From 99a1786221effba91582b638149f21845ec8ed87 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 28 Sep 2026 15:26:30 -0400 Subject: [PATCH] fix(ci): pick the ancestor release in the Lambda ship-gate (PLAT-79) --- .github/workflows/cd-hcp-lambda.yaml | 31 ++++++++++++++++++++-------- 1 file changed, 22 insertions(+), 9 deletions(-) diff --git a/.github/workflows/cd-hcp-lambda.yaml b/.github/workflows/cd-hcp-lambda.yaml index ced3a1e..aaa5e65 100644 --- a/.github/workflows/cd-hcp-lambda.yaml +++ b/.github/workflows/cd-hcp-lambda.yaml @@ -123,7 +123,10 @@ jobs: fi export PATTERN TAG - PREV="$( + # Newest matching release that is an ancestor of TAG. The highest + # release overall is not that ancestor when a hotfix is cut from an + # older line (v2.0.0 exists, v1.2.1 is cut from v1.2.0). + CANDIDATES="$( gh api "repos/${REPO}/releases" --paginate --jq '.[].tag_name' | python3 -c ' import os, re, sys pattern = re.compile(os.environ["PATTERN"]) @@ -137,21 +140,31 @@ jobs: body = tag[1:] core = body.split("-", 1)[0] return tuple(int(part) for part in core.split(".")) - tags.sort(key=key) - print(tags[-1] if tags else "") + tags.sort(key=key, reverse=True) + print("\n".join(tags)) ' )" + PREV="" + if [ -n "${CANDIDATES}" ]; then + while IFS= read -r candidate; do + if [ -z "${candidate}" ]; then + continue + fi + candidate_status="$(gh api "repos/${REPO}/compare/${candidate}...${TAG}" --jq .status)" + if [ "${candidate_status}" = "ahead" ]; then + PREV="${candidate}" + break + fi + done <<< "${CANDIDATES}" + fi + if [ -z "${PREV}" ]; then - echo "ship-gate: no previous matching release tag; hotfix path requires a prior ${PATTERN} release" >&2 + echo "ship-gate: no prior ${PATTERN} release is an ancestor of ${TAG}" >&2 exit 1 fi - ff_status="$(gh api "repos/${REPO}/compare/${PREV}...${TAG}" --jq .status)" - if [ "${ff_status}" != "ahead" ]; then - echo "ship-gate: ${TAG} is not a fast-forward of ${PREV} (status: ${ff_status})" >&2 - exit 1 - fi + echo "ship-gate: ${TAG} is ahead of ${PREV}" from_train=false TARGET_COMMITISH="$(gh api "repos/${REPO}/releases/tags/${TAG}" --jq .target_commitish 2>/dev/null || true)"