Skip to content

feat(deps): Validate dependency pins against the pinned Presto commit. - #29

Merged
jackluo923 merged 17 commits into
mainfrom
feat/validate-dep-sync
Jul 28, 2026
Merged

jackluo923 merged 17 commits into
mainfrom
feat/validate-dep-sync

Conversation

@jackluo923

@jackluo923 jackluo923 commented Jul 22, 2026 •

Copy link
Copy Markdown
Member

Description

Several dependency versions in this repository must stay synchronized with the pinned Presto commit, and until now that synchronization was maintained by hand and comment: the pom's Presto-synced version pins (Presto's plugin classloader supplies some packages from the Presto runtime rather than from the plugin, so drift crashes the coordinator when it loads the plugin), and the Velox header pins that must match the Velox tree Presto builds with.

This PR makes all of that automatically checked, and (per review) consolidates where the pin itself lives:

  • The Presto pin is now repo-scoped. G_PRESTO_GIT_URL/G_PRESTO_GIT_TAG move from taskfiles/velox-connector/deps.yaml to the root taskfile.yaml: both connectors and the tools/presto-deps/ scripts consume them, so the velox-scoped location was misleading. deps.yaml keeps only the Velox-only G_*_VERSION header pins.
  • tools/presto-deps/validate-presto-dep-sync.py validates 12 pins — the 4 pom pins against the Presto root pom at G_PRESTO_GIT_TAG (the root pom's dep.* properties are Presto's source of truth; modules such as presto-spi inherit them), and the 8 Velox header pins against the pinned commit's presto-native-execution/velox submodule tree. On drift it fails, naming the pin, both versions, and the exact fix; it never edits anything.
  • The validator is two independent checks: a Presto class and a Velox class, each deriving its inputs from the pin and its own files, runnable without the other.
  • One clone per side: the Presto-side tools (validator + installer) share build/presto-src, seeded with a blobless fetch by whichever runs first; the Velox check clones build/velox-src from the submodule URL in Presto's own .gitmodules. The velox-connector's CMake FetchContent tree stays its own — no cross-cache scavenging.
  • One task: validate-dep-sync is defined once in the root taskfile, next to the pin it guards. The presto-connector build/test tasks and the velox-connector build depend on it via :validate-dep-sync; the packaging build and the standalone validate-deps workflow (pull requests, pushes to main, manual dispatch) invoke the script directly — an out-of-sync pin cannot survive unnoticed.
  • One owner for version checking (per review): the installer's own presto.version re-check was dropped — every path that runs it runs the validator first.

Validation performed

  • All 12 pins pass warm (existing clones, zero network) and cold (empty build directory; both blobless fetches complete in ~7 s).

  • Each class verified in isolation: Presto() alone (4 checks) and Velox() alone (8 checks), confirming the paths are independent.

  • Negative tests: perturbed pins (pom and deps.yaml) fail with the expected suggested value and a non-zero exit:

    Output on failure (jackson.version perturbed to 2.15.4)
    Presto (presto@6e1942b72a9f, 0.299-SNAPSHOT)
      FAIL jackson.version: pom.xml pins 2.15.4 but presto@6e1942b72 ships 2.18.6
           Suggestion: set <jackson.version> to 2.18.6 in presto-connector/pom.xml.
      OK   slice.version: 0.38
      OK   jackson.annotations.version: 2.18.6
      OK   presto.version: 0.299-SNAPSHOT
    Velox (velox@0dbf1731fb6e, presto-native-execution/velox submodule)
      OK   G_DOUBLE_CONVERSION_VERSION: v3.1.5
      OK   G_FAST_FLOAT_VERSION: v8.0.2
      OK   G_FMT_VERSION: 11.2.0
      OK   G_FOLLY_VERSION: v2026.01.05.00
      OK   G_GFLAGS_VERSION: v2.2.2
      OK   G_GLOG_VERSION: v0.6.0
      OK   G_RE2_VERSION: 2024-07-02
      OK   G_XSIMD_VERSION: 10.0.0
    ERROR: 1 of 12 dependency pins out of sync with presto@6e1942b72a9f32191dcd0ba49812f2ac96a25615. Update the files above to match the suggested versions.
    (exit status 1)
    
  • Verified on Python 3.6.8 inside the packaging build-env container.

  • task presto-connector:build and task presto-connector:test (32/32 tests) pass through the root-task wiring, exercising the validator and the installer's relocated pin parsing.

  • task package passes end to end in a cold build-env container: in-container validation (fresh clones), Presto artifact installation from the relocated pin, and all three package formats produced.

  • The validate-deps CI workflow passes on this PR:

    Output on success (CI run)
    Run ./tools/presto-deps/validate-presto-dep-sync.py
    ==> Fetching https://github.com/prestodb/presto.git at 6e1942b72a9f (blobless)...
    Presto (presto@6e1942b72a9f, 0.299-SNAPSHOT)
      OK   jackson.version: 2.18.6
      OK   slice.version: 0.38
      OK   jackson.annotations.version: 2.18.6
      OK   presto.version: 0.299-SNAPSHOT
    ==> Fetching https://github.com/facebookincubator/velox.git at 0dbf1731fb6e (blobless)...
    Velox (velox@0dbf1731fb6e, presto-native-execution/velox submodule)
      OK   G_DOUBLE_CONVERSION_VERSION: v3.1.5
      OK   G_FAST_FLOAT_VERSION: v8.0.2
      OK   G_FMT_VERSION: 11.2.0
      OK   G_FOLLY_VERSION: v2026.01.05.00
      OK   G_GFLAGS_VERSION: v2.2.2
      OK   G_GLOG_VERSION: v0.6.0
      OK   G_RE2_VERSION: 2024-07-02
      OK   G_XSIMD_VERSION: 10.0.0
    All 12 dependency pins are in sync with presto@6e1942b72a9f.
    

Summary by CodeRabbit

  • New Features
    • Added a dependency synchronization validator to ensure Presto/Velox/connector version pins stay consistent.
    • Introduced a validation task and wired it into connector artifact installation and the main build flow.
    • Added a GitHub Actions workflow to run the validation on pull requests, pushes to the main branch, and manual runs.
  • Bug Fixes
    • Improved pre-build checks to fail early when pinned Presto configuration is missing or mismatched, preventing inconsistent builds and test dependencies.

@jackluo923
jackluo923 requested review from a team and 20001020ycx as code owners July 22, 2026 15:55
@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Changes

The change centralizes the pinned Presto repository and commit in taskfile.yaml, adds a Python validator for Presto and Velox dependency consistency, and runs it through CI, connector builds, container builds, and artifact installation.

Dependency validation

Layer / File(s) Summary
Centralized Presto pin contract
taskfile.yaml, taskfiles/velox-connector/deps.yaml, presto-connector/pom.xml
Presto URL and commit values move to the root taskfile, while duplicate references and related comments are updated or removed.
Presto and Velox consistency checks
tools/presto-deps/validate-presto-dep-sync.py
The new CLI resolves pinned Presto and Velox sources, compares Maven and Velox version pins, and reports failures with suggested values.
Build and CI validation entry points
taskfile.yaml, taskfiles/*/main.yaml, tools/build-packages/internal/container/build-artifacts.sh, .github/workflows/validate-deps.yaml
Connector tasks, container builds, and GitHub Actions run dependency validation before build operations.
Presto installer pin-source migration
tools/presto-deps/install-presto-artifacts.sh
The installer reads Presto metadata from the root taskfile, simplifies checkout fetching, and removes the previous POM version verification.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant BuildOrCI
  participant Validator as validate-presto-dep-sync.py
  participant Presto as Pinned Presto checkout
  participant Velox as Pinned Velox tree
  BuildOrCI->>Validator: Run dependency validation
  Validator->>Presto: Read pinned commit and Maven versions
  Validator->>Velox: Read submodule SHA and Velox versions
  Validator-->>BuildOrCI: Return validation status
Loading

Possibly related PRs

Suggested reviewers: 20001020ycx

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: validating dependency pins against the pinned Presto commit.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/validate-dep-sync

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jackluo923
jackluo923 force-pushed the feat/validate-dep-sync branch 2 times, most recently from bb68d9a to 0853437 Compare July 22, 2026 22:45
@jackluo923

Copy link
Copy Markdown
Member Author

@coderabbitai let's run the code review

@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

@jackluo923, I’ll review the changes in #29, with particular attention to validation correctness, offline/clone fallback behavior, build integration, and CI coverage.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jackluo923
jackluo923 force-pushed the feat/validate-dep-sync branch 3 times, most recently from cc0b0dd to fdfc2ee Compare July 23, 2026 06:12
jackluo923 and others added 2 commits July 23, 2026 12:33
Adds tools/presto-deps/validate-presto-dep-sync.py, which checks the pom.xml
Presto-synced version pins against the Presto root pom at G_PRESTO_GIT_TAG,
and the deps.yaml G_*_VERSION header pins against that commit's
presto-native-execution/velox submodule tree. It prints OK/FAIL per pin with a
suggested value and never edits anything; sources come from a local checkout
containing the pinned commit when available, otherwise from blobless shallow
clones under the build directory.

Runs before the presto-connector build/test tasks, the velox-connector build,
and the packaging build, plus a standalone validate-deps workflow on pull
requests and pushes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@jackluo923
jackluo923 changed the base branch from feat/build-pinned-presto to main July 23, 2026 16:33
@jackluo923
jackluo923 force-pushed the feat/validate-dep-sync branch from fdfc2ee to 36d878e Compare July 23, 2026 16:35

@20001020ycx 20001020ycx left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did a pass for everything except validate-presto-dep-sync.py.

Comment thread taskfiles/velox-connector/main.yaml Outdated
Comment thread .github/workflows/validate-deps.yaml Outdated

@20001020ycx 20001020ycx left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Velox side looks pretty aligned with what I have in mind, but I do have a few question regarding the Presto side, might have been me missing some context.

Comment thread tools/presto-deps/validate-presto-dep-sync.py Outdated
Comment thread tools/presto-deps/validate-presto-dep-sync.py Outdated
Comment thread tools/presto-deps/validate-presto-dep-sync.py Outdated
…alidator into Presto and Velox classes.

The pin (G_PRESTO_GIT_URL/G_PRESTO_GIT_TAG) is consumed by both connectors and
the tools/presto-deps/ scripts, so it belongs in taskfile.yaml rather than the
velox-connector deps taskfile; Task's global vars propagate to all includes.

Per review, the validator now encapsulates each side's constants, sources, and
checks: Presto owns the pin (taskfile.yaml), the connector pom pins, and the
pinned-commit checkout; Velox owns deps.yaml's G_*_VERSION pins and the
submodule resolution. Also documents why the Presto root pom (not presto-spi)
is the version source of truth and what each checkout candidate is, and
rewords the validate-deps workflow header to describe the report output.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@taskfiles/velox-connector/main.yaml`:
- Around line 17-20: Update the build task’s deps configuration to run
validate-dep-sync before deps:install-all, using go-task’s sequential dependency
mechanism rather than parallel deps entries. Preserve the existing task names
and ensure dependency installation starts only after validation succeeds.

In `@tools/presto-deps/validate-presto-dep-sync.py`:
- Around line 3-6: Add S603 to the file-level Ruff noqa suppression list in
validate-presto-dep-sync.py, preserving the existing rationale for trusted
PATH-resolved git subprocess usage and leaving the subprocess.run call
unchanged.
- Around line 99-109: Protect the shared checkout operations in shallow_repo
with a file lock located under BUILD_DIR, acquiring it before directory creation
and releasing it after the repository validation or fetch completes. Ensure
concurrent validate-dep-sync invocations serialize the entire shallow_repo
critical section, including git init, remote updates, and fetches, while
preserving the existing return behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 7ef77aaa-b2e1-4092-89d0-34f96a0d5469

📥 Commits

Reviewing files that changed from the base of the PR and between d1c2739 and 0504789.

📒 Files selected for processing (9)
  • .github/workflows/validate-deps.yaml
  • presto-connector/pom.xml
  • taskfile.yaml
  • taskfiles/presto-connector/main.yaml
  • taskfiles/velox-connector/deps.yaml
  • taskfiles/velox-connector/main.yaml
  • tools/build-packages/internal/container/build-artifacts.sh
  • tools/presto-deps/install-presto-artifacts.sh
  • tools/presto-deps/validate-presto-dep-sync.py
💤 Files with no reviewable changes (1)
  • taskfiles/velox-connector/deps.yaml

Comment thread taskfiles/velox-connector/main.yaml Outdated
Comment thread tools/presto-deps/validate-presto-dep-sync.py
Comment thread tools/presto-deps/validate-presto-dep-sync.py
…cross-cache scavenging.

The Presto-side tools (validator + installer) share build-dir presto-src,
seeded by whichever runs first; the velox-connector's FetchContent tree stays
its own. The FetchContent-cache candidate scanning was nearly dead code: the
validator runs before the builds as a task dependency, so presto-src is
already populated when the installer looks.
The check is repo-scoped (like the pin it guards), so both connectors now
depend on the root task via ":validate-dep-sync" instead of defining
identical copies.
Velox no longer takes the Presto instance: both classes independently derive
their inputs from the root taskfile pin and the shared presto-src clone via
module helpers, so either check can run without the other.
…banners.

Per review (too many variables to keep track of): classes keep only the
attributes their checks read (Presto: pin/connector_pom/root_pom; Velox:
presto_pin/sha/repo), every comparison uses one ours/theirs vocabulary, the
unv_* locals fold into strip_v(), and the color constants move inside
Reporter. Section banners group the file's helpers, and the ElementTree
namespace and blobless-fetch idioms are now explained where used.
Parallel deps let the (long) dependency install start even when validation was
about to fail; sequential cmds make the validator a true gate.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
tools/presto-deps/install-presto-artifacts.sh (1)

75-79: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

Reject ambiguous pin definitions.

The sed patterns match the key anywhere in a line and only check for a non-empty result. A commented-out key or multiple matching entries can therefore be accepted even when the Taskfile/validator resolves a different value. Anchor the match to an active mapping entry and fail unless exactly one value is found.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tools/presto-deps/install-presto-artifacts.sh` around lines 75 - 79, Update
the `presto_git_url` and `presto_git_tag` extraction in the install script to
match only active Taskfile mapping entries, not commented or unrelated text.
Require exactly one matching value for each key and call `die` when zero or
multiple entries are found, keeping the resolved value consistent with the
Taskfile/validator.
taskfiles/velox-connector/main.yaml (1)

16-22: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

:validate-dep-sync still races with deps:install-all instead of gating it.

Both entries remain under deps:, which go-task runs in parallel by default, so validation isn't guaranteed to complete before deps:install-all starts — contradicting this PR's stated goal that "validation runs before connector builds." This is the same gap raised on a prior revision (then against the un-prefixed validate-dep-sync name); the suggested reordering was never applied.

🔧 Suggested fix: sequence validation first
   build:
     deps:
-      - "deps:install-all"
-      - ":validate-dep-sync"
+      - ":validate-dep-sync"
     cmds:
+      - task: "deps:install-all"
       - task: "build-with-installed-deps"

[reliability_and_availability]

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@taskfiles/velox-connector/main.yaml` around lines 16 - 22, Update the build
task’s dependency orchestration so :validate-dep-sync completes before
deps:install-all starts, rather than listing both under parallel deps. Preserve
the existing build-with-installed-deps command and ensure the validation-first
ordering is enforced by the task configuration.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@taskfiles/velox-connector/main.yaml`:
- Around line 16-22: Update the build task’s dependency orchestration so
:validate-dep-sync completes before deps:install-all starts, rather than listing
both under parallel deps. Preserve the existing build-with-installed-deps
command and ensure the validation-first ordering is enforced by the task
configuration.

In `@tools/presto-deps/install-presto-artifacts.sh`:
- Around line 75-79: Update the `presto_git_url` and `presto_git_tag` extraction
in the install script to match only active Taskfile mapping entries, not
commented or unrelated text. Require exactly one matching value for each key and
call `die` when zero or multiple entries are found, keeping the resolved value
consistent with the Taskfile/validator.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: c7a5789a-6200-4dc4-a0ba-b03f04c4e325

📥 Commits

Reviewing files that changed from the base of the PR and between 0504789 and a2d8419.

📒 Files selected for processing (6)
  • .github/workflows/validate-deps.yaml
  • taskfile.yaml
  • taskfiles/presto-connector/main.yaml
  • taskfiles/velox-connector/main.yaml
  • tools/presto-deps/install-presto-artifacts.sh
  • tools/presto-deps/validate-presto-dep-sync.py

@20001020ycx 20001020ycx left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the refactor, I think the code structure is clean now, I dont have too much comment on the code itself, but I do have a few questions regarding the design.

Comment thread tools/presto-deps/install-presto-artifacts.sh
Comment thread tools/presto-deps/validate-presto-dep-sync.py
validate-presto-dep-sync.py checks the same invariant against the pinned
commit, and every path that runs the installer (task deps, the packaging
container, CI) runs the validator first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@jackluo923
jackluo923 merged commit d5a54a4 into main Jul 28, 2026
11 checks passed
@jackluo923
jackluo923 deleted the feat/validate-dep-sync branch July 28, 2026 15:41
jackluo923 added a commit that referenced this pull request Jul 28, 2026
The Presto pin moved there in #29.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
jackluo923 added a commit that referenced this pull request Jul 31, 2026
The Presto pin moved there in #29.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants