mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-18 19:02:18 +02:00
fix(ci-image): the dependency layer carries patches/ — bun install needs the patch files the lock declares
bun.lock's patchedDependencies (playwright-core windowsHide) made 'bun install --frozen-lockfile' fail inside the image build: the Dockerfile copied package.json + bun.lock but not patches/. The image-tag hash in all three workflows (ci-image, evals, evals-periodic — kept in lockstep) now includes patches/** so editing a patch rebuilds the layer instead of serving a stale cache. Verified: the exact COPY set (package.json + bun.lock + patches) installs clean in a Linux container; without patches it reproduces the CI failure. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
415beedfea
commit
fe20340fba
@@ -104,7 +104,12 @@ RUN for i in 1 2 3; do \
|
|||||||
# resolution. Without bun.lock here, bun install resolved transitive deps
|
# resolution. Without bun.lock here, bun install resolved transitive deps
|
||||||
# differently in CI vs local (observed on v1.28.0.0: socks landed but
|
# differently in CI vs local (observed on v1.28.0.0: socks landed but
|
||||||
# smart-buffer + ip-address didn't make it into the cached node_modules).
|
# smart-buffer + ip-address didn't make it into the cached node_modules).
|
||||||
|
# patches/ rides along: bun.lock's patchedDependencies (playwright-core
|
||||||
|
# windowsHide, v1.67) makes install fail without the patch files present —
|
||||||
|
# and the workflows' image-tag hash includes patches/** so editing a patch
|
||||||
|
# rebuilds this layer.
|
||||||
COPY package.json bun.lock /workspace/
|
COPY package.json bun.lock /workspace/
|
||||||
|
COPY patches /workspace/patches
|
||||||
WORKDIR /workspace
|
WORKDIR /workspace
|
||||||
RUN bun install --frozen-lockfile && rm -rf /tmp/*
|
RUN bun install --frozen-lockfile && rm -rf /tmp/*
|
||||||
|
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ jobs:
|
|||||||
# This is the tag the eval matrix looks up first — without pushing it
|
# This is the tag the eval matrix looks up first — without pushing it
|
||||||
# here, the weekly/main prebuild never warms the cache that matters.
|
# here, the weekly/main prebuild never warms the cache that matters.
|
||||||
- id: meta
|
- id: meta
|
||||||
run: echo "tag=ghcr.io/${{ github.repository }}/ci:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock') }}" >> "$GITHUB_OUTPUT"
|
run: echo "tag=ghcr.io/${{ github.repository }}/ci:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock', 'patches/**') }}" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- uses: docker/login-action@v4
|
- uses: docker/login-action@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ jobs:
|
|||||||
- id: meta
|
- id: meta
|
||||||
# Keep in sync with evals.yml — key on Dockerfile + lockfile only
|
# Keep in sync with evals.yml — key on Dockerfile + lockfile only
|
||||||
# (package.json's version field would bust the key on every ship).
|
# (package.json's version field would bust the key on every ship).
|
||||||
run: echo "tag=${{ env.IMAGE }}:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock') }}" >> "$GITHUB_OUTPUT"
|
run: echo "tag=${{ env.IMAGE }}:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock', 'patches/**') }}" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- uses: docker/login-action@v4
|
- uses: docker/login-action@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ jobs:
|
|||||||
# which rebuilt the image each time for a dependency set that only
|
# which rebuilt the image each time for a dependency set that only
|
||||||
# bun.lock determines. A stale baked package.json is harmless — checkout
|
# bun.lock determines. A stale baked package.json is harmless — checkout
|
||||||
# overwrites /workspace and node_modules comes from the lockfile.
|
# overwrites /workspace and node_modules comes from the lockfile.
|
||||||
run: echo "tag=${{ env.IMAGE }}:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock') }}" >> "$GITHUB_OUTPUT"
|
run: echo "tag=${{ env.IMAGE }}:${{ hashFiles('.github/docker/Dockerfile.ci', 'bun.lock', 'patches/**') }}" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- uses: docker/login-action@v4
|
- uses: docker/login-action@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
Reference in New Issue
Block a user