PSA: New Automated Backport Auditing CI (releng-audit)
Hi everyone, To help streamline and secure our backport process, I have introduced a new automated GitHub Actions CI workflow: `releng-audit`. This tool enforces our backport rules by automatically checking PRs targeting stable branches (e.g., `squid`, `tentacle`, `umbrella`). Please note: in the near future, passing this audit will become a required check for merging backport PRs. ### What it checks * Commit Parity: Ensures all commits from the original `main` PR(s) are present. * Conflict Simulation: Performs a dry-run of the cherry-pick sequence to detect undocumented conflicts or unapproved deviations. * Redmine Linkage: Verifies that the backport PR and original PR are properly linked to their respective Redmine tracker tickets. * Clean Merges: Checks that the PR merges cleanly into the target base branch. ### How it affects your workflow * Pass/Fail Labels: The bot will automatically apply a `releng-audit-pass` or `releng-audit-fail` label based on the results. * Retesting: If your PR fails the audit, review the bot's feedback, fix the issues, and then trigger a retest by either removing the `releng-audit-fail` label or commenting `/audit retest`. * Overrides: If the audit flags a legitimate manual conflict resolution or an intentional deviation, authorized users (Component Leads, release managers, or repo admins) can bypass the check by commenting `/audit override` or labeling the pr `releng-audit-override`. ### Documentation For full details on the technical requirements, rules, and troubleshooting, please refer to the updated backporter manual: * Submitting Patches to Ceph - Backports: https://github.com/ceph/ceph/blob/main/SubmittingPatches-backports.rst Please reach out if you have any questions or run into unexpected behavior with the new tooling. Best regards, -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D
participants (1)
-
Patrick Donnelly