[llvm] [Flang] Github action to check for integration tests (PR #221766)

Kiran Chandramohan via llvm-commits llvm-commits at lists.llvm.org
Tue Sep 22 08:50:24 PDT 2026


https://github.com/kiranchandramohan updated https://github.com/llvm/llvm-project/pull/221766

>From d3c8c390758f3c7dc97ea56cf9d8354ac8bd3a31 Mon Sep 17 00:00:00 2001
From: Kiran Chandramohan <kiran.chandramohan at arm.com>
Date: Fri, 21 Aug 2026 22:23:56 +0200
Subject: [PATCH 1/2] [Flang] Github action to check for integration tests

---
 .../flang-integration-test-check.yml          | 104 ++++++++++++++++++
 1 file changed, 104 insertions(+)
 create mode 100644 .github/workflows/flang-integration-test-check.yml

diff --git a/.github/workflows/flang-integration-test-check.yml b/.github/workflows/flang-integration-test-check.yml
new file mode 100644
index 00000000000000..452b650db0beb7
--- /dev/null
+++ b/.github/workflows/flang-integration-test-check.yml
@@ -0,0 +1,104 @@
+name: Flang integration test check
+
+on:
+  pull_request_target:
+    types: [opened, synchronize, reopened]
+    paths:
+      - "flang/test/**"
+
+# This workflow only inspects file patches through the GitHub API. In
+# particular, it must not check out or execute code from the pull request.
+permissions:
+  contents: read
+  pull-requests: write
+
+jobs:
+  check-for-full-pipeline-tests:
+    runs-on: ubuntu-24.04
+    steps:
+      - name: Check for new full-pipeline test invocations
+        uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+        with:
+          script: |
+            const marker = "<!-- flang-integration-test-check -->";
+            const pr = context.payload.pull_request;
+
+            const files = await github.paginate(
+              github.rest.pulls.listFiles,
+              {
+                owner: context.repo.owner,
+                repo: context.repo.repo,
+                pull_number: pr.number,
+                per_page: 100,
+              },
+            );
+
+            const findings = [];
+            for (const file of files) {
+              if (!file.filename.startsWith("flang/test/") || !file.patch)
+                continue;
+
+              // Only report newly added uses. Existing full-pipeline tests do
+              // not need to be justified again when an unrelated line changes.
+              const addsEmitLLVM = file.patch.split("\n").some(
+                line => /^\+(?!\+\+)/.test(line) && /\bRUN:/.test(line) &&
+                  /(^|\s)-emit-llvm(?=\s|=|$)/.test(line),
+              );
+              if (addsEmitLLVM)
+                findings.push(`- \`${file.filename}\``);
+            }
+
+            const comments = await github.paginate(
+              github.rest.issues.listComments,
+              {
+                owner: context.repo.owner,
+                repo: context.repo.repo,
+                issue_number: pr.number,
+                per_page: 100,
+              },
+            );
+            const previous = comments.find(
+              comment => comment.user.type === "Bot" && comment.body.includes(marker),
+            );
+
+            if (findings.length === 0) {
+              if (previous) {
+                await github.rest.issues.deleteComment({
+                  owner: context.repo.owner,
+                  repo: context.repo.repo,
+                  comment_id: previous.id,
+                });
+              }
+              return;
+            }
+
+            const body = [
+              marker,
+              "This pull request adds a Flang test invocation that exercises the compiler " +
+                "pipeline through LLVM IR generation:",
+              "",
+              findings.join("\n"),
+              "",
+              "Please consider whether the same behavior can be covered by a focused test " +
+                "that stops at the relevant compiler stage. If LLVM IR generation is " +
+                "necessary, add a nearby, test-specific comment explaining why. See the " +
+                "[Flang integration test guidance](https://github.com/llvm/llvm-project/blob/main/flang/test/Integration/README.md).",
+              "",
+              "_This is an informational reminder; it does not fail the workflow._",
+            ].join("\n");
+
+            if (previous) {
+              await github.rest.issues.updateComment({
+                owner: context.repo.owner,
+                repo: context.repo.repo,
+                comment_id: previous.id,
+                body,
+              });
+            } else {
+              await github.rest.issues.createComment({
+                owner: context.repo.owner,
+                repo: context.repo.repo,
+                issue_number: pr.number,
+                body,
+              });
+            }

>From 11e14ee13fdebc29bd0a4f8f4c1d9320f60b91bb Mon Sep 17 00:00:00 2001
From: Kiran Chandramohan <kiran.chandramohan at arm.com>
Date: Tue, 22 Sep 2026 17:46:38 +0200
Subject: [PATCH 2/2] Address security warning and limit the action to the
 llvm-project repo

---
 .github/workflows/flang-integration-test-check.yml | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/.github/workflows/flang-integration-test-check.yml b/.github/workflows/flang-integration-test-check.yml
index 452b650db0beb7..b03af46ee2caaf 100644
--- a/.github/workflows/flang-integration-test-check.yml
+++ b/.github/workflows/flang-integration-test-check.yml
@@ -1,19 +1,23 @@
 name: Flang integration test check
 
 on:
-  pull_request_target:
+  # This workflow needs pull_request_target so it can comment on pull requests
+  # from forks. It only examines patches using the GitHub API and never checks
+  # out or executes code from the pull request branch.
+  pull_request_target: # zizmor: ignore[dangerous-triggers]
     types: [opened, synchronize, reopened]
     paths:
       - "flang/test/**"
 
-# This workflow only inspects file patches through the GitHub API. In
-# particular, it must not check out or execute code from the pull request.
 permissions:
   contents: read
-  pull-requests: write
 
 jobs:
   check-for-full-pipeline-tests:
+    if: github.repository == 'llvm/llvm-project'
+    permissions:
+      contents: read
+      pull-requests: write
     runs-on: ubuntu-24.04
     steps:
       - name: Check for new full-pipeline test invocations



More information about the llvm-commits mailing list