

Merged
coneilen merged 5 commits into
mainfrom
coneilen-microsoft-scope-ci-to-changed-paths
Sep 28, 2026
Merged

coneilen merged 5 commits into
mainfrom
coneilen-microsoft-scope-ci-to-changed-paths

Conversation

@coneilen

@coneilen coneilen commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Every PR ran every platform pipeline, including documentation-only PRs such as edits to the parity ledger (investigation/ui-parity-matrix.md) or the macOS evidence prompt. Now a PR runs the Windows, macOS shared Swift, and Linux validation only when relevant paths changed. Every required check still reports a result.

Changes

  • Classifier: Tools/ci/classify-changes.sh is a bash script kept in this repo. It diffs base.sha...head.sha and outputs windows, macos, and linux true/false values. It fails safe to full validation for events other than PRs, unknown paths, empty diffs, and diffs it can't compute. A change under Tools/ci/** turns on every suite.
  • Classifier tests: Tools/ci/tests/classify-changes.test.sh has 47 path-mapping assertions. They run in the Linux workflow's classifier job.
  • Gated jobs: each gated workflow gets a small changes job on ubuntu-latest. The existing jobs windows-shell, windows-spikes, macos, and Linux build keep their IDs and names. Each is guarded by if: !cancelled() && (event != pull_request || changes failed || output == 'true'). A job skips only when classification succeeded and said its suite isn't needed. GitHub counts a skipped job as a pass for required checks.
  • Hardening matrix: the ruleset requires the two windows-hardening.yml deterministic legs by their expanded names. A job-level if on a matrix job reports one unexpanded name and leaves both required checks pending. So the legs always run, and their steps are gated instead. A leg with nothing to check runs on ubuntu-latest and does no work. The scheduled and manual full-pinned and environment jobs are unchanged.
  • Privacy scan: the new investigation-privacy job ("Investigation privacy scan") in windows-port-validation.yml runs validate.ps1 -Task privacy on every PR, with no gate. Docs-only investigation/ PRs therefore still get checked for leaked local paths and generated artifacts. The task needs no toolchain and ran in about a second locally.
  • Always full: Linux push and merge_group still run everything. The manual-only windows-release.yml is unchanged. DCO and TDD evidence still run on every PR.
  • AGENTS.md: adds a short "Path-gated CI" note.

This uses no workflow-level paths/paths-ignore filters and no third-party path-filter actions.

Test plan

RED: bash Tools/ci/tests/classify-changes.test.sh (before classify-changes.sh existed) -> classify-changes: 0 passed, 47 failed, exit 1
GREEN: bash Tools/ci/tests/classify-changes.test.sh -> classify-changes: 49 passed, 0 failed, exit 0 (47 path mappings + 2 LF line-ending guards)
REGRESSION: pwsh -NoProfile -File Tools/windows/Tests/ValidationRunner.Tests.ps1 -> ValidationRunner.Tests.ps1: PASS; pwsh -NoProfile -File Tools/windows/validate.ps1 -Task privacy -> Privacy checks passed; actionlint v1.7.7 -> only the pre-existing unknown macos-26 runner label finding

I also ran the classifier locally in real git-diff mode:

  • This branch against main reports all true, because Tools/ci changed.
  • A synthetic commit that touches only investigation/ui-parity-matrix.md reports all false.

Not yet verified: none of the gated workflows has run in GitHub Actions. Three things are unconfirmed until real runs happen: how GitHub evaluates needs, if, and the dynamic runs-on, and whether skipped jobs satisfy the ruleset. This PR's own checks should run every suite, because the classifier changed. A later docs-only PR will be the first real test of the skipping.

CI finding on this PR: the first push committed the two classifier scripts with CRLF endings, so every Classify changed paths job failed with $'\r': command not found. As designed, the downstream jobs failed safe and ran in full. c550d35 forces *.sh to LF in .gitattributes and adds a test that asserts it; the classifier jobs now pass.

Follow-up: once "Investigation privacy scan" has reported on this PR, add it to the MainProtector required checks.

Checklist

  • I have read the Contributing Guidelines
  • I have signed off my commits (git commit -s) per the DCO
  • Tests pass locally (make test) (no macOS host here; macOS CI runs on this PR)
  • Code follows the existing style (make check) (no macOS host; no Swift changed)
  • I added the test/contract before the implementation and observed the intended RED failure

coneilen and others added 5 commits September 28, 2026 09:48
A repository-owned classifier gates the Windows, macOS shared Swift, and
Linux jobs on pull requests so documentation-only changes such as the
parity ledger skip them. Required check names stay present: plain jobs
skip (reported as success), and the required deterministic hardening
matrix legs run step-gated on a Linux runner. Non-PR events and any
classifier failure run full validation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Path gating lets docs-only investigation/ changes skip windows-spikes,
which was the only job running validate.ps1 -Task privacy. Run that
toolchain-free task in its own ungated job.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
The classifier was committed with CRLF endings, so every 'Classify changed
paths' job on #497 failed with \\$'\r': command not found\ (downstream
jobs then ran in full, as designed). Force *.sh to LF and assert it in
the classifier tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
@coneilen
coneilen merged commit 717240c into main Sep 28, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant