Files
max-sixty__worktrunk/.github/workflows/benchmarks.yaml
Worktrunk Bot 1b278042de chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary

Weekly CI renovation check found the following updates:

- `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) —
`ci.yaml` ×2, `nightly.yaml`
- `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`,
`coverage.yaml`, `actions/test-setup`, and
`scripts/codex-cloud/Taskfile.yaml`
- `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml`
- `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and
the root `Taskfile.yaml`'s `setup-web` task

The Codex Cloud archive checksums were recomputed from the new upstream
tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is
copied into both README launcher commands.

The `setup-web` PowerShell pin came in as a follow-up commit: the
initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so
the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing
tests the two PowerShell pins against each other, so that one drifts
silently — worth a note for future renovation runs. The
`powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch
downloads is present in the v7.6.5 release.

## Already up to date

- Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest
stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`,
`rust-toolchain.toml` need no change, and `flake.lock` is untouched.
- `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7,
`cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61,
`lychee` 0.24.2
- Task 3.52.0 (mise, Codex Cloud)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Held back: zola 0.22.1 → 0.23.3

Not bumped. Zola 0.23.0 shipped [Tera2 +
refactoring](https://github.com/getzola/zola/pull/3105), which is a
templating-engine swap rather than a routine release. Building `docs/`
with the 0.23.3 binary fails at the first line of `templates/base.html`:

```
ERROR error: Unknown tag
 --> base.html:1:4
  |
1 | {% import "macros.html" as macros %}
  |    ^^^^^^
```

`templates/base.html` and `templates/macros.html` are the two files that
use the `import`/`macro` pair, so the migration looks small, but it is
template work with its own review rather than a pin bump — kept out of
this PR so the rest can land. Raised separately.

<details><summary>Verification</summary>

- Every version above was read from the upstream source of truth:
`crates.io` for the cargo tools, `nushell/nushell` and
`PowerShell/PowerShell` releases, PyPI for pre-commit, and
`static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable
(1.97.1).
- Checksums were computed from the downloaded archives and the extracted
binaries were run (`nu --version` → `0.115.0`); the archive layouts
(`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are
unchanged, so the `install_binary` paths still resolve.
- All six edited YAML files parse.
- The nushell bump was exercised against the shell-integration suite:
`cargo test --features shell-integration-tests --test integration --
nushell` with 0.115.0 on `PATH`. 13 of 14 pass;
`test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it
fails identically on the currently-pinned 0.114.1, and passes on *both*
versions when run alone. It is a pre-existing shared-state race in the
sandbox, not a regression from this bump: the test asserts against the
real user `$nu.vendor-autoload-dirs` entry rather than one under its
temp `HOME` (nu resolves the home dir from the passwd database, so the
test's `HOME` override does not move it), and a sibling uninstall test
in the same filter removes `wt.nu` from that shared directory. Noted
rather than fixed here — it is unrelated to the pins.
- The zola failure above was reproduced with the official 0.23.3
`x86_64-unknown-linux-gnu` release binary against this repo's `docs/`.

</details>

---------

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-17 01:48:26 -07:00

166 lines
5.9 KiB
YAML

name: benchmarks
# Full criterion suite plus the time-series gist append. Runs ~80 min and
# checks performance, not correctness, so it stands apart from the PR/merge
# flow and from nightly's correctness checks: a slow or failing bench never
# gates a merge. The daily cron is the perf-history feed (it appends to the
# gist); workflow_dispatch covers on-demand runs against a chosen branch.
#
# Not run on PRs or pushes, so the daily run is the only signal that the bench
# harness still builds — create-issue-on-benchmark-failure surfaces a break.
#
# Runner version pinned; see ci.yaml header comment for rationale.
on:
schedule:
# 3:47 UTC daily. Off-peak, offset from nightly's 5:37 so the two long
# runs don't contend, and off :00 to be a good citizen w.r.t. GitHub's
# cron scheduler.
- cron: '47 3 * * *'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
env:
# Match ci.yaml/nightly.yaml: Swatinem/rust-cache hashes CARGO*/RUST* into
# the cache key, so the shared `test` cache only restores when these agree
# (see .github/CLAUDE.md).
CARGO_TERM_COLOR: always
CARGO_INCREMENTAL: 0
RUSTFLAGS: -C debuginfo=0
jobs:
benchmarks:
runs-on: ubuntu-24.04
steps:
- name: 📂 Checkout code
uses: actions/checkout@v7
- name: 💰 Cache
uses: Swatinem/rust-cache@v2
with:
# Restore the shared `test` cache (registry + deps), never save —
# `cargo bench` is release-profile so it rebuilds its own artifacts,
# but the dependency download/extract is still worth restoring.
prefix-key: v1-rust
shared-key: shared
cache-bin: "false"
save-if: false
- name: Install shells and jq
run: sudo apt-get update && sudo apt-get install -y zsh fish jq
- name: Install nushell
uses: hustcer/setup-nu@v3
with:
version: '0.115.0'
- name: 💰 Imported fixture cache
uses: actions/cache@v6
with:
# The fixture file pins the corpus revision. Including its hash keeps
# a prior corpus out of the cache after either constant changes.
path: target/wt-perf/bench-repos
key: bench-repos-imported-${{ runner.os }}-${{ hashFiles('benches/imported-fixture') }}
- name: 📊 Run benchmarks
run: cargo bench
- name: 📦 Upload benchmark results
uses: actions/upload-artifact@v7
with:
name: benchmark-results-${{ github.run_id }}
path: target/criterion
# Time-series benchmark store, owned by worktrunk-bot:
# https://gist.github.com/worktrunk-bot/19bb23cb9658722abfe69479d0a4f9bf
#
# Cron-only: workflow_dispatch runs aren't appended (would pollute the
# time series). Skipped on forks: the environment's secrets aren't exposed
# there.
#
# Its own job so the token stays off `benchmarks`. The copy this job reads
# is in the `tend` environment, whose policy admits `main` alone, so a job
# naming it is refused on every other ref — which would take
# workflow_dispatch against a chosen branch with it. A job GitHub skips
# never requests its environment, so the cron gate above keeps the gate off
# the dispatch path.
append-gist:
needs: benchmarks
if: github.repository_owner == 'max-sixty' && github.event_name == 'schedule'
runs-on: ubuntu-24.04
environment:
name: tend
# A secret scope, not a deploy target — see .github/CLAUDE.md.
deployment: false
permissions:
contents: read
steps:
- name: 📦 Download benchmark results
uses: actions/download-artifact@v8
with:
name: benchmark-results-${{ github.run_id }}
path: target/criterion
- name: 💾 Append results to gist
env:
GITHUB_TOKEN: ${{ secrets.TEND_BOT_TOKEN }}
GIST_ID: 19bb23cb9658722abfe69479d0a4f9bf
run: |
set -euo pipefail
timestamp="$(date -u +'%Y-%m-%dT%H:%M:%SZ')"
find target/criterion -path '*/new/estimates.json' -print0 \
| sort -z \
| xargs -0 -r jq -c --arg ts "$timestamp" --arg sha "$GITHUB_SHA" '
{
ts: $ts,
sha: $sha,
bench: (
input_filename
| sub("^target/criterion/"; "")
| sub("/new/estimates\\.json$"; "")
),
mean_ns: .mean.point_estimate,
stddev_ns: .std_dev.point_estimate
}
' > new-rows.jsonl
test -s new-rows.jsonl
git clone "https://x-access-token:${GITHUB_TOKEN}@gist.github.com/${GIST_ID}.git" /tmp/gist
cat new-rows.jsonl >> /tmp/gist/results.jsonl
git -C /tmp/gist \
-c user.name=worktrunk-bot \
-c user.email=worktrunk-bot@users.noreply.github.com \
commit -am "benchmarks: ${GITHUB_SHA::7}"
git -C /tmp/gist push
create-issue-on-benchmark-failure:
needs:
- benchmarks
- append-gist
if: always() && contains(needs.*.result, 'failure') && github.repository_owner == 'max-sixty' && github.event_name == 'schedule'
runs-on: ubuntu-24.04
environment:
name: tend
# A secret scope, not a deploy target — see .github/CLAUDE.md.
deployment: false
permissions:
contents: read
issues: write
steps:
- name: 📂 Checkout code
uses: actions/checkout@v7
- uses: JasonEtco/create-an-issue@v2
env:
# Use TEND_BOT_TOKEN for a consistent bot identity (per
# .github/CLAUDE.md) and so any future issue-triage automation can
# cascade off issue creation — events from the default GITHUB_TOKEN
# don't trigger other workflows.
GITHUB_TOKEN: ${{ secrets.TEND_BOT_TOKEN }}
LINK: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
with:
filename: .github/benchmark-failure.md
update_existing: true
search_existing: open