From acda59fc737bc8c8383105ca844622da87ced427 Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Wed, 7 Oct 2026 23:17:10 -0400 Subject: [PATCH] ci: integration finds only its own service containers The runner's docker daemon is shared, so `--filter name= | head -n1` can pick another repo's Postgres when two jobs run side by side (Steward run 8358, Inkwell run 8653). Scope the lookup to this job's own task prefix and require exactly one match. Done from Inkwell #5313 with the operator's permission; the recipe is rule 79. Co-Authored-By: Claude Opus 5.5 --- .forgejo/workflows/ci.yml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index 56904b47..d86579ba 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -296,8 +296,18 @@ jobs: set -eux echo "=== container landscape (diagnostic for the name filter) ===" docker ps -a --format '{{.ID}} {{.Image}} -> {{.Names}}' - PG=$(docker ps --filter "name=integration" --filter "ancestor=pgvector/pgvector:pg17" -q | head -n1) - test -n "$PG" + # Only THIS job's services. The runner's docker daemon is shared, so another + # repo's job can be running beside this one, and a job-name filter matches its + # containers too (Steward run 8358 and Inkwell run 8653 each took another repo's + # Postgres). act names every container of a task GITEA-ACTIONS-TASK--...: read + # from our own container (its id is in the /etc/hostname bind mount) and + # require exactly one match. + SELF=$(grep -o '/containers/[0-9a-f]\{64\}/' /proc/self/mountinfo | head -n1 | cut -d/ -f3 || true) + SELF=${SELF:-$(hostname)} + TASK=$(docker inspect -f '{{.Name}}' "$SELF" | grep -o 'GITEA-ACTIONS-TASK-[0-9]*-') + test -n "$TASK" + PG=$(docker ps --filter "name=$TASK" --filter "ancestor=pgvector/pgvector:pg17" -q) + test "$(printf '%s\n' "$PG" | grep -c .)" -eq 1 PG_IP=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$PG") test -n "$PG_IP" export DATABASE_URL="postgresql+asyncpg://scribe:ci_integration@${PG_IP}:5432/scribe_test"