Skip to content

fix: stabilize required checks and CI runtime - #3264

Merged
imbajin merged 4 commits into
apache:masterfrom
hugegraph:fix/stable-server-ci-gate
Oct 4, 2026
Merged

imbajin merged 4 commits into
apache:masterfrom
hugegraph:fix/stable-server-ci-gate

Conversation

@imbajin

@imbajin imbajin commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Purpose of the PR

After a Java upgrade, CI reports build-server (memory, 17) while branch protection still waits for build-server (memory, 11). This PR introduces the fixed required check Server memory tests, so changing the runtime JDK no longer requires renaming the protection context.

The preparation still runs on Java 11. A shared runtime file prepares CI for Java 17/21, while temporary result checks retain the current Server/Commons protection names during migration. This PR also refreshes GitHub Actions runtimes and fixes Maven cache initialization. Related: #3261, #3262, #3263.

Stable CI checks across Java upgrades

Main Changes

Workflow job Responsibility
java-runtime Read the project runtime and generate the Server/Commons JDK matrix. Invalid configuration fails this job.
build-server Run memory tests for every configured Linux JDK, shown as Server memory (Java 11). Keep the job ID for the existing Codecov validator.
server-memory-required Publish Server memory tests. Pass only when runtime resolution and the entire memory matrix succeed.
build-server-backends Continue RocksDB/HBase coverage using the same environment, JDK list and test steps. Their results remain optional.
Temporary legacy result jobs Publish build-server (memory, 11) and build-commons (11) until ASF applies the new protection configuration. Both check the real runtime and matrix results, including failures and skips.

.asf.yaml requires the fixed memory gate and removes Commons from required checks. Commons CI continues to run. macOS and RISC-V coverage remain optional.

The memory job defines the shared Linux environment and test steps with YAML & anchors; the backend job reuses them with * aliases. Comments explain the shared configuration, temporary legacy checks and why the result jobs use always().

One runtime setting

.github/workflows/.java-version contains 11. Change it to 17 or 21 to update the standard Server, Commons, PD/Store, dependency and CodeQL jobs. Single-JDK jobs use setup-java's native java-version-file; Server/Commons use the reusable reader to construct their matrices. Additional test JDKs can be supplied to that reader as extra-java-versions: '["11", "21"]'; it always includes the configured runtime and removes duplicates.

This setting controls the CI runtime, independently of Maven compiler/bytecode settings. No Java source or POM changes are included. RISC-V continues to use its existing SHA-verified Dragonwell 11 artifact: a vendor-specific upgrade must update its archive, URL and checksum together.

The matrix fallback keeps job evaluation valid when the reader fails. It cannot pass the gate: result jobs require both the reader and actual test matrix to succeed, and explicitly fail for cancellation, failure or skips. This also protects the current legacy requirements before ASF applies the fixed context.

Actions and cache maintenance

  • Upgrade official Actions to Node 24 releases: checkout v7, setup-java v6, upload-artifact v7, CodeQL v4 and stale v11. Java runtime versions and the configured stale policy remain the same; explicitly retain close-issue-reason: completed instead of inheriting the newer not_planned default.
  • Upgrade Codecov to v7 and the PR comment action to v5 for Node 24 compatibility, preserving the configured report paths, token handling and upload error policy.
  • Replace separate Maven cache steps with setup-java's native cache: maven. Checkout runs first so dependency files are available when the cache key is computed. Cache Maven dependencies instead of the whole .m2 directory; keep downloaded-JDK caching disabled.
  • Replace the removed adopt distribution identifier with its supported temurin successor in dependency CI, retaining Java 11.
  • Align the RocksDB compatibility job with the shared runtime, reading after/.github/workflows/.java-version from its explicit head checkout. Preserve the before/after revision selection, compatibility commands and artifact paths.

Existing build/test commands, conditional test behavior and coverage upload inputs are preserved. Workflows consuming the runtime file include it in their PR path filters. New reader/result jobs have read-only or empty permissions. Cluster Test remains manually disabled. PR concurrency, automatic rerun policy and build/test scope changes are outside this change.

Migration order

  1. Merge this PR after Java 11 Server/Commons and the new gate pass under the current protection rules.
  2. Wait for ASF configuration to apply. Verify that live protection requires Server memory tests and no longer requires the Java 11 Server/Commons contexts.
  3. Remove the temporary legacy result jobs once their contexts are no longer required. Sync the Java upgrade branches with master, retaining the fixed gate and shared runtime file. Then change the runtime file without renaming protection checks.

Verifying these changes

  • Need tests and can be verified as follows:
    • YAML and Actions syntax validation, whitespace checks, Maven formatting and compilation.
    • Execute the actual Server/Commons result-check scripts across runtime/test success, failure, cancelled, skipped and empty combinations; only two successful results pass.
    • Run the actual runtime reader against Java 11/17/21, additional-JDK deduplication and invalid configuration fixtures. Check unique matrix names, legacy compatibility names, runtime path triggers and cache ordering.
    • Existing Codecov upload configuration and JaCoCo report validator tests.
    • Execute the actual RocksDB compatibility runner against latest master and the synchronized branch. Effective POMs resolve identical Server/PD/Store RocksDB versions, so the runner exits successfully without version-pair tests.
    • Compare existing workflow events, test/coverage commands and conditional test behavior before and after modernization.
    • Independent review of the final workflow diff.

Local Actions/YAML validation, runtime/result-check fixtures, coverage configuration validators, Maven formatting and full compilation pass. The synchronized head's live RocksDB compatibility check also passes. Full CI on the latest head must finish before merging. Existing shellcheck warnings in unchanged scripts remain.

References: GitHub's Node 24 migration notice, native Maven caching, YAML anchors and job dependencies with always().

Does this PR potentially affect the following parts?

  • Dependencies
  • Modify configurations
  • The public API
  • Other affects
  • Nope

Documentation Status

  • Doc - TODO: required documentation is pending; complete it before merging.
  • Doc - Done: documentation is included here or linked below.
  • Doc - No Need: internal CI and branch protection only.

- add a fixed memory matrix result gate
- share Linux build steps with backend jobs
- preserve Java 11 checks during migration
- remove Commons from required contexts
@codecov

codecov Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 41.57%. Comparing base (cb458ba) to head (e28ba3e).

Additional details and impacted files
@@            Coverage Diff            @@
##             master    #3264   +/-   ##
=========================================
  Coverage     41.57%   41.57%           
  Complexity     7312     7312           
=========================================
  Files           794      794           
  Lines         69127    69127           
  Branches       9258     9258           
=========================================
+ Hits          28739    28743    +4     
+ Misses        37110    37109    -1     
+ Partials       3278     3275    -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

- name memory and optional backend jobs explicitly
- group the memory tests with their stable result gate
- explain shared Linux configuration and migration constraints
- Centralize the project JDK and generate validated test matrices
- Fail required and legacy result checks on runtime or test skips
- Refresh Actions runtimes and use native Maven dependency caching
- Trigger affected workflows when the shared runtime file changes
@imbajin imbajin changed the title fix: stabilize required server CI check fix: stabilize required checks and CI runtime Oct 4, 2026
- Merge the latest RocksDB and JRaft baseline from master
- Align the new compatibility job with the shared CI runtime
- Refresh comparison and artifact Actions while preserving inputs
@imbajin
imbajin merged commit 89cd937 into apache:master Oct 4, 2026
30 checks passed
@imbajin
imbajin deleted the fix/stable-server-ci-gate branch October 4, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants