[llvm] workflows: Add require-release-manager composite action (PR #194758)

Tom Stellard via llvm-commits llvm-commits at lists.llvm.org
Wed Apr 29 07:13:23 PDT 2026


https://github.com/tstellar updated https://github.com/llvm/llvm-project/pull/194758

>From 05dc342236746300a377d5d5aea1df6e4c7f218c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:16:56 -0700
Subject: [PATCH 1/3] workflows: Add require-release-manager composite action

This action checks that the workflow was started by someone in the
llvm-release-managers team.  This is meant to replace the existing
checks which use a python script and will help to consolidate the
access token generation into a single place.

Also start using it in the release-binaries workflow.
---
 .github/workflows/release-binaries.yml        | 22 +++---------
 .../require-release-manager/action.yml        | 35 +++++++++++++++++++
 2 files changed, 40 insertions(+), 17 deletions(-)
 create mode 100644 .github/workflows/require-release-manager/action.yml

diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 1ea01738d75b7..cb77a32a50195 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,6 +50,7 @@ permissions:
 jobs:
   prepare:
     name: Prepare to build binaries
+    environment: release
     runs-on: ${{ inputs.runs-on }}
     if: github.repository_owner == 'llvm'
     outputs:
@@ -65,12 +66,6 @@ jobs:
       attestation-name: ${{ steps.vars.outputs.attestation-name }}
 
     steps:
-    # It's good practice to use setup-python, but this is also required on macos-14
-    # due to https://github.com/actions/runner-images/issues/10385
-    - uses: actions/setup-python at a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
-      with:
-        python-version: '3.14'
-
     - name: Install Windows ARM64 dependencies
       if: runner.os == 'Windows' && runner.arch == 'ARM64'
       run: |
@@ -83,19 +78,12 @@ jobs:
       with:
           persist-credentials: false
 
-    - name: Install Dependencies
-      shell: bash
-      run: |
-        pip install --require-hashes -r ./llvm/utils/git/requirements.txt
-
     - name: Check Permissions
       if: github.event_name != 'pull_request'
-      env:
-        GITHUB_TOKEN: ${{ github.token }}
-        USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
-      shell: bash
-      run: |
-        ./llvm/utils/release/./github-upload-release.py --token "$GITHUB_TOKEN" --user "$GITHUB_ACTOR" --user-token "$USER_TOKEN" check-permissions
+      uses: ./.github/workflows/require-release-manager
+      with:
+        LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+        LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
 
     # The name of the Windows binaries uses the version from source, so we need
     # to fetch it here.
diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
new file mode 100644
index 0000000000000..520b2d02693a3
--- /dev/null
+++ b/.github/workflows/require-release-manager/action.yml
@@ -0,0 +1,35 @@
+name: Require Release Manager
+description: >-
+  This checks to make sure the person that initiated the workflow is a
+  release manager.
+inputs:
+  LLVM_TOKEN_GENERATOR_CLIENT_ID:
+    description: >-
+      Client ID for generating access tokens.
+    required: true
+  LLVM_TOKEN_GENERATOR_PRIVATE_KEY:
+    description: >-
+      Private key for generating access tokens
+    required: true
+
+runs:
+  using: "composite"
+  steps:
+    - id: app-token
+      uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3  # v3.1.1
+      with:
+        app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+        private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+        owner: ${{ github.repository_owner }}
+        permission-members: read
+
+    - name: Check Permissions
+      uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+      with:
+        github-token: ${{ steps.app-token.outputs.token }}
+        script: |
+          await github.rest.teams.getMembershipForUserInOrg({
+             org: context.repo.owner,
+             team_slug: "llvm-release-managers"
+             username: context.actor
+          });

>From cfbb00258931bc2789206b699f9b998dd4916cfa Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:12:46 -0700
Subject: [PATCH 2/3] fix environment

---
 .github/workflows/release-binaries.yml | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index cb77a32a50195..af25c04bdfee7 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,7 +50,9 @@ permissions:
 jobs:
   prepare:
     name: Prepare to build binaries
-    environment: release
+    environment:
+      deployment: false
+      environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
     runs-on: ${{ inputs.runs-on }}
     if: github.repository_owner == 'llvm'
     outputs:

>From c8fb0eb18209389cccda99c35d423f20b8458aad Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:28:51 -0700
Subject: [PATCH 3/3] XXX: debug

---
 .../require-release-manager/action.yml        | 27 ++++++++++---------
 .../test-require-release-manager.yml          | 19 +++++++++++++
 2 files changed, 34 insertions(+), 12 deletions(-)
 create mode 100644 .github/workflows/test-require-release-manager.yml

diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
index 520b2d02693a3..4c2cfd5917410 100644
--- a/.github/workflows/require-release-manager/action.yml
+++ b/.github/workflows/require-release-manager/action.yml
@@ -15,21 +15,24 @@ inputs:
 runs:
   using: "composite"
   steps:
-    - id: app-token
-      uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3  # v3.1.1
-      with:
-        app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
-        private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
-        owner: ${{ github.repository_owner }}
-        permission-members: read
-
     - name: Check Permissions
       uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
       with:
-        github-token: ${{ steps.app-token.outputs.token }}
+        github-token: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
         script: |
           await github.rest.teams.getMembershipForUserInOrg({
-             org: context.repo.owner,
-             team_slug: "llvm-release-managers"
-             username: context.actor
+             org: "llvm",
+             team_slug: "llvm-release-managers",
+             username: "nikic"
+          });
+          console.log(response)
+    - name: Check Permissions 2
+      uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+      with:
+        github-token: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+        script: |
+          const response = await github.rest.teams.getMembershipForUserInOrg({
+             org: "llvm",
+             team_slug: "llvm-release-managers",
+             username: "nikic"
           });
diff --git a/.github/workflows/test-require-release-manager.yml b/.github/workflows/test-require-release-manager.yml
new file mode 100644
index 0000000000000..d6e7027662fe8
--- /dev/null
+++ b/.github/workflows/test-require-release-manager.yml
@@ -0,0 +1,19 @@
+name: Test
+on:
+  push:
+
+
+jobs:
+  test-require-release-manager:
+    runs-on: ubuntu-24.04
+    steps:
+      - name: Checkout
+        uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+        with:
+          persist-credentials: false
+          sparse-checkout: .github/workflows/
+      - name: Test
+        uses: ./.github/workflows/require-release-manager
+        with:
+          LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
+          LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}



More information about the llvm-commits mailing list