Skip to content

Conversation

@yuanjingx87
Copy link
Collaborator

@yuanjingx87 yuanjingx87 commented Sep 16, 2025

Summary by CodeRabbit

  • Chores
    • Expanded CI authorization to include additional trusted contributors, allowing them to trigger and pass workflow checks without manual intervention.
    • Improves contributor onboarding and speeds up review cycles by reducing approval bottlenecks in automated checks.
    • No impact on application features, behavior, or user experience.

Description

Test Coverage

PR Checklist

Please review the following before submitting your PR:

  • PR description clearly explains what and why. If using CodeRabbit's summary, please make sure it makes sense.

  • PR Follows TRT-LLM CODING GUIDELINES to the best of your knowledge.

  • Test cases are provided for new code paths (see test instructions)

  • Any new dependencies have been scanned for license and vulnerabilities

  • CODEOWNERS updated if ownership changes

  • Documentation updated as needed

  • The reviewers assigned automatically/manually are appropriate for the PR.

  • Please check this after reviewing the above items as appropriate for this PR.

GitHub Bot Help

/bot [-h] ['run', 'kill', 'skip', 'reuse-pipeline'] ...

Provide a user friendly way for developers to interact with a Jenkins server.

Run /bot [-h|--help] to print this help message.

See details below for each supported subcommand.

run [--reuse-test (optional)pipeline-id --disable-fail-fast --skip-test --stage-list "A10-PyTorch-1, xxx" --gpu-type "A30, H100_PCIe" --test-backend "pytorch, cpp" --add-multi-gpu-test --only-multi-gpu-test --disable-multi-gpu-test --post-merge --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" --detailed-log --debug(experimental)]

Launch build/test pipelines. All previously running jobs will be killed.

--reuse-test (optional)pipeline-id (OPTIONAL) : Allow the new pipeline to reuse build artifacts and skip successful test stages from a specified pipeline or the last pipeline if no pipeline-id is indicated. If the Git commit ID has changed, this option will be always ignored. The DEFAULT behavior of the bot is to reuse build artifacts and successful test results from the last pipeline.

--disable-reuse-test (OPTIONAL) : Explicitly prevent the pipeline from reusing build artifacts and skipping successful test stages from a previous pipeline. Ensure that all builds and tests are run regardless of previous successes.

--disable-fail-fast (OPTIONAL) : Disable fail fast on build/tests/infra failures.

--skip-test (OPTIONAL) : Skip all test stages, but still run build stages, package stages and sanity check stages. Note: Does NOT update GitHub check status.

--stage-list "A10-PyTorch-1, xxx" (OPTIONAL) : Only run the specified test stages. Examples: "A10-PyTorch-1, xxx". Note: Does NOT update GitHub check status.

--gpu-type "A30, H100_PCIe" (OPTIONAL) : Only run the test stages on the specified GPU types. Examples: "A30, H100_PCIe". Note: Does NOT update GitHub check status.

--test-backend "pytorch, cpp" (OPTIONAL) : Skip test stages which don't match the specified backends. Only support [pytorch, cpp, tensorrt, triton]. Examples: "pytorch, cpp" (does not run test stages with tensorrt or triton backend). Note: Does NOT update GitHub pipeline status.

--only-multi-gpu-test (OPTIONAL) : Only run the multi-GPU tests. Note: Does NOT update GitHub check status.

--disable-multi-gpu-test (OPTIONAL) : Disable the multi-GPU tests. Note: Does NOT update GitHub check status.

--add-multi-gpu-test (OPTIONAL) : Force run the multi-GPU tests in addition to running L0 pre-merge pipeline.

--post-merge (OPTIONAL) : Run the L0 post-merge pipeline instead of the ordinary L0 pre-merge pipeline.

--extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" (OPTIONAL) : Run the ordinary L0 pre-merge pipeline and specified test stages. Examples: --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx".

--detailed-log (OPTIONAL) : Enable flushing out all logs to the Jenkins console. This will significantly increase the log volume and may slow down the job.

--debug (OPTIONAL) : Experimental feature. Enable access to the CI container for debugging purpose. Note: Specify exactly one stage in the stage-list parameter to access the appropriate container environment. Note: Does NOT update GitHub check status.

For guidance on mapping tests to stage names, see docs/source/reference/ci-overview.md
and the scripts/test_to_stage_mapping.py helper.

kill

kill

Kill all running builds associated with pull request.

skip

skip --comment COMMENT

Skip testing for latest commit on pull request. --comment "Reason for skipping build/test" is required. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

reuse-pipeline

reuse-pipeline

Reuse a previous pipeline to validate current commit. This action will also kill all currently running builds associated with the pull request. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

@yuanjingx87 yuanjingx87 requested review from a team as code owners September 16, 2025 19:58
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Sep 16, 2025

📝 Walkthrough

Walkthrough

The CI workflow at .github/workflows/blossom-ci.yml updates the Authorization job’s gating condition by adding seven GitHub usernames to the allowlist in the contains(fromJson(...), github.actor) check. No other steps, jobs, or logic were altered.

Changes

Cohort / File(s) Summary of Changes
CI Workflow Authorization Allowlist
`.github/workflows/blossom-ci.yml`
Expanded the fromJson(...) array used by contains(..., github.actor) to include: yumin066, sychen52, xxi-nv, barneuman, xuanzic, yufeiwu-nv, richardhuo-nv. No other workflow changes.

Sequence Diagram(s)

sequenceDiagram
    autonumber
    actor Dev as GitHub Actor
    participant GH as GitHub Actions
    participant Auth as Authorization Job
    participant Jobs as Downstream Jobs

    Dev->>GH: Push/PR event
    GH->>Auth: Start Authorization check
    Auth->>Auth: contains(fromJson(allowlist), github.actor)?
    alt Authorized
        Auth-->>Jobs: Proceed
        Jobs->>Jobs: Run remaining workflow
    else Not Authorized
        Auth-->>GH: Stop downstream execution
    end
Loading

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested reviewers

  • schetlur-nv
  • tburt-nv
  • zeroepoch
✨ Finishing touches
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Tip

👮 Agentic pre-merge checks are now available in preview!

Pro plan users can now enable pre-merge checks in their settings to enforce checklists before merging PRs.

  • Built-in checks – Quickly apply ready-made checks to enforce title conventions, require pull request descriptions that follow templates, validate linked issues for compliance, and more.
  • Custom agentic checks – Define your own rules using CodeRabbit’s advanced agentic capabilities to enforce organization-specific policies and workflows. For example, you can instruct CodeRabbit’s agent to verify that API documentation is updated whenever API schema files are modified in a PR. Note: Upto 5 custom checks are currently allowed during the preview period. Pricing for this feature will be announced in a few weeks.

Please see the documentation for more information.

Example:

reviews:
  pre_merge_checks:
    custom_checks:
      - name: "Undocumented Breaking Changes"
        mode: "warning"
        instructions: |
          Pass/fail criteria: All breaking changes to public APIs, CLI flags, environment variables, configuration keys, database schemas, or HTTP/GraphQL endpoints must be documented in the "Breaking Change" section of the PR description and in CHANGELOG.md. Exclude purely internal or private changes (e.g., code not exported from package entry points or explicitly marked as internal).

Please share your feedback with us on this Discord post.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Pre-merge checks

❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Description Check ⚠️ Warning The PR body contains only the repository's PR template with empty "Description" and "Test Coverage" sections and no concise explanation of what changed, why, or which files are affected. The PR metadata shows the title "Update CI allowlist 2025-09-16" but reviewers must inspect diffs to learn that .github/workflows/blossom-ci.yml was modified. Required checklist items, explicit test plans, and risk/impact notes are missing, preventing a proper pre-merge assessment. Please update the PR description to fully follow the repository template by adding a clear Description that lists the exact file(s) changed and reason for the change, a Test Coverage section describing how the change is validated and any CI implications, and complete the PR checklist. Explicitly state the precise additions (the seven handles added to the allowlist: yumin066, sychen52, xxi-nv, barneuman, xuanzic, yufeiwu-nv, richardhuo-nv), add reviewer suggestions and any risk/rollback notes, and link to a related issue or ticket if available so reviewers can assess impact quickly.
✅ Passed checks (2 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changes. Docstring coverage check skipped.
Title Check ✅ Passed The PR title "[None][infra] Update CI allowlist 2025-09-16" is concise, follows the repository's [ticket][type] pattern, and accurately summarizes the primary change (updating the CI allowlist), so it correctly reflects the changeset.

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (4)
.github/workflows/blossom-ci.yml (4)

43-44: Deduplicate allowlist entries to avoid bloat and review noise.

Detected duplicates: "heyuhhh" (appears twice) and "ixlmar" (appears twice). Please remove the extra occurrences. The condition still works, but duplicates add churn and risk of future merge conflicts.


39-44: Externalize the allowlist to a repo/org variable for maintainability.

Define a JSON array variable (e.g., BLOSSOM_AUTH_USERS) and reference it here. This avoids massive diffs for every update and enables out‑of‑band changes via settings.

Apply pattern example:

 jobs:
   Authorization:
     name: Authorization
+    env:
+      AUTH_USERS_JSON: ${{ vars.BLOSSOM_AUTH_USERS || '[]' }}
     runs-on: blossom
@@
-        startsWith(github.event.comment.body, '/bot kill')) && contains(
-        fromJson('["byshiue", "...", "richardhuo-nv"]'),
-        github.actor)
+        startsWith(github.event.comment.body, '/bot kill')) &&
+        contains(fromJson(env.AUTH_USERS_JSON), github.actor)

Ensure the repo/org variable is created before merging.


58-60: Upgrade and pin actions/checkout for supply‑chain hygiene.

actions/checkout@v2 is outdated. Recommend v4 with SHA pinning (GitHub’s guidance) to reduce tampering risk.

Apply:

-        uses: actions/checkout@v2
+        uses: actions/checkout@v4
+# Optionally pin to a commit SHA for defense-in-depth:
+#       uses: actions/checkout@<commit-sha>

66-66: Pin blossom action to a tag or SHA.

Using @main is mutable. Pin to a version tag or commit SHA to ensure reproducible runs.

-        uses: NVIDIA/blossom-action@main
+        uses: NVIDIA/[email protected]
+# or
+#       uses: NVIDIA/blossom-action@<commit-sha>
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 471723b and 0e38af4.

📒 Files selected for processing (1)
  • .github/workflows/blossom-ci.yml (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
  • GitHub Check: Pre-commit Check
🔇 Additional comments (1)
.github/workflows/blossom-ci.yml (1)

43-43: Verified: newly added GitHub handles exist and canonical casing matches.
contains() is case‑sensitive — confirmed the seven logins exist with canonical casings: yumin066, sychen52, xxi-nv, barneuman, xuanzic, yufeiwu-nv, richardhuo-nv.

@yuanjingx87 yuanjingx87 changed the title Update CI allowlist 2025-09-16 [None][infra] Update CI allowlist 2025-09-16 Sep 16, 2025
@yuanjingx87
Copy link
Collaborator Author

/bot skip --comment "no need to run CI"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18828 [ skip ] triggered by Bot

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18828 [ skip ] completed with state SUCCESS
Skipping testing for commit 0e38af4

@yuanjingx87 yuanjingx87 merged commit 88d9d77 into NVIDIA:main Sep 16, 2025
6 of 11 checks passed
yuanjingx87 added a commit that referenced this pull request Sep 18, 2025
Wong4j pushed a commit to Wong4j/TensorRT-LLM that referenced this pull request Sep 20, 2025
MrGeva pushed a commit to nv-auto-deploy/TensorRT-LLM that referenced this pull request Sep 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants