Skip to content

Refresh Gradle and pip-compile smoke recordings after cache-key drift - #595

Open
myevolve wants to merge 1 commit into
dependabot:mainfrom
myevolve:fix/gradle-pip-smoke-caches
Open

myevolve wants to merge 1 commit into
dependabot:mainfrom
myevolve:fix/gradle-pip-smoke-caches

Conversation

@myevolve

@myevolve myevolve commented Oct 8, 2026 •

Copy link
Copy Markdown

Summary

Refresh the Gradle and pip-compile recordings after diagnosing the two remaining failures in Core Smoke run 37818658609 (95/97 E2E jobs passed).

  • pip-compile: five generated requirements files now contain the uncapped transitive dependency pycparser==3.1, rather than 3.0.
  • Gradle: a clean recording adds the real Hibernate 5.3.39 release notes. The original four PRs, selected versions and dependency-file changes remain unchanged.
  • Document why request-key drift bypasses old caches and why regeneration must also be checked with the clean-cache flow used by Cache One.

Both complete fixtures equal actual CLI-generated output. All original input fields, pinned source commits, ignore conditions and expected event sets are unchanged. No Core/proxy code, cache-key policy, workflow assertions or npm fixtures changed. This is independent of #593 and does not require the unreleased CLI clock feature.

Root cause and evidence

The original caches came from run 37309245577: cache-gradle artifact 11344887698 and cache-python-pip-compile artifact 11344573838.

  • Gradle: successful Maven metadata responses existed under URLs without the explicit HTTPS :443 port. Current requests use that port and miss the old keys. The failing CI job reached live Maven 404s and omitted all four expected PRs (95/125 calls cached). A local baseline reached live 200s and matched the old fixture, but only 75/116 calls were cached. Warming that cache restored a byte-identical 116/116-cached replay of the old fixture. A separate empty-cache recording then exposed the additional legitimate Hibernate release notes captured here.
  • pip-compile: the cached PyPI simple-index key includes Cache-Control: max-age=0; the current request omits that header. Hashing the same Accept value with/without Cache-Control reproduces the old c9790a025c1b… and new db00c559751e… keys exactly. The miss reaches the live index and selects pycparser 3.1. The source lockfile omits the argon2/cffi/pycparser chain requested by django[argon2], so native pip-compile legitimately resolves these new, unpinned dependencies. Both CI and the original-cache local baseline fail with exactly the same five 3.0 → 3.1 changes (96/130 calls cached). A separate empty-cache recording produces exactly the same regenerated fixture.

No resolver failure was demonstrated that warrants changing Core. Broadening ignore conditions, dropping PR expectations, or normalizing proxy keys would not be a justified fix for these recordings.

Verification

Actual released CLI v1.94.0, with the published Core-main 0286aa0868b1f0de1b908ce3358bbf994e5272c1 updater images and the unmodified CI proxy:

Final fixture Result Cache replay Output contract
smoke-gradle.yaml PASS 119/119 (100%) Full YAML byte-identical; 4 PRs
smoke-python-pip-compile.yaml PASS 130/130 (100%) Full YAML byte-identical; 5 PRs

No metadata/job errors, missing cache bodies, HTTP 403s or HTTP 429s in either final replay. No host GitHub/job/OIDC credentials were forwarded to updater containers. Final captures were made from empty cache directories, not by editing cached responses.

Pinned images:

  • Gradle: ghcr.io/dependabot/dependabot-updater-gradle@sha256:fbd707ca255d913da710a1038bc6edfae548c0274253bb2330ec0165d02a5488
  • pip: ghcr.io/dependabot/dependabot-updater-pip@sha256:da5b3474c71ce9ed8bcd253e9be0f5d886139bf1e43914a2ba1620d528044972
  • proxy: ghcr.io/dependabot/proxy@sha256:a39e7ef7188c9a4b36692df47a0e8f876e83199e657cd0b6be00e736fbe03c2f (commit 20763b13426c928305a465bbada1fde7a88104fe)

Fixture SHA-256s:

  • Gradle: 13d35a825dce1a53f08d2efeeaabf2e705105e6a93fde4f1ddaaa77f980d1efc
  • pip-compile: b3161ea2ee5febb3022378a79eed7ef0b833745352be0b95b8c971ebef232225

Released CI at ddcf3e2

Run 37840899141 used the same updater/proxy image contents as the local proof (registry manifest config digests checked against the job logs). pip-compile PASS with an identical diff result, but only 96/130 calls cached. Gradle FAIL at 75/116 cached: all four expected PRs were created, and the entire diff is the missing 29-line Hibernate release-note block. The job explicitly replayed the old cached 200 response for hibernate/hibernate-orm/releases?per_page=100. This is the documented stale-metadata cache gate, not a reason to delete those genuine expectations. Suite discovery and yamllint also pass.

The verified matching local cache archive is gradle-pip-replay-caches-ddcf3e2.tar.gz, SHA-256 691a966dd96f7346ee295d48abe6bdae8c9c5851429214cdf9b155f1adeb52a9. It is not an upstream Actions artifact.

Hosted clean-cache proof (fork only)

The unchanged upstream Cache One workflow now passes on GitHub-hosted Ubuntu runners for this exact head, ddcf3e24cea11fcd30a7e8de4b2f62d5278b6421. Workflow blob c4853add0bd80f64618e6c18a2c4bc300558957c is identical in the fork and upstream. Both jobs used released CLI v1.94.0, the same updater/proxy image contents documented above, and read-only job-token permissions. No workflow, fixture or updater source was changed for these runs.

Suite Hosted clean recording Downloadable artifact Replay of downloaded artifact
Gradle PASS: 37856549299 cache-gradle / 11584556767 119/119 cached (100%); full YAML byte-identical
pip-compile PASS: 37856549293 cache-python-pip-compile / 11583888174 130/130 cached (100%); full YAML byte-identical

The clean recordings naturally show only 54/119 and 30/130 in-run cache hits, respectively: each began with an empty directory. The downloaded artifacts were then replayed without editing their responses, producing the 100%-cached results above with no metadata/job errors. Fixture SHA-256s still match those listed above.

GitHub-reported upload SHA-256s (also recorded in each upload log):

  • Gradle: 3047ed8721a26fc4678b64e5cebc32ca6a7dfb7be2ec0170d803ad7bdcda4e7d
  • pip-compile: 62a47894871b19dc7de237d981b1c56a8695d53ae41d29d7888a19a758d60772

Both artifacts expire 2027-01-06. Download them with:

gh run download 37856549299 --repo myevolve/smoke-tests --name cache-gradle --dir cache-gradle
gh run download 37856549293 --repo myevolve/smoke-tests --name cache-python-pip-compile --dir cache-python-pip-compile

These are fork evidence, not upstream cache publication. Core and upstream Smoke still download artifacts from dependabot/smoke-tests. The upstream Gradle check therefore remains failed until a maintainer runs the two upstream Cache One commands below and reruns Smoke. This PR is ready for review; merging still requires the upstream cache refresh and passing Smoke checks. The temporary fork workflow was disabled after capture; all fork workflows are inactive.

Maintainer landing gate

Ready for review, not ready to merge. The dependabot/maintainers team is already requested; no duplicate review request is needed. Local and fork-hosted green runs are not an upstream CI-green claim. The old Gradle cache does not contain the added release-note metadata, so this fixture and its cache must be refreshed together.

  1. Run Cache One in this repository at this PR's refs/pull/595/head, once with package_manager=gradle and once with package_manager=python-pip-compile. Both runs must pass and publish their matching named artifacts.

    gh workflow run cache-one.yml --repo dependabot/smoke-tests --ref main \
      -f git-ref=refs/pull/595/head -f package_manager=gradle
    
    gh workflow run cache-one.yml --repo dependabot/smoke-tests --ref main \
      -f git-ref=refs/pull/595/head -f package_manager=python-pip-compile

    --ref main selects the existing workflow; git-ref selects the reviewed fixture checkout. These commands require upstream Actions write access.

  2. Review can proceed now. Rerun this PR's Smoke checks against the published artifacts and merge only after those checks pass and review is complete.

  3. Rerun Core #16498 Smoke after the fixture merge so discovery uses the new fixture blobs and caches. The historical 95/97 run remains failed until replaced by actual successful CI evidence.

Contributor access is read-only upstream; the official cache workflow/merge actions need a maintainer. Existing review and release gates on the independent Core/CLI/npm work are unchanged.

Related: #592; dependabot/dependabot-core#16498; dependabot/dependabot-core#16488.

@myevolve myevolve left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent AI-assisted technical review

Reviewed ddcf3e24cea11fcd30a7e8de4b2f62d5278b6421 with a separate fixture/workflow reviewer. No actionable introduced defect was identified. Original job inputs, source commits, primary version selections, and expected event contracts were preserved; the generated Hibernate release metadata and uncapped pycparser transitive result were not hand-pinned to stale cache contents.

Existing runtime evidence at this unchanged head (not rerun by the review agent): the unchanged Cache One workflow passed for Gradle and pip-compile. Downloaded artifacts replayed with released CLI 1.94.0, full byte-identical YAML, and 119/119 and 130/130 cached calls.

A direct upstream gh workflow run cache-one.yml attempt returned HTTP 403: Must have admin rights to Repository. Fork artifacts are not upstream cache publication; the stale upstream Gradle check is still a real failure.

This is an explicitly AI-authored technical COMMENT, not maintainer approval. Upstream cache publication and required maintainer approval remain external gates.

@emancu

emancu commented Oct 9, 2026

Copy link
Copy Markdown

pycparser 3.11 was released on 2026-10-09, so this needs pycparser==3.11 now (it fails on dependabot/dependabot-core#16468 and others with 3.0 → 3.11).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants