Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -790,6 +790,10 @@ jobs:
# `contents: write` is for GitHub Releases, never for refs: this job runs
# no `git push` of any kind.
contents: write
# `actions: read` is the Releases backfill's guard: the audit reads this
# workflow's runs and their jobs to ask whether the same version's
# publish is in flight in another run. Reads only, never a cancel.
actions: read
outputs:
# "the docker job must build" — set only when npm ALREADY has this
# version's WHOLE fixed group and its runtime image is missing.
Expand Down Expand Up @@ -1066,9 +1070,33 @@ jobs:
;;
esac

# ── the publish in flight, before any Releases backfill ───────────
# npm settles BEFORE the publish job reaches its own "Create GitHub
# Releases" step, so a landing audited in that window found the group
# complete and wrote the same Releases beside it: on 17.6.0 the
# publish of run 36955885276 wrote them 03:03:47Z -> 03:05:42Z, this
# backfill in run 36958423332 started at 03:04:37Z, and five tags got
# two Release objects each. The two writers are in different runs,
# so no `needs:` can order them; the publish's own run creates its
# Releases and D4 asset, and a landing after it finishes backfills
# whatever it did not. scripts/release-pending-publish.mjs `in-flight`
# (its --self-test, run by lint.yml, holds the rule) answers
# `in-flight` on anything it cannot read, so nothing is backfilled off
# a guess. It only ever leaves `releases-missing` unset: this step
# stays green and the image request below is not its business.
if [ "$releases_ok" = true ]; then
echo "GitHub Releases + ADR-0087 D4 asset are present for ${version}."
elif ! flight=$(GITHUB_TOKEN="$GH_TOKEN" node scripts/release-pending-publish.mjs in-flight --version "$version" --version-commit "$version_commit" --head "$SHA" --workflow release.yml); then
echo "::warning::${version}'s GitHub Releases or ADR-0087 D4 asset are incomplete, and whether its publish is still in flight could not be asked (reason above). Nothing is backfilled off a guess; the next landing reads again."
elif [ "$(jq -r '.state' <<<"$flight")" != 'clear' ]; then
jq -c . <<<"$flight"
if [ "$(jq -r '.reason' <<<"$flight")" = 'publish-in-flight' ]; then
echo "::notice::${version}'s GitHub Releases or ADR-0087 D4 asset are incomplete, but its publish is still in flight ($(jq -r '.detail' <<<"$flight")). That run creates them; nothing is backfilled beside it. A landing after it finishes backfills whatever it did not."
else
echo "::warning::${version}'s GitHub Releases or ADR-0087 D4 asset are incomplete, and whether its publish is still in flight could not be read ($(jq -r '.detail' <<<"$flight")). Nothing is backfilled off a guess; the next landing reads again."
fi
else
jq -c . <<<"$flight"
echo "::warning::${version} is on npm but its GitHub Releases or the ADR-0087 D4 asset are incomplete (#4900) — backfilling."
echo "releases-missing=true" >> "$GITHUB_OUTPUT"
fi
Expand Down
Loading
Loading