Repository navigation
ci(dev): make the container say which source it was built from (ADR-1195) - #1337
Merged
Merged
Conversation
lusoris
added a commit
that referenced
this pull request
Sep 5, 2026
…ouch gate) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
42 tasks
lusoris
added a commit
that referenced
this pull request
Sep 6, 2026
…ouch gate) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
lusoris
force-pushed
the
ci/container-source-guard
branch
from
September 6, 2026 00:00
7e9936f to
a0df85d
Compare
lusoris
added a commit
that referenced
this pull request
Sep 6, 2026
…ouch gate) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
lusoris
force-pushed
the
ci/container-source-guard
branch
from
September 6, 2026 03:03
a0df85d to
0f8ab06
Compare
…195) CLAUDE.md rule 15 says to rebuild the container when "its image predates the last master sync". That is stated in terms of time, and time cannot answer the question. A build run against a checkout that is behind master produces an image newer than every commit in the repository and missing exactly the work it was rebuilt for. That happened today. The container was rebuilt specifically to pick up the GPU default-model fixes (#1307, #1312, #1324) so the epic #1246 GPU smoke could run against them. The build succeeded, the image was the newest thing on disk, and it contained none of the three: the build context was 28 commits behind origin/master. It was caught only because a test file added by one of those PRs was missing. Had the smoke run instead, it would have reported green numbers for code that was not in the image, and those numbers would have been cited as a retrain gate. ADR-1102's marker answers "did a container build this?". It cannot answer "which code was in that container?", and that second question is the one that was wrong. dev/Containerfile now records /etc/vmafx-dev-source (source_rev, source_ref, source_repo) from a VMAFX_SOURCE_REV build argument supplied by dev/docker-compose.yml. It is written in the LAST stage, deliberately away from the ADR-1102 marker in the first: the first stage is reused by every rebuild, so a marker there would report the revision of whichever build first populated the layer cache -- authoritative and stale, which is worse than absent. scripts/dev/check-container-source.sh answers it in both directions. --pre-build refuses a checkout that is behind the reference and lists the commits under baked-in paths the image would be missing; --image reads the marker out of an existing image and reports current, stale (naming what is missing), or unverifiable. A build that never received the argument records `unknown`, and `unknown` is reported as "cannot verify", not as a pass: an image that cannot say what it holds is not evidence. dev/scripts/container-build.sh makes the correct path the easy one -- check, build with the verified revision, re-verify the result. --allow-behind exists for local experiments and says so loudly. Verified by scripts/ci/tests/test-check-container-source.sh: 8 assertions, hermetic apart from one Docker case that skips when no daemon is reachable. The stale-context case reproduces today's shape; ahead-of-master is deliberately allowed, since a feature branch legitimately leads master. no digest needed: trivial Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ouch gate) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Each dropped row restates one origin/master already carries; master is the authoritative record. Verified with scripts/ci/check-state-md-rows.sh. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
lusoris
force-pushed
the
ci/container-source-guard
branch
from
September 6, 2026 03:34
0f8ab06 to
194d43b
Compare
lusoris
marked this pull request as ready for review
September 6, 2026 03:34
This was referenced Sep 6, 2026
3 of 6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CLAUDE.md rule 15 says to rebuild the dev container when "its image predates the last
mastersync". Time cannot answer that question. A build run against a checkout that is behindmasterproduces an image newer than every commit in the repository and missing exactly the work it was rebuilt for.That happened today, on the path this campaign depends on. The container was rebuilt specifically to pick up the GPU default-model fixes (#1307, #1312, #1324) so the epic #1246 GPU smoke could run against them. The build succeeded and the image was the newest thing on disk. It contained none of the three — the build context was 28 commits behind
origin/master— and it was caught only because a test file added by one of those PRs was missing. Had the smoke run instead, it would have reported green numbers for code that was not in the image, and those numbers would have been cited as a retrain gate.ADR-1102's marker answers "did a container build this?". It cannot answer "which code was in that container?". This adds the second answer.
Type
build/ci— tooling / infraChecklist
make format && make lintis green locally. —pre-commit run --filesclean on all 15 touched files;shellcheckclean on both new scripts;actionlintclean onrule-enforcement.yml.bash scripts/ci/tests/test-check-container-source.sh: 8/8 assertions, output pasted under "Reproducer"./cross-backend-diffand the worst ULP is ≤ 2. — no SIMD or GPU code path is touched..c/.cpp/.cu/.h/.hpp, it has the appropriate license header. — no C/C++ source is added; the new files are two shell scripts and a test.!orBREAKING CHANGE:. — not breaking.docker compose buildkeeps working; it simply recordssource_rev=unknown, which the checker reports as unverifiable rather than as a pass.docs/adr/_index_fragments/<NNNN-slug>.mdand the slug is appended to_order.txt. — number allocated withscripts/adr/next-free.sh --claim;README.mdregenerated viascripts/docs/concat-adr-index.sh --writeand verified with--check.Bug-status hygiene (ADR-0165)
docs/state.mdupdated —T-DEV-CONTAINER-STALE-SOURCE-UNDETECTABLE-2026-09-06added to Recently closed with the reproduction, the reason timestamps cannot detect it, and the verification command.Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables (ADR-0108)
## Alternatives consideredweighs five options, including the timestamp comparison that rule 15's current wording implies — which is rejected because it returns "current" for precisely this failure.AGENTS.mdinvariant note — no rebase-sensitive invariants:dev/,scripts/dev/andscripts/ci/tests/are fork-only with no upstream counterpart. The one invariant a rebase could break (the marker must stay in the final stage) is recorded indocs/rebase-notes.md, where this repo keeps container-level ones.changelog.d/added/adr-1195-container-source-guard.md;CHANGELOG.mdregenerated with--writeand verified with--check.docs/rebase-notes.md, sectionci/container-source-guard — record the container's source revision (2026-09-06).Reproducer
Actual output on this workstation:
And against the live checkout:
bash scripts/dev/check-container-source.sh --pre-build # check-container-source: OK — HEAD cd52f2670 matches origin/master; safe to build.Known follow-ups
/etc/vmafx-dev-sourceand reportsrc=2(cannot verify) rather thanrc=0. That is the intended reading — it is not a regression, and one rebuild throughdev/scripts/container-build.shclears it.source_rev=unknownremains reachable for anyone invokingdocker compose builddirectly, because compose cannot rungit. The checker reports it honestly rather than guessing; the wrapper is the documented path.