fix(ci): pin synthetic merge to event SHA
This commit is contained in:
+11
-11
@@ -411,7 +411,7 @@ jobs:
|
||||
if: steps.classify.outputs.changelog_only != 'true' && steps.classify.outputs.docs_only != 'true'
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
if: steps.classify.outputs.changelog_only != 'true' && steps.classify.outputs.docs_only != 'true'
|
||||
@@ -450,7 +450,7 @@ jobs:
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Verify authoritative synthetic merge
|
||||
env:
|
||||
@@ -513,7 +513,7 @@ jobs:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -553,7 +553,7 @@ jobs:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -585,7 +585,7 @@ jobs:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -710,7 +710,7 @@ jobs:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -733,7 +733,7 @@ jobs:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -1240,7 +1240,7 @@ jobs:
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
|
||||
@@ -1433,7 +1433,7 @@ jobs:
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.interface_sensitive == 'true') }}
|
||||
@@ -1463,7 +1463,7 @@ jobs:
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.mcp_sensitive == 'true') }}
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.mcp_sensitive == 'true') }}
|
||||
@@ -1489,7 +1489,7 @@ jobs:
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.edition_sensitive == 'true') }}
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.merge_commit_sha || github.sha }}
|
||||
ref: ${{ github.sha }}
|
||||
|
||||
- name: Set up Go
|
||||
if: ${{ needs.lint.outputs.changelog_only != 'true' && needs.lint.outputs.docs_only != 'true' && (needs.lint.outputs.full_suite == 'true' || needs.lint.outputs.edition_sensitive == 'true') }}
|
||||
|
||||
@@ -569,19 +569,20 @@ func TestChangelogPRFastPathWorkflowContract(t *testing.T) {
|
||||
t.Error("Code Admission must not suppress required contexts with paths-ignore")
|
||||
}
|
||||
|
||||
// Every checkout must resolve an immutable event SHA. Pull-request jobs
|
||||
// that exercise the synthetic merge use the event's merge_commit_sha;
|
||||
// source/baseline jobs intentionally use the event's head SHA. Leaving a
|
||||
// checkout unpinned lets refs/pull/*/merge move after the event payload was
|
||||
// created and makes the parent verification race with updates to main.
|
||||
// Every checkout must resolve an immutable event SHA. Jobs that exercise
|
||||
// the synthetic merge use github.sha; source/baseline jobs intentionally
|
||||
// use the event's head SHA. Do not use pull_request.merge_commit_sha here:
|
||||
// that payload field can still refer to the previous synthetic merge on a
|
||||
// synchronize event. Leaving a checkout unpinned lets refs/pull/*/merge move
|
||||
// after the event was created and races parent verification with main.
|
||||
checkoutUses := strings.Count(admission, "uses: actions/checkout@v4")
|
||||
pinnedCheckouts := strings.Count(admission, "github.event.pull_request.merge_commit_sha || github.sha") +
|
||||
pinnedCheckouts := strings.Count(admission, "ref: ${{ github.sha }}") +
|
||||
strings.Count(admission, "github.event.pull_request.head.sha || github.sha")
|
||||
if checkoutUses == 0 || pinnedCheckouts != checkoutUses {
|
||||
t.Errorf("Code Admission immutable checkout pins = %d, want one for each of %d checkouts", pinnedCheckouts, checkoutUses)
|
||||
}
|
||||
if !strings.Contains(admission, "github.event.pull_request.merge_commit_sha || github.sha") {
|
||||
t.Error("Code Admission synthetic-merge jobs must pin the event merge_commit_sha")
|
||||
if !strings.Contains(admission, "ref: ${{ github.sha }}") {
|
||||
t.Error("Code Admission synthetic-merge jobs must pin github.sha")
|
||||
}
|
||||
|
||||
focusedStart := strings.Index(admission, "\n test-focused:\n")
|
||||
|
||||
Reference in New Issue
Block a user