fix(ci): repair draft PR command dispatch (#9271)

* fix(ci): repair draft PR command dispatch

Signed-off-by: WenyXu <wenymedia@gmail.com>

* fix(ci): dispatch command workflows by branch ref

Signed-off-by: WenyXu <wenymedia@gmail.com>

* fix(ci): admit PR authors and writers for CI commands

Signed-off-by: WenyXu <wenymedia@gmail.com>

* fix(ci): preserve dispatch guard dependency semantics

Signed-off-by: WenyXu <wenymedia@gmail.com>

* fix(ci): configure slash command permissions individually

Signed-off-by: WenyXu <wenymedia@gmail.com>

* refactor(ci): run command workflows at dispatch branch head

Signed-off-by: WenyXu <wenymedia@gmail.com>

* fix(ci): rerun fork PR checks and report command failures

Signed-off-by: WenyXu <wenymedia@gmail.com>

---------

Signed-off-by: WenyXu <wenymedia@gmail.com>
This commit is contained in:
Weny Xu
2026-09-23 10:32:19 +00:00
committed by GitHub
parent d910183cc4
commit 37fed9f12b
12 changed files with 239 additions and 50 deletions
+1
View File
@@ -5,6 +5,7 @@ name: Cargo.lock Diff Check
# posts/updates a PR comment when the threshold is exceeded.
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
paths:
- "Cargo.lock"
+1
View File
@@ -2,6 +2,7 @@ name: Check Git Dependencies on Main Branch
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
branches: [main]
paths:
- 'Cargo.toml'
+5 -5
View File
@@ -32,7 +32,7 @@ concurrency:
jobs:
check-typos-and-docs:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check typos and docs
runs-on: ubuntu-latest
steps:
@@ -47,7 +47,7 @@ jobs:
|| (echo "'config/config.md' is not up-to-date, please run 'make config-docs'." && exit 1)
license-header-check:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
runs-on: ubuntu-latest
name: Check License Header
steps:
@@ -63,7 +63,7 @@ jobs:
config: licenserc-enterprise.toml
github-script-tests:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: GitHub Script Tests
runs-on: ubuntu-latest
timeout-minutes: 5
@@ -100,7 +100,7 @@ jobs:
python3 tests/perf/test_agent_observability_summary.py
check:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check
runs-on: ${{ matrix.os }}
strategy:
@@ -129,7 +129,7 @@ jobs:
run: cargo check --locked --workspace --all-targets --all-features
toml:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Toml Check
runs-on: ubuntu-latest
timeout-minutes: 60
+32 -9
View File
@@ -30,23 +30,46 @@ jobs:
DISPATCH_SENDER: ${{ github.event.sender.login }}
DISPATCH_HEAD_SHA: ${{ github.event.client_payload.pull_request.head.sha }}
run: python3 .github/scripts/ci-slash.py
- name: Reply with command result
if: ${{ steps.admit.outputs.reply != '' }}
env:
GH_TOKEN: ${{ github.token }}
REPLY: ${{ steps.admit.outputs.reply }}
PR_NUMBER: ${{ steps.admit.outputs.pr_number }}
run: printf '%s\n' "${REPLY}" | gh pr comment "${PR_NUMBER}" --body-file -
- name: Dispatch selected CI workflow
id: dispatch
if: ${{ steps.admit.outputs.skip == 'false' }}
env:
GH_TOKEN: ${{ github.token }}
RUN_IDS: ${{ steps.admit.outputs.run_ids }}
WORKFLOWS: ${{ steps.admit.outputs.workflow }}
HEAD_SHA: ${{ steps.admit.outputs.head_sha }}
HEAD_REF: ${{ steps.admit.outputs.head_ref }}
FUZZ_PROFILE: ${{ steps.admit.outputs.fuzz_profile }}
run: |
if [[ -n "${RUN_IDS}" ]]; then
IFS=, read -ra runs <<<"${RUN_IDS}"
for run in "${runs[@]}"; do
gh api --method POST "/repos/${GITHUB_REPOSITORY}/actions/runs/${run}/rerun"
done
exit 0
fi
IFS=, read -ra workflows <<<"${WORKFLOWS}"
for workflow in "${workflows[@]}"; do
inputs=(-F 'inputs[ci_command]=true')
if [[ "${workflow}" == 'integration.yml' ]]; then
inputs+=(-f "inputs[fuzz_profile]=${FUZZ_PROFILE}")
fi
gh api --method POST "/repos/${GITHUB_REPOSITORY}/actions/workflows/${workflow}/dispatches" \
-f ref="${HEAD_SHA}" -F 'inputs[ci_command]=true' -f "inputs[fuzz_profile]=${FUZZ_PROFILE}"
-f ref="${HEAD_REF}" "${inputs[@]}"
done
- name: Reply with command result
if: ${{ !cancelled() && github.event.sender.login == 'github-actions[bot]' }}
env:
GH_TOKEN: ${{ github.token }}
REPLY: ${{ steps.admit.outputs.reply }}
PR_NUMBER: ${{ steps.admit.outputs.pr_number || github.event.client_payload.github.payload.issue.number }}
ADMIT_OUTCOME: ${{ steps.admit.outcome }}
DISPATCH_OUTCOME: ${{ steps.dispatch.outcome }}
# Use the issue-comment endpoint with the existing issues: write permission.
run: |
[[ "${PR_NUMBER}" =~ ^[0-9]+$ ]] || exit 1
if [[ "${ADMIT_OUTCOME}" == failure || "${DISPATCH_OUTCOME}" == failure ]]; then
REPLY="CI trigger failed; some workflows may already have been requested. See ${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID} for details."
fi
[[ -n "${REPLY}" ]] || exit 1
gh api --method POST "/repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/comments" \
-f "body=${REPLY}"
+1
View File
@@ -2,6 +2,7 @@ name: Check Dependencies
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
branches:
- main
+3 -3
View File
@@ -38,7 +38,7 @@ name: Docs CI
jobs:
typos:
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }}
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1 }}
name: Spell Check with Typos
runs-on: ubuntu-latest
steps:
@@ -48,7 +48,7 @@ jobs:
- uses: crate-ci/typos@v1.50.2
license-header-check:
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }}
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1 }}
runs-on: ubuntu-latest
name: Check License Header
steps:
@@ -58,7 +58,7 @@ jobs:
- uses: korandoru/hawkeye@v5
required-checks:
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }}
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1 }}
name: ${{ matrix.check }}
runs-on: ubuntu-slim
strategy:
+1
View File
@@ -2,6 +2,7 @@ name: Check Grafana Panels
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
branches:
- main
paths:
+5 -5
View File
@@ -43,7 +43,7 @@ concurrency:
jobs:
build:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Build GreptimeDB binaries
runs-on: ${{ matrix.os }}
strategy:
@@ -104,7 +104,7 @@ jobs:
version: current
sqlness:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Sqlness Test (${{ matrix.mode.name }})
needs: build
runs-on: ${{ matrix.os }}
@@ -184,7 +184,7 @@ jobs:
retention-days: 3
export-import-v2-e2e:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Export/Import V2 E2E Test
needs: build
runs-on: ubuntu-latest
@@ -254,7 +254,7 @@ jobs:
retention-days: 3
run-multi-lang-tests:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Run Multi-language SDK Tests
needs: build
uses: ./.github/workflows/run-multi-lang-tests.yml
@@ -262,7 +262,7 @@ jobs:
artifact-name: bins
compat-updater-check:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) && (github.event_name == 'merge_group' || github.event_name == 'pull_request') }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) && (github.event_name == 'merge_group' || github.event_name == 'pull_request') }}
name: Check compat version updater
runs-on: ubuntu-latest
timeout-minutes: 10
+7 -7
View File
@@ -32,7 +32,7 @@ concurrency:
jobs:
fmt:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Rustfmt
runs-on: ubuntu-latest
timeout-minutes: 60
@@ -50,7 +50,7 @@ jobs:
run: make fmt-check
clippy:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Clippy
runs-on: ubuntu-latest
timeout-minutes: 60
@@ -76,7 +76,7 @@ jobs:
run: make clippy
check-udeps:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check Unused Dependencies
runs-on: ubuntu-latest
timeout-minutes: 60
@@ -94,7 +94,7 @@ jobs:
run: make check-udeps
check-riscv64:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check riscv64 build
runs-on: ubuntu-latest
timeout-minutes: 90
@@ -120,7 +120,7 @@ jobs:
run: cargo check --locked --workspace --all-targets --features servers/dashboard --target riscv64gc-unknown-linux-gnu
check-windows:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check Windows build
runs-on: windows-2022
timeout-minutes: 60
@@ -191,7 +191,7 @@ jobs:
run: cargo nextest run --locked --workspace -F dashboard --no-fail-fast
conflict-check:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
name: Check for conflict
runs-on: ubuntu-latest
steps:
@@ -202,7 +202,7 @@ jobs:
uses: olivernybroe/action-conflict-finder@v4.0
test:
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && github.event_name != 'merge_group' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
if: ${{ github.repository == 'GreptimeTeam/greptimedb' && github.event_name != 'merge_group' && (github.event_name != 'pull_request' || github.event.pull_request.draft == false || github.run_attempt > 1) }}
runs-on: ubuntu-22.04-arm
timeout-minutes: 60
needs: [conflict-check, clippy, fmt, check-udeps]
+17 -8
View File
@@ -1,13 +1,13 @@
name: Slash Command Dispatch
# ChatOps front door: parse `/command` on PR comments, check admin
# permission, and repository_dispatch to a per-command handler. Handlers
# ChatOps front door: parse `/command` on PR comments, apply command-specific
# permissions, and repository_dispatch to a per-command handler. Handlers
# own allowlists, SHA admission, and the actual work. Same-repo dispatch
# uses github.token with contents: write; GitHub starts the handler run
# for GITHUB_TOKEN-created repository_dispatch events. Do not pass the
# long-lived GH_PERSONAL_ACCESS_TOKEN into this third-party action.
#
# To add a command: list it under `commands` and add a workflow with
# To add a command: add it to `config` and add a workflow with
# `on.repository_dispatch.types: ["<command>-command"]`.
on:
@@ -30,8 +30,17 @@ jobs:
uses: peter-evans/slash-command-dispatch@9bdcd7914ec1b75590b790b844aa3b8eee7c683a # v5.0.2
with:
token: ${{ github.token }}
permission: admin
issue-type: pull-request
commands: |
query-regression
ci
# CI admission re-fetches the comment and checks author/member permissions.
config: >-
[
{"command": "query-regression", "permission": "admin", "issue_type": "pull-request"},
{"command": "ci", "permission": "none", "issue_type": "pull-request"}
]
- name: Report CI dispatch failure
if: ${{ failure() && (github.event.comment.body == '/ci' || startsWith(github.event.comment.body, '/ci ')) }}
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.issue.number }}
run: |
gh api --method POST "/repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/comments" \
-f "body=CI command dispatch failed. See ${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID} for details."