diff --git a/.github/workflows/pre_commit.yaml b/.github/workflows/pre_commit.yaml index c0aaf890efb3..1f93a7282b7e 100644 --- a/.github/workflows/pre_commit.yaml +++ b/.github/workflows/pre_commit.yaml @@ -6,6 +6,9 @@ name: pre-commit on: pull_request: + merge_group: + push: + branches: [trunk] jobs: pre-commit: @@ -14,14 +17,21 @@ jobs: - uses: actions/checkout@v3 - uses: actions/setup-python@v4 - uses: pre-commit/action@v3.0.0 + + # We want to automatically create github suggestions for pre-commit file + # changes for a pull request. But `pull_request` actions never have write + # permissions to the repository, so we create the suggestions in a separate + # privileged `workflow_run` action in pre_commit_suggestions.yaml. Here, + # we upload the diffs and event configuration to an artifact for use by + # that action. - name: Collect pre-commit output - if: ${{ failure() }} + if: failure() run: | mkdir -p pre-commit-output git diff > pre-commit-output/diff cp $GITHUB_EVENT_PATH pre-commit-output/event - uses: actions/upload-artifact@v4 - if: ${{ failure() }} + if: failure() with: name: pre-commit output path: pre-commit-output/* diff --git a/.github/workflows/pre_commit_on_merge.yaml b/.github/workflows/pre_commit_on_merge.yaml deleted file mode 100644 index 76102eed58e4..000000000000 --- a/.github/workflows/pre_commit_on_merge.yaml +++ /dev/null @@ -1,21 +0,0 @@ -# Part of the Carbon Language project, under the Apache License v2.0 with LLVM -# Exceptions. See /LICENSE for license information. -# SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception - -# Run pre-commit checks after a commit is merged into trunk. This is like -# pre-commit, but does not trigger adding suggested edits. In principle, this -# should never fail. -name: pre-commit-on-merge - -on: - merge_group: - push: - branches: [trunk] - -jobs: - pre-commit: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v3 - - uses: actions/setup-python@v4 - - uses: pre-commit/action@v3.0.0 diff --git a/.github/workflows/pre_commit_suggestions.yaml b/.github/workflows/pre_commit_suggestions.yaml index 96dbe828ecd2..6e4a915baa9a 100644 --- a/.github/workflows/pre_commit_suggestions.yaml +++ b/.github/workflows/pre_commit_suggestions.yaml @@ -5,6 +5,14 @@ # Create PR suggestions based on problems found by pre-commit action. name: pre-commit-suggestions +# This action is run whenever the `pre-commit` action finishes. Because the +# `pre-commit` action is an unprivileged action running on (for example) the +# `pull_request` event, it's run without write permissions to the repository, so +# we use a separate privileged `workflow_run` action here to pick up its results +# and convert them into suggestion comments. +# +# This action is only run from the workflow file on the trunk branch. Changes to +# this file will not take effect until they are merged to trunk. on: workflow_run: workflows: [pre-commit] @@ -16,42 +24,23 @@ permissions: jobs: pull-request-suggestions: - if: ${{ github.event.workflow_run.conclusion == 'failure' }} + # Only generate suggestions if pre-commit for a PR failed. + if: | + github.event.workflow_run.conclusion == 'failure' && + github.event.workflow_run.event == 'pull_request' runs-on: ubuntu-latest steps: - - name: Print event - run: cat $GITHUB_EVENT_PATH - - name: Download pre-commit output - uses: actions/github-script@v6 + uses: actions/download-artifact@v4 with: - script: | - let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({ - owner: context.repo.owner, - repo: context.repo.repo, - run_id: context.payload.workflow_run.id, - }); - - let matchArtifact = allArtifacts.data.artifacts.filter((artifact) => { - return artifact.name == "pre-commit output" - })[0]; - - let download = await github.rest.actions.downloadArtifact({ - owner: context.repo.owner, - repo: context.repo.repo, - artifact_id: matchArtifact.id, - archive_format: 'zip', - }); - - let fs = require('fs'); - fs.writeFileSync(`${process.env.HOME}/output.zip`, Buffer.from(download.data)); - - - name: Unzip output - run: | - mkdir -p ~/output - unzip -d ~/output ~/output.zip diff event + name: pre-commit output + run-id: ${{ github.event.workflow_run.id }} + # Use https://github.com/tido64/suggestion-bot to create PR suggestions + # matching the diff that pre-commit created. - name: Create suggestions env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: GITHUB_EVENT_PATH=~/output/event npx suggestion-bot ~/output/diff + run: | + GITHUB_EVENT_PATH=./event cat ./diff | \ + npx suggestion-bot -f -m "pre-commit checks made changes to the following files:"