返回 DeepSeek-Reasonix
CI_PERFORMANCE.md
根目录 / .github / CI_PERFORMANCE.md
1 # CI and release execution
2
3 [中文](CI_PERFORMANCE.zh-CN.md)
4
5 ## Desktop PR checks
6
7 `scripts/ci-paths.mjs` is the shared path classifier for normal and memory CI.
8 It distinguishes frontend, Go, generated protocol, Electron, native and
9 packaging inputs. Explicit documentation such as `desktop/AGENTS.md` skips
10 build and soak work, while Markdown inside the frontend remains a build input.
11 Unknown paths and unavailable diffs fail closed. Pull requests use merge-base
12 diffs; pushes use `before..sha`; normal `main-v2` pushes keep the complete
13 qualification matrix after the existing release-notes-only exception.
14
15 The desktop race sweep (`desktop-go-race`, eleven partitions) runs on `main-v2`
16 pushes and manual dispatch, never on pull requests. Pull requests still run the
17 same partitions without `-race` (`desktop-go` and the Windows groups), so a data
18 race introduced by a pull request is reported by the push run after it merges.
19
20 `desktop-prepare` regenerates the desktop host contract (failing on drift) and
21 produces the required `electron/stable` and `electron/canary` frontend variants
22 once on Linux. Each artifact carries a versioned manifest with checkout,
23 workflow attempt, variant, build inputs, toolchain and every `dist` file hash.
24 Linux, macOS and Windows consumers verify it before compilation or packaging.
25 Explicit reuse fails on a missing, stale or damaged manifest and never falls
26 back to a hidden rebuild. Static frontend files are portable; dependencies,
27 native modules and Electron binaries are not shared. Build-input verification
28 streams every committed blob through one Git batch process instead of starting
29 one process per file; the version-one digest remains byte-for-byte compatible.
30
31 The protected `lint` job aggregates `lint-code` and, when selected, the
32 complete `desktop-frontend` result. Motion unit tests remain in that frontend
33 plan and run once. `desktop-browser-group` runs application/settings/motion and
34 Transcript as two groups with `max-parallel: 2`; the `desktop-browser` summary
35 rejects failed, cancelled or unexpected skips. Go-only changes retain protocol
36 and native validation without launching browser or memory work.
37
38 `node desktop/frontend/scripts/run-ci-tests.mjs --list` prints the unit test
39 plan. It expands the existing dedicated scripts and lifecycle hooks, discovers
40 new tests, and schedules each TypeScript suite once with its original loader.
41 Unsupported script syntax and conflicting explicit invocations fail closed.
42 CI runs two isolated processes at a time; the history performance benchmark
43 runs alone after them. Local dedicated `pnpm test:*` commands remain available.
44
45 ## Timing reports
46
47 The CI and memory workflow summaries report stage execution without queue time,
48 workflow wall time, recorded job queue time and the sum of runner execution.
49 Frontend builds, dependency and browser installation, each browser group and
50 each memory shard are listed separately. These measurements describe a single
51 run; comparisons should use the same candidate and report the median and range
52 of three runs so runner variance is visible. The Windows Desktop Go step keeps
53 native non-verbose output because Go's JSON mode made Windows spend several
54 minutes finalizing verbose test-cache output; the central report records its
55 step execution time from the Actions API without wrapping the test process.
56
57 ## Memory screening
58
59 Protocol v4 records the selected screening profile in every manifest, shard and
60 aggregate. Ordinary frontend pull requests use the `short` profile: one process
61 completes 32 full, 32 windowed, 32 safety and 128 mixed round trips. Pull requests
62 that change App lifecycle, Transcript, navigation, subscription ownership, memory
63 fixtures or CI routing use the `full` profile. Pushes to `main-v2`, the daily
64 scheduled run and manual dispatches also use `full`: three independent processes
65 each complete 128 full, 128 windowed, 128 safety and 512 mixed round trips.
66
67 Both profiles keep the same evidence requirements: exact checkpoints, five heap
68 snapshots per process, GC, frame settling, source/build identity and screening
69 thresholds. Aggregation rejects missing shards and profile or protocol mismatches.
70 Only the explicit mock memory-soak URL removes the fixture's artificial
71 1.5-second hydration latency. Hydration still crosses an asynchronous timer
72 task. Default browser and native geometry fixtures retain the delayed path.
73
74 The pointer rests outside topic rows and the warmed baseline follows a complete
75 round trip after layout switching, avoiding samples of temporary menu state.
76 Reports declare the profile and protocol, and aggregation rejects older protocols.
77 `timings.json` records host-side counts, total time and maximum time for
78 navigation, frame settling, GC and heap capture/analysis. Aggregate results label
79 their `screeningLevel`, so a passing short PR screen cannot be mistaken for full
80 qualification. A green gate still does not prove offline heap-retainer attribution.
81
82 ## Signed release artifacts
83
84 The successful stable SignPath preflight hands its full native matrix to the
85 desktop publisher. The publisher revalidates authorization, candidate identity,
86 signing contract and cache/docs guards, then verifies and publishes the same
87 signed bytes without rebuilding or signing them again. CLI and npm publication
88 still wait for the entire preflight; no public surface starts early.
89
90 Each platform bundle binds file sizes and SHA-256 hashes to candidate/control
91 SHAs, version, tag, channel, signing fingerprint, run, invocation and producer
92 attempt. Missing/extra platforms, conflicting identities, symlinks, duplicate
93 filenames or modified bytes stop publication. These transport hashes supplement
94 the existing Authenticode/minisign checks; they are not signature verification.
95
96 A failed-job retry may reuse earlier successful platforms from the same run
97 and invocation. A rebuilt platform replaces only its own fully verified bundle.
98 New workflow runs prepare a new artifact set. Standalone recovery still builds
99 and validates its own full matrix. pnpm dependencies are cached by lockfile;
100 signed release artifacts are transported as artifacts, never dependency caches.
101
101 lines MARKDOWN