@@ -350,7 +350,8 @@ jobs:
350350 # (.github/scripts/find-turbo-origins.sh has the exact conditions), and
351351 # its turbo-compile-core leg skips the build altogether: it runs on
352352 # ubuntu-latest, outside any build container, and only carries that core
353- # over into this run. The per-version extensions always compile (a
353+ # over into this run. The same goes for each turbo-shared-core-gate
354+ # leg's fingerprint. The per-version extensions always compile (a
354355 # minute each) against it, then go through the version check and the
355356 # differential tests of the turbo-differential jobs like any build —
356357 # they compare the native side with the PHP side of this commit, which
@@ -1030,31 +1031,114 @@ jobs:
10301031 # compile to identical code against each supported version's — a source
10311032 # reading a member whose offset moved, a constant whose value changed or
10321033 # a function whose signature did would otherwise misbehave on the other
1033- # versions only, on the paths that touch it. Compiles every source
1034- # against each version's (and the 8.6 thread-safe) headers in the CI
1035- # build images with clang, and fails on any difference outside the
1036- # version-specific sources (turbo-ext/bin/shared-core/check-linux.sh).
1034+ # versions only, on the paths that touch it. Each leg compiles every
1035+ # source against one version's headers in its CI build image with clang
1036+ # and uploads a fingerprint of the result (a hash per function, data
1037+ # section and relocation table, see turbo-ext/bin/shared-core/gate.py);
1038+ # turbo-shared-core-gate-compare compares them. A leg whose fingerprint
1039+ # turbo-origins found in an earlier run from identical build inputs only
1040+ # carries it over, like a reused core.
1041+ needs : turbo-origins
10371042 runs-on : " ubuntu-latest"
1038- timeout-minutes : 40
1043+ timeout-minutes : 30
1044+
1045+ permissions :
1046+ contents : read # actions/checkout of this repository
1047+ actions : read # downloads a reused fingerprint from an earlier run, see turbo-origins
1048+
1049+ env :
1050+ GATE_ARTIFACT : " turbo-gate-fingerprint-${{ matrix.php-version }}"
1051+ ORIGIN_RUN_ID : ${{ fromJSON(needs.turbo-origins.outputs.origins || '{}')[format('turbo-gate-fingerprint-{0}', matrix.php-version)] }}
1052+
1053+ strategy :
1054+ fail-fast : false
1055+ matrix :
1056+ # every PHP the cores run on; thread-safe builds are "<minor>-zts"
1057+ php-version : ["8.3", "8.4", "8.5", "8.6", "8.3-zts", "8.4-zts", "8.5-zts", "8.6-zts"]
10391058
10401059 steps :
10411060 - name : Harden the runner (Audit all outbound calls)
10421061 uses : step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
10431062 with :
10441063 egress-policy : audit
10451064
1065+ - name : " Download the fingerprint compiled from identical build inputs"
1066+ if : env.ORIGIN_RUN_ID != ''
1067+ uses : actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
1068+ with :
1069+ name : ${{ env.GATE_ARTIFACT }}
1070+ path : " fingerprints"
1071+ run-id : ${{ env.ORIGIN_RUN_ID }}
1072+ github-token : ${{ github.token }}
1073+
1074+ - name : " Record the run that compiled the fingerprint"
1075+ if : env.ORIGIN_RUN_ID != ''
1076+ run : echo "$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$ORIGIN_RUN_ID" | tee turbo-reused.txt
1077+
10461078 - name : " Checkout"
1079+ if : env.ORIGIN_RUN_ID == ''
10471080 uses : actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
10481081 with :
10491082 persist-credentials : false
10501083
1051- - name : " Compare the shared code across the supported PHP versions"
1084+ - name : " Compile against the PHP ${{ matrix.php-version }} headers and fingerprint the result"
1085+ if : env.ORIGIN_RUN_ID == ''
10521086 env :
10531087 SHARED_CORE_WORK_DIR : ${{ runner.temp }}/shared-core
1088+ GATE_VERSIONS : ${{ matrix.php-version }}
10541089 run : |
1055- mkdir -p "$SHARED_CORE_WORK_DIR"
1056- bash turbo-ext/bin/shared-core/check-linux.sh
1090+ mkdir -p "$SHARED_CORE_WORK_DIR" fingerprints
1091+ GATE_JOBS="$(nproc)" bash turbo-ext/bin/shared-core/fingerprint-linux.sh
1092+ cp "$SHARED_CORE_WORK_DIR/fingerprints/fingerprint-$GATE_VERSIONS.tsv" fingerprints/
1093+
1094+ - name : " Upload the fingerprint"
1095+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
1096+ with :
1097+ name : ${{ env.GATE_ARTIFACT }}
1098+ path : " fingerprints/fingerprint-${{ matrix.php-version }}.tsv"
1099+ if-no-files-found : " error"
1100+
1101+ - name : " Mark the fingerprint as reused"
1102+ if : env.ORIGIN_RUN_ID != ''
1103+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
1104+ with :
1105+ name : " turbo-reused-${{ env.GATE_ARTIFACT }}"
1106+ path : " turbo-reused.txt"
1107+ if-no-files-found : " error"
1108+
1109+ turbo-shared-core-gate-compare :
1110+ name : " Turbo Shared Core Gate (compare)"
1111+ # Fails on any function, data section or relocation table outside the
1112+ # version-specific sources (Abi.cpp, Shadow.cpp, TrustedTypes.cpp,
1113+ # main.cpp) whose fingerprint differs from the build against the
1114+ # version the cores are compiled against (turbo-compile-core). Not a
1115+ # gate of the commit job, like the other jobs that only test the
1116+ # shipped bits (see there).
1117+ needs : turbo-shared-core-gate
1118+ runs-on : " ubuntu-latest"
1119+ timeout-minutes : 5
1120+
1121+ steps :
1122+ - name : Harden the runner (Audit all outbound calls)
1123+ uses : step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
1124+ with :
1125+ egress-policy : audit
10571126
1127+ - name : " Checkout"
1128+ uses : actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
1129+ with :
1130+ persist-credentials : false
1131+ sparse-checkout : turbo-ext/bin/shared-core
1132+
1133+ - name : " Download the fingerprints"
1134+ uses : actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
1135+ with :
1136+ pattern : " turbo-gate-fingerprint-*"
1137+ path : " fingerprints"
1138+ merge-multiple : true
1139+
1140+ - name : " Compare the shared code across the supported PHP versions"
1141+ run : python3 -I turbo-ext/bin/shared-core/gate.py compare 8.5 fingerprints
10581142 turbo-docker-run :
10591143 name : " Run with Turbo Extension (Docker PHP builds)"
10601144 needs : " turbo-compile"
@@ -2491,7 +2575,8 @@ jobs:
24912575 # guards the version constant the staging logic compares. The jobs
24922576 # that only test those bits are deliberately not gates: the
24932577 # "Run with Turbo Extension" jobs (turbo-differential,
2494- # turbo-differential-musl, turbo-run, turbo-docker-run) and
2578+ # turbo-differential-musl, turbo-run, turbo-docker-run), the shared-core
2579+ # gate (turbo-shared-core-gate, turbo-shared-core-gate-compare) and
24952580 # turbo-phpize, whose build nothing ships (PIE
24962581 # builds from the phpstan/turbo-ext subsplit). They produce nothing the
24972582 # commit consumes, waiting for them would delay every dev phar by their
@@ -2503,7 +2588,6 @@ jobs:
25032588 needs :
25042589 - compiler-tests
25052590 - turbo-version
2506- - turbo-shared-core-gate
25072591 - turbo-compile
25082592 - turbo-compile-musl-arm64
25092593 - turbo-compile-windows
0 commit comments