This is an automated email from the ASF dual-hosted git repository.

hansva pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/hop.git


The following commit(s) were added to refs/heads/main by this push:
     new 6301a76ecd [CI] harden gib (#8571)
6301a76ecd is described below

commit 6301a76ecd84528f3f44f9b187faea6e13fa02f0
Author: Hans Van Akelyen <[email protected]>
AuthorDate: Thu Sep 24 11:24:37 2026 +0200

    [CI] harden gib (#8571)
---
 .github/workflows/pr_build_code.yml | 17 ++++++++++++-----
 pom.xml                             | 14 ++++++++++----
 2 files changed, 22 insertions(+), 9 deletions(-)

diff --git a/.github/workflows/pr_build_code.yml 
b/.github/workflows/pr_build_code.yml
index 87364992be..26c112f430 100644
--- a/.github/workflows/pr_build_code.yml
+++ b/.github/workflows/pr_build_code.yml
@@ -84,12 +84,15 @@ jobs:
             ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
             ${{ runner.os }}-m2-
             ${{ runner.os }}-
+      # Source checks resolve no dependencies, so they skip GIB's upstream 
modules. Without
+      # this, buildUpstreamMode=impacted would pull in every plugin as an 
upstream of the
+      # assemblies (these steps do not pass -Dassemblies=false).
       - name: RAT Check
-        run: mvn clean apache-rat:check -Dgib.disable=$GIB_DISABLE
+        run: mvn clean apache-rat:check -Dgib.disable=$GIB_DISABLE 
-Dgib.buildUpstream=false
       - name: Checkstyle
-        run: mvn clean checkstyle:check -Dgib.disable=$GIB_DISABLE
+        run: mvn clean checkstyle:check -Dgib.disable=$GIB_DISABLE 
-Dgib.buildUpstream=false
       - name: Spotless check
-        run: mvn spotless:check -Dgib.disable=$GIB_DISABLE
+        run: mvn spotless:check -Dgib.disable=$GIB_DISABLE 
-Dgib.buildUpstream=false
       - name: Build with Maven
         run: MAVEN_OPTS="-XX:+TieredCompilation -XX:TieredStopAtLevel=1"; mvn 
clean install -T 1C -B -C -e -fae -V -Dmaven.compiler.fork=true 
-Dsurefire.rerunFailingTestsCount=2 -Dassemblies=false -Dmodule.zips=false 
-Djacoco.skip=true -Dgib.disable=$GIB_DISABLE --file pom.xml
 
@@ -110,8 +113,12 @@ jobs:
         with:
           java-version: '21'
           distribution: 'temurin'
-      - name: Cache Maven packages
-        uses: actions/cache@v6
+      # Restore only: this job runs `package` and installs nothing, and it 
finishes before
+      # the build job. Saving here took the shared key first, so the build 
job's installed
+      # repository was never cached ("Unable to reserve cache"). Keep path and 
keys in sync
+      # with the build job, or the restore misses.
+      - name: Restore Maven packages
+        uses: actions/cache/restore@v6
         with:
           path: ~/.m2/repository
           key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
diff --git a/pom.xml b/pom.xml
index d8457faf64..2a1f3847e8 100644
--- a/pom.xml
+++ b/pom.xml
@@ -107,6 +107,12 @@
         <commonmark.version>0.30.0</commonmark.version>
         <cyclonedx-maven-plugin.version>2.9.3</cyclonedx-maven-plugin.version>
         <gib.buildUpstream>always</gib.buildUpstream>
+        <!-- Build the upstreams of every impacted module, not only of the 
directly changed
+             ones. With the default (changed), a REST change selects 
hop-tech-opensearch as
+             downstream but not its hop-transform-datagrid dependency, which 
then has to come
+             from ~/.m2. Hop snapshots are not resolved remotely and the CI 
Maven cache does
+             not reliably hold them (#8569, #8558, #8542). Extra upstreams 
skip tests. -->
+        <gib.buildUpstreamMode>impacted</gib.buildUpstreamMode>
         <gib.disable>true</gib.disable>
         <!-- Paths that never affect the Maven build result. GIB maps a 
changed file to the
              nearest enclosing module; files outside every module land on the 
ROOT module,
@@ -119,10 +125,10 @@
         <gib.fetchReferenceBranch>true</gib.fetchReferenceBranch>
         <!-- lib-p2 wrappers are never published (maven.deploy.skip, and they 
are
              excluded from the snapshot wagon deploy). Incremental PR builds 
must
-             still produce them locally: GIB's default 
buildUpstreamMode=changed
-             only rebuilds upstreams of *directly changed* modules, so a hop-ui
-             change selects hop-ui-rcp as downstream and then cannot resolve
-             org.eclipse.tm4e.core:jar:${project.version} from any repository. 
-->
+             still produce them locally, or a hop-ui change selects hop-ui-rcp 
as
+             downstream and then cannot resolve 
org.eclipse.tm4e.core:jar:${project.version}
+             from any repository. buildUpstreamMode=impacted covers this too; 
the
+             forced build keeps it independent of that setting. -->
         
<gib.forceBuildModules>org.eclipse.tm4e.core,org.eclipse.swtbot.swt.finder</gib.forceBuildModules>
         <gib.referenceBranch>refs/remotes/origin/main</gib.referenceBranch>
         <gib.skipTestsForUpstreamModules>true</gib.skipTestsForUpstreamModules>

Reply via email to