From bce5f351f025d8b5cca392001ae852bcccfb5420 Mon Sep 17 00:00:00 2001 From: nandi <78769380+codegod100@users.noreply.github.com> Date: Tue, 18 Aug 2026 02:59:49 -0700 Subject: [PATCH] proxy-latha-org: fix tag-push builds by pinning commit_sha, not branch MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit triggerBuild() was sending branch: tagName for tag pushes. BuildBuddy's hosted-runner repo setup does an unconditional `git checkout -B origin/` after a shallow `git fetch --depth=1 origin ` — that only works when resolves as a branch (the fetch populates refs/remotes/origin/). A tag ref only populates FETCH_HEAD, so origin/ never exists and checkout fails with "fatal: 'origin/' is not a commit", killing the run before our own build script step ever executes. Confirmed live debugging the sif-egl-fix invocation, which hit exactly this failure mode. Fix: send commit_sha (api/v1/service.proto RunRequest field 3) instead, which pins the exact commit regardless of ref type — we always have the real sha in scope here. branch is still sent for main-branch pushes only, purely as a snapshot-affinity hint. Also adds .github/workflows/deploy-proxy-latha-org.yml (manual workflow_dispatch, same OpenBao-secrets pattern as cachix.yml) since this sandbox has no Cloudflare deploy credentials of its own — needed to actually get this fix live so a real tag push can publish an artifact to tangled. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/deploy-proxy-latha-org.yml | 50 ++++++++++++++++++++ cloudflare/proxy-latha-org/test_worker.mjs | 6 ++- cloudflare/proxy-latha-org/worker.js | 23 +++++++-- 3 files changed, 72 insertions(+), 7 deletions(-) create mode 100644 .github/workflows/deploy-proxy-latha-org.yml diff --git a/.github/workflows/deploy-proxy-latha-org.yml b/.github/workflows/deploy-proxy-latha-org.yml new file mode 100644 index 0000000..6353462 --- /dev/null +++ b/.github/workflows/deploy-proxy-latha-org.yml @@ -0,0 +1,50 @@ +# Deploys cloudflare/proxy-latha-org/worker.js via its own deploy.sh — +# manual only (workflow_dispatch), same rationale as rbe-image.yml: this +# only needs re-running when worker.js/deploy.sh actually change, not on +# every push, and this sandbox/dev machine has no Cloudflare credentials +# of its own — OpenBao (same secret store cachix.yml already pulls from) +# is the only place they live outside a human's own machine. +# +# Expects these keys under OpenBao's secret/data/ai-api-keys (or wherever +# OPENBAO_SECRET_PATH points): CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, +# TANGLED_WEBHOOK_SECRET, BUILDBUDDY_API_KEY, UPLOAD_TOKEN — see +# deploy.sh's own header comment for what each one needs to be able to do. +# If any are missing, fetch-openbao-env.sh fails loudly (no partial/silent +# deploy). +name: Deploy proxy.latha.org + +on: + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }} + cancel-in-progress: false + +jobs: + deploy: + name: Deploy Worker + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Fetch secrets from OpenBao + env: + OPENBAO_ADDR: https://openbao.boxd.sh + OPENBAO_TOKEN: ${{ secrets.OPENBAO_TOKEN }} + OPENBAO_SECRET_PATH: secret/data/ai-api-keys + run: | + set -euo pipefail + if [[ -z "${OPENBAO_TOKEN:-}" ]]; then + echo "OPENBAO_TOKEN repository secret is not set" >&2 + exit 1 + fi + chmod +x scripts/fetch-openbao-env.sh + ./scripts/fetch-openbao-env.sh --github-env --keys \ + CLOUDFLARE_API_TOKEN,CLOUDFLARE_ACCOUNT_ID,TANGLED_WEBHOOK_SECRET,BUILDBUDDY_API_KEY,UPLOAD_TOKEN + + - name: Run worker test suite + run: node cloudflare/proxy-latha-org/test_worker.mjs + + - name: ./deploy.sh + working-directory: cloudflare/proxy-latha-org + run: ./deploy.sh diff --git a/cloudflare/proxy-latha-org/test_worker.mjs b/cloudflare/proxy-latha-org/test_worker.mjs index 5e63ab4..e041c32 100644 --- a/cloudflare/proxy-latha-org/test_worker.mjs +++ b/cloudflare/proxy-latha-org/test_worker.mjs @@ -123,6 +123,7 @@ async function testValidPushWebhook() { const bbBody = JSON.parse(calls.fetch[0].opts.body); assert.equal(bbBody.repo, "https://tangled.org/nandi.uk/sleek"); assert.equal(bbBody.branch, "main"); + assert.equal(bbBody.commit_sha, "abc123", "commit_sha is always sent, even for main pushes"); assert.equal(bbBody.platform_properties, undefined, "no disk override needed — compute runs on BuildBuddy's RE cluster, not this trigger executor"); assert.match(bbBody.steps[0].run, /buck2 build --show-output \/\/:sleek-android-apk/); assert.equal(calls.fetch[0].opts.headers["x-buildbuddy-api-key"], "test-bb-key"); @@ -336,10 +337,11 @@ async function testTagPushTriggersBuildAndPublishStep() { await Promise.all(pending); assert.equal(calls.fetch.length, before + 1, "tag push must also trigger exactly one BuildBuddy call"); const bbBody = JSON.parse(calls.fetch[calls.fetch.length - 1].opts.body); - assert.equal(bbBody.branch, "v1.2.3", "tag name used as the checkout ref"); + assert.equal(bbBody.commit_sha, "tagcommitsha", "commit_sha pins the exact checkout for tag pushes"); + assert.equal(bbBody.branch, undefined, "no branch field for tag pushes — a tag name isn't a valid checkout branch and would hit BuildBuddy's origin/ checkout bug"); assert.match(bbBody.steps[0].run, /refs\/tags\/v1\.2\.3\^\{tag\}/, "build script computes the annotated tag object hash"); assert.match(bbBody.steps[0].run, /\/publish-release\/v1\.2\.3/, "build script calls back to publish the release"); - console.log("PASS: tag push -> build queued with branch=tag and a release-publish step appended"); + console.log("PASS: tag push -> build queued with commit_sha (not branch) and a release-publish step appended"); } async function testPublishReleaseRejectsBadToken() { diff --git a/cloudflare/proxy-latha-org/worker.js b/cloudflare/proxy-latha-org/worker.js index c50b93c..fb588a4 100644 --- a/cloudflare/proxy-latha-org/worker.js +++ b/cloudflare/proxy-latha-org/worker.js @@ -225,11 +225,24 @@ function buildScript(env, sha, tagName) { async function triggerBuild(env, cloneUrl, sha, { tagName } = {}) { const body = { repo: cloneUrl, - // Tag names work as a checkout ref here the same way branch names do - // (plain `git clone --branch ` semantics) — not yet verified - // against a real tag push through BuildBuddy specifically, only - // against main-branch pushes. First real tag push is the test. - branch: tagName || "main", + // commit_sha pins the exact checkout regardless of ref type — required + // for tag pushes. Confirmed live (debugging the sif-egl-fix invocation) + // that BuildBuddy's hosted-runner repo setup does an unconditional + // `git checkout -B origin/` after a shallow + // `git fetch --depth=1 origin `. That works for a branch (the + // fetch creates `refs/remotes/origin/`), but a tag ref only + // populates FETCH_HEAD — `origin/` never exists, so the checkout + // fails with "fatal: 'origin/' is not a commit" and the run never + // gets past setup. commit_sha (api/v1/service.proto's RunRequest field + // 3, independent of `branch`) sidesteps ref-type resolution entirely — + // we always have the real sha here regardless of tag vs. branch push. + commit_sha: sha, + // branch is *also* sent, but only for main-branch pushes, purely as a + // snapshot-affinity hint (BuildBuddy prefers reusing a runner snapshot + // from a matching branch to warm-start git/bazel state) — skip it for + // tag pushes so there's no `branch` value that could reintroduce the + // same ref-resolution path this is fixing. + ...(tagName ? {} : { branch: "main" }), // No platform_properties override needed now that buildScript() runs // buck2 instead of Nix: the actual compile happens on BuildBuddy's own // RE cluster (platforms/defs.bzl's custom sleek-rbe image), so this -- 2.51.2