From 843e79a7255d7a4c735042f4428348e62eab9704 Mon Sep 17 00:00:00 2001 From: andig Date: Sun, 12 Jul 2026 15:50:57 +0200 Subject: [PATCH] CI: extract shared build toolchain into composite action (#31726) --- .github/actions/build-toolchain/action.yml | 41 ++++++++++++++++++++++ .github/workflows/command-nightly.yml | 13 +------ .github/workflows/command-pr-build.yml | 13 ++----- 3 files changed, 44 insertions(+), 23 deletions(-) create mode 100644 .github/actions/build-toolchain/action.yml diff --git a/.github/actions/build-toolchain/action.yml b/.github/actions/build-toolchain/action.yml new file mode 100644 index 000000000..032cdad61 --- /dev/null +++ b/.github/actions/build-toolchain/action.yml @@ -0,0 +1,41 @@ +name: Build toolchain +description: Go and Node toolchain plus UI build, shared by the PR and nightly build commands. Requires the repo to be checked out first. + +inputs: + cache-scope: + description: > + Go cache namespace. "main" (default) writes the shared cache the nightly + build relies on. Untrusted callers (e.g. PR builds) should pass a + different value such as "pr": writes stay isolated so they cannot poison + the shared cache, while reads still fall back to it. + default: main + +runs: + using: composite + steps: + - uses: actions/setup-go@v6 + with: + go-version-file: go.mod + cache: false # managed explicitly below to keep the scoped namespaces + + - uses: actions/setup-node@v6 + with: + node-version: "26" + cache: "npm" + + # Writes are namespaced by cache-scope so a PR build cannot poison the + # shared "main" cache; PRs still read it through the fallback restore-key. + - name: Go module and build cache + uses: actions/cache@v6 + with: + path: | + ~/.cache/go-build + ~/go/pkg/mod + key: ${{ runner.os }}-go-toolchain-${{ inputs.cache-scope }}-${{ hashFiles('**/go.sum') }} + restore-keys: | + ${{ runner.os }}-go-toolchain-${{ inputs.cache-scope }}- + ${{ runner.os }}-go-toolchain-main- + + - name: Build UI + shell: bash + run: make install-ui ui diff --git a/.github/workflows/command-nightly.yml b/.github/workflows/command-nightly.yml index 0d94307e0..795a28371 100644 --- a/.github/workflows/command-nightly.yml +++ b/.github/workflows/command-nightly.yml @@ -41,18 +41,7 @@ jobs: fetch-depth: 0 persist-credentials: false - - uses: actions/setup-go@v6 - with: - go-version-file: go.mod - id: go - - - uses: actions/setup-node@v6 - with: - node-version: "26" - cache: "npm" - - - name: Build UI - run: make install-ui ui + - uses: ./.github/actions/build-toolchain - name: Patch ASN1 run: make patch-asn1-sudo diff --git a/.github/workflows/command-pr-build.yml b/.github/workflows/command-pr-build.yml index 07a671f0f..cc5c601dc 100644 --- a/.github/workflows/command-pr-build.yml +++ b/.github/workflows/command-pr-build.yml @@ -83,18 +83,9 @@ jobs: fetch-depth: 0 persist-credentials: false - - uses: actions/setup-go@v6 + - uses: ./.github/actions/build-toolchain with: - go-version-file: go.mod - id: go - - - uses: actions/setup-node@v6 - with: - node-version: "26" - cache: "npm" - - - name: Build UI - run: make install-ui ui + cache-scope: pr # isolated cache, cannot poison the nightly/main cache - name: Build binary env: