fix: the ml artifact was in a second list I never grepped for (4311)
CI / lint (push) Successful in 3s
CI / extension-version (push) Successful in 3s
extension / lint (push) Successful in 18s
CI / frontend-build (push) Successful in 24s
CI / backend-lint-and-test (push) Successful in 32s
Build images / sign-extension (push) Successful in 2s
Build images / build-agent (push) Successful in 5s
Build images / build-web (push) Successful in 5s
Build images / smoke-web (push) Successful in 26s
Build images / promote (push) Skipped
CI / integration (push) Successful in 2m11s
CI / lint (push) Successful in 3s
CI / extension-version (push) Successful in 3s
extension / lint (push) Successful in 18s
CI / frontend-build (push) Successful in 24s
CI / backend-lint-and-test (push) Successful in 32s
Build images / sign-extension (push) Successful in 2s
Build images / build-agent (push) Successful in 5s
Build images / build-web (push) Successful in 5s
Build images / smoke-web (push) Successful in 26s
Build images / promote (push) Skipped
CI / integration (push) Successful in 2m11s
ac70f2a removed the `ml` image but CI went red on six tests:
`tests/test_artifact_identity.py` parametrises over its own
`ARTIFACTS = ("web", "ml", "agent", "extension")`, and every case now hits
the dispatch guard that same commit added.
My miss, and a specific one. I grepped for `fabledcurator-ml` and `ML_PATHS`
and called the survey done — but the artifact is also named as a bare `"ml"`,
which neither pattern finds. Rule 90 (grep pinned tests when changing a
shared symbol) was surfaced to me while I was making the change and I ran a
narrower sweep than it asks for. Lesson #4275 names the shape exactly: an
absence claim is only as good as the search behind it, and a grep that
matched nothing looks identical to a grep that asked the wrong question.
The re-run was done by value, not by name: every occurrence of a bare `ml` in
the repo, then filtering. That distinguishes the two things the token means —
the celery LANE `ml` and the `backend/app/services/ml` package both stay and
account for nearly every hit; only the IMAGE name went. Worth stating in the
test, since the next person to grep will hit the same ambiguity.
Also swept the prose the first pass left describing the old pipeline: "Four
artifacts" (README, ci-requirements), "leaves web and ml alone" (×5 in
build.yml, plus both docs), "CI publishes it alongside the web/ml images"
(agent/README). The run 4896 build-time measurements keep their `ml` number —
that was measured when ml was a real build — with a note saying the name has
since gone.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LVjrnpQjRgHdvq95rASoiR
This commit is contained in:
@@ -277,8 +277,8 @@ jobs:
|
||||
# build — no `set -e`, and every derivation falls back to UNAVAILABLE.
|
||||
#
|
||||
# What to watch across pushes, because this is what step 3 will trust:
|
||||
# * a push touching only agent/ moves the agent and leaves web and ml
|
||||
# STILL. If web moves, its path set is too wide.
|
||||
# * a push touching only agent/ moves the agent and leaves web STILL.
|
||||
# If web moves, its path set is too wide.
|
||||
# * a push touching only docs moves nothing.
|
||||
# * a push touching the extension moves the extension AND web, since
|
||||
# web bakes in the XPI. If web does not move, its set is too narrow:
|
||||
@@ -561,8 +561,8 @@ jobs:
|
||||
# never be the reason an image does not ship.
|
||||
#
|
||||
# What it should say:
|
||||
# * a push touching only agent/ moves the agent and leaves web and ml
|
||||
# STILL. If web moves, its path set is too wide.
|
||||
# * a push touching only agent/ moves the agent and leaves web STILL.
|
||||
# If web moves, its path set is too wide.
|
||||
# * a push touching only docs moves nothing.
|
||||
# * a push touching the extension moves the extension AND web, since
|
||||
# web bakes in the XPI. If web does not move, its set is too narrow:
|
||||
@@ -709,7 +709,7 @@ jobs:
|
||||
# Each artifact pays one rebuild, once.
|
||||
#
|
||||
# This is what stops a push that touched only `agent/` from rebuilding
|
||||
# web and ml, and a merge to main from rebuilding what dev already built.
|
||||
# web, and a merge to main from rebuilding what dev already built.
|
||||
#
|
||||
# The failure direction is deliberate. An inspect that errors for ANY
|
||||
# reason — network, auth, a registry hiccup — reads as a miss and the
|
||||
@@ -1665,8 +1665,8 @@ jobs:
|
||||
# never be the reason an image does not ship.
|
||||
#
|
||||
# What it should say:
|
||||
# * a push touching only agent/ moves the agent and leaves web and ml
|
||||
# STILL. If web moves, its path set is too wide.
|
||||
# * a push touching only agent/ moves the agent and leaves web STILL.
|
||||
# If web moves, its path set is too wide.
|
||||
# * a push touching only docs moves nothing.
|
||||
# * a push touching the extension moves the extension AND web, since
|
||||
# web bakes in the XPI. If web does not move, its set is too narrow:
|
||||
@@ -1751,7 +1751,7 @@ jobs:
|
||||
# Each artifact pays one rebuild, once.
|
||||
#
|
||||
# This is what stops a push that touched only `agent/` from rebuilding
|
||||
# web and ml, and a merge to main from rebuilding what dev already built.
|
||||
# web, and a merge to main from rebuilding what dev already built.
|
||||
#
|
||||
# The failure direction is deliberate. An inspect that errors for ANY
|
||||
# reason — network, auth, a registry hiccup — reads as a miss and the
|
||||
|
||||
@@ -245,9 +245,9 @@ reasoning is note #3127 §5). Rolling back is `docker pull …:c-<sha>`.
|
||||
|
||||
Each artifact still has a version, derived rather than chosen: the commit time
|
||||
of the newest change to that artifact's *own* shipped files, as
|
||||
`YYYY.MM.DD.HHMM` UTC (rule 148). Four artifacts, four independent versions —
|
||||
a push touching only `agent/` re-versions the agent and leaves web and ml
|
||||
alone, and CI skips the builds whose content did not move.
|
||||
`YYYY.MM.DD.HHMM` UTC (rule 148). Three artifacts, three independent versions
|
||||
— a push touching only `agent/` re-versions the agent and leaves web and the
|
||||
extension alone, and CI skips the builds whose content did not move.
|
||||
|
||||
Because no registry name carries it, the running instance's own report is the
|
||||
only answer to "which build is this?". The foot of Settings shows
|
||||
|
||||
+1
-1
@@ -21,7 +21,7 @@ docker run --rm --gpus all nvidia/cuda:12.4.1-base-ubuntu22.04 nvidia-smi
|
||||
## 1. Get a token
|
||||
In FC: **Settings → Tagging → GPU agent → Generate token** (or Rotate). Copy it.
|
||||
|
||||
## 2. Pull (CI publishes it alongside the web/ml images)
|
||||
## 2. Pull (CI publishes it alongside the web image)
|
||||
```sh
|
||||
docker pull git.fabledsword.com/bvandeusen/fabledcurator-agent:latest
|
||||
```
|
||||
|
||||
+4
-3
@@ -99,8 +99,8 @@ per `docs/process.md`'s "add deps to the image when used by >1 project".
|
||||
- **`scripts/artifacts.sh` is the same shape one level up: one definition per
|
||||
artifact of what it is built from, and the two values derived from it.**
|
||||
`revision` (12 hex of the newest commit touching that set) and `version`
|
||||
(`YYYY.MM.DD.HHMM` UTC, rule 148). Four artifacts, four independent answers,
|
||||
so a push touching only `agent/` leaves web and ml alone.
|
||||
(`YYYY.MM.DD.HHMM` UTC, rule 148). Three artifacts, three independent
|
||||
answers, so a push touching only `agent/` leaves web and the extension alone.
|
||||
`tests/test_artifact_paths.py` reads each Dockerfile and asserts every COPY
|
||||
source is covered, so adding a COPY without updating the script fails CI.
|
||||
- **A file that DECIDES an artifact's identity belongs in its set even though it
|
||||
@@ -153,7 +153,8 @@ per `docs/process.md`'s "add deps to the image when used by >1 project".
|
||||
layer store at all**, where the old `docker` driver at least reused whatever
|
||||
the runner's dockerd happened to hold. Measured on run 4896, the first builds
|
||||
after the driver moved: web 3m44s (was 2m23s), ml 3m49s (was 3m20s), agent
|
||||
11m12s (was 9m26s) — every one slower. A `:buildcache` tag is read by every
|
||||
11m12s (was 9m26s) — every one slower. (`ml` was its own build then; #4311
|
||||
retired it once it became the same bytes as web under a second name.) A `:buildcache` tag is read by every
|
||||
build that runs, is one moving ref per image, holds cache blobs rather than a
|
||||
shippable artifact, and is overwritten in place, so it is not a return of the
|
||||
per-version tags milestone 318 withdrew (#3114).
|
||||
|
||||
@@ -58,7 +58,12 @@ import pytest
|
||||
|
||||
ROOT = Path(__file__).resolve().parent.parent
|
||||
|
||||
ARTIFACTS = ("web", "ml", "agent", "extension")
|
||||
# `ml` was here until #4311. It was never a separate artifact — the same
|
||||
# Dockerfile and context as `web`, published under a second image name — and
|
||||
# the name is gone now that the stack referencing it is collapsing onto the
|
||||
# consolidated image. The celery LANE called `ml` is a different thing and
|
||||
# stays; only the image name went.
|
||||
ARTIFACTS = ("web", "agent", "extension")
|
||||
|
||||
# 12 hex chars — the prefix build.yml stamps and compares.
|
||||
_REVISION = re.compile(r"^[0-9a-f]{12}$")
|
||||
|
||||
Reference in New Issue
Block a user