From 8b01847388db5ca1f2371d0c5298ba2b1db8d323 Mon Sep 17 00:00:00 2001 From: claude Date: Tue, 1 Sep 2026 11:10:32 -0400 Subject: [PATCH] fix(ci): derive IMAGE from github.repository, not the schedule-empty event payload MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `${{ github.event.repository.name }}` resolves to EMPTY on `schedule` events since the Gitea upgrade between 2026-07-01 and 2026-08-01, so IMAGE became "justin/" and the monthly refresh died at the last step: ERROR: failed to build: invalid tag "192.168.0.2:1234/justin/:latest": invalid reference format Both the 2026-08-01 and 2026-09-01 refreshes scraped, committed, pushed and reindexed successfully, then failed to build the image — so the corpus on main is current but the published container has been stale since the 2026-07-01 run. - IMAGE now comes from `${{ github.repository }}` (run context, not the event payload — `github.repository_owner` from the same source was resolving fine all along). - The package-link and registry-GC steps take the bare repo name from `${GITHUB_REPOSITORY##*/}` (POSIX, safe under dash). - New `Verify image name resolves` step fails in seconds instead of after a ~30 min scrape if this ever regresses. Same fix applies to image-only.yml, which only escaped the bug because push/workflow_dispatch events still carry the repository payload. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01FnVuG79cYPcRLTp4pC8ujR --- .gitea/workflows/image-only.yml | 19 ++++++++++++++++--- .gitea/workflows/refresh.yml | 19 ++++++++++++++++--- CLAUDE.md | 6 +++++- 3 files changed, 37 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/image-only.yml b/.gitea/workflows/image-only.yml index 6d5c65f7..9d507d53 100644 --- a/.gitea/workflows/image-only.yml +++ b/.gitea/workflows/image-only.yml @@ -31,7 +31,7 @@ concurrency: env: REGISTRY_PUSH: 192.168.0.2:1234 REGISTRY_PULL: git.jpaul.io - IMAGE: ${{ github.repository_owner }}/${{ github.event.repository.name }} + IMAGE: ${{ github.repository }} # 3-GPU LAN pool, weighted toward .0.125 (4090). See refresh.yml for # the bench numbers. .0.2:11434 excluded (not GPU-pinned). localhost # excluded from CI (runner container has no Ollama on its loopback; @@ -51,6 +51,19 @@ jobs: with: fetch-depth: 0 + - name: Verify image name resolves + # ${{ github.event.repository.name }} silently resolves to EMPTY on + # schedule events (Gitea >=1.27), which built the tag + # "192.168.0.2:1234/justin/:latest" and failed the build only AFTER + # the full scrape. IMAGE now comes from github.repository; this step + # fails in seconds if it ever goes empty again. + run: | + echo "IMAGE=${IMAGE}" + case "${IMAGE}" in + */?*) ;; + *) echo "ERROR: IMAGE did not resolve to owner/repo"; exit 1 ;; + esac + - name: Set up Python uses: actions/setup-python@v5 with: @@ -92,7 +105,7 @@ jobs: GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | OWNER="${{ github.repository_owner }}" - PKG="${{ github.event.repository.name }}" + PKG="${GITHUB_REPOSITORY##*/}" BODY=$(mktemp) CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \ -H "Authorization: token ${GITEA_TOKEN}" \ @@ -116,6 +129,6 @@ jobs: run: | python scripts/registry_gc.py \ --owner "${{ github.repository_owner }}" \ - --package "${{ github.event.repository.name }}" \ + --package "${GITHUB_REPOSITORY##*/}" \ --keep-days 180 \ --keep-latest 6 diff --git a/.gitea/workflows/refresh.yml b/.gitea/workflows/refresh.yml index defa037e..e32c9b0f 100644 --- a/.gitea/workflows/refresh.yml +++ b/.gitea/workflows/refresh.yml @@ -32,7 +32,7 @@ env: # through the public hostname (response bodies aren't capped). REGISTRY_PUSH: 192.168.0.2:1234 REGISTRY_PULL: git.jpaul.io - IMAGE: ${{ github.repository_owner }}/${{ github.event.repository.name }} + IMAGE: ${{ github.repository }} # Embedder pool — 3 GPU-pinned endpoints reachable from the runner # container on .0.2. Measured throughput (50-chunk batches on @@ -63,6 +63,19 @@ jobs: # produces a 0-byte history file. fetch-depth: 0 + - name: Verify image name resolves + # ${{ github.event.repository.name }} silently resolves to EMPTY on + # schedule events (Gitea >=1.27), which built the tag + # "192.168.0.2:1234/justin/:latest" and failed the build only AFTER + # the full scrape. IMAGE now comes from github.repository; this step + # fails in seconds if it ever goes empty again. + run: | + echo "IMAGE=${IMAGE}" + case "${IMAGE}" in + */?*) ;; + *) echo "ERROR: IMAGE did not resolve to owner/repo"; exit 1 ;; + esac + - name: Set up Python uses: actions/setup-python@v5 with: @@ -176,7 +189,7 @@ jobs: GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | OWNER="${{ github.repository_owner }}" - PKG="${{ github.event.repository.name }}" + PKG="${GITHUB_REPOSITORY##*/}" BODY=$(mktemp) CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \ -H "Authorization: token ${GITEA_TOKEN}" \ @@ -201,6 +214,6 @@ jobs: run: | python scripts/registry_gc.py \ --owner "${{ github.repository_owner }}" \ - --package "${{ github.event.repository.name }}" \ + --package "${GITHUB_REPOSITORY##*/}" \ --keep-days 180 \ --keep-latest 6 diff --git a/CLAUDE.md b/CLAUDE.md index 469332a0..dcb2b3f1 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -194,7 +194,11 @@ template's PLAN.md. ### Image name and package linking are repo-name-derived `IMAGE` and `--package` derive from the repo at runtime via -`${{ github.repository_owner }}` / `${{ github.event.repository.name }}`. +`${{ github.repository }}` / `${GITHUB_REPOSITORY##*/}`. Do **not** use +`${{ github.event.repository.name }}` — it resolves to EMPTY on +`schedule` events (Gitea >= 1.27), which silently builds the tag +`192.168.0.2:1234//:latest` and fails the build *after* the +full scrape. The `Verify image name resolves` step guards it. The only workflow placeholders customized per clone are `REGISTRY_PUSH=192.168.0.2:1234`, `REGISTRY_PULL=git.jpaul.io`, and the `OLLAMA_URL` embed pool.