Skip to content

ci: gate expensive jobs on 'ci-approved' label for fork PRs - #1232

Closed
CatherineSue wants to merge 1 commit into
mainfrom
fix/ci-remove-pull-request-target
Closed

CatherineSue wants to merge 1 commit into
mainfrom
fix/ci-remove-pull-request-target

Conversation

@CatherineSue

@CatherineSue CatherineSue commented Apr 17, 2026 •

Copy link
Copy Markdown
Member

Description

Problem

After #1175 reverted pull_request_target and removed the ci-approved gate entirely, fork PRs that pass the one-time "Approve and run" check now run the full expensive tier on every push — GPU runners (build-wheel, benchmarks, all e2e-*, go-bindings-e2e) and paid third-party APIs (e2e-vendor hits Anthropic, OpenAI, xAI). That's uncapped cost exposure on approved-but-not-yet-reviewed fork contributions.

Solution

Gate the first-tier expensive job (build-wheel) on a ci-approved label for fork PRs. Everything downstream inherits the gate via needs: build-wheel. Internal (non-fork) PRs run unconditionally — no behavior change for maintainers.

Minimal, additive change only. Does not reintroduce pull_request_target, the prior ci-gate job, or any labeled-type trigger.

Changes

  • pr-test-rust.yml — single if: on build-wheel:
    if: >-
      !github.event.pull_request.head.repo.fork ||
      contains(github.event.pull_request.labels.*.name, 'ci-approved')

Behavior matrix:

PR type ci-approved label build-wheel + downstream
Internal (not fork) — runs
Fork absent skipped
Fork present runs

Trigger timing for fork PRs

Adding the ci-approved label alone does not re-trigger CI (this PR intentionally does not add labeled to types:, to avoid skipped-run noise on unrelated labels). To kick off expensive jobs after labeling:

  • Contributor pushes another commit (synchronize event fires, if: picks up the label), or
  • Maintainer clicks "Re-run all jobs" in the Actions UI.

Recommended companion setting (repo admin)

Settings → Actions → General → Fork pull request workflows from outside collaborators: change from "Require approval for all outside collaborators" to "Require approval for first-time contributors". Without this, returning fork contributors still need a manual "Approve and run" click on every push.

Test Plan

  • This PR's own CI runs normally (internal PR; if: short-circuits on !fork == true).
  • Post-merge: on the next fork PR without ci-approved, verify build-wheel and everything downstream show as skipped.
  • Post-merge: add ci-approved to that fork PR and verify (after a new push or manual Re-run) the full tier runs.
Checklist
  • cargo +nightly fmt passes (N/A — YAML-only change)
  • cargo clippy --all-targets --all-features -- -D warnings passes (N/A — YAML-only change)
  • (Optional) Documentation updated
  • (Optional) Please join us on Slack #sig-smg to discuss, review, and merge PRs

Summary by CodeRabbit

  • Chores
    • Updated CI/CD workflow configuration to optimize testing efficiency for pull requests based on approval status and repository context.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@github-actions github-actions Bot added the ci CI/CD configuration changes label Apr 17, 2026
@coderabbitai

coderabbitai Bot commented Apr 17, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Updated GitHub Actions workflow configuration in .github/workflows/pr-test-rust.yml to add conditional gating for the build-wheel job. The job now executes on fork PRs only when labeled with ci-approved, while non-fork PRs run without this restriction.

Changes

Cohort / File(s) Summary
GitHub Actions Workflow Configuration
.github/workflows/pr-test-rust.yml
Added conditional gating to build-wheel job to require ci-approved label for fork PRs while allowing unrestricted execution for non-fork PRs.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~5 minutes

Possibly related PRs

Suggested reviewers

  • key4ng
  • slin1237
  • XinyueZhang369

Poem

🐰 A gate for the forks, a guard at the door,
No rushing the builds without labels adore!
The ci-approved stamp, a ticket so bright,
While upstream PRs still flow left and right.
Hops approvingly ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: gating expensive CI jobs on the 'ci-approved' label for fork PRs, which is exactly what the raw summary and PR objectives describe.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/ci-remove-pull-request-target

Comment @coderabbitai help to get the list of available commands and usage tips.

@mergify

mergify Bot commented Apr 17, 2026

Copy link
Copy Markdown
Contributor

Hi @CatherineSue, this PR has merge conflicts that must be resolved before it can be merged. Please rebase your branch:

git fetch origin main
git rebase origin/main
# resolve any conflicts, then:
git push --force-with-lease

@mergify mergify Bot added the needs-rebase PR has merge conflicts that need to be resolved label Apr 17, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c188c84193

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/pr-test-rust.yml Outdated
Comment on lines +43 to +45
github.event_name != 'pull_request' ||
github.event.action != 'labeled' ||
github.event.label.name == 'ci-approved'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep ci-gate open when ci-approved PR gets other labels

This gate now only passes on labeled events when the newly added label is exactly ci-approved, so a PR that is already approved can still have the entire workflow skipped if any other label is added. With the workflow’s concurrency.cancel-in-progress: true, that skipped run can cancel an in-flight synchronize run and leave the latest commit with only skipped checks and no replacement test run. Previously the gate used contains(..., 'ci-approved'), so once approved, additional labels did not suppress CI.

Useful? React with 👍 / 👎.

Adds an if: condition on build-wheel that skips expensive GPU and paid-API
jobs for fork PRs unless they carry the 'ci-approved' label. Internal PRs
run unconditionally.

build-wheel is the first-tier expensive job; benchmarks, e2e-* (1/2/4-GPU),
e2e-vendor (paid Anthropic/OpenAI/xAI APIs), python-unit-tests,
go-unit-tests, and go-bindings-e2e all inherit the gate transitively
through their needs: build-wheel chain.

Does not reintroduce pull_request_target or the prior ci-gate job (both
reverted in #1175). To kick off expensive jobs on a fork PR after adding
the label: wait for the contributor's next push (synchronize event), or
click "Re-run all jobs" in the Actions UI.

Recommended companion setting (repo admin): Settings -> Actions -> General
-> Fork pull request workflows from outside collaborators: change to
"Require approval for first-time contributors" so returning fork
contributors don't need the manual approve-and-run click on every push.

Signed-off-by: Chang Su <chang.s.su@oracle.com>
@CatherineSue
CatherineSue force-pushed the fix/ci-remove-pull-request-target branch from c188c84 to 1789cd0 Compare April 17, 2026 16:59
@CatherineSue CatherineSue changed the title ci: remove pull_request_target, gate expensive jobs on ci-approved label ci: gate expensive jobs on 'ci-approved' label for fork PRs Apr 17, 2026
@mergify mergify Bot removed the needs-rebase PR has merge conflicts that need to be resolved label Apr 17, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1789cd065b

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/pr-test-rust.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/pr-test-rust.yml:
- Around line 106-113: The build-wheel job is missing cheap-tier dependencies,
allowing expensive work to run before quick prechecks finish; update the
workflow so the build-wheel job (job id "build-wheel") includes a needs: array
referencing the cheap precheck jobs (e.g., "pre-commit", "python-lint",
"grpc-proto-build-check", "unit-tests") so it only runs after those succeed,
preserving the intended fail-fast/cost gate.
- Around line 106-113: The workflow's fork-PR gate (the if: condition using
contains(github.event.pull_request.labels.*.name, 'ci-approved')) won't
self-unblock because the workflow doesn't listen for pull_request labeled
events; update the workflow's triggers so pull_request includes types: [opened,
synchronize, reopened, labeled] (or add labeled to the existing types list) so
that adding the 'ci-approved' label will re-run the workflow and allow the
contains(...) check to evaluate; ensure the change is made where pull_request
types are declared in the YAML.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: af523fba-5050-4783-851d-72e02a6c8072

📥 Commits

Reviewing files that changed from the base of the PR and between c188c84 and 1789cd0.

📒 Files selected for processing (1)
  • .github/workflows/pr-test-rust.yml

Comment thread .github/workflows/pr-test-rust.yml
@lightseek-bot
lightseek-bot deleted the fix/ci-remove-pull-request-target branch April 17, 2026 23:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant