-
Notifications
You must be signed in to change notification settings - Fork 114
Run the full test matrix in the Release workflow before publishing #862
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -31,6 +31,23 @@ jobs: | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| with: | ||
| fetch-depth: 0 # Fetch all history for sphinx-multiversion | ||
| # sphinx-multiversion builds every version tag in the checkout. A tag | ||
| # gets its GitHub release only after the Release workflow's tests and | ||
| # PyPI upload succeed, so drop tags without one: a release still in | ||
| # progress or refused by its tests is not documented. | ||
|
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Independent review (relayed): Codex CLI 0.157.0, model
Reviewer result, verbatim:
Author verification: confirmed, and made more likely by this PR.
Repair in
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Independent follow-up (relayed): Codex CLI 0.157.0, model
Reviewer result, verbatim:
|
||
| - name: Drop unreleased version tags | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| run: | | ||
| released=$(gh api --paginate "repos/$GITHUB_REPOSITORY/releases?per_page=100" \ | ||
| --jq '.[] | select(.draft | not) | .tag_name') | ||
| if [[ -z "$released" ]]; then | ||
| echo "::error::No published GitHub releases found" | ||
| exit 1 | ||
| fi | ||
| git tag --list 'v*' | while read -r tag; do | ||
| grep -qxF "$tag" <<< "$released" || git tag --delete "$tag" | ||
| done | ||
| - name: Setup Pages | ||
| uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 | ||
| - uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0 | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -12,13 +12,24 @@ on: | |
| tags: | ||
| - 'v*' | ||
|
|
||
| permissions: | ||
| id-token: write | ||
| contents: write | ||
| permissions: {} | ||
|
|
||
| jobs: | ||
| # Runs every suite on every supported Python version for the tagged commit; | ||
| # nothing is built or published unless all of them pass. | ||
| test: | ||
| uses: ./.github/workflows/test.yaml | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| pull-requests: read | ||
|
|
||
| release: | ||
| needs: test | ||
|
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Self-review round two (claims, callers, operations), full pass: CLEAN after a description fix Base Claims checked:
Operational:
Not exercised: a real tag-push Release run (stated in TEST).
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Round-two follow-up on the repair (
|
||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| id-token: write | ||
| contents: write | ||
|
|
||
| env: | ||
| PYTHON_VERSION: '3.12' | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,13 +18,21 @@ on: | |
| - 'docs/**' | ||
| - '**.md' | ||
| # The scheduled run executes every suite, including the ones that pull | ||
| # requests only run when related files change. | ||
| # requests only run when related files change, on the newest Python version. | ||
| schedule: | ||
| - cron: '0 0 * * 0' | ||
| # Runs every suite on the selected branch: before a release, on demand for | ||
| # a pull request, and to refresh the README status badge after a transient | ||
| # failure on the default branch. | ||
| # Runs every suite on the selected branch: on demand for a pull request, and | ||
| # to refresh the README status badge after a transient failure on the | ||
| # default branch. | ||
| workflow_dispatch: | ||
| inputs: | ||
| python-versions: | ||
| description: Comma-separated Python versions, such as 3.12 or 3.11,3.14; empty for every supported version | ||
| type: string | ||
| default: '' | ||
| # The Release workflow runs every suite on every supported Python version | ||
| # before publishing. | ||
| workflow_call: | ||
|
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Self-review round one (implementation behavior), full pass on the rework: CLEAN Base Covered:
Checked:
No findings.
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Round-one follow-up on the repair (
|
||
|
|
||
| permissions: | ||
| id-token: write | ||
|
|
@@ -60,8 +68,9 @@ jobs: | |
| # requests run none. A ready pull request always runs the PyAthena suite; it | ||
| # runs the SQLAlchemy tests (the compliance suites and the PyAthena suite's | ||
| # SQLAlchemy tests) and the Spark tests only when their code, tests, | ||
| # dependencies, or this workflow change. Pull requests test the newest | ||
| # Python version only; the schedule and dispatch test every version. | ||
| # dependencies, or this workflow change. Pull requests and the schedule test | ||
| # the newest Python version; a dispatch tests the requested versions or | ||
| # every version, and the Release workflow every version. | ||
| changes: | ||
| if: >- | ||
| github.event_name != 'pull_request' || | ||
|
|
@@ -81,19 +90,36 @@ jobs: | |
| EVENT_NAME: ${{ github.event_name }} | ||
| REPO: ${{ github.repository }} | ||
| PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| REQUESTED_VERSIONS: ${{ inputs.python-versions }} | ||
| # Every supported version, oldest first; keep in sync with the | ||
| # pyproject.toml classifiers. | ||
| PYTHON_VERSIONS: '["3.10", "3.11", "3.12", "3.13", "3.14"]' | ||
| run: | | ||
| case "$EVENT_NAME" in | ||
| pull_request | schedule) | ||
| versions=$(jq -c '[last]' <<< "$PYTHON_VERSIONS") | ||
| ;; | ||
| workflow_dispatch) | ||
| versions=$(jq -c --arg requested "$REQUESTED_VERSIONS" ' | ||
| ($requested | split(",") | map(gsub("\\s"; "")) | map(select(. != "")) | unique) as $selected | ||
| | if $selected == [] then . | ||
| elif ($selected - .) == [] then $selected | ||
| else error("unsupported Python versions: \($selected - . | join(", "))") | ||
| end' <<< "$PYTHON_VERSIONS") | ||
| ;; | ||
| *) | ||
| # The Release workflow (a workflow_call from a tag push). | ||
| versions=$(jq -c '.' <<< "$PYTHON_VERSIONS") | ||
| ;; | ||
| esac | ||
| echo "python-versions=$versions" >> "$GITHUB_OUTPUT" | ||
| if [[ "$EVENT_NAME" != "pull_request" ]]; then | ||
| { | ||
| echo "python-versions=$(jq -c '.' <<< "$PYTHON_VERSIONS")" | ||
| echo "sqla=true" | ||
| echo "spark=true" | ||
| } >> "$GITHUB_OUTPUT" | ||
| exit 0 | ||
| fi | ||
| echo "python-versions=$(jq -c '[last]' <<< "$PYTHON_VERSIONS")" >> "$GITHUB_OUTPUT" | ||
| files=$(gh api "repos/$REPO/pulls/$PR_NUMBER/files" --paginate --jq '.[].filename') | ||
| printf 'Changed files:\n%s\n' "$files" | ||
| shared='^(\.github/workflows/test(-suite)?\.yaml|justfile|pyproject\.toml|uv\.lock)$' | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Self-review round two (claims, callers, operations): FINDINGS, repaired
Base
531185619465b809331a9a8cf2083884365de193. Reviewed head600b13da7abd522ecda1e90d8fe17ba0482b4818; repair head345ad32029f8e5f7b30a20d342c120406edbef99.Findings:
.github/workflows/docs-trigger.yaml:10-12dispatcheddocs.yamlon everyv*tag push.docs/conf.pyanddocs.yamlbuild tag versions with sphinx-multiversion. So a tag that the new gate refuses, or one whose PyPI upload fails, would still get a documentation build for an unpublished version.workflow_runof Release withconclusion == 'success', and the workflow is renamed "Trigger Docs on Release".docs.yamlalso builds on every push to master, so a refused tag that is left in place would still appear later.docs/testing.mdnow says to delete a refused tag, run the tests, and push the tag again.origin/3.xhas the sametest,test-sqla, andtest-sqla-async/run (<version>)job names, and a 3.10–3.14 matrix equal to its classifiers.Checked and held:
release.yaml":git show --stat 073635fshows 1 file, and4ef4d3ehas no Test run. The gate would have stopped that re-tag, which is stated as a consequence.test.yaml'schangesjob gates the suites forpull_requestonly.find_full_runandexpected_jobs.Validation after the repair:
just scripts(actionlint, 124 script tests) andjust docs lintpassed. Neither trigger has run through a real tag push; this is stated in the PR's TEST section.