Repository navigation
build: bound local Docker context (W1-8) - #481
Merged
Merged
Conversation
This was referenced Sep 8, 2026
pull Bot
pushed a commit
to asleekgeek/Cortex
that referenced
this pull request
Sep 8, 2026
Root cause of the cdeust#509 -> cdeust#510 incident. The `changes` filter classifies '*.md' out of `code`: code: - '**' - '!{*.md,docs/**/*.md,...}' so a README-only PR sets code=false and every test job is skipped. But part of that suite takes documentation as its INPUT: tests_py/scripts/test_codex_plugin_contract.py reads README.md and asserts on the canonical published identities (the hypermnesia-mcp-viz anchor, the viz/spec migration strings). The guards were therefore switched OFF exactly when their subject changed. cdeust#509 was a README-only diff, every test job skipped, it merged green, and the push to main went red on that test across five jobs (run 34238410970 — 7663 passed, 1 failed). cdeust#510 fixed the symptom; this fixes the reason it could reach main at all. Adds `docs` to test-sqlite's predicate only, not to the 3.10-3.13 matrix: test-sqlite already runs THE FULL SUITE in one ~5-minute job, so it covers the doc-contract tests at the smallest cost that closes the gap. Waking the whole matrix on every prose edit would undo cdeust#475-cdeust#481. scripts/check_ci_gate_results.py mirrors ci.yml's predicates — its own check_policy docstring requires the workflow and the executable policy to stay "in exact agreement". Changing only the workflow would have left two sources of truth disagreeing about when test-sqlite may skip, so _required_jobs gains the same condition and both files carry the same note. Caught by re-reading the diff, not by CI. Its two docs-only tests are updated to the new policy, and the first is turned into a named regression test that asserts skipping test-sqlite on a docs-only PR is NOT justified — the exact hole cdeust#509 fell through. Verified: actionlint 1.7.12 (the pinned version) clean on ci.yml; check_ci_gate_complete.py OK; both gate test files 38 passed, 159 subtests; craftsmanship, ruff check, ruff format, doc-claims all clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01StMBvNd7eVJGtpnC2zNsx1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Symptôme
W1-8 / H9 : un build local transmet les installations Python et l'état généré
du poste au démon Docker. Le contexte mesuré atteint 11,99 Go. PR empilée sur #479.
Cause racine
Les 14 règles de
.dockerignorene couvraient ni.venv, nideps, ni lesdonnées
.claude, nigraphify-out, ni les journaux de benchmark générés.Le Dockerfile runtime utilise
COPY .dans ses deux stages.Changement
Un seul fichier modifié :
.dockerignore. Exclusions des installations locales,caches Python/node, état généré et sorties texte/logs de benchmark. Le fichier
suivi
.claude/settings.jsonreste inclus, ainsi que.claude-plugin, lessources, tests, contraintes, scripts et entrées de benchmark.
Preuve
Hôte macOS ARM64, 10 cœurs. Base
d72e8b83955234d8f944ac95ec39059723f710f6;seul diff de production :
.dockerignore. Docker 28.3.3, Buildx 0.37.0,BuildKit 0.33.0, profil Colima temporaire dédié (4 CPU, 4 GiB RAM, disque 40 GiB).
Un constructeur neuf par phase empêche le transfert incrémental de fausser
l'avant/après.
FROM scratch+COPY . /context/, exporttype=cacheonly:transferring contextValeurs de taille arrondies affichées par BuildKit, pas une mesure d'énergie.
Le contexte après est inférieur à 100 Mo. Les scripts avant et après terminent
avec le code 0.
Les trois images complètes se construisent ensuite séquentiellement avec
--load, sans changer leurs Dockerfiles, pins ou préchargements de modèles :docker image inspect .SizeDockerfilefb51535bcf5ddae03c121b4691fd989ccbc8c2a7167c87ddaf75533ad53f7e54docker/Dockerfilec8d5ebd8fce4d9f6948f302eb43be1cce6ef52d018c9f46206dec258a1c82e92.devcontainer/Dockerfile7a11088330325905a72a05b1fb1e3446e0e4a9c97f76fcae9352a62a2e47466cCommandes exactes archivées dans
/private/tmp/cortex-green-docker-context-proof.shet/private/tmp/cortex-green-docker-images-proof.sh:bash /private/tmp/cortex-green-docker-context-proof.sh before # appliquer le diff .dockerignore bash /private/tmp/cortex-green-docker-context-proof.sh after bash /private/tmp/cortex-green-docker-images-proof.shLa première commande a précédé le diff. Les deux scripts contiennent les appels
docker buildx build --progress=plain, la création de constructeurs distincts,git rev-parse HEAD,uptimeetdf -h /. Les trois builds terminent avec lecode 0. Journaux :
cortex-green-w1-8-{before,after}-context.log,cortex-green-w1-8-images.log; identifiants archivés danscortex-green-w1-8-image-inspect.json, tous sous/private/tmp/.Commit final :
d0f7c19bf64a2d994b2e9a2a9818244c994bc972(aucun rebase après les mesures).Gates locaux ordonnés, code final 0 : Ruff/format (1 416 fichiers), craftsmanship,
Pyright (zéro diagnostic), scripts 830 passed / 5 skipped / 292 subtests,
puis suite complète 7 577 passed / 221 skipped / 292 subtests en 149,00 s.
Charge initiale 4,29 / 10 cœurs ; disque 62 GiB avant et après.
Le driver effectue
uv sync --locked --no-default-groups --extra dev --extra sqlite --group lint, Ruff check/format, craftsmanship ; puis sync des extrasdev,postgresql,sqlite,codebase,otelavec groupestypecheck,lint, Pyright surmcp_server/, pytest scripts et pytest complet. Journal :/private/tmp/cortex-green-w1-8-gates.log.Les dépendances du launcher et les données sont dans un arbre privé jetable ;
les trois DSN explicites visent un socket Unix inexistant. Les skips PostgreSQL
sont signalés, sans accès à une base de production.
CI externe 34042623702 :
success. Les trois jobs Docker sont verts ; les jobs Python sont ignorés conformément au filtre Docker seul, après validation locale complète.Conformité
Diff limité à un fichier de configuration ; aucune constante algorithmique,
aucune nouvelle baseline craftsmanship, aucun changement mémoire. Un seul
travail local lourd à la fois, charge initiale toujours inférieure aux cœurs.
Données de validation jetables, aucun accès à la production. Aucun cache de
modèle sous
/tmp: les préchargements Docker restent dans les images.Candidats issues
Les tailles des installations et sorties générées dépendent du poste. Les
Dockerfiles conservent leurs dépendances et préchargements existants ; leurs
coûts ne sont pas assimilés au seul contexte de build. Aucun nouveau ticket créé.
Runbook
Le profil Colima
cortex-green-w1-8créé pour cette preuve a été supprimé aprèsles trois builds. Le profil utilisateur
defaultest toujours en cours et sesimages/caches ont été conservés ; 62 GiB disponibles au début des gates suivants.
Le propriétaire décide de la fusion. Aucun nettoyage de ses installations n'a
été effectué, aucune image publiée dans un registre.