Repository navigation
feat(workflows): step 2, add reusable stale and Fabrica codegen checks - #39
seantronsen wants to merge 5 commits into
Conversation
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| with: | ||
| repository: openchami/fabrica | ||
| ref: ${{ steps.fabrica-ref.outputs.ref }} |
There was a problem hiding this comment.
The Go ref is passed directly to the Git ref here, but a valid Go pseudo-version such as:
v0.4.9-0.20260701000000-123456789abc
identifies a commit and ordinarily has no corresponding Git tag.
Instead, it's probably better to try the tag first and fallback to a commit (text after second -), erring if the ref is completely invalid:
- name: Validate and select Fabrica ref
working-directory: fabrica
shell: bash
env:
FABRICA_REF: ${{ inputs.fabrica-ref }}
run: |
ref="$FABRICA_REF"
# An explicit input takes precedence over the caller's go.mod.
if [[ -z "$ref" ]]; then
if ! ref=$(go mod edit -json "$GITHUB_WORKSPACE/go.mod" | jq -er '
.Require[]?
| select(.Path == "github.com/openchami/fabrica")
| .Version
| select(type == "string" and length > 0)
'); then
echo "::error::Set fabrica-ref or require github.com/openchami/fabrica in the caller's go.mod"
exit 1
fi
fi
# Prefer an exact tag, then a branch.
if git show-ref --verify --quiet "refs/tags/$ref"; then
target="refs/tags/$ref"
elif git show-ref --verify --quiet "refs/remotes/origin/$ref"; then
target="refs/remotes/origin/$ref"
else
commit="$ref"
# Resolve release-based and prerelease-based Go pseudo-versions.
if [[ "$ref" =~ [.-][0-9]{14}-([0-9a-f]{12})$ ]]; then
commit="${BASH_REMATCH[1]}"
fi
if [[ ! "$commit" =~ ^[0-9a-fA-F]{7,40}$ ]] ||
! target=$(git rev-parse --verify --end-of-options "${commit}^{commit}"); then
echo "::error::Fabrica ref not found: $ref"
exit 1
fi
fi
git checkout --detach "$target"There was a problem hiding this comment.
I'm not sure this is better. .Origin.Hash is not guaranteed (Origin marked with omitempty) in the Go proxy protocol so at the very least we should check if it's empty, e.g.:
jq -er '.Origin.Hash | select(type == "string" and test("^[0-9a-f]{40}$"))'Right now, jq succeeds and sets the version to null if empty.
Also, it doesn't look like we are accepting user input for the ref in that commit anymore.
However, I will say I do prefer the tag-first approach of my snippet above (modified to add go.mod checking if user input is empty) since the tag will be used in the comment headers marking the fabrica version for the comparison.
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
…ration Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
23a6353 to
e9cb5c9
Compare
Description
Ports two workflows duplicated across org repos into reusable workflows:
stale.yml: org-defaultactions/stalepolicy (35d stale / 7d close, same labels/exemptions/messages as the existing copies), all settings overridable via inputs. Callers keep the schedule.lint-codegen-fabrica.yml: runs the caller'smake generate-checkagainst Fabrica built from source (version fromgo.mod, orfabrica-reftag/branch/SHA). A source build is required: Fabrica stamps its version into generated code and ago runbuild reportsdev, which is why thego run-based copies (fru-tracker, tpm-identity-service) fail on every run.Both follow the v4.0 conventions (kebab-case inputs, SHA-pinned actions,
ubuntu-slim,name:= filename). README updated with usage and all optional inputs. Validated locally with actionlint and zizmor (no findings).Depends on #38 (
seantronsen/chore/cleanup). This branch is stacked on it; merge #38 first so this diff stays limited to the two new workflows.Fixes #36
Partially addresses #37 (codegen check;
build-debto be tracked separately)Checklist
make test(or equivalent) locally and all tests passgit commit -s) with my real name and email<filename>.licensesidecarLICENSES/directoryType of Change