ci: select affected extension packages for PR boundary checks (#162640)

PR boundary selection: check only extension packages the PR's own diff can affect. When core/SDK declaration inputs change, select directly touched extension packages, a fixed smoke set of at most three broad SDK consumers, and packages that import a changed public plugin-sdk entry directly; skip transitive declaration fan-out. Hourly/schedule and release keep the full boundary check and the negative canary. Kill switch: repository variable OPENCLAW_CI_BOUNDARY_SELECTION=full restores full PR selection (unset means aggressive).

Backtest: all 10 historical PR boundary failures remain selected. 20-PR replay: modeled boundary median 7:22 -> 2:55 (conservative 4:49).

Merged past one inherited red: published-driver-update / Published driver update was cancelled at its 10-minute job timeout. It is cancelled the same way on main in hourlies 36863974207 and 36869865743, and its owner is fixing it (reuse build artifacts; timeout becomes a failure with reason). All other 67 jobs, including tooling, passed.
This commit is contained in:
Peter Steinberger 2026-10-01 07:36:04 -07:00 • committed by GitHub
parent 150e60a613
commit cd8907aa0c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 453 additions and 7 deletions

View file

@ -4136,7 +4136,6 @@ jobs:
needs: [preflight]
if: ${{ !cancelled() && always() && needs.preflight.outputs.run_check_additional == 'true' }}
runs-on: ${{ (github.event_name == 'workflow_dispatch' && startsWith(inputs.dispatch_id, 'full-release-validation-') && vars.OPENCLAW_RELEASE_RUNNER_GROUP || '') != '' && fromJSON(format('{{"group":{0},"labels":{1}}}', toJSON((github.event_name == 'workflow_dispatch' && startsWith(inputs.dispatch_id, 'full-release-validation-') && vars.OPENCLAW_RELEASE_RUNNER_GROUP || '')), toJSON((contains(fromJSON('["hybrid","runson"]'), (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND)) && github.run_attempt == 1 && needs.preflight.outputs.hybrid_hosted_checks == 'true' && contains(fromJSON('["runtime-topology-architecture","dependencies"]'), matrix.group)) && 'ubuntu-24.04' || (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND) == 'github' && 'ubuntu-24.04' || (contains(fromJSON('["hybrid","runson"]'), (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND)) && (github.run_attempt > 1 || !contains(fromJSON('["extension-package-boundary","runtime-topology-architecture","plugin-sdk-api-diff","dependencies"]'), matrix.group))) && 'ubuntu-24.04' || ((github.event_name == 'workflow_dispatch' && ((needs.preflight.outputs.node_runner_backend != 'runson' && needs.preflight.outputs.ci_qualification != 'true') || github.run_attempt != 1)) || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository && github.run_attempt > 1)) && 'ubuntu-24.04' || (github.repository == 'openclaw/openclaw' && (github.event_name != 'pull_request' || contains(fromJSON('["OWNER","MEMBER","COLLABORATOR","CONTRIBUTOR"]'), github.event.pull_request.author_association)) && (matrix.runner || 'blacksmith-4vcpu-ubuntu-2404') || 'ubuntu-24.04')))) || ((contains(fromJSON('["hybrid","runson"]'), (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND)) && github.run_attempt == 1 && needs.preflight.outputs.hybrid_hosted_checks == 'true' && contains(fromJSON('["runtime-topology-architecture","dependencies"]'), matrix.group)) && 'ubuntu-24.04' || (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND) == 'github' && 'ubuntu-24.04' || (contains(fromJSON('["hybrid","runson"]'), (needs.preflight.outputs.ci_qualification == 'true' && (github.run_attempt == 1 && needs.preflight.outputs.qualification_runner_backend || 'github') || vars.OPENCLAW_CI_RUNNER_BACKEND)) && (github.run_attempt > 1 || !contains(fromJSON('["extension-package-boundary","runtime-topology-architecture","plugin-sdk-api-diff","dependencies"]'), matrix.group))) && 'ubuntu-24.04' || ((github.event_name == 'workflow_dispatch' && ((needs.preflight.outputs.node_runner_backend != 'runson' && needs.preflight.outputs.ci_qualification != 'true') || github.run_attempt != 1)) || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository && github.run_attempt > 1)) && 'ubuntu-24.04' || (github.repository == 'openclaw/openclaw' && (github.event_name != 'pull_request' || contains(fromJSON('["OWNER","MEMBER","COLLABORATOR","CONTRIBUTOR"]'), github.event.pull_request.author_association)) && (matrix.runner || 'blacksmith-4vcpu-ubuntu-2404') || 'ubuntu-24.04')) }}
# Cold package validation exceeds 20 min on 4-CPU hosted runners.
timeout-minutes: ${{ matrix.group == 'extension-package-boundary' && 30 || 20 }}
strategy:
fail-fast: false
@ -4168,10 +4167,8 @@ jobs:
if: &additional_boundary_sticky_disk_gate matrix.group == 'extension-package-boundary' && steps.extension-boundary-inputs.outputs.enabled == 'true' && vars.OPENCLAW_CI_RUNNER_BACKEND != 'github' && !contains(fromJSON('["hybrid","runson"]'), vars.OPENCLAW_CI_RUNNER_BACKEND) && github.event_name != 'workflow_dispatch' && github.repository == 'openclaw/openclaw' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == 'openclaw/openclaw')
uses: useblacksmith/stickydisk@94697d49e77d0dd78b77deb85ad3de63a28b4b8a # v1.7.1
with:
# Stable disk keys avoid quota exhaustion; markers detect source/toolchain changes.
key: ${{ github.repository }}-ext-boundary-v2
path: /var/tmp/openclaw-ext-boundary
# Only protected successful pushes publish. Explicit commit:true refreshes same-size changes.
commit: ${{ github.event_name != 'pull_request' && 'true' || 'false' }}
- name: Restore extension boundary artifacts from sticky disk
@ -4185,8 +4182,6 @@ jobs:
echo "restored=false" >> "$GITHUB_OUTPUT"
exit 0
fi
# Restore an exact-commit transport snapshot here. The preparer still
# validates per-owner content, topology, toolchain and output inventories.
current_fingerprint="${{ steps.extension-boundary-inputs.outputs.fingerprint }}"
if [ ! -f "$sticky_root/.source-fingerprint" ] || [ "$current_fingerprint" != "$(cat "$sticky_root/.source-fingerprint")" ]; then
echo "boundary source trees changed since snapshot; building cold"
@ -4225,8 +4220,9 @@ jobs:
RUN_PROMPT_SNAPSHOTS: ${{ needs.preflight.outputs.run_prompt_snapshots }}
OPENCLAW_ADDITIONAL_BOUNDARY_SHARD: ""
OPENCLAW_ADDITIONAL_BOUNDARY_CONCURRENCY: 4
# Runner labels are not CPU counts; preserve the CI worker budget.
OPENCLAW_EXTENSION_BOUNDARY_CONCURRENCY: 16
OPENCLAW_CI_EXTENSION_BOUNDARY_BASE: ${{ needs.preflight.outputs.diff_base_revision }}
OPENCLAW_CI_EXTENSION_BOUNDARY_FULL: ${{ vars.OPENCLAW_CI_EXTENSION_BOUNDARY_FULL }}
shell: bash
run: |
set -euo pipefail