From a0b48034069352e40a696132b46bb2f50d0747c9 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sun, 25 May 2025 13:42:32 +0200 Subject: [PATCH 1/5] workflows/eval: fix comparison with merge conflicts In PRs with multiple commits and merge conflicts the logic "targetSha == immediate parent of mergedSha" doesn't hold anymore. The head and base commits of the PR's branch have some commits inbetween them, instead. Before this change, we'd get a "fatal: invalid reference" on the "worktree add". Now, not anymore, because we fetch the right commit directly. (cherry picked from commit cd9a22d7530baf33890971b01af8798069c3fea9) (cherry picked from commit 6cddb25b5b9af84e3cac2b7132221319cc545475) --- .github/workflows/eval.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index bec9c23de6a0..3acfbdf25e37 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -101,7 +101,6 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ needs.prepare.outputs.mergedSha }} - fetch-depth: 2 path: nixpkgs - name: Install Nix @@ -168,6 +167,7 @@ jobs: env: AUTHOR_ID: ${{ github.event.pull_request.user.id }} run: | + git -C nixpkgs fetch --depth 1 origin ${{ needs.prepare.outputs.targetSha }} git -C nixpkgs worktree add ../target ${{ needs.prepare.outputs.targetSha }} git -C nixpkgs diff --name-only ${{ needs.prepare.outputs.targetSha }} \ | jq --raw-input --slurp 'split("\n")[:-1]' > touched-files.json From b4944c3388398cc41a7ad1d3946d9e949f9b14c2 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sun, 25 May 2025 13:25:24 +0200 Subject: [PATCH 2/5] actions/get-merge-conflict: refactor Using core.setOutput is much nicer than having to parse the json "result" on the outside. This also avoids some very odd errors, when the result can, for unknown reasons, *not* be parsed as JSON later on. Also avoiding a bit of duplication between the "if mergeable" branches. (cherry picked from commit 539e8d4f66323b87aa1b8e715ec01b9f5199ca82) (cherry picked from commit 13fbecb916beb183f0af906453bf3b891d246f56) --- .github/actions/get-merge-commit/action.yml | 29 ++++++++++----------- 1 file changed, 14 insertions(+), 15 deletions(-) diff --git a/.github/actions/get-merge-commit/action.yml b/.github/actions/get-merge-commit/action.yml index 1505d582efd8..51f8a00286b5 100644 --- a/.github/actions/get-merge-commit/action.yml +++ b/.github/actions/get-merge-commit/action.yml @@ -5,10 +5,10 @@ description: 'Checks whether the Pull Request is mergeable and returns two commi outputs: mergedSha: description: "The merge commit SHA" - value: ${{ fromJSON(steps.merged.outputs.result).mergedSha }} + value: ${{ steps.merged.outputs.mergedSha }} targetSha: description: "The target commit SHA" - value: ${{ fromJSON(steps.merged.outputs.result).targetSha }} + value: ${{ steps.merged.outputs.targetSha }} runs: using: composite @@ -17,7 +17,7 @@ runs: uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 with: script: | - if (context.eventName == 'push') return { mergedSha: context.sha } + if (context.eventName == 'push') return core.setOutput('mergedSha', context.sha) for (const retryInterval of [5, 10, 20, 40, 80]) { console.log("Checking whether the pull request can be merged...") @@ -35,32 +35,31 @@ runs: continue } + let mergedSha, targetSha + if (prInfo.mergeable) { console.log("The PR can be merged.") - const mergedSha = prInfo.merge_commit_sha - const targetSha = (await github.rest.repos.getCommit({ + mergedSha = prInfo.merge_commit_sha + targetSha = (await github.rest.repos.getCommit({ owner: context.repo.owner, repo: context.repo.repo, ref: prInfo.merge_commit_sha })).data.parents[0].sha - - console.log(`Checking the commits:\nmerged:${mergedSha}\ntarget:${targetSha}`) - - return { mergedSha, targetSha } } else { console.log("The PR has a merge conflict.") - const mergedSha = prInfo.head.sha - const targetSha = (await github.rest.repos.compareCommitsWithBasehead({ + mergedSha = prInfo.head.sha + targetSha = (await github.rest.repos.compareCommitsWithBasehead({ owner: context.repo.owner, repo: context.repo.repo, basehead: `${prInfo.base.sha}...${prInfo.head.sha}` })).data.merge_base_commit.sha - - console.log(`Checking the commits:\nmerged:${mergedSha}\ntarget:${targetSha}`) - - return { mergedSha, targetSha } } + + console.log(`Checking the commits:\nmerged:${mergedSha}\ntarget:${targetSha}`) + core.setOutput('mergedSha', mergedSha) + core.setOutput('targetSha', targetSha) + return } throw new Error("Not retrying anymore. It's likely that GitHub is having internal issues: check https://www.githubstatus.com.") From 3539b268eee4ab17250402d95853bda897c1d4c7 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sat, 24 May 2025 14:05:26 +0200 Subject: [PATCH 3/5] workflows: checkout nixpkgs into trusted/untrusted directories By consistently checking out nixpkgs into the same location in every workflow, it's easier to reason about the different workflows at once. We also use crystal-clear names to make clear, which checkouts are considered trusted, because they only contain target-branch-code and which checkouts are untrusted, because they contain code from the head branch. By naming the checkout directories trusted/untrusted, it's obvious at the call-site. One example of where we likely did the wrong thing is the nixpkgs-vet workflow: Fetching the toolVersion from the untrusted checkout opens the door for an injection into the download URL, thus code could be downloaded from anywhere. This is not a problem, because this workflow does not run with elevated privileges, but it's a scary oversight nonetheless. (cherry picked from commit 6720d254294220cdfce18c3f981a8aabffb3de94) (cherry picked from commit a55f7ddced785a7d8631d027b06af9574f6b181b) --- .github/workflows/check-cherry-picks.yml | 3 ++- .github/workflows/check-format.yml | 3 ++- .github/workflows/check-shell.yml | 3 ++- .github/workflows/codeowners-v2.yml | 15 +++++++++------ .github/workflows/eval-aliases.yml | 6 +++--- .github/workflows/eval.yml | 22 +++++++++++----------- .github/workflows/lib-tests.yml | 3 ++- .github/workflows/manual-nixos-v2.yml | 3 ++- .github/workflows/manual-nixpkgs-v2.yml | 3 ++- .github/workflows/nix-parse-v2.yml | 3 ++- .github/workflows/nixpkgs-vet.yml | 9 ++++----- 11 files changed, 41 insertions(+), 32 deletions(-) diff --git a/.github/workflows/check-cherry-picks.yml b/.github/workflows/check-cherry-picks.yml index 70dfdfba1e5f..e85fa59bb699 100644 --- a/.github/workflows/check-cherry-picks.yml +++ b/.github/workflows/check-cherry-picks.yml @@ -21,10 +21,11 @@ jobs: with: fetch-depth: 0 filter: blob:none + path: trusted - name: Check cherry-picks env: BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} run: | - ./maintainers/scripts/check-cherry-picks.sh "$BASE_SHA" "$HEAD_SHA" + ./trusted/maintainers/scripts/check-cherry-picks.sh "$BASE_SHA" "$HEAD_SHA" diff --git a/.github/workflows/check-format.yml b/.github/workflows/check-format.yml index 58c76f97da6b..ec83ffcce07c 100644 --- a/.github/workflows/check-format.yml +++ b/.github/workflows/check-format.yml @@ -23,6 +23,7 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -33,7 +34,7 @@ jobs: # Note that it's fine to run this on untrusted code because: # - There's no secrets accessible here # - The build is sandboxed - if ! nix-build ci -A fmt.check; then + if ! nix-build untrusted/ci -A fmt.check; then echo "Some files are not properly formatted" echo "Please format them by going to the Nixpkgs root directory and running one of:" echo " nix-shell --run treefmt" diff --git a/.github/workflows/check-shell.yml b/.github/workflows/check-shell.yml index 01dd64913b6a..39fb722ae87a 100644 --- a/.github/workflows/check-shell.yml +++ b/.github/workflows/check-shell.yml @@ -40,8 +40,9 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - name: Build shell - run: nix-build ci -A shell + run: nix-build untrusted/ci -A shell diff --git a/.github/workflows/codeowners-v2.yml b/.github/workflows/codeowners-v2.yml index e22ccfcea52d..085abced061c 100644 --- a/.github/workflows/codeowners-v2.yml +++ b/.github/workflows/codeowners-v2.yml @@ -63,10 +63,11 @@ jobs: # so it's important this is not the PRs code. - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - path: base + ref: ${{ steps.get-merge-commit.outputs.targetSha }} + path: trusted - name: Build codeowners validator - run: nix-build base/ci -A codeownersValidator + run: nix-build trusted/ci -A codeownersValidator - uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6 if: vars.OWNER_RO_APP_ID @@ -80,14 +81,14 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: pr + path: untrusted - name: Validate codeowners if: steps.app-token.outputs.token env: - OWNERS_FILE: pr/${{ env.OWNERS_FILE }} + OWNERS_FILE: untrusted/${{ env.OWNERS_FILE }} GITHUB_ACCESS_TOKEN: ${{ steps.app-token.outputs.token }} - REPOSITORY_PATH: pr + REPOSITORY_PATH: untrusted OWNER_CHECKER_REPOSITORY: ${{ github.repository }} # Set this to "notowned,avoid-shadowing" to check that all files are owned by somebody EXPERIMENTAL_CHECKS: "avoid-shadowing" @@ -104,6 +105,8 @@ jobs: # Important: Because we use pull_request_target, this checks out the base branch of the PR, not the PR head. # This is intentional, because we need to request the review of owners as declared in the base branch. - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + path: trusted - uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6 if: vars.OWNER_APP_ID @@ -116,7 +119,7 @@ jobs: permission-pull-requests: write - name: Build review request package - run: nix-build ci -A requestReviews + run: nix-build trusted/ci -A requestReviews - name: Request reviews if: steps.app-token.outputs.token diff --git a/.github/workflows/eval-aliases.yml b/.github/workflows/eval-aliases.yml index 941ffd378ef7..dc5bad6572fb 100644 --- a/.github/workflows/eval-aliases.yml +++ b/.github/workflows/eval-aliases.yml @@ -24,7 +24,7 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: nixpkgs + path: untrusted - name: Install Nix uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 @@ -32,8 +32,8 @@ jobs: extra_nix_config: sandbox = true - name: Ensure flake outputs on all systems still evaluate - run: nix flake check --all-systems --no-build ./nixpkgs + run: nix flake check --all-systems --no-build ./untrusted - name: Query nixpkgs with aliases enabled to check for basic syntax errors run: | - time nix-env -I ./nixpkgs -f ./nixpkgs -qa '*' --option restrict-eval true --option allow-import-from-derivation false >/dev/null + time nix-env -I ./untrusted -f ./untrusted -qa '*' --option restrict-eval true --option allow-import-from-derivation false >/dev/null diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 3acfbdf25e37..0063ad1a12e9 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -61,7 +61,7 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ needs.prepare.outputs.mergedSha }} - path: nixpkgs + path: untrusted - name: Install Nix uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 @@ -72,7 +72,7 @@ jobs: env: MATRIX_SYSTEM: ${{ matrix.system }} run: | - nix-build nixpkgs/ci -A eval.singleSystem \ + nix-build untrusted/ci -A eval.singleSystem \ --argstr evalSystem "$MATRIX_SYSTEM" \ --arg chunkSize 10000 # If it uses too much memory, slightly decrease chunkSize @@ -101,7 +101,7 @@ jobs: uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ needs.prepare.outputs.mergedSha }} - path: nixpkgs + path: untrusted - name: Install Nix uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 @@ -110,7 +110,7 @@ jobs: - name: Combine all output paths and eval stats run: | - nix-build nixpkgs/ci -A eval.combine \ + nix-build untrusted/ci -A eval.combine \ --arg resultsDir ./intermediate \ -o prResult @@ -167,13 +167,13 @@ jobs: env: AUTHOR_ID: ${{ github.event.pull_request.user.id }} run: | - git -C nixpkgs fetch --depth 1 origin ${{ needs.prepare.outputs.targetSha }} - git -C nixpkgs worktree add ../target ${{ needs.prepare.outputs.targetSha }} - git -C nixpkgs diff --name-only ${{ needs.prepare.outputs.targetSha }} \ + git -C untrusted fetch --depth 1 origin ${{ needs.prepare.outputs.targetSha }} + git -C untrusted worktree add ../trusted ${{ needs.prepare.outputs.targetSha }} + git -C untrusted diff --name-only ${{ needs.prepare.outputs.targetSha }} \ | jq --raw-input --slurp 'split("\n")[:-1]' > touched-files.json # Use the target branch to get accurate maintainer info - nix-build target/ci -A eval.compare \ + nix-build trusted/ci -A eval.compare \ --arg beforeResultDir ./targetResult \ --arg afterResultDir "$(realpath prResult)" \ --arg touchedFilesJson ./touched-files.json \ @@ -222,15 +222,15 @@ jobs: # Important: This workflow job runs with extra permissions, # so we need to make sure to not run untrusted code from PRs - - name: Check out Nixpkgs at the base commit + - name: Check out Nixpkgs at the target commit uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ needs.prepare.outputs.targetSha }} - path: base + path: trusted sparse-checkout: ci - name: Build the requestReviews derivation - run: nix-build base/ci -A requestReviews + run: nix-build trusted/ci -A requestReviews - name: Labelling pull request if: ${{ github.event_name == 'pull_request_target' && github.repository_owner == 'NixOS' }} diff --git a/.github/workflows/lib-tests.yml b/.github/workflows/lib-tests.yml index 345d59bb9cc4..5e3a7a5cba66 100644 --- a/.github/workflows/lib-tests.yml +++ b/.github/workflows/lib-tests.yml @@ -26,6 +26,7 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -33,4 +34,4 @@ jobs: - name: Building Nixpkgs lib-tests run: | - nix-build ci -A lib-tests + nix-build untrusted/ci -A lib-tests diff --git a/.github/workflows/manual-nixos-v2.yml b/.github/workflows/manual-nixos-v2.yml index 5d5acdd377e7..ce5313c8135f 100644 --- a/.github/workflows/manual-nixos-v2.yml +++ b/.github/workflows/manual-nixos-v2.yml @@ -42,6 +42,7 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -55,7 +56,7 @@ jobs: - name: Build NixOS manual id: build-manual - run: NIX_PATH=nixpkgs=$(pwd) nix-build --option restrict-eval true ci -A manual-nixos --argstr system ${{ matrix.system }} + run: NIX_PATH=nixpkgs=$(pwd)/untrusted nix-build --option restrict-eval true untrusted/ci -A manual-nixos --argstr system ${{ matrix.system }} - name: Upload NixOS manual uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 diff --git a/.github/workflows/manual-nixpkgs-v2.yml b/.github/workflows/manual-nixpkgs-v2.yml index b31a6b4949e1..5cb63a2c88bd 100644 --- a/.github/workflows/manual-nixpkgs-v2.yml +++ b/.github/workflows/manual-nixpkgs-v2.yml @@ -29,6 +29,7 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -41,4 +42,4 @@ jobs: authToken: '${{ secrets.CACHIX_AUTH_TOKEN }}' - name: Building Nixpkgs manual - run: NIX_PATH=nixpkgs=$(pwd) nix-build --option restrict-eval true ci -A manual-nixpkgs -A manual-nixpkgs-tests + run: NIX_PATH=nixpkgs=$(pwd)/untrusted nix-build --option restrict-eval true untrusted/ci -A manual-nixpkgs -A manual-nixpkgs-tests diff --git a/.github/workflows/nix-parse-v2.yml b/.github/workflows/nix-parse-v2.yml index 6ae66e964474..ecbb9c843389 100644 --- a/.github/workflows/nix-parse-v2.yml +++ b/.github/workflows/nix-parse-v2.yml @@ -24,6 +24,7 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} + path: untrusted - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -33,4 +34,4 @@ jobs: - name: Parse all nix files run: | # Tests multiple versions at once, let's make sure all of them run, so keep-going. - nix-build ci -A parse --keep-going + nix-build untrusted/ci -A parse --keep-going diff --git a/.github/workflows/nixpkgs-vet.yml b/.github/workflows/nixpkgs-vet.yml index 761ecbf08f2f..aefed2b267ce 100644 --- a/.github/workflows/nixpkgs-vet.yml +++ b/.github/workflows/nixpkgs-vet.yml @@ -36,12 +36,11 @@ jobs: ref: ${{ steps.get-merge-commit.outputs.mergedSha }} # Fetches the merge commit and its parents fetch-depth: 2 + path: untrusted - name: Checking out target branch run: | - target=$(mktemp -d) - git worktree add "$target" "$(git rev-parse HEAD^1)" - echo "target=$target" >> "$GITHUB_ENV" + git -C untrusted worktree add ../trusted ${{ steps.get-merge-commit.outputs.targetSha }} - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 @@ -49,7 +48,7 @@ jobs: # Update the pinned version using ci/nixpkgs-vet/update-pinned-tool.sh run: | # The pinned version of the tooling to use. - toolVersion=$( Date: Sat, 24 May 2025 15:01:44 +0200 Subject: [PATCH 4/5] workflows/nixpkgs-vet: use nixpkgs-vet from pinned nixpkgs We have added nixpkgs-vet as a regular package to nixpkgs a while ago, so we can now use it from pinned nixpkgs. This avoids pulling a platform-specific binary version from upstream. This change also allows to run the tool easily locally, the same way as other tools: nix-build ci -A nixpkgs-vet This will do a full check of the repo with the exception of nixpkgs-vet's "ratchet" checks: Those depend on having two branches to compare, but the default is to only look at the head branch. Those ratchet checks will still be run in CI, though. (cherry picked from commit 942c377476675848155e860b9d41d869589b8a47) (cherry picked from commit 8eef7754077b467e2b17d6fdd14387c1d73ac4d3) --- .github/workflows/nixpkgs-vet.yml | 18 ++---------------- ci/default.nix | 1 + ci/nixpkgs-vet.nix | 31 +++++++++++++++++++++++++++++++ ci/nixpkgs-vet.sh | 4 +--- 4 files changed, 35 insertions(+), 19 deletions(-) create mode 100644 ci/nixpkgs-vet.nix diff --git a/.github/workflows/nixpkgs-vet.yml b/.github/workflows/nixpkgs-vet.yml index aefed2b267ce..dffa9b63dd89 100644 --- a/.github/workflows/nixpkgs-vet.yml +++ b/.github/workflows/nixpkgs-vet.yml @@ -19,8 +19,7 @@ permissions: {} jobs: check: name: nixpkgs-vet - # This needs to be x86_64-linux, because we depend on the tooling being pre-built in the GitHub releases. - runs-on: ubuntu-24.04 + runs-on: ubuntu-24.04-arm # This should take 1 minute at most, but let's be generous. The default of 6 hours is definitely too long. timeout-minutes: 10 steps: @@ -44,25 +43,12 @@ jobs: - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - - name: Fetching the pinned tool - # Update the pinned version using ci/nixpkgs-vet/update-pinned-tool.sh - run: | - # The pinned version of the tooling to use. - toolVersion=$( Date: Sat, 24 May 2025 16:13:22 +0200 Subject: [PATCH 5/5] workflows: checkout nixpkgs in get-merge-commit action This makes checking out the nixpkgs repo even more consistent and almost forces us to use the trusted/untrusted path pattern. (cherry picked from commit 0e1c284b1321a3a2cacf96068fdba7b59ed0602b) (cherry picked from commit bfe12571b4da2d2dc28574e9b5a20f47316f631b) --- .github/actions/get-merge-commit/action.yml | 31 ++++++++++++++++++--- .github/workflows/check-format.yml | 8 ++---- .github/workflows/check-shell.yml | 8 ++---- .github/workflows/codeowners-v2.yml | 19 +++---------- .github/workflows/eval-aliases.yml | 9 ++---- .github/workflows/lib-tests.yml | 8 ++---- .github/workflows/manual-nixos-v2.yml | 8 ++---- .github/workflows/manual-nixpkgs-v2.yml | 8 ++---- .github/workflows/nix-parse-v2.yml | 8 ++---- .github/workflows/nixpkgs-vet.yml | 15 ++-------- 10 files changed, 48 insertions(+), 74 deletions(-) diff --git a/.github/actions/get-merge-commit/action.yml b/.github/actions/get-merge-commit/action.yml index 51f8a00286b5..a16d289cc6e0 100644 --- a/.github/actions/get-merge-commit/action.yml +++ b/.github/actions/get-merge-commit/action.yml @@ -1,19 +1,27 @@ name: Get merge commit -description: 'Checks whether the Pull Request is mergeable and returns two commit hashes: The result of a temporary merge of the head branch into the target branch ("merged"), and the parent of that commit on the target branch ("target"). Handles push events and merge conflicts gracefully.' +description: 'Checks whether the Pull Request is mergeable and checks out the repo at up to two commits: The result of a temporary merge of the head branch into the target branch ("merged"), and the parent of that commit on the target branch ("target"). Handles push events and merge conflicts gracefully.' + +inputs: + merged-as-untrusted: + description: "Whether to checkout the merge commit in the ./untrusted folder." + type: boolean + target-as-trusted: + description: "Whether to checkout the target commit in the ./trusted folder." + type: boolean outputs: mergedSha: description: "The merge commit SHA" - value: ${{ steps.merged.outputs.mergedSha }} + value: ${{ steps.commits.outputs.mergedSha }} targetSha: description: "The target commit SHA" - value: ${{ steps.merged.outputs.targetSha }} + value: ${{ steps.commits.outputs.targetSha }} runs: using: composite steps: - - id: merged + - id: commits uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 with: script: | @@ -63,3 +71,18 @@ runs: return } throw new Error("Not retrying anymore. It's likely that GitHub is having internal issues: check https://www.githubstatus.com.") + + # Would be great to do the checkouts in git worktrees of the existing spare checkout instead, + # but Nix is broken with them: + # https://github.com/NixOS/nix/issues/6073 + - if: inputs.merged-as-untrusted && steps.commits.outputs.mergedSha + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: ${{ steps.commits.outputs.mergedSha }} + path: untrusted + + - if: inputs.target-as-trusted && steps.commits.outputs.targetSha + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: ${{ steps.commits.outputs.targetSha }} + path: trusted diff --git a/.github/workflows/check-format.yml b/.github/workflows/check-format.yml index ec83ffcce07c..4216c6bd1c70 100644 --- a/.github/workflows/check-format.yml +++ b/.github/workflows/check-format.yml @@ -16,14 +16,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: diff --git a/.github/workflows/check-shell.yml b/.github/workflows/check-shell.yml index 39fb722ae87a..014b60a492fa 100644 --- a/.github/workflows/check-shell.yml +++ b/.github/workflows/check-shell.yml @@ -33,14 +33,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 diff --git a/.github/workflows/codeowners-v2.yml b/.github/workflows/codeowners-v2.yml index 085abced061c..e858615c0828 100644 --- a/.github/workflows/codeowners-v2.yml +++ b/.github/workflows/codeowners-v2.yml @@ -46,9 +46,11 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge and target commits uses: ./.github/actions/get-merge-commit - id: get-merge-commit + with: + merged-as-untrusted: true + target-as-trusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 @@ -58,14 +60,6 @@ jobs: name: nixpkgs-ci authToken: '${{ secrets.CACHIX_AUTH_TOKEN }}' - # Important: Because we use pull_request_target, this checks out the base branch of the PR, not the PR itself. - # We later build and run code from the base branch with access to secrets, - # so it's important this is not the PRs code. - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ steps.get-merge-commit.outputs.targetSha }} - path: trusted - - name: Build codeowners validator run: nix-build trusted/ci -A codeownersValidator @@ -78,11 +72,6 @@ jobs: permission-administration: read permission-members: read - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted - - name: Validate codeowners if: steps.app-token.outputs.token env: diff --git a/.github/workflows/eval-aliases.yml b/.github/workflows/eval-aliases.yml index dc5bad6572fb..892dfe79907b 100644 --- a/.github/workflows/eval-aliases.yml +++ b/.github/workflows/eval-aliases.yml @@ -16,15 +16,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - name: Check out the PR at the test merge commit - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - name: Install Nix uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 diff --git a/.github/workflows/lib-tests.yml b/.github/workflows/lib-tests.yml index 5e3a7a5cba66..c147d0084123 100644 --- a/.github/workflows/lib-tests.yml +++ b/.github/workflows/lib-tests.yml @@ -19,14 +19,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: diff --git a/.github/workflows/manual-nixos-v2.yml b/.github/workflows/manual-nixos-v2.yml index ce5313c8135f..653a5a92fbfd 100644 --- a/.github/workflows/manual-nixos-v2.yml +++ b/.github/workflows/manual-nixos-v2.yml @@ -35,14 +35,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: diff --git a/.github/workflows/manual-nixpkgs-v2.yml b/.github/workflows/manual-nixpkgs-v2.yml index 5cb63a2c88bd..13949dd3c36e 100644 --- a/.github/workflows/manual-nixpkgs-v2.yml +++ b/.github/workflows/manual-nixpkgs-v2.yml @@ -22,14 +22,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: diff --git a/.github/workflows/nix-parse-v2.yml b/.github/workflows/nix-parse-v2.yml index ecbb9c843389..f75a46957f5a 100644 --- a/.github/workflows/nix-parse-v2.yml +++ b/.github/workflows/nix-parse-v2.yml @@ -17,14 +17,10 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout the merge commit uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - path: untrusted + merged-as-untrusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: diff --git a/.github/workflows/nixpkgs-vet.yml b/.github/workflows/nixpkgs-vet.yml index dffa9b63dd89..e4fd7aa06c92 100644 --- a/.github/workflows/nixpkgs-vet.yml +++ b/.github/workflows/nixpkgs-vet.yml @@ -26,20 +26,11 @@ jobs: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: sparse-checkout: .github/actions - - name: Check if the PR can be merged and get the test merge commit + - name: Check if the PR can be merged and checkout merged and target commits uses: ./.github/actions/get-merge-commit - id: get-merge-commit - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ steps.get-merge-commit.outputs.mergedSha }} - # Fetches the merge commit and its parents - fetch-depth: 2 - path: untrusted - - - name: Checking out target branch - run: | - git -C untrusted worktree add ../trusted ${{ steps.get-merge-commit.outputs.targetSha }} + merged-as-untrusted: true + target-as-trusted: true - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31