ci: skip platform validation for unrelated pull request paths - #497
Merged
Merged
Conversation
A repository-owned classifier gates the Windows, macOS shared Swift, and Linux jobs on pull requests so documentation-only changes such as the parity ledger skip them. Required check names stay present: plain jobs skip (reported as success), and the required deterministic hardening matrix legs run step-gated on a Linux runner. Non-PR events and any classifier failure run full validation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Path gating lets docs-only investigation/ changes skip windows-spikes, which was the only job running validate.ps1 -Task privacy. Run that toolchain-free task in its own ungated job. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Colin Neilens <coneilen@microsoft.com>
The classifier was committed with CRLF endings, so every 'Classify changed paths' job on #497 failed with \\$'\r': command not found\ (downstream jobs then ran in full, as designed). Force *.sh to LF and assert it in the classifier tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Colin Neilens <coneilen@microsoft.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every PR ran every platform pipeline, including documentation-only PRs such as edits to the parity ledger (
investigation/ui-parity-matrix.md) or the macOS evidence prompt. Now a PR runs the Windows, macOS shared Swift, and Linux validation only when relevant paths changed. Every required check still reports a result.Changes
Tools/ci/classify-changes.shis a bash script kept in this repo. It diffsbase.sha...head.shaand outputswindows,macos, andlinuxtrue/false values. It fails safe to full validation for events other than PRs, unknown paths, empty diffs, and diffs it can't compute. A change underTools/ci/**turns on every suite.Tools/ci/tests/classify-changes.test.shhas 47 path-mapping assertions. They run in the Linux workflow's classifier job.changesjob onubuntu-latest. The existing jobswindows-shell,windows-spikes,macos, andLinux buildkeep their IDs and names. Each is guarded byif: !cancelled() && (event != pull_request || changes failed || output == 'true'). A job skips only when classification succeeded and said its suite isn't needed. GitHub counts a skipped job as a pass for required checks.windows-hardening.ymldeterministic legs by their expanded names. A job-levelifon a matrix job reports one unexpanded name and leaves both required checks pending. So the legs always run, and their steps are gated instead. A leg with nothing to check runs onubuntu-latestand does no work. The scheduled and manualfull-pinnedandenvironmentjobs are unchanged.investigation-privacyjob ("Investigation privacy scan") inwindows-port-validation.ymlrunsvalidate.ps1 -Task privacyon every PR, with no gate. Docs-onlyinvestigation/PRs therefore still get checked for leaked local paths and generated artifacts. The task needs no toolchain and ran in about a second locally.pushandmerge_groupstill run everything. The manual-onlywindows-release.ymlis unchanged. DCO and TDD evidence still run on every PR.This uses no workflow-level
paths/paths-ignorefilters and no third-party path-filter actions.Test plan
RED: bash Tools/ci/tests/classify-changes.test.sh (before classify-changes.sh existed) -> classify-changes: 0 passed, 47 failed, exit 1
GREEN: bash Tools/ci/tests/classify-changes.test.sh -> classify-changes: 49 passed, 0 failed, exit 0 (47 path mappings + 2 LF line-ending guards)
REGRESSION: pwsh -NoProfile -File Tools/windows/Tests/ValidationRunner.Tests.ps1 -> ValidationRunner.Tests.ps1: PASS; pwsh -NoProfile -File Tools/windows/validate.ps1 -Task privacy -> Privacy checks passed; actionlint v1.7.7 -> only the pre-existing unknown
macos-26runner label findingI also ran the classifier locally in real git-diff mode:
mainreports all true, becauseTools/cichanged.investigation/ui-parity-matrix.mdreports all false.Not yet verified: none of the gated workflows has run in GitHub Actions. Three things are unconfirmed until real runs happen: how GitHub evaluates
needs,if, and the dynamicruns-on, and whether skipped jobs satisfy the ruleset. This PR's own checks should run every suite, because the classifier changed. A later docs-only PR will be the first real test of the skipping.CI finding on this PR: the first push committed the two classifier scripts with CRLF endings, so every
Classify changed pathsjob failed with$'\r': command not found. As designed, the downstream jobs failed safe and ran in full. c550d35 forces*.shto LF in.gitattributesand adds a test that asserts it; the classifier jobs now pass.Follow-up: once "Investigation privacy scan" has reported on this PR, add it to the MainProtector required checks.
Checklist
git commit -s) per the DCOmake test) (no macOS host here; macOS CI runs on this PR)make check) (no macOS host; no Swift changed)