Commit Graph
103 Commits
Author SHA1 Message Date
Jon Ross-Perkins 0405fff68c Update to checkout v4 (#3759)
Noticed due to
https://github.com/carbon-language/carbon-lang/actions/runs/8207272518

```
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
```

I'm expecting we can just update the version number on these.
2024-03-08 20:25:04 +00:00
Jon Ross-Perkins 1d2b7db482 Switch reviewdog to a bespoke secret. (#3757)
This uses a token from the low-privilege CarbonInfraBot, which should
allow us to separate out permission for Google's CLA bot.
2024-03-08 16:41:36 +00:00
Richard Smith 56d70dc3a2 Provide a git checkout for reviewdog. (#3754)
It shouldn't actually need or use this, but it fails if there's no
`.git` directory at all.
2024-03-08 00:18:29 +00:00
Richard Smith b0dc6d2996 Pass the event path to reviewdog, not to cat. (#3753)
Should hopefully cause suggestions to be successfully created.
2024-03-07 23:28:06 +00:00
Richard Smith 2424ea16ea Use reviewdog rather than suggestion-bot to create suggestions. (#3752) 2024-03-07 22:57:18 +00:00
Richard Smith 43bfbbe6d5 Explicitly pass in github token to download action. (#3751) 2024-03-07 22:00:24 +00:00
Richard Smith 648f0ccd78 Unify pre-commit actions and attempt to fix suggestion-bot (#3750) 2024-03-07 21:44:49 +00:00
Richard Smith 61ea4f8344 Use suggestion-bot to convert pre-commit errors in PRs with fixes into code review suggestions. (#3746)
This can't be done directly from a `pull_request` action, because that's
run without write privileges. This is done for security reasons, because
it runs in the context of the pull request branch. So instead, we
perform this in two steps:

- The `pull_request` action runs `pre-commit` and uploads an artifact
containing the diffs and the event information (which is only used to
extract the pull request number).
- A separate `workflow_run` action is triggered when the `pre-commit`
action finishes. This action is privileged, and should be able to
download the artifact and create corresponding suggestions.

Unfortunately, due to the permissions model in play here, the second
half of this appears to only be testable live in production.

For now, we're splitting the pre-commit action into two actions -- one
to run on PRs and one to run when actually merging commits -- so that
the suggestions are only triggered in the former case. It might be
possible to recombine these using data in the `workflow_run` invocation
to tell them apart, but the documentation here isn't very good so I've
made this PR dump out that event information so that we can look at it
and see if it contains the relevant information.
2024-03-07 20:54:17 +00:00
Chandler Carruth 524902b540 Switch our main macOS actions to Arm. (#3677)
GitHub has publicly available Arm macOS runners now:
https://github.blog/changelog/2024-01-30-github-actions-introducing-the-new-m1-macos-runner-available-to-open-source/

These runners are used when the OS label is `macos-14` instead of
`macos-12`.

This PR switches the main PR and merge queue macOS runs to that OS. It
adds a push-only `macos-12` run to check post-merge whether Intel macOS
keeps working as we don't want that to break too badly. Given how much
faster the M1 is, it didn't seem worth it to keep this in the critical
path of development. And the Intel path here is more likely than others
to diminish in importance over time.

All our OS predicates in the action encoded a specific OS version which
no longer works given two macOS versions, so I've switch all the OS
predicates to a generic pattern that doesn't encode a version.

Example run on a PR:
https://github.com/carbon-language/carbon-lang/actions/runs/7766629200?pr=3686
Example run on push:
https://github.com/carbon-language/carbon-lang/actions/runs/7766480822
2024-02-06 00:19:03 +00:00
Chandler Carruthandjosh11b da7533ae7f Update project to require Clang 16 or newer. (#3649)
This should also unblock our switch to C++20 and other improvements.

There are three core parts of the change --

1) Updating our infrastructure to fetch and find Clang-16.
2) Updating our documentation to reflect this and help folks with any
   system issues they encounter.

The infrastructure change is unfortunately tricky. We can't get Clang 16
easily on GitHub's runner images, and in the past we've had persistent
problems with flakiness when our actions download this much during their
runs. Due to the flakiness, we've previously removed all downloading of
dependencies outside of Bazel itself, and added retry loops around Bazel
specifically to overcome flaky downloads.

This change tries to address these problems by populating the Clang and
LLVM toolchain in a place that we can then cache using the built-in
GitHub action caching infrastructure. This seems like by far the least
likely to flake way of downloading extra things into our runs. And since
these are relatively slow moving dependencies, we should populate this
cache very, very rarely.

For Linux, this downloads the binary release artifact from GitHub,
prunes out large parts of it that we don't need, and then caches this as
a local toolchain. This proves both small and fast.

For macOS, this uses a trick to cache the destination of Homebrew
installs. It unfortunately caches the *entire* Homebrew installation
though, and so it also goes to some lengths to prune and minimize how
much is installed from Homebrew. The result is "only" a 2gb cache image.
Because of the size and slower download and filesystem, the macOS runs
see a 1 - 2 minute slowdown.

We might extend the Linux infrastructure here usefully if we want to
test multiple LLVM versions. We might also extend the macOS version to
get a cheaper way to prune parts of the system and free up disk space,
or to cache other Homebrew installed tools if needed.

Last but not least, this brought to the forefront an issue with our C++
toolchain integration which relied on a specific CMake build option
being set in the LLVM toolchain install. This option isn't used in the
official release artifacts. Instead, switch to a more robust approach to
linking libc++abi statically that shouldn't have these problems.

Beyond the infrastructure changes, this also updates the documentation
to reflect requiring Clang 16 or newer, and adds some extra tips for
folks that are missing this.

The documentation is also updated to address a problem with getting the
right libc++abi files installed to support the more robust linking
strategy. This may reduce the problems we've seen in the past around
libc++abi and linking on other Linux distros as well.

---------

Co-authored-by: josh11b <josh11b@users.noreply.github.com>
2024-01-25 01:23:09 +00:00
Jon Ross-Perkins 848d4d7ec0 Add geoffromer and josh11b as toolchain reviewers (#3584) 2024-01-10 01:12:36 +00:00
Jon Ross-Perkins facf6eea04 Check clang-tidy in tests.yaml (#3567)
Example success:
https://github.com/carbon-language/carbon-lang/actions/runs/7414437667/job/20175507192
Example failure:
https://github.com/carbon-language/carbon-lang/actions/runs/7414486486/job/20175656728
2024-01-04 21:45:53 +00:00
Jon Ross-Perkins 3fea3dd401 Verify bazel mod deps (#3517)
Query `bazel mod deps` with `--lockfile_mode=error` to detect
out-of-sync lockfiles; print the output to support cross-platform
updates.

Add a workaround for target-determinator problems to prevent them from
blocking changes (e.g.,
https://github.com/carbon-language/carbon-lang/actions/runs/7225229412/job/19694000744?pr=3514)

Example verify failure to merge into end result:

https://github.com/carbon-language/carbon-lang/actions/runs/7227335045/job/19694765560?pr=3517

Success after updates:

https://github.com/carbon-language/carbon-lang/actions/runs/7227387163/job/19694933047
2023-12-18 17:12:40 +00:00
Jon Ross-Perkins 226b653e11 Fix tests.yaml to execute tests when there's a mix of code and ignored files. (#3472)
Fix an error in tests.yaml where tests wouldn't be run if *any* file was
ignored. Instead, only skip tests if *all* files are ignored.

Example run:
https://github.com/carbon-language/carbon-lang/actions/runs/7132705321/job/19423815707
2023-12-07 19:16:49 +00:00
Chandler Carruthandjosh11b 49d46bd8a4 Add up to 10 retries to our test action. (#3401)
This captures the exit code of Bazel and checks for success or permanent
errors on each attempt. It also sleeps a small amount between attempts.
We should be able to increase the retries and sleeps as needed to
minimize flakiness here, and Bazel should even persist incremental
progress efficiently. Hopefully this helps reduce the failure rate of
our CI.

It also changes how we build on a `push` to use a single Bazel clause to
hold this logic.

Managed to get one of the download failures when testing this, and the
retry logic worked but there was a bug in the success logic.

Otherwise seems to work:
- Synthetic failure:
https://github.com/carbon-language/carbon-lang/actions/runs/6872431707/job/18690894069
- Success:
https://github.com/carbon-language/carbon-lang/actions/runs/6872461061

---------

Co-authored-by: josh11b <josh11b@users.noreply.github.com>
2023-11-15 15:34:50 +00:00
Jon Ross-Perkins fc1d71d382 Split build keys so that a read-write key is only used for merged PRs, and read-only is used otherwise. (#3364)
The final test commit has an example of the push run:

https://github.com/carbon-language/carbon-lang/actions/runs/6748256043/job/18346225812

But pull request runs require merging to trunk, AFAIK. Unfortunately
that means the remote upload disabling isn't really tested in full.
2023-11-06 16:03:58 +00:00
Jon Ross-Perkins f2b3a319af Fix use of backtick in shell code. (#3241)
The way this is written, it's executed, not a comment.

`/home/runner/work/_temp/1007824c-f2f7-49dd-ab5f-f5f5364a1864.sh: line
1: --local_*_resources: command not found`

https://github.com/carbon-language/carbon-lang/actions/runs/6203167016/job/16843338592
2023-09-15 22:18:06 +00:00
josh11b f8fd8648ec Reduce bazel job limit to try to avoid IOExceptions (#3240)
Issue reported in [#infra on
Discord](https://discord.com/channels/655572317891461132/707150492370862090/1152031995740827718).
2023-09-15 21:20:06 +00:00
Richard Smith 6245ba82a3 Reduce job count to try to reduce the incidence rate of network errors (#3227)
Also remove duplicated configuration.
2023-09-13 20:53:02 +00:00
Jon Ross-Perkins 2800fc86c9 Stop looking for llvm-15 due to config issues. (#3225)
We're seeing issues building on the 20230911.1.0 release. I think there
may be a misconfiguration; using `/usr/lib/llvm-15/bin/clang++`, I'm
getting errors such as:

```
external/com_google_absl/absl/base/config.h:56:10: fatal error: 'cstddef' file not found
#include <cstddef>
         ^~~~~~~~~
```

e.g.:
https://github.com/carbon-language/carbon-lang/actions/runs/6166275499/job/16735504697
(the passing ubuntu run is on a 20230903.1.0 image using llvm-14)

(note if this PR fails testing, it needs to be merged before it would
take effect)

Reported on https://github.com/actions/runner-images/issues/8253
2023-09-13 15:54:06 +00:00
2751f02258 Introduce git-based target selection. (#3106)
This adds access to the `target-determinator` tool that computes the
possibly impacted set of targets between the current checkout and a
specific `git` commit. The tool is downloaded (and cached) with a Python
script that wraps it and allows us to easily run it in our CI
environment.

And finally, switches the CI for pull requests and the merge queue to
use this script and run a minimal set of impacted tests rather than all
of them. In order to make this as simple as possible, this also merges
the previously separate build and test steps of our CI.

Note that the CI testing post-submit (push events) continues to use a
blanket target pattern so that we have a good backstop in case something
outside of what is tracked here changes. The important paths, especially
the ones that might be in an interactive critical path, are the PR and
merge queue.

This has been tested on the `action-test` branch to try to make sure it
works. Some example runs for folks to inspect:

- `push` event with blanket test:
https://github.com/carbon-language/carbon-lang/actions/runs/6070060958/job/16465422569
- A "large" PR that impacts a bunch of toolchain tests:
- ubuntu-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070063050/job/16465428107?pr=3188
- macos-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070063050/job/16465428420?pr=3188
- The merge queue for this PR:
- ubuntu-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070202665/job/16465825387
- macos-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070202665/job/16465825740
- A "small" PR that impacts one test:
- ubuntu-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070659668/job/16467147641?pr=3189
- macos-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070659668/job/16467147933?pr=3189
- The merge queue for the small PR:
- ubuntu-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070754584/job/16467427268
- macos-opt:
https://github.com/carbon-language/carbon-lang/actions/runs/6070754584/job/16467427736

I have observed one failure while testing with this PR, but I've not yet
been able to reproduce it. Every other failure (including empty lists,
etc.) I've tried to address. However, we may have to keep an eye on
actions after this to make sure there isn't some scenario I've not been
able to work through in a test branch.

---------

Co-authored-by: Jon Ross-Perkins <jperkins@google.com>
Co-authored-by: Geoff Romer <gromer@google.com>
2023-09-08 00:18:50 +00:00
Chandler Carruth cce013b43e Use high concurrency on CI build & test. (#3192)
The expensive local actions will be separately gated to not overwhelm
the machine, and currently highly asynchronous actions are a dominant
part of our builds due to downloading cached artifacts. Without a high
concurrency, these are downloaded roughly 2-at-a-time currently.

I've verified that on a small machine without a good cache this doesn't
seem to generate huge amounts of work and local build and test actions
are successfully gated on the local flags.

There is already a Bazel issue tracking this limitation:
https://github.com/bazelbuild/bazel/issues/6394
2023-09-05 20:06:41 +00:00
Geoff Romer f4d45c8d88 Fix newline formatting in stale-issue message (#3045)
YAML string literals don't seem to support escape sequences like `\n`,
so `\n\n\n` was showing up literally in the issue messages.
2023-08-01 19:33:00 +00:00
Jon Ross-Perkins 9c4188ab9f Free disk space because we seem to be encroaching on limits. (#3009)
At present, it looks like tools consume 3GB and fastbuild consumes 20GB
versus 23GB available. We've apparently been on the edge of this, and
are just now getting pushed over.


https://github.com/carbon-language/carbon-lang/actions/runs/5625169220/job/15243450729
shows what this looks like (review actions are run from trunk versions,
not this branch).
2023-07-21 23:17:07 +00:00
Jon Ross-Perkins f4fd12def9 Use paths-filter to fix the test action. (#2972)
Trying to fix merge queue support for PRs that don't need tests, #2971
didn't work because it lacks the matrix configuration. This takes a
different approach from that, instead filtering each step based on
affected paths. This way we're also less likely to see skew in behavior.
2023-07-06 18:08:45 +00:00
Chandler Carruth c75b41bb01 Add a fallback test workflow. (#2971)
To make this cleaner, this switches the main `test` workflow to use
exclusion path patterns as that was the clearly documented intent
anyways.

This works around a problem with required GitHub status checks:
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#onpushpull_requestpull_request_targetpathspaths-ignore

Without something like this, we won't be able to use the merge queue (or
require passing tests).
2023-07-06 15:43:42 +00:00
Adrien Leravat f091a45c19 Infra: run pre-commit on merge groups (#2960) 2023-06-28 17:21:54 -07:00
Jon Ross-Perkins 594ebff23b Copy-paste paths since the action isn't running. (#2954) 2023-06-27 15:48:50 -07:00
Adrien Leravat 92d73985df CI: tentative enabling of tests workflow for merge group (#2933) 2023-06-24 12:08:50 -07:00
Jon Ross-Perkins 8aca184cdb Remove dependent issues trigger (#2815)
Essentially, on #2814 I noticed that saying `#2811 depends` [word break] `on #2813` led to this trigger activating. This led to me asking whether anyone uses it, and responses were okay with it being removed. It's had [limited use](https://github.com/carbon-language/carbon-lang/pulls?q=is%3Apr+%22By+Dependent+Issues%22+), so this shouldn't be expected to affect workflows (unfortunately partly because dependent PRs aren't handled well by GitHub's review interface).

Discussed [on Discord](https://discord.com/channels/655572317891461132/707150492370862090/1103721071221407835).

Also minor edit to replace `-` with `_` in pre-commit filename ([style](https://github.com/carbon-language/carbon-lang/blob/trunk/docs/project/cpp_style_guide.md#file-names)).
2023-05-15 13:58:20 -07:00
Jon Ross-Perkins b22e585285 Bump action versions. (#2591)
I was looking at this due to some warnings about node 12 deprecation. This resolves some of it, where updates are available. We'll probably need to keep half an eye on this for https://github.com/hkusu/review-assign-action/issues/20 and https://github.com/z0al/dependent-issues/issues/535, which haven't been addressed yet.

AFAICT no config versions are needed for these version bumps.
2023-02-11 11:00:30 -08:00
Jon Ross-Perkins 69117bc9c3 Exempt leads questions from inactive labeling. (#2589)
@chandlerc requested that leads questions not be marked inactive. These arise when there *isn't* a clear-cut answer, and so seem to make more sense to be effectively long-term.

The \n\n\n is trying to get a blank line between paragraphs. Right now it gets a newline, but the paragraphs sort of blend. I might need more \n's, don't know but I'll keep an eye on messages. The examples that I could find don't have multiple paragraphs.
2023-02-10 11:53:50 -08:00
Jon Ross-Perkins 2e6bf0dea6 Support using llvm-15 if GH images provide it (#2543)
A migration by GH that drops LLVM 14 is breaking builds. It seems to still be getting canaried, so this is showing as flaky behavior. I think it's https://github.com/actions/runner-images/pull/6871

The set of runs at https://github.com/carbon-language/carbon-lang/actions/runs/3970825811/jobs/6807006626 show the fix behavior.
2023-01-20 12:07:40 -08:00
Jon Ross-Perkins 09ac000305 Add some ls commands to help diagnose tool issues (#2540)
We're seeing some test runs where `clang` isn't in the path on macos. I suspect it's a bad image, and can't reproduce it, but want to add these commands to help provide debug info for potential future problems.

e.g., the `ls` output: https://github.com/carbon-language/carbon-lang/actions/runs/3963366092/jobs/6791110228

e.g., the bad image: https://github.com/carbon-language/carbon-lang/actions/runs/3963270727/jobs/6790912681
2023-01-19 18:24:13 -08:00
Chandler Carruth 2c198865ff Mark some other issue categories as not-stale. (#2496)
While we have a generic 'long term' label, it seems redundant for some
issues that are already labeled with something that clearly is
open-ended and not something we should expect to have a bounded
timeline. For example, we want to actively curate a backlog of design
ideas and good first issues for folks to browse and pick up, so we
shouldn't be marking them as inactive after any fixed time frame.
2022-12-22 19:17:51 -08:00
Jon Ross-Perkins cc9ea4da66 Add auto-labeling for some docs and infra. (#2481) 2022-12-20 11:17:45 -08:00
Jon Ross-Perkins 8dc12df71d Automate labeling of explorer and toolchain PRs (#2470)
Pixep has been doing this by hand, so offering up some automation.

This is derivative of other workflows for [path-filter](https://github.com/carbon-language/carbon-lang/blob/trunk/.github/workflows/assign_prs.yaml) and [using gh for labels](https://github.com/carbon-language/carbon-lang/blob/trunk/.github/workflows/proposal_labeled.yaml). It felt best to stick it in its own workflow rather than merging with assign_prs.yaml, just to make the boundary clearer (I believe the separate workflow is cheap).
2022-12-14 14:27:30 -08:00
Jon Ross-Perkins e45ab50e5b Switch testing to pre-installed versions of clang-14 (#2402)
We keep seeing fragility installing software, with both brew (e.g., the recent python issues) and apt.llvm.org (currently flaky).

At this point, images for both ubuntu and macos have versions of llvm-14 that seem to successfully compile:
https://github.com/carbon-language/carbon-lang/actions/runs/3474670746/jobs/5808098087

Although we may want to figure out a way to resume running llvm-15 so that we can see compatibility issues, this seems preferable for baseline testing in order to reduce maintenance churn.

In addition to the above changes, this also configures cancellation more precisely, and stops installing bazel/bazelisk (it should already be preinstalled).
2022-11-17 08:54:44 -08:00
Jon Ross-Perkins 3b4bb985fb Explicitly install python with --overwrite (#2393)
```
==> Pouring python@3.11--3.11.0.monterey.bottle.tar.gz
Error: The brew link step did not complete successfully
The formula built, but is not symlinked into /usr/local
Could not symlink bin/2to3-3.11
Target /usr/local/bin/2to3-3.11
already exists. You may want to remove it:
  rm '/usr/local/bin/2to3-3.11'
```

Installing llvm with --overwrite didn't seem to pass it on dependencies, particularly python (https://github.com/carbon-language/carbon-lang/actions/runs/3464174572/jobs/5785378508). So this instead installs python separately, and then --overwrite works.

See https://github.com/carbon-language/carbon-lang/actions/runs/3464364789/jobs/5785802783 for the example passing run. The actions on this PR will probably still use the trunk version.
2022-11-14 14:33:03 -08:00
Jon Ross-Perkins 418b28d12b Fix filter step reference (#2273)
* Fix filter step reference

* pipe
2022-10-12 17:45:33 -07:00
Jon Ross-Perkins 9be6939ee9 Fix LLVM compilation issues (#2198)
We've been having issues with asan builds on linux. This change should fix all of that. A build run can be found at:
https://github.com/carbon-language/carbon-lang/actions/runs/3093378863/jobs/5005683059

(currently in progress, but I'm expecting it to succeed at this point)

It may be that the issues with asan builds were actually related to caching. That is, maybe the brew build command didn't change enough between v14 and v15 that the cache hits were still an issue. We did notice this with 15.0.0 versus 15.0.1 include paths (that is, bazel wasn't happy using the cached results of a 15.0.0 build due to the skew in include paths). In order to address this, I've added CACHE_VERSION to the remote_cache setup. I've also set up corresponding buckets in Cloud.

However, I'm also switching Linux to llvm-15 and apt. I'd originally been looking at this because the issues were linux-specific, and we've previously had linux-specific issues with Homebrew. Although it may have been the cache all along, I would prefer to keep this setup (if nothing else, it made the caching issues more obvious, even though we were still confused by the include path manifestation).
2022-09-20 14:21:02 -07:00
Jon Ross-Perkins 7e4e73b6c0 Specify llvm@14 (#2195)
This should be temporary while trying to diagnose why llvm@15 fails.
2022-09-19 16:20:54 -07:00
Jon Ross-Perkins 0c20fbb0e6 Switch to llvm apt for ubuntu (#2160)
We've been encountering issues installing llvm via brew on linux, e.g.:
https://github.com/carbon-language/carbon-lang/runs/8258419618?check_suite_focus=true

```
==> Reinstalling 2 dependents with broken linkage from source:
llvm, mpdecimal
```

(but then llvm doesn't get reinstalled)

This should resolve it:
https://github.com/carbon-language/carbon-lang/runs/8260573590?check_suite_focus=true
2022-09-08 16:41:33 -07:00
Jon Ross-Perkins 6a9326f9e7 Set HOMEBREW_NO_INSTALL_CLEANUP due to llvm reinstall errors (#2157)
Trying to address issues like:
https://github.com/carbon-language/carbon-lang/runs/8252863868?check_suite_focus=true

```
==> Reinstalling 2 dependents with broken linkage from source:
llvm, mpdecimal
```

But llvm doesn't get reinstalled (but we also probably don't need/want this, particularly building from source).
2022-09-08 09:28:00 -07:00
Jon Ross-Perkins 2bc6da2967 Try a different autoassign action (#2093)
This removes the separate data files, which have been failing to load properly ([example](https://github.com/carbon-language/carbon-lang/runs/7957047892?check_suite_focus=true)). This one wasn't working previously, but hopefully will with these changes (and it might've also just been a pull_request_target issue, but the silent "Resource not accessible by integration" failures aren't great).
2022-08-23 12:13:19 -07:00
Jon Ross-Perkins ed3a81aa08 Add action for wiki change notifications. (#2089)
Wiki can either be "require push access" or "everyone" -- apparently there's no other option. I've set it to "everyone" so that contributors can make edits without needing push access. So the options as I see it are:

- Leave wiki as "everyone" can edit, use this for notifications.
    - GitHub doesn't give notifications for wiki edits. This is trying a different approach for notifications.
- Grant push access to a larger group (contributors), don't add CODEOWNERS.
    - Not sure this is the right choice because of the implications around merges, but again maybe it'd be fine and we can expect the approval requirement to work out.
- Grant push access to contributors, add CODEOWNERS.
    - This causes the auto-assignment to CODEOWNERS that we don't want. (details in https://github.com/carbon-language/carbon-lang/pull/1367)
- Create a separate wiki repo so that we can differently handle push access.
    - This seems overly complex a solution though.

I'm hoping this approach works.
2022-08-23 12:11:58 -07:00
Jon Ross-Perkins 21311334cb Switch to pull_request_target (#2014)
https://securitylab.github.com/research/github-actions-preventing-pwn-requests/#:~:text=The%20main%20differences%20between%20the,but%20not%20from%20external%20forks.

I'm hoping I actually have the cause of my issues right this time.
2022-08-12 11:57:25 -07:00
Jon Ross-Perkins efde2dcdd9 Switch token approach (#2013)
According to this run, the attempt to get write permissions failed:
https://github.com/carbon-language/carbon-lang/runs/7811743119?check_suite_focus=true

So I'm switching to an org secret, which I believe I can definitely make work.
2022-08-12 11:42:51 -07:00
Jon Ross-Perkins 767e712b47 Try adjusting permissions to label (#2012)
Context: https://github.com/carbon-language/carbon-lang/runs/7811528469?check_suite_focus=true

Permissions seem to be different from when I was testing, seeing if this is enough.
2022-08-12 11:27:09 -07:00
Jon Ross-Perkins 9b3f80c6d6 Switch proposal process from projects to labels (#1981)
This is being done because Projects v1 requires repo write access, a serious limitation for letting people use it. Projects v2 isn't a great option because it lacks event support. Labels are pretty stable in GitHub, so this switches to that.

Note this assumes we're fine renaming "decision: accepted" -> "proposal accepted", etc. There are two reasons for this:

1) To make it clear that this is a proposal-specific label, versus something like an issue for leads label.
2) Removing the colon because it was causing trouble with yaml syntax.

This also adds the "proposal draft" label, mainly to complete the taxonomy.

I was considering whether this should be a proposal itself, but it feels like maybe it's not necessary because it's a fairly low-key infrastructure change, and I'm not sure how much people were relying on the project board anyways.

I tested this in a personal repo, basically just poking at https://github.com/jonmeow/test/pull/2
2022-08-12 11:11:09 -07:00