You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CI.md
+13-7Lines changed: 13 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,6 +8,12 @@ For local test commands see [TESTING.md](TESTING.md). For PR conventions see [CO
8
8
9
9
PR CI that runs on NVIDIA self-hosted runners uses NVIDIA's copy-pr-bot. The bot mirrors trusted PR commits to internal `pull-request/<N>` branches in this repository. The gated workflows trigger on pushes to those branches, not on the original PR.
10
10
11
+
When a PR is not mirrored automatically, only the GitHub users listed in
12
+
`.github/copy-pr-bot.yaml` under `vetters_override` can admit its current
13
+
revision with `/ok to test <SHA>`. The list is a snapshot of the codeowners
14
+
and selected repository maintainers; update it when those people change.
15
+
This setting does not change the bot's automatic trust policy for ready PRs.
16
+
11
17
`Branch Checks` run automatically after copy-pr-bot mirrors the PR. `Required CI Gates` posts PR-head statuses that verify the mirror exists, is current, and ran the expected push-based workflows. E2E suites are opt-in because they are more expensive and publish temporary images.
12
18
13
19
Merge queue validation is a second integration gate for `main`. After a PR has passed the required PR-head statuses, a maintainer adds it to the merge queue. GitHub creates a temporary merge-group branch that combines the latest `main`, the queued PR, and any earlier queued PRs. The same required `OpenShell / ...` status contexts are then published against the merge-group SHA before GitHub merges it.
@@ -313,21 +319,21 @@ Flow:
313
319
6. New commits push to the mirror automatically and re-trigger `Branch Checks` plus any labeled E2E jobs in `Branch E2E Checks`.
314
320
7. When the PR is ready to merge, use **Add to merge queue** instead of merging directly. The queue validates the final integration state before updating `main`.
315
321
316
-
### Forked PR
322
+
### PR requiring manual admission
317
323
318
324
Prerequisites:
319
325
320
-
- DCO sign-off (`git commit -s`) on every commit. Commit signing is not required for forks - copy-pr-bot trusts forks based on maintainer review, not signing.
321
-
- A maintainer must vouch you. See the [Vouch System](AGENTS.md#vouch-system).
326
+
- DCO sign-off (`git commit -s`) on every commit. Manual admission does not require cryptographic commit signing.
327
+
- First-time external contributors must be vouched. See the [Vouch System](AGENTS.md#vouch-system).
322
328
323
329
Flow:
324
330
325
-
1. Open the PR. The vouch check confirms you are vouched (otherwise the PR is auto-closed).
326
-
2. copy-pr-bot does not mirror forks automatically. A maintainer reviews the diff and comments `/ok to test <SHA>` with your latest commit SHA.
327
-
3. After `/ok to test`, copy-pr-bot mirrors to `pull-request/<N>`. From here the flow is identical to internal PRs: `Required CI Gates`verifies the mirror and required push workflows, and maintainers apply the E2E label when the extra suites are needed.
331
+
1. Open the PR. The vouch check confirms first-time external contributors are vouched (otherwise their PRs are auto-closed).
332
+
2. If copy-pr-bot does not mirror it automatically, a listed vetter reviews the diff and comments `/ok to test <SHA>` with the latest commit SHA. Fork location alone does not determine whether a PR is mirrored automatically.
333
+
3. After `/ok to test`, copy-pr-bot mirrors to `pull-request/<N>`. From here the flow is identical to automatically admitted PRs: `Required CI Gates`verifies the mirror and required push workflows, and maintainers apply the E2E label when the extra suites are needed.
328
334
4. When the PR is ready to merge, maintainers add it to the merge queue so the queued integration state is tested before it reaches `main`.
329
335
330
-
Important: every new commit you push requires another `/ok to test <new-SHA>` from a maintainer before push-based CI will run on it. If a label is applied while the mirror is stale, `E2E Label Help` will post a comment explaining what's needed.
336
+
Important: if a PR requires manual admission, every new commit needs another `/ok to test <new-SHA>` from a listed vetter before push-based CI will run on it. If a label is applied while the mirror is stale, `E2E Label Help` will post a comment explaining what's needed.
Copy file name to clipboardExpand all lines: architecture/build.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -372,6 +372,10 @@ the release tag.
372
372
373
373
Required checks run on GitHub Actions. Pull-request workflows that use NVIDIA self-hosted runners trigger from copy-pr-bot mirror branches, so trusted PRs are mirrored into `pull-request/<N>` branches before those workflows run. `main` also uses GitHub merge queue so the final queued integration commit is validated before it merges.
374
374
375
+
For PRs that need manual admission, copy-pr-bot accepts `/ok to test <SHA>`
376
+
only from the explicit `vetters_override` list in `.github/copy-pr-bot.yaml`.
377
+
This list is maintained separately from the bot's automatic PR trust policy.
378
+
375
379
The high-level CI model:
376
380
377
381
1. PR-context gate jobs publish required statuses for the PR head commit.
0 commit comments