fix(docker): the storage node images run the real-code guard - #1047
Merged
Merged
Conversation
Main's Docker job has been red since #1045: every crate's build script now runs scripts/real_code_guard.py through python3. - ci/docker/StorageNode.Dockerfile installs python3 (the image copies the whole workspace, so the guard has everything else). - dsm_storage_node/Dockerfile.cloud, the image deploy/push_and_start.sh builds, could not find the guard at all: it copied selected folders and built against stand-ins (fn main(){} crates, invented manifests for tools that no longer exist, empty lib.rs files) behind a cargo build whose failure was thrown away (2>/dev/null || true). Its builder now installs python3, copies the whole workspace as the CI image does, and builds --locked on rust:1.98, the pinned toolchain. The runtime stage is unchanged. Both images build locally and their binaries answer --help. Gemini (gate round 1) was satisfied.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Main's Docker job is red, and the deploy image cannot build
Since #1045 every crate's build script runs
scripts/real_code_guard.pythroughpython3. Reproduced locally on main:ci/docker/StorageNode.Dockerfile(CI's Docker job)real-code guard: python3 could not run: No such file or directorydsm_storage_node/Dockerfile.cloud(whatdeploy/push_and_start.shbuilds)couldn't read .../scripts/real_code_guard_build.rs: the image never copies the guardThe fix
python3. It already copies the whole workspace, so the guard has its script, its baseline and the files its wiring check reads.fn main(){}crates and invented manifests fortools/vector_runnerandtools/vector_builder(which no longer exist) andtools/vertical_validation, emptylib.rsfiles, and acargo build … 2>/dev/null || truewhose failure was thrown away. It now installspython3, copies the whole workspace as the CI image does (.dockerignorekeeps outtarget/,node_modules/,.git/), and builds--lockedonrust:1.98-slim-bookworm, the pinned toolchain. The runtime stage is unchanged. The cost: no dependency-only cache layer, so a deploy rebuild compiles the dependencies again.Verification
--help).Not changed, found on the way
dsm_client/frontend/Dockerfilerunsnpm ci --only=productionand thennpm run ci, which needs dev dependencies (TypeScript, ESLint, Jest, webpack), and Alpine has nopython3for the guard. Nothing in CI or the deploy scripts builds it.dsm_client/deterministic_state_machine/dsm/Dockerfilebuilds--bin dsm --bin cli --bin serverfrom a crate that is a library only. Nothing builds it either..git), so inside an image it checks the scan and the wiring only. The guard is the owner's to change.