name: CI Command on: repository_dispatch: types: [ci-command] permissions: actions: write contents: read issues: write pull-requests: write jobs: admit: runs-on: ubuntu-latest timeout-minutes: 5 steps: - name: Checkout trusted admission script uses: actions/checkout@v4 with: ref: ${{ github.event.repository.default_branch }} persist-credentials: false - name: Admit CI command id: admit env: GITHUB_TOKEN: ${{ github.token }} GITHUB_REPOSITORY: ${{ github.repository }} GITHUB_API_URL: ${{ github.api_url }} COMMENT_ID: ${{ github.event.client_payload.github.payload.comment.id }} DISPATCH_SENDER: ${{ github.event.sender.login }} DISPATCH_HEAD_SHA: ${{ github.event.client_payload.pull_request.head.sha }} run: python3 .github/scripts/ci-slash.py - name: Dispatch selected CI workflow id: dispatch if: ${{ steps.admit.outputs.skip == 'false' }} env: GH_TOKEN: ${{ github.token }} RUN_IDS: ${{ steps.admit.outputs.run_ids }} WORKFLOWS: ${{ steps.admit.outputs.workflow }} HEAD_REF: ${{ steps.admit.outputs.head_ref }} FUZZ_PROFILE: ${{ steps.admit.outputs.fuzz_profile }} run: | if [[ -n "${RUN_IDS}" ]]; then IFS=, read -ra runs <<<"${RUN_IDS}" for run in "${runs[@]}"; do gh api --method POST "/repos/${GITHUB_REPOSITORY}/actions/runs/${run}/rerun" done exit 0 fi IFS=, read -ra workflows <<<"${WORKFLOWS}" for workflow in "${workflows[@]}"; do inputs=(-F 'inputs[ci_command]=true') if [[ "${workflow}" == 'integration.yml' ]]; then inputs+=(-f "inputs[fuzz_profile]=${FUZZ_PROFILE}") fi gh api --method POST "/repos/${GITHUB_REPOSITORY}/actions/workflows/${workflow}/dispatches" \ -f ref="${HEAD_REF}" "${inputs[@]}" done - name: Reply with command result if: ${{ !cancelled() && github.event.sender.login == 'github-actions[bot]' }} env: GH_TOKEN: ${{ github.token }} REPLY: ${{ steps.admit.outputs.reply }} PR_NUMBER: ${{ steps.admit.outputs.pr_number || github.event.client_payload.github.payload.issue.number }} ADMIT_OUTCOME: ${{ steps.admit.outcome }} DISPATCH_OUTCOME: ${{ steps.dispatch.outcome }} # PR replies require pull-requests: write even through the issue-comment endpoint. run: | [[ "${PR_NUMBER}" =~ ^[0-9]+$ ]] || exit 1 if [[ "${ADMIT_OUTCOME}" == failure || "${DISPATCH_OUTCOME}" == failure ]]; then REPLY="CI trigger failed; some workflows may already have been requested. See ${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID} for details." fi [[ -n "${REPLY}" ]] || exit 1 gh api --method POST "/repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/comments" \ -f "body=${REPLY}"