cibuild: the org model, which runs every check uncached (closes #37) #72

Merged
clawbot merged 1 commits from fix/cibuild-no-cache into next 2026-09-29 11:55:52 +02:00
Collaborator

script/cibuild was a plain docker build ., so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is now https://git.eeqj.de/sneak/prompts/raw/branch/main/script/cibuild byte for byte, as script/docker already is: script/bootstrap, script/check on the host, then docker build --no-cache tagged netwatch with the git describe version as the VERSION build argument.

For that step to pass on the Gitea runner, which has node 18 and neither yarn nor Go:

  • .gitea/workflows/check.yml runs it with ~/.local/bin on PATH, where script/bootstrap links what it installs.
  • script/bootstrap installs its pinned node when the installed one is older than NODE_MIN_VERSION, 22.12.0, taken from the engines field of puppeteer-core, the most demanding frontend dependency, as it already did for Go against backend/go.mod.

What the diff does not show:

  • The Dockerfile is unchanged: its builder stage already declares ARG VERSION=dev.
  • #16 landed first (#38); with one image, this covers frontend and backend.
  • Judgement call, as the issue asks: blanket --no-cache, because the org model prescribes it. Dependency layers are rebuilt and every check runs twice per CI run, on the host and in the image.
  • On the runner, node 18's corepack adds a packageManager field to package.json during bootstrap, so the CI image's version ends in -dirty. That image is never published.
  • Deviation: REPO_POLICIES.md still says bootstrap uses any installed node and that script/cibuild runs docker build .; this repo's copy of the org file is unchanged.

Model: opus-5-5

`script/cibuild` was a plain `docker build .`, so on a tree Docker had seen before every check step came from the build cache and the build still passed. It is now `https://git.eeqj.de/sneak/prompts/raw/branch/main/script/cibuild` byte for byte, as `script/docker` already is: `script/bootstrap`, `script/check` on the host, then `docker build --no-cache` tagged `netwatch` with the `git describe` version as the `VERSION` build argument. For that step to pass on the Gitea runner, which has node 18 and neither yarn nor Go: - `.gitea/workflows/check.yml` runs it with `~/.local/bin` on `PATH`, where `script/bootstrap` links what it installs. - `script/bootstrap` installs its pinned node when the installed one is older than `NODE_MIN_VERSION`, 22.12.0, taken from the `engines` field of `puppeteer-core`, the most demanding frontend dependency, as it already did for Go against `backend/go.mod`. What the diff does not show: - The `Dockerfile` is unchanged: its builder stage already declares `ARG VERSION=dev`. - https://git.eeqj.de/sneak/netwatch/issues/16 landed first (https://git.eeqj.de/sneak/netwatch/pulls/38); with one image, this covers frontend and backend. - Judgement call, as the issue asks: blanket `--no-cache`, because the org model prescribes it. Dependency layers are rebuilt and every check runs twice per CI run, on the host and in the image. - On the runner, node 18's corepack adds a `packageManager` field to `package.json` during bootstrap, so the CI image's version ends in `-dirty`. That image is never published. - Deviation: `REPO_POLICIES.md` still says bootstrap uses any installed node and that `script/cibuild` runs `docker build .`; this repo's copy of the org file is unchanged. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 10:35:32 +02:00
clawbot self-assigned this 2026-09-29 10:35:32 +02:00
Author
Collaborator
  1. The workflow's only build step fails on this Gitea's runner (.gitea/workflows/check.yml together with script/bootstrap). The runner image has node but neither yarn nor Go. script/bootstrap installs both and links them into ~/.local/bin, which is not on the job's PATH, so the script/check that script/cibuild runs next cannot find yarn. The same happens on a runner with nothing installed, where bootstrap links node there as well. Acceptable: the script/cibuild step passes on the runner while script/cibuild stays byte-identical to the model, for example because the workflow puts $HOME/.local/bin on the job's PATH before that step.
  2. script/bootstrap (ensure_node) keeps whatever node is already installed, whatever its version. The runner that picks up this workflow's ubuntu-latest jobs has node 18, so yarn install --frozen-lockfile stops bootstrap: puppeteer-core needs node 22.12 or newer. Acceptable: the step passes on that runner, for example because script/bootstrap installs its pinned node when the installed one is older than the frontend's dependencies need, as it already does for Go against backend/go.mod.

Judgement call: REPO_POLICIES.md has bootstrap use an installed node if one is present; I read the plan's requirement that the step pass on the runner as covering an installed node too old to run the install.

Model: opus-5-5

1. The workflow's only build step fails on this Gitea's runner (`.gitea/workflows/check.yml` together with `script/bootstrap`). The runner image has node but neither yarn nor Go. `script/bootstrap` installs both and links them into `~/.local/bin`, which is not on the job's `PATH`, so the `script/check` that `script/cibuild` runs next cannot find `yarn`. The same happens on a runner with nothing installed, where bootstrap links node there as well. Acceptable: the `script/cibuild` step passes on the runner while `script/cibuild` stays byte-identical to the model, for example because the workflow puts `$HOME/.local/bin` on the job's `PATH` before that step. 2. `script/bootstrap` (`ensure_node`) keeps whatever node is already installed, whatever its version. The runner that picks up this workflow's `ubuntu-latest` jobs has node 18, so `yarn install --frozen-lockfile` stops bootstrap: `puppeteer-core` needs node 22.12 or newer. Acceptable: the step passes on that runner, for example because `script/bootstrap` installs its pinned node when the installed one is older than the frontend's dependencies need, as it already does for Go against `backend/go.mod`. Judgement call: `REPO_POLICIES.md` has bootstrap use an installed node if one is present; I read the plan's requirement that the step pass on the runner as covering an installed node too old to run the install. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 11:00:43 +02:00
clawbot added 1 commit 2026-09-29 11:26:38 +02:00
script/cibuild was a plain docker build ., so on a tree Docker had
seen before every check step came from the build cache and the build
still passed. It is now the org model from sneak/prompts, byte for
byte: script/bootstrap, script/check, then docker build --no-cache
with the git describe version as the VERSION build argument.

The workflow puts ~/.local/bin, where bootstrap links what it
installs, on the step's PATH. Bootstrap now installs its pinned node
when the installed one is older than 22.12.0, the oldest the
frontend's dependencies accept (puppeteer-core's engines field), as
it already does for Go against backend/go.mod.

Model: opus-5-5
clawbot force-pushed fix/cibuild-no-cache from 994c83334a to a9c647a13b 2026-09-29 11:26:38 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-29 11:26:52 +02:00
Author
Collaborator

Rework:

  1. Fixed in .gitea/workflows/check.yml: the step runs script/cibuild with $HOME/.local/bin on PATH; script/cibuild is still byte-identical to the model.
  2. Fixed in script/bootstrap: ensure_node installs the pinned node unless the installed one is at least NODE_MIN_VERSION, which is stated once, next to the pinned versions, with where it comes from.

Model: opus-5-5

Rework: 1. Fixed in `.gitea/workflows/check.yml`: the step runs `script/cibuild` with `$HOME/.local/bin` on `PATH`; `script/cibuild` is still byte-identical to the model. 2. Fixed in `script/bootstrap`: `ensure_node` installs the pinned node unless the installed one is at least `NODE_MIN_VERSION`, which is stated once, next to the pinned versions, with where it comes from. Model: opus-5-5
Author
Collaborator

PASS: both earlier findings are fixed: the workflow step finds what script/bootstrap links into ~/.local/bin, script/bootstrap replaces an installed node older than the frontend's dependencies accept, and script/cibuild stays byte-identical to the org model.

Model: opus-5-5

PASS: both earlier findings are fixed: the workflow step finds what `script/bootstrap` links into `~/.local/bin`, `script/bootstrap` replaces an installed node older than the frontend's dependencies accept, and `script/cibuild` stays byte-identical to the org model. Model: opus-5-5
clawbot merged commit f423768975 into next 2026-09-29 11:55:52 +02:00
clawbot deleted branch fix/cibuild-no-cache 2026-09-29 11:55:53 +02:00
clawbot removed the needs-review label 2026-09-29 11:55:53 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#72