Skip to content

Align the v1.21 CI configuration with v2.1 and v2.5, and pin all GitHub Actions - #2129

Merged
GromNaN merged 10 commits into
mongodb:v1.21from
GromNaN:align-ci-with-v2.1
Sep 29, 2026
Merged

GromNaN merged 10 commits into
mongodb:v1.21from
GromNaN:align-ci-with-v2.1

Conversation

@GromNaN

@GromNaN GromNaN commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Brings the GitHub Actions workflows and the Evergreen configuration of v1.21 in line with v2.1, pins every action to its latest release commit, and ports the v2.5 additions that apply here. It also fixes a flaky test in tests/standalone.

What changed

  • adopt the .github and .evergreen layout of v2.1, including the tests/drivers-evergreen-tools submodule
  • drop the old OCSP responder script and use the shared OCSP scripts
  • pin every action to its latest release commit, each SHA checked against its upstream tag
  • port from v2.5: Codecov upload, PECL test on RHEL 8, Alpine PECL test, SBOM check, static PHP and out-of-source builds
  • fix dependabot.yml: drop the target-branch and groups keys added by PHPC-2774: Pin all GitHub Actions to exact release tags #2121, and point the git submodule updates at the repository root, because Dependabot reads the root .gitmodules
  • stop failMaxTimeMS() from arming an unfiltered fail point, whose single slot the monitoring connection's hello can consume on a replica set, with a fall back to the old fail point before MongoDB 4.2

Kept out

The test-system-libs job is added so its definition reaches v2.1 and v2.5 through the merge-up, but it does not run here: v1.21 and v2.1 build libmongoc 1.x, whose trace output the driver does not capture. An exclusion list is used rather than >= 'v2.5', because GitHub compares strings lexicographically.

Also left out: PHP 8.5 (removed IS_INTERNED), the v2.5 release workflow, the 32-bit Windows builds, the libmongoc 2.x tasks and the corresponding CONTRIBUTING.md parts.

The MongoDB 4.0 tasks are the one thing that is deliberately not taken from v2.1. v2.1 dropped 4.0 in PHPC-2555, with DRIVERS-3034 marking server 4.0 as end of life for the drivers. v1.21 still supports it, so this branch keeps testing it, on the rhel80 variants as before.

Notes

  • The merge-up Merge v1.21 into v2.1 #2128 conflicts stay limited to .github/dependabot.yml. Taking this branch's version also fixes v2.1, which points the gitsubmodule update at /tests/drivers-evergreen-tools, a path Dependabot cannot see.
  • The OCSP tasks stay excluded from pull request checks.
  • The Codecov upload requires a CODECOV_TOKEN secret.

When merging up to v2.1 and v2.5

This branch deviates from v2.1 in three places on purpose. Each one has to be resolved by hand.

  • MongoDB 4.0 tasks. Keep them on v1.21 only. On merge, do not propagate '4.0' in .evergreen/config/generate-config.php, the !.4.0 exclusions of the debian and rhel90 variant templates, or the two storage engine tasks of .evergreen/config/test-tasks.yml. v2.1 and v2.5 do not support server 4.0, so carrying them over would schedule tasks that cannot pass.
  • failMaxTimeMS() in tests/utils/tools.php. Keep our change, but delete the version_compare(..., '4.2', '<') fallback so that only the failCommand branch remains. That fallback exists only because v1.21 still tests MongoDB 4.0. The same simplification applies on v2.5 and v2.x.
  • scripts/generate-purls.sh header. Our wording names only the check-sbom workflow, its only consumer on v1.21. v2.5 and v2.x also use that script from update-sbom.sh, so keep their wording and discard ours.

Two fixes from this branch are worth keeping on the way up: the added scripts/generate-purls.sh path in .github/workflows/check-sbom.yml, and the wording fix in CONTRIBUTING.md. Both defects are present on v2.5 and v2.x as well.

@GromNaN
GromNaN requested a review from a team as a code owner September 28, 2026 13:21
@GromNaN
GromNaN requested review from paulinevos and a lite review from Copilot and removed request for a team and Copilot September 28, 2026 13:21
Copilot AI lite review requested due to automatic review settings September 28, 2026 13:30

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 28, 2026 13:52

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 28, 2026 14:18

This comment was marked as outdated.

@GromNaN
GromNaN marked this pull request as draft September 28, 2026 14:26
Bring the GitHub Actions workflows and the Evergreen configuration of the
v1.21 branch in line with v2.1. The two branches had drifted apart, so every
merge-up pull request conflicted on the CI files.

Changes:
- adopt the GitHub Actions and Evergreen layout of v2.1, including the
  drivers-evergreen-tools submodule
- pin every GitHub Action to the commit of its latest release
- port the v2.5 additions that apply to this branch: Codecov test result
  upload, PECL package test on RHEL 8, Alpine PECL test, SBOM check, static
  PHP and out-of-source build jobs
- keep the OCSP tasks excluded from pull request checks

Left out, because they do not apply to this branch:
- PHP 8.5, since the branch still calls IS_INTERNED, which PHP 8.5 removed
- the system libraries job, which needs a libmongoc built with tracing, and
  the trace output breaks the whole test suite on this branch
- the v2.5 release workflow, the 32-bit Windows builds and the libmongoc 2.x
  build tasks
@GromNaN
GromNaN marked this pull request as ready for review September 28, 2026 15:16
Copilot AI review requested due to automatic review settings September 28, 2026 15:16

This comment was marked as outdated.

The job is kept in the branch so that its definition reaches v2.1 and v2.5
through the merge-up, but it is skipped on v1.21 and v2.1. Those branches build
libmongoc 1.x, whose trace output the driver does not capture, and those traces
would break every test in the job.

Also brings over the parts of CONTRIBUTING.md that do not depend on the
libmongoc version: the Alpine PECL section, the specification links pointing to
Markdown files, the `git submodule` typos and a note about the system library
job. The libmongoc 2.x instructions and the arginfo rewrite are left out, as
they do not match this branch.
Copilot AI review requested due to automatic review settings September 28, 2026 16:15

This comment was marked as outdated.

…cription'

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 16:22

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 28, 2026 19:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved CI issues affect Codecov secret handling, SBOM triggers, and complete action pinning.

Review effort: Lite
Findings: 3 High severity

Open (3)
Resolved since last review (3)

@GromNaN
GromNaN enabled auto-merge (squash) September 28, 2026 20:33
@GromNaN
GromNaN requested a review from kevinAlbs September 28, 2026 20:33
Comment thread scripts/generate-purls.sh Outdated
Copilot AI review requested due to automatic review settings September 29, 2026 12:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two unresolved CI configuration issues must be addressed before approval.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (3)

Comment thread .evergreen/config/functions.yml

@kevinAlbs kevinAlbs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • drop the MongoDB 4.0 tasks

Can tests for MongoDB 4.0 be restored? Though a breaking backport may be low risk, I expect dropping server 4.0 support in a patch release of v1.21 would be not-OK.

v1.21 still supports MongoDB 4.0: the test suite branches on that version in
tests/utils/skipif.php, and the tasks passed on every recent mainline run. The
v2.1 configuration dropped them in PHPC-2555, as part of DRIVERS-3034 marking
server 4.0 as end of life for the drivers, so adopting that configuration
removed the coverage as a side effect.

Put the version back in the generator, restore the "!.4.0" exclusions of the
debian and rhel90 variants so 4.0 keeps running only on the rhel80 variants as
before, and restore the two storage engine tasks.

Verified with a trial patch on the four rhel80 variants: 32 tasks, all green.
The "failCommand" fail point is not available on MongoDB 4.0, where a sharded
cluster answers "failCommand not found". Keep the restricted fail point on newer
servers, where it removes the race with the monitoring connection's "hello", and
use "maxTimeAlwaysTimeOut" on the older ones.
Copilot AI review requested due to automatic review settings September 29, 2026 17:15
@GromNaN

GromNaN commented Sep 29, 2026 •

Copy link
Copy Markdown
Member Author

Can tests for MongoDB 4.0 be restored? Though a breaking backport may be low risk, I expect dropping server 4.0 support in a patch release of v1.21 would be not-OK.

Restored, and checking first turned up why the tasks were not passing.

The removal was a side effect of adopting the v2.1 configuration, not a decision about v1.21. v2.1 dropped MongoDB 4.0 in PHPC-2555, as part of DRIVERS-3034 marking server 4.0 as end of life for the drivers. v1.21 still supports it, tests/utils/skipif.php still branches on that version, so the coverage had to stay.

Two commits:

  • 63d2ec2 puts 4.0 back in the generator's version list, restores the !.4.0 exclusions of the debian and rhel90 variants so that 4.0 keeps running only on the rhel80 variants as before, and restores the two storage engine tasks. That is 32 tasks per patch run.
  • 9cad193 comes out of the check described below.

I ran a trial patch before committing. The first one had those 32 tasks with exactly one failure on each of the four variants, always the same task, test-mongodb-4.0-sharded-noauth-nossl:

CommandException: failCommand not found

The failCommand fail point does not exist on MongoDB 4.0, and the fail point fix in this pull request is what uses it. The tasks were failing because of that fix, not because of the restoration. 9cad193 makes failMaxTimeMS() fall back to maxTimeAlwaysTimeOut before 4.2.

The second trial patch was 32 tasks, all green.

For the record, the 4.0 tasks were green on the mainline runs before this pull request, 96 out of 96 over three versions and the four rhel80 variants. The only failure I found was a crash of the uv bootstrap building pymongo-4.13.2, unrelated to 4.0.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved moderate issues affect Evergreen scope, SBOM triggers, action pinning, failure reporting, branch gating, and timeout handling.

Review effort: Lite
Findings: None

Resolved since last review (1)

@GromNaN
GromNaN merged commit 79c08af into mongodb:v1.21 Sep 29, 2026
51 checks passed
@GromNaN
GromNaN deleted the align-ci-with-v2.1 branch September 29, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants