Repository navigation
ci: resolve contrib repo SHA once for hermetic CI - #5625
mwimpelberg28 wants to merge 4 commits into
Conversation
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKP2UVjDuXMFBeNLGs6QqE
CONTRIB_REPO_SHA was independently re-derived as a branch name (not a pinned commit) in ci.yml, misc.yml, test.yml, and lint.yml, so different jobs in the same CI run (or a later re-run) could end up testing against different contrib commits if contrib's target branch moved in between. Resolve the contrib branch to a concrete commit SHA once, in a new resolve-contrib-sha job in ci.yml, and pass it down to misc/tests/contrib via workflow_call inputs instead of recomputing it in each workflow. Also drop CORE_REPO_SHA from misc.yml/lint.yml/test.yml: it was declared in each workflow's env block but never actually referenced anywhere, and lint.yml never used CONTRIB_REPO_SHA either, so both are removed there. The contrib job in ci.yml already pins CORE_REPO_SHA correctly via github.sha. Fixes open-telemetry#4305 Assisted-by: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKP2UVjDuXMFBeNLGs6QqE
Assisted-by: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKP2UVjDuXMFBeNLGs6QqE
1a5b9f0 to
4a3efae
Compare
Pull request dashboard statusWaiting on the author · refreshed 2026-10-07 00:47 UTC Resolve merge conflicts. Respond to 2 review items (e.g. link a commit, explain why not, ask a follow-up): Status above doesn't look right?
|
Assisted-by: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QfkYRgR6uK63pkrd955gbv
ba066ac to
f91cdb0
Compare
| # For PRs you can change the inner fallback ('main') | ||
| # For pushes you change the outer fallback ('main') | ||
| # The logic below is used during releases and depends on having an equivalent branch name in the contrib repo. | ||
| CONTRIB_REPO_SHA: {% raw %}${{ github.event_name == 'pull_request' && ( |
There was a problem hiding this comment.
Don't we need CONTRIB_REPO_SHA in lint?
There was a problem hiding this comment.
I'm pretty sure we use CONTRIB_REPO_SHA in tox.ini, otherwise, CI will fail during releases.
| contrib-repo-sha: ${% raw %}{{ needs.resolve-contrib-sha.outputs.sha }}{% endraw %} | ||
| contrib: | ||
| needs: resolve-contrib-sha | ||
| uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@main |
There was a problem hiding this comment.
The major problem still this, where we can't pass a dynamic value for the reusable workflow
|
Hi @mwimpelberg28 — just a friendly reminder that this pull request is waiting on you. The dashboard status comment has the open items and is kept current.
|
|
This PR has been automatically marked as stale because it has not had any activity for 14 days. It will be closed if no further activity occurs within 14 days of this comment. |
Summary
Fixes #4305.
CONTRIB_REPO_SHAwas independently re-derived from a branch-name expression in four places (ci.yml,misc.yml,test.yml,lint.yml), always resolving to a branch name, not a pinned commit:Since each job re-evaluates this independently, jobs in the same CI run (or a re-run hours later) could end up checking out different contrib commits if contrib's target branch moved in between — not hermetic, and a likely contributor to flakiness like #4853.
This PR resolves the contrib branch to a concrete commit SHA once, in a new
resolve-contrib-shajob inci.yml(viagit ls-remote), and passes that SHA down tomisc,tests, andcontribviaworkflow_callinputs instead of each workflow recomputing its own branch-name expression.While in there, I also removed
CORE_REPO_SHA: mainfrommisc.yml/lint.yml/test.yml— it was declared in each workflow'senv:block but never actually referenced anywhere in.github/. The one meaningful use ofCORE_REPO_SHA(passed to contrib'score_contrib_test.ymlreusable workflow) was already correctly pinned togithub.sha, so this only removes dead code.lint.ymlalso never usedCONTRIB_REPO_SHAat all, so that's dropped there too.Changes
.github/workflows/templates/ci.yml.j2: addresolve-contrib-shajob; wire its output intomisc,tests, andcontribjobs vianeeds/with.github/workflows/templates/misc.yml.j2/test.yml.j2: acceptcontrib-repo-shaas aworkflow_callinput instead of recomputing it; drop unusedCORE_REPO_SHA.github/workflows/templates/lint.yml.j2: drop unusedCORE_REPO_SHA/CONTRIB_REPO_SHA(neither is referenced anywhere in this workflow).github/workflows/{ci,misc,lint,test}.yml: regenerated viatox -e generate-workflows(no manual edits)Test plan
tox -e generate-workflowsregenerates the four.ymlfiles with no diff beyond what the template changes produce (confirms templates and generated output stay in sync, matching the repo's owngenerate-workflowsCI check)resolve-contrib-shajob and downstreammisc/tests/contribjobs end-to-endNote: this doesn't fully resolve #4853 (release-branch instrumentation mismatch) on its own — that likely needs a follow-up decision on what should happen when a release-branch PR's contrib ref doesn't have a matching instrumentation set. Left a note on that issue tracking it separately.
🤖 Generated with Claude Code
https://claude.ai/code/session_01TKP2UVjDuXMFBeNLGs6QqE