fix(ci): bound pkgcache _metadata growth to stop macmini disk-fill (#110)
Some checks failed
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
ci/crow/cron/process-updates/9 Pipeline was canceled
ci/crow/cron/process-updates/4 Pipeline was successful
ci/crow/manual/build-all-versions-install-deps/2 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was canceled
ci/crow/cron/process-updates/8 Pipeline failed
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was canceled
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline failed
ci/crow/manual/build-all-versions-install-deps/1 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline failed
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/manual/build-all-versions/2 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/manual/build-all-versions/3 Pipeline failed
ci/crow/manual/build-all-versions/1 Pipeline failed
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/manual/build-all-versions/6 Pipeline failed
ci/crow/manual/build-all-versions/5 Pipeline was canceled
ci/crow/manual/build-all-versions/8 Pipeline was canceled
ci/crow/cron/process-updates/12 Pipeline was canceled
ci/crow/manual/build-all-versions/7 Pipeline was canceled
ci/crow/cron/process-updates/6 Pipeline failed
ci/crow/cron/process-updates/2 Pipeline failed
ci/crow/manual/build-all-versions/4 Pipeline was canceled

## Problem

The arm64 `build-all` pipeline fills the macmini (gaia) host disk despite an 8h prune.
Root cause is not images or job volumes: it is the persistent dep-cache volume, specifically `pkgcache/R/pkgcache/_metadata`, which grew to ~165 GB.
`{pkgcache}` mints a new content hash for the "patched" binaries repo on every PACKAGES change, so each per-package build writes a fresh ~70 MB `pkgs-<hash>.rds` (+ `patched-<hash>/`) that is never evicted (2407 snapshots observed).
When the disk hits 100% OrbStack stops and the on-host prune can no longer connect to the daemon, so it never self-heals.

## Change (Workstream A of the disk-fill fix)

- Add `trim_pkgcache_metadata()` to `local/r-minor-helpers.R`: keeps the newest `keep` (default 20) `patched-*`/`pkgs-*.rds` entries under `_metadata`, deleting only entries older than `min_age_secs` (default 600s) so it never races the up-to-4 concurrent split-jobs sharing the volume.
Preserves `pkg/` downloads and the stable CRAN/BioC/INLA repo dirs.
No-op when `R_PKG_CACHE_DIR` is empty (amd64) or `_metadata` is absent (first run).
- Call it every 25 packages inside the build loop in `local/build-all.R`.
- Add a defensive start-of-run cleanup of `_metadata/patched-*` + `pkgs-*.rds` to the two workflows that mount the persistent volume (`build-all-versions.yaml`, `build-all-versions-install-deps.yaml`).

Only these paths are touched; `process-updates.yaml`/`weekly-rebuild-missing.yaml` (no persistent volume) are unchanged.

Follow-ups (separate workstreams): on-host self-healing prune watcher + OrbStack disk cap (ansible), and Prometheus/Grafana alerting (k8s-talos).
Upstream: bincraft patched-repo hash churn is the true source fix.

New unit tests (6) for the helper; full suite 24/24 green.

Reviewed-on: #110
This commit is contained in:
Patrick Schratz 2026-07-13 09:31:29 +00:00 committed by Patrick Schratz
commit a4b274f281
5 changed files with 130 additions and 4 deletions

View file

@ -4,7 +4,7 @@
# they are merged with build-all-versions' identical declarations.
variables:
target_arch:
description: "Architecture to build."
description: 'Architecture to build.'
options:
- amd64
- arm64
@ -27,7 +27,7 @@ variables:
- "noble"
default: "3.24"
R_VERSION:
description: "Primary R version under /opt/R."
description: 'Primary R version under /opt/R.'
options:
- 4.5.3
- 4.4.3
@ -74,6 +74,10 @@ steps:
commands:
# one-time full wipe to fix corrupted .so files from previous failed builds
# - rm -rf /mnt/cache/R-pkgs
# Clear churny pkgcache metadata left by a prior crashed run (the "patched"
# repo mints a new hash per PACKAGES change -> unbounded pkgs-*.rds/patched-*).
# Keep pkg/ downloads and the stable CRAN/BioC/INLA repo dirs.
- rm -rf /mnt/cache/pkgcache/R/pkgcache/_metadata/patched-* /mnt/cache/pkgcache/R/pkgcache/_metadata/pkgs-*.rds || true
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
# Pin the same bincraft version the build steps use, so the precomputed

View file

@ -5,7 +5,7 @@
# Skip list lives in local/excluded-packages.json (read by local/build-all.R).
variables:
target_arch:
description: "Architecture to build."
description: 'Architecture to build.'
options:
- amd64
- arm64
@ -31,7 +31,7 @@ variables:
- "resolute"
default: "3.24"
R_VERSION:
description: "Primary R version under /opt/R."
description: 'Primary R version under /opt/R.'
options:
- 4.5.3
- 4.4.3
@ -116,6 +116,11 @@ steps:
- ${ARCH}-binaries-r-dep-cache-${OS}-${OS_VERSION//./}:/mnt/cache
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
# Clear churny pkgcache metadata left by a prior crashed run (the "patched"
# repo mints a new hash per PACKAGES change -> unbounded pkgs-*.rds/patched-*).
# Keep pkg/ downloads and the stable CRAN/BioC/INLA repo dirs. Within-run
# growth is bounded separately by trim_pkgcache_metadata() in build-all.R.
- rm -rf /mnt/cache/pkgcache/R/pkgcache/_metadata/patched-* /mnt/cache/pkgcache/R/pkgcache/_metadata/pkgs-*.rds || true
- mkdir -p /mnt/cache/pkgcache /mnt/cache/R-pkgs /mnt/cache/ccache /mnt/cache/packages
# The primary pass must not rely on build-all-versions-install-deps having
# run on *this* agent: depends_on only orders the steps, but the cache

View file

@ -122,6 +122,10 @@ s3_cache <- readRDS("/mnt/cache/packages/s3_cache.rds")
sprintf("S3 cache: %s files", length(s3_cache))
n <- nrow(chunk)
# Every `trim_every` packages, bound the pkgcache _metadata dir so a full-platform
# run does not accumulate thousands of ~70 MB snapshots and fill the host disk.
# No-op on amd64 (R_PKG_CACHE_DIR is empty / cache not persisted).
trim_every <- 25L
mapply(
function(pkg, ver, sens, i) {
cat(sprintf("[%d/%d] %s_%s (r_minor_sensitive=%s)\n", i, n, pkg, ver, sens))
@ -147,6 +151,12 @@ mapply(
upload = TRUE,
store_build_metadata = TRUE
)
if (i %% trim_every == 0L) {
removed <- trim_pkgcache_metadata()
if (removed > 0L) {
cat(sprintf(" [pkgcache trim] removed %d stale _metadata entries\n", removed))
}
}
},
chunk$Package,
chunk$Version,

View file

@ -31,3 +31,42 @@ parse_build_args <- function(args) {
ncpus = as.integer(pos[3L])
)
}
# Bound the {pkgcache} metadata dir, which otherwise grows without limit: the
# "patched" repo mints a new content hash on every PACKAGES change, so each build
# writes a fresh ~70 MB _metadata/pkgs-<hash>.rds (+ patched-<hash>/) that is
# never reused. Keep the `keep` newest entries by mtime; only remove entries
# older than `min_age_secs`, so a concurrent split-job's in-flight files are
# never deleted (each build uses a unique hash, so aged entries are
# unreferenced). Stable repo dirs (CRAN-*, BioC*, INLA-*) and pkg/ downloads are
# not matched and thus preserved. Returns the number of entries removed.
trim_pkgcache_metadata <- function(cache_dir = Sys.getenv("R_PKG_CACHE_DIR"),
keep = 20L,
min_age_secs = 600) {
meta <- file.path(cache_dir, "R", "pkgcache", "_metadata")
if (!nzchar(cache_dir) || !dir.exists(meta)) {
return(0L)
}
entries <- c(
Sys.glob(file.path(meta, "patched-*")),
Sys.glob(file.path(meta, "pkgs-*.rds"))
)
if (length(entries) == 0L) {
return(0L)
}
info <- file.info(entries)
order_new_first <- order(info$mtime, decreasing = TRUE)
ranked <- entries[order_new_first]
ranked_mtime <- info$mtime[order_new_first]
if (length(ranked) <= keep) {
return(0L)
}
candidates <- ranked[(keep + 1L):length(ranked)]
candidate_age <- as.numeric(Sys.time()) - as.numeric(ranked_mtime[(keep + 1L):length(ranked)])
removable <- candidates[candidate_age >= min_age_secs]
if (length(removable) == 0L) {
return(0L)
}
unlink(removable, recursive = TRUE, force = TRUE)
length(removable)
}

View file

@ -0,0 +1,68 @@
source(file.path("..", "r-minor-helpers.R"))
# Build a fake _metadata dir under a temp R_PKG_CACHE_DIR. Each entry's mtime is
# set to `age_secs` in the past so we can exercise the age gate deterministically.
make_meta <- function(patched = 0L, pkgs = 0L, keep_repos = TRUE, age_secs = 3600) {
root <- tempfile("pkgcache-")
meta <- file.path(root, "R", "pkgcache", "_metadata")
dir.create(meta, recursive = TRUE)
old <- Sys.time() - age_secs
mk_dir <- function(p) { dir.create(p); Sys.setFileTime(p, old); p }
mk_file <- function(p) { writeLines("x", p); Sys.setFileTime(p, old); p }
for (i in seq_len(patched)) mk_dir(file.path(meta, sprintf("patched-%03d", i)))
for (i in seq_len(pkgs)) mk_file(file.path(meta, sprintf("pkgs-%03d.rds", i)))
if (keep_repos) {
mk_dir(file.path(meta, "CRAN-075c426938"))
mk_dir(file.path(meta, "BioCsoft-1ac964ed6c"))
mk_file(file.path(meta, "bioc-sysreqs.dcf.gz"))
mk_dir(file.path(root, "R", "pkgcache", "pkg")) # downloads, must survive
}
root
}
n_churn <- function(root) {
meta <- file.path(root, "R", "pkgcache", "_metadata")
length(Sys.glob(file.path(meta, "patched-*"))) +
length(Sys.glob(file.path(meta, "pkgs-*.rds")))
}
test_that("empty cache_dir is a no-op", {
expect_identical(trim_pkgcache_metadata("", keep = 5L, min_age_secs = 0), 0L)
})
test_that("missing _metadata dir is a no-op", {
expect_identical(
trim_pkgcache_metadata(tempfile("absent-"), keep = 5L, min_age_secs = 0),
0L
)
})
test_that("fewer than keep entries removes nothing", {
root <- make_meta(patched = 2L, pkgs = 2L)
expect_identical(trim_pkgcache_metadata(root, keep = 20L, min_age_secs = 0), 0L)
expect_identical(n_churn(root), 4L)
})
test_that("trims down to keep newest, leaving churn == keep", {
root <- make_meta(patched = 30L, pkgs = 30L) # 60 churn entries, all old
removed <- trim_pkgcache_metadata(root, keep = 20L, min_age_secs = 0)
expect_identical(removed, 40L)
expect_identical(n_churn(root), 20L)
})
test_that("entries younger than min_age_secs are protected", {
root <- make_meta(patched = 30L, pkgs = 0L, keep_repos = FALSE, age_secs = 60)
# keep=5 would drop 25, but all are 60s old < 600s gate -> nothing removed
expect_identical(trim_pkgcache_metadata(root, keep = 5L, min_age_secs = 600), 0L)
expect_identical(n_churn(root), 30L)
})
test_that("stable repo dirs and pkg downloads are never touched", {
root <- make_meta(patched = 30L, pkgs = 30L)
trim_pkgcache_metadata(root, keep = 0L, min_age_secs = 0)
meta <- file.path(root, "R", "pkgcache", "_metadata")
expect_true(dir.exists(file.path(meta, "CRAN-075c426938")))
expect_true(dir.exists(file.path(meta, "BioCsoft-1ac964ed6c")))
expect_true(file.exists(file.path(meta, "bioc-sysreqs.dcf.gz")))
expect_true(dir.exists(file.path(root, "R", "pkgcache", "pkg")))
})