mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
ebb7980369
## Why Bazel remote configuration was selected in several CI scripts and workflow steps. That made the BuildBuddy tenant policy easy to duplicate and harder to audit, especially for fork pull requests that must not use the OpenAI tenant. This builds on [sluongng/buildbuddy-ci-host-routing](https://github.com/openai/codex/compare/main...sluongng:codex:sluongng/buildbuddy-ci-host-routing) and consolidates the policy in one place. ## What to do if this breaks you See `codex-rs/docs/bazel.md` for details. TLDR: 1. make a BuildBuddy API key and put it in `~/.bazelrc` 2. if you're an OpenAI employee, add `common --config=buildbuddy-openai-rbe` to `user.bazelrc` in the repo root Run `just bazel-test` to ensure it works. Note that `just bazel-remote-test` no longer exists, you need to select a remote configuration as documented to use RBE. ## What changed - Add `.github/scripts/run_bazel_with_buildbuddy.py` as the shared Bazel wrapper and Python library. It selects the OpenAI host only for trusted upstream GitHub Actions runs, routes keyed fork runs to the generic host, and falls back to local Bazel execution when no key is available. - Move endpoint selection into explicit `.bazelrc` configurations and update Bazel CI, query helpers, and `rusty_v8` staging to use the shared policy. Loading-phase target-discovery queries remain local. - Add wrapper and `rusty_v8` unit coverage, plus `just test-scripts` for the `.github/scripts` Python tests. - Document local Bazel usage, `user.bazelrc` setup, BuildBuddy configurations, and CI behavior in `codex-rs/docs/bazel.md`. ## Validation - `just test-scripts` - `bash -n .github/scripts/run-bazel-ci.sh .github/scripts/run-bazel-query-ci.sh .github/scripts/run-argument-comment-lint-bazel.sh scripts/list-bazel-clippy-targets.sh` - `python3 -m py_compile .github/scripts/run_bazel_with_buildbuddy.py .github/scripts/test_run_bazel_with_buildbuddy.py .github/scripts/test_rusty_v8_bazel.py .github/scripts/rusty_v8_bazel.py` - `ruff check .github/scripts/run_bazel_with_buildbuddy.py .github/scripts/test_run_bazel_with_buildbuddy.py .github/scripts/test_rusty_v8_bazel.py .github/scripts/rusty_v8_bazel.py`
185 lines
6.4 KiB
Python
185 lines
6.4 KiB
Python
#!/usr/bin/env python3
|
|
|
|
import json
|
|
import unittest
|
|
from pathlib import Path
|
|
from tempfile import TemporaryDirectory
|
|
|
|
import run_bazel_with_buildbuddy
|
|
|
|
|
|
class RunBazelWithBuildBuddyTest(unittest.TestCase):
|
|
def github_env(
|
|
self,
|
|
temp_dir: str,
|
|
*,
|
|
repository: str = "openai/codex",
|
|
fork: bool = False,
|
|
event_name: str = "pull_request",
|
|
) -> dict[str, str]:
|
|
event_path = Path(temp_dir) / "event.json"
|
|
event_path.write_text(
|
|
json.dumps({"pull_request": {"head": {"repo": {"fork": fork}}}}),
|
|
encoding="utf-8",
|
|
)
|
|
return {
|
|
"BUILDBUDDY_API_KEY": "token",
|
|
"GITHUB_ACTIONS": "true",
|
|
"GITHUB_EVENT_NAME": event_name,
|
|
"GITHUB_EVENT_PATH": str(event_path),
|
|
"GITHUB_REPOSITORY": repository,
|
|
}
|
|
|
|
def test_keyless_invocation_drops_remote_ci_configuration(self) -> None:
|
|
self.assertIsNone(
|
|
run_bazel_with_buildbuddy.remote_config(
|
|
["build", "--config=ci-linux", "//codex-rs/cli:codex"],
|
|
{},
|
|
)
|
|
)
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_args_with_remote_config(
|
|
["build", "--config=ci-linux", "--", "//codex-rs/cli:codex"],
|
|
{},
|
|
),
|
|
["build", "--", "//codex-rs/cli:codex"],
|
|
)
|
|
|
|
def test_program_arguments_after_separator_do_not_select_or_lose_rbe(self) -> None:
|
|
args = ["run", "//codex-rs/cli:codex", "--", "--config=remote"]
|
|
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_args_with_remote_config(args, {}),
|
|
args,
|
|
)
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.remote_config(
|
|
args, {"BUILDBUDDY_API_KEY": "fork-token"}
|
|
),
|
|
"buildbuddy-generic",
|
|
)
|
|
|
|
def test_upstream_push_selects_openai_rbe_before_target_separator(self) -> None:
|
|
with TemporaryDirectory() as temp_dir:
|
|
env = self.github_env(temp_dir, event_name="push")
|
|
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_args_with_remote_config(
|
|
["build", "--config=ci-linux", "--", "//codex-rs/cli:codex"],
|
|
env,
|
|
),
|
|
[
|
|
"build",
|
|
"--config=buildbuddy-openai-rbe",
|
|
"--remote_header=x-buildbuddy-api-key=token",
|
|
"--config=ci-linux",
|
|
"--",
|
|
"//codex-rs/cli:codex",
|
|
],
|
|
)
|
|
|
|
def test_windows_cross_ci_configuration_follows_remote_configuration(self) -> None:
|
|
env = {"BUILDBUDDY_API_KEY": "fork-token"}
|
|
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_args_with_remote_config(
|
|
["build", "--config=ci-windows-cross", "//codex-rs/cli:codex"],
|
|
env,
|
|
),
|
|
[
|
|
"build",
|
|
"--config=buildbuddy-generic-rbe",
|
|
"--remote_header=x-buildbuddy-api-key=fork-token",
|
|
"--config=ci-windows-cross",
|
|
"//codex-rs/cli:codex",
|
|
],
|
|
)
|
|
|
|
def test_query_remote_configuration_is_inserted_before_expression(self) -> None:
|
|
expression = 'kind("rust_library rule", //codex-rs/...)'
|
|
env = {"BUILDBUDDY_API_KEY": "fork-token"}
|
|
|
|
for command in ("query", "cquery", "aquery"):
|
|
with self.subTest(command=command):
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_args_with_remote_config(
|
|
[
|
|
command,
|
|
"--config=ci-windows-cross",
|
|
"--output=label",
|
|
expression,
|
|
],
|
|
env,
|
|
),
|
|
[
|
|
command,
|
|
"--config=buildbuddy-generic-rbe",
|
|
"--remote_header=x-buildbuddy-api-key=fork-token",
|
|
"--config=ci-windows-cross",
|
|
"--output=label",
|
|
expression,
|
|
],
|
|
)
|
|
|
|
def test_same_repository_pull_request_selects_openai_host(self) -> None:
|
|
with TemporaryDirectory() as temp_dir:
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.remote_config(
|
|
["build", "--config=ci-v8"], self.github_env(temp_dir)
|
|
),
|
|
"buildbuddy-openai-rbe",
|
|
)
|
|
|
|
def test_fork_pull_request_cannot_select_openai_host(self) -> None:
|
|
with TemporaryDirectory() as temp_dir:
|
|
env = self.github_env(temp_dir, fork=True)
|
|
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.remote_config(
|
|
["build", "--config=ci-v8"], env
|
|
),
|
|
"buildbuddy-generic-rbe",
|
|
)
|
|
|
|
def test_run_in_fork_repository_cannot_select_openai_host(self) -> None:
|
|
with TemporaryDirectory() as temp_dir:
|
|
env = self.github_env(temp_dir, repository="contributor/codex")
|
|
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.remote_config(
|
|
["build", "--config=ci-v8"], env
|
|
),
|
|
"buildbuddy-generic-rbe",
|
|
)
|
|
|
|
def test_pull_request_without_readable_event_payload_fails_closed(self) -> None:
|
|
for event_path in (None, "missing-event.json"):
|
|
env = {
|
|
"BUILDBUDDY_API_KEY": "token",
|
|
"GITHUB_ACTIONS": "true",
|
|
"GITHUB_EVENT_NAME": "pull_request",
|
|
"GITHUB_REPOSITORY": "openai/codex",
|
|
}
|
|
if event_path is not None:
|
|
env["GITHUB_EVENT_PATH"] = event_path
|
|
|
|
with self.subTest(event_path=event_path):
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.remote_config(["build"], env),
|
|
"buildbuddy-generic",
|
|
)
|
|
|
|
def test_bazel_command_uses_configured_binary_locally(self) -> None:
|
|
self.assertEqual(
|
|
run_bazel_with_buildbuddy.bazel_command(
|
|
"info",
|
|
"execution_root",
|
|
env={"CODEX_BAZEL_BIN": "fake-bazel"},
|
|
),
|
|
["fake-bazel", "info", "execution_root"],
|
|
)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|