fix(sql): handle ORDER BY in embedded MSSQL queries (#43127) #89153
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build & publish docker images | |
| on: | |
| push: | |
| branches: | |
| - "master" | |
| - "[0-9].[0-9]*" | |
| pull_request: | |
| branches: | |
| - "master" | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} | |
| cancel-in-progress: true | |
| jobs: | |
| changes: | |
| runs-on: ubuntu-26.04 | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| python: ${{ steps.check.outputs.python }} | |
| frontend: ${{ steps.check.outputs.frontend }} | |
| docker: ${{ steps.check.outputs.docker }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Check for file changes | |
| id: check | |
| uses: ./.github/actions/change-detector/ | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| setup_matrix: | |
| runs-on: ubuntu-slim | |
| timeout-minutes: 5 | |
| outputs: | |
| matrix_config: ${{ steps.set_matrix.outputs.matrix_config }} | |
| steps: | |
| - id: set_matrix | |
| run: | | |
| MATRIX_CONFIG=$(if [ "${{ github.event_name }}" == "pull_request" ]; then echo '["dev", "lean"]'; else echo '["dev", "lean", "websocket", "dockerize", "py311", "py312"]'; fi) | |
| echo "matrix_config=${MATRIX_CONFIG}" >> $GITHUB_OUTPUT | |
| echo $GITHUB_OUTPUT | |
| docker-build: | |
| name: docker-build | |
| needs: [setup_matrix, changes] | |
| if: >- | |
| needs.changes.outputs.python == 'true' || | |
| needs.changes.outputs.frontend == 'true' || | |
| needs.changes.outputs.docker == 'true' | |
| runs-on: ubuntu-26.04 | |
| timeout-minutes: 60 | |
| strategy: | |
| matrix: | |
| build_preset: ${{fromJson(needs.setup_matrix.outputs.matrix_config)}} | |
| fail-fast: false | |
| env: | |
| DOCKERHUB_USER: ${{ secrets.DOCKERHUB_USER }} | |
| DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} | |
| IMAGE_TAG: apache/superset:GHA-${{ matrix.build_preset }}-${{ github.run_id }} | |
| steps: | |
| - name: "Checkout ${{ github.ref }} ( ${{ github.sha }} )" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Free up disk space | |
| shell: bash | |
| run: | | |
| # Reclaim large preinstalled toolchains we don't use. The image | |
| # build, and especially the docker-compose sanity check (which | |
| # rebuilds from scratch whenever the registry cache image | |
| # apache/superset-cache is unavailable), can otherwise exhaust the | |
| # runner's root disk and fail with "no space left on device". | |
| echo "Disk before cleanup:"; df -h / | |
| sudo rm -rf \ | |
| /usr/share/dotnet \ | |
| /usr/local/lib/android \ | |
| /opt/ghc \ | |
| /usr/local/.ghcup \ | |
| /opt/hostedtoolcache/CodeQL \ | |
| /usr/local/share/boost || true | |
| echo "Disk after cleanup:"; df -h / | |
| - name: Setup Docker Environment | |
| uses: ./.github/actions/setup-docker | |
| with: | |
| dockerhub-user: ${{ secrets.DOCKERHUB_USER }} | |
| dockerhub-token: ${{ secrets.DOCKERHUB_TOKEN }} | |
| build: "true" | |
| - name: Setup supersetbot | |
| uses: ./.github/actions/setup-supersetbot/ | |
| - name: Build Docker Image | |
| shell: bash | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| BUILD_PRESET: ${{ matrix.build_preset }} | |
| run: | | |
| # Single platform builds in pull_request context to speed things up | |
| if [ "$GITHUB_EVENT_NAME" = "push" ]; then | |
| PLATFORM_ARG="--platform linux/arm64 --platform linux/amd64" | |
| # can only --load images in single-platform builds | |
| PUSH_OR_LOAD="--push" | |
| elif [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then | |
| PLATFORM_ARG="--platform linux/amd64" | |
| PUSH_OR_LOAD="--load" | |
| fi | |
| # Retry to absorb transient Docker Hub registry errors (base-image | |
| # pull timeouts, 504/401 on push, ECONNRESET) that otherwise fail | |
| # the whole job. buildx reuses the buildkit layer cache from the | |
| # failed attempt, so a retry mostly re-does just the failed push. | |
| # | |
| # supersetbot's "dev"/"lean" presets pin their own --build-arg | |
| # PY_VER, which lands ahead of --extra-flags on the assembled | |
| # buildx command line; docker/buildx keeps the last value for a | |
| # repeated --build-arg key, so appending PY_VER here overrides | |
| # supersetbot's pin and keeps the build on the Dockerfile's own | |
| # supported Python version. | |
| for attempt in 1 2 3; do | |
| if supersetbot docker \ | |
| $PUSH_OR_LOAD \ | |
| --preset "$BUILD_PRESET" \ | |
| --context "$EVENT" \ | |
| --context-ref "$RELEASE" $FORCE_LATEST \ | |
| --extra-flags "--build-arg PY_VER=3.11.14-slim-trixie --build-arg INCLUDE_CHROMIUM=false --tag $IMAGE_TAG" \ | |
| $PLATFORM_ARG; then | |
| break | |
| fi | |
| if [ "$attempt" -eq 3 ]; then | |
| echo "::error::supersetbot docker build failed after 3 attempts" | |
| exit 1 | |
| fi | |
| echo "::warning::Build attempt ${attempt} failed; retrying in 30s..." | |
| sleep 30 | |
| done | |
| # in the context of push (using multi-platform build), we need to pull the image locally | |
| - name: Docker pull | |
| if: github.event_name == 'push' | |
| run: | | |
| for i in 1 2 3; do | |
| docker pull $IMAGE_TAG && break | |
| [ $i -lt 3 ] && sleep 30 | |
| done | |
| - name: Print docker stats | |
| run: | | |
| echo "SHA: ${{ github.sha }}" | |
| echo "IMAGE: $IMAGE_TAG" | |
| docker images $IMAGE_TAG | |
| docker history $IMAGE_TAG | |
| - name: docker-compose sanity check | |
| if: matrix.build_preset == 'dev' | |
| shell: bash | |
| env: | |
| BUILD_PRESET: ${{ matrix.build_preset }} | |
| run: | | |
| export SUPERSET_BUILD_TARGET=$BUILD_PRESET | |
| # This should reuse the CACHED image built in the previous steps | |
| docker compose build superset-init --build-arg DEV_MODE=false --build-arg INCLUDE_CHROMIUM=false | |
| docker compose up superset-init --exit-code-from superset-init | |
| docker-compose-image-tag: | |
| # Run this job only on pushes to master (not for PRs) | |
| # goal is to check that building the latest image works, not required for all PR pushes | |
| needs: changes | |
| if: github.event_name == 'push' && github.ref == 'refs/heads/master' && needs.changes.outputs.docker == 'true' | |
| runs-on: ubuntu-26.04 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: "Checkout ${{ github.ref }} ( ${{ github.sha }} )" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Free up disk space | |
| shell: bash | |
| run: | | |
| # The sanity check rebuilds the image from scratch whenever the | |
| # registry cache image apache/superset-cache is unavailable, which | |
| # can exhaust the runner's root disk ("no space left on device"). | |
| echo "Disk before cleanup:"; df -h / | |
| sudo rm -rf \ | |
| /usr/share/dotnet \ | |
| /usr/local/lib/android \ | |
| /opt/ghc \ | |
| /usr/local/.ghcup \ | |
| /opt/hostedtoolcache/CodeQL \ | |
| /usr/local/share/boost || true | |
| echo "Disk after cleanup:"; df -h / | |
| - name: Setup Docker Environment | |
| uses: ./.github/actions/setup-docker | |
| with: | |
| dockerhub-user: ${{ secrets.DOCKERHUB_USER }} | |
| dockerhub-token: ${{ secrets.DOCKERHUB_TOKEN }} | |
| build: "false" | |
| install-docker-compose: "true" | |
| - name: docker-compose sanity check | |
| shell: bash | |
| run: | | |
| docker compose -f docker-compose-image-tag.yml up superset-init --exit-code-from superset-init | |
| actions-timeline: | |
| needs: [docker-build, docker-compose-image-tag] | |
| if: always() | |
| runs-on: ubuntu-26.04 | |
| permissions: | |
| actions: read | |
| steps: | |
| - uses: Kesin11/actions-timeline@57fc93f20c6da7fbc14063c6d24a2a5627c799ad # v3.2.0 | |
| with: | |
| expand-composite-actions: true |