Skip to content

fix: add missing vendor/open-webui path to deploy-demo-box.yml filter - #976

Merged
sakibsadmanshajib merged 2 commits into
mainfrom
fix/deploy-paths-filter-vendor-owui
Aug 18, 2026
Merged

sakibsadmanshajib merged 2 commits into
mainfrom
fix/deploy-paths-filter-vendor-owui

Conversation

@sakibsadmanshajib

Copy link
Copy Markdown
Owner

Summary

deploy-demo-box.yml's push.paths filter had no entry for vendor/open-webui, the forked chat frontend's source tree that Dockerfile.open-webui compiles directly from (COPY vendor/open-webui ./). A change under that tree merges to main and triggers no deploy at all. PR #971 (nav fixes, merged clean) is the live example: it touched only vendor/open-webui, and no deploy run followed. The fork build in PR #938 deployed only because it also touched deploy/docker/Dockerfile.open-webui, which the filter does cover, so past deploys were incidental rather than evidence the path worked.

The workflow's own comment already documents this exact failure class for apps/web-console (PR #786) and supabase/migrations. This is the same defect recurring a second time in the same file.

I audited every other Dockerfile the deploy job builds (edge-api, control-plane, agent-console, web-console.prod, agent-engine) plus the ones it does not (sdk-tests-*, toolchain, desktop-linux, non-prod web-console). Every COPY/ADD source across all of them falls under apps/**, packages/**, deploy/docker/**, or go.work(.sum), all already present in the filter. vendor/open-webui was the only gap.

Changes

  • .github/workflows/deploy-demo-box.yml: add vendor/open-webui/** to push.paths, with a comment pointing at the new guard below.
  • New .github/ci/lint-deploy-paths-filter.mjs: parses the deploy workflow's push.paths and every deploy/docker/Dockerfile.*'s COPY/ADD sources, fails if any source is not covered by the filter. Skips --from= stage copies, which read a prior build stage rather than the host filesystem.
  • Wired into .github/workflows/ci.yml's existing repo-policy-lints job (already a required check, already installs node+yaml), right after the sibling lint-workflow-check-names.mjs step. No new CI job.

Deliberately not added to .github/branch-protection-main.json's required-checks list: repo-policy-lints is already required, so this step riding inside it already fails the PR loudly on a gap. Promoting it to its own named required check is a separate, more sensitive branch-protection change and out of scope here.

Verification

Ran the new guard locally (npm ci --ignore-scripts && node .github/ci/lint-deploy-paths-filter.mjs):

  • Passes after this fix: Deploy path-filter coverage OK: every COPY/ADD source across 14 Dockerfiles under deploy/docker/ is covered...
  • Stashed only the deploy-demo-box.yml change and reran: fails loud, naming vendor/open-webui/package.json, vendor/open-webui/package-lock.json, and vendor/open-webui itself as uncovered. Confirms the guard would have caught the original bug.
  • Re-ran the sibling lint-workflow-check-names.mjs: still passes, no regression (23 check names, 6 required contexts).
  • Both edited workflow YAMLs parse cleanly.

Deploy note

Merging this PR changes .github/workflows/deploy-demo-box.yml itself, which is already in its own filter, so the merge will trigger a real deploy to the demo box. That deploy will also carry every other merged-but-undeployed change currently sitting on main (including PR #971). Given the open P0 on the shared Supabase connection pool, hold this merge for explicit go-ahead rather than merging on green CI alone.

Buglog entry

Second instance of the same defect class in the same file (first: PR #786, apps/web-console).

{"error_message":"vendor/open-webui had no entry in deploy-demo-box.yml's push.paths filter; a change under that tree merged to main and triggered no deploy","root_cause":"the paths filter is a hand-maintained allowlist and the fork's frontend source tree (added when the chat frontend was forked to compile from source) was never added to it, so PR #971 (nav fixes touching only vendor/open-webui) merged clean with zero deploy run","fix":"added vendor/open-webui/** to the filter; added .github/ci/lint-deploy-paths-filter.mjs (wired into ci.yml's repo-policy-lints required check) which parses every deploy/docker/Dockerfile.*'s COPY/ADD sources against the filter and fails loud on the next missing entry instead of silently never deploying","tags":["ci","deploy","paths-filter","open-webui","recurring"]}

deploy-demo-box.yml's push.paths filter had no entry for vendor/open-webui,
the forked chat frontend's source tree that Dockerfile.open-webui compiles
directly (COPY vendor/open-webui ./). A change under that tree merges to
main and triggers no deploy at all: PR #971 (nav fixes) is the live
example, merged clean with zero deploy run. The workflow's own comment
already documents this exact failure class for apps/web-console (PR #786)
and supabase/migrations; this is the same defect recurring a second time
in the same file.

Also adds .github/ci/lint-deploy-paths-filter.mjs, wired into ci.yml's
existing repo-policy-lints required check, which parses every
deploy/docker/Dockerfile.*'s COPY/ADD sources and fails the build if any
is not covered by the deploy workflow's paths filter. Verified locally
that it both passes after this fix and fails loud (naming vendor/open-webui
specifically) when the fix is reverted, so the next missing entry blocks a
PR instead of silently never deploying.

Audited every other Dockerfile the deploy job builds; all other COPY
sources already fall under apps/**, packages/**, deploy/docker/**, or
go.work(.sum), all already present in the filter. vendor/open-webui was
the only gap.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@sakibsadmanshajib, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 46 minutes

Limit details: You’ve used all 1 included review currently available under your plan.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f8630407-59a3-401e-a9d8-8ac5072fd95f

📥 Commits

Reviewing files that changed from the base of the PR and between a92785e and 0fec64d.

📒 Files selected for processing (3)
  • .github/ci/lint-deploy-paths-filter.mjs
  • .github/workflows/ci.yml
  • .github/workflows/deploy-demo-box.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CodeRabbit review on PR #976 flagged that comparing an un-expanded Docker
glob (go.work.sum*) against the filter's literal entry (go.work.sum) by
stripping the trailing star made them equal by construction, which would
silently approve a future go.work.sum.bak that Docker's own wildcard would
also copy and that the filter does not cover -- the exact silent-drift bug
class this guard exists to catch, reintroduced inside the guard itself.

Fixed by expanding each wildcard source against the real files in that
directory (the way Docker itself resolves it at build time) and checking
every actual match, instead of string-matching the glob. Also fixes a
slicing bug this rewrite introduced and caught in self-testing: stripping
a directory prefix from a root-level pattern (dirname() returning '.')
one character too many, which silently produced zero expansions for any
root-level wildcard and would have made the whole check pass regardless.

Verified: a `touch go.work.sum.bak` in the repo root now fails the guard
by name; removing it and re-running still passes; the original
vendor/open-webui regression test (old filter fails, current filter
passes) and the sibling lint-workflow-check-names.mjs guard both still
pass unchanged.
@sakibsadmanshajib

Copy link
Copy Markdown
Owner Author

Adversarial review summary (pipeline stage 6)

CodeRabbit CLI (local, coderabbit review --committed --base main): ran successfully, 1 major finding.

go.work.sum* is reduced to go.work.sum. A future file such as go.work.sum.bak can match the Docker source pattern while remaining outside the exact go.work.sum workflow filter. The guard would then pass although the deploy workflow would not trigger.

Valid. Fixed in 0fec64d: the guard now expands each wildcard COPY source against the real files on disk (the way Docker itself resolves the glob at build time) instead of string-matching the un-expanded glob text. Self-testing that fix (touch go.work.sum.bak) also caught a slicing bug the rewrite introduced, which made every root-level wildcard silently expand to nothing; fixed in the same commit. Re-verified: the go.work.sum.bak repro now fails the guard by name, the original vendor/open-webui regression test still passes, and the sibling lint-workflow-check-names.mjs guard is unaffected.

CodeRabbit GitHub App (bot review on this PR): SKIPPED. Rate limited on this account ("Review rate limited", next available in ~54 min at the time checked). The CodeRabbit status check itself reports pass/neutral, not a real review; do not read it as one.

ecc:code-review skill: SKIPPED. This subagent's toolset (Read/Write/Edit/Bash only, no Skill or Task/Agent tool) cannot invoke it. Structural capability gap, not a bypass.

Plain adversarial pass (self, manual): diff is CI/workflow-only (a new .mjs static-analysis script plus two workflow YAML edits), no auth/money/input-parsing path, so no domain specialist or /codex:adversarial-review added per the dynamic selector. Checked: instruction-parsing regex anchoring (comments/RUN lines cannot false-match COPY/ADD), --chown=/other COPY flags correctly stripped without skipping the line, --from= stage copies correctly excluded, backslash line-continuation joining scoped safely, the new repo-policy-lints step correctly gated by the same changes job output that this very diff triggers (*.mjs and workflow-YAML changes both fall to run="true", confirmed by reading that job's case statement), and confirmed via git diff main...HEAD that no unrelated file (a background hook had transiently modified go.work.sum in the local worktree; discarded before commit, never staged).

No domain specialist required for a CI/workflow-only diff with no auth, money, or input-parsing surface.

@sakibsadmanshajib
sakibsadmanshajib merged commit 796d678 into main Aug 18, 2026
18 checks passed
@github-actions
github-actions Bot deleted the fix/deploy-paths-filter-vendor-owui branch August 18, 2026 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant