Skip to content

ci: dispatch coverage-fanout on merged source PRs#459

Merged
eric-wang-1990 merged 12 commits into
mainfrom
eric-wang-1990/ci/coverage-fanout-sender
Jul 24, 2026
Merged

ci: dispatch coverage-fanout on merged source PRs#459
eric-wang-1990 merged 12 commits into
mainfrom
eric-wang-1990/ci/coverage-fanout-sender

Conversation

@eric-wang-1990

Copy link
Copy Markdown
Contributor

Summary

Wires databricks-sql-nodejs into the multi-language coverage fan-out in databricks/databricks-driver-test. When a PR merges to main and touched driver source (a file under lib/), dispatch a coverage-fanout repository_dispatch to driver-test; its coverage-fanout-tracker.yml opens a tracking issue and runs the language-agnostic fan-out — a spec authored from this PR's diff, conformed as tests across every driver (csharp/python/go/nodejs/rust/kernel/jdbc).

Same sender adbc-drivers/databricks already runs; this is one of a set of sibling PRs bringing the remaining driver repos onto the flow.

What it does

  • Adds closed to the pull_request trigger types; the new trigger-coverage-fanout job gates on github.event.pull_request.merged == true.
  • Source-path filter (lib/): docs/CI/test-only merges don't kick off a full 7-leg fan-out.
  • Reuses the existing INTEGRATION_TEST_APP_ID/_PRIVATE_KEY App token (scoped to driver-test) + the same peter-evans/repository-dispatch pin adbc uses.
  • Tightens skip-integration-tests-pr's guard to exclude closed so it doesn't re-stamp a check on merged PRs.

Test Plan

  • YAML validates; job-guard audit confirms no existing job misfires on the new closed event.
  • After merge: a subsequent merged source PR shows a coverage-fanout dispatch + a new tracking issue in databricks/databricks-driver-test.

This pull request and its description were written by Isaac.

…ce PRs

Wires databricks-sql-nodejs into the multi-language coverage fan-out. When a PR merges to
main and touched driver source (a file under lib/), dispatch a
`coverage-fanout` repository_dispatch to databricks/databricks-driver-test.
Its coverage-fanout-tracker.yml then opens a tracking issue and runs the
language-agnostic fan-out (a spec authored from this PR's diff, conformed
across every driver).

- Adds `closed` to the pull_request trigger types; the new trigger-coverage-fanout
  job gates on pull_request.merged == true.
- Source-path filter (lib/): docs/CI/test-only merges don't warrant a full fan-out.
- Reuses the existing INTEGRATION_TEST App token (scoped to driver-test) + the
  same peter-evans/repository-dispatch pin adbc-drivers/databricks uses.
- Tightens skip-integration-tests-pr's guard to exclude `closed` so it doesn't
  re-stamp a check on merged PRs.

Co-authored-by: Isaac
Signed-off-by: Eric Wang <e.wang@databricks.com>
Copilot AI review requested due to automatic review settings July 23, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

…ermissions

peco-review-bot findings on the coverage-fanout sender (apply to all driver
repos — the job is identical everywhere):

- F1 (Medium): the merged-PR guard didn't constrain the base branch, so a PR
  merged into a release/feature branch that touched source would also dispatch
  a full fan-out authoring a spec from a diff that never reached main. Add
  `github.event.pull_request.base.ref == 'main'` to match the stated intent.
- F2 (Low): the job declared no permissions block, relying on the default
  GITHUB_TOKEN read scope for github.rest.pulls.listFiles; if org defaults
  tighten to none it 403s silently. Scope it explicitly: contents: read +
  pull-requests: read.

Co-authored-by: Isaac
Signed-off-by: Eric Wang <e.wang@databricks.com>
Further peco-review-bot findings on the coverage-fanout sender:

- Narrow the minted App installation token with `permission-contents: write`
  (all coverage_fanout needs is repository_dispatch → contents:write), matching
  the defense-in-depth the other dispatch jobs in these repos already use — so a
  leaked token can only fire dispatches, not exercise the App's full scope.
- Restore the version tag in two action-pin comments (`# pinned` → the exact
  `# vX.Y.Z` the SHA corresponds to, per repo convention) for auditability.

Co-authored-by: Isaac
Signed-off-by: Eric Wang <e.wang@databricks.com>
Send proxy_mode=replay in both dispatch payloads (the label preview and the
merge-queue required gate) so the databricks-sql-nodejs PR gate runs the Node.js
suite in REPLAY against the PR's driver commit — deterministic, credential-free,
no live warehouse — instead of the live passthrough run it does today.

Paired with the driver-test receiver change (databricks-driver-test#909) that
adds proxy_mode=replay to databricks-sql-nodejs-integration-tests.yml and skips
the recording-less reyden leg in replay. Both must merge for the gate to run
replay; until #909 lands the receiver ignores proxy_mode (stays passthrough).

Co-authored-by: Isaac
Signed-off-by: Eric Wang <e.wang@databricks.com>
@eric-wang-1990 eric-wang-1990 added the integration-test Trigger the cross-repo driver-test Node.js integration suite on this PR label Jul 24, 2026
@github-actions

Copy link
Copy Markdown

Node.js integration tests triggered. View workflow run.

@eric-wang-1990 eric-wang-1990 removed the integration-test Trigger the cross-repo driver-test Node.js integration suite on this PR label Jul 24, 2026
… (fork enqueue)

`Node.js Integration Tests` is now a required status check. The PR-open placeholder
was posted by an inline job via `github.token`, which 403s on fork PRs (read-only
token), so fork PRs could never satisfy the required check and were stuck out of
the merge queue.

Replace the inline stub with a companion `skip-checks-reporter.yml` triggered by
`workflow_run`. It runs in the base-repo context with a read-write token even for
fork-triggered runs, so it posts `Node.js Integration Tests`=success on every PR
head — fork or not — letting all PRs auto-enqueue with no label. The check is
unpinned in the ruleset, so the github.token (github-actions) check satisfies it;
no app token/secrets are needed in the reporter, and it never checks out or runs
PR/fork content. The real suite still runs as the required gate on the merge_group
commit (driver-test app) and as a label preview on internal PRs.

Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <115501094+eric-wang-1990@users.noreply.github.com>
Switch the skip-checks-reporter to mint the INTEGRATION_TEST_APP token (scoped to
this repo) and post `Node.js Integration Tests` as the driver-test app, instead of
github.token. This matches the ruleset pinning the required check to that app's
integration id — a github.token (github-actions) check would not satisfy a pinned
gate. Secrets are available because the reporter runs in the base-repo context via
workflow_run, so this also works for fork PRs. Mirrors databricks-sql-go.

Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <115501094+eric-wang-1990@users.noreply.github.com>
Condense the explanatory comments on the e2e-test/coverage/codecov fork guards
to one line each; logic unchanged.

Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <115501094+eric-wang-1990@users.noreply.github.com>
Rewrite the coverage gate from `!cancelled() && ... && e2e != 'failure'` to the
positive `unit == success && (e2e == success || e2e == skipped)`. Same behavior —
runs when e2e passed or was skipped (fork PRs), a real e2e failure still blocks —
but reads directly and also treats a cancelled e2e as "don't run" rather than
letting it through.

Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <115501094+eric-wang-1990@users.noreply.github.com>
`prettier . --check` (the lint job) covers .github; the new reporter used
double-quoted `workflows:` which violates the repo's singleQuote rule. Reformat.

Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <115501094+eric-wang-1990@users.noreply.github.com>
@eric-wang-1990 eric-wang-1990 added the integration-test Trigger the cross-repo driver-test Node.js integration suite on this PR label Jul 24, 2026
@github-actions

Copy link
Copy Markdown

Node.js integration tests triggered. View workflow runs. The result posts back here as the "Node.js Integration Tests" check.

@eric-wang-1990
eric-wang-1990 added this pull request to the merge queue Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

integration-test Trigger the cross-repo driver-test Node.js integration suite on this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants