diff mbox series

[1/2] devtool: upgrade: ignore changelogs from 3rd party

Message ID 20260803100231.3752129-1-daniel.turull@ericsson.com
State New
Headers show
Series [1/2] devtool: upgrade: ignore changelogs from 3rd party | expand

Commit Message

Daniel Turull Aug. 3, 2026, 10:02 a.m. UTC
From: Daniel Turull <daniel.turull@ericsson.com>

Some upstream projects bundle vendored dependencies in their source
tree (e.g. nghttp2 ships third-party/mruby, which has its own
NEWS.md). The changelog extractor could mistake one of these
vendored changelogs for the recipe's own, misattributing unrelated
upstream changes to the package being upgraded.

Exclude paths under common vendoring directory names (third-party,
vendor, external, deps, etc.) from changelog candidates.

AI-Generated: Kiro with Claude Sonnet 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
---
 scripts/lib/devtool/upgrade.py | 10 ++++++++++
 1 file changed, 10 insertions(+)

Comments

Richard Purdie Aug. 3, 2026, 1:12 p.m. UTC | #1
On Mon, 2026-08-03 at 12:02 +0200, Daniel Turull via lists.openembedded.org wrote:
> From: Daniel Turull <daniel.turull@ericsson.com>
> 
> Some upstream projects bundle vendored dependencies in their source
> tree (e.g. nghttp2 ships third-party/mruby, which has its own
> NEWS.md). The changelog extractor could mistake one of these
> vendored changelogs for the recipe's own, misattributing unrelated
> upstream changes to the package being upgraded.
> 
> Exclude paths under common vendoring directory names (third-party,
> vendor, external, deps, etc.) from changelog candidates.
> 
> AI-Generated: Kiro with Claude Sonnet 5
> Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
> ---
>  scripts/lib/devtool/upgrade.py | 10 ++++++++++
>  1 file changed, 10 insertions(+)

Thanks for these. Unfortunately something in here caused the devtool tests to fail:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/4274

Cheers,

Richard
Daniel Turull Aug. 3, 2026, 1:16 p.m. UTC | #2
On Mon, 2026-08-03 at 14:12 +0100, Richard Purdie wrote:
> On Mon, 2026-08-03 at 12:02 +0200, Daniel Turull via lists.openembedded.org wrote:
> > From: Daniel Turull <daniel.turull@ericsson.com>
> > 
> > Some upstream projects bundle vendored dependencies in their source
> > tree (e.g. nghttp2 ships third-party/mruby, which has its own
> > NEWS.md). The changelog extractor could mistake one of these
> > vendored changelogs for the recipe's own, misattributing unrelated
> > upstream changes to the package being upgraded.
> > 
> > Exclude paths under common vendoring directory names (third-party,
> > vendor, external, deps, etc.) from changelog candidates.
> > 
> > AI-Generated: Kiro with Claude Sonnet 5
> > Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
> > ---
> >  scripts/lib/devtool/upgrade.py | 10 ++++++++++
> >  1 file changed, 10 insertions(+)
> 
> Thanks for these. Unfortunately something in here caused the devtool tests to fail:
> 

Ok. I'll take a look and run the test locally. I just did happy testing with a couple of packages
and miss to run the devtool selftests.

Best regards,

Daniel
> 
> Cheers,
> 
> Richard
diff mbox series

Patch

diff --git a/scripts/lib/devtool/upgrade.py b/scripts/lib/devtool/upgrade.py
index 13d51bf952..495a5b8217 100644
--- a/scripts/lib/devtool/upgrade.py
+++ b/scripts/lib/devtool/upgrade.py
@@ -55,6 +55,13 @@  _CHANGELOG_BASENAMES = {
     'perldelta.pod',
 }
 
+# Path components indicating a bundled/vendored dependency rather than the
+# recipe's own source, so its changelog-like files should not be mistaken
+# for the recipe's own changes (e.g. third-party/mruby/NEWS.md in nghttp2).
+_VENDORED_PATH_RE = re.compile(
+    r'(^|/)(third[-_]party|vendor|vendored|external|extern|deps|3rdparty)(/|$)',
+    re.IGNORECASE)
+
 def _run(cmd, cwd=''):
     logger.debug("Running command %s> %s" % (cwd,cmd))
     return bb.process.run('%s' % cmd, cwd=cwd)
@@ -591,6 +598,9 @@  def _extract_changelog(srctree, pn, old_ver, new_ver, old_tag, new_tag, workspac
     try:
         stdout, _ = _run('git diff --name-only %s %s' % (old_tag, new_tag), srctree)
         changed_files = [f.strip() for f in stdout.splitlines() if f.strip()]
+        # Exclude bundled/vendored dependencies; their changelogs are not
+        # relevant to this recipe's own version bump.
+        changed_files = [f for f in changed_files if not _VENDORED_PATH_RE.search(f)]
 
         # First pass: collect per-version release notes that changed
         # Matches files with a version number whose path suggests release notes