Skip to content

Commit a00ea31

Browse files
authored
ci: restrict copy-pr-bot manual vetters (#3678)
Signed-off-by: Jim Meyer <jimeyer@nvidia.com>
1 parent 52cb8ec commit a00ea31

3 files changed

Lines changed: 35 additions & 7 deletions

File tree

‎.github/copy-pr-bot.yaml‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,21 @@
11
enabled: true
22
auto_sync_draft: false
33
auto_sync_ready: true
4+
vetters_override:
5+
- alangou
6+
- derekwaynecarr
7+
- drew
8+
- elezar
9+
- johnnygreco
10+
- johntmyers
11+
- kirit93
12+
- krishicks
13+
- matthewgrossman
14+
- mrunalp
15+
- pimlock
16+
- purp
17+
- SDAChess
18+
- shailendra-nv
19+
- sjenning
20+
- TaylorMutch
21+
- zredlined

‎CI.md‎

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,12 @@ For local test commands see [TESTING.md](TESTING.md). For PR conventions see [CO
88

99
PR CI that runs on NVIDIA self-hosted runners uses NVIDIA's copy-pr-bot. The bot mirrors trusted PR commits to internal `pull-request/<N>` branches in this repository. The gated workflows trigger on pushes to those branches, not on the original PR.
1010

11+
When a PR is not mirrored automatically, only the GitHub users listed in
12+
`.github/copy-pr-bot.yaml` under `vetters_override` can admit its current
13+
revision with `/ok to test <SHA>`. The list is a snapshot of the codeowners
14+
and selected repository maintainers; update it when those people change.
15+
This setting does not change the bot's automatic trust policy for ready PRs.
16+
1117
`Branch Checks` run automatically after copy-pr-bot mirrors the PR. `Required CI Gates` posts PR-head statuses that verify the mirror exists, is current, and ran the expected push-based workflows. E2E suites are opt-in because they are more expensive and publish temporary images.
1218

1319
Merge queue validation is a second integration gate for `main`. After a PR has passed the required PR-head statuses, a maintainer adds it to the merge queue. GitHub creates a temporary merge-group branch that combines the latest `main`, the queued PR, and any earlier queued PRs. The same required `OpenShell / ...` status contexts are then published against the merge-group SHA before GitHub merges it.
@@ -313,21 +319,21 @@ Flow:
313319
6. New commits push to the mirror automatically and re-trigger `Branch Checks` plus any labeled E2E jobs in `Branch E2E Checks`.
314320
7. When the PR is ready to merge, use **Add to merge queue** instead of merging directly. The queue validates the final integration state before updating `main`.
315321

316-
### Forked PR
322+
### PR requiring manual admission
317323

318324
Prerequisites:
319325

320-
- DCO sign-off (`git commit -s`) on every commit. Commit signing is not required for forks - copy-pr-bot trusts forks based on maintainer review, not signing.
321-
- A maintainer must vouch you. See the [Vouch System](AGENTS.md#vouch-system).
326+
- DCO sign-off (`git commit -s`) on every commit. Manual admission does not require cryptographic commit signing.
327+
- First-time external contributors must be vouched. See the [Vouch System](AGENTS.md#vouch-system).
322328

323329
Flow:
324330

325-
1. Open the PR. The vouch check confirms you are vouched (otherwise the PR is auto-closed).
326-
2. copy-pr-bot does not mirror forks automatically. A maintainer reviews the diff and comments `/ok to test <SHA>` with your latest commit SHA.
327-
3. After `/ok to test`, copy-pr-bot mirrors to `pull-request/<N>`. From here the flow is identical to internal PRs: `Required CI Gates` verifies the mirror and required push workflows, and maintainers apply the E2E label when the extra suites are needed.
331+
1. Open the PR. The vouch check confirms first-time external contributors are vouched (otherwise their PRs are auto-closed).
332+
2. If copy-pr-bot does not mirror it automatically, a listed vetter reviews the diff and comments `/ok to test <SHA>` with the latest commit SHA. Fork location alone does not determine whether a PR is mirrored automatically.
333+
3. After `/ok to test`, copy-pr-bot mirrors to `pull-request/<N>`. From here the flow is identical to automatically admitted PRs: `Required CI Gates` verifies the mirror and required push workflows, and maintainers apply the E2E label when the extra suites are needed.
328334
4. When the PR is ready to merge, maintainers add it to the merge queue so the queued integration state is tested before it reaches `main`.
329335

330-
Important: every new commit you push requires another `/ok to test <new-SHA>` from a maintainer before push-based CI will run on it. If a label is applied while the mirror is stale, `E2E Label Help` will post a comment explaining what's needed.
336+
Important: if a PR requires manual admission, every new commit needs another `/ok to test <new-SHA>` from a listed vetter before push-based CI will run on it. If a label is applied while the mirror is stale, `E2E Label Help` will post a comment explaining what's needed.
331337

332338
## Merge queue
333339

‎architecture/build.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -372,6 +372,10 @@ the release tag.
372372

373373
Required checks run on GitHub Actions. Pull-request workflows that use NVIDIA self-hosted runners trigger from copy-pr-bot mirror branches, so trusted PRs are mirrored into `pull-request/<N>` branches before those workflows run. `main` also uses GitHub merge queue so the final queued integration commit is validated before it merges.
374374

375+
For PRs that need manual admission, copy-pr-bot accepts `/ok to test <SHA>`
376+
only from the explicit `vetters_override` list in `.github/copy-pr-bot.yaml`.
377+
This list is maintained separately from the bot's automatic PR trust policy.
378+
375379
The high-level CI model:
376380

377381
1. PR-context gate jobs publish required statuses for the PR head commit.

0 commit comments

Comments
 (0)