This is an automated email from the ASF dual-hosted git repository.
github-merge-queue[bot] pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/texera.git
The following commit(s) were added to refs/heads/main by this push:
new f9c7b613ef revert: "ci: give GitHub Actions bypass on the
release-branch ruleset" (#8624)
f9c7b613ef is described below
commit f9c7b613ef601e38bf8a2134463a623fa94def9a
Author: Meng Wang <[email protected]>
AuthorDate: Mon Sep 21 20:34:14 2026 +0000
revert: "ci: give GitHub Actions bypass on the release-branch ruleset"
(#8624)
### What changes were proposed in this PR?
Reverts #8379. GitHub will not create the `Merge Queue (release)`
ruleset it adds — asfyaml has rejected it on every push to main since
that PR merged, 38 mails to `commits@` so far, the first 49 seconds
after the merge:
```
Validation failed while creating ruleset 'Merge Queue (release)':
['Actor GitHub Actions integration must be part of the ruleset source or
owner organization']
```
The fail-safe ordering #8379 built held: the apply aborts on that
ruleset, so `Merge Queue` was never shrunk and the release branches were
never left uncovered. But the abort takes the whole `github` feature
with it, so nothing in `.asf.yaml`'s `github:` block has been applied to
this repo since 2026-09-11 — the next label, notification or
collaborator change would merge, do nothing, and say so only on a list
its author does not read.
Two side effects of #8379 go with it. The `push-backports` job's
permissions were narrowed to `actions`, `contents`, `issues` and
`statuses`; commenting on a pull request is scoped by `pull-requests`,
not `issues`, so since 2026-09-11 the step that annotates the original
PR when a backport fails has taken four 403s and given up with a
warning, leaving the step green. The 2026-09-03 failures (#8347, #8343)
did comment and were noticed; #8432, #8494 and #8562 did not. Dropping
the block restores the workflow-level scope, which has `pull-requests:
write`. The push also goes back to `AUTO_MERGE_TOKEN`, and the
`workflow_dispatch` of `Required Checks` that only a `GITHUB_TOKEN` push
needed goes with it.
This does not revive the backport fast path — that push stays rejected,
as it has been since 2026-07-24. Routing a clean backport through a pull
request instead is #8378's job, and #8377 stays open until it lands.
### Any related issues, documentation, discussions?
Relates to #8377 (closed by #8379, not actually fixed) and #8379.
### How was this PR tested?
`git revert` applies cleanly to main, and the resulting `.asf.yaml` is
byte-identical to the commit before #8379 — the file was not touched in
between — so applying it asks asfyaml for exactly the configuration `GET
/repos/apache/texera/rulesets` already returns.
`.github/scripts/test_asf_rulesets.sh` is removed with the rest of
#8379. Its duplicate-key-strict parse of `.asf.yaml` and every workflow
is worth keeping and comes back on its own, without the ruleset
assertions that no longer have a subject.
### Was this PR authored or co-authored using generative AI tooling?
Yes. Generated-by: Claude Code (claude-opus-5)
---
.asf.yaml | 60 +-------------
.github/scripts/test_asf_rulesets.sh | 122 -----------------------------
.github/workflows/direct-backport-push.yml | 36 ++-------
.github/workflows/required-checks.yml | 2 -
amber/dev-requirements.txt | 1 -
5 files changed, 7 insertions(+), 214 deletions(-)
diff --git a/.asf.yaml b/.asf.yaml
index 7e4f86a375..42316db44a 100644
--- a/.asf.yaml
+++ b/.asf.yaml
@@ -69,76 +69,20 @@ github:
rebase: false
rulesets:
- # Rule-for-rule identical to "Merge Queue" below; split out so the bypass
- # here stays off main. The bypass exempts actions performed as the GitHub
- # Actions app — i.e. any workflow's GITHUB_TOKEN, which is what
- # direct-backport-push.yml's fast path pushes with (#8377). It cannot be
- # scoped to a single workflow. People and PATs still face every rule.
- #
- # Listed BEFORE "Merge Queue" deliberately: asfyaml applies rulesets in
- # file order, so this one is created before that one stops covering the
- # release branches. If GitHub rejects this ruleset, the apply aborts with
- # the old protections fully intact; the failure order never leaves the
- # release branches uncovered.
- - name: "Merge Queue (release)"
+ - name: Merge Queue
target: branch
enforcement: active
conditions:
ref_name:
exclude: []
include:
+ - "~DEFAULT_BRANCH"
# Merge queue rules do NOT support wildcard ref patterns, so
# release branches must be listed explicitly (not release/*).
# Add each release line here as it is cut.
- "refs/heads/release/v1.1"
- "refs/heads/release/v1.2"
- "refs/heads/release/v1.3"
- bypass_actors:
- # The GitHub Actions app.
- - actor_id: 15368
- actor_type: Integration
- bypass_mode: always
- rules:
- - type: deletion
- - type: non_fast_forward
- - type: merge_queue
- parameters:
- merge_method: SQUASH
- max_entries_to_build: 2
- min_entries_to_merge: 2
- max_entries_to_merge: 5
- min_entries_to_merge_wait_minutes: 3
- grouping_strategy: HEADGREEN
- check_response_timeout_minutes: 45
- - type: pull_request
- parameters:
- allowed_merge_methods:
- - squash
- dismiss_stale_reviews_on_push: false
- require_code_owner_review: false
- require_last_push_approval: false
- required_approving_review_count: 1
- required_review_thread_resolution: true
- - type: required_linear_history
- - type: required_status_checks
- parameters:
- strict_required_status_checks_policy: false
- required_status_checks:
- - context: Required Checks
- - context: Check License Headers
- - context: Validate PR title
-
- - name: Merge Queue
- target: branch
- enforcement: active
- conditions:
- ref_name:
- exclude: []
- include:
- # Release branches carry these same rules in "Merge Queue
- # (release)" above — a separate ruleset because its Actions
- # bypass must not extend to main.
- - "~DEFAULT_BRANCH"
rules:
- type: deletion
- type: non_fast_forward
diff --git a/.github/scripts/test_asf_rulesets.sh
b/.github/scripts/test_asf_rulesets.sh
deleted file mode 100755
index 66bd29c3dc..0000000000
--- a/.github/scripts/test_asf_rulesets.sh
+++ /dev/null
@@ -1,122 +0,0 @@
-#!/usr/bin/env bash
-# Licensed to the Apache Software Foundation (ASF) under one
-# or more contributor license agreements. See the NOTICE file
-# distributed with this work for additional information
-# regarding copyright ownership. The ASF licenses this file
-# to you under the Apache License, Version 2.0 (the
-# "License"); you may not use this file except in compliance
-# with the License. You may obtain a copy of the License at
-#
-# http://www.apache.org/licenses/LICENSE-2.0
-#
-# Unless required by applicable law or agreed to in writing,
-# software distributed under the License is distributed on an
-# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
-# KIND, either express or implied. See the License for the
-# specific language governing permissions and limitations
-# under the License.
-
-# Invariants over the CI configuration that a plain YAML parse cannot see.
-#
-# 1. "Merge Queue" and "Merge Queue (release)" in .asf.yaml must carry
-# identical rules: they are one policy split across two rulesets only so
-# the release half can hold an Actions bypass that must not reach main.
-# Nothing else keeps the copies from drifting apart.
-# 2. .asf.yaml and every workflow must parse with a duplicate-key-strict
-# loader. PyYAML silently keeps the last duplicate, but GitHub's loader
-# rejects the file, so a duplicated trigger key passes local checks and
-# then stops the workflow from ever starting.
-
-set -uo pipefail
-
-command -v python3 >/dev/null || { echo "python3 is required to run these
tests" >&2; exit 1; }
-# Runners ship python3 but not necessarily PyYAML (see release_branches.py);
-# CI installs it via amber/dev-requirements.txt.
-python3 -c 'import yaml' 2>/dev/null || { echo "PyYAML is required (pip
install pyyaml)" >&2; exit 1; }
-
-cd "$(git rev-parse --show-toplevel)"
-
-python3 - <<'EOF'
-import glob
-import sys
-
-import yaml
-
-
-class StrictLoader(yaml.SafeLoader):
- pass
-
-
-def no_duplicates(loader, node, deep=False):
- seen = set()
- for key_node, _ in node.value:
- key = loader.construct_object(key_node, deep=deep)
- if key in seen:
- raise yaml.YAMLError(
- f"duplicate key {key!r} at line {key_node.start_mark.line + 1}"
- )
- seen.add(key)
- return yaml.SafeLoader.construct_mapping(loader, node, deep)
-
-
-StrictLoader.add_constructor(
- yaml.resolver.BaseResolver.DEFAULT_MAPPING_TAG, no_duplicates
-)
-
-failures = []
-
-files = sorted(glob.glob(".github/workflows/*.yml")) + [".asf.yaml"]
-for path in files:
- with open(path) as fh:
- try:
- yaml.load(fh, StrictLoader)
- except yaml.YAMLError as exc:
- failures.append(f"{path}: {exc}")
-
-with open(".asf.yaml") as fh:
- ruleset_list = [
- r for r in yaml.safe_load(fh)["github"]["rulesets"] if isinstance(r,
dict)
- ]
-rulesets = {r.get("name"): r for r in ruleset_list}
-main_rs = rulesets.get("Merge Queue")
-release_rs = rulesets.get("Merge Queue (release)")
-if main_rs is None or release_rs is None:
- failures.append(
- ".asf.yaml: expected rulesets named 'Merge Queue' and 'Merge Queue
(release)'"
- )
-elif main_rs["rules"] != release_rs["rules"]:
- failures.append(
- ".asf.yaml: 'Merge Queue' and 'Merge Queue (release)' rules differ -- "
- "these are one policy in two rulesets; change both or neither"
- )
-if main_rs is not None and "bypass_actors" in main_rs:
- failures.append(
- ".asf.yaml: 'Merge Queue' must not carry bypass_actors -- "
- "keeping the bypass off main is what the split exists for"
- )
-ACTIONS_APP = [{"actor_id": 15368, "actor_type": "Integration", "bypass_mode":
"always"}]
-if release_rs is not None and release_rs.get("bypass_actors") != ACTIONS_APP:
- failures.append(
- ".asf.yaml: 'Merge Queue (release)' bypass_actors must be exactly the "
- "GitHub Actions app -- widen this list and the test together,
deliberately"
- )
-names = [r.get("name") for r in ruleset_list]
-if main_rs is not None and release_rs is not None and names.index(
- "Merge Queue (release)"
-) > names.index("Merge Queue"):
- failures.append(
- ".asf.yaml: 'Merge Queue (release)' must be listed before 'Merge
Queue' -- "
- "asfyaml applies rulesets in file order, and creating the release
ruleset "
- "before shrinking the main one is what keeps a rejected run fail-safe"
- )
-
-for failure in failures:
- print(f"FAIL: {failure}")
-if failures:
- sys.exit(1)
-print(
- f"OK: {len(files)} files duplicate-key clean; "
- "Merge Queue rules identical; bypass only on the release ruleset; "
- "release ruleset listed first"
-)
-EOF
diff --git a/.github/workflows/direct-backport-push.yml
b/.github/workflows/direct-backport-push.yml
index 149c608556..b67fcc90fc 100644
--- a/.github/workflows/direct-backport-push.yml
+++ b/.github/workflows/direct-backport-push.yml
@@ -342,15 +342,6 @@ jobs:
needs: discover
if: ${{ needs.discover.outputs.has_push == 'true' }}
runs-on: ubuntu-latest
- permissions:
- # Everything this job's steps call, and nothing more: push the
- # cherry-pick and comment on the commit (contents), dispatch Required
- # Checks (actions), set the per-target commit status (statuses),
- # annotate the original PR (issues).
- actions: write
- contents: write
- issues: write
- statuses: write
name: "backport #${{ matrix.pr_number }} to ${{ matrix.target }}"
strategy:
fail-fast: false
@@ -365,12 +356,11 @@ jobs:
uses: actions/checkout@v7
with:
fetch-depth: 0
- # Push with the default GITHUB_TOKEN: the release rulesets admit the
- # GitHub Actions app as a bypass actor, while a PAT-authored push is
- # evaluated as that person and rejected. A GITHUB_TOKEN push starts
- # no downstream workflows, so the step after the cherry-pick
- # dispatches Required Checks itself — workflow_dispatch runs are the
- # documented exception that GITHUB_TOKEN may create.
+ # Use AUTO_MERGE_TOKEN (fine-grained PAT) so the push to the release
+ # branch retriggers workflows on that branch. GITHUB_TOKEN-authored
+ # pushes are excluded from triggering downstream workflows, which
+ # silences post-merge CI on backport commits.
+ token: ${{ secrets.AUTO_MERGE_TOKEN || secrets.GITHUB_TOKEN }}
- name: Cherry-pick merge commit onto target branch
id: cherry_pick
env:
@@ -581,22 +571,6 @@ jobs:
log "new_sha=${new_sha}"
echo "new_sha=${new_sha}" >> "$GITHUB_OUTPUT"
- - name: Run Required Checks on the pushed release branch
- if: success()
- env:
- GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- TARGET_BRANCH: ${{ matrix.target }}
- run: |
- # The GITHUB_TOKEN push above starts no push-triggered workflows;
- # dispatch the run the release branch would otherwise have gotten.
- # Best-effort: the backport itself has landed, so a dispatch
- # failure must not demote this job to failed -- the failure
- # reporter below would then claim a landed backport was lost.
- if ! gh workflow run required-checks.yml \
- --repo "${GITHUB_REPOSITORY}" --ref "${TARGET_BRANCH}"; then
- echo "::warning::Could not start Required Checks on
${TARGET_BRANCH}; start it manually from the Actions tab."
- fi
-
- name: Annotate original PR and commit on success
if: success()
uses: actions/github-script@v9
diff --git a/.github/workflows/required-checks.yml
b/.github/workflows/required-checks.yml
index 42b31d37fd..1db8a52668 100644
--- a/.github/workflows/required-checks.yml
+++ b/.github/workflows/required-checks.yml
@@ -30,8 +30,6 @@ on:
- labeled
- unlabeled
merge_group:
- # Also dispatched by direct-backport-push.yml after its GITHUB_TOKEN push
- # to a release branch, which starts no push-triggered runs.
workflow_dispatch:
permissions:
diff --git a/amber/dev-requirements.txt b/amber/dev-requirements.txt
index 593c70d130..848104e776 100644
--- a/amber/dev-requirements.txt
+++ b/amber/dev-requirements.txt
@@ -42,5 +42,4 @@ textual==8.2.8
# Reads bin/k8s/values.yaml in bin/k8s/tests/test_helm_values.sh. That check
fails
# rather than skipping when this is missing, so the suite cannot go green by
accident.
-# Also read by .github/scripts/test_asf_rulesets.sh (infra job shell tests).
PyYAML==6.0.2