Skip to content

fix(docker): the storage node images run the real-code guard - #1047

Merged
cryptskii merged 1 commit into
mainfrom
fix/docker-builds-run-the-guard
Sep 28, 2026
Merged

cryptskii merged 1 commit into
mainfrom
fix/docker-builds-run-the-guard

Conversation

@cryptskii

Copy link
Copy Markdown
Collaborator

Main's Docker job is red, and the deploy image cannot build

Since #1045 every crate's build script runs scripts/real_code_guard.py through python3. Reproduced locally on main:

Image Failure on main
ci/docker/StorageNode.Dockerfile (CI's Docker job) real-code guard: python3 could not run: No such file or directory
dsm_storage_node/Dockerfile.cloud (what deploy/push_and_start.sh builds) couldn't read .../scripts/real_code_guard_build.rs: the image never copies the guard

The fix

  • CI image: installs python3. It already copies the whole workspace, so the guard has its script, its baseline and the files its wiring check reads.
  • Deploy image: the builder stage copied selected folders and built against stand-ins: fn main(){} crates and invented manifests for tools/vector_runner and tools/vector_builder (which no longer exist) and tools/vertical_validation, empty lib.rs files, and a cargo build … 2>/dev/null || true whose failure was thrown away. It now installs python3, copies the whole workspace as the CI image does (.dockerignore keeps out target/, node_modules/, .git/), and builds --locked on rust:1.98-slim-bookworm, the pinned toolchain. The runtime stage is unchanged. The cost: no dependency-only cache layer, so a deploy rebuild compiles the dependencies again.

Verification

  • Both images build locally with Docker 29.8: CI image in 72 s, deploy image in 116 s (release build finished; the guard ran inside every build script).
  • Both built binaries run and print their usage (--help).
  • Gemini (the review gate, round 1): satisfied on every dimension.

Not changed, found on the way

  • dsm_client/frontend/Dockerfile runs npm ci --only=production and then npm run ci, which needs dev dependencies (TypeScript, ESLint, Jest, webpack), and Alpine has no python3 for the guard. Nothing in CI or the deploy scripts builds it.
  • dsm_client/deterministic_state_machine/dsm/Dockerfile builds --bin dsm --bin cli --bin server from a crate that is a library only. Nothing builds it either.
  • The guard skips its comparison against main when git history is absent (a Docker context has no .git), so inside an image it checks the scan and the wiring only. The guard is the owner's to change.

Main's Docker job has been red since #1045: every crate's build script now runs
scripts/real_code_guard.py through python3.

- ci/docker/StorageNode.Dockerfile installs python3 (the image copies the whole
  workspace, so the guard has everything else).
- dsm_storage_node/Dockerfile.cloud, the image deploy/push_and_start.sh builds,
  could not find the guard at all: it copied selected folders and built against
  stand-ins (fn main(){} crates, invented manifests for tools that no longer
  exist, empty lib.rs files) behind a cargo build whose failure was thrown away
  (2>/dev/null || true). Its builder now installs python3, copies the whole
  workspace as the CI image does, and builds --locked on rust:1.98, the pinned
  toolchain. The runtime stage is unchanged.

Both images build locally and their binaries answer --help. Gemini (gate round
1) was satisfied.
@cryptskii
cryptskii merged commit 30bdac7 into main Sep 28, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant