ci: shard Python tests and reuse combined coverage for Sonar - #3989
Merged
Merged
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pytestcheck as a fail-closed aggregator: all upstream jobs must succeed, both coverage files must exist, and combined coverage must meet the unchanged 19.6% floor.Scheduling tradeoff
The workflow now uses the union of the previous Python/Sonar path filters. App-only and Sonar-configuration changes also run the Python lane, including forks without a Sonar token. This avoids a second routing framework and ensures coverage belongs to the exact analyzed run. Local full pytest remains unsharded by default. Timing-history-based balancing is not introduced in this iteration.
Evidence
ba3da4808: Python run passed 6040 tests / 25 skips; pytest 804.83s, Linux job 14m57s. Sonar run independently repeated them in 904.90s.cqr_4f8d5981c6fd511a8c93, fingerprint4f8d5981c6fd511a8c9322c579548ac4c2b2808c03ec5ebe206e13da246f8628, 9 files, valid; safe-fix allowed/not used, zero blockers/warnings; one resolved Sonar mode-conflict advisory and one remaining scan-scope advisory below.Hosted outcome
Run 34016648962 tested head
58646c326as mergeff3f69b7589ed16a6e7d14c2b4d0d9107a399080against base8c08efd3a. Both shards and the aggregate checked out that same merge commit.The second runner started approximately one minute later than the first; that delay is included. This is one hosted sample, not strict same-source/hardware A/B: main advanced with 31 additional tests after the local collection proof. No changed PR path overlaps the new base changes. The full Python workflow, Windows tests, other build checks and final premerge passed. Final premerge ran 4 direct checks, 9 catalog canaries, 8 risk-profile smokes and one public-boundary check, with zero failures or manual holds. No merge requested or performed for this CI change.
Sonar platform repair and remaining scope limitation
Both the baseline and first candidate scanner attempt reported an existing Automatic Analysis/CI conflict. With explicit owner authorization, the project's Automatic Analysis was switched Off; no organization settings or quality gate thresholds changed. Only the Sonar job was rerun, reusing artifact
9984231555from the completed pytest aggregator. It took 3m26s, explicitly importedcoverage.xml, and loggedANALYSIS SUCCESSFULandEXECUTION SUCCESS. Server background taskAaB1fPSRbMgFd3KsTHjuis Success; the separate PR SonarCloud Code Analysis check and quality gate now pass. The earlier Python timing is unaffected by this Sonar-only retry. Do not treat the first rejected 33-second scan as successful analysis latency.The existing
sonar-project.propertiesanalyzesloopx,apps,scriptswithtestsas test sources; it does not include.github. Automatic analysis previously reported two dependency-version-lock findings on the new workflow install steps (lines 113 and 154). Those dependency locks have not been fixed, waived or marked false positive; the warnings disappear from the CI scan because of its pre-existing scope, not because this PR fixes dependency pinning. Expanding workflow scanning and introducing a shared Python test lockfile remain explicit follow-up work. A later, separate main-branch background task failure is not the successful PR analysis task.No runtime code, reduced coverage floor, private state, credentials, raw logs or generated timing data are included. The bounded future-facing pass removes duplicate test and coverage ownership rather than adding production caching.