fix(ci): pin synthetic merge to event SHA

This commit is contained in:
玉澜
2026-08-10 21:08:55 +08:00
parent 9f3df91584
commit 8eae408e28
2 changed files with 20 additions and 19 deletions
+11 -11
View File
@@ -411,7 +411,7 @@ jobs:
if: steps.classify.outputs.changelog_only != 'true' && steps.classify.outputs.docs_only != 'true'
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
if: steps.classify.outputs.changelog_only != 'true' && steps.classify.outputs.docs_only != 'true'
@@ -450,7 +450,7 @@ jobs:
uses: actions/checkout@v4
with:
fetch-depth: 0
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Verify authoritative synthetic merge
env:
@@ -513,7 +513,7 @@ jobs:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
uses: actions/setup-go@v5
@@ -553,7 +553,7 @@ jobs:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
uses: actions/setup-go@v5
@@ -585,7 +585,7 @@ jobs:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
uses: actions/setup-go@v5
@@ -710,7 +710,7 @@ jobs:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
uses: actions/setup-go@v5
@@ -733,7 +733,7 @@ jobs:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
uses: actions/setup-go@v5
@@ -1240,7 +1240,7 @@ jobs:
uses: actions/checkout@v4
with:
fetch-depth: 0
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
@@ -1433,7 +1433,7 @@ jobs:
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
@@ -1463,7 +1463,7 @@ jobs:
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.mcp_sensitive == 'true') }}
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.mcp_sensitive == 'true') }}
@@ -1489,7 +1489,7 @@ jobs:
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.edition_sensitive == 'true') }}
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
ref: ${{ github.sha }}
- name: Set up Go
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.edition_sensitive == 'true') }}
+9 -8
View File
@@ -569,19 +569,20 @@ func TestChangelogPRFastPathWorkflowContract(t *testing.T) {
t.Error("Code Admission must not suppress required contexts with paths-ignore")
}
// Every checkout must resolve an immutable event SHA. Pull-request jobs
// that exercise the synthetic merge use the event's merge_commit_sha;
// source/baseline jobs intentionally use the event's head SHA. Leaving a
// checkout unpinned lets refs/pull/*/merge move after the event payload was
// created and makes the parent verification race with updates to main.
// Every checkout must resolve an immutable event SHA. Jobs that exercise
// the synthetic merge use github.sha; source/baseline jobs intentionally
// use the event's head SHA. Do not use pull_request.merge_commit_sha here:
// that payload field can still refer to the previous synthetic merge on a
// synchronize event. Leaving a checkout unpinned lets refs/pull/*/merge move
// after the event was created and races parent verification with main.
checkoutUses := strings.Count(admission, "uses: actions/checkout@v4")
pinnedCheckouts := strings.Count(admission, "github.event.pull_request.merge_commit_sha || github.sha") +
pinnedCheckouts := strings.Count(admission, "ref: ${{ github.sha }}") +
strings.Count(admission, "github.event.pull_request.head.sha || github.sha")
if checkoutUses == 0 || pinnedCheckouts != checkoutUses {
t.Errorf("Code Admission immutable checkout pins = %d, want one for each of %d checkouts", pinnedCheckouts, checkoutUses)
}
if !strings.Contains(admission, "github.event.pull_request.merge_commit_sha || github.sha") {
t.Error("Code Admission synthetic-merge jobs must pin the event merge_commit_sha")
if !strings.Contains(admission, "ref: ${{ github.sha }}") {
t.Error("Code Admission synthetic-merge jobs must pin github.sha")
}
focusedStart := strings.Index(admission, "\n test-focused:\n")