Repository navigation
land: batched landing (one proof per batch, prefix bisect, per-PR merges in order) - #145
Merged
Merged
Conversation
…ide it The parallel scheduler took a whole-tree git add -A snapshot when one step finished, while another was deleting and rewriting its outputs, and aborted on 'unable to stat'. Snapshots now exclude (git exclude pathspecs, same glob semantics) the declared outputs of every step still running; those paths were already left out of change detection, so the stray-write guard is unchanged.
…ct on failure, per-PR merges in order
…ly on its parent's position
…ish; non-test proof errors stop the driver; clean other trees' ignored outputs before a proof
Commands: pnpm regen
… reruns failing files alone; skip the master proof for a tree this run proved
regen: a snapshot never reads the outputs of a step still running beside it
Commands: pnpm regen
This was referenced Oct 5, 2026
Merged
thejackshelton
added a commit
that referenced
this pull request
Oct 5, 2026
land: keep installs when cleaning ignored outputs before a proof (hotfix for #145)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed (head 5d4276d):
pnpm landproves PRs in batches. It runs one fullpnpm testfor up toLAND_BATCHPRs (default 4, 1 to 8). Each PR still gets its own landing commit, its owngh pr merge --match-head-commit, its own record and its own comment.LAND_BATCH=1behaves as before.Design
Positions, not one combined commit. A landing commit that merges every PR would put every PR's commits into master with the first merge. GitHub would then mark the other PRs merged with no merge of their own and no
--match-head-commitpin. So each PR k gets a position, built the way the merge train built them:origin/master.When PR k merges, master's tree is exactly position k's tree. The tree check still runs after every merge.
Device evidence from each master merge's own tree (AGENTS.md). Each position runs
pnpm regen,pnpm typecheckandpnpm evidence:stamp --compare <previous position>:Every position also gets the regen-only check and the floors check against the previous position. Because of this, every master merge commit carries device evidence from its own tree. A batch with no evidence-code change runs no device lanes. A batch with one evidence-changing PR runs the devices once, at that PR's position.
One proof.
pnpm test(with the quiet rerun) runs once, on the top position. Positions below the top get no full test of their own, but each has its own regen, typecheck, devices, regen-only and floors checks. Each also passes thechecksCI (typecheck plus the platform-free suites) on its own sha before it merges.Self-check. Before any proof,
planPositionschecks that the chain is exactly what it claims: each head is one regen commit on a merge of [previous position, member tip], the chain starts on master, and every tip passestipProblem. A mismatch is fatal.Publish in order, never ahead. PR k's position is pushed to its branch only after PR k-1 has merged. The driver checks this before the push: the previous position must be in master. So a PR branch never carries another PR's unlanded commits, even when a later step fails. Each publish runs today's steps unchanged:
pr:review;mergeGate;gh pr merge --merge --match-head-commit;Bisect. When the top fails, the driver binary-searches the prefixes. The positions are already built, so each probe is just a test of an existing commit. The first failing position is the culprit, found in at most ceil(log2 n) more proofs:
Ejection. Each of these fails one PR with the step name, the label and the comment, as today:
pr:review --waitat the current head. When that head is UNREVIEWED, it also runs the Claude review gate (the precomputed review for the clean head). A review that is not clean ejects the PR (review-before,claude-review-before), and the batch fills from the queue.Every round lands or fails at least one PR, so the loop always ends.
Stacks. A PR whose base is the branch of a PR admitted earlier in the same batch is admitted. The parent's publish moves it to master (
retargetChildrenThenDelete). If that did not happen,mergeGaterefuses it. If the parent was ejected, the child's build refuses to run unless the parent's head is in the chain (retarget: land its parent first), so the parent's commits never land through the child.The driver also releases the heavy-lease priority while it waits in admission, as it already does while publishing.
Hooks for CI-OFFLOAD (#135, #144).
runBatches(inland-lib.ts) takes its steps as functions:admit,base,build,verify,proveandpublish.prove(position)is the only full-test call. A CI full-test mode (CI-FULLTEST: the full pnpm test on GitHub runners, sharded (full-test.yml) #144) replaces its body with one dispatched run on the top position's sha, so proving a batch is one CI run, and each bisect probe is one more.buildPositionis the block Landing driver: LAND_DEVICES=ci (device lanes on GitHub runners, hybrid) #135'sLAND_DEVICES=cireplaces. It runs at most once per stamp change rather than once per PR.Expected time: one build-and-prove (regen per position plus one full test), then about one CI run plus review per PR while publishing, instead of a full build and test per PR. Pipelining (building batch K+1 on batch K's top while K publishes) is the planned second PR.
Outside the spec:
AGENTS.mdstep 7 now describes batched landing.What passed
pnpm typecheckpassed.vitest run packages/parity/test/land.test.tspassed: 66 tests, 16 of them new.runBatches:bisectPrefixesfor every n ≤ 8 and every culprit;LAND_BATCHparsing.planPositionsaccepts the chain, and every regen commit is regen-only and vouchable. An intermediate position holds only its prefix. A reordered or duplicated chain is refused.runQueuetests stay, becauserunQueueis kept and still exported.pnpm test: this is tooling only, and the driver proves it.Review round 1 (precomputed review of a6ad40b: 2 Medium, 3 Low), fixed in 8428aee
Medium: a partial publish could leave master on an untested tree. Fixed.
master-red, writes the fatal to the status, and stops.Medium: bisect blamed position 1 when master itself was red. Fixed.
proveMaster).Low: non-test errors counted as a failing prefix. Fixed.
testis a verdict on a tree (isTestVerdict,proofVerdict).Low: ignored outputs of other trees. Fixed.
proveCommittests in place only the tree the last build left untouched.git clean -fdX, keepingKEEP_IGNORED(node_modules, vendor/wpt, native build caches and the zig and cargo outputs), and then installed.git cleanarguments are pinned on a scratch repository.Low: the #144 and #135 hooks. Agreed. #144's CI full test must push each proved position to a scratch ref keyed by position (as #135 does with
land-devices/pr-<n>), because positions are never on a PR branch before publish. When #135 is merged intobuildPosition, itsjudgeDevicesand its scratch commit must useprevand the position tree, not origin/master. #141's solo rerun goes intoproveCommit's quiet-rerun block.AGENTS.md step 7 now says the same.
What passed (8428aee):
pnpm typecheckpassed.vitest run packages/parity/test/land.test.tspassed: 70 tests. 4 tests are new this round:Catch-up with master (#141), at 5d4276d
origin/masteris merged in, and #141's solo rerun is now part ofproveCommit:SOLO_RERUN_MAXfiles failed.A failed solo rerun is still a
testverdict, so bisect and the master proofs treat it as a failing tree.Low 1 (round 2): the master proof is skipped when master's tree, ignoring
docs/goals/**, equals a commit whose full test passed in this run (provedTree, tested).What passed (5d4276d):
pnpm typecheckpassed.vitest run packages/parity/test/land.test.tspassed: 72 tests, including land: rerun each failing test file alone on a quiet machine #141's tests.🤖 Generated with Claude Code