diff --git a/.github/workflows/hosted-kache-canary.yml b/.github/workflows/hosted-kache-canary.yml index ba0669a..bcb2f72 100644 --- a/.github/workflows/hosted-kache-canary.yml +++ b/.github/workflows/hosted-kache-canary.yml @@ -75,9 +75,15 @@ jobs: pr-comment: "false" - name: Seed identical release build run: cargo build --release --locked --manifest-path "$CANARY_MANIFEST" + - name: Drain seed transfers and upload the canary workspace + run: | + kache daemon stop + kache sync --push --manifest-path "$CANARY_MANIFEST" 2>&1 \ + | tee "$RUNNER_TEMP/kache-seed-sync.log" + grep -Eq 'Uploaded:[[:space:]]+1/1' "$RUNNER_TEMP/kache-seed-sync.log" - name: Record seed evidence run: | - kache report --format json --root "$GITHUB_WORKSPACE/$CANARY_ROOT" \ + kache report --format json \ | jq '.summary | {local_hits, prefetch_hits, remote_hits, misses, errors, fallbacks, store_failures}' \ >> "$GITHUB_STEP_SUMMARY" diff --git a/tests/test_validate.py b/tests/test_validate.py index 24bf159..33ce50c 100644 --- a/tests/test_validate.py +++ b/tests/test_validate.py @@ -187,6 +187,17 @@ def test_canary_keeps_shared_credentials_off_pull_requests(self) -> None: self.assertIn("kache-0.28.1", workflow["env"]["CANARY_CACHE_PREFIX"]) self.assertNotIn("secrets.", str(workflow["jobs"]["pr-build"])) + def test_canary_upload_is_scoped_to_its_build_root(self) -> None: + workflow = yaml.load( + (ROOT / ".github/workflows/hosted-kache-canary.yml").read_text(), + Loader=yaml.BaseLoader, + ) + steps = workflow["jobs"]["seed"]["steps"] + upload = next(step for step in steps if step.get("name") == "Drain seed transfers and upload the canary workspace") + self.assertIn('kache sync --push --manifest-path "$CANARY_MANIFEST"', upload["run"]) + self.assertLess(upload["run"].index("kache daemon stop"), upload["run"].index("kache sync")) + self.assertIn("Uploaded:", upload["run"]) + def test_platform_release_cache_stays_credentialless(self) -> None: workflow = yaml.load( (ROOT / ".github/workflows/hosted-rust-platform-release.yml").read_text(),