diff --git a/.github/workflows/woa-transport-check.yml b/.github/workflows/woa-transport-check.yml new file mode 100644 index 00000000000..93ca7bde429 --- /dev/null +++ b/.github/workflows/woa-transport-check.yml @@ -0,0 +1,106 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: "WoA transport check" +run-name: "WoA transport smoke for PR #${{ inputs.pr_number }}" + +on: + workflow_dispatch: + inputs: + pr_number: + description: Open same-repository PR to receive the smoke Check Run + required: true + type: number + +permissions: {} + +jobs: + resolve-public-pr: + if: ${{ github.repository == 'NVIDIA/cuda-python' }} + runs-on: ubuntu-latest + timeout-minutes: 5 + permissions: + pull-requests: read + outputs: + correlation-id: ${{ steps.resolve.outputs.correlation_id }} + public-sha: ${{ steps.resolve.outputs.public_sha }} + steps: + - name: Resolve exact same-repository PR head + id: resolve + env: + GH_TOKEN: ${{ github.token }} + PR_NUMBER: ${{ inputs.pr_number }} + run: | + set -euo pipefail + [[ "$PR_NUMBER" =~ ^[1-9][0-9]*$ ]] + pr=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/pulls/$PR_NUMBER") + jq -e ' + .state == "open" and + .base.ref == "main" and + .head.repo.full_name == "NVIDIA/cuda-python" and + (.head.sha | test("^[0-9a-f]{40}$")) + ' <<< "$pr" >/dev/null + public_sha=$(jq -r .head.sha <<< "$pr") + correlation_id="smoke:381173759:$PR_NUMBER:$public_sha:${GITHUB_RUN_ID}:${GITHUB_RUN_ATTEMPT}" + echo "public_sha=$public_sha" >> "$GITHUB_OUTPUT" + echo "correlation_id=$correlation_id" >> "$GITHUB_OUTPUT" + + dispatch-private-smoke: + needs: resolve-public-pr + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: {} + steps: + - name: Create private dispatch token + id: private-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + with: + client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }} + private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }} + owner: NVIDIA-dev + repositories: cuda-python-private + permission-actions: write + + - name: Dispatch and verify private smoke workflow + env: + CORRELATION_ID: ${{ needs.resolve-public-pr.outputs.correlation-id }} + GH_TOKEN: ${{ steps.private-app-token.outputs.token }} + PR_NUMBER: ${{ inputs.pr_number }} + PUBLIC_SHA: ${{ needs.resolve-public-pr.outputs.public-sha }} + run: | + set -euo pipefail + payload=$(jq -n \ + --arg correlation_id "$CORRELATION_ID" \ + --arg pr_number "$PR_NUMBER" \ + --arg public_sha "$PUBLIC_SHA" \ + '{ + ref: "ctk-next", + return_run_details: true, + inputs: { + schema_version: "1", + public_repository: "NVIDIA/cuda-python", + public_repository_id: "381173759", + public_pr_number: $pr_number, + public_sha: $public_sha, + correlation_id: $correlation_id + } + }') + response=$(gh api \ + --method POST \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + repos/NVIDIA-dev/cuda-python-private/actions/workflows/ctk-next-woa-transport-check.yml/dispatches \ + --input - <<< "$payload") + private_run_id=$(jq -er '.workflow_run_id | tostring' <<< "$response") + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA-dev/cuda-python-private/actions/runs/$private_run_id") + jq -e ' + .repository.id == 809898190 and + .path == ".github/workflows/ctk-next-woa-transport-check.yml" and + .event == "workflow_dispatch" and + .head_branch == "ctk-next" + ' <<< "$run" >/dev/null + echo "Private transport-smoke workflow accepted the exact dispatch." >> "$GITHUB_STEP_SUMMARY" diff --git a/.github/workflows/woa-validation-dispatch.yml b/.github/workflows/woa-validation-dispatch.yml new file mode 100644 index 00000000000..af59544c7e1 --- /dev/null +++ b/.github/workflows/woa-validation-dispatch.yml @@ -0,0 +1,192 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: "WoA validation dispatch" +run-name: "WoA exact dispatch for public run ${{ inputs.public_run_id }}" + +on: + workflow_dispatch: + inputs: + public_run_id: + description: Successful public main CI run containing the exact WoA artifacts + required: true + type: string + +permissions: {} + +jobs: + resolve-public-build: + if: ${{ github.repository == 'NVIDIA/cuda-python' }} + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + actions: read + contents: read + checks: read + outputs: + artifacts-json: ${{ steps.resolve.outputs.artifacts_json }} + correlation-id: ${{ steps.resolve.outputs.correlation_id }} + public-producer-job-id: ${{ steps.resolve.outputs.public_producer_job_id }} + public-run-attempt: ${{ steps.resolve.outputs.public_run_attempt }} + public-sha: ${{ steps.resolve.outputs.public_sha }} + steps: + - name: Resolve exact successful public build + id: resolve + env: + GH_TOKEN: ${{ github.token }} + PUBLIC_RUN_ID: ${{ inputs.public_run_id }} + run: | + set -euo pipefail + [[ "$PUBLIC_RUN_ID" =~ ^[1-9][0-9]*$ ]] + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID") + jq -e ' + .repository.id == 381173759 and + .workflow_id == 155304118 and + .path == ".github/workflows/ci.yml" and + .event == "push" and + .head_branch == "main" and + .status == "completed" and + .conclusion == "success" and + (.head_sha | test("^[0-9a-f]{40}$")) + ' <<< "$run" >/dev/null + public_sha=$(jq -r .head_sha <<< "$run") + public_run_attempt=$(jq -r '.run_attempt | tostring' <<< "$run") + + comparison=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/compare/$public_sha...main") + jq -e '.status == "ahead" or .status == "identical"' <<< "$comparison" >/dev/null + + jobs=$(gh api --paginate \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/attempts/$public_run_attempt/jobs?per_page=100" \ + --jq '.jobs') + producer_jobs=$(jq -s -c ' + add + | map(select(.name == "Build win-arm64, CUDA 13.4.2 / py3.13")) + ' <<< "$jobs") + jq -e ' + length == 1 and + .[0].status == "completed" and + .[0].conclusion == "success" + ' <<< "$producer_jobs" >/dev/null + public_producer_job_id=$(jq -r '.[0].id | tostring' <<< "$producer_jobs") + + expected_names=$(jq -n \ + --arg sha "$public_sha" '[ + "cuda-pathfinder-wheel", + ("cuda-bindings-python313-cuda13.4.2-win-arm64-" + $sha), + ("cuda-core-python313-win-arm64-" + $sha) + ]') + artifacts_json='[]' + while IFS= read -r artifact_name; do + response=$(gh api --method GET \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/artifacts" \ + -f name="$artifact_name" \ + -F per_page=100) + artifact=$(jq -c -e \ + --arg name "$artifact_name" ' + if .total_count == 1 and + (.artifacts | length) == 1 and + .artifacts[0].name == $name and + .artifacts[0].expired == false + then .artifacts[0] | {id, name, digest} + else error("expected exactly one unexpired artifact named " + $name) + end + ' <<< "$response") + artifacts_json=$(jq -c \ + --argjson artifact "$artifact" \ + '. + [$artifact] | sort_by(.name)' <<< "$artifacts_json") + done < <(jq -r '.[]' <<< "$expected_names") + jq -e ' + length == 3 and + all(.[ ]; + (.id | type == "number") and + (.digest | test("^sha256:[0-9a-f]{64}$"))) + ' <<< "$artifacts_json" >/dev/null + + correlation_id="v1:381173759:$PUBLIC_RUN_ID:$public_run_attempt:$public_sha" + echo "artifacts_json=$artifacts_json" >> "$GITHUB_OUTPUT" + echo "correlation_id=$correlation_id" >> "$GITHUB_OUTPUT" + echo "public_producer_job_id=$public_producer_job_id" >> "$GITHUB_OUTPUT" + echo "public_run_attempt=$public_run_attempt" >> "$GITHUB_OUTPUT" + echo "public_sha=$public_sha" >> "$GITHUB_OUTPUT" + { + echo "Resolved public run \`$PUBLIC_RUN_ID\` attempt \`$public_run_attempt\` and producer job \`$public_producer_job_id\`." + echo "" + echo "Exact Windows Arm64 artifacts:" + jq -r '.[] | "- `\(.name)` (`\(.digest)`)"' <<< "$artifacts_json" + } >> "$GITHUB_STEP_SUMMARY" + + dispatch-private-validation: + needs: resolve-public-build + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: {} + steps: + - name: Create private dispatch token + id: private-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + with: + client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }} + private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }} + owner: NVIDIA-dev + repositories: cuda-python-private + permission-actions: write + + - name: Dispatch and verify exact private validation + env: + ARTIFACTS_JSON: ${{ needs.resolve-public-build.outputs.artifacts-json }} + CORRELATION_ID: ${{ needs.resolve-public-build.outputs.correlation-id }} + GH_TOKEN: ${{ steps.private-app-token.outputs.token }} + PUBLIC_RUN_ATTEMPT: ${{ needs.resolve-public-build.outputs.public-run-attempt }} + PUBLIC_RUN_ID: ${{ inputs.public_run_id }} + PUBLIC_PRODUCER_JOB_ID: ${{ needs.resolve-public-build.outputs.public-producer-job-id }} + PUBLIC_SHA: ${{ needs.resolve-public-build.outputs.public-sha }} + run: | + set -euo pipefail + payload=$(jq -n \ + --arg artifacts_json "$ARTIFACTS_JSON" \ + --arg correlation_id "$CORRELATION_ID" \ + --arg producer_job_id "$PUBLIC_PRODUCER_JOB_ID" \ + --arg run_attempt "$PUBLIC_RUN_ATTEMPT" \ + --arg run_id "$PUBLIC_RUN_ID" \ + --arg sha "$PUBLIC_SHA" \ + '{ + ref: "ctk-next", + return_run_details: true, + inputs: { + schema_version: "1", + public_repository: "NVIDIA/cuda-python", + public_repository_id: "381173759", + public_workflow_id: "155304118", + public_producer_job_id: $producer_job_id, + public_run_id: $run_id, + public_run_attempt: $run_attempt, + public_sha: $sha, + artifacts_json: $artifacts_json, + baseline_sha: "", + commit_count: "1", + correlation_id: $correlation_id + } + }') + response=$(gh api \ + --method POST \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + repos/NVIDIA-dev/cuda-python-private/actions/workflows/ctk-next-woa-validation.yml/dispatches \ + --input - <<< "$payload") + private_run_id=$(jq -er '.workflow_run_id | tostring' <<< "$response") + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA-dev/cuda-python-private/actions/runs/$private_run_id") + jq -e ' + .repository.id == 809898190 and + .path == ".github/workflows/ctk-next-woa-validation.yml" and + .event == "workflow_dispatch" and + .head_branch == "ctk-next" + ' <<< "$run" >/dev/null + echo "Private validation workflow accepted the exact dispatch." >> "$GITHUB_STEP_SUMMARY"