diff --git a/.github/scripts/report_external_links.py b/.github/scripts/report_external_links.py new file mode 100644 index 0000000..03ff100 --- /dev/null +++ b/.github/scripts/report_external_links.py @@ -0,0 +1,78 @@ +"""On-demand, advisory external-link report; never a PR merge gate.""" +from concurrent.futures import ThreadPoolExecutor +from pathlib import Path +import os +import re +from urllib.error import HTTPError, URLError +from urllib.parse import urlsplit +from urllib.request import Request, urlopen + + +def eligible(url): + parsed = urlsplit(url) + host = (parsed.hostname or '').lower() + return (parsed.scheme in {'http', 'https'} and bool(host) + and not parsed.username and not parsed.password + and not (host == 'zoom.us' or host.endswith('.zoom.us')) + and host not in {'docs.google.com', 'drive.google.com'} + and not re.search(r'(?:token|password|pwd|secret|key)=', parsed.query, re.I)) + + +def collect(root): + references = {} + for path in sorted(root.rglob('*')): + if path.name == 'external-link-report.md' or path.suffix not in {'.md', '.rst'} or '.git' in path.relative_to(root).parts: + continue + # Operational guidance and indexes; historical minutes need a separate review. + if re.match(r'\d{4}-\d|\d{3}-', path.name): + continue + for number, line in enumerate(path.read_text(encoding='utf-8').splitlines(), 1): + for url in re.findall(r'https?://[^\s<>`"\)\]]+', line): + url = url.rstrip('.,;').split('#')[0] + if eligible(url): + references.setdefault(url, []).append(f'{path.relative_to(root).as_posix()}:{number}') + return references + + +def probe(url): + try: + request = Request(url, headers={'User-Agent': 'UXL-documentation-link-review/1.0'}) + with urlopen(request, timeout=12) as response: + return ('reachable', str(response.status)) + except HTTPError as error: + if error.code in {404, 410}: + return ('missing', str(error.code)) + if error.code in {401, 403}: + return ('restricted or bot-blocked', str(error.code)) + return ('retry or investigate', str(error.code)) + except (URLError, TimeoutError, OSError, ValueError) as error: + return ('unverified', type(error).__name__) + + +def report(root): + references = collect(root) + with ThreadPoolExecutor(max_workers=8) as pool: + results = dict(zip(references, pool.map(probe, references))) + lines = ['# External documentation link review', '', + f'Checked {len(results)} unique URLs in guidance and indexes.', '', + 'Advisory only: 403 responses may indicate access controls or bot protection. ' + 'A successful response does not verify page content or section anchors. ' + 'Dated minutes, archived RFCs, PDFs, restricted recording links and Google documents are excluded.', '', + '| Result | URL | Source |', '| --- | --- | --- |'] + for url, (status, detail) in results.items(): + if status != 'reachable': + safe_url = url.replace('|', '%7C') + sources = ', '.join(references[url]).replace('|', '\\|') + lines.append(f'| {status} ({detail}) | <{safe_url}> | {sources} |') + if all(status == 'reachable' for status, _ in results.values()): + lines.append('| No failed requests | — | — |') + return '\n'.join(lines) + '\n' + + +if __name__ == '__main__': + result = report(Path.cwd()) + Path('external-link-report.md').write_text(result, encoding='utf-8') + if os.environ.get('GITHUB_STEP_SUMMARY'): + with open(os.environ['GITHUB_STEP_SUMMARY'], 'a', encoding='utf-8') as summary: + summary.write(result) + print(result) diff --git a/.github/scripts/test_external_links.py b/.github/scripts/test_external_links.py new file mode 100644 index 0000000..142f29a --- /dev/null +++ b/.github/scripts/test_external_links.py @@ -0,0 +1,20 @@ +from urllib.error import HTTPError +from unittest import TestCase +from unittest.mock import patch +from report_external_links import eligible, probe + + +class ExternalLinkReportTests(TestCase): + def test_restricted_response_is_not_reported_as_dead(self): + with patch('report_external_links.urlopen', side_effect=HTTPError('https://example.org', 403, '', {}, None)): + self.assertEqual(probe('https://example.org'), ('restricted or bot-blocked', '403')) + + def test_missing_response_is_reported(self): + with patch('report_external_links.urlopen', side_effect=HTTPError('https://example.org', 404, '', {}, None)): + self.assertEqual(probe('https://example.org'), ('missing', '404')) + + def test_private_recording_and_credential_links_are_excluded(self): + for url in ['https://zoom.us/rec/share/abc', 'https://docs.google.com/document/d/abc', + 'https://example.org/?token=secret', 'https://user:password@example.org/']: + self.assertFalse(eligible(url)) + self.assertTrue(eligible('https://uxlfoundation.org/')) diff --git a/.github/workflows/external-links.yml b/.github/workflows/external-links.yml new file mode 100644 index 0000000..d319375 --- /dev/null +++ b/.github/workflows/external-links.yml @@ -0,0 +1,15 @@ +name: External link review +on: + workflow_dispatch: +permissions: + contents: read +jobs: + report: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + with: + persist-credentials: false + - name: Report external link availability + run: python3 .github/scripts/report_external_links.py diff --git a/.gitignore b/.gitignore index c18dd8d..b12aff3 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,3 @@ __pycache__/ + +/external-link-report.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 59b5b0b..e6f9ff5 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -46,3 +46,9 @@ For rendering and meeting-index checks, install `docutils==0.19` and run `python .github/scripts/check_document_structure.py`. The check reports malformed reStructuredText and dated records missing from sibling indexes. External URLs and cross-document section anchors still require review. + +Maintainers can run **External link review** from the Actions tab to obtain an +advisory report for guidance and indexes. It distinguishes missing pages from +access restrictions and transient failures, and does not block pull requests. +PDFs and restricted meeting materials are excluded. To run locally, use +`python .github/scripts/report_external_links.py`; it writes `external-link-report.md`. diff --git a/meetings/notes/2025-06-22.rst b/meetings/notes/2025-06-22.rst index a936035..b77024f 100644 --- a/meetings/notes/2025-06-22.rst +++ b/meetings/notes/2025-06-22.rst @@ -1,140 +1,12 @@ -============================ -Open Source WG: 06/22/2025 -============================ +July 2025 meeting record: corrected filename +============================================ -.. note:: +These minutes belong to the `July 22, 2025 meeting <2025-07-22.rst>`__. - Record verification pending: the body of these notes matches - `2025-07-22 <2025-07-22.rst>`__ apart from the meeting date. Both records - are preserved while the original calendar or recording is checked. +`PR #230 `__ +published July's minutes under a June filename. +`PR #231 `__ +then corrected the dates from June to July. This page preserves the earlier URL; +it is not a separate June meeting record. -Recording: A recording of the meeting is available in the Linux Foundation https://openprofile.dev/ profile. If you are -a member of the Working Group you can access this through your account. - -Attendees -=========== - -* Megan Knight - Arm - -* Kuldeep Pal - C-DAC - -* Rod Burns - Codeplay - -* Abhishek Jain - Fujitsu - -* Ed Tuke - Imagination Technologies - -* Irina Topinskaia - Intel -* John Melonakos - Intel -* Andrey Fedorov - Intel -* Nikolay Petrov - Intel -* Mike Voss - Intel -* Mourad Gouicem - Intel -* Maria Petrova - Intel -* Timmie Smith - Intel -* Alexey Kukanov - Intel -* Aleksandr Solovev - Intel -* Vasudha Badri-Paul - Intel -* Ian Faust - Intel - - -Quick Recap -============= - -The meeting began with introductions and agenda setting, followed by discussions about OFAC sanctions and updates from -various open source projects. The team reviewed upcoming releases across multiple projects including oneDNN, oneDPL, and -oneCCL, with specific focus on new features and performance improvements. The conversation ended with reminders about -sharing work through presentations at upcoming events and thanks to participants. - -Next Steps -============ - -* Megan to reach out to OpenSSF security experts for guidance on implementing OFAC sanctions compliance -* Megan to discuss OFAC sanctions implementation with Dolan and Rod -* Megan to add OFAC sanctions discussion to next OpenSSF working group meeting agenda (scheduled for next Tuesday) -* Megan to follow up with JDF contacts regarding OFAC sanctions guidance -* Mourad to update release timeline for 3.9 release (potentially delayed due to PyTorch dependencies) -* Maria to deliver patches for Battlemage and Arc GPU support -* Maria to prepare patches for PyTorch 1.16 release (targeted for mid-August) -* Maria to implement new C API design for 21.17 release (as non-default option) -* Rod to send Open Source Summit recording links to meeting attendees -* Rod to share Dev Summit call for presentations with meeting attendees - -Summary -========= - -OFAC Sanctions and Project Updates: -===================================== - -The meeting began with Megan introducing herself and the agenda, which included a focus on OFAC sanctions and updates -from open source projects. Rod confirmed that the recordings from the Mini summit were published and agreed to send them -out. The group discussed the OFAC sanctions issue raised by Michael Voss, with Michael providing an overview of the -topic and emphasizing that he is not a lawyer. The conversation ended with a reminder for participants to add any -additional agenda items to the chat or to Megan and John. - -Sanctions Compliance and Legal Implications: -============================================== - -Mike explained the legal implications of sanctions against specially designated nationals, noting that US citizens and -organizations must comply with these rules worldwide, even if unaware of violations. He highlighted that the rules -impose strict liability, meaning any infractions can result in fines or criminal penalties, and emphasized that -ownership of 50% or more by sanctioned individuals or organizations can also trigger sanctions. - -Open Source Contribution Policy Challenges: -============================================= - -Mike raised concerns about the challenges of enforcing contribution policies for open source projects, particularly -regarding unsolicited patches and two-way engagement with individuals or organizations on restricted lists. Megan -acknowledged these issues and suggested exploring guidance from the Linux Foundation and OpenSSF, noting the need for -unified policies across projects. She proposed taking the lead on this matter, including consulting with OpenSSF's -security experts and discussing it with the operations team, to find practical solutions for identity management and -contribution verification. - -oneDNN Updates: -================= - -Mourad reported on oneDNN, mentioning a release candidate for 3.9 expected at the end of the week, with potential delays -due to new features and PyTorch's schedule. They also noted interest from the Barcelona supercomputing group in adding -RISC-V capabilities. - -oneMath Updates: -================== - -Andrey said oneMath did not have much of a update. The are focused on maintenance releases at the moment. - -oneDAL Updates: -================= - -Ian and Aleksandr ("Sasha") provided updates on oneDAL, mentioning bug fixes and preparation for the 2025.3 release in -November. - -oneTBB Updates: -================= - -Mike shared that oneTBB's next release in 2022.3 would focus on improvements to the tasking API, requested by the visual -effects community. The team agreed that monthly releases generally work well for them, allowing for better feedback on -dependencies. - -oneDPL Updates: -================= - -The team discussed the status and development of oneDPL, a portable library for CPUs, which currently sees primarily -Intel-related usage. Timmie reported ongoing work on range-based APIs for parallel algorithms and GPU performance -improvements, particularly for set operation algorithms. Alexey explained that oneDPL's CPU support serves as an -upstream source for the C++ standard library's parallel algorithms, though this relationship has recently become less -active. - -oneCCL Updates: -================= - -Maria provided updates on CCL, noting their work on supporting Battle Match ARB-PE and PyTorch upstream, with plans for -a patch release in mid-August and a major release in October that will include a new C API design as a non-default -option. - -Dev Summit Presentation Submissions Discussion: -================================================= - -The meeting was shorter than usual due to the summer season, with Aaron absent from the office. Rod requested that John -share videos from the Open Source Summit and a link to the Call for Presentations for the upcoming Dev summit. John -encouraged all projects to submit presentations, emphasizing the importance of sharing their work within the -foundation. The conversation ended with thanks from Megan and the participants. +`Meeting index `__ diff --git a/meetings/notes/2025-07-22.rst b/meetings/notes/2025-07-22.rst index 775421e..20f0806 100644 --- a/meetings/notes/2025-07-22.rst +++ b/meetings/notes/2025-07-22.rst @@ -4,9 +4,10 @@ Open Source WG: 07/22/2025 .. note:: - Record verification pending: the body of these notes matches - `2025-06-22 <2025-06-22.rst>`__ apart from the meeting date. Both records - are preserved while the original calendar or recording is checked. + This is the corrected July record. `PR #231 + `__ + explicitly corrected the dates from June to July. The earlier + `June-labelled URL <2025-06-22.rst>`__ is retained as a redirect. Recording: A recording of the meeting is available in the Linux Foundation https://openprofile.dev/ profile. If you are a member of the Working Group you can access this through your account. diff --git a/meetings/notes/README.rst b/meetings/notes/README.rst index 2216a99..a6fd960 100644 --- a/meetings/notes/README.rst +++ b/meetings/notes/README.rst @@ -56,10 +56,7 @@ already published in this repository. - Infrastructure handover; hardware and administrator support; developer summit planning - `CI transition <../presentations/2025-08-26-UXL-Working-Group-CI-Transition.pdf>`__ * - `2025-07-22 <2025-07-22.rst>`__ - - Contribution policies and compliance; project updates (June/July record duplication under review) - - — - * - `2025-06-22 <2025-06-22.rst>`__ - - Contribution policies and compliance; project updates (June/July record duplication under review) + - Contribution policies and compliance; updates from the six library projects - — * - `2025-05-27 <2025-05-27.rst>`__ - Security progress; hardware runners; CPU-inclusive APIs; library proposals @@ -91,3 +88,10 @@ already published in this repository. * `2024-03-26 <2024-03-26.rst>`__ * `2024-02-27 <2024-02-27.rst>`__ * `2024-01-24 <2024-01-24.rst>`__ + +Corrected record URLs +---------------------- + +The `June-labelled record <2025-06-22.rst>`__ redirects to the July 22, 2025 +minutes following the date correction in PR #231. It is not counted as an +additional meeting. diff --git a/project-infrastructure/project-ci-documentation.md b/project-infrastructure/project-ci-documentation.md index d5f1d64..dd6ce20 100644 --- a/project-infrastructure/project-ci-documentation.md +++ b/project-infrastructure/project-ci-documentation.md @@ -23,6 +23,27 @@ The [August 2025 infrastructure discussion](../meetings/notes/2025-08-26.rst) records changes to hardware access and support. Earlier runner catalogues should not be used as current availability guarantees. +## Public workflow evidence + +Reviewed September 9, 2026 using GitHub's successful workflow-run records. +These are observed examples, not a complete coverage assessment or a guarantee +that runners are currently available. A workflow-level success can include skipped +jobs; inspect its jobs and logs before claiming support for a particular platform. +Dates below are the run creation dates in UTC. + +| Project | Successful run observed | Run date | What the evidence establishes | +| --- | --- | --- | --- | +| oneDNN | [CI AArch64](https://github.com/uxlfoundation/oneDNN/actions/runs/28283384460) | 2026-06-27 | A successful architecture-labelled CI workflow; this is older evidence, not current capacity verification. | +| oneDAL | [docker-validation Nightly](https://github.com/uxlfoundation/oneDAL/actions/runs/34415652999) | 2026-09-09 | A successful nightly validation workflow; shared capacity and full platform coverage are not established. | +| oneMath | [PR Tests (x86_64)](https://github.com/uxlfoundation/oneMath/actions/runs/33626039801), [PR Tests (aarch64)](https://github.com/uxlfoundation/oneMath/actions/runs/33626039750) | 2026-09-02 | Successful architecture-labelled PR workflows; GPU coverage is not established by these runs. | +| oneTBB | [oneTBB CI](https://github.com/uxlfoundation/oneTBB/actions/runs/34341528354) | 2026-09-09 | A successful project CI workflow; inspect job results for the exact platform matrix. | +| oneDPL | [oneDPL CI Docs](https://github.com/uxlfoundation/oneDPL/actions/runs/34399254049) | 2026-09-09 | Documentation CI only; this example does not establish functional CPU or GPU testing. | +| oneCCL | [Coverity Scan](https://github.com/uxlfoundation/oneCCL/actions/runs/25319695571) | 2026-05-04 | An older static-analysis workflow; functional testing and current availability remain unverified. | + +Use each project's Actions page and maintainer guidance to obtain newer evidence. +Update the verification date with the evidence; do not replace it merely because +this document was edited. + ## Previously reported shared capacity | Owner | Type | OS | Number | Verified availability | Notes |