Don't mistake a refetched repo for an externally modified one (#31108)

### Description

After `bazel fetch --force` (or any other command that refetches a repo without loading its packages), the next `bazel build` warned that a file of the repo "has been modified externally" and fetched the repo a second time.

The check for external modifications of repo files scanned all `FileStateValue` nodes in the graph via `MemoizingEvaluator#getValues()`, which also returns the last values of nodes that are already dirty. Refetching a repo re-evaluates its `RepositoryDirectoryValue`, which is not comparable and thus dirties the file state nodes of all files in the repo. A build re-evaluates these nodes when it loads the affected packages, but `fetch` doesn't request them and, unlike `BuildTool`, also doesn't delete dirty nodes at the end of the command. The stale nodes then survived until the next build, where the `ExternalDirtinessChecker` compared their old contents proxies with the rewritten files, reported an external modification and deleted the marker file to force another fetch.

Only scan nodes that are done: dirty nodes are re-evaluated when they are next requested anyway, so their last values can't be used to detect changes that Skyframe doesn't already know about.

### Motivation

Every `bazel fetch --force` was followed by a second fetch of the same repos in the next build, together with a misleading warning about external modifications.

### Build API Changes

No

### Release Notes

RELNOTES: `bazel fetch --force` no longer causes the fetched repos to be fetched again by the next build with a spurious warning about external modifications.

Closes #31108

COPYBARA_INTEGRATE_REVIEW=https://github.com/bazelbuild/bazel/pull/31108 from fmeum:fix-stale-external-repo-file-check 739a90bd6f1b0d3d1d9f2ad88078fca2762fe2bf
PiperOrigin-RevId: 981245657
Change-Id: I98bc3c1162e55361ca435823c749f25759a0469f
2 files changed
tree: 1d7ab6dad754c1bf0fd4d02ad185225de1723d8e
  1. .bazelci/
  2. .devcontainer/
  3. .gemini/
  4. .github/
  5. docs/
  6. examples/
  7. scripts/
  8. src/
  9. third_party/
  10. tools/
  11. .bazelrc
  12. .bazelversion
  13. .gitattributes
  14. .gitignore
  15. AGENTS.md
  16. AUTHORS
  17. bazel_downloader.cfg
  18. BUILD
  19. CHANGELOG.md
  20. CODE_OF_CONDUCT.md
  21. CODEOWNERS
  22. combine_distfiles.py
  23. combine_distfiles_to_tar.sh
  24. compile.sh
  25. CONTRIBUTING.md
  26. CONTRIBUTORS
  27. distdir.bzl
  28. extensions.bzl
  29. LICENSE
  30. maven_install.json
  31. MODULE.bazel
  32. MODULE.bazel.lock
  33. oneversion_allowlist.csv
  34. oneversion_allowlist_for_tests.csv
  35. pyproject.toml
  36. README.md
  37. repositories.bzl
  38. requirements.txt
  39. SECURITY.md
  40. verify_module_bazel_lock.sh
README.md

Bazel

{Fast, Correct} - Choose two

Build and test software of any size, quickly and reliably.

  • Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.

  • One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.

  • Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.

  • Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.

Getting Started

Documentation

Reporting a Vulnerability

To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.

Contributing to Bazel

See CONTRIBUTING.md

Build status