Skip to content

Commit 3f76801

Browse files
solderzzcclaude
andauthored
fix: make the dependency automation work without a PAT (#140)
* feat: bump mlx-swift-lm for glm_moe_dsa (GLM-5.2) support Points at bfc2462, which brings two things: - SharpAI/mlx-swift-lm#48 — glm_moe_dsa / deepseek_v3_2 load and run with dense attention (stage 1 of #111). GLM-5.2 is DeepSeek V3.2, whose indexer is inert below index_topk (2048), so output is exact for the first 2048 positions of context and diverges beyond them. That is enough to exercise --stream-experts against the 308GB checkpoint, which is what the issue actually asks for. - SharpAI/mlx-swift-lm#47 — the all-KV-shared assistant regression tests, which had not been picked up by a bump yet. #48 also generalises a latent trap in DeepseekV3.sanitize, which dropped `model.layers.61` by string literal. That number is just numHiddenLayers; on GLM-5.2's 78 layers it would have deleted a real layer while keeping the MTP block. Verified past the registry: pointing the binary at a glm_moe_dsa config constructs the model and fails only on absent weights — Key model.embed_tokens.weight not found in DeepseekV32Model.DeepseekV3ModelInner.Embedding so the architecture is reachable end to end, not merely registered. No real weights have been run: the smallest glm_moe_dsa checkpoint is 308GB. Refs #111 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: make the dependency automation work without a PAT Dependency Automation has failed all 12 times it has run since 2026-04-27 — it has never once succeeded. Every failure is the same: ##[error]Input 'token' not supplied. Unable to continue. The Create Pull Request step reads secrets.SWIFTLM_PR_TOKEN, which is not set in this repository. The dispatch side is fine: mlx-swift-lm's auto_release does hold a token that can dispatch cross-repo, so the event arrives and the job runs, does its work, and dies at the last step. Rather than add the secret, stop trying to open the PR. A workflow needs a personal access token to open one usefully because GitHub does not start workflow runs for events raised by GITHUB_TOKEN — a bot-opened PR would arrive with no checks at all, permanently pending rather than green, and release.yml gates releases on CI concluding successfully. A pushed branch plus a compare link in the job summary costs one click and gets real CI, because the PR event is then the human's. Keeping a human in that loop is not a consolation prize. Bumps here have needed a pointer check, an umbrella build and a smoke test before they were trustworthy; this does the mechanical part and leaves the judgement. Three further problems fixed while in here: - The mlx-swift branch ran `swift package update mlx-swift`, which does nothing: both dependencies are `.package(path: "./…")` local paths backed by submodules, and SwiftPM takes whatever is on disk for a path dependency. It could only ever have produced an empty commit. Both are now handled the same way, as the pointer move they are. - client_payload was interpolated straight into run blocks, so a crafted new_tag would have been executed rather than compared. Values are now validated (source_repo against an allowlist, new_tag against a plain-tag pattern) and passed through the environment. Verified rejecting `b554; rm -rf /`, `$(whoami)`, `b554 && curl evil.sh`, `../../../etc/passwd`, `-x` and empty, while accepting b554, b459 and v1.2.3. - A re-dispatch for a tag already checked out produced an empty commit; that case now reports and stops. Exercised against the real submodule: an already-current tag (b500) takes the no-op path, a nonexistent tag (b99999) fails with a clear message, and a real older tag (b497) computes bfc2462 → b320bc4. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent 649a91f commit 3f76801

1 file changed

Lines changed: 108 additions & 29 deletions

File tree

Lines changed: 108 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,25 @@
11
name: Dependency Automation
22

3+
# Prepares a submodule bump when mlx-swift or mlx-swift-lm cuts a release, and stops
4+
# at a pushed branch rather than opening a pull request.
5+
#
6+
# Opening the PR from a workflow needs a personal access token, because GitHub does
7+
# not start workflow runs for events raised by GITHUB_TOKEN. A bot-opened PR would
8+
# therefore arrive with no checks at all — permanently pending, never green — and this
9+
# repository gates releases on CI concluding successfully (see release.yml). A branch
10+
# is the honest stopping point: opening the PR yourself takes one click, and CI then
11+
# runs normally because the event is yours.
12+
#
13+
# That a human sees the bump before it merges is a feature. Bumps here have needed a
14+
# pointer check, an umbrella build and a smoke test to be trustworthy; the automation
15+
# does the mechanical part and leaves the judgement.
16+
317
on:
418
repository_dispatch:
519
types: [dependency_bump]
620

721
permissions:
822
contents: write
9-
pull-requests: write
1023

1124
jobs:
1225
bump-dependencies:
@@ -18,34 +31,100 @@ jobs:
1831
submodules: recursive
1932
fetch-depth: 0
2033

21-
- name: Update swift-mlx dependencies
22-
if: ${{ github.event.client_payload.source_repo == 'mlx-swift' }}
34+
# client_payload is attacker-controlled in principle — anything able to dispatch
35+
# to this repository chooses these strings — and they end up in shell and in a
36+
# ref name. Validate them here and pass them onward through the environment
37+
# rather than interpolating ${{ }} into a run block, where a crafted tag would
38+
# be executed rather than compared.
39+
- name: Validate dispatch payload
40+
env:
41+
PAYLOAD_SOURCE_REPO: ${{ github.event.client_payload.source_repo }}
42+
PAYLOAD_NEW_TAG: ${{ github.event.client_payload.new_tag }}
2343
run: |
24-
echo "Bumping mlx-swift dependency to ${{ github.event.client_payload.new_tag }}"
25-
# In Package.swift we depend on branch main, but if we wanted to depend on a tag:
26-
# SwiftPM resolves "main" to the latest commit automatically, but updating the SPM resolved file ensures deterministic builds:
27-
swift package update mlx-swift
44+
set -euo pipefail
45+
case "$PAYLOAD_SOURCE_REPO" in
46+
mlx-swift|mlx-swift-lm) ;;
47+
*)
48+
echo "::error::unexpected source_repo '$PAYLOAD_SOURCE_REPO' — expected mlx-swift or mlx-swift-lm"
49+
exit 1
50+
;;
51+
esac
52+
if ! printf '%s' "$PAYLOAD_NEW_TAG" | grep -Eq '^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$'; then
53+
echo "::error::refusing tag '$PAYLOAD_NEW_TAG' — not a plain tag name"
54+
exit 1
55+
fi
56+
{
57+
echo "SOURCE_REPO=$PAYLOAD_SOURCE_REPO"
58+
echo "NEW_TAG=$PAYLOAD_NEW_TAG"
59+
} >> "$GITHUB_ENV"
2860
29-
- name: Update swift-mlx-lm dependencies
30-
if: ${{ github.event.client_payload.source_repo == 'mlx-swift-lm' }}
61+
# Both dependencies are `.package(path: "./…")` in Package.swift, backed by git
62+
# submodules, so bumping either one is a pointer move. `swift package update`
63+
# does nothing for a path dependency — SwiftPM takes whatever is on disk — which
64+
# is why the mlx-swift branch of the previous version of this workflow could only
65+
# ever have produced an empty commit.
66+
- name: Move submodule to the released tag
3167
run: |
32-
echo "Bumping local mlx-swift-lm submodule to ${{ github.event.client_payload.new_tag }}"
33-
git submodule update --remote mlx-swift-lm
34-
# Force the submodule onto the specific new release tag
35-
cd mlx-swift-lm
36-
git checkout ${{ github.event.client_payload.new_tag }}
37-
cd ..
38-
git add mlx-swift-lm
39-
40-
- name: Create Pull Request
41-
uses: peter-evans/create-pull-request@v6
42-
with:
43-
token: ${{ secrets.SWIFTLM_PR_TOKEN }}
44-
commit-message: "chore(deps): bump ${{ github.event.client_payload.source_repo }} to ${{ github.event.client_payload.new_tag }}"
45-
title: "Update ${{ github.event.client_payload.source_repo }} Dependency to ${{ github.event.client_payload.new_tag }}"
46-
body: |
47-
Automated dependency update triggered by release `${{ github.event.client_payload.new_tag }}` in `SharpAI/${{ github.event.client_payload.source_repo }}`.
48-
49-
This PR ensures SwiftLM is tracking the latest validated architectural improvements.
50-
branch: "auto-update/${{ github.event.client_payload.source_repo }}-${{ github.event.client_payload.new_tag }}"
51-
base: main
68+
set -euo pipefail
69+
git -C "$SOURCE_REPO" fetch --tags --force origin
70+
if ! git -C "$SOURCE_REPO" rev-parse -q --verify "refs/tags/${NEW_TAG}^{commit}" >/dev/null; then
71+
echo "::error::tag $NEW_TAG does not exist in $SOURCE_REPO"
72+
exit 1
73+
fi
74+
before=$(git rev-parse "HEAD:$SOURCE_REPO")
75+
git -C "$SOURCE_REPO" checkout --detach "refs/tags/$NEW_TAG"
76+
after=$(git -C "$SOURCE_REPO" rev-parse HEAD)
77+
{
78+
echo "BEFORE_SHA=$before"
79+
echo "AFTER_SHA=$after"
80+
} >> "$GITHUB_ENV"
81+
if [ "$before" = "$after" ]; then
82+
echo "ALREADY_CURRENT=1" >> "$GITHUB_ENV"
83+
fi
84+
85+
- name: Report an already-current submodule and stop
86+
if: env.ALREADY_CURRENT == '1'
87+
run: |
88+
{
89+
echo "### Nothing to bump"
90+
echo
91+
echo "\`$SOURCE_REPO\` is already at \`$NEW_TAG\` (\`${AFTER_SHA:0:7}\`)."
92+
} >> "$GITHUB_STEP_SUMMARY"
93+
94+
- name: Push the bump branch
95+
if: env.ALREADY_CURRENT != '1'
96+
run: |
97+
set -euo pipefail
98+
branch="auto-update/${SOURCE_REPO}-${NEW_TAG}"
99+
git checkout -B "$branch"
100+
git add "$SOURCE_REPO"
101+
git \
102+
-c user.name='github-actions[bot]' \
103+
-c user.email='41898282+github-actions[bot]@users.noreply.github.com' \
104+
commit -m "chore(deps): bump $SOURCE_REPO to $NEW_TAG
105+
106+
Moves the $SOURCE_REPO submodule from ${BEFORE_SHA:0:7} to ${AFTER_SHA:0:7},
107+
the commit tagged $NEW_TAG.
108+
109+
Prepared automatically; opened by hand so that CI runs against it."
110+
# The auto-update/* namespace belongs to this workflow, so replacing a branch
111+
# left by an earlier run for the same tag is safe and keeps re-runs idempotent.
112+
git push --force origin "$branch"
113+
echo "BUMP_BRANCH=$branch" >> "$GITHUB_ENV"
114+
115+
- name: Summarise, with a link that opens the pull request
116+
if: env.ALREADY_CURRENT != '1'
117+
run: |
118+
{
119+
echo "### \`$SOURCE_REPO\` → \`$NEW_TAG\` is ready"
120+
echo
121+
echo "Branch \`$BUMP_BRANCH\` pushed, moving the submodule from"
122+
echo "\`${BEFORE_SHA:0:7}\` to \`${AFTER_SHA:0:7}\`."
123+
echo
124+
echo "**[Open the pull request](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/compare/main...${BUMP_BRANCH}?expand=1)**"
125+
echo
126+
echo "No PR is opened here on purpose: GitHub does not start workflow runs"
127+
echo "for events raised by \`GITHUB_TOKEN\`, so a bot-opened PR would never"
128+
echo "get CI. Opening it yourself gets the checks this repository gates"
129+
echo "releases on."
130+
} >> "$GITHUB_STEP_SUMMARY"

0 commit comments

Comments
 (0)