Add backport publish command - #3415
Open
tianyiy-tim wants to merge 1 commit into
Open
Conversation
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 10, 2026 18:08
86cc7f5 to
f303452
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 10, 2026 18:09
4ef4e67 to
80da763
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 10, 2026 21:43
f303452 to
ea3a08a
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 10, 2026 21:43
80da763 to
a76adef
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 10, 2026 22:20
ea3a08a to
5f40255
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 10, 2026 22:20
a76adef to
e3e0ae2
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 11, 2026 17:53
5f40255 to
a87a83d
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 11, 2026 17:53
e3e0ae2 to
4c1a2b2
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 12, 2026 16:46
a87a83d to
cefd5e7
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 12, 2026 16:46
4c1a2b2 to
55b39ad
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 13, 2026 18:26
cefd5e7 to
ea6425c
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 13, 2026 18:26
55b39ad to
89fe5fe
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 13, 2026 18:39
ea6425c to
2bd6434
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 13, 2026 18:39
89fe5fe to
f3823ea
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 13, 2026 19:23
2bd6434 to
bf2c1c4
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
2 times, most recently
from
August 17, 2026 22:02
5dbb56f to
ee46cde
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 17, 2026 22:02
f3823ea to
963e957
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
2 times, most recently
from
August 17, 2026 22:17
57377eb to
258f262
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 17, 2026 22:17
963e957 to
fe8e27f
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 17, 2026 22:28
258f262 to
0c5e4ca
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 17, 2026 22:28
fe8e27f to
621e230
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 17, 2026 22:52
0c5e4ca to
b238fa1
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 17, 2026 22:52
621e230 to
0497369
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 18, 2026 03:37
b238fa1 to
efe1412
Compare
tianyiy-tim
force-pushed
the
backport-stack/apply
branch
from
August 18, 2026 03:37
0497369 to
71c1a9a
Compare
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 18, 2026 21:25
efe1412 to
ed04f36
Compare
tianyiy-tim
had a problem deploying
to
auto-approve
August 19, 2026 21:23 — with
GitHub Actions
Error
tianyiy-tim
had a problem deploying
to
auto-approve
August 19, 2026 21:23 — with
GitHub Actions
Error
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 19, 2026 21:27
9492ba6 to
455dae6
Compare
tianyiy-tim
had a problem deploying
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Failure
tianyiy-tim
had a problem deploying
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Error
tianyiy-tim
temporarily deployed
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Inactive
tianyiy-tim
had a problem deploying
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Error
tianyiy-tim
temporarily deployed
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 19, 2026 21:29 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 19, 2026 21:35 — with
GitHub Actions
Inactive
Contributor
|
🔒 Security Review — View Report Please review before merging. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3415 +/- ##
==========================================
- Coverage 78.43% 78.26% -0.18%
==========================================
Files 698 699 +1
Lines 124594 124592 -2
Branches 17292 17287 -5
==========================================
- Hits 97729 97507 -222
- Misses 25939 26215 +276
+ Partials 926 870 -56 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
nhatnghiho
reviewed
Aug 21, 2026
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 21, 2026 17:14
455dae6 to
1bdc3fe
Compare
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:14 — with
GitHub Actions
Inactive
tianyiy-tim
had a problem deploying
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Error
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Inactive
tianyiy-tim
had a problem deploying
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Error
tianyiy-tim
had a problem deploying
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Error
tianyiy-tim
had a problem deploying
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Error
tianyiy-tim
had a problem deploying
to
auto-approve
August 21, 2026 17:15 — with
GitHub Actions
Error
Pushes the branches apply built and opens one pull request per affected branch. apply --open-pr offers it as soon as the cherry-picks are done. A branch is publishable once its cherry-pick is finished, which is read from git, so resolving a conflict by hand is enough for the next publish to pick it up. A branch carrying no pick of its own is measured against the release ref apply cut it from, so a stale fork cannot make it look ready. Branches go to a fork and the pull requests are opened against aws/aws-lc, both worked out from the checkout instead of assuming origin and upstream. --base-repo points the pull requests elsewhere, for a staging repo. Pushing to aws/aws-lc is refused. A branch that already has an open pull request is left alone, so re-running is safe. Everything that talks to GitHub lives in util/github.py. --dry-run prints the summary comment instead of posting it, and says how many pull requests it would have opened. A fix inside crypto/fipsmodule carries the FIPS boundary warning into every pull request body and the summary comment, from the file list analyze saved. Nothing is ever a draft and nothing is auto-merged.
tianyiy-tim
force-pushed
the
add-backport-publish
branch
from
August 21, 2026 17:30
1bdc3fe to
34234b7
Compare
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
tianyiy-tim
temporarily deployed
to
auto-approve
August 21, 2026 17:31 — with
GitHub Actions
Inactive
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issues:
Addresses
P425131803Description of changes:
After
applyyou're left with one local branch per affected branch, and opening a pull request for each of them is still manual. For a fix that hits seven branches that's seven trips through the GitHub UI.This pull request adds
publish, which pushes those branches and opens one pull request each, in one command.Most of the time you never type it.
apply --open-proffers to run it as soon as the cherry-picks are done, so a local session staysanalyzethenapply.Stacked on #3414. The base here is
backport-stack/apply, a scaffolding branch holding the commits below it, so this diff is only the 9 files this change touches. I will retarget it tomainas the stack lands. Please don't merge it into the scaffolding branch.Call-outs:
Branches go to your fork, pull requests are opened against
aws/aws-lc. Pushing branches toaws/aws-lcis refused, so a mistyped--remotecan't put half-reviewed work on the real repository.Whether a branch is ready is read from git, not from anything
applyrecorded. So resolving a conflict by hand is enough for the nextpublishto pick that branch up, with no need to runapplyagain.A branch that already has an open pull request is left alone, so re-running is safe.
Nothing is ever a draft and nothing is auto-merged.
Everything that talks to GitHub lives in
util/github.py, so a second command needing to open a pull request later reuses this one rather than growing its own. The previous version of this tool grew two openers and they drifted apart.A fix that reaches inside
crypto/fipsmodule/puts a FIPS boundary warning at the top of every pull request body and in the summary comment, plus a "needs FIPS review" line.analyzealready prints it, but nobody reviewing a backport rananalyze, and the module is validated as a build of exactly that source.publishnever reads the diff, so the file list comes from the saved run.--dry-runpushes nothing, opens nothing, and prints the summary comment instead of posting it. It used to print what it would push and then comment on the source pull request anyway, which belongs to whoever wrote the fix. It also reports how many pull requests it would have opened, rather than "0 opened", which read as nothing to do.ghis a new prerequisite, for this command only.Testing:
Unit tests - 34 new, 188 total:
They cover reading a remote URL, the refusal to push to
aws/aws-lc, how a branch is named to GitHub across repos versus within one, each outcome a branch can end in, that a dry run posts no comment while a real run does, and that the FIPS warning reaches both the pull request body and the summary.Real fix - ran the whole chain against
#3105(the CRL scope check) with the release branches wound back to before its backports existed, so the tool had to work them out:analyzeflagged the three branches that really did get backports,applycherry-picked onto all three, andpublish --dry-runreported those three and the conflicted ones separately. The three commitsapplyproduced have the same patch-id as the human backports in #3109, #3106 and #3110.Also verified
--remote upstreamis refused before anything is printed or pushed, and that resolving one conflict by hand moved that branch from unfinished to publishable without re-runningapply.By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license and the ISC license.