fix(ci): resolve the upstream pin to a BSR commit id - #76
Merged
Merged
Conversation
Run 33778594627 failed for all seven proto clients with: Failure: resource with name "authzed/api:3fe8742a11c..." was not found The main path pinned to the api git commit SHA, on the assumption that buf-action labels every commit with its SHA. It does not -- it labels by branch and by tag. Verified against the live registry: recent labels are `main`, `clients-prototype-regen`, `materialize-stats-service`, `v1.53.0`; the SHA-shaped labels that suggested otherwise are historical artifacts, and one of them is not even a git object in this repository. The BSR does know the git commit, but as a commit's source_control_url rather than as a label. So resolve it explicitly, then pin generation to the resulting immutable BSR commit id. That is stronger than the original intent: a commit id cannot move, so all seven clients generate from exactly one revision even if another api merge lands mid-run. Verified against the live registry for every input shape: 3fe8742a11c2... (git SHA, the one that failed) -> 2361586d43254e82... main (branch label) -> 2361586d43254e82... v1.53.0 (version tag) -> 55aa23d533a34fa8... 2361586d4325... (already a commit id) -> 2361586d43254e82... deadbeef... (garbage) -> fails loudly PR titles and branch names keep the human-readable ref; the PR body records both it and the resolved commit, and the reproduce line uses the commit id so a local run reproduces the exact revision. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the failure of the first fully-automatic run (33778594627), where all seven proto clients failed identically:
Cause
The main path pinned to the api git commit SHA, on the assumption that
buf-actionlabels every commit with its SHA. It doesn't — it labels by branch and by tag.Verified against the live registry:
3fe8742…(the merge that triggered this)7144bbf4ecce…50996d88f11f…Recent labels are all branch names —
main,clients-prototype-regen,materialize-stats-service— plus version tags. The SHA-shaped labels that made the original assumption look correct are historical artifacts.The failure was at least loud:
bufexited 1 rather than silently generating from a stalemain, which is what the pinning design was for. Everything else in the chain worked — dispatch, authorize, BUFTAG plumbing, partial-failure handling, Slack, and the job going red.Fix
The BSR does know the git commit — as a commit's
source_control_urlrather than as a label. So resolve it explicitly, then pin generation to the resulting immutable BSR commit id.That's stronger than the original intent. A commit id cannot move, so all seven clients generate from exactly one revision even if another api merge lands mid-run — something a
mainlabel could not guarantee.Verified against the live registry for every input shape the workflow can receive:
PR titles and branch names keep the human-readable ref, so
regen/api-mainstaysregen/api-main. The PR body now records both the original ref and the resolved commit, and the reproduce line uses the commit id so a local run reproduces the exact revision.🤖 Generated with Claude Code