Skip to content

Commit ca8d602

Browse files
committed
refactor(ci): reuse protobuf compatibility action
Signed-off-by: Simon Scatton <sscatton@nvidia.com>
1 parent 79961df commit ca8d602

5 files changed

Lines changed: 57 additions & 29 deletions

File tree

‎.agents/skills/watch-github-actions/SKILL.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -132,10 +132,11 @@ not substitute the current `main` tip or the event's older PR base SHA. Merge
132132
groups and manual runs use their explicit baseline. Findings are reported by
133133
`Reject new high or critical findings`; distinguish those from scanner failures.
134134

135-
For `Protobuf API compatibility`, check the logged train and comparison baseline.
135+
For `Protobuf Compatibility`, check the logged train and comparison baseline.
136136
Branch Checks compares the prospective merge tree with its target; Release Tag
137137
compares the tagged candidate with the previous stable release. Both use
138-
`nix develop .#proto`. During `0.x`, a minor train permits compatibility findings
138+
the shared `check-protobuf-compatibility` action with `nix develop .#proto`.
139+
During `0.x`, a minor train permits compatibility findings
139140
as warnings; a patch train or no active train rejects them. Compare the current
140141
train's version with the latest stable release; commit messages are irrelevant.
141142
Compilation, baseline, and tool errors remain fatal. The `protobuf_compatibility` suite participates in
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
2+
# SPDX-License-Identifier: Apache-2.0
3+
4+
name: Check Protobuf Compatibility
5+
description: Check protobuf compatibility against the target or latest stable release using the release train policy. Requires a checkout with full history and tags.
6+
7+
inputs:
8+
target-ref:
9+
description: PR or merge-group target commit/ref. Supply either target-ref or release-tag.
10+
required: false
11+
default: ""
12+
release-tag:
13+
description: Prerelease or stable tag to qualify. Supply either target-ref or release-tag.
14+
required: false
15+
default: ""
16+
17+
runs:
18+
using: composite
19+
steps:
20+
- uses: ./.github/actions/setup-nix
21+
22+
- name: Check protobuf compatibility
23+
shell: nix develop .#proto --no-write-lock-file -c bash -euo pipefail {0}
24+
env:
25+
TARGET_REF: ${{ inputs.target-ref }}
26+
RELEASE_TAG: ${{ inputs.release-tag }}
27+
run: |
28+
args=()
29+
if [[ -n "$TARGET_REF" ]]; then
30+
args+=(--target "$TARGET_REF")
31+
fi
32+
if [[ -n "$RELEASE_TAG" ]]; then
33+
args+=(--release "$RELEASE_TAG")
34+
fi
35+
uv run --no-project --python python3 tasks/scripts/check_proto_compatibility.py "${args[@]}"

‎.github/workflows/branch-checks.yml‎

Lines changed: 9 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -37,32 +37,25 @@ jobs:
3737
- id: gate
3838
uses: ./.github/actions/pr-gate
3939

40-
proto-breaking:
41-
name: Protobuf API compatibility
40+
protobuf-compatibility:
41+
name: Protobuf Compatibility
4242
needs: pr_metadata
4343
if: needs.pr_metadata.outputs.should_run == 'true'
4444
runs-on: linux-amd64-cpu8
4545
timeout-minutes: 15
46-
defaults:
47-
run:
48-
shell: nix develop .#proto --no-write-lock-file -c bash -euo pipefail {0}
4946
steps:
5047
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
5148
with:
5249
fetch-depth: 0
5350
persist-credentials: false
5451

55-
- uses: ./.github/actions/setup-nix
56-
57-
- name: Check protobuf API compatibility
58-
env:
59-
TARGET_REF: ${{ github.event.merge_group.base_sha || needs.pr_metadata.outputs.base_sha }}
60-
DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
61-
run: |
62-
if [[ "$GITHUB_EVENT_NAME" == workflow_dispatch ]]; then
63-
TARGET_REF="refs/remotes/origin/$DEFAULT_BRANCH"
64-
fi
65-
uv run --no-project --python python3 tasks/scripts/check_proto_compatibility.py --target "$TARGET_REF"
52+
- uses: ./.github/actions/check-protobuf-compatibility
53+
with:
54+
target-ref: >-
55+
${{ github.event_name == 'workflow_dispatch'
56+
&& format('refs/remotes/origin/{0}', github.event.repository.default_branch)
57+
|| github.event.merge_group.base_sha
58+
|| needs.pr_metadata.outputs.base_sha }}
6659
6760
mise-lockfile:
6861
name: mise Lockfile

‎.github/workflows/release-tag.yml‎

Lines changed: 7 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -214,8 +214,8 @@ jobs:
214214
checkout-ref: ${{ needs.compute-versions.outputs.source_sha }}
215215
conformance-artifact-prefix: openshell-conformance
216216

217-
proto-breaking:
218-
name: Protobuf API compatibility
217+
protobuf-compatibility:
218+
name: Protobuf Compatibility
219219
needs: compute-versions
220220
runs-on: linux-amd64-cpu8
221221
timeout-minutes: 15
@@ -226,18 +226,16 @@ jobs:
226226
persist-credentials: false
227227
ref: ${{ needs.compute-versions.outputs.source_sha }}
228228

229-
- uses: ./.github/actions/setup-nix
230-
231-
- name: Check release protobuf API compatibility
232-
shell: nix develop .#proto --no-write-lock-file -c bash -euo pipefail {0}
233-
run: uv run --no-project --python python3 tasks/scripts/check_proto_compatibility.py --release "$RELEASE_TAG"
229+
- uses: ./.github/actions/check-protobuf-compatibility
230+
with:
231+
release-tag: ${{ env.RELEASE_TAG }}
234232

235233
qualification-result:
236234
name: Release Qualification
237235
if: always()
238236
needs:
239237
- compute-versions
240-
- proto-breaking
238+
- protobuf-compatibility
241239
- security
242240
- conformance-integration
243241
- feature-specific-integration
@@ -263,7 +261,7 @@ jobs:
263261
DOCKER_E2E_RESULT: ${{ needs.docker-e2e.result }}
264262
FEATURE_INTEGRATION_RESULT: ${{ needs.feature-specific-integration.result }}
265263
IS_PRERELEASE: ${{ needs.compute-versions.outputs.is_prerelease }}
266-
PROTO_COMPATIBILITY_RESULT: ${{ needs.proto-breaking.result }}
264+
PROTO_COMPATIBILITY_RESULT: ${{ needs.protobuf-compatibility.result }}
267265
SECURITY_RESULT: ${{ needs.security.result }}
268266
SOURCE_SHA: ${{ needs.compute-versions.outputs.source_sha }}
269267
VM_E2E_RESULT: ${{ needs.vm-e2e.result }}

‎CI.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,8 +19,9 @@ Merge queue validation is a second integration gate for `main`. After a PR has p
1919

2020
### Protobuf API compatibility
2121

22-
`Protobuf API compatibility` runs in Branch Checks and Release Tag through the
23-
lockfile-pinned `proto` Nix shell. It uses Buf's `FILE` policy for the `proto/`
22+
`Protobuf Compatibility` runs in Branch Checks and Release Tag through the shared
23+
`check-protobuf-compatibility` action and lockfile-pinned `proto` Nix shell.
24+
It uses Buf's `FILE` policy for the `proto/`
2425
module, covering SDK descriptors and extension contracts. Storage-only protobufs
2526
remain subject to their separate durability checks.
2627

0 commit comments

Comments
 (0)