Skip to content

feat(workflows): step 2, add reusable stale and Fabrica codegen checks - #39

Open
seantronsen wants to merge 5 commits into
seantronsen/release-400from
seantronsen/feat/workflow-ports
Open

seantronsen wants to merge 5 commits into
seantronsen/release-400from
seantronsen/feat/workflow-ports

Conversation

@seantronsen

Copy link
Copy Markdown
Contributor

Description

Ports two workflows duplicated across org repos into reusable workflows:

  • stale.yml: org-default actions/stale policy (35d stale / 7d close, same labels/exemptions/messages as the existing copies), all settings overridable via inputs. Callers keep the schedule.
  • lint-codegen-fabrica.yml: runs the caller's make generate-check against Fabrica built from source (version from go.mod, or fabrica-ref tag/branch/SHA). A source build is required: Fabrica stamps its version into generated code and a go run build reports dev, which is why the go run-based copies (fru-tracker, tpm-identity-service) fail on every run.

Both follow the v4.0 conventions (kebab-case inputs, SHA-pinned actions, ubuntu-slim, name: = filename). README updated with usage and all optional inputs. Validated locally with actionlint and zizmor (no findings).

Depends on #38 (seantronsen/chore/cleanup). This branch is stacked on it; merge #38 first so this diff stays limited to the two new workflows.

Fixes #36
Partially addresses #37 (codegen check; build-deb to be tracked separately)

Checklist

  • My code follows the style guidelines of this project
  • I have added/updated comments where needed
  • I have added tests that prove my fix is effective or my feature works
  • I have run make test (or equivalent) locally and all tests pass
  • I have updated the relevant documentation (CLI examples, man pages, README, other docs, etc.)
  • DCO Sign-off: All commits are signed off (git commit -s) with my real name and email
  • REUSE Compliance:
    • Each new/modified source file has SPDX copyright and license headers
    • Any non-commentable files include a <filename>.license sidecar
    • All referenced licenses are present in the LICENSES/ directory

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Dependency update
  • Build system/CI

@seantronsen
seantronsen requested a review from synackd October 5, 2026 21:07
@seantronsen seantronsen changed the title Seantronsen/feat/workflow ports v4: step 2, add more org workflows Oct 5, 2026
@seantronsen
seantronsen changed the base branch from main to seantronsen/chore/cleanup October 5, 2026 21:10
@seantronsen
seantronsen added this pull request to stack #40 October 5, 2026 21:10
@seantronsen seantronsen self-assigned this Oct 6, 2026
@synackd synackd added this to the v4 milestone Oct 7, 2026
@synackd synackd changed the title v4: step 2, add more org workflows feat(workflows): step 2, add reusable stale and Fabrica codegen checks Oct 7, 2026
Comment thread .github/workflows/lint-codegen-fabrica.yml Outdated
Comment thread .github/workflows/lint-codegen-fabrica.yml Outdated
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: openchami/fabrica
ref: ${{ steps.fabrica-ref.outputs.ref }}

@synackd synackd Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Go ref is passed directly to the Git ref here, but a valid Go pseudo-version such as:

v0.4.9-0.20260701000000-123456789abc

identifies a commit and ordinarily has no corresponding Git tag.

Instead, it's probably better to try the tag first and fallback to a commit (text after second -), erring if the ref is completely invalid:

- name: Validate and select Fabrica ref
  working-directory: fabrica
  shell: bash
  env:
    FABRICA_REF: ${{ inputs.fabrica-ref }}
  run: |
    ref="$FABRICA_REF"

    # An explicit input takes precedence over the caller's go.mod.
    if [[ -z "$ref" ]]; then
      if ! ref=$(go mod edit -json "$GITHUB_WORKSPACE/go.mod" | jq -er '
        .Require[]?
        | select(.Path == "github.com/openchami/fabrica")
        | .Version
        | select(type == "string" and length > 0)
      '); then
        echo "::error::Set fabrica-ref or require github.com/openchami/fabrica in the caller's go.mod"
        exit 1
      fi
    fi

    # Prefer an exact tag, then a branch.
    if git show-ref --verify --quiet "refs/tags/$ref"; then
      target="refs/tags/$ref"
    elif git show-ref --verify --quiet "refs/remotes/origin/$ref"; then
      target="refs/remotes/origin/$ref"
    else
      commit="$ref"

      # Resolve release-based and prerelease-based Go pseudo-versions.
      if [[ "$ref" =~ [.-][0-9]{14}-([0-9a-f]{12})$ ]]; then
        commit="${BASH_REMATCH[1]}"
      fi

      if [[ ! "$commit" =~ ^[0-9a-fA-F]{7,40}$ ]] ||
         ! target=$(git rev-parse --verify --end-of-options "${commit}^{commit}"); then
        echo "::error::Fabrica ref not found: $ref"
        exit 1
      fi
    fi

    git checkout --detach "$target"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure this is better. .Origin.Hash is not guaranteed (Origin marked with omitempty) in the Go proxy protocol so at the very least we should check if it's empty, e.g.:

jq -er '.Origin.Hash | select(type == "string" and test("^[0-9a-f]{40}$"))'

Right now, jq succeeds and sets the version to null if empty.

Also, it doesn't look like we are accepting user input for the ref in that commit anymore.

However, I will say I do prefer the tag-first approach of my snippet above (modified to add go.mod checking if user input is empty) since the tag will be used in the comment headers marking the fabrica version for the comparison.

@seantronsen
seantronsen requested a review from synackd October 8, 2026 18:03
Base automatically changed from seantronsen/chore/cleanup to seantronsen/release-400 October 8, 2026 21:54
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
…ration

Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
@synackd
synackd force-pushed the seantronsen/feat/workflow-ports branch from 23a6353 to e9cb5c9 Compare October 8, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: add actions/stale

2 participants