From dee739618ab939ab127564946c59912460d814dd Mon Sep 17 00:00:00 2001 From: imbajin Date: Sun, 4 Oct 2026 13:56:26 +0800 Subject: [PATCH 1/3] fix: stabilize required server CI check - add a fixed memory matrix result gate - share Linux build steps with backend jobs - preserve Java 11 checks during migration - remove Commons from required contexts --- .asf.yaml | 4 ++-- .github/workflows/server-ci.yml | 37 +++++++++++++++++++++++++++++---- 2 files changed, 35 insertions(+), 6 deletions(-) diff --git a/.asf.yaml b/.asf.yaml index 9aa07d545a..24f5d72069 100644 --- a/.asf.yaml +++ b/.asf.yaml @@ -41,8 +41,8 @@ github: - Analyze (java) - CodeQL - check-license - - build-server (memory, 11) - - build-commons (11) + # Stable across JDK upgrades; Commons still runs as an optional check. + - Server memory tests required_pull_request_reviews: dismiss_stale_reviews: true require_code_owner_reviews: false diff --git a/.github/workflows/server-ci.yml b/.github/workflows/server-ci.yml index b5f5efc270..6fd0fd354e 100644 --- a/.github/workflows/server-ci.yml +++ b/.github/workflows/server-ci.yml @@ -22,9 +22,10 @@ jobs: - name: Run wait-storage.sh peer failover tests run: hugegraph-server/hugegraph-dist/src/assembly/travis/test-wait-storage.sh + # Keep the legacy memory check name until the new protection context is active. build-server: runs-on: ubuntu-24.04 - env: + env: &server-env USE_STAGE: 'false' # Whether to include the stage repository. TRAVIS_DIR: hugegraph-server/hugegraph-dist/src/assembly/travis REPORT_DIR: target/site/jacoco @@ -39,10 +40,10 @@ jobs: strategy: fail-fast: false matrix: - BACKEND: [ memory, rocksdb, hbase ] - JAVA_VERSION: [ '11' ] + BACKEND: [ memory ] + JAVA_VERSION: &server-java-versions [ '11' ] - steps: + steps: &server-steps - name: Checkout uses: actions/checkout@v4 with: @@ -177,6 +178,34 @@ jobs: disable_search: true fail_ci_if_error: false + build-server-backends: + name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) + runs-on: ubuntu-24.04 + env: *server-env + strategy: + fail-fast: false + matrix: + BACKEND: [ rocksdb, hbase ] + JAVA_VERSION: *server-java-versions + steps: *server-steps + + server-memory-required: + # Aggregate every memory JDK without making other backends required. + name: Server memory tests + needs: build-server + if: ${{ always() }} + runs-on: ubuntu-24.04 + permissions: {} + steps: + - name: Require successful memory tests + env: + RESULT: ${{ needs.build-server.result }} + run: | + if [ "$RESULT" != "success" ]; then + echo "::error::Server memory tests ended with: $RESULT" + exit 1 + fi + build-server-macos-rocksdb: runs-on: ${{ matrix.os }} strategy: From af399afa8e3dd85ff01a891e77111461a424310e Mon Sep 17 00:00:00 2001 From: imbajin Date: Sun, 4 Oct 2026 16:03:23 +0800 Subject: [PATCH 2/3] refactor: clarify memory CI workflow - name memory and optional backend jobs explicitly - group the memory tests with their stable result gate - explain shared Linux configuration and migration constraints --- .asf.yaml | 3 +- .github/workflows/server-ci.yml | 51 +++++++++++++++++++-------------- 2 files changed, 31 insertions(+), 23 deletions(-) diff --git a/.asf.yaml b/.asf.yaml index 24f5d72069..39b9cb32bf 100644 --- a/.asf.yaml +++ b/.asf.yaml @@ -41,7 +41,8 @@ github: - Analyze (java) - CodeQL - check-license - # Stable across JDK upgrades; Commons still runs as an optional check. + # Require the fixed memory result gate, independent of the runtime JDK list. + # Commons CI continues to run without blocking merges. - Server memory tests required_pull_request_reviews: dismiss_stale_reviews: true diff --git a/.github/workflows/server-ci.yml b/.github/workflows/server-ci.yml index 6fd0fd354e..11c77a55e9 100644 --- a/.github/workflows/server-ci.yml +++ b/.github/workflows/server-ci.yml @@ -22,10 +22,12 @@ jobs: - name: Run wait-storage.sh peer failover tests run: hugegraph-server/hugegraph-dist/src/assembly/travis/test-wait-storage.sh - # Keep the legacy memory check name until the new protection context is active. - build-server: + # Required coverage: memory on every configured JDK. + # Keep the old check display name so this Java 11 PR satisfies current protection. + build-server-memory: + name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) runs-on: ubuntu-24.04 - env: &server-env + env: &linux-server-env USE_STAGE: 'false' # Whether to include the stage repository. TRAVIS_DIR: hugegraph-server/hugegraph-dist/src/assembly/travis REPORT_DIR: target/site/jacoco @@ -41,9 +43,11 @@ jobs: fail-fast: false matrix: BACKEND: [ memory ] - JAVA_VERSION: &server-java-versions [ '11' ] + # Change this shared list for Linux JDK upgrades; the required check name stays fixed. + JAVA_VERSION: &linux-server-jdks [ '11' ] - steps: &server-steps + # YAML & defines shared configuration; * reuses it in the optional backend job below. + steps: &linux-server-steps - name: Checkout uses: actions/checkout@v4 with: @@ -178,34 +182,37 @@ jobs: disable_search: true fail_ci_if_error: false - build-server-backends: - name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) - runs-on: ubuntu-24.04 - env: *server-env - strategy: - fail-fast: false - matrix: - BACKEND: [ rocksdb, hbase ] - JAVA_VERSION: *server-java-versions - steps: *server-steps - server-memory-required: - # Aggregate every memory JDK without making other backends required. + # This is the only Server check referenced by .asf.yaml; keep its name stable. name: Server memory tests - needs: build-server + needs: build-server-memory + # Without always(), an upstream failure/skip would skip this gate too. if: ${{ always() }} runs-on: ubuntu-24.04 permissions: {} steps: - - name: Require successful memory tests + - name: Require all memory tests to pass env: - RESULT: ${{ needs.build-server.result }} + MEMORY_RESULT: ${{ needs.build-server-memory.result }} run: | - if [ "$RESULT" != "success" ]; then - echo "::error::Server memory tests ended with: $RESULT" + if [ "$MEMORY_RESULT" != "success" ]; then + echo "::error::Memory test matrix must succeed; got: $MEMORY_RESULT" exit 1 fi + # Optional coverage uses the same Linux environment, JDK list and test steps. + # Keep it separate so backend failures do not become required memory failures. + build-server-backends: + name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) + runs-on: ubuntu-24.04 + env: *linux-server-env + strategy: + fail-fast: false + matrix: + BACKEND: [ rocksdb, hbase ] + JAVA_VERSION: *linux-server-jdks + steps: *linux-server-steps + build-server-macos-rocksdb: runs-on: ${{ matrix.os }} strategy: From bf4bfdd4791a39755ab2c784a4b753e42d43b848 Mon Sep 17 00:00:00 2001 From: imbajin Date: Sun, 4 Oct 2026 21:27:29 +0800 Subject: [PATCH 3/3] fix: modernize CI runtime configuration - Centralize the project JDK and generate validated test matrices - Fail required and legacy result checks on runtime or test skips - Refresh Actions runtimes and use native Maven dependency caching - Trigger affected workflows when the shared runtime file changes --- .github/workflows/.java-version | 1 + .github/workflows/auto-pr-review.yml | 2 +- .github/workflows/check-dependencies.yml | 13 ++-- .github/workflows/cluster-test-ci.yml | 24 +++--- .github/workflows/codeql-analysis.yml | 12 +-- .github/workflows/commons-ci.yml | 50 ++++++++---- .github/workflows/docker-build-ci.yml | 4 +- .github/workflows/java-runtime.yml | 69 +++++++++++++++++ .github/workflows/licence-checker.yml | 2 +- .github/workflows/pd-store-ci.yml | 99 ++++++++++-------------- .github/workflows/riscv64-ci.yml | 4 +- .github/workflows/server-ci.yml | 90 +++++++++++---------- .github/workflows/stale.yml | 4 +- 13 files changed, 228 insertions(+), 146 deletions(-) create mode 100644 .github/workflows/.java-version create mode 100644 .github/workflows/java-runtime.yml diff --git a/.github/workflows/.java-version b/.github/workflows/.java-version new file mode 100644 index 0000000000..b4de394767 --- /dev/null +++ b/.github/workflows/.java-version @@ -0,0 +1 @@ +11 diff --git a/.github/workflows/auto-pr-review.yml b/.github/workflows/auto-pr-review.yml index 6a585355f7..df4bfeb690 100644 --- a/.github/workflows/auto-pr-review.yml +++ b/.github/workflows/auto-pr-review.yml @@ -28,7 +28,7 @@ jobs: pull-requests: write steps: - name: Add review comment - uses: peter-evans/create-or-update-comment@v4 + uses: peter-evans/create-or-update-comment@v5 with: issue-number: ${{ github.event.pull_request.number }} body: | diff --git a/.github/workflows/check-dependencies.yml b/.github/workflows/check-dependencies.yml index 23efa75ddb..fc6de5b560 100644 --- a/.github/workflows/check-dependencies.yml +++ b/.github/workflows/check-dependencies.yml @@ -8,6 +8,7 @@ on: pull_request: # Keep source/resources and shared build inputs; skip named documentation files. paths: + - '.github/workflows/.java-version' - '**/pom.xml' - '.mvn/**' - '.github/configs/**' @@ -29,12 +30,12 @@ jobs: SCRIPT_DEPENDENCY: install-dist/scripts/dependency steps: - name: Checkout source - uses: actions/checkout@v4 - - name: Set up JDK 11 - uses: actions/setup-java@v3 + uses: actions/checkout@v7 + - name: Set up project JDK + uses: actions/setup-java@v6 with: - java-version: '11' - distribution: 'adopt' + java-version-file: .github/workflows/.java-version + distribution: 'temurin' - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} @@ -56,7 +57,7 @@ jobs: runs-on: ubuntu-latest steps: - name: 'Checkout Repository' - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: 'Dependency Review' uses: actions/dependency-review-action@v5 # Refer: https://github.com/actions/dependency-review-action diff --git a/.github/workflows/cluster-test-ci.yml b/.github/workflows/cluster-test-ci.yml index c2972cb9f9..3edcfcb874 100644 --- a/.github/workflows/cluster-test-ci.yml +++ b/.github/workflows/cluster-test-ci.yml @@ -9,6 +9,7 @@ on: pull_request: # Keep source/resources and shared build inputs; skip named documentation files. paths: + - '.github/workflows/.java-version' - 'pom.xml' - '.mvn/**' - 'style/**' @@ -33,24 +34,19 @@ jobs: USE_STAGE: 'false' # Whether to include the stage repository. steps: - - name: Install JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2 - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 + - name: Install project JDK + uses: actions/setup-java@v6 + with: + java-version-file: .github/workflows/.java-version + distribution: 'zulu' + cache: maven + cache-jdk: false + - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} run: | diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index d66dc8cee9..23f1807dc2 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -27,13 +27,13 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Setup Java JDK - uses: actions/setup-java@v3 + uses: actions/setup-java@v6 with: distribution: 'zulu' - java-version: '11' + java-version-file: .github/workflows/.java-version - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} @@ -43,7 +43,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -54,7 +54,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 # â„šī¸ Command-line programs to run using the OS shell. # 📚 https://git.io/JvXDl @@ -68,4 +68,4 @@ jobs: # make release - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 diff --git a/.github/workflows/commons-ci.yml b/.github/workflows/commons-ci.yml index fd01df1825..0e7d4d8d95 100644 --- a/.github/workflows/commons-ci.yml +++ b/.github/workflows/commons-ci.yml @@ -10,7 +10,14 @@ on: pull_request: jobs: + java-runtime: + uses: ./.github/workflows/java-runtime.yml + permissions: + contents: read + build-commons: + name: Commons tests (Java ${{ matrix.JAVA_VERSION }}) + needs: java-runtime runs-on: ubuntu-latest env: USE_STAGE: 'false' # Whether to include the stage repository. @@ -18,26 +25,21 @@ jobs: strategy: fail-fast: false matrix: - JAVA_VERSION: ['11'] + JAVA_VERSION: ${{ fromJSON(needs.java-runtime.outputs.versions || '["unavailable"]') }} steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 2 + - name: Install JDK ${{ matrix.JAVA_VERSION }} - uses: actions/setup-java@v3 + uses: actions/setup-java@v6 with: java-version: ${{ matrix.JAVA_VERSION }} distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2 - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - - name: Checkout - uses: actions/checkout@v3 - with: - fetch-depth: 2 + cache: maven + cache-jdk: false - name: Use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} @@ -58,9 +60,27 @@ jobs: mvn test -pl hugegraph-commons/hugegraph-rpc -Dtest=UnitTestSuite -DskipCommonsTests=false - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: hugegraph-commons/target/jacoco.xml disable_search: true fail_ci_if_error: false + + # Temporary compatibility check; Commons becomes optional when .asf.yaml takes effect. + legacy-commons-required: + name: build-commons (11) + needs: [ java-runtime, build-commons ] + if: ${{ always() }} + runs-on: ubuntu-24.04 + permissions: {} + steps: + - name: Require the runtime configuration and all Commons tests to pass + env: + RUNTIME_RESULT: ${{ needs.java-runtime.result }} + COMMONS_RESULT: ${{ needs.build-commons.result }} + run: | + if [ "$RUNTIME_RESULT" != "success" ] || [ "$COMMONS_RESULT" != "success" ]; then + echo "::error::Runtime configuration: $RUNTIME_RESULT; Commons tests: $COMMONS_RESULT" + exit 1 + fi diff --git a/.github/workflows/docker-build-ci.yml b/.github/workflows/docker-build-ci.yml index 97e2d37a41..90d1c5610f 100644 --- a/.github/workflows/docker-build-ci.yml +++ b/.github/workflows/docker-build-ci.yml @@ -49,7 +49,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Verify shared Maven stages stay identical shell: bash @@ -121,7 +121,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Build ${{ matrix.dockerfile }} run: | diff --git a/.github/workflows/java-runtime.yml b/.github/workflows/java-runtime.yml new file mode 100644 index 0000000000..3dbb207090 --- /dev/null +++ b/.github/workflows/java-runtime.yml @@ -0,0 +1,69 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one or more +# contributor license agreements. See the NOTICE file distributed with +# this work for additional information regarding copyright ownership. +# The ASF licenses this file to You under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance with +# the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +name: CI Java runtime + +on: + workflow_call: + inputs: + extra-java-versions: + description: Additional JDKs to test alongside the configured project runtime (JSON array). + type: string + default: '[]' + outputs: + versions: + description: Project runtime followed by any additional test JDKs (JSON array). + value: ${{ jobs.read-version.outputs.versions }} + +permissions: + contents: read + +jobs: + read-version: + runs-on: ubuntu-24.04 + outputs: + versions: ${{ steps.java.outputs.versions }} + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + persist-credentials: false + + - name: Read the project runtime and optional test JDKs + id: java + env: + EXTRA_JAVA_VERSIONS: ${{ inputs.extra-java-versions }} + run: | + python3 - <<'PYTHON' + import json + import os + import re + from pathlib import Path + + runtime = Path('.github/workflows/.java-version').read_text().strip() + extra = json.loads(os.environ['EXTRA_JAVA_VERSIONS']) + if not isinstance(extra, list): + raise ValueError('extra-java-versions must be a JSON array') + versions = [] + for version in [runtime, *extra]: + if not isinstance(version, str) or not re.fullmatch(r'[1-9][0-9]*(\.[0-9]+)*', version): + raise ValueError('Java versions must be non-empty numeric strings') + if version not in versions: + versions.append(version) + with open(os.environ['GITHUB_OUTPUT'], 'a') as output: + print('versions=' + json.dumps(versions), file=output) + PYTHON diff --git a/.github/workflows/licence-checker.yml b/.github/workflows/licence-checker.yml index a6e6990a64..3d36ad4597 100644 --- a/.github/workflows/licence-checker.yml +++ b/.github/workflows/licence-checker.yml @@ -13,7 +13,7 @@ jobs: env: USE_STAGE: 'false' # Whether to include the stage repository. steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Check License Header uses: apache/skywalking-eyes@main diff --git a/.github/workflows/pd-store-ci.yml b/.github/workflows/pd-store-ci.yml index 79217cfc58..a52af6c5ad 100644 --- a/.github/workflows/pd-store-ci.yml +++ b/.github/workflows/pd-store-ci.yml @@ -9,6 +9,7 @@ on: pull_request: # Keep source/resources and shared build inputs; skip named documentation files. paths: + - '.github/workflows/.java-version' - 'pom.xml' - '.mvn/**' - 'style/**' @@ -33,24 +34,19 @@ jobs: env: USE_STAGE: 'false' steps: - - name: Install JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 + - name: Install project JDK + uses: actions/setup-java@v6 + with: + java-version-file: .github/workflows/.java-version + distribution: 'zulu' + cache: maven + cache-jdk: false + - name: Run JaCoCo report validator tests run: hugegraph-server/hugegraph-dist/src/assembly/travis/test-check-jacoco-report.sh @@ -93,24 +89,19 @@ jobs: TEST_REPORT_DIR: hugegraph-pd/hg-pd-test/target/surefire-reports steps: - - name: Install JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 + - name: Install project JDK + uses: actions/setup-java@v6 + with: + java-version-file: .github/workflows/.java-version + distribution: 'zulu' + cache: maven + cache-jdk: false + - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} run: | @@ -213,7 +204,7 @@ jobs: hg-pd-grpc hg-pd-common hg-pd-client hg-pd-core hg-pd-service hg-pd-dist - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: ${{ env.REPORT_FILE }} @@ -231,24 +222,19 @@ jobs: TEST_REPORT_DIR: hugegraph-store/hg-store-test/target/surefire-reports steps: - - name: Install JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 + - name: Install project JDK + uses: actions/setup-java@v6 + with: + java-version-file: .github/workflows/.java-version + distribution: 'zulu' + cache: maven + cache-jdk: false + - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} run: | @@ -357,7 +343,7 @@ jobs: hg-store-grpc hg-store-common hg-store-client hg-store-rocksdb hg-store-core - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: ${{ env.REPORT_FILE }} @@ -375,24 +361,19 @@ jobs: RELEASE_BRANCH: ${{ startsWith(github.ref_name, 'release-') || startsWith(github.ref_name, 'test-') || startsWith(github.base_ref, 'release-') }} steps: - - name: Install JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v3 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 - - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v7 with: fetch-depth: 2 + - name: Install project JDK + uses: actions/setup-java@v6 + with: + java-version-file: .github/workflows/.java-version + distribution: 'zulu' + cache: maven + cache-jdk: false + - name: use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} run: | @@ -433,7 +414,7 @@ jobs: $TRAVIS_DIR/run-tinkerpop-test.sh $BACKEND tinkerpop - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: ${{ env.REPORT_DIR }}/*.xml diff --git a/.github/workflows/riscv64-ci.yml b/.github/workflows/riscv64-ci.yml index 9f8ca12057..51d161a978 100644 --- a/.github/workflows/riscv64-ci.yml +++ b/.github/workflows/riscv64-ci.yml @@ -32,6 +32,8 @@ env: Alibaba_Dragonwell_Extended_11.0.31.28.11_riscv64_linux.tar.gz DRAGONWELL_RISCV64_SHA256: >- 7df2d308f0dca7a779d2854e6da19214f99cd77aa6d4982c3bf981a77266a79b + # This verified vendor artifact stays separate from setup-java's project runtime. + # A RISC-V runtime upgrade must update the archive, URL and checksum together. DRAGONWELL_RISCV64_URL: >- https://github.com/dragonwell-project/dragonwell11/releases/download/dragonwell-extended-11.0.31.28_jdk-11.0.31-ga/Alibaba_Dragonwell_Extended_11.0.31.28.11_riscv64_linux.tar.gz RISCV64_CONTAINER: >- @@ -44,7 +46,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: persist-credentials: false diff --git a/.github/workflows/server-ci.yml b/.github/workflows/server-ci.yml index 11c77a55e9..ef47e8f294 100644 --- a/.github/workflows/server-ci.yml +++ b/.github/workflows/server-ci.yml @@ -9,23 +9,31 @@ on: pull_request: jobs: + java-runtime: + uses: ./.github/workflows/java-runtime.yml + permissions: + contents: read + wait-storage-shell-test: permissions: contents: read runs-on: ubuntu-24.04 steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: persist-credentials: false - name: Run wait-storage.sh peer failover tests run: hugegraph-server/hugegraph-dist/src/assembly/travis/test-wait-storage.sh - # Required coverage: memory on every configured JDK. - # Keep the old check display name so this Java 11 PR satisfies current protection. - build-server-memory: - name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) + # Required coverage: memory on the project runtime and any additional test JDKs. + # The shared runtime comes from .github/workflows/.java-version, independent of bytecode targets. + # Keep the job ID for the Codecov configuration validator. + # The old required check name is provided by the temporary result job below. + build-server: + needs: java-runtime + name: Server memory (Java ${{ matrix.JAVA_VERSION }}) runs-on: ubuntu-24.04 env: &linux-server-env USE_STAGE: 'false' # Whether to include the stage repository. @@ -43,19 +51,19 @@ jobs: fail-fast: false matrix: BACKEND: [ memory ] - # Change this shared list for Linux JDK upgrades; the required check name stays fixed. - JAVA_VERSION: &linux-server-jdks [ '11' ] + # Keep the graph evaluable when the reader fails; result checks still reject skips. + JAVA_VERSION: ${{ fromJSON(needs.java-runtime.outputs.versions || '["unavailable"]') }} # YAML & defines shared configuration; * reuses it in the optional backend job below. steps: &linux-server-steps - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 # TODO: Remove this step after install-backend.sh updated - name: Install Java8 for backend - uses: actions/setup-java@v4 + uses: actions/setup-java@v6 with: java-version: '8' distribution: 'zulu' @@ -65,17 +73,12 @@ jobs: $TRAVIS_DIR/install-backend.sh $BACKEND && jps -l - name: Install Java ${{ matrix.JAVA_VERSION }} - uses: actions/setup-java@v4 + uses: actions/setup-java@v6 with: java-version: ${{ matrix.JAVA_VERSION }} distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v4 - with: - path: ~/.m2 - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 + cache: maven + cache-jdk: false - name: Use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} @@ -175,7 +178,7 @@ jobs: $TRAVIS_DIR/run-tinkerpop-test.sh $BACKEND tinkerpop - name: Upload coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: ${{ env.REPORT_DIR }}/*.xml @@ -185,24 +188,37 @@ jobs: server-memory-required: # This is the only Server check referenced by .asf.yaml; keep its name stable. name: Server memory tests - needs: build-server-memory - # Without always(), an upstream failure/skip would skip this gate too. + needs: [ java-runtime, build-server ] + # Always evaluate results, including dependency failures and unexpected skips. if: ${{ always() }} runs-on: ubuntu-24.04 permissions: {} - steps: - - name: Require all memory tests to pass - env: - MEMORY_RESULT: ${{ needs.build-server-memory.result }} + env: &memory-results + RUNTIME_RESULT: ${{ needs.java-runtime.result }} + MEMORY_RESULT: ${{ needs.build-server.result }} + steps: &require-memory-success + - name: Require the runtime configuration and all memory tests to pass run: | - if [ "$MEMORY_RESULT" != "success" ]; then - echo "::error::Memory test matrix must succeed; got: $MEMORY_RESULT" + if [ "$RUNTIME_RESULT" != "success" ] || [ "$MEMORY_RESULT" != "success" ]; then + echo "::error::Runtime configuration: $RUNTIME_RESULT; memory tests: $MEMORY_RESULT" exit 1 fi - # Optional coverage uses the same Linux environment, JDK list and test steps. + # Temporary alias for live protection. Remove after ASF activates the stable context. + # Reuse the real result check so a skipped matrix cannot satisfy the old requirement. + legacy-server-memory-required: + name: build-server (memory, 11) + needs: [ java-runtime, build-server ] + if: ${{ always() }} + runs-on: ubuntu-24.04 + permissions: {} + env: *memory-results + steps: *require-memory-success + + # Optional coverage uses the same Linux environment, resolved JDKs and test steps. # Keep it separate so backend failures do not become required memory failures. build-server-backends: + needs: java-runtime name: build-server (${{ matrix.BACKEND }}, ${{ matrix.JAVA_VERSION }}) runs-on: ubuntu-24.04 env: *linux-server-env @@ -210,7 +226,7 @@ jobs: fail-fast: false matrix: BACKEND: [ rocksdb, hbase ] - JAVA_VERSION: *linux-server-jdks + JAVA_VERSION: ${{ fromJSON(needs.java-runtime.outputs.versions || '["unavailable"]') }} steps: *linux-server-steps build-server-macos-rocksdb: @@ -228,27 +244,21 @@ jobs: TRAVIS_DIR: hugegraph-server/hugegraph-dist/src/assembly/travis REPORT_DIR: target/site/jacoco BACKEND: rocksdb - JAVA_VERSION: '11' SERVER_JAVA_OPTIONS: ${{ matrix.server_java_options }} steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 5 - - name: Install Java ${{ env.JAVA_VERSION }} - uses: actions/setup-java@v4 + - name: Install project JDK + uses: actions/setup-java@v6 with: - java-version: ${{ env.JAVA_VERSION }} + java-version-file: .github/workflows/.java-version distribution: 'zulu' - - - name: Cache Maven packages - uses: actions/cache@v4 - with: - path: ~/.m2 - key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} - restore-keys: ${{ runner.os }}-m2 + cache: maven + cache-jdk: false - name: Use staged maven repo settings if: ${{ env.USE_STAGE == 'true' }} diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 4f8484ce69..5c50204aef 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -13,9 +13,11 @@ jobs: pull-requests: write steps: - - uses: actions/stale@v3 + - uses: actions/stale@v11 with: repo-token: ${{ secrets.GITHUB_TOKEN }} + # Preserve the old issue-close classification across the action upgrade. + close-issue-reason: completed stale-issue-message: 'Due to the lack of activity, the current issue is marked as stale and will be closed after 20 days, any update will remove the stale label' stale-pr-message: 'Due to the lack of activity, the current pr is marked as stale and will be closed after 180 days, any update will remove the stale label' stale-issue-label: 'inactive'