From 3d99f261ff83be61a6d04ce5d144f89eda27d1a5 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 20:59:20 +0300 Subject: [PATCH] fix(ci): fetch release tags where the range base reads them (#703) Review r1 (High): actions/checkout passes `git fetch --no-tags` unless `fetch-tags: true`, even with fetch-depth 0, so releaseTaggedShas() was always empty in CI and a candidate outside the 100-run API window fell back to event.before instead of the last release tag. Preflight and changes now fetch tags; the workflow contract pins the option. The AC2 dev-push case now uses its own input (dev runs only, an older `before`) instead of repeating the main call (review r1, Low). Issue: #703 User-Visible: no Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd --- .github/workflows/validate.yml | 10 +++++++--- test/promotion-range.test.mjs | 4 +++- test/validate-workflow.test.mjs | 8 ++++++-- 3 files changed, 16 insertions(+), 6 deletions(-) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index d162ed63..80c3aab8 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -68,8 +68,10 @@ jobs: # Коммиты и деревья скачиваются целиком, поэтому диапазоны и `merge-base` # работают как раньше. Единственная догрузка по требованию здесь — # `git show origin/main:.github/workflows/<тонкий файл>`: по блобу на файл. + # `fetch-tags: true` (#703): теги релиза — граница проверенного материала + # для базы диапазона, а checkout по умолчанию качает с `--no-tags`. - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - with: { fetch-depth: 0, filter: 'blob:none' } + with: { fetch-depth: 0, filter: 'blob:none', fetch-tags: true } - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: { node-version: 22 } @@ -338,9 +340,11 @@ jobs: range_base: ${{ steps.base.outputs.range_base }} steps: # `git diff --name-only` содержимого файлов не читает вовсе, поэтому - # блобы истории этой job не нужны ни на одном шаге (#345). + # блобы истории этой job не нужны ни на одном шаге (#345). Теги — нужны: + # они граница проверенного материала для `range_base` (#703), а checkout + # по умолчанию передаёт `git fetch --no-tags`. - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - with: { fetch-depth: 0, filter: 'blob:none' } + with: { fetch-depth: 0, filter: 'blob:none', fetch-tags: true } # База диапазона — самый новый предок с УСПЕШНО завершённым Validate # (#387). Прежде бралась голова предыдущего пуша (`github.event.before`), # то есть допущение «до этого всё проверено». Concurrency отменяет прогон diff --git a/test/promotion-range.test.mjs b/test/promotion-range.test.mjs index a5f9d8d5..f79f1e68 100644 --- a/test/promotion-range.test.mjs +++ b/test/promotion-range.test.mjs @@ -128,7 +128,9 @@ test('#703 AC2: новое нарушение после границы крас const found = privateWrites(fx, onMain.base, hotfix); assert.equal(found.length, 1); assert.equal(found[0].field, '_tool'); - const onDev = rangeBase(fx, hotfix, { dev, main }, fx.candidate); + // Пуш в dev: другой вход — только прогоны dev и `before` раньше кандидата. + const onDev = rangeBase(fx, hotfix, { dev }, fx.beta3); + assert.equal(onDev.base, fx.candidate); assert.equal(privateWrites(fx, onDev.base, hotfix).length, 1); }); }); diff --git a/test/validate-workflow.test.mjs b/test/validate-workflow.test.mjs index c17627a1..8ed79cc7 100644 --- a/test/validate-workflow.test.mjs +++ b/test/validate-workflow.test.mjs @@ -372,8 +372,12 @@ test('#703 AC3: на пуше в main база диапазона видит п assert.match(range, /other=dev; \[ "\$BRANCH" = "dev" \] && other=main/); assert.match(range, /-f branch="\$other" -f status=completed/); assert.match(range, /--runs=\/tmp\/validate-runs\.json --runs=\/tmp\/validate-runs-other\.json/); - // Теги релиза читаются из истории: обе job клонируют её целиком. - for (const job of [preflight, changes]) assert.match(job, /fetch-depth: 0/); + // Теги релиза — граница материала. `actions/checkout` по умолчанию качает с + // `--no-tags` даже при `fetch-depth: 0` (r1 ревью #703): без `fetch-tags` + // `releaseTaggedShas()` в CI всегда пуст. + for (const job of [preflight, changes]) { + assert.match(job, /with: \{ fetch-depth: 0, filter: 'blob:none', fetch-tags: true \}/); + } }); /** Ставит ли workflow python-зависимости — по собственному содержимому.