From 605e9b144ed9fa40be5b84f5aa518e15cc032367 Mon Sep 17 00:00:00 2001 From: Moulik Aggarwal Date: Fri, 31 Jul 2026 09:20:40 +0530 Subject: [PATCH 1/3] ci: fix regen discovery and sed, guard release to upstream Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_0173tbY2QAvy8Sw2uVuHV4SP --- .github/workflows/regen.yml | 39 ++++++++++++++++++++++++++--------- .github/workflows/release.yml | 1 + scripts/regen.sh | 26 ++++++++++++----------- 3 files changed, 44 insertions(+), 22 deletions(-) diff --git a/.github/workflows/regen.yml b/.github/workflows/regen.yml index 1a783ef..b5a614d 100644 --- a/.github/workflows/regen.yml +++ b/.github/workflows/regen.yml @@ -16,17 +16,26 @@ jobs: steps: - uses: actions/checkout@v4 - - name: Discover latest archive version + - uses: bufbuild/buf-action@v1 + with: + setup_only: true + + - name: Discover latest schema commit id: latest run: | - current=$(grep -E 'readonly BUF_PY_VERSION="' scripts/regen.sh \ + current=$(grep -E 'readonly BUF_SCHEMA_COMMIT="' scripts/regen.sh \ | sed -E 's/.*="([^"]+)".*/\1/') echo "current=$current" >> "$GITHUB_OUTPUT" - # Buf does not expose a public version-list endpoint; we resolve - # `main` to a pinned ref by introspecting the redirect target. - latest=$(curl -sI \ - "https://buf.build/gen/archive/openstatus/api/protocolbuffers/python/main.zip" \ - | grep -i '^location:' | sed -E 's/.*\/([^/]+)\.zip.*/\1/' | tr -d '\r') + # Version string looks like 35.1.0.1.20260727085848+65e5c3248a1e; + # the commit suffix is the only coordinate shared across languages. + version=$(buf registry sdk version \ + --module=buf.build/openstatus/api \ + --plugin=buf.build/protocolbuffers/python) + latest="${version##*+}" + if [[ -z "$latest" || "$latest" == "$version" ]]; then + echo "::error::schema version discovery returned empty" + exit 1 + fi echo "latest=$latest" >> "$GITHUB_OUTPUT" - name: No-op when already up to date @@ -36,18 +45,28 @@ jobs: - name: Bump pin and regenerate if: steps.latest.outputs.latest != steps.latest.outputs.current run: | - sed -i -E "s/(readonly BUF_PY_VERSION=)\"[^\"]+\"/\1\"${{ steps.latest.outputs.latest }}\"/" \ + sed -i -E "s/(readonly BUF_SCHEMA_COMMIT=)\"[^\"]+\"/\1\"${{ steps.latest.outputs.latest }}\"/" \ scripts/regen.sh bash scripts/regen.sh + - name: Bump patch version + if: steps.latest.outputs.latest != steps.latest.outputs.current + run: | + cur=$(grep -oP '^version = "\K[^"]+' pyproject.toml) + IFS=. read -r maj min pat <<< "$cur" + next="$maj.$min.$((pat + 1))" + sed -i -E "0,/^version = \"[^\"]+\"/s//version = \"$next\"/" pyproject.toml + echo "bumped $cur -> $next" + - name: Open PR if: steps.latest.outputs.latest != steps.latest.outputs.current uses: peter-evans/create-pull-request@v6 with: + token: ${{ secrets.SDK_BOT_TOKEN || github.token }} branch: regen/${{ steps.latest.outputs.latest }} commit-message: "chore: bump buf schema to ${{ steps.latest.outputs.latest }}" title: "chore: bump buf schema to ${{ steps.latest.outputs.latest }}" body: | - Automated bump of the pinned `protocolbuffers/python` archive - version from `${{ steps.latest.outputs.current }}` to + Automated regeneration from `buf.build/openstatus/api` schema + commit `${{ steps.latest.outputs.current }}` to `${{ steps.latest.outputs.latest }}`. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index dc1adf1..ef1cf92 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -10,6 +10,7 @@ permissions: jobs: publish: + if: github.repository == 'openstatusHQ/sdk-python' name: build and publish to PyPI runs-on: ubuntu-latest environment: diff --git a/scripts/regen.sh b/scripts/regen.sh index ba0b6c9..2eaae73 100755 --- a/scripts/regen.sh +++ b/scripts/regen.sh @@ -1,9 +1,11 @@ #!/usr/bin/env bash set -euo pipefail -# Pinned Buf-generated archives for buf.build/openstatus/api. -# To upgrade: change this line, run `bash scripts/regen.sh`, commit the result. -readonly BUF_PY_VERSION="v35.0-7d7b7047611f.1" +# Schema commit of buf.build/openstatus/api that this tree was generated from. +# Change-detection marker only — the archive itself is fetched by the `main` +# label, since the archive URL uses a plugin-version coordinate that cannot be +# reconstructed from the commit alone. +readonly BUF_SCHEMA_COMMIT="65e5c3248a1e" # Transitive deps. Buf does not expose pinned versions for these from the # openstatus/api module, so we track main. The PHP plan ships empty initOnce() @@ -31,12 +33,12 @@ fetch() { unzip -q "${TMP}/${name}-${plugin}.zip" -d "${TMP}/${name}-${plugin}" } -fetch "openstatus/api" python "${BUF_PY_VERSION}" openstatus -fetch "openstatus/api" pyi "${BUF_PY_VERSION}" openstatus -fetch "${BUF_VALIDATE_REF}" python main bufvalidate -fetch "${BUF_VALIDATE_REF}" pyi main bufvalidate -fetch "${GNOSTIC_REF}" python main gnostic -fetch "${GNOSTIC_REF}" pyi main gnostic +fetch "openstatus/api" python main openstatus +fetch "openstatus/api" pyi main openstatus +fetch "${BUF_VALIDATE_REF}" python main bufvalidate +fetch "${BUF_VALIDATE_REF}" pyi main bufvalidate +fetch "${GNOSTIC_REF}" python main gnostic +fetch "${GNOSTIC_REF}" pyi main gnostic # Merge a top-level package from a buf archive into $DEST. # - archive layout: /_//... @@ -67,7 +69,7 @@ merge gnostic-pyi gnostic # `openstatus` package is not polluted and so the buf/gnostic vendored copies # do not collide with any user-installed packages of the same name. find "$DEST" -type f \( -name '*.py' -o -name '*.pyi' \) -print0 \ - | xargs -0 sed -i '' \ + | xargs -0 sed -i \ -e 's|^from openstatus\.|from openstatus._gen.openstatus.|g' \ -e 's|^from buf\.|from openstatus._gen.buf.|g' \ -e 's|^from gnostic\.|from openstatus._gen.gnostic.|g' \ @@ -78,8 +80,8 @@ find "$DEST" -type f \( -name '*.py' -o -name '*.pyi' \) -print0 \ # Generated trees ship no __init__.py — create empty shims so packages import. find "$DEST" -type d -exec sh -c 'touch "$0/__init__.py"' {} \; -echo "${BUF_PY_VERSION}" > "$DEST/VERSION" +echo "${BUF_SCHEMA_COMMIT}" > "$DEST/VERSION" echo echo "Done. Generated tree at $DEST" -echo "Pinned openstatus version recorded at $DEST/VERSION" +echo "Schema commit recorded at $DEST/VERSION" From 876212c10226dc716839f4483631cc8694cf6058 Mon Sep 17 00:00:00 2001 From: Moulik Aggarwal Date: Fri, 31 Jul 2026 09:26:20 +0530 Subject: [PATCH 2/3] fix: seed schema marker to the commit the vendored code came from Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_0173tbY2QAvy8Sw2uVuHV4SP --- scripts/regen.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/regen.sh b/scripts/regen.sh index 2eaae73..715eae9 100755 --- a/scripts/regen.sh +++ b/scripts/regen.sh @@ -5,7 +5,7 @@ set -euo pipefail # Change-detection marker only — the archive itself is fetched by the `main` # label, since the archive URL uses a plugin-version coordinate that cannot be # reconstructed from the commit alone. -readonly BUF_SCHEMA_COMMIT="65e5c3248a1e" +readonly BUF_SCHEMA_COMMIT="7d7b7047611f" # Transitive deps. Buf does not expose pinned versions for these from the # openstatus/api module, so we track main. The PHP plan ships empty initOnce() From 11a82b81b70093ebe072ea0a8d44b6c4afa6b34a Mon Sep 17 00:00:00 2001 From: Moulik Aggarwal Date: Sat, 1 Aug 2026 16:06:51 +0530 Subject: [PATCH 3/3] refactor: resolve schema commit from BSR instead of a hand-seeded marker Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_0173tbY2QAvy8Sw2uVuHV4SP --- .github/workflows/regen.yml | 53 +++++++++++++++---------------------- scripts/regen.sh | 7 +++-- 2 files changed, 25 insertions(+), 35 deletions(-) diff --git a/.github/workflows/regen.yml b/.github/workflows/regen.yml index b5a614d..a3d11cc 100644 --- a/.github/workflows/regen.yml +++ b/.github/workflows/regen.yml @@ -20,38 +20,29 @@ jobs: with: setup_only: true - - name: Discover latest schema commit - id: latest + - name: Resolve schema commit + id: schema run: | - current=$(grep -E 'readonly BUF_SCHEMA_COMMIT="' scripts/regen.sh \ - | sed -E 's/.*="([^"]+)".*/\1/') - echo "current=$current" >> "$GITHUB_OUTPUT" - # Version string looks like 35.1.0.1.20260727085848+65e5c3248a1e; - # the commit suffix is the only coordinate shared across languages. - version=$(buf registry sdk version \ - --module=buf.build/openstatus/api \ - --plugin=buf.build/protocolbuffers/python) - latest="${version##*+}" - if [[ -z "$latest" || "$latest" == "$version" ]]; then - echo "::error::schema version discovery returned empty" + json=$(buf registry module commit resolve \ + buf.build/openstatus/api:main --format json) + commit=$(jq -r '.commit' <<< "$json") + source_url=$(jq -r '.source_control_url' <<< "$json") + if [[ -z "$commit" || "$commit" == "null" ]]; then + echo "::error::schema commit resolution returned empty" exit 1 fi - echo "latest=$latest" >> "$GITHUB_OUTPUT" + echo "commit=$commit" >> "$GITHUB_OUTPUT" + echo "source_url=$source_url" >> "$GITHUB_OUTPUT" - - name: No-op when already up to date - if: steps.latest.outputs.latest == steps.latest.outputs.current - run: echo "Already on ${{ steps.latest.outputs.current }}; nothing to do." - - - name: Bump pin and regenerate - if: steps.latest.outputs.latest != steps.latest.outputs.current - run: | - sed -i -E "s/(readonly BUF_SCHEMA_COMMIT=)\"[^\"]+\"/\1\"${{ steps.latest.outputs.latest }}\"/" \ - scripts/regen.sh - bash scripts/regen.sh + - name: Regenerate + run: bash scripts/regen.sh "${{ steps.schema.outputs.commit }}" - name: Bump patch version - if: steps.latest.outputs.latest != steps.latest.outputs.current run: | + if git diff --quiet -- src/openstatus/_gen; then + echo "no schema change; skipping version bump" + exit 0 + fi cur=$(grep -oP '^version = "\K[^"]+' pyproject.toml) IFS=. read -r maj min pat <<< "$cur" next="$maj.$min.$((pat + 1))" @@ -59,14 +50,14 @@ jobs: echo "bumped $cur -> $next" - name: Open PR - if: steps.latest.outputs.latest != steps.latest.outputs.current uses: peter-evans/create-pull-request@v6 with: token: ${{ secrets.SDK_BOT_TOKEN || github.token }} - branch: regen/${{ steps.latest.outputs.latest }} - commit-message: "chore: bump buf schema to ${{ steps.latest.outputs.latest }}" - title: "chore: bump buf schema to ${{ steps.latest.outputs.latest }}" + branch: regen/${{ steps.schema.outputs.commit }} + commit-message: "chore: bump buf schema to ${{ steps.schema.outputs.commit }}" + title: "chore: bump buf schema to ${{ steps.schema.outputs.commit }}" body: | Automated regeneration from `buf.build/openstatus/api` schema - commit `${{ steps.latest.outputs.current }}` to - `${{ steps.latest.outputs.latest }}`. + commit `${{ steps.schema.outputs.commit }}`. + + Source: ${{ steps.schema.outputs.source_url }} diff --git a/scripts/regen.sh b/scripts/regen.sh index 715eae9..418a739 100755 --- a/scripts/regen.sh +++ b/scripts/regen.sh @@ -1,11 +1,10 @@ #!/usr/bin/env bash set -euo pipefail -# Schema commit of buf.build/openstatus/api that this tree was generated from. -# Change-detection marker only — the archive itself is fetched by the `main` +# Recorded in $DEST/VERSION only — the archive itself is fetched by the `main` # label, since the archive URL uses a plugin-version coordinate that cannot be # reconstructed from the commit alone. -readonly BUF_SCHEMA_COMMIT="7d7b7047611f" +SCHEMA_COMMIT="${1:?usage: regen.sh }" # Transitive deps. Buf does not expose pinned versions for these from the # openstatus/api module, so we track main. The PHP plan ships empty initOnce() @@ -80,7 +79,7 @@ find "$DEST" -type f \( -name '*.py' -o -name '*.pyi' \) -print0 \ # Generated trees ship no __init__.py — create empty shims so packages import. find "$DEST" -type d -exec sh -c 'touch "$0/__init__.py"' {} \; -echo "${BUF_SCHEMA_COMMIT}" > "$DEST/VERSION" +echo "${SCHEMA_COMMIT}" > "$DEST/VERSION" echo echo "Done. Generated tree at $DEST"