[llvm] workflows: Add require-release-manager composite action (PR #194758)
Tom Stellard via llvm-commits
llvm-commits at lists.llvm.org
Wed Apr 29 07:13:23 PDT 2026
https://github.com/tstellar updated https://github.com/llvm/llvm-project/pull/194758
>From 05dc342236746300a377d5d5aea1df6e4c7f218c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:16:56 -0700
Subject: [PATCH 1/3] workflows: Add require-release-manager composite action
This action checks that the workflow was started by someone in the
llvm-release-managers team. This is meant to replace the existing
checks which use a python script and will help to consolidate the
access token generation into a single place.
Also start using it in the release-binaries workflow.
---
.github/workflows/release-binaries.yml | 22 +++---------
.../require-release-manager/action.yml | 35 +++++++++++++++++++
2 files changed, 40 insertions(+), 17 deletions(-)
create mode 100644 .github/workflows/require-release-manager/action.yml
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 1ea01738d75b7..cb77a32a50195 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,6 +50,7 @@ permissions:
jobs:
prepare:
name: Prepare to build binaries
+ environment: release
runs-on: ${{ inputs.runs-on }}
if: github.repository_owner == 'llvm'
outputs:
@@ -65,12 +66,6 @@ jobs:
attestation-name: ${{ steps.vars.outputs.attestation-name }}
steps:
- # It's good practice to use setup-python, but this is also required on macos-14
- # due to https://github.com/actions/runner-images/issues/10385
- - uses: actions/setup-python at a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
- with:
- python-version: '3.14'
-
- name: Install Windows ARM64 dependencies
if: runner.os == 'Windows' && runner.arch == 'ARM64'
run: |
@@ -83,19 +78,12 @@ jobs:
with:
persist-credentials: false
- - name: Install Dependencies
- shell: bash
- run: |
- pip install --require-hashes -r ./llvm/utils/git/requirements.txt
-
- name: Check Permissions
if: github.event_name != 'pull_request'
- env:
- GITHUB_TOKEN: ${{ github.token }}
- USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
- shell: bash
- run: |
- ./llvm/utils/release/./github-upload-release.py --token "$GITHUB_TOKEN" --user "$GITHUB_ACTOR" --user-token "$USER_TOKEN" check-permissions
+ uses: ./.github/workflows/require-release-manager
+ with:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
# The name of the Windows binaries uses the version from source, so we need
# to fetch it here.
diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
new file mode 100644
index 0000000000000..520b2d02693a3
--- /dev/null
+++ b/.github/workflows/require-release-manager/action.yml
@@ -0,0 +1,35 @@
+name: Require Release Manager
+description: >-
+ This checks to make sure the person that initiated the workflow is a
+ release manager.
+inputs:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID:
+ description: >-
+ Client ID for generating access tokens.
+ required: true
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY:
+ description: >-
+ Private key for generating access tokens
+ required: true
+
+runs:
+ using: "composite"
+ steps:
+ - id: app-token
+ uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
+ with:
+ app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+ owner: ${{ github.repository_owner }}
+ permission-members: read
+
+ - name: Check Permissions
+ uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+ with:
+ github-token: ${{ steps.app-token.outputs.token }}
+ script: |
+ await github.rest.teams.getMembershipForUserInOrg({
+ org: context.repo.owner,
+ team_slug: "llvm-release-managers"
+ username: context.actor
+ });
>From cfbb00258931bc2789206b699f9b998dd4916cfa Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:12:46 -0700
Subject: [PATCH 2/3] fix environment
---
.github/workflows/release-binaries.yml | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index cb77a32a50195..af25c04bdfee7 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,7 +50,9 @@ permissions:
jobs:
prepare:
name: Prepare to build binaries
- environment: release
+ environment:
+ deployment: false
+ environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
runs-on: ${{ inputs.runs-on }}
if: github.repository_owner == 'llvm'
outputs:
>From c8fb0eb18209389cccda99c35d423f20b8458aad Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:28:51 -0700
Subject: [PATCH 3/3] XXX: debug
---
.../require-release-manager/action.yml | 27 ++++++++++---------
.../test-require-release-manager.yml | 19 +++++++++++++
2 files changed, 34 insertions(+), 12 deletions(-)
create mode 100644 .github/workflows/test-require-release-manager.yml
diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
index 520b2d02693a3..4c2cfd5917410 100644
--- a/.github/workflows/require-release-manager/action.yml
+++ b/.github/workflows/require-release-manager/action.yml
@@ -15,21 +15,24 @@ inputs:
runs:
using: "composite"
steps:
- - id: app-token
- uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
- with:
- app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
- private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
- owner: ${{ github.repository_owner }}
- permission-members: read
-
- name: Check Permissions
uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
- github-token: ${{ steps.app-token.outputs.token }}
+ github-token: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
script: |
await github.rest.teams.getMembershipForUserInOrg({
- org: context.repo.owner,
- team_slug: "llvm-release-managers"
- username: context.actor
+ org: "llvm",
+ team_slug: "llvm-release-managers",
+ username: "nikic"
+ });
+ console.log(response)
+ - name: Check Permissions 2
+ uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+ with:
+ github-token: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+ script: |
+ const response = await github.rest.teams.getMembershipForUserInOrg({
+ org: "llvm",
+ team_slug: "llvm-release-managers",
+ username: "nikic"
});
diff --git a/.github/workflows/test-require-release-manager.yml b/.github/workflows/test-require-release-manager.yml
new file mode 100644
index 0000000000000..d6e7027662fe8
--- /dev/null
+++ b/.github/workflows/test-require-release-manager.yml
@@ -0,0 +1,19 @@
+name: Test
+on:
+ push:
+
+
+jobs:
+ test-require-release-manager:
+ runs-on: ubuntu-24.04
+ steps:
+ - name: Checkout
+ uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ with:
+ persist-credentials: false
+ sparse-checkout: .github/workflows/
+ - name: Test
+ uses: ./.github/workflows/require-release-manager
+ with:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
More information about the llvm-commits
mailing list