Wire mergedTracerTags as a read-through parent at span build (level-split) (phase 1a) #19251
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Validate PR Label Format | |
| on: | |
| pull_request: | |
| types: [opened, edited, ready_for_review, labeled, synchronize] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| check_pr_labels: | |
| name: Check pull request labels | |
| permissions: | |
| id-token: write # Required for OIDC token federation | |
| issues: write | |
| pull-requests: write | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Get GitHub Token via dd-octo-sts | |
| id: generate-token | |
| uses: DataDog/dd-octo-sts-action@96a25462dbcb10ebf0bfd6e2ccc917d2ab235b9a # v1.0.4 | |
| with: | |
| scope: DataDog/dd-trace-java | |
| policy: self.check-pull-request-labels | |
| - name: Clean up tool labels | |
| id: clean_up_labels | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # 9.0.0 | |
| with: | |
| github-token: ${{ steps.generate-token.outputs.token }} | |
| script: | | |
| // Skip draft pull requests | |
| if (context.payload.pull_request.draft) { | |
| return | |
| } | |
| const prNumber = context.payload.pull_request.number | |
| const owner = context.repo.owner | |
| const repo = context.repo.repo | |
| // Labels applied by external tooling that are never allowed on a pull request | |
| const toolLabels = [ | |
| 'Bits AI', // Applied by the Bits AI tooling | |
| 'campaigner-automated-change' // Applied by the Campaigner tooling | |
| ] | |
| const prLabels = context.payload.pull_request.labels.map(l => l.name) | |
| const cleanedLabels = toolLabels.filter(label => prLabels.includes(label)) | |
| for (const label of cleanedLabels) { | |
| // Remove label from the PR | |
| try { | |
| await github.rest.issues.removeLabel({ | |
| owner, repo, | |
| issue_number: prNumber, | |
| name: label | |
| }) | |
| } catch (e) { | |
| core.warning(`Could not remove '${label}' label from PR: ${e.message}`) | |
| } | |
| // Delete label from the repository as the tooling applying it also recreates it | |
| try { | |
| await github.rest.issues.deleteLabel({ owner, repo, name: label }) | |
| } catch (e) { | |
| core.warning(`Could not delete '${label}' label from repo: ${e.message}`) | |
| } | |
| } | |
| core.setOutput('cleaned_labels', JSON.stringify(cleanedLabels)) | |
| - name: Flag AI-generated pull requests | |
| id: flag_ai_generated | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # 9.0.0 | |
| env: | |
| CLEANED_LABELS: ${{ steps.clean_up_labels.outputs.cleaned_labels }} | |
| with: | |
| github-token: ${{ steps.generate-token.outputs.token }} | |
| script: | | |
| // Skip draft pull requests | |
| if (context.payload.pull_request.draft) { | |
| return | |
| } | |
| const prNumber = context.payload.pull_request.number | |
| const owner = context.repo.owner | |
| const repo = context.repo.repo | |
| // Skip if the PR is already labeled as AI-generated | |
| const aiGeneratedLabel = 'tag: ai generated' | |
| if (context.payload.pull_request.labels.some(l => l.name === aiGeneratedLabel)) { | |
| core.info(`PR #${prNumber} is already labeled as AI-generated, skipping commit scan.`) | |
| return | |
| } | |
| // The cleaned up 'Bits AI' label flags an AI-generated pull request | |
| let isAiGenerated = JSON.parse(process.env.CLEANED_LABELS || '[]').includes('Bits AI') | |
| // Inspect commits for AI authorship signals | |
| if (!isAiGenerated) { | |
| const aiRegex = /\b(anthropic|chatgpt|codex|copilot|cursor|openai)\b/i | |
| const commits = await github.paginate(github.rest.pulls.listCommits, { | |
| owner, repo, | |
| pull_number: prNumber, | |
| per_page: 100 | |
| }) | |
| for (const { commit } of commits) { | |
| const authorName = commit.author?.name ?? '' | |
| const authorEmail = commit.author?.email ?? '' | |
| const committerName = commit.committer?.name ?? '' | |
| const committerEmail = commit.committer?.email ?? '' | |
| // Extract Co-authored-by trailer lines from commit message | |
| const coAuthors = (commit.message ?? '').split('\n') | |
| .filter(line => /^co-authored-by:/i.test(line.trim())) | |
| const fieldsToCheck = [authorName, authorEmail] | |
| // Skip GitHub's generic noreply for committer | |
| if (committerEmail !== 'noreply@github.com') { | |
| fieldsToCheck.push(committerName, committerEmail) | |
| } | |
| fieldsToCheck.push(...coAuthors) | |
| if (fieldsToCheck.some(field => aiRegex.test(field))) { | |
| isAiGenerated = true | |
| break | |
| } | |
| } | |
| } | |
| // Add 'tag: ai generated' label if AI-generated | |
| if (isAiGenerated) { | |
| try { | |
| await github.rest.issues.addLabels({ | |
| owner, repo, | |
| issue_number: prNumber, | |
| labels: [aiGeneratedLabel] | |
| }) | |
| core.info(`Added '${aiGeneratedLabel}' label to PR #${prNumber}`) | |
| } catch (e) { | |
| core.setFailed(`Could not add '${aiGeneratedLabel}' label to PR #${prNumber}: ${e.message}`) | |
| } | |
| } | |
| - name: Check pull request labels | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # 9.0.0 | |
| env: | |
| CLEANED_LABELS: ${{ steps.clean_up_labels.outputs.cleaned_labels }} | |
| with: | |
| github-token: ${{ steps.generate-token.outputs.token }} | |
| script: | | |
| // Skip draft pull requests | |
| if (context.payload.pull_request.draft) { | |
| return | |
| } | |
| // Define valid label categories | |
| const validCategories = [ | |
| 'type:', | |
| 'comp:', | |
| 'inst:', | |
| 'tag:', | |
| 'performance:', // To refactor to 'ci: ' in the future | |
| 'run-tests:' // Unused since GitLab migration | |
| ] | |
| // Re-fetch labels only if the clean up step removed some of them | |
| let prLabels | |
| if (JSON.parse(process.env.CLEANED_LABELS || '[]').length > 0) { | |
| const { data: currentPr } = await github.rest.pulls.get({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| pull_number: context.payload.pull_request.number | |
| }) | |
| prLabels = currentPr.labels | |
| } else { | |
| prLabels = context.payload.pull_request.labels | |
| } | |
| // Look for invalid labels | |
| const invalidLabels = prLabels | |
| .map(label => label.name) | |
| .filter(label => validCategories.every(prefix => !label.startsWith(prefix))) | |
| const hasInvalidLabels = invalidLabels.length > 0 | |
| // Get existing comments to check for blocking comment | |
| const comments = await github.rest.issues.listComments({ | |
| issue_number: context.payload.pull_request.number, | |
| owner: context.repo.owner, | |
| repo: context.repo.repo | |
| }) | |
| const commentMarker = '<!-- dd-trace-java-check-pr-labels-workflow -->' | |
| let blockingComment = comments.data.find(comment => comment.body.includes(commentMarker)) | |
| // Create or update blocking comment if there are invalid labels | |
| if (hasInvalidLabels) { | |
| const commentBody = '**PR Blocked - Invalid Label**\n\n' + | |
| `The pull request introduced unexpected labels:\n\n` + | |
| invalidLabels.map(label => `* \`${label}\``).join('\n') + '\n\n' + | |
| '**This PR is blocked until:**\n' + | |
| '1. The invalid labels are deleted, and\n' + | |
| '2. A maintainer deletes this comment to unblock the PR\n\n' + | |
| '**Note:** Simply removing labels from the pull request is not enough - a maintainer must delete this comment then remove the label to remove the block.\n\n' + | |
| commentMarker | |
| if (blockingComment) { | |
| // Update existing blocking comment | |
| await github.rest.issues.updateComment({ | |
| comment_id: blockingComment.id, | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| body: commentBody | |
| }) | |
| } else { | |
| // Create new blocking comment | |
| await github.rest.issues.createComment({ | |
| issue_number: context.payload.pull_request.number, | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| body: commentBody | |
| }) | |
| } | |
| blockingComment = true | |
| } | |
| if (blockingComment) { | |
| // Block the PR by failing the workflow | |
| if (hasInvalidLabels) { | |
| core.setFailed(`PR blocked: Invalid labels detected: (${invalidLabels.join(', ')}). A maintainer must delete the blocking comment after fixing the labels to allow merging.`) | |
| } else { | |
| core.setFailed(`PR blocked: A previous blocking comment still exists. A maintainer must delete it to allow merging.`) | |
| } | |
| } |