Skip to content

Validation: consolidated analysis optimizations (#1484) - #37

Closed
joaodinissf wants to merge 4 commits into
codex/validation-20260926-1483from
codex/validation-20260926-1484
Closed

joaodinissf wants to merge 4 commits into
codex/validation-20260926-1483from
codex/validation-20260926-1484

Conversation

@joaodinissf

@joaodinissf joaodinissf commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Consolidated optimization validation

Validates upstream dsldevkit#1484's combined optimization change against the validated dsldevkit#1483 candidate. This replaces the intermediate validation PRs #38 and #39.

  • Base: 230afc4d11902623937c0752a8f2f91367056688 (PR Validation: SARIF gates and merge (#1483) #36).
  • Head: 6fe886964305f0395bda66be00ee6149d4fb0c26.
  • Four existing signed optimization commits; the final source tree is identical to the previously tested final candidate.
  • Purpose: confirm CI for the consolidated two-PR merge context. No release or merge is intended.

Result

All five jobs passed. The test aggregator reported 366 tests, zero failures/errors, and two skipped. This validation is complete; the exact head is now published in upstream dsldevkit#1484.

joaodinissf and others added 4 commits September 26, 2026 13:28
SpotBugs' per-module analysis is the spotbugs job's long pole. A PR only needs
its changed modules scanned, so a pre-step injects <spotbugs.skip>true> into
every unchanged reactor module's pom — the plugin then skips the goal, and the
per-module JVM fork, for them. The full-reactor compile is kept (a changed
module keeps its complete aux-classpath); a build/config change falls back to a
full scan. pull_request only — master/snapshot run a full scan.

-Dspotbugs.onlyAnalyze was the cleaner-looking alternative but screens too late
(after the per-module fork), ~17% vs ~88% measured; the script header documents
the migration if an upstream SpotBugs early-exit ever lands.

- .github/scripts/compute-spotbugs-skip.sh: diff -> changed modules -> inject
  skip into the unchanged ones (idempotent; build/config change -> full scan).
- verify.yml spotbugs job: fetch-depth 0 + a scope step before compile;
  -Djgit.dirtyWorkingTree=ignore because the scope step dirties poms on purpose
  and this job releases nothing (releases/maven-verify keep =error); SARIF upload
  guarded so an empty scan set (no module scanned) doesn't fail the upload.

Validate and merge only expected SpotBugs reports. When the scope contains
no analysable modules, both merging and gating succeed without reports.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Export SPOTBUGS_SCOPE_ARGS with the changed modules and -am so the lane
compiles only those modules and their upstream dependencies. Unchanged
dependencies retain spotbugs.skip and provide the analysis classpath without
being analysed themselves. Include ddk-target explicitly because the target
definition is not a MANIFEST dependency that -am can discover.

Shared build/config changes retain a full reactor and scan. Export the full
expected-report list and an explicit scope state on that path. With no
analysable changed modules, skip Maven and accept no reports in the merge
and gate. Otherwise preserve shared validation for every expected report,
including failed analysis and invalid input, before counting findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CPD tokenizes sources under src/ and needs neither bytecode nor a
resolved target platform, so the second lint invocation drops its
compile goals. cpd.xml outputs are identical with and without the
compile pass, verified at the current token threshold and at the
PMD default of 100 (timestamp attributes aside).

Measured locally (warm tree, JDK 21): 6.8s vs 44.3s at the current
threshold; 4.5s vs 28.5s at threshold 100. In CI the invocation was
53s, ~40s of it redundant recompilation and JVM startup.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Generalize compute-spotbugs-skip.sh to compute-analysis-skip.sh with a mode
argument. The lint mode injects pmd.skip, cpd.skip and checkstyle.skip into
unchanged modules and exports the expected reports and -pl/-am scope.
SpotBugs keeps its existing scoping behavior through the same script.

Compile the changed modules and their dependencies before PMD/Checkstyle
so type resolution has the complete classpath. Run CPD separately without
compilation. Shared build/config changes trigger a full scan in both lanes.

Skip the report goals, merging and gating when the scope contains no
analysable modules. Otherwise retain the common validation of every expected
SARIF report, URI bases and rule descriptors. Count CPD duplications from
the expected reports, including a single-module scope.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joaodinissf
joaodinissf force-pushed the codex/validation-20260926-1483 branch from 949b75a to 230afc4 Compare September 26, 2026 11:31
@joaodinissf
joaodinissf force-pushed the codex/validation-20260926-1484 branch from f82fbf8 to 8d721b6 Compare September 26, 2026 11:31
@joaodinissf joaodinissf changed the title Validation: SpotBugs module scoping (#1484) Validation: consolidated analysis optimizations (#1484) Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant