Skip to content

github/workflows: fix zizmor syntax - #3170

Merged
Ricardo Salveti (ricardosalveti) merged 2 commits into
qualcomm-linux:masterfrom
quaresmajose:zizmor
Sep 22, 2026
Merged

Ricardo Salveti (ricardosalveti) merged 2 commits into
qualcomm-linux:masterfrom
quaresmajose:zizmor

Conversation

@quaresmajose

@quaresmajose Jose Quaresma (quaresmajose) commented Sep 16, 2026 •

Copy link
Copy Markdown
Member
  • Use GitHub's dedicated self-repository syntax: use '$/...' instead of './...'
  • Secrets unconditionally inherited by called workflow: this reusable workflow

Comment thread .github/workflows/push.yml Fixed
Comment thread .github/workflows/push.yml Fixed
Comment thread .github/workflows/test-pr-wrynose.yml Fixed
Comment thread .github/workflows/test-pr.yml Fixed
Comment thread .github/workflows/test-pr.yml Fixed
@quaresmajose

Copy link
Copy Markdown
Member Author

Issue reported in #1900 (comment)

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Test run workflow

Test jobs for commit c7d6e50

qcom-distro
Pass: 295 | Fail: 21 | Total: 357
qcom-distro_linux-qcom-6.18
Pass: 232 | Fail: 7 | Total: 259
nodistro
Pass: 10 | Fail: 0 | Total: 10

@test-reporting-app

test-reporting-app Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Test Results

  119 files  +   51    715 suites  +396   9h 32m 31s ⏱️ + 4h 25m 7s
  175 tests +   24    144 ✅  -     1   1 💤 + 1  30 ❌ +24 
4 590 runs  +2 489  4 490 ✅ +2 414  61 💤 +42  39 ❌ +33 

For more details on these failures, see this check.

Results for commit c7d6e50. ± Comparison against base commit cbf084d.

♻️ This comment has been updated with latest results.

@ricardosalveti

Copy link
Copy Markdown
Contributor

Not really fixed it seems?

@quaresmajose

Copy link
Copy Markdown
Member Author

Not really fixed it seems?

It looks like there is a new error now, but I can't quite figure out if it's caused by the change. It seems more likely that the error is appearing because the file in question was modified. I also don't know how to fix this new issue with the secrets unconditionally inherited.

@quaresmajose

Copy link
Copy Markdown
Member Author

Not really fixed it seems?

It looks like there is a new error now, but I can't quite figure out if it's caused by the change. It seems more likely that the error is appearing because the file in question was modified. I also don't know how to fix this new issue with the secrets unconditionally inherited.

Some useful information in https://docs.github.com/en/actions/how-tos/reuse-automations/reuse-workflows#using-inputs-and-secrets-in-a-reusable-workflow

@ricardosalveti

Ricardo Salveti (ricardosalveti) commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

It looks like there is a new error now, but I can't quite figure out if it's caused by the change. It seems more likely that the error is appearing because the file in question was modified. I also don't know how to fix this new issue with the secrets unconditionally inherited.

Some useful information in https://docs.github.com/en/actions/how-tos/reuse-automations/reuse-workflows#using-inputs-and-secrets-in-a-reusable-workflow

Maybe:

diff --git a/.github/workflows/test-pr.yml b/.github/workflows/test-pr.yml
index 0b990aed..a2342576 100644
--- a/.github/workflows/test-pr.yml
+++ b/.github/workflows/test-pr.yml
@@ -69,7 +69,8 @@ jobs:
       checks: write
       pull-requests: write
     uses: $/.github/workflows/test.yml
-    secrets: inherit
+    secrets:
+      LAVATOKEN: ${{ secrets.LAVATOKEN }}
     with:
       build_id: ${{ github.event.workflow_run.id }}
       pr_number: ${{ needs.determine-target-branch.outputs.pr_number }}

@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit 32a3010

  • qcomdistro: multimedia image-prop
    Pass: 36 | Fail: 3 | Others: 2 | Total: 41
  • qcomdistro: multimedia image
    Pass: 9 | Fail: 0 | Total: 9

Use GitHub's dedicated self-repository syntax:
| use '$/...' instead of './...'

Signed-off-by: Jose Quaresma <jose.quaresma@oss.qualcomm.com>
@quaresmajose Jose Quaresma (quaresmajose) changed the title github/workflows: fix zizmor 'uses' syntax github/workflows: fix zizmor syntax Sep 21, 2026
@quaresmajose

Copy link
Copy Markdown
Member Author

It looks like there is a new error now, but I can't quite figure out if it's caused by the change. It seems more likely that the error is appearing because the file in question was modified. I also don't know how to fix this new issue with the secrets unconditionally inherited.

Some useful information in https://docs.github.com/en/actions/how-tos/reuse-automations/reuse-workflows#using-inputs-and-secrets-in-a-reusable-workflow

Maybe:

diff --git a/.github/workflows/test-pr.yml b/.github/workflows/test-pr.yml
index 0b990aed..a2342576 100644
--- a/.github/workflows/test-pr.yml
+++ b/.github/workflows/test-pr.yml
@@ -69,7 +69,8 @@ jobs:
       checks: write
       pull-requests: write
     uses: $/.github/workflows/test.yml
-    secrets: inherit
+    secrets:
+      LAVATOKEN: ${{ secrets.LAVATOKEN }}
     with:
       build_id: ${{ github.event.workflow_run.id }}
       pr_number: ${{ needs.determine-target-branch.outputs.pr_number }}

Thanks

@ricardosalveti

Copy link
Copy Markdown
Contributor

publish-results is not really using LAVATOKEN, so that can be removed, and we can replace with TEST_REPORTING_APP_TOKEN instead, like:

--- a/.github/workflows/publish-results.yml
+++ b/.github/workflows/publish-results.yml
@@ -19,9 +19,6 @@ on:
       TEST_REPORTING_APP_TOKEN:
         required: true
         description: "Private key of the GitHub App used to report test results"
-      LAVATOKEN:
-        required: true
-        description: "Token used to submit jobs to the LAVA lab"

 permissions:
   checks: write
--- a/.github/workflows/push.yml
+++ b/.github/workflows/push.yml
@@ -37,7 +37,7 @@ jobs:
     uses: $/.github/workflows/publish-results.yml
     needs: test
     secrets:
-      LAVATOKEN: ${{ secrets.LAVATOKEN }}
+      TEST_REPORTING_APP_TOKEN: ${{ secrets.TEST_REPORTING_APP_TOKEN }}
     with:
       workflow_id: ${{ github.run_id }}
--- a/.github/workflows/test-pr-wrynose.yml
+++ b/.github/workflows/test-pr-wrynose.yml
@@ -117,7 +117,7 @@ jobs:
     uses: $/.github/workflows/publish-results.yml
     secrets:
-      LAVATOKEN: ${{ secrets.LAVATOKEN }}
+      TEST_REPORTING_APP_TOKEN: ${{ secrets.TEST_REPORTING_APP_TOKEN }}
     needs: [test-wrynose]
--- a/.github/workflows/test-pr.yml
+++ b/.github/workflows/test-pr.yml
@@ -141,7 +141,7 @@ jobs:
     uses: $/.github/workflows/publish-results.yml
     secrets:
-      LAVATOKEN: ${{ secrets.LAVATOKEN }}
+      TEST_REPORTING_APP_TOKEN: ${{ secrets.TEST_REPORTING_APP_TOKEN }}
     needs: [test]

Secrets unconditionally inherited by called workflow: this reusable workflow

Signed-off-by: Jose Quaresma <jose.quaresma@oss.qualcomm.com>
@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit 4c4d3e5

  • qcomdistro: multimedia image-prop
    Pass: 35 | Fail: 6 | Total: 41
  • qcomdistro: multimedia image
    Pass: 9 | Fail: 0 | Total: 9

@ricardosalveti

Copy link
Copy Markdown
Contributor

@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit c7d6e50

  • qcomdistro: multimedia image-prop
    Pass: 40 | Fail: 0 | Others: 2 | Total: 42
  • qcomdistro: multimedia image
    Pass: 9 | Fail: 0 | Total: 9

@ricardosalveti

Copy link
Copy Markdown
Contributor

Next is good.

@ricardosalveti
Ricardo Salveti (ricardosalveti) merged commit 1d8048f into qualcomm-linux:master Sep 22, 2026
412 of 416 checks passed
@ricardosalveti

Copy link
Copy Markdown
Contributor

Jose Quaresma (@quaresmajose) can you look at mirroring these changes to the other branches and repos?

@quaresmajose

Copy link
Copy Markdown
Member Author

Yes, I will handle that.

@quaresmajose

Copy link
Copy Markdown
Member Author

Need to also pick from #3222

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants