From 3c3045190dadaf51de152d84630767209c17f56a Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Wed, 7 Oct 2026 23:17:10 -0400 Subject: [PATCH] ci: integration finds only its own service containers The runner's docker daemon is shared, so `--filter name= | head -n1` can pick another repo's Postgres when two jobs run side by side (Steward run 8358, Inkwell run 8653). Scope the lookup to this job's own task prefix and require exactly one match. Done from Inkwell #5313 with the operator's permission; the recipe is rule 79. Co-Authored-By: Claude Opus 5.5 --- .forgejo/workflows/baseline.yml | 14 ++++++++++++-- .forgejo/workflows/build.yml | 34 +++++++++++++++++++++++++++------ 2 files changed, 40 insertions(+), 8 deletions(-) diff --git a/.forgejo/workflows/baseline.yml b/.forgejo/workflows/baseline.yml index f56f4ba..5835341 100644 --- a/.forgejo/workflows/baseline.yml +++ b/.forgejo/workflows/baseline.yml @@ -81,8 +81,18 @@ jobs: set -eux # Same service-IP dance as build.yml's integration job; see the long # comment there for why the job name must stay separator-free. - PG=$(docker ps --filter "name=compare" --filter "ancestor=pgvector/pgvector:pg16" -q | head -n1) - test -n "$PG" + # Only THIS job's services. The runner's docker daemon is shared, so another + # repo's job can be running beside this one, and a job-name filter matches its + # containers too (Steward run 8358 and Inkwell run 8653 each took another repo's + # Postgres). act names every container of a task GITEA-ACTIONS-TASK--...: read + # from our own container (its id is in the /etc/hostname bind mount) and + # require exactly one match. + SELF=$(grep -o '/containers/[0-9a-f]\{64\}/' /proc/self/mountinfo | head -n1 | cut -d/ -f3 || true) + SELF=${SELF:-$(hostname)} + TASK=$(docker inspect -f '{{.Name}}' "$SELF" | grep -o 'GITEA-ACTIONS-TASK-[0-9]*-') + test -n "$TASK" + PG=$(docker ps --filter "name=$TASK" --filter "ancestor=pgvector/pgvector:pg16" -q) + test "$(printf '%s\n' "$PG" | grep -c .)" -eq 1 PG_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$PG") test -n "$PG_IP" echo "PG_CONTAINER=$PG" >> "$GITHUB_ENV" diff --git a/.forgejo/workflows/build.yml b/.forgejo/workflows/build.yml index 2dab36a..8538bb3 100644 --- a/.forgejo/workflows/build.yml +++ b/.forgejo/workflows/build.yml @@ -532,9 +532,20 @@ jobs: echo "=== container landscape (diagnostic for filter scoping) ===" docker ps -a --format '{{.ID}} {{.Image}} -> {{.Names}}' echo "=== end landscape ===" - PG=$(docker ps --filter "name=integration" --filter "ancestor=pgvector/pgvector:pg16" -q | head -n1) - RD=$(docker ps --filter "name=integration" --filter "ancestor=redis:8-alpine" -q | head -n1) - test -n "$PG" && test -n "$RD" + # Only THIS job's services. The runner's docker daemon is shared, so another + # repo's job can be running beside this one, and a job-name filter matches its + # containers too (Steward run 8358 and Inkwell run 8653 each took another repo's + # Postgres). act names every container of a task GITEA-ACTIONS-TASK--...: read + # from our own container (its id is in the /etc/hostname bind mount) and + # require exactly one match. + SELF=$(grep -o '/containers/[0-9a-f]\{64\}/' /proc/self/mountinfo | head -n1 | cut -d/ -f3 || true) + SELF=${SELF:-$(hostname)} + TASK=$(docker inspect -f '{{.Name}}' "$SELF" | grep -o 'GITEA-ACTIONS-TASK-[0-9]*-') + test -n "$TASK" + PG=$(docker ps --filter "name=$TASK" --filter "ancestor=pgvector/pgvector:pg16" -q) + test "$(printf '%s\n' "$PG" | grep -c .)" -eq 1 + RD=$(docker ps --filter "name=$TASK" --filter "ancestor=redis:8-alpine" -q) + test "$(printf '%s\n' "$RD" | grep -c .)" -eq 1 PG_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$PG") RD_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$RD") test -n "$PG_IP" && test -n "$RD_IP" @@ -1718,9 +1729,20 @@ jobs: # Service discovery mirrors the integration lane above: these jobs run # in a container against a mounted docker socket, so the services are # SIBLINGS reachable by IP, not by hostname. - PG=$(docker ps --filter "name=smoke" --filter "ancestor=pgvector/pgvector:pg16" -q | head -n1) - RD=$(docker ps --filter "name=smoke" --filter "ancestor=redis:8-alpine" -q | head -n1) - test -n "$PG" && test -n "$RD" + # Only THIS job's services. The runner's docker daemon is shared, so another + # repo's job can be running beside this one, and a job-name filter matches its + # containers too (Steward run 8358 and Inkwell run 8653 each took another repo's + # Postgres). act names every container of a task GITEA-ACTIONS-TASK--...: read + # from our own container (its id is in the /etc/hostname bind mount) and + # require exactly one match. + SELF=$(grep -o '/containers/[0-9a-f]\{64\}/' /proc/self/mountinfo | head -n1 | cut -d/ -f3 || true) + SELF=${SELF:-$(hostname)} + TASK=$(docker inspect -f '{{.Name}}' "$SELF" | grep -o 'GITEA-ACTIONS-TASK-[0-9]*-') + test -n "$TASK" + PG=$(docker ps --filter "name=$TASK" --filter "ancestor=pgvector/pgvector:pg16" -q) + test "$(printf '%s\n' "$PG" | grep -c .)" -eq 1 + RD=$(docker ps --filter "name=$TASK" --filter "ancestor=redis:8-alpine" -q) + test "$(printf '%s\n' "$RD" | grep -c .)" -eq 1 PG_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$PG") RD_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$RD") test -n "$PG_IP" && test -n "$RD_IP"