Copilot commented on code in PR #12388:
URL: https://github.com/apache/gluten/pull/12388#discussion_r3659868584
##########
.github/workflows/velox_backend_x86.yml:
##########
@@ -101,6 +106,70 @@ jobs:
path: ./cpp/build/
if-no-files-found: error
+ # Gate the (expensive) Delta Spark UT suite so per-PR it runs only when the
PR
+ # touches high-signal Delta paths -- the Delta integration code
+ # (backends-velox/src-delta*), the gluten-delta module, or this pipeline's
own
+ # files -- or carries the `run-delta-ci` opt-in label. Changes to general
+ # Velox/core/native code can also affect Delta offload but are touched
+ # constantly, so per-PR they skip it; the nightly full run
(delta_spark_ut.yml
+ # `schedule`) and the opt-in label are the safety nets. This keeps GHA usage
+ # down. NOTE: the label is read from the event that triggered this run, so
add
+ # it before/with a push; labeling an already-finished run needs a new push.
+ delta-changes:
+ runs-on: ubuntu-22.04
+ outputs:
+ run_delta: ${{ steps.filter.outputs.run_delta }}
+ steps:
+ - uses: actions/checkout@v4
+ with:
+ fetch-depth: 0
+ - name: Detect Delta-relevant changes / opt-in label
+ id: filter
+ env:
+ HAS_LABEL: ${{ contains(github.event.pull_request.labels.*.name,
'run-delta-ci') }}
+ BASE_SHA: ${{ github.event.pull_request.base.sha }}
+ HEAD_SHA: ${{ github.event.pull_request.head.sha }}
Review Comment:
These expressions dereference `github.event.pull_request.*` unconditionally,
but the step script explicitly anticipates non-PR triggers. On non-PR events,
this can fail at workflow evaluation time before the shell `fail-open` logic
runs. Guard the expressions (e.g., condition on `github.event_name ==
'pull_request'`) and default to empty strings/false when not a PR.
##########
.github/workflows/util/delta-spark-ut/setup-delta.sh:
##########
@@ -0,0 +1,208 @@
+#!/usr/bin/env bash
+
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+#
+# Prepares a delta-io/delta clone for running its `spark` module tests with the
+# Gluten (Velox) bundle jar on the classpath.
+#
+# Usage:
+# setup-delta.sh <delta_ref> <delta_dir> <gluten_bundle_jar>
<gluten_repo_root>
+#
+# Arguments:
+# delta_ref - git ref (tag/branch/sha) to check out (e.g. v4.2.0)
+# delta_dir - destination directory for the Delta clone
+# gluten_bundle_jar - path to the gluten-velox-bundle fat jar
+# gluten_repo_root - path to the Gluten repository root (used to locate
+#
backends-velox/src-delta40/.../DeltaSQLCommandTest.scala)
+#
+
+set -euo pipefail
+
+if [ "$#" -ne 4 ]; then
+ echo "Usage: $0 <delta_ref> <delta_dir> <gluten_bundle_jar>
<gluten_repo_root>" >&2
+ exit 1
+fi
+
+DELTA_REF="$1"
+DELTA_DIR="$2"
+GLUTEN_BUNDLE_JAR="$3"
+GLUTEN_ROOT="$4"
+
+if [ ! -f "$GLUTEN_BUNDLE_JAR" ]; then
+ echo "Gluten bundle jar not found: $GLUTEN_BUNDLE_JAR" >&2
+ exit 1
+fi
+
+# Reuse the existing DeltaSQLCommandTest from Gluten's backends-velox module
+# rather than maintaining a separate copy. This file is compiled as part of the
+# unified `spark` project's Test scope, which has the Gluten bundle on its
+# classpath (via spark-unified/lib/), so the typed GlutenConfig /
VeloxDeltaConfig
+# imports resolve correctly.
+PATCH_SOURCE="$GLUTEN_ROOT/backends-velox/src-delta40/test/scala/org/apache/spark/sql/delta/test/DeltaSQLCommandTest.scala"
+if [ ! -f "$PATCH_SOURCE" ]; then
+ echo "Gluten DeltaSQLCommandTest not found: $PATCH_SOURCE" >&2
+ exit 1
+fi
+
+echo "::group::Cloning delta-io/delta @ ${DELTA_REF}"
+# init + shallow fetch resolves a tag, branch OR commit SHA in a single path
+# (`git clone --branch` rejects SHAs). Avoids a full-clone fallback and the
+# destructive `rm -rf "$DELTA_DIR"` it required. `--` terminates options so a
+# DELTA_REF starting with `-` can't be misread as a git flag (this script is
+# workflow_dispatch-runnable with a user-supplied ref).
+git init -q "$DELTA_DIR"
+git -C "$DELTA_DIR" remote add origin https://github.com/delta-io/delta.git
+git -C "$DELTA_DIR" fetch -q --depth 1 origin -- "$DELTA_REF"
+git -C "$DELTA_DIR" checkout -q FETCH_HEAD
+git -C "$DELTA_DIR" --no-pager log -1 --oneline
+echo "::endgroup::"
+
+echo "::group::Injecting Gluten bundle jar onto the spark project's TEST
classpath"
+# The Gluten bundle jar must be on the spark project's TEST runtime classpath
+# (so DeltaSQLCommandTest can load org.apache.gluten.GlutenPlugin by name) but
+# NOT on the COMPILE classpath of `sparkV1`, which is the project that holds
+# Delta's main sources. The bundle's transitive contents include extra symbols
+# under `org.apache.spark.sql` that collide with Delta's main sources -- e.g.
+# MergeOutputGeneration.scala imports both `org.apache.spark.sql._` and
+# `org.apache.spark.sql.delta.ClassicColumnConversions._`, and would then fail
+# with `reference to expression is ambiguous`.
+#
+# sbt auto-scans `<baseDirectory>/lib` via `unmanagedBase`. Two relevant
+# projects in Delta v4.2.0 have a `lib/` baseDirectory:
+# - sparkV1: `project in file("spark")` -> spark/lib
+# - spark : `project in file("spark-unified")` -> spark-unified/lib
+# unmanagedJars are project-scoped (NOT inherited by dependents), so dropping
+# the bundle into spark-unified/lib/ adds it to the unified `spark` project's
+# Compile *and* Test classpaths -- but NOT to sparkV1's. That's exactly what
+# we want:
+# * sparkV1/Compile sees ONLY Delta's regular deps -> Delta main compiles.
+# * spark/Test/fullClasspath sees the bundle -> tests load GlutenPlugin.
+# (Verified empirically: with bundle only in spark-unified/lib/, sbt's
+# `show sparkV1/Compile/dependencyClasspath` excludes the bundle and
+# `show spark/Test/fullClasspath` includes it.)
+#
+# We deliberately do NOT also drop the bundle into spark/lib/, which is what
+# caused the previous compile failure: spark/lib/ is sparkV1's unmanagedBase,
+# and putting the bundle there would re-introduce the ambiguity errors.
+SPARK_UNIFIED_LIB="$DELTA_DIR/spark-unified/lib"
+mkdir -p "$SPARK_UNIFIED_LIB"
+cp "$GLUTEN_BUNDLE_JAR" "$SPARK_UNIFIED_LIB/gluten-velox-bundle.jar"
+ls -lh "$SPARK_UNIFIED_LIB"
+echo "::endgroup::"
+
+echo "::group::Patching DeltaSQLCommandTest to enable Gluten plugin"
+TARGET="$DELTA_DIR/spark/src/test/scala/org/apache/spark/sql/delta/test/DeltaSQLCommandTest.scala"
+if [ ! -f "$TARGET" ]; then
+ echo "Expected file not found in Delta clone: $TARGET" >&2
+ echo "The Delta directory layout for ref '${DELTA_REF}' may have changed."
+ exit 1
+fi
+cp "$PATCH_SOURCE" "$TARGET"
+echo "Patched $TARGET"
+echo "--- diff vs. upstream ---"
+git -C "$DELTA_DIR" --no-pager diff --
"spark/src/test/scala/org/apache/spark/sql/delta/test/DeltaSQLCommandTest.scala"
|| true
+echo "::endgroup::"
+
+# Delta's tests collect file-source scans by matching the concrete
+# `FileSourceScanExec` case class; Gluten offloads the scan to
+# DeltaScanTransformer, a `FileSourceScanLike` sibling, so those matches miss
+# (`scala.MatchError: List()`, empty partition filters, broken column-pruning /
+# scan-metric checks across many suites). delta-io/delta#7104 and #7105 widen
the
+# matches to the shared `FileSourceScanLike` interface that both the vanilla
and
+# Gluten scans implement (behavior-preserving for vanilla). Both are merged
+# upstream but land after the pinned DELTA_REF (v4.2.0), so apply them here;
once
+# DELTA_REF includes a commit its cherry-pick is a clean no-op and the call
can go.
+#
+# Depth-2 fetch brings each fix commit and its parent, which cherry-pick needs
to
+# diff against (a depth-1 fetch grafts the parent away); `-n` stages the change
+# without requiring a committer identity.
+cherry_pick_delta_fix() {
+ local sha="$1" pr="$2"
+ echo "Cherry-picking delta-io/delta${pr}"
+ git -C "$DELTA_DIR" fetch --quiet --depth 2 origin "$sha"
+ git -C "$DELTA_DIR" cherry-pick -n "$sha"
+}
+
+echo "::group::Cherry-picking upstream Delta FileSourceScanLike test fixes"
+cherry_pick_delta_fix 46bd45d57eadd7e528002a0ae7bd36ce5a456eca "#7104
(ScanReportHelper.collectScans)"
+cherry_pick_delta_fix 959e00e15f41f56afc1c9bb95d160c55c6dc7068 "#7105 (9 more
test suites)"
Review Comment:
Despite the comment claiming this becomes a 'clean no-op' when `DELTA_REF`
already contains the fix, `git cherry-pick` typically fails (empty change /
already applied) and can leave the repo in a cherry-pick state, breaking the
workflow for newer Delta refs. Add an explicit 'already contained' check (e.g.,
`merge-base --is-ancestor`) to skip, or handle empty cherry-picks by
aborting/skipping safely.
##########
.github/workflows/delta_spark_ut.yml:
##########
@@ -0,0 +1,459 @@
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+# Runs Delta Lake's `spark` sbt module unit tests against a Gluten Velox bundle
+# that is built from the source in this repository. The pipeline:
+#
+# 1. Builds the Velox/Gluten native libraries (centos-7 + vcpkg, x86_64).
+# 2. Builds the Gluten Java/Scala jars and assembles the
+# `gluten-velox-bundle-spark<spark>_<scala>-linux_amd64-<version>.jar`
+# fat jar for Spark 4.1 + Scala 2.13 + Java 17 with the Delta profile.
+# 3. Clones delta-io/delta at the requested release tag (default `v4.2.0`),
+# drops the bundle jar into `spark-unified/lib/` only (NOT `spark/lib/`
+# -- see setup-delta.sh for the unmanagedJars scoping rationale),
+# patches Delta's `DeltaSQLCommandTest` to register the Gluten plugin,
+# and runs `sbt spark/test` sharded across the matrix.
+#
+# Limited to Velox + x86 to keep the matrix simple, per the pipeline's purpose
+# of validating Gluten changes against the latest Delta release.
+
+name: Delta Spark UT (Gluten)
+
+on:
+ # Reusable workflow. velox_backend_x86.yml calls this (gated on
Delta-relevant
+ # changes) and passes the native-lib artifact it already built, so the
expensive
+ # native C++ build is NOT duplicated. That artifact lives in the CALLER's
run (a
+ # called workflow runs as part of the caller run), so the jobs below
download it
+ # by name. See velox_backend_x86.yml `delta-spark-ut`.
+ #
+ # NOTE: the `pull_request` trigger was removed so this no longer runs as its
own
+ # workflow on PRs (which would double-run the Delta suite).
velox_backend_x86.yml
+ # is now the single PR entry point; `workflow_dispatch` keeps manual
standalone
+ # runs working (those build the native lib themselves -- see
build-native-lib).
+ workflow_call:
+ inputs:
+ native_lib_artifact:
+ description: 'Name of the cpp/build artifact uploaded by the caller'
+ type: string
+ required: true
+ delta_ref:
+ type: string
+ required: false
+ default: 'v4.2.0'
+ spark_version:
+ description: 'Spark version driving both the Gluten bundle profile
(-Pspark-<v>) and Delta -DsparkVersion.'
+ type: string
+ required: false
+ default: '4.1'
+ test_parallelism:
+ type: string
+ required: false
+ default: '4'
+ update_baseline:
+ type: boolean
+ required: false
+ default: false
+ fail_on_fixed:
+ type: boolean
+ required: false
+ default: true
+ workflow_dispatch:
+ inputs:
+ delta_ref:
+ description: 'delta-io/delta git ref (tag/branch/SHA) to test against'
+ required: true
+ default: 'v4.2.0'
+ spark_version:
+ description: 'Spark version: drives the Gluten bundle profile
(-Pspark-<v>) and Delta -DsparkVersion together. Scala 2.13 + JDK 17 are
assumed, so pair a non-4.1 value with a compatible delta_ref.'
+ required: true
+ default: '4.1'
+ test_parallelism:
+ description: 'Forked test JVMs per shard (TEST_PARALLELISM_COUNT)'
+ required: true
+ default: '4'
+ update_baseline:
+ description: 'Seed/refresh the known-failures baseline instead of
enforcing it'
+ type: boolean
+ required: false
+ default: false
+ fail_on_fixed:
+ description: 'Fail when a baseline test now passes (keeps the baseline
honest)'
+ type: boolean
+ required: false
+ default: true
+ # Nightly full run against the latest default branch. The per-PR entry point
+ # (velox_backend_x86.yml) now runs the Delta suite only when a PR touches
+ # Delta-relevant paths (or carries the opt-in label), to save GHA minutes;
this
+ # scheduled run keeps full coverage once a day so rarer regressions are still
+ # caught. It builds its own native lib (build-native-lib-centos-7 below)
since
+ # there is no caller to provide one, and uses the workflow's default inputs.
+ schedule:
+ - cron: '0 5 * * *'
+
+env:
+ ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true
Review Comment:
Setting `ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true` relaxes GitHub
Actions Node runtime restrictions and can re-enable deprecated/insecure Node
versions for actions. If not strictly required, remove it; otherwise, prefer
updating/pinning actions to versions that run on supported Node runtimes so
this flag isn't needed.
##########
.github/workflows/delta_spark_ut.yml:
##########
@@ -0,0 +1,459 @@
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+# Runs Delta Lake's `spark` sbt module unit tests against a Gluten Velox bundle
+# that is built from the source in this repository. The pipeline:
+#
+# 1. Builds the Velox/Gluten native libraries (centos-7 + vcpkg, x86_64).
+# 2. Builds the Gluten Java/Scala jars and assembles the
+# `gluten-velox-bundle-spark<spark>_<scala>-linux_amd64-<version>.jar`
+# fat jar for Spark 4.1 + Scala 2.13 + Java 17 with the Delta profile.
+# 3. Clones delta-io/delta at the requested release tag (default `v4.2.0`),
+# drops the bundle jar into `spark-unified/lib/` only (NOT `spark/lib/`
+# -- see setup-delta.sh for the unmanagedJars scoping rationale),
+# patches Delta's `DeltaSQLCommandTest` to register the Gluten plugin,
+# and runs `sbt spark/test` sharded across the matrix.
+#
+# Limited to Velox + x86 to keep the matrix simple, per the pipeline's purpose
+# of validating Gluten changes against the latest Delta release.
+
+name: Delta Spark UT (Gluten)
+
+on:
+ # Reusable workflow. velox_backend_x86.yml calls this (gated on
Delta-relevant
+ # changes) and passes the native-lib artifact it already built, so the
expensive
+ # native C++ build is NOT duplicated. That artifact lives in the CALLER's
run (a
+ # called workflow runs as part of the caller run), so the jobs below
download it
+ # by name. See velox_backend_x86.yml `delta-spark-ut`.
+ #
+ # NOTE: the `pull_request` trigger was removed so this no longer runs as its
own
+ # workflow on PRs (which would double-run the Delta suite).
velox_backend_x86.yml
+ # is now the single PR entry point; `workflow_dispatch` keeps manual
standalone
+ # runs working (those build the native lib themselves -- see
build-native-lib).
+ workflow_call:
+ inputs:
+ native_lib_artifact:
+ description: 'Name of the cpp/build artifact uploaded by the caller'
+ type: string
+ required: true
+ delta_ref:
+ type: string
+ required: false
+ default: 'v4.2.0'
+ spark_version:
+ description: 'Spark version driving both the Gluten bundle profile
(-Pspark-<v>) and Delta -DsparkVersion.'
+ type: string
+ required: false
+ default: '4.1'
+ test_parallelism:
+ type: string
+ required: false
+ default: '4'
+ update_baseline:
+ type: boolean
+ required: false
+ default: false
+ fail_on_fixed:
+ type: boolean
+ required: false
+ default: true
+ workflow_dispatch:
+ inputs:
+ delta_ref:
+ description: 'delta-io/delta git ref (tag/branch/SHA) to test against'
+ required: true
+ default: 'v4.2.0'
+ spark_version:
+ description: 'Spark version: drives the Gluten bundle profile
(-Pspark-<v>) and Delta -DsparkVersion together. Scala 2.13 + JDK 17 are
assumed, so pair a non-4.1 value with a compatible delta_ref.'
+ required: true
+ default: '4.1'
+ test_parallelism:
+ description: 'Forked test JVMs per shard (TEST_PARALLELISM_COUNT)'
+ required: true
+ default: '4'
+ update_baseline:
+ description: 'Seed/refresh the known-failures baseline instead of
enforcing it'
+ type: boolean
+ required: false
+ default: false
+ fail_on_fixed:
+ description: 'Fail when a baseline test now passes (keeps the baseline
honest)'
+ type: boolean
+ required: false
+ default: true
+ # Nightly full run against the latest default branch. The per-PR entry point
+ # (velox_backend_x86.yml) now runs the Delta suite only when a PR touches
+ # Delta-relevant paths (or carries the opt-in label), to save GHA minutes;
this
+ # scheduled run keeps full coverage once a day so rarer regressions are still
+ # caught. It builds its own native lib (build-native-lib-centos-7 below)
since
+ # there is no caller to provide one, and uses the workflow's default inputs.
+ schedule:
+ - cron: '0 5 * * *'
+
+env:
+ ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true
+ MVN_CMD: 'build/mvn -ntp'
+ CCACHE_DIR: "${{ github.workspace }}/.ccache"
+ # Gluten profile / bundle naming for the build-gluten-bundle and
+ # delta-spark-test jobs. `spark_version` is the single source of truth for
the
+ # Spark version: it drives the Gluten bundle profile (-Pspark-<v>), the
bundle
+ # jar name, and Delta's -DsparkVersion, so the tests always run against a
bundle
+ # built for the same Spark version (no separate value to keep in sync). Scala
+ # 2.13 + JDK 17 are pinned -- they match Delta v4.2.0's default Spark 4.1.0
from
+ # project/CrossSparkVersions.scala -- so pair a non-default spark_version
with a
+ # compatible delta_ref.
+ GLUTEN_SPARK_PROFILE: spark-${{ inputs.spark_version || '4.1' }}
+ GLUTEN_SCALA_PROFILE: 'scala-2.13'
+ GLUTEN_JAVA_PROFILE: 'java-17'
+ GLUTEN_BUNDLE_SPARK_VERSION: ${{ inputs.spark_version || '4.1' }}
+ GLUTEN_BUNDLE_SCALA_VERSION: '2.13'
+ DELTA_SCALA_VERSION: '2.13.16'
+ # Number of shards in the delta-spark-test matrix. Must equal the length of
+ # the `shard` matrix below.
+ #
+ # 4 shards x TEST_PARALLELISM_COUNT=4 gives ~16-way parallelism packed into 4
+ # runner jobs (4 forks each) rather than 16 single-fork jobs -- fewer
concurrent
+ # runners for the same throughput. Sharding is by SUITE; total work
+ # (~1250 shard-minutes) is fixed. Each forked test JVM uses ~4G (2G heap + 2G
+ # off-heap), so 4 forks plus the sbt launcher sit close to the ~16G runner
limit;
+ # this fits because the worst memory hog (DeletionVectorsSuite 2B-row) is
+ # force-failed in setup-delta.sh.
+ DELTA_NUM_SHARDS: '4'
+
+# No `concurrency:` here on purpose. As a reusable workflow this runs inside
the
+# caller's run, where `github.workflow` resolves to the CALLER's name -- a
group
+# keyed on it would collide with the caller's own group and, with
+# cancel-in-progress, could cancel the parent run. The caller's concurrency
+# already governs cancellation. (A standalone workflow_dispatch run just won't
+# auto-cancel, which is fine for infrequent manual runs.)
+
+jobs:
+ build-native-lib-centos-7:
+ # Standalone runs (workflow_dispatch + nightly schedule) build the native
lib
+ # here. When called by velox_backend_x86.yml the caller already built it
and
+ # passes it as an input, so this job is skipped and the duplicate build
avoided.
+ if: github.event_name == 'workflow_dispatch' || github.event_name ==
'schedule'
+ runs-on: ubuntu-22.04
+ steps:
+ - uses: actions/checkout@v4
+ - name: Get Ccache
+ uses: actions/cache/restore@v4
+ with:
+ path: '${{ env.CCACHE_DIR }}'
+ key: ccache-delta-spark-ut-centos7-release-default-${{github.sha}}
+ restore-keys: |
+ ccache-delta-spark-ut-centos7-release-default
+ ccache-centos7-release-default
+ - name: Build Gluten native libraries
+ run: |
+ docker run -v $GITHUB_WORKSPACE:/work -w /work
apache/gluten:vcpkg-centos-7-gcc13 bash -c "
+ set -e
+ yum install tzdata -y
+ df -a
+ cd /work
+ export CCACHE_DIR=/work/.ccache
+ export CCACHE_MAXSIZE=1G
+ mkdir -p /work/.ccache
+ ccache -sz
+ bash dev/ci-velox-buildstatic-centos-7.sh
+ ccache -s
+ "
+ - name: Save Ccache
+ if: always()
+ uses: actions/cache/save@v4
+ with:
+ path: '${{ env.CCACHE_DIR }}'
+ key: ccache-delta-spark-ut-centos7-release-default-${{github.sha}}
+ - uses: actions/upload-artifact@v4
+ with:
+ name: delta-spark-ut-native-lib-centos-7-${{github.sha}}
+ path: ./cpp/build/
+ if-no-files-found: error
+
+ build-gluten-bundle:
+ needs: build-native-lib-centos-7
+ # Run whether the native lib was built here (dispatch -> success) or
provided
+ # by the caller (workflow_call -> build-native-lib-centos-7 skipped).
+ if: ${{ always() && needs.build-native-lib-centos-7.result != 'failure' &&
needs.build-native-lib-centos-7.result != 'cancelled' }}
+ runs-on: ubuntu-22.04
+ container: apache/gluten:centos-9-jdk17
Review Comment:
The workflow relies on unpinned container image tags (e.g.,
`apache/gluten:centos-9-jdk17`). For stronger supply-chain security and
reproducibility, pin these images by digest (or at least by an immutable
version tag) so CI behavior can't change unexpectedly when the tag is updated.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]