From fb3b1ba6ae8bf407f69c56f7a9a9ae389c1e114a Mon Sep 17 00:00:00 2001 From: isVoid <13521008+isVoid@users.noreply.github.com> Date: Mon, 5 Oct 2026 22:48:07 +0000 Subject: [PATCH 1/2] ci: add manual WoA cross-repository broker --- .github/workflows/woa-crossrepo-smoke.yml | 106 +++++++++++++ .github/workflows/woa-private-dispatch.yml | 172 +++++++++++++++++++++ 2 files changed, 278 insertions(+) create mode 100644 .github/workflows/woa-crossrepo-smoke.yml create mode 100644 .github/workflows/woa-private-dispatch.yml diff --git a/.github/workflows/woa-crossrepo-smoke.yml b/.github/workflows/woa-crossrepo-smoke.yml new file mode 100644 index 00000000000..4f2fd49f913 --- /dev/null +++ b/.github/workflows/woa-crossrepo-smoke.yml @@ -0,0 +1,106 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: "WoA cross-repository transport smoke" +run-name: "WoA transport smoke for PR #${{ inputs.pr_number }}" + +on: + workflow_dispatch: + inputs: + pr_number: + description: Open same-repository PR to receive the smoke Check Run + required: true + type: number + +permissions: {} + +jobs: + resolve-public-pr: + if: ${{ github.repository == 'NVIDIA/cuda-python' }} + runs-on: ubuntu-latest + timeout-minutes: 5 + permissions: + pull-requests: read + outputs: + correlation-id: ${{ steps.resolve.outputs.correlation_id }} + public-sha: ${{ steps.resolve.outputs.public_sha }} + steps: + - name: Resolve exact same-repository PR head + id: resolve + env: + GH_TOKEN: ${{ github.token }} + PR_NUMBER: ${{ inputs.pr_number }} + run: | + set -euo pipefail + [[ "$PR_NUMBER" =~ ^[1-9][0-9]*$ ]] + pr=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/pulls/$PR_NUMBER") + jq -e ' + .state == "open" and + .base.ref == "main" and + .head.repo.full_name == "NVIDIA/cuda-python" and + (.head.sha | test("^[0-9a-f]{40}$")) + ' <<< "$pr" >/dev/null + public_sha=$(jq -r .head.sha <<< "$pr") + correlation_id="smoke:381173759:$PR_NUMBER:$public_sha:${GITHUB_RUN_ID}:${GITHUB_RUN_ATTEMPT}" + echo "public_sha=$public_sha" >> "$GITHUB_OUTPUT" + echo "correlation_id=$correlation_id" >> "$GITHUB_OUTPUT" + + dispatch-private-smoke: + needs: resolve-public-pr + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: {} + steps: + - name: Create private dispatch token + id: private-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + with: + client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }} + private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }} + owner: NVIDIA-dev + repositories: cuda-python-private + permission-actions: write + + - name: Dispatch and verify private smoke workflow + env: + CORRELATION_ID: ${{ needs.resolve-public-pr.outputs.correlation-id }} + GH_TOKEN: ${{ steps.private-app-token.outputs.token }} + PR_NUMBER: ${{ inputs.pr_number }} + PUBLIC_SHA: ${{ needs.resolve-public-pr.outputs.public-sha }} + run: | + set -euo pipefail + payload=$(jq -n \ + --arg correlation_id "$CORRELATION_ID" \ + --arg pr_number "$PR_NUMBER" \ + --arg public_sha "$PUBLIC_SHA" \ + '{ + ref: "ctk-next", + return_run_details: true, + inputs: { + schema_version: "1", + public_repository: "NVIDIA/cuda-python", + public_repository_id: "381173759", + public_pr_number: $pr_number, + public_sha: $public_sha, + correlation_id: $correlation_id + } + }') + response=$(gh api \ + --method POST \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + repos/NVIDIA-dev/cuda-python-private/actions/workflows/woa-crossrepo-smoke.yml/dispatches \ + --input - <<< "$payload") + private_run_id=$(jq -er '.workflow_run_id | tostring' <<< "$response") + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA-dev/cuda-python-private/actions/runs/$private_run_id") + jq -e ' + .repository.id == 809898190 and + .path == ".github/workflows/woa-crossrepo-smoke.yml" and + .event == "workflow_dispatch" and + .head_branch == "ctk-next" + ' <<< "$run" >/dev/null + echo "Private transport-smoke workflow accepted the exact dispatch." >> "$GITHUB_STEP_SUMMARY" diff --git a/.github/workflows/woa-private-dispatch.yml b/.github/workflows/woa-private-dispatch.yml new file mode 100644 index 00000000000..0a9d234545e --- /dev/null +++ b/.github/workflows/woa-private-dispatch.yml @@ -0,0 +1,172 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: "WoA exact public-main dispatch" +run-name: "WoA exact dispatch for public run ${{ inputs.public_run_id }}" + +on: + workflow_dispatch: + inputs: + public_run_id: + description: Successful public main CI run containing the exact WoA artifacts + required: true + type: string + +permissions: {} + +jobs: + resolve-public-build: + if: ${{ github.repository == 'NVIDIA/cuda-python' }} + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + actions: read + contents: read + checks: read + outputs: + artifacts-json: ${{ steps.resolve.outputs.artifacts_json }} + correlation-id: ${{ steps.resolve.outputs.correlation_id }} + public-run-attempt: ${{ steps.resolve.outputs.public_run_attempt }} + public-sha: ${{ steps.resolve.outputs.public_sha }} + steps: + - name: Resolve exact successful public build + id: resolve + env: + GH_TOKEN: ${{ github.token }} + PUBLIC_RUN_ID: ${{ inputs.public_run_id }} + run: | + set -euo pipefail + [[ "$PUBLIC_RUN_ID" =~ ^[1-9][0-9]*$ ]] + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID") + jq -e ' + .repository.id == 381173759 and + .workflow_id == 155304118 and + .path == ".github/workflows/ci.yml" and + .event == "push" and + .head_branch == "main" and + .status == "completed" and + .conclusion == "success" and + (.head_sha | test("^[0-9a-f]{40}$")) + ' <<< "$run" >/dev/null + public_sha=$(jq -r .head_sha <<< "$run") + public_run_attempt=$(jq -r '.run_attempt | tostring' <<< "$run") + + comparison=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/compare/$public_sha...main") + jq -e '.status == "ahead" or .status == "identical"' <<< "$comparison" >/dev/null + + jobs=$(gh api --paginate \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/attempts/$public_run_attempt/jobs?per_page=100" \ + --jq '.jobs') + jq -s -e ' + add + | map(select(.name | startswith("Build win-arm64, CUDA "))) + | length > 0 and all(.[]; .status == "completed" and .conclusion == "success") + ' <<< "$jobs" >/dev/null + + artifacts=$(gh api --paginate \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/artifacts?per_page=100" \ + --jq '.artifacts' | jq -s 'add') + artifacts_json=$(jq -c \ + --arg sha "$public_sha" ' + map(select( + .expired == false and + ( + .name == "cuda-pathfinder-wheel" or + (.name | test("^cuda-bindings-python313-cuda[0-9.]+-win-arm64-" + $sha + "$")) or + .name == ("cuda-core-python313-win-arm64-" + $sha) + ) + )) + | map({id, name, digest}) + | sort_by(.name) + ' <<< "$artifacts") + jq -e ' + length == 3 and + all(.[ ]; + (.id | type == "number") and + (.digest | test("^sha256:[0-9a-f]{64}$"))) + ' <<< "$artifacts_json" >/dev/null + + correlation_id="v1:381173759:$PUBLIC_RUN_ID:$public_run_attempt:$public_sha" + echo "artifacts_json=$artifacts_json" >> "$GITHUB_OUTPUT" + echo "correlation_id=$correlation_id" >> "$GITHUB_OUTPUT" + echo "public_run_attempt=$public_run_attempt" >> "$GITHUB_OUTPUT" + echo "public_sha=$public_sha" >> "$GITHUB_OUTPUT" + { + echo "Resolved public run \`$PUBLIC_RUN_ID\` attempt \`$public_run_attempt\`." + echo "" + echo "Exact Windows Arm64 artifacts:" + jq -r '.[] | "- `\(.name)` (`\(.digest)`)"' <<< "$artifacts_json" + } >> "$GITHUB_STEP_SUMMARY" + + dispatch-private-validation: + needs: resolve-public-build + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: {} + steps: + - name: Create private dispatch token + id: private-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + with: + client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }} + private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }} + owner: NVIDIA-dev + repositories: cuda-python-private + permission-actions: write + + - name: Dispatch and verify exact private validation + env: + ARTIFACTS_JSON: ${{ needs.resolve-public-build.outputs.artifacts-json }} + CORRELATION_ID: ${{ needs.resolve-public-build.outputs.correlation-id }} + GH_TOKEN: ${{ steps.private-app-token.outputs.token }} + PUBLIC_RUN_ATTEMPT: ${{ needs.resolve-public-build.outputs.public-run-attempt }} + PUBLIC_RUN_ID: ${{ inputs.public_run_id }} + PUBLIC_SHA: ${{ needs.resolve-public-build.outputs.public-sha }} + run: | + set -euo pipefail + payload=$(jq -n \ + --arg artifacts_json "$ARTIFACTS_JSON" \ + --arg correlation_id "$CORRELATION_ID" \ + --arg run_attempt "$PUBLIC_RUN_ATTEMPT" \ + --arg run_id "$PUBLIC_RUN_ID" \ + --arg sha "$PUBLIC_SHA" \ + '{ + ref: "ctk-next", + return_run_details: true, + inputs: { + schema_version: "1", + public_repository: "NVIDIA/cuda-python", + public_repository_id: "381173759", + public_workflow_id: "155304118", + public_run_id: $run_id, + public_run_attempt: $run_attempt, + public_sha: $sha, + artifacts_json: $artifacts_json, + baseline_sha: "", + commit_count: "1", + correlation_id: $correlation_id + } + }') + response=$(gh api \ + --method POST \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + repos/NVIDIA-dev/cuda-python-private/actions/workflows/woa-main-validation.yml/dispatches \ + --input - <<< "$payload") + private_run_id=$(jq -er '.workflow_run_id | tostring' <<< "$response") + run=$(gh api \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA-dev/cuda-python-private/actions/runs/$private_run_id") + jq -e ' + .repository.id == 809898190 and + .path == ".github/workflows/woa-main-validation.yml" and + .event == "workflow_dispatch" and + .head_branch == "ctk-next" + ' <<< "$run" >/dev/null + echo "Private validation workflow accepted the exact dispatch." >> "$GITHUB_STEP_SUMMARY" From eb4adeaee6abcfc4e80e39925dfc471903bcd64b Mon Sep 17 00:00:00 2001 From: isVoid <13521008+isVoid@users.noreply.github.com> Date: Tue, 6 Oct 2026 06:26:19 +0000 Subject: [PATCH 2/2] ci: dispatch exact WoA producer identity --- .github/workflows/woa-private-dispatch.yml | 64 ++++++++++++++-------- 1 file changed, 42 insertions(+), 22 deletions(-) diff --git a/.github/workflows/woa-private-dispatch.yml b/.github/workflows/woa-private-dispatch.yml index 0a9d234545e..e01fd107243 100644 --- a/.github/workflows/woa-private-dispatch.yml +++ b/.github/workflows/woa-private-dispatch.yml @@ -27,6 +27,7 @@ jobs: outputs: artifacts-json: ${{ steps.resolve.outputs.artifacts_json }} correlation-id: ${{ steps.resolve.outputs.correlation_id }} + public-producer-job-id: ${{ steps.resolve.outputs.public_producer_job_id }} public-run-attempt: ${{ steps.resolve.outputs.public_run_attempt }} public-sha: ${{ steps.resolve.outputs.public_sha }} steps: @@ -63,29 +64,44 @@ jobs: -H 'X-GitHub-Api-Version: 2026-03-10' \ "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/attempts/$public_run_attempt/jobs?per_page=100" \ --jq '.jobs') - jq -s -e ' + producer_jobs=$(jq -s -c ' add - | map(select(.name | startswith("Build win-arm64, CUDA "))) - | length > 0 and all(.[]; .status == "completed" and .conclusion == "success") - ' <<< "$jobs" >/dev/null + | map(select(.name == "Build win-arm64, CUDA 13.4.2 / py3.13")) + ' <<< "$jobs") + jq -e ' + length == 1 and + .[0].status == "completed" and + .[0].conclusion == "success" + ' <<< "$producer_jobs" >/dev/null + public_producer_job_id=$(jq -r '.[0].id | tostring' <<< "$producer_jobs") - artifacts=$(gh api --paginate \ - -H 'X-GitHub-Api-Version: 2026-03-10' \ - "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/artifacts?per_page=100" \ - --jq '.artifacts' | jq -s 'add') - artifacts_json=$(jq -c \ - --arg sha "$public_sha" ' - map(select( - .expired == false and - ( - .name == "cuda-pathfinder-wheel" or - (.name | test("^cuda-bindings-python313-cuda[0-9.]+-win-arm64-" + $sha + "$")) or - .name == ("cuda-core-python313-win-arm64-" + $sha) - ) - )) - | map({id, name, digest}) - | sort_by(.name) - ' <<< "$artifacts") + expected_names=$(jq -n \ + --arg sha "$public_sha" '[ + "cuda-pathfinder-wheel", + ("cuda-bindings-python313-cuda13.4.2-win-arm64-" + $sha), + ("cuda-core-python313-win-arm64-" + $sha) + ]') + artifacts_json='[]' + while IFS= read -r artifact_name; do + response=$(gh api --method GET \ + -H 'X-GitHub-Api-Version: 2026-03-10' \ + "repos/NVIDIA/cuda-python/actions/runs/$PUBLIC_RUN_ID/artifacts" \ + -f name="$artifact_name" \ + -F per_page=100) + artifact=$(jq -c -e \ + --arg name "$artifact_name" ' + if .total_count == 1 and + (.artifacts | length) == 1 and + .artifacts[0].name == $name and + .artifacts[0].expired == false + then .artifacts[0] | {id, name, digest} + else error("expected exactly one unexpired artifact named " + $name) + end + ' <<< "$response") + artifacts_json=$(jq -c \ + --argjson artifact "$artifact" \ + '. + [$artifact] | sort_by(.name)' <<< "$artifacts_json") + done < <(jq -r '.[]' <<< "$expected_names") jq -e ' length == 3 and all(.[ ]; @@ -96,10 +112,11 @@ jobs: correlation_id="v1:381173759:$PUBLIC_RUN_ID:$public_run_attempt:$public_sha" echo "artifacts_json=$artifacts_json" >> "$GITHUB_OUTPUT" echo "correlation_id=$correlation_id" >> "$GITHUB_OUTPUT" + echo "public_producer_job_id=$public_producer_job_id" >> "$GITHUB_OUTPUT" echo "public_run_attempt=$public_run_attempt" >> "$GITHUB_OUTPUT" echo "public_sha=$public_sha" >> "$GITHUB_OUTPUT" { - echo "Resolved public run \`$PUBLIC_RUN_ID\` attempt \`$public_run_attempt\`." + echo "Resolved public run \`$PUBLIC_RUN_ID\` attempt \`$public_run_attempt\` and producer job \`$public_producer_job_id\`." echo "" echo "Exact Windows Arm64 artifacts:" jq -r '.[] | "- `\(.name)` (`\(.digest)`)"' <<< "$artifacts_json" @@ -128,12 +145,14 @@ jobs: GH_TOKEN: ${{ steps.private-app-token.outputs.token }} PUBLIC_RUN_ATTEMPT: ${{ needs.resolve-public-build.outputs.public-run-attempt }} PUBLIC_RUN_ID: ${{ inputs.public_run_id }} + PUBLIC_PRODUCER_JOB_ID: ${{ needs.resolve-public-build.outputs.public-producer-job-id }} PUBLIC_SHA: ${{ needs.resolve-public-build.outputs.public-sha }} run: | set -euo pipefail payload=$(jq -n \ --arg artifacts_json "$ARTIFACTS_JSON" \ --arg correlation_id "$CORRELATION_ID" \ + --arg producer_job_id "$PUBLIC_PRODUCER_JOB_ID" \ --arg run_attempt "$PUBLIC_RUN_ATTEMPT" \ --arg run_id "$PUBLIC_RUN_ID" \ --arg sha "$PUBLIC_SHA" \ @@ -145,6 +164,7 @@ jobs: public_repository: "NVIDIA/cuda-python", public_repository_id: "381173759", public_workflow_id: "155304118", + public_producer_job_id: $producer_job_id, public_run_id: $run_id, public_run_attempt: $run_attempt, public_sha: $sha,