Keep sync PRs building across bot pushes
Three things kept the upstream sync PR (#589) from ever finishing a build: Scoped dispatches wiped the shared PR. A workflow_dispatch with `packages` regenerates only those packages from master, and pushing that to auto/sync-upstream replaced 38 pending updates with one. Scoped runs now push to their own auto/sync-{upstream,rebuilds}-<packages> branch and PR; scheduled runs keep the shared branch. build-approved stopped working after the first bot push. A GITHUB_TOKEN push creates pull_request runs held for approval but no pull_request_target run, so approve-pr.yml never saw it: its last run on the branch was the label itself (2026-09-25T19:26), and each of the next four syncs sat at action_required. The sync workflows now release the held runs for the commit they just pushed, from a separate job holding actions: write, and only for their own bot-authored, same-repo PR while build-approved is on it. Each approved push cancelled the in-flight build. Approving the 21:43 sync's build cancelled the label-triggered one still queued on strata and schist-bin. On auto/sync-* branches a new build now waits for the running one instead, then reuses its artifacts. The approval script no longer waits for a lone approved build to start before releasing tests, which a queued build would have turned into a timeout.
This commit is contained in:
1 parent
6df9953d8f
commit
4aca3bdbc7
8 files changed
+363
-9
No files matched your search
@@ -0,0 +1,33 @@
|
||||
const approvePrWorkflows = require('./approve-pr-workflows.cjs');
|
||||
|
||||
const BOT = 'github-actions[bot]';
|
||||
|
||||
// A sync workflow pushes its branch with GITHUB_TOKEN. GitHub holds the
|
||||
// resulting pull_request runs for approval and, unlike a person's push,
|
||||
// creates no pull_request_target run, so approve-pr.yml never sees it. The
|
||||
// sync workflow therefore releases the runs for the commit it just pushed,
|
||||
// under the same rule approve-pr.yml applies: only while a maintainer's
|
||||
// build-approved label is on the PR. It acts only on its own bot-authored,
|
||||
// same-repository PR for the branch and commit it pushed.
|
||||
module.exports = async function approveSyncPush({ github, context, core,
|
||||
number, branch, headSha, since, approve = approvePrWorkflows, ...options }) {
|
||||
if (!Number.isInteger(number) || !branch || !headSha || !since) {
|
||||
throw new Error('Missing sync PR number, branch, head SHA or push time.');
|
||||
}
|
||||
const { data: pr } = await github.rest.pulls.get({ ...context.repo, pull_number: number });
|
||||
const repository = `${context.repo.owner}/${context.repo.repo}`;
|
||||
if (pr.user?.login !== BOT || pr.head.repo?.full_name !== repository ||
|
||||
pr.base.repo?.full_name !== repository || pr.head.ref !== branch) {
|
||||
throw new Error(`PR #${number} is not ${BOT}'s ${branch} PR in ${repository}; refusing to approve.`);
|
||||
}
|
||||
if (pr.state !== 'open' || pr.head.sha !== headSha) {
|
||||
core.info(`PR #${number} is closed or has moved past ${headSha}; nothing to approve.`);
|
||||
return;
|
||||
}
|
||||
if (!pr.labels.some(label => label.name === 'build-approved')) {
|
||||
core.info(`PR #${number} has no build-approved label; its runs wait for a maintainer.`);
|
||||
return;
|
||||
}
|
||||
await approve({ github, context, core, vouchStatus: 'bot', pullRequest: pr,
|
||||
action: 'synchronize', since, ...options });
|
||||
};
|
||||
Reference in new issue
Block a user