feat(bazel): auto-refresh http_archive sha256 on Renovate PRs - #50030
Conversation
|
🎯 Code Coverage (details) 🔗 Commit SHA: df55afb | Docs | Datadog PR Page | Give us feedback! |
Files inventory check summaryFile checks results against ancestor 804dec95: Results for datadog-agent_7.80.0~devel.git.726.df55afb.pipeline.112916336-1_amd64.deb:No change detected |
Static quality checks✅ Please find below the results from static quality gates 32 successful checks with minimal change (< 2 KiB)
|
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: 88d9d89 Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | docker_containers_cpu | % cpu utilization | -0.46 | [-3.45, +2.53] | 1 | Logs |
Fine details of change detection per experiment
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | file_tree | memory utilization | +0.34 | [+0.30, +0.38] | 1 | Logs |
| ➖ | ddot_logs | memory utilization | +0.31 | [+0.25, +0.37] | 1 | Logs |
| ➖ | ddot_metrics_sum_cumulativetodelta_exporter | memory utilization | +0.23 | [-0.01, +0.48] | 1 | Logs |
| ➖ | quality_gate_metrics_logs | memory utilization | +0.20 | [-0.04, +0.45] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | +0.19 | [+0.14, +0.23] | 1 | Logs bounds checks dashboard |
| ➖ | ddot_metrics | memory utilization | +0.15 | [-0.05, +0.36] | 1 | Logs |
| ➖ | file_to_blackhole_500ms_latency | egress throughput | +0.09 | [-0.31, +0.49] | 1 | Logs |
| ➖ | uds_dogstatsd_to_api_v3 | ingress throughput | +0.03 | [-0.16, +0.23] | 1 | Logs |
| ➖ | file_to_blackhole_1000ms_latency | egress throughput | +0.02 | [-0.43, +0.48] | 1 | Logs |
| ➖ | file_to_blackhole_100ms_latency | egress throughput | +0.02 | [-0.12, +0.16] | 1 | Logs |
| ➖ | file_to_blackhole_0ms_latency | egress throughput | +0.00 | [-0.49, +0.50] | 1 | Logs |
| ➖ | tcp_dd_logs_filter_exclude | ingress throughput | -0.01 | [-0.10, +0.08] | 1 | Logs |
| ➖ | uds_dogstatsd_to_api | ingress throughput | -0.02 | [-0.22, +0.18] | 1 | Logs |
| ➖ | uds_dogstatsd_20mb_12k_contexts_20_senders | memory utilization | -0.09 | [-0.14, -0.05] | 1 | Logs |
| ➖ | ddot_metrics_sum_delta | memory utilization | -0.14 | [-0.33, +0.05] | 1 | Logs |
| ➖ | ddot_metrics_sum_cumulative | memory utilization | -0.16 | [-0.32, -0.01] | 1 | Logs |
| ➖ | quality_gate_idle_all_features | memory utilization | -0.18 | [-0.22, -0.14] | 1 | Logs bounds checks dashboard |
| ➖ | docker_containers_cpu | % cpu utilization | -0.46 | [-3.45, +2.53] | 1 | Logs |
| ➖ | otlp_ingest_metrics | memory utilization | -0.48 | [-0.65, -0.32] | 1 | Logs |
| ➖ | otlp_ingest_logs | memory utilization | -0.60 | [-0.70, -0.50] | 1 | Logs |
| ➖ | docker_containers_memory | memory utilization | -0.62 | [-0.73, -0.52] | 1 | Logs |
| ➖ | quality_gate_logs | % cpu utilization | -1.19 | [-2.24, -0.15] | 1 | Logs bounds checks dashboard |
| ➖ | tcp_syslog_to_blackhole | ingress throughput | -2.36 | [-2.54, -2.18] | 1 | Logs |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | docker_containers_cpu | simple_check_run | 10/10 | 728 ≥ 26 | |
| ✅ | docker_containers_memory | memory_usage | 10/10 | 243.95MiB ≤ 370MiB | |
| ✅ | docker_containers_memory | simple_check_run | 10/10 | 691 ≥ 26 | |
| ✅ | file_to_blackhole_0ms_latency | memory_usage | 10/10 | 0.16GiB ≤ 1.20GiB | |
| ✅ | file_to_blackhole_0ms_latency | missed_bytes | 10/10 | 0B = 0B | |
| ✅ | file_to_blackhole_1000ms_latency | memory_usage | 10/10 | 0.20GiB ≤ 1.20GiB | |
| ✅ | file_to_blackhole_1000ms_latency | missed_bytes | 10/10 | 0B = 0B | |
| ✅ | file_to_blackhole_100ms_latency | memory_usage | 10/10 | 0.17GiB ≤ 1.20GiB | |
| ✅ | file_to_blackhole_100ms_latency | missed_bytes | 10/10 | 0B = 0B | |
| ✅ | file_to_blackhole_500ms_latency | memory_usage | 10/10 | 0.18GiB ≤ 1.20GiB | |
| ✅ | file_to_blackhole_500ms_latency | missed_bytes | 10/10 | 0B = 0B | |
| ✅ | quality_gate_idle | intake_connections | 10/10 | 3 ≤ 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 143.43MiB ≤ 147MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 737.37KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 3 ≤ 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 472.35MiB ≤ 495MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.13MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 3 ≤ 6 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 176.03MiB ≤ 195MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 264.11MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 361.39 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 3 ≤ 6 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 369.63MiB ≤ 430MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
d5d3772 to
3453065
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3453065037
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
I would actually ask you to convert those dda tasks into bazel runnable commands |
Gitlab CI Configuration Changes
|
| Removed | Modified | Added | Renamed |
|---|---|---|---|
| 0 | 29 | 1 | 0 |
ℹ️ Diff available in the job log.
…_archive sha256
Fixes silent skip of sqlite3/sqlite3_license blocks whose URLs are built
from top-level Starlark variables. Adds _parse_top_level_namespace to eval
preamble assignments, _extract_balanced_expr for multi-line expressions, and
extends _extract_urls to fall back to namespace-aware eval when no plain
literals are found. URL_LITERAL_RE now excludes template strings containing {}.
Adds 16 unit tests covering namespace parsing, URL extraction, and
end-to-end sqlite integration.
|
FYI. We would like to land #43376 sometime soon. One warning though. |
|
|
||
|
|
||
| def _extract_balanced_expr(text: str, start: int) -> str | None: | ||
| """Extract a Starlark expression starting at ``start``, respecting bracket depth. |
There was a problem hiding this comment.
Have we considered using this? https://github.com/inducer/starlark-pyo3
What does this PR do?
Adds a CI companion workflow that auto-refreshes the
sha256field of anyhttp_archive(...)block indeps/repos.MODULE.bazelwhose version literal was changed by Renovate. Without it, every Renovate-generated bump PR for native deps fails Bazel CI immediately because Renovate updatesstrip_prefixandurlsbut cannot recompute the hash.Three pieces:
tasks/bazel.py::refresh_archive_hashes— invoke task that diffsdeps/repos.MODULE.bazelagainst a base ref, identifies blocks whose non-sha256 fields changed, downloads the new tarball from the first reachable URL inurls = [...], computes the sha256, and rewrites the source line. Block-scoped substitutions and strict match-count validation prevent silent partial edits. URL string literals are filtered so computed expressions (e.g. sqlite3's.format(...)) are skipped gracefully..github/workflows/bazel-native-tidy.yml— runs the task on Renovate PRs labeleddependencies-bazel-native, then commits and force-pushes viadd-octo-sts+chouetz/push-signed-commits. Mirrors the structure of.github/workflows/cargo-bazel-tidy.ymland.github/workflows/go-mod-tidy.yml..github/chainguard/self.bazel-native-tidy.push-branch.sts.yaml— dd-octo-sts policy grantingcontents: writeto the workflow's job-workflow-ref. Identical shape toself.cargo-bazel-tidy.push-branch.sts.yaml.Motivation
https://datadoghq.atlassian.net/browse/ACIX-1493
This is a precondition for the upcoming Renovate-tracking PRs that add
customManagersfor the 29 native deps indeps/repos.MODULE.bazel. Renovate's regex managers can update version literals but never the sha256 (no native Bazel command does this either —bazel mod tidyonly refreshesMODULE.bazel.lock, not the inlinesha256 = "..."strings). Without this companion, every Renovate-bumped PR for natives would land with a broken Bazel build and need manual intervention.The repo already has the same shape for cpython (
tasks/python_version.py::_prepare_bazel_update) — this generalizes that approach so it applies to anyhttp_archiveblock driven by Renovate.Describe how you validated your changes
dda inv -- bazel.refresh-archive-hashes --base-ref=origin/mainis a no-op on a clean branch (no http_archive blocks differ from main).zlib-1.3.1→zlib-1.3(a real older release) indeps/repos.MODULE.bazelwhile leaving the sha256 stale. Randda inv -- bazel.refresh-archive-hashes --base-ref=HEAD. The task:zlibblock as changed,ff0ba4c292013dbc..., matches zlib 1.3 upstream),Additional Notes
renovate[bot]user +dependencies-bazel-nativelabel) follows the existingcargo-bazel-tidy.ymlandgo-mod-tidy.ymlpatterns. Thedependencies-bazel-nativelabel will be applied automatically by Renovate via a packageRule added in the upcoming Phase 2a/b/c tracking PRs.dd-agent-omnibus.s3.amazonaws.com, but Bazel'shttp_archivetriesurlsin order, so a 404 on S3 falls through cleanly to upstream. No mirror-push is added in this PR; that can be a separate follow-up if desired.http_archiveblocks added in a PR (i.e. not present in the base ref) are deliberately NOT auto-hashed — initial sha256 is the human's job, since the base reviewer needs to verify the upstream source.