Skip to content

fix(ci): keep .github/actions in the source archive - #3193

Merged
kevinjqliu merged 2 commits into
apache:mainfrom
xanderbailey:xb/fix-github-actions-export-ignore
Sep 10, 2026
Merged

kevinjqliu merged 2 commits into
apache:mainfrom
xanderbailey:xb/fix-github-actions-export-ignore

Conversation

@xanderbailey

@xanderbailey xanderbailey commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

What changes are included in this PR?

CI is currently red on main and on every open PR. Jobs fail at action-resolution time, before anything is built:

Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action
'apache/iceberg-rust/.github/actions/setup-builder@<sha>'

Cause

Two changes that are each fine in isolation:

GitHub resolves a uses: $/... reference by fetching a repository archive, and those archives honour export-ignore. Excluding .github wholesale therefore hides .github/actions from that fetch, so every workflow using a local composite action (setup-builder, get-msrv, overwrite-package-version) fails to resolve it. ./... references read the checked-out worktree and were unaffected, which is why this only surfaced once both changes were on main.

Timeline on main (workflow CI):

commit result
1deceb138 #3161 — $/ migration, 09-07 success
28ede505e … 4d83bc77d, 09-07 → 09-09 success
d6c2eb440 #3189 — .github export-ignore, 09-10 failure

Fix

List the .github entries individually rather than excluding the directory, so the repo-only files #3189 targeted stay out of the tarball while .github/actions remains resolvable.

A -export-ignore negation on the subdirectory does not work — git does not descend into an export-ignored directory, so the child attribute is never consulted. Verified below.

This keeps both earlier changes intact: no $/ reference is reverted, and no zizmor suppression is added.

Are these changes tested?

The archive half is verified locally with git archive --worktree-attributes HEAD | tar t, comparing attribute sets:

.gitattributes .github/actions .github/workflows other .github
main today 0 0 0
.github export-ignore + .github/actions -export-ignore 0 0 0
this PR 7 0 0

Everything else #3189 excluded (website, .asf.yaml, .devcontainer, .gitattributes, .gitignore, .idea) remains excluded — verified as 0 entries each.

The action-resolution half cannot be verified by this PR's own checks. ci.yml, bindings_python_ci.yml and public-api.yml all carry - '!.gitattributes' in their pull_request path filters, so a .gitattributes-only change does not trigger them. The checks that do run here (asf-allowlist-check, Analyze Actions, CodeQL, zizmor) contain no uses: $/... reference, so their passing says nothing about the fix.

Those workflows trigger unconditionally on push to main, so the fix validates on merge. If you would rather confirm before merging, re-running the failed CI job on any open PR with this branch merged in will exercise it — or I am happy to push a throwaway one-character change to a crates/** file here to force the full suite to run, if that is preferred over merging on the strength of the archive evidence.

`.github export-ignore` (apache#3189) hides `.github/actions` from repository
archives. GitHub resolves the `uses: $/...` self-repository references
introduced in apache#3161 by fetching such an archive, so every workflow that
uses a local composite action now fails at action resolution:

  Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action
  'apache/iceberg-rust/.github/actions/setup-builder@<sha>'

This breaks CI on main and on all open pull requests.

List the .github entries individually instead, so the repo-only files
apache#3189 targeted stay out of the release tarball while `.github/actions`
remains resolvable. A `-export-ignore` negation on the subdirectory does
not work: git does not descend into an export-ignored directory.
@dannycjones

Copy link
Copy Markdown
Contributor

Another instance #3140 would have saved us

@dannycjones dannycjones left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for acting on this, lgtm!

@kevinjqliu kevinjqliu left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for looking into this! What do you think about if we just remove the .github entry entirely?

Comment thread .gitattributes Outdated
Comment on lines +14 to +18
.github/ISSUE_TEMPLATE export-ignore
.github/PULL_REQUEST_TEMPLATE.md export-ignore
.github/copilot-instructions.md export-ignore
.github/dependabot.yml export-ignore
.github/workflows export-ignore

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
.github/ISSUE_TEMPLATE export-ignore
.github/PULL_REQUEST_TEMPLATE.md export-ignore
.github/copilot-instructions.md export-ignore
.github/dependabot.yml export-ignore
.github/workflows export-ignore

what do you think about if we just remove .github export-ignore entirely?

so we dont need to keep this list updated

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .gitattributes Outdated
Comment on lines +4 to +9
#
# .github is listed entry by entry rather than wholesale: GitHub resolves the
# `uses: $/...` self-repository action references in our workflows by fetching a
# repository archive, which honours export-ignore. Excluding .github as a whole
# therefore hides .github/actions from that fetch and every workflow using a
# local composite action fails with "Can't find 'action.yml'".

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
#
# .github is listed entry by entry rather than wholesale: GitHub resolves the
# `uses: $/...` self-repository action references in our workflows by fetching a
# repository archive, which honours export-ignore. Excluding .github as a whole
# therefore hides .github/actions from that fetch and every workflow using a
# local composite action fails with "Can't find 'action.yml'".
# .github must stay in too: `uses: $/...` action references are resolved from
# the repository archive, which honors export-ignore.

maybe something smaller

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kevinjqliu kevinjqliu left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kevinjqliu
kevinjqliu merged commit 6f062aa into apache:main Sep 10, 2026
4 checks passed
@kevinjqliu

Copy link
Copy Markdown
Contributor

thanks! @xanderbailey

kevinjqliu added a commit that referenced this pull request Sep 10, 2026
* chore: exclude repo-only files from the source archive (#3189)

The release tarball is built with git archive and ships .asf.yaml,
.devcontainer, .github, .gitignore, .gitattributes, and .idea, none of
which are needed to build, test, or verify from source. Ryan raised this
in the 0.2.0 vote and Kurtis called out .idea in the 0.9.1 vote.

Files the verification scripts rely on (.licenserc.yaml, lint configs,
dev/) stay in.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit d6c2eb4)

* fix(ci): keep .github/actions in the source archive (#3193)

`.github export-ignore` (#3189) hides `.github/actions` from repository
archives. GitHub resolves the `uses: ./...` self-repository references by
fetching such an archive, so every workflow that uses a local composite
action fails at action resolution:

  Can't find 'action.yml', 'action.yaml' or 'Dockerfile' for action
  'apache/iceberg-rust/.github/actions/setup-builder@<sha>'

List the .github entries individually instead, so the repo-only files
#3189 targeted stay out of the release tarball while `.github/actions`
remains resolvable. A `-export-ignore` negation on the subdirectory does
not work: git does not descend into an export-ignored directory.

(cherry picked from commit 6f062aa)

---------

Co-authored-by: Kevin Liu <kevinjqliu@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Xander <zander181@googlemail.com>
dannycjones added a commit to dannycjones/iceberg-rust that referenced this pull request Sep 15, 2026
Brings the 0.11.0 release-branch changes back to `main`. Only the release
metadata is merged; everything else on `0.11.x` is either already on
`main` or was deliberately superseded there.

* `Cargo.toml`: `workspace.package.version` 0.10.1 -> 0.11.0, and the
  nine workspace path dependencies 0.10.0 -> 0.11.0.
* `CHANGELOG.md`: the `## [v0.11.0]` section.
* `Cargo.lock`: regenerated from `main`'s lock with
  `cargo update --workspace --offline`, not merged. Only the 17
  workspace-member versions change; no third-party dependency moves.

Not merged:

* `DEPENDENCIES.rust.tsv` (17 files). These are generated during release
  prep on the release branch and describe the released dependency graph
  (arrow 58 / DataFusion 54 for 0.11.0). `main` is on arrow 59 /
  DataFusion 55, so carrying them across would replace stale data with
  data that is wrong for this branch. apache#3074 excluded them likewise.
* Source, CI, and release-tooling changes. `main` is ahead on every file
  that differs, including the two that conflict during a naive merge:
  `dev/hms/Dockerfile` (main is on the Hive 4.2.1 image) and
  `.gitattributes`/`dev/release/create_rc.sh` (apache#3193, apache#3200). Fixes
  belong on `main` first and are then backported, so nothing here needs
  to travel in this direction.
dannycjones added a commit to dannycjones/iceberg-rust that referenced this pull request Sep 15, 2026
Brings the 0.11.0 release metadata back to `main`. Only `CHANGELOG.md`,
`Cargo.toml`, and `Cargo.lock` change; everything else on `0.11.x` is
either already on `main` or was deliberately superseded there.

`CHANGELOG.md` and `Cargo.toml` are three-way merged, not copied from the
release branch. `main` has moved its dependencies on since the 0.11.x cut
(arrow 58.4 -> 59.2, DataFusion 54 -> 55, pyo3 0.28 -> 0.29, and
datafusion-ffi dropped in apache#3149), and a merge keeps those while taking
the release branch's version bumps. The result is
`workspace.package.version` 0.10.1 -> 0.11.0, the nine workspace path
dependencies 0.10.0 -> 0.11.0, and the `## [v0.11.0]` changelog section.

`Cargo.lock` is regenerated from `main`'s lock with
`cargo update --workspace`, not merged. Only the 17 workspace-member
versions change; no third-party dependency moves.

All other paths are resolved to `main`, including the two that conflict:
`dev/hms/Dockerfile` (`main` is on the Hive 4.2.1 image) and
`.gitattributes` (apache#3193). `dev/release/create_rc.sh` and `deny.toml` also
differ, both because `main` removed things on purpose (apache#3200, apache#3149).
Fixes land on `main` first and are backported, so nothing needs to travel
in this direction.

`DEPENDENCIES.rust.tsv` is not merged either. Those files are generated
during release prep on the release branch and describe the released
dependency graph, which is older than `main`'s, so carrying them across
would replace stale data with data that is wrong for `main`. Per apache#2706
generating them is a release-manager task and is not enforced by CI, so
`main`'s copies are refreshed at the next release, on the next release
branch. apache#3074 excluded them likewise.
dannycjones added a commit to dannycjones/iceberg-rust that referenced this pull request Sep 15, 2026
Brings the 0.11.0 release metadata back to `main`. Only `CHANGELOG.md`,
`Cargo.toml`, and `Cargo.lock` change; everything else on `0.11.x` is
either already on `main` or was deliberately superseded there.

`CHANGELOG.md` and `Cargo.toml` are three-way merged, not copied from the
release branch. `main` has moved its dependencies on since the 0.11.x cut
(arrow 58.4 -> 59.2, DataFusion 54 -> 55, pyo3 0.28 -> 0.29, and
datafusion-ffi dropped in apache#3149), and a merge keeps those while taking
the release branch's version bumps. The result is
`workspace.package.version` 0.10.1 -> 0.11.0, the nine workspace path
dependencies 0.10.0 -> 0.11.0, and the `## [v0.11.0]` changelog section.
No third-party dependency version changes.

`Cargo.lock` is regenerated from `main`'s lock with
`cargo update --workspace`, not merged. Only the 17 workspace-member
versions change.

All other paths are resolved to `main`, including the two that conflict:
`dev/hms/Dockerfile` (`main` is on the Hive 4.2.1 image) and
`.gitattributes` (apache#3193). `dev/release/` and `deny.toml` also differ,
because `main` is ahead (apache#3194) or removed things on purpose (apache#3200,
apache#3149). Fixes land on `main` first and are backported, so nothing needs
to travel in this direction.

`DEPENDENCIES.rust.tsv` is not merged. Those files are generated during
release prep on the release branch and describe the released dependency
graph, which is older than `main`'s, so carrying them across would
replace stale data with data that is wrong for `main`. Per apache#2706
generating them is a release-manager task and is not enforced by CI, so
`main`'s copies are refreshed at the next release, on the next release
branch. apache#3074 excluded them likewise.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants