Skip to content

fix(buildimages-update): keep full diff when Go-update PR is updated with final image tags - #57918

Draft
jinh-labs wants to merge 1 commit into
mainfrom
jinh/buildimages-update-reset-head-to-base
Draft

jinh-labs wants to merge 1 commit into
mainfrom
jinh/buildimages-update-reset-head-to-base

Conversation

@jinh-labs

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds a git reset --hard ${{ github.sha }} step after the conditional PR-branch checkout in .github/workflows/buildimages-update.yml. HEAD is then on the base ref before the dda inv task step runs.

Also adds short comments to the existing Fetch branch and Checkout branch steps to explain their intent.

Motivation

The workflow is dispatched twice per Go-update cycle: once with test image tags while the buildimages PR is still open, once with final tags after it merges. Both dispatches target the same PR branch, so the first dispatch creates the Go-update PR and the second updates it.

Earlier in the workflow, a Fetch branch step checks whether the PR branch exists on origin, and a Checkout branch step then checks it out locally if it does. On the first dispatch the branch does not yet exist and the checkout is skipped, so HEAD stays on the base ref. On the second dispatch the branch exists (created by the first dispatch), so it is checked out and HEAD ends up on the PR branch.

Because the PR branch already contains the Go bump commit, Update buildimages IDs and Go version calls dda inv -- -e buildimages.update --tag ... and only the image-tag file is modified. Peter-evans commits that single file onto a temp branch, then cherry-picks only commits that are new since the branch's remote tip (see create-or-update-branch.ts#L244-L247). The Go bump is already on origin, so it is excluded from the cherry-pick range, and the force-pushed PR branch is rewritten to contain only the one-file tag change. The PR collapses from a full Go update to a single-file update.

The fix resets HEAD to the dispatch SHA before the task step runs. The task then regenerates all Go and image-tag files from the base state, and peter-evans cherry-picks that complete commit onto the PR branch.

Describe how you validated your changes

The workflow can only run on main and release branches, so it can only be tested in a real scenario. The next Go-update cycle will be closely monitored for behaviour affected by this PR.

Additional Notes

  • ${{ github.sha }} is pinned (not origin/${{ github.ref_name }}) so every step in the job works against the same commit.
  • On a first dispatch the reset is a no-op since HEAD is already at github.sha.
  • Direct commits to the PR branch are not preserved by peter-evans' force-push regardless of this reset, so this change does not alter that invariant.

@dd-octo-sts dd-octo-sts Bot added the internal Identify a non-fork PR label Oct 9, 2026
@github-actions github-actions Bot added the short review PR is simple enough to be reviewed quickly label Oct 9, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI review by Codex (OpenAI) - workflow run

patch is correct. Resetting the working tree to the dispatch SHA lets the update task regenerate the complete Go and image changes on subsequent dispatches. No actionable regressions found. Validation was limited to static review; the workflow was not executed.

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🎯 Code Coverage (details)
• Patch Coverage: 100.00%
• Overall Coverage: 62.79% (+4.18%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 8035b70 | Docs | Give us feedback!

@dd-octo-sts

dd-octo-sts Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Files inventory check summary

File checks results against ancestor 8d6360c8:

Results for datadog-agent_7.86.0~devel.git.315.8035b70.pipeline.143721730-1_amd64.deb:

No change detected

Results for datadog-iot-agent_7.86.0~devel.git.315.8035b70.pipeline.143721730-1_amd64.deb:

No change detected

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal Identify a non-fork PR short review PR is simple enough to be reviewed quickly team/agent-build team/agent-devx team/agent-runtimes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant