Skip to content

ci: Include root pubspec.yaml in pub cache key#189826

Merged
auto-submit[bot] merged 3 commits into
flutter:masterfrom
cbracken:fix-pub-cache-hash
Jul 22, 2026
Merged

ci: Include root pubspec.yaml in pub cache key#189826
auto-submit[bot] merged 3 commits into
flutter:masterfrom
cbracken:fix-pub-cache-hash

Conversation

@cbracken

@cbracken cbracken commented Jul 22, 2026

Copy link
Copy Markdown
Member

The pub package cache step in composite-flutter-setup keys its cache on a hash of the pubspec.yaml files found under dev/, examples/, and packages/, but omits the root workspace pubspec.yaml. The root pubspec pins the versions of all transitive dependencies, so a pub roll that only touches the root, leaves the hash, and therefore the hash key, unchanged. This is exactly what happens on pub package rolls like #189760.

When that happens the cache still hits and restores a stale pubspec.lock over the freshly checked-out one. At that point, the following flutter update-packages then fails when run with --enforce-lockfile, since the lock file we just restored from cache no longer matches the pinned versions in the checked-out root pubspec.yaml, which breaks the Tree Analyze step tree-wide until the cache is manually invalidated.

We now include the root pubspec.yaml in the hash so that a packages only roll changes the cache key, forcing a fresh package resolve rather than restoring a stale lock.

Fixes: #189825

Pre-launch Checklist

If you need help, consider asking for advice on the #hackers-new channel on Discord.

If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.

Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the gemini-code-assist bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.

The `pub package cache` step in composite-flutter-setup keys its cache
on a hash of the pubspec.yaml files found under dev/, examples/, and
packages/, but omits the root workspace pubspec.yaml. The root pubspec
pins the versions of all transitive dependencies, so a pub roll that
only touches the root, leaves the hash, and therefore the hash key,
unchanged. This is exactly what happens on pub package rolls like
flutter#189760.

When that happens the cache still hits and restores a stale pubspec.lock
over the freshly checked-out one. At that point, the following `flutter
update-packages` then fails when run with `--enforce-lockfile`, since
the lock file we just restored from cache no longer matches the pinned
versions in the checked-out root pubspec.yaml, which breaks the Tree
Analyze step tree-wide until the cache is manually invalidated.

We now include the root pubspec.yaml in the hash so that a packages only
roll changes the cache key, forcing a fresh package resolve rather than
restoring a stale lock.

Fixes: flutter#189825
@cbracken
cbracken requested review from ievdokdm and jtmcdole July 22, 2026 04:36
@flutter-dashboard flutter-dashboard Bot added the CICD Run CI/CD label Jul 22, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the GitHub Action composite-flutter-setup to include the root pubspec.yaml file when generating the stable hash for dependency caching. Feedback was provided to correct a typo in the updated comment, which incorrectly refers to pubspec.yaml as package.yaml.

Comment thread .github/actions/composite-flutter-setup/action.yml Outdated
# Generate a stable hash for github caching from the pubspec.yaml
# files that drive dependency resolution. Includes the root
# pubspec.yaml and all pubspec.yaml files from dev/examples/packages.
find pubspec.yaml dev examples packages -name "pubspec.yaml" -print0 | sort -z | xargs -0 cat | sha256sum >> "$RUNNER_TEMP/pub_deps_sha"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hash only tracked pubspec.yaml files in the tree and their contents... its faster because the objects are already in the git db:

git ls-tree HEAD  -- $(git ls-files '*/pubspec.yaml') | git hash-object --stdin

jtmcdole
jtmcdole previously approved these changes Jul 22, 2026
@jtmcdole jtmcdole added autosubmit Merge PR when tree becomes green via auto submit App and removed autosubmit Merge PR when tree becomes green via auto submit App labels Jul 22, 2026
Updated the method for generating a stable hash for GitHub caching from pubspec.yaml files to use git commands for improved accuracy.

@jtmcdole jtmcdole left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

my approval isn't enough since I made the last commit.

@ievdokdm ievdokdm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jmagman jmagman added the autosubmit Merge PR when tree becomes green via auto submit App label Jul 22, 2026
@auto-submit
auto-submit Bot added this pull request to the merge queue Jul 22, 2026
Merged via the queue into flutter:master with commit 5f8d728 Jul 22, 2026
20 checks passed
@flutter-dashboard flutter-dashboard Bot removed the autosubmit Merge PR when tree becomes green via auto submit App label Jul 22, 2026
auto-submit Bot pushed a commit to flutter/packages that referenced this pull request Jul 22, 2026
flutter/flutter@1ac2e82...2a2a79d

2026-07-22 [email protected] Clear cached directional focus history on a non-directional focus request  (flutter/flutter#187957)
2026-07-22 [email protected] ci: Include root pubspec.yaml in pub cache key (flutter/flutter#189826)
2026-07-22 [email protected] Remove codecov badge from README (flutter/flutter#189728)
2026-07-22 [email protected] Clean android engine/embedding tests (flutter/flutter#189276)
2026-07-22 [email protected] Add barrierBuilder support to showDialog and showGeneralDialog (flutter/flutter#187992)
2026-07-22 [email protected] Fix Mockito dynamic agent loading warnings in Robolectric tests (flutter/flutter#189804)
2026-07-22 [email protected] [iOS] Remove dead RasterThreadMerger plumbing from platform views (flutter/flutter#189753)
2026-07-22 [email protected] Add OverlayPortal.overlayChildLayoutBuilder sample (flutter/flutter#188930)
2026-07-22 [email protected] Automate recurring tasks via workflows - localizations (flutter/flutter#189750)
2026-07-21 [email protected] [iOS] Remove dead parameters and no-op overrides (flutter/flutter#189754)
2026-07-21 [email protected] [iOS] Inject DisplayLinkManager into FlutterViewController (flutter/flutter#189764)
2026-07-21 [email protected] Support custom BoxBorder animation in BoxDecoration (flutter/flutter#186348)
2026-07-21 [email protected] Rename CpuArch.x86_64 to CpuArch.x64 (flutter/flutter#189478)
2026-07-21 [email protected] Roll Skia from 569534e9fa59 to 5e183e5aeac5 (3 revisions) (flutter/flutter#189795)
2026-07-21 [email protected] Roll Dart SDK from 3b2f5ad7718d to 1e65011ee004 (4 revisions) (flutter/flutter#189791)
2026-07-21 [email protected] Run delete-bot-branches.yaml on `pull_request_target` instead of `pull_request` so that we can access secrets. (flutter/flutter#189793)
2026-07-21 [email protected] Batch release directory correction (flutter/flutter#189738)
2026-07-21 [email protected] [flutter_test][Test cross imports] Move TestWidgetsApp to flutter_test (flutter/flutter#189435)
2026-07-21 [email protected] Fix null-deref/double-dispose in StretchingOverscrollIndicator (#189589) (flutter/flutter#189667)
2026-07-21 [email protected] Roll Packages from 611899b to 8260a1e (10 revisions) (flutter/flutter#189782)
2026-07-21 [email protected] [iOS] Inject DisplayLinkManager into FlutterMetalLayer (flutter/flutter#189752)
2026-07-21 [email protected] Derive the SkImage size used by ImageEncodingImpeller::ConvertDlImageToSkImage from the size of the underlying texture, not the size of the DlImage (flutter/flutter#189739)

If this roll has caused a breakage, revert this CL and stop the roller
using the controls here:
https://autoroll.skia.org/r/flutter-packages
Please CC [email protected],[email protected] on the revert to ensure that a human
is aware of the problem.

To file a bug in Packages: https://github.com/flutter/flutter/issues/new/choose

To report a problem with the AutoRoller itself, please file a bug:
https://issues.skia.org/issues/new?component=1389291&template=1850622

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+doc/main/autoroll/README.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CICD Run CI/CD

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pub package cache key omits root pubspec.yaml

4 participants