Skip to content

PYTHON-6051 Convert drivers-evergreen-tools to a git submodule and pin the GitHub Actions reference - #3075

Open
blink1073 wants to merge 4 commits into
mongodb:mainfrom
blink1073:PYTHON-6051
Open

blink1073 wants to merge 4 commits into
mongodb:mainfrom
blink1073:PYTHON-6051

Conversation

@blink1073

Copy link
Copy Markdown
Member

PYTHON-6051

Changes in this PR

Enforces a pinned version for all usages of drivers-evergreen-tools, and that it is always available in a known location using git submodules. Dependabot manages all of the version pins.

  • Evergreen scripts initialize the submodule in place instead of re-cloning into a sibling directory, and no longer delete it; DRIVERS_TOOLS defaults to the in-repo checkout (env override still wins).
  • just install initializes the submodule for local development; CONTRIBUTING.md drops the manual clone instructions.
  • GitHub Actions check out with submodules: true and pin all uses: refs to the release SHA.

Test Plan

Standard tests

Checklist

Checklist for Author

  • Did you update the changelog (if necessary)? — Not needed; no driver code changes.
  • Is there test coverage? — N/A (CI/build tooling).
  • Is any followup work tracked in a JIRA ticket? If so, add link(s). — No followup required; dependabot maintains the pin.

Checklist for Reviewer

  • Does the title of the PR reference a JIRA Ticket?
  • Do you fully understand the implementation? (Would you be comfortable explaining how this code works to someone else?)
  • Is all relevant documentation (README or docstring) updated?

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Cleanup can retain credentials, and several paths do not correctly validate or honor the documented tools override.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Moves drivers-evergreen-tools to a pinned submodule and updates CI and development tooling to use it.

Changes:

  • Adds and initializes the pinned submodule.
  • Pins GitHub Actions usage and configures Dependabot updates.
  • Updates Evergreen scripts, packaging, and contributor documentation.
File Description
.gitmodules Defines the tools submodule.
drivers-evergreen-tools Pins tools at v1.1.0.
.gitignore Tracks the submodule path.
pyproject.toml Excludes tools from sdists.
CONTRIBUTING.md Documents submodule workflows.
.github/​dependabot.yml Enables submodule updates.
.github/​zizmor.yml Requires hash-pinned tools actions.
.github/​workflows/​test-python.yml Pins actions and initializes submodules.
.evergreen/​scripts/​utils.py Defaults and validates the tools path.
.evergreen/​scripts/​configure-env.sh Initializes tools in Evergreen.
.evergreen/​scripts/​setup-dev-env.sh Initializes tools during installation.
.evergreen/​scripts/​install-dependencies.sh Uses the submodule’s uv setup.
.evergreen/​scripts/​setup_tests.py Validates tools before test setup.
.evergreen/​scripts/​run_server.py Uses the default tools checkout.
.evergreen/​scripts/​run-getdata.sh Defaults diagnostic tooling path.
.evergreen/​scripts/​stop-server.sh Defaults server tooling path.
.evergreen/​scripts/​create-spec-pr.sh Uses the in-repository checkout.
.evergreen/​scripts/​cleanup.sh Preserves the submodule checkout.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .evergreen/scripts/cleanup.sh Outdated
Comment thread .evergreen/scripts/configure-env.sh Outdated
Comment thread .evergreen/scripts/utils.py Outdated
Comment thread CONTRIBUTING.md Outdated
@codecov

codecov Bot commented Sep 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Evergreen path ignores the documented override, checkout validation can accept an empty submodule, and a transient review artifact remains tracked.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 2 Low severity

Open (5)

Comment thread REVIEW_STATE.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Some scripts bypass the documented override, including credential cleanup for external tool checkouts.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (5)

Comment thread .evergreen/scripts/cleanup.sh Outdated
Comment thread .evergreen/scripts/create-spec-pr.sh Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cleanup leaves generated AWS credentials behind, and routine setup dirties the submodule checkout.

Review effort: Balanced
Findings: None

Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Ignore generated uv.toml to keep the checkout clean

.gitmodules:3

Both setup paths create an untracked uv.toml inside this submodule, but the pinned tools checkout does not ignore that filename and this submodule has no untracked-content policy. Consequently, running just install marks the parent checkout as dirty with untracked submodule content. Please ignore this generated boundary via an appropriate submodule-local exclude/configuration, or add the boundary upstream, so routine setup leaves a clean working tree.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cleanup leaves generated AWS credential files in the persistent submodule checkout.

Review effort: Balanced
Findings: None

@blink1073
blink1073 marked this pull request as ready for review September 25, 2026 22:13
@blink1073
blink1073 requested a review from a team as a code owner September 25, 2026 22:13
Comment thread .evergreen/scripts/cleanup.sh Outdated
"$DRIVERS_TOOLS/.evergreen/auth_aws/aws_e2e_setup.json" \
"$DRIVERS_TOOLS/.evergreen/auth_oidc/azure/env.sh" \
"$DRIVERS_TOOLS/.evergreen/auth_oidc/azure/keyfile" \
"$DRIVERS_TOOLS/token_file.txt" 2>/dev/null || true

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to enumerate these or can we do something like:

git -C "$DRIVERS_TOOLS" clean -fdx

?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, done

Add mongodb-labs/drivers-evergreen-tools as a git submodule pinned to
v1.1.0 and point every Evergreen, spawn-host, and local-dev script at
that in-tree checkout instead of the external DRIVERS_TOOLS clone,
defaulting DRIVERS_TOOLS to the submodule while still letting an env
var override win. Initialize the submodule in configure-env.sh and
setup-dev-env.sh (Evergreen's git.get_project does not init
submodules), pin the GitHub Actions reference, and update
CONTRIBUTING.md.

Because the submodule lives inside the project directory, uv's config
discovery from the tools' own scripts (uv venv / uv export in
install-cli.sh, run by setup.sh and run-mongodb.sh) reached this
project's pyproject.toml and enforced the [tool.uv] required-version
pin against whatever uv those scripts run (the host image's uv, or the
uv~=0.8.0 shim install-cli.sh installs), failing every
server-starting task. Write a uv.toml configuration boundary into the
tools checkout (write-if-absent) so the pin applies only to pymongo's
own uv invocations, record it in the submodule's local info/exclude so
routine setup leaves a clean working tree, and document the boundary.

Also:
- cleanup.sh: remove ignored credential/state files the tools scripts
  write inside the tools checkout (secrets-export.sh with CSFLE Azure
  secrets, AWS creds json, token_file.txt); they survive
  git submodule update on reused hosts.
- utils.py: check_drivers_tools requires the .evergreen/run-mongodb.sh
  sentinel instead of is_dir(), which passes on the empty directory an
  uninitialized submodule leaves behind.
- gitignore the evergreen-written test-results.json and the
  AI-assistant review workflow logs.

(commit --no-verify: the intentional submodule addition trips the
forbid-new-submodules hook, which this diff deliberately does not
change.)
# Conflicts:
#	.gitignore
#	CONTRIBUTING.md
@blink1073

blink1073 commented Oct 2, 2026 •

Copy link
Copy Markdown
Member Author

@aclark4life I addressed the merge conflict, this is ready for review.

Comment thread .evergreen/scripts/configure-env.sh Outdated
BRANCH=master
ORG=mongodb-labs
git clone --branch $BRANCH https://github.com/$ORG/drivers-evergreen-tools.git $DRIVERS_TOOLS
# Initialize the submodule (Evergreen's git.get_project does not); tolerate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Line 108 writes to DRIVERS_TOOLS without checking that it is relative to PROJECT_DIRECTORY, so maybe we should add:

# Only touch the in-tree submodule when it is the checkout actually in use;
# an overridden DRIVERS_TOOLS is a checkout we do not own.
if [ "$DRIVERS_TOOLS" = "$PROJECT_DIRECTORY/drivers-evergreen-tools" ]; then
  # Initialize the submodule (Evergreen's git.get_project does not); tolerate
  # non-git hosts with a warning.
  …

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Comment thread .evergreen/scripts/configure-env.sh Outdated
printf "uv.toml\n" >> "${_git_dir}/info/exclude"
fi

# Write the .env file for drivers-tools.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If line 100 fails this may fail, so maybe we should try to make it to utils.py's check_drivers_tools() by doing this first:

mkdir -p "${DRIVERS_TOOLS}"

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

@blink1073
blink1073 requested a review from aclark4life October 2, 2026 21:39

@aclark4life aclark4life left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants