fix(ci): keep .github/actions in the source archive - #3193
Merged
kevinjqliu merged 2 commits intoSep 10, 2026
Merged
Conversation
`.github export-ignore` (apache#3189) hides `.github/actions` from repository archives. GitHub resolves the `uses: $/...` self-repository references introduced in apache#3161 by fetching such an archive, so every workflow that uses a local composite action now fails at action resolution: Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action 'apache/iceberg-rust/.github/actions/setup-builder@<sha>' This breaks CI on main and on all open pull requests. List the .github entries individually instead, so the repo-only files apache#3189 targeted stay out of the release tarball while `.github/actions` remains resolvable. A `-export-ignore` negation on the subdirectory does not work: git does not descend into an export-ignored directory.
Contributor
|
Another instance #3140 would have saved us |
dannycjones
approved these changes
Sep 10, 2026
dannycjones
left a comment
Contributor
There was a problem hiding this comment.
Thanks for acting on this, lgtm!
3 tasks
kevinjqliu
reviewed
Sep 10, 2026
kevinjqliu
left a comment
Contributor
There was a problem hiding this comment.
Thanks for looking into this! What do you think about if we just remove the .github entry entirely?
Comment on lines
+14
to
+18
| .github/ISSUE_TEMPLATE export-ignore | ||
| .github/PULL_REQUEST_TEMPLATE.md export-ignore | ||
| .github/copilot-instructions.md export-ignore | ||
| .github/dependabot.yml export-ignore | ||
| .github/workflows export-ignore |
Contributor
There was a problem hiding this comment.
Suggested change
| .github/ISSUE_TEMPLATE export-ignore | |
| .github/PULL_REQUEST_TEMPLATE.md export-ignore | |
| .github/copilot-instructions.md export-ignore | |
| .github/dependabot.yml export-ignore | |
| .github/workflows export-ignore |
what do you think about if we just remove .github export-ignore entirely?
so we dont need to keep this list updated
Comment on lines
+4
to
+9
| # | ||
| # .github is listed entry by entry rather than wholesale: GitHub resolves the | ||
| # `uses: $/...` self-repository action references in our workflows by fetching a | ||
| # repository archive, which honours export-ignore. Excluding .github as a whole | ||
| # therefore hides .github/actions from that fetch and every workflow using a | ||
| # local composite action fails with "Can't find 'action.yml'". |
Contributor
There was a problem hiding this comment.
Suggested change
| # | |
| # .github is listed entry by entry rather than wholesale: GitHub resolves the | |
| # `uses: $/...` self-repository action references in our workflows by fetching a | |
| # repository archive, which honours export-ignore. Excluding .github as a whole | |
| # therefore hides .github/actions from that fetch and every workflow using a | |
| # local composite action fails with "Can't find 'action.yml'". | |
| # .github must stay in too: `uses: $/...` action references are resolved from | |
| # the repository archive, which honors export-ignore. |
maybe something smaller
Contributor
|
thanks! @xanderbailey |
kevinjqliu
added a commit
that referenced
this pull request
Sep 10, 2026
* chore: exclude repo-only files from the source archive (#3189) The release tarball is built with git archive and ships .asf.yaml, .devcontainer, .github, .gitignore, .gitattributes, and .idea, none of which are needed to build, test, or verify from source. Ryan raised this in the 0.2.0 vote and Kurtis called out .idea in the 0.9.1 vote. Files the verification scripts rely on (.licenserc.yaml, lint configs, dev/) stay in. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit d6c2eb4) * fix(ci): keep .github/actions in the source archive (#3193) `.github export-ignore` (#3189) hides `.github/actions` from repository archives. GitHub resolves the `uses: ./...` self-repository references by fetching such an archive, so every workflow that uses a local composite action fails at action resolution: Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action 'apache/iceberg-rust/.github/actions/setup-builder@<sha>' List the .github entries individually instead, so the repo-only files #3189 targeted stay out of the release tarball while `.github/actions` remains resolvable. A `-export-ignore` negation on the subdirectory does not work: git does not descend into an export-ignored directory. (cherry picked from commit 6f062aa) --------- Co-authored-by: Kevin Liu <kevinjqliu@users.noreply.github.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Xander <zander181@googlemail.com>
dannycjones
added a commit
to dannycjones/iceberg-rust
that referenced
this pull request
Sep 15, 2026
Brings the 0.11.0 release-branch changes back to `main`. Only the release metadata is merged; everything else on `0.11.x` is either already on `main` or was deliberately superseded there. * `Cargo.toml`: `workspace.package.version` 0.10.1 -> 0.11.0, and the nine workspace path dependencies 0.10.0 -> 0.11.0. * `CHANGELOG.md`: the `## [v0.11.0]` section. * `Cargo.lock`: regenerated from `main`'s lock with `cargo update --workspace --offline`, not merged. Only the 17 workspace-member versions change; no third-party dependency moves. Not merged: * `DEPENDENCIES.rust.tsv` (17 files). These are generated during release prep on the release branch and describe the released dependency graph (arrow 58 / DataFusion 54 for 0.11.0). `main` is on arrow 59 / DataFusion 55, so carrying them across would replace stale data with data that is wrong for this branch. apache#3074 excluded them likewise. * Source, CI, and release-tooling changes. `main` is ahead on every file that differs, including the two that conflict during a naive merge: `dev/hms/Dockerfile` (main is on the Hive 4.2.1 image) and `.gitattributes`/`dev/release/create_rc.sh` (apache#3193, apache#3200). Fixes belong on `main` first and are then backported, so nothing here needs to travel in this direction.
dannycjones
added a commit
to dannycjones/iceberg-rust
that referenced
this pull request
Sep 15, 2026
Brings the 0.11.0 release metadata back to `main`. Only `CHANGELOG.md`, `Cargo.toml`, and `Cargo.lock` change; everything else on `0.11.x` is either already on `main` or was deliberately superseded there. `CHANGELOG.md` and `Cargo.toml` are three-way merged, not copied from the release branch. `main` has moved its dependencies on since the 0.11.x cut (arrow 58.4 -> 59.2, DataFusion 54 -> 55, pyo3 0.28 -> 0.29, and datafusion-ffi dropped in apache#3149), and a merge keeps those while taking the release branch's version bumps. The result is `workspace.package.version` 0.10.1 -> 0.11.0, the nine workspace path dependencies 0.10.0 -> 0.11.0, and the `## [v0.11.0]` changelog section. `Cargo.lock` is regenerated from `main`'s lock with `cargo update --workspace`, not merged. Only the 17 workspace-member versions change; no third-party dependency moves. All other paths are resolved to `main`, including the two that conflict: `dev/hms/Dockerfile` (`main` is on the Hive 4.2.1 image) and `.gitattributes` (apache#3193). `dev/release/create_rc.sh` and `deny.toml` also differ, both because `main` removed things on purpose (apache#3200, apache#3149). Fixes land on `main` first and are backported, so nothing needs to travel in this direction. `DEPENDENCIES.rust.tsv` is not merged either. Those files are generated during release prep on the release branch and describe the released dependency graph, which is older than `main`'s, so carrying them across would replace stale data with data that is wrong for `main`. Per apache#2706 generating them is a release-manager task and is not enforced by CI, so `main`'s copies are refreshed at the next release, on the next release branch. apache#3074 excluded them likewise.
dannycjones
added a commit
to dannycjones/iceberg-rust
that referenced
this pull request
Sep 15, 2026
Brings the 0.11.0 release metadata back to `main`. Only `CHANGELOG.md`, `Cargo.toml`, and `Cargo.lock` change; everything else on `0.11.x` is either already on `main` or was deliberately superseded there. `CHANGELOG.md` and `Cargo.toml` are three-way merged, not copied from the release branch. `main` has moved its dependencies on since the 0.11.x cut (arrow 58.4 -> 59.2, DataFusion 54 -> 55, pyo3 0.28 -> 0.29, and datafusion-ffi dropped in apache#3149), and a merge keeps those while taking the release branch's version bumps. The result is `workspace.package.version` 0.10.1 -> 0.11.0, the nine workspace path dependencies 0.10.0 -> 0.11.0, and the `## [v0.11.0]` changelog section. No third-party dependency version changes. `Cargo.lock` is regenerated from `main`'s lock with `cargo update --workspace`, not merged. Only the 17 workspace-member versions change. All other paths are resolved to `main`, including the two that conflict: `dev/hms/Dockerfile` (`main` is on the Hive 4.2.1 image) and `.gitattributes` (apache#3193). `dev/release/` and `deny.toml` also differ, because `main` is ahead (apache#3194) or removed things on purpose (apache#3200, apache#3149). Fixes land on `main` first and are backported, so nothing needs to travel in this direction. `DEPENDENCIES.rust.tsv` is not merged. Those files are generated during release prep on the release branch and describe the released dependency graph, which is older than `main`'s, so carrying them across would replace stale data with data that is wrong for `main`. Per apache#2706 generating them is a release-manager task and is not enforced by CI, so `main`'s copies are refreshed at the next release, on the next release branch. apache#3074 excluded them likewise.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue does this PR close?
mainintroduced by the interaction of chore(deps): bump zizmor-action to 0.6.3 #3161 and chore: exclude repo-only files from the source archive #3189.What changes are included in this PR?
CI is currently red on
mainand on every open PR. Jobs fail at action-resolution time, before anything is built:Cause
Two changes that are each fine in isolation:
./...to GitHub self-repository$/...references, to resolve a zizmor 1.30 audit. CI passed on that commit and for three days afterwards..github export-ignoreto.gitattributes, to trim repo-only files from the release source archive.GitHub resolves a
uses: $/...reference by fetching a repository archive, and those archives honourexport-ignore. Excluding.githubwholesale therefore hides.github/actionsfrom that fetch, so every workflow using a local composite action (setup-builder,get-msrv,overwrite-package-version) fails to resolve it../...references read the checked-out worktree and were unaffected, which is why this only surfaced once both changes were onmain.Timeline on
main(workflowCI):1deceb138#3161 —$/migration, 09-0728ede505e…4d83bc77d, 09-07 → 09-09d6c2eb440#3189 —.github export-ignore, 09-10Fix
List the
.githubentries individually rather than excluding the directory, so the repo-only files #3189 targeted stay out of the tarball while.github/actionsremains resolvable.A
-export-ignorenegation on the subdirectory does not work — git does not descend into an export-ignored directory, so the child attribute is never consulted. Verified below.This keeps both earlier changes intact: no
$/reference is reverted, and no zizmor suppression is added.Are these changes tested?
The archive half is verified locally with
git archive --worktree-attributes HEAD | tar t, comparing attribute sets:.gitattributes.github/actions.github/workflows.githubmaintoday.github export-ignore+.github/actions -export-ignoreEverything else #3189 excluded (
website,.asf.yaml,.devcontainer,.gitattributes,.gitignore,.idea) remains excluded — verified as 0 entries each.The action-resolution half cannot be verified by this PR's own checks.
ci.yml,bindings_python_ci.ymlandpublic-api.ymlall carry- '!.gitattributes'in theirpull_requestpath filters, so a.gitattributes-only change does not trigger them. The checks that do run here (asf-allowlist-check,Analyze Actions,CodeQL,zizmor) contain nouses: $/...reference, so their passing says nothing about the fix.Those workflows trigger unconditionally on
pushtomain, so the fix validates on merge. If you would rather confirm before merging, re-running the failedCIjob on any open PR with this branch merged in will exercise it — or I am happy to push a throwaway one-character change to acrates/**file here to force the full suite to run, if that is preferred over merging on the strength of the archive evidence.