From a8e2ac8ff52f45dceded9df16da0197902898494 Mon Sep 17 00:00:00 2001 From: Joseph Schorr Date: Thu, 3 Sep 2026 12:33:52 -0400 Subject: [PATCH] fix(ci): resolve the upstream pin to a BSR commit id Run 33778594627 failed for all seven proto clients with: Failure: resource with name "authzed/api:3fe8742a11c..." was not found The main path pinned to the api git commit SHA, on the assumption that buf-action labels every commit with its SHA. It does not -- it labels by branch and by tag. Verified against the live registry: recent labels are `main`, `clients-prototype-regen`, `materialize-stats-service`, `v1.53.0`; the SHA-shaped labels that suggested otherwise are historical artifacts, and one of them is not even a git object in this repository. The BSR does know the git commit, but as a commit's source_control_url rather than as a label. So resolve it explicitly, then pin generation to the resulting immutable BSR commit id. That is stronger than the original intent: a commit id cannot move, so all seven clients generate from exactly one revision even if another api merge lands mid-run. Verified against the live registry for every input shape: 3fe8742a11c2... (git SHA, the one that failed) -> 2361586d43254e82... main (branch label) -> 2361586d43254e82... v1.53.0 (version tag) -> 55aa23d533a34fa8... 2361586d4325... (already a commit id) -> 2361586d43254e82... deadbeef... (garbage) -> fails loudly PR titles and branch names keep the human-readable ref; the PR body records both it and the resolved commit, and the reproduce line uses the commit id so a local run reproduces the exact revision. Co-Authored-By: Claude Opus 5 --- .github/workflows/regen-from-api.yaml | 45 +++++++++++++++++++++++++-- 1 file changed, 42 insertions(+), 3 deletions(-) diff --git a/.github/workflows/regen-from-api.yaml b/.github/workflows/regen-from-api.yaml index 1b702613..001ec604 100644 --- a/.github/workflows/regen-from-api.yaml +++ b/.github/workflows/regen-from-api.yaml @@ -151,6 +151,43 @@ jobs: run: sudo apt-get update && sudo apt-get install -y protobuf-compiler - name: Install buf uses: bufbuild/buf-setup-action@a47c93e0b1648d5651a065437926377d060baa99 # v1 + + # The pin arrives as a git SHA (main path), a version tag (release path), + # or a branch name such as `main` (manual). Only the last two are BSR + # *labels*: buf-action labels by branch and by tag, NOT by git commit SHA. + # That is why run 33778594627 failed for all seven clients with + # Failure: resource with name "authzed/api:3fe8742..." was not found + # The BSR does know the git commit, but as a commit's source_control_url + # rather than as a label -- so map it here, then pin everything to the + # resulting immutable BSR commit id. Pinning to the id rather than to a + # moving label also guarantees all seven clients generate from exactly one + # revision even if another api merge lands mid-run. + - name: Resolve the pin to a BSR commit + id: bsr + env: + RAW: ${{ steps.pin.outputs.buftag }} + run: | + set -euo pipefail + + if buf build "buf.build/authzed/api:$RAW" -o /dev/null >/dev/null 2>&1; then + ref="$RAW" + else + echo "::notice::'$RAW' is not a BSR label; looking it up as a git commit" + ref=$(buf registry module commit list buf.build/authzed/api:main --page-size 50 --format json 2>/dev/null \ + | python3 -c 'import json,os,sys; raw=os.environ["RAW"]; print(next((c["commit"] for c in json.load(sys.stdin).get("commits",[]) if c.get("source_control_url","").endswith(raw)), ""))') + if [ -z "$ref" ]; then + echo "::error::Could not resolve $RAW to a BSR commit. buf-action labels by branch and tag, not by git SHA, so a commit SHA resolves only via its source_control_url, and none of the last 50 commits on the main label matches. Most likely the BSR push for this commit has not landed yet." + exit 1 + fi + fi + + commit=$(buf registry module commit list "buf.build/authzed/api:$ref" --page-size 1 --format json 2>/dev/null | python3 -c 'import json,sys; print(json.load(sys.stdin)["commits"][0]["commit"])') + if [ -z "$commit" ]; then + echo "::error::Resolved $RAW to ref $ref but could not read its BSR commit id." + exit 1 + fi + echo "resolved $RAW -> BSR commit $commit" + echo "commit=$commit" >> "$GITHUB_OUTPUT" - name: Install mage timeout-minutes: 5 run: go install github.com/magefile/mage@latest @@ -175,7 +212,8 @@ jobs: continue-on-error: true env: CI_REGENERATION: "1" - BUFTAG: ${{ steps.pin.outputs.buftag }} + # The resolved BSR commit, not the raw ref -- see "Resolve the pin". + BUFTAG: ${{ steps.bsr.outputs.commit }} CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} run: | set -o pipefail @@ -240,12 +278,13 @@ jobs: - **Trigger:** `${{ github.event_name }}` / `${{ github.event.action }}` - **Generation result:** `${{ steps.regen.outcome }}` - **Failed languages:** `${{ steps.state.outputs.failed }}` + - **Resolved BSR commit:** `${{ steps.bsr.outputs.commit }}` - **Run:** ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} - Reproduce locally: + Reproduce locally, against the exact revision this ran on: ``` - BUFTAG=${{ steps.pin.outputs.buftag }} mage gen:all + BUFTAG=${{ steps.bsr.outputs.commit }} mage gen:all ``` # Gated on the operation, not merely on a populated number: