Repository navigation
bug(deploy): the code-sync path installs three components' requirements without the constraint rewrite — the same abort #14272 fixed for ansible #14275
Description
Activity
- added 4 commits that reference this issue
on Aug 15, 2026 github-actions commented
on Aug 15, 2026 on Aug 15, 2026 – with GitHub ActionsContributorMore actionsClosing — delivered and verified in base
PR #14276 merged into
Dev_new_gui.Evidence, read from the base tip:
_rsync_source_path has a delete flag : False returns False on a missing source : True bare `pip install -r` remaining : 0 tests/services/…14275 : 14 passedWhat this changes for an operator
Code-sync is an update procedure. It costs downtime; it no longer costs the installation.
- The rsync onto a node's
target_pathno longer deletes. The venv, the ansible-generatedsrc/
symlinks and the deployed app files survive, so the service restarts instead of needing a
re-provision. The two rsyncs that write the checkout into the sync cache keep the delete flag —
they carry the full tree, and I verified that before assuming they shared the defect. source_pathsfor ai-stack points at the real sources. It pointed at a directory holding one
README, so a sync copied that README over the live install and reported success.- A source path missing from the checkout fails instead of returning
True, "skipped". - All four components install with
venv/bin/pip— the interpreter their unit actually runs.
slm-backendwas also runningalembicfrom system Python, migrating with a different
interpreter than the service. - A failed post-sync command stops the sync before the restart and before the DB record. It
used to be logged at WARNING and ignored, so a failedpip installproduced a green sync with
nothing installed.
Four defects found in my own work along the way
Three were the same shape — asserting on source text rather than behaviour — and each survived
the mutation it existed to catch:"HOST_STATE_EXCLUDES" in sourcestayed true after the excludes left the argv; the import
line still named them.- Reading
rsync_artifact_excludes()directly could not see a second exclude set added back. "returncode" in body and "return False" in bodystayed true after
if proc.returncode != 0:becameif False:— both words survive in the dead branch.
The fourth was worse: I applied
HOST_STATE_EXCLUDEShere because it is the canonical vocabulary
api/code_sync.pyprotects — canonical for that layout. On this pathdata/,config/and
.env.exampleare tracked source (autobot-backend/,autobot-frontend/,
autobot-slm-backend/), so excluding them would have made the update silently incomplete: the
exact failure this issue is about, reintroduced by its own fix.Recorded as [assert behaviour, not source text] in the session's memory, since four instances in
one PR is a habit rather than an accident.Still open
#14279 — the AI stack's spacy build failure on Python 3.14 — is a separate cause in the same
provisioning run and is not addressed here.- The rsync onto a node's
- added 7 commits that reference this issue
on Sep 12, 2026
Problem
The code-sync / self-update path — the mechanism CLAUDE.md designates as the only way system
updates may reach a host — installs three components' requirements without rewriting their
relative constraint includes.
autobot-slm-backend/services/role_registry.py:Both worker requirements files carry a relative constraint:
Only
backend'spost_sync_cmd(:129) delegates toscripts/build-filtered-requirements.sh, and its own comment at:124says why:Three siblings do exactly that bare install.
Why this matters now
#14272 fixed the ai-stack's ansible deploy path. This is its other path, and the one an
operator actually reaches from the maintenance UI. A code-sync of npu-worker or tts-worker
plausibly reproduces the same abort:
It depends on whether
{BASE}/autobot-npu-worker/../constraints/shared.txtexists on the host —i.e. whether the deployed layout preserves the repo's sibling relationship. The ansible path did
not, which is what #14272 was.
Secondary drift on the ai-stack entry
role_registry.py'sai-stackentry hassource_paths: ["autobot-ai-stack/"], but that repodirectory holds only a placeholder
README.md— the real files live underautobot-infrastructure/shared/docker/ai-stack/. Itspost_sync_cmdalso expectsrequirements.txtwhile the ansible role deploysrequirements-ai.txt. So that entry may beinert rather than live, which is its own problem: a sync path that silently syncs nothing looks
identical to one that works.
Fix
post_sync_cmds throughbuild-filtered-requirements.sh, asbackendalready does — one implementation, not four.
ai-stackentry'ssource_pathsand filename with what actually ships, orremove the entry if the ansible role is the only real path. An inert entry is worse than an
absent one.
role_registry.py. It scans ansible role YAML only, so thiswhole class is invisible to it — which is why the gap survived the fix next door.
Acceptance criteria
a host rather than by diff.
post_sync_cmdcannot pip-install a requirements file carrying a relative includewithout the rewrite — asserted by a test that reads
role_registry.py, not only YAML.ai-stackentry either syncs the files that actually exist, or is gone.Context
Found reviewing PR #14273 (#14272), which fixed the ansible half. Same defect, different deploy
trigger — and the trigger the operator uses.