From 1fcd5329ccd0a3d4730ce85dd8639c0c239c345b Mon Sep 17 00:00:00 2001 From: Filip Skokan Date: Sun, 27 Sep 2026 17:34:27 +0200 Subject: [PATCH 1/3] tools: share CI and benchmark build configuration Benchmark builds kept Temporal enabled on macOS after the Nix default changed, while shared-library CI disabled it. This forced benchmarks to rebuild V8 instead of reusing the cached derivation. Define the common build defaults in a Nix shell used by CI, benchmark builds, and the V8 cache job to keep their configurations aligned. Signed-off-by: Filip Skokan Assisted-by: Codex --- .github/workflows/benchmark.yml | 12 ++---------- .github/workflows/build-shared.yml | 11 +++++++---- .github/workflows/test-shared.yml | 16 ++-------------- tools/nix/ci-shell.nix | 25 +++++++++++++++++++++++++ 4 files changed, 36 insertions(+), 28 deletions(-) create mode 100644 tools/nix/ci-shell.nix diff --git a/.github/workflows/benchmark.yml b/.github/workflows/benchmark.yml index 92bab7856bb6..d46ab7886155 100644 --- a/.github/workflows/benchmark.yml +++ b/.github/workflows/benchmark.yml @@ -121,15 +121,11 @@ jobs: --pure --keep TAR_DIR --keep FLAKY_TESTS \ --keep SCCACHE_GHA_ENABLED --keep SCCACHE_GHA_RW_MODE \ --keep ACTIONS_CACHE_SERVICE_V2 --keep ACTIONS_RESULTS_URL --keep ACTIONS_RUNTIME_TOKEN \ - --arg useSeparateDerivationForV8 true \ --arg withPerfetto ${{ matrix.perfetto || false }} \ - --arg loadJSBuiltinsDynamically false \ --arg ccache '(import {}).sccache' \ - --arg devTools '[]' \ - --arg benchmarkTools '[]' \ --run ' make build-ci -j4 V=1 && sccache --stop-server - ' + ' tools/nix/ci-shell.nix mv out/Release/node base_node - name: Checkout the merge commit @@ -141,15 +137,11 @@ jobs: nix-shell \ -I nixpkgs=./tools/nix/pkgs.nix \ --pure --keep SCCACHE_LOCAL_RW_MODE \ - --arg useSeparateDerivationForV8 true \ --arg withPerfetto ${{ matrix.perfetto || false }} \ - --arg loadJSBuiltinsDynamically false \ --arg ccache '(import {}).sccache' \ - --arg devTools '[]' \ - --arg benchmarkTools '[]' \ --run ' make build-ci -j4 V=1 - ' + ' tools/nix/ci-shell.nix env: SCCACHE_LOCAL_RW_MODE: READ_ONLY diff --git a/.github/workflows/build-shared.yml b/.github/workflows/build-shared.yml index 7d77c13e568d..995692d0afe1 100644 --- a/.github/workflows/build-shared.yml +++ b/.github/workflows/build-shared.yml @@ -17,6 +17,11 @@ on: required: false type: boolean default: false + with-perfetto: + description: Whether to enable Perfetto + required: false + type: boolean + default: false v8-nar: description: An optional name for the NAR archive for V8 that needs to be downloaded required: false @@ -85,12 +90,10 @@ jobs: -I "nixpkgs=$TAR_DIR/tools/nix/pkgs.nix" \ --pure --keep TAR_DIR --keep FLAKY_TESTS \ --keep SCCACHE_GHA_ENABLED --keep ACTIONS_CACHE_SERVICE_V2 --keep ACTIONS_RESULTS_URL --keep ACTIONS_RUNTIME_TOKEN \ - --arg loadJSBuiltinsDynamically false \ + --arg withPerfetto ${{ inputs.with-perfetto }} \ --arg ccache "${NIX_SCCACHE:-null}" \ - --arg devTools '[]' \ - --arg benchmarkTools '[]' \ --arg pkcs11 ${{ inputs.pkcs11-store-test }} \ ${{ inputs.extra-nix-flags }} \ --run ' make -C "$TAR_DIR" run-ci -j4 V=1 TEST_CI_ARGS="-p actions --measure-flakiness 9 --skip-tests=$CI_SKIP_TESTS" - ' "$TAR_DIR/shell.nix" + ' "$TAR_DIR/tools/nix/ci-shell.nix" diff --git a/.github/workflows/test-shared.yml b/.github/workflows/test-shared.yml index 1a5e9c3261fe..0e37e2dc7a8c 100644 --- a/.github/workflows/test-shared.yml +++ b/.github/workflows/test-shared.yml @@ -165,19 +165,7 @@ jobs: with: runner: ${{ matrix.runner }} with-sccache: ${{ github.base_ref == 'main' || github.ref_name == 'main' }} - extra-nix-flags: | - --arg useSeparateDerivationForV8 true \ - ${{ matrix.perfetto && '--arg withPerfetto true \' || '\' }} - ${{ endsWith(matrix.system, '-darwin') && '\ - --arg withAmaro false \ - --arg withFFI false \ - --arg withLief false \ - --arg withSQLite false \ - --arg withTemporal false \ - --arg extraConfigFlags ''[ - "--without-inspector" - "--without-node-options" - ]'' \' || '\' }} + with-perfetto: ${{ matrix.perfetto || false }} secrets: CACHIX_AUTH_TOKEN: ${{ secrets.CACHIX_AUTH_TOKEN }} @@ -209,7 +197,7 @@ jobs: id: v8-drv run: | V8_DRV=$( - nix-instantiate -E "builtins.filter (p: p.pname == ''v8'') (import $TAR_DIR/shell.nix { useSeparateDerivationForV8=true; }).buildInputs" + nix-instantiate -E "builtins.filter (p: p.pname == ''v8'') (import $TAR_DIR/tools/nix/ci-shell.nix {}).buildInputs" ) V8_STORE_PATH=$(nix-store -q --outputs "$V8_DRV") echo "V8_DRV=$V8_DRV" >> "$GITHUB_OUTPUT" diff --git a/tools/nix/ci-shell.nix b/tools/nix/ci-shell.nix new file mode 100644 index 000000000000..caaaaba5215a --- /dev/null +++ b/tools/nix/ci-shell.nix @@ -0,0 +1,25 @@ +args@{ + pkgs ? import ./pkgs.nix { }, + ... +}: +import ../../shell.nix ( + { + inherit pkgs; + useSeparateDerivationForV8 = true; + loadJSBuiltinsDynamically = false; + devTools = [ ]; + benchmarkTools = [ ]; + } + // pkgs.lib.optionalAttrs pkgs.stdenv.hostPlatform.isDarwin { + withAmaro = false; + withFFI = false; + withLief = false; + withSQLite = false; + withTemporal = false; + extraConfigFlags = [ + "--without-inspector" + "--without-node-options" + ]; + } + // args +) From b6cf7d8ccaf73c8bb901a755e450e3f47957c76c Mon Sep 17 00:00:00 2001 From: Filip Skokan Date: Mon, 28 Sep 2026 08:01:20 +0200 Subject: [PATCH 2/3] fixup! tools: share CI and benchmark build configuration --- .github/workflows/build-shared.yml | 6 ------ .github/workflows/test-shared.yml | 2 +- tools/nix/ci-shell.nix | 25 ++++++++++++++----------- 3 files changed, 15 insertions(+), 18 deletions(-) diff --git a/.github/workflows/build-shared.yml b/.github/workflows/build-shared.yml index 995692d0afe1..73f7ec6afbbf 100644 --- a/.github/workflows/build-shared.yml +++ b/.github/workflows/build-shared.yml @@ -17,11 +17,6 @@ on: required: false type: boolean default: false - with-perfetto: - description: Whether to enable Perfetto - required: false - type: boolean - default: false v8-nar: description: An optional name for the NAR archive for V8 that needs to be downloaded required: false @@ -90,7 +85,6 @@ jobs: -I "nixpkgs=$TAR_DIR/tools/nix/pkgs.nix" \ --pure --keep TAR_DIR --keep FLAKY_TESTS \ --keep SCCACHE_GHA_ENABLED --keep ACTIONS_CACHE_SERVICE_V2 --keep ACTIONS_RESULTS_URL --keep ACTIONS_RUNTIME_TOKEN \ - --arg withPerfetto ${{ inputs.with-perfetto }} \ --arg ccache "${NIX_SCCACHE:-null}" \ --arg pkcs11 ${{ inputs.pkcs11-store-test }} \ ${{ inputs.extra-nix-flags }} \ diff --git a/.github/workflows/test-shared.yml b/.github/workflows/test-shared.yml index 0e37e2dc7a8c..436ca26d94c7 100644 --- a/.github/workflows/test-shared.yml +++ b/.github/workflows/test-shared.yml @@ -165,7 +165,7 @@ jobs: with: runner: ${{ matrix.runner }} with-sccache: ${{ github.base_ref == 'main' || github.ref_name == 'main' }} - with-perfetto: ${{ matrix.perfetto || false }} + extra-nix-flags: ${{ matrix.perfetto && '--arg withPerfetto true' || '' }} secrets: CACHIX_AUTH_TOKEN: ${{ secrets.CACHIX_AUTH_TOKEN }} diff --git a/tools/nix/ci-shell.nix b/tools/nix/ci-shell.nix index caaaaba5215a..3e804f0f2dc6 100644 --- a/tools/nix/ci-shell.nix +++ b/tools/nix/ci-shell.nix @@ -10,16 +10,19 @@ import ../../shell.nix ( devTools = [ ]; benchmarkTools = [ ]; } - // pkgs.lib.optionalAttrs pkgs.stdenv.hostPlatform.isDarwin { - withAmaro = false; - withFFI = false; - withLief = false; - withSQLite = false; - withTemporal = false; - extraConfigFlags = [ - "--without-inspector" - "--without-node-options" - ]; - } + // pkgs.lib.optionalAttrs pkgs.stdenv.hostPlatform.isDarwin ( + # Disable optional features on Darwin for coverage and faster CI. + builtins.mapAttrs (n: v: false) ( + pkgs.lib.filterAttrs (n: v: builtins.match "with[A-Z].+" n != null) ( + builtins.functionArgs (import ../../shell.nix) + ) + ) + // { + extraConfigFlags = [ + "--without-inspector" + "--without-node-options" + ]; + } + ) // args ) From 52f23c9d9f9dadd65df6b2db87a2b03e135a074b Mon Sep 17 00:00:00 2001 From: Filip Skokan Date: Mon, 28 Sep 2026 09:50:28 +0200 Subject: [PATCH 3/3] fixup! tools: share CI and benchmark build configuration --- tools/nix/ci-shell.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/tools/nix/ci-shell.nix b/tools/nix/ci-shell.nix index 3e804f0f2dc6..b446c9e33d3b 100644 --- a/tools/nix/ci-shell.nix +++ b/tools/nix/ci-shell.nix @@ -18,6 +18,7 @@ import ../../shell.nix ( ) ) // { + withSSL = true; # no-SSL coverage is ensured by Jenkins extraConfigFlags = [ "--without-inspector" "--without-node-options"