Skip to content

ci: compose CI from devenv's building blocks - #954

Merged
ajslater merged 4 commits into
developfrom
v-devenv-ci
Sep 29, 2026
Merged

ajslater merged 4 commits into
developfrom
v-devenv-ci

Conversation

@ajslater

@ajslater ajslater commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

ci.yml becomes a caller of devenv's CI building blocks (the devenv-* workflows and actions, copied in by make update-devenv), plus codex's own image jobs. It's the same design as the September gate/matrix/release work, now shared with the other repos and tested in devenv.

Job What changed
ci devenv-check.yml with ci-target: codex-ci and the same four checks, described below.
build Unchanged in substance. The version now comes from ci's outputs, not from grepping pyproject.toml.
deploy Manifest, then PyPI through devenv-pypi (uv publish --check-url, so a re-run skips files already on PyPI).
deploy-hub Final releases only, now enforced at the job level instead of by skipping steps.
release devenv-release.yml: tag, GitHub Release, merge-back. Runs after deploy and deploy-hub.

What devenv-check does inside ci:

  • Gate: runs the Release Preflight on main pushes and PRs into main.
  • Dist reuse: on a main push, reuses the python-dist of an earlier run that passed on the same git tree. It keys on the tree hash, replacing the "last merged PR" lookup, and ignores runs from forks.
  • One CI image: a single image job builds codex-ci and pushes it by digest to ghcr.io/ajslater/codex-ci. The four checks pull it instead of each building and loading their own. In bochord's pilot this cut runner time by 40%.
  • Required check: becomes CI / Lint, Test & Build Dist.

Every later job reads ci's outputs (deploy, release, version, final) instead of testing the event, and gates on !cancelled() plus an explicit needs.X.result.

Removed:

  • .github/actions/ci-container, now devenv's devenv-ci-container.
  • tests/test_release_tag_script.py and the engine tests in tests/test_release_info.py. devenv owns and tests the release engine now; codex keeps its golden NEWS.md tests.

Also updated: tests/test_ci_workflow.py now pins how codex wires the blocks. CLAUDE.md describes the new graph, and its Docker section now matches the actual Dockerfile stages.

Also fixes CI Lint, which was already broken on develop.

The first commit is a routine make update-devenv:

  • the .circleci ignore lines are retired
  • the ESLint base config now lints Markdown code blocks, which reformats the YAML example in docs/DOCKER.md
  • one dependency bump

Required check on main

Done: main's branch protection now requires CI / Lint, Test & Build Dist (GitHub Actions app, strict) instead of Lint, Test & Build Dist.

Test plan

  • make fix, make lint (including actionlint on every workflow) and make ty pass
    • basedpyright reports two "unreachable code" warnings in codex/views/browser/annotate/cover.py, which this PR doesn't touch
  • make lint from a checkout with no generated choices (CI's conditions): build-choices runs first and lint passes
  • make test:
    • Python: 1568 passed, 1 known xfail
    • frontend: 930 passed
  • This PR's run:
    • Gate
    • CI Image builds codex-ci and pushes it by digest
    • Lint, Test Frontend, Test Python and Build Dist pull it and pass
    • CI / Lint, Test & Build Dist is green
    • the ci-passed-<tree> marker and python-dist are uploaded
  • build, deploy, deploy-hub and release first run on a pre-release PR or the next main push

🤖 Generated with Claude Code

ajslater and others added 4 commits September 28, 2026 20:53
- Retire the dead .circleci ignore lines (devenv's new retirement lists).
- eslint base config: presets apply again and Markdown code blocks are
  linted, which reformats the compose YAML example in docs/DOCKER.md.
- pyproject template: T201 exemption for bin/release_info.py.
- eslint-plugin-package-json bump.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ci.yml is now a caller of devenv's CI building blocks (copied in by
`make update-devenv`) plus codex's own image jobs:

- ci: devenv-check.yml with ci-target codex-ci and the same four checks.
  Its gate runs the Release Preflight and, on a main push, reuses the
  python-dist of an earlier run that passed on the same git tree (keyed
  by tree hash, replacing the "last merged PR" lookup). One image job
  builds codex-ci and pushes it by digest; each check pulls it instead of
  building and loading its own. The required check becomes
  "CI / Lint, Test & Build Dist".
- build, deploy, deploy-hub: unchanged in substance, but they read
  deploy/version/final from ci's outputs instead of testing the event or
  grepping pyproject.toml. deploy publishes to PyPI through devenv-pypi
  (uv publish --check-url) after the manifest. deploy-hub now skips at the
  job level for alphas.
- release: devenv-release.yml (tag, GitHub Release, merge-back), after
  deploy and deploy-hub.

Removes .github/actions/ci-container (now devenv-ci-container) and the
release-engine tests, which devenv owns now; codex keeps its golden
NEWS.md tests. tests/test_ci_workflow.py pins how codex wires the blocks.
CLAUDE.md describes the new graph and the current Dockerfile stages.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Since the ESLint preset fix (#931, #932), import-x/no-unresolved resolves
the frontend's `@/choices/*.json` imports, which bin/build-choices.sh
generates and git ignores. A checkout that never built them, such as CI's
fresh codex-ci container, fails `make lint` and `make fix` with 19
unresolved-import errors. Give lint and fix the same build-choices
prerequisite test-frontend and build already have.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ajslater
ajslater merged commit 8c63260 into develop Sep 29, 2026
13 checks passed
@ajslater
ajslater deleted the v-devenv-ci branch September 29, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant