Repository navigation
fix: add missing vendor/open-webui path to deploy-demo-box.yml filter - #976
Conversation
deploy-demo-box.yml's push.paths filter had no entry for vendor/open-webui, the forked chat frontend's source tree that Dockerfile.open-webui compiles directly (COPY vendor/open-webui ./). A change under that tree merges to main and triggers no deploy at all: PR #971 (nav fixes) is the live example, merged clean with zero deploy run. The workflow's own comment already documents this exact failure class for apps/web-console (PR #786) and supabase/migrations; this is the same defect recurring a second time in the same file. Also adds .github/ci/lint-deploy-paths-filter.mjs, wired into ci.yml's existing repo-policy-lints required check, which parses every deploy/docker/Dockerfile.*'s COPY/ADD sources and fails the build if any is not covered by the deploy workflow's paths filter. Verified locally that it both passes after this fix and fails loud (naming vendor/open-webui specifically) when the fix is reverted, so the next missing entry blocks a PR instead of silently never deploying. Audited every other Dockerfile the deploy job builds; all other COPY sources already fall under apps/**, packages/**, deploy/docker/**, or go.work(.sum), all already present in the filter. vendor/open-webui was the only gap.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
Next review available in: 46 minutes Limit details: You’ve used all 1 included review currently available under your plan. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
CodeRabbit review on PR #976 flagged that comparing an un-expanded Docker glob (go.work.sum*) against the filter's literal entry (go.work.sum) by stripping the trailing star made them equal by construction, which would silently approve a future go.work.sum.bak that Docker's own wildcard would also copy and that the filter does not cover -- the exact silent-drift bug class this guard exists to catch, reintroduced inside the guard itself. Fixed by expanding each wildcard source against the real files in that directory (the way Docker itself resolves it at build time) and checking every actual match, instead of string-matching the glob. Also fixes a slicing bug this rewrite introduced and caught in self-testing: stripping a directory prefix from a root-level pattern (dirname() returning '.') one character too many, which silently produced zero expansions for any root-level wildcard and would have made the whole check pass regardless. Verified: a `touch go.work.sum.bak` in the repo root now fails the guard by name; removing it and re-running still passes; the original vendor/open-webui regression test (old filter fails, current filter passes) and the sibling lint-workflow-check-names.mjs guard both still pass unchanged.
Adversarial review summary (pipeline stage 6)CodeRabbit CLI (local,
Valid. Fixed in 0fec64d: the guard now expands each wildcard COPY source against the real files on disk (the way Docker itself resolves the glob at build time) instead of string-matching the un-expanded glob text. Self-testing that fix ( CodeRabbit GitHub App (bot review on this PR): SKIPPED. Rate limited on this account ("Review rate limited", next available in ~54 min at the time checked). The ecc:code-review skill: SKIPPED. This subagent's toolset (Read/Write/Edit/Bash only, no Skill or Task/Agent tool) cannot invoke it. Structural capability gap, not a bypass. Plain adversarial pass (self, manual): diff is CI/workflow-only (a new No domain specialist required for a CI/workflow-only diff with no auth, money, or input-parsing surface. |
Summary
deploy-demo-box.yml'spush.pathsfilter had no entry forvendor/open-webui, the forked chat frontend's source tree thatDockerfile.open-webuicompiles directly from (COPY vendor/open-webui ./). A change under that tree merges tomainand triggers no deploy at all. PR #971 (nav fixes, merged clean) is the live example: it touched onlyvendor/open-webui, and no deploy run followed. The fork build in PR #938 deployed only because it also toucheddeploy/docker/Dockerfile.open-webui, which the filter does cover, so past deploys were incidental rather than evidence the path worked.The workflow's own comment already documents this exact failure class for
apps/web-console(PR #786) andsupabase/migrations. This is the same defect recurring a second time in the same file.I audited every other Dockerfile the deploy job builds (
edge-api,control-plane,agent-console,web-console.prod,agent-engine) plus the ones it does not (sdk-tests-*,toolchain,desktop-linux, non-prodweb-console). Every COPY/ADD source across all of them falls underapps/**,packages/**,deploy/docker/**, orgo.work(.sum), all already present in the filter.vendor/open-webuiwas the only gap.Changes
.github/workflows/deploy-demo-box.yml: addvendor/open-webui/**topush.paths, with a comment pointing at the new guard below..github/ci/lint-deploy-paths-filter.mjs: parses the deploy workflow'spush.pathsand everydeploy/docker/Dockerfile.*'s COPY/ADD sources, fails if any source is not covered by the filter. Skips--from=stage copies, which read a prior build stage rather than the host filesystem..github/workflows/ci.yml's existingrepo-policy-lintsjob (already a required check, already installsnode+yaml), right after the siblinglint-workflow-check-names.mjsstep. No new CI job.Deliberately not added to
.github/branch-protection-main.json's required-checks list:repo-policy-lintsis already required, so this step riding inside it already fails the PR loudly on a gap. Promoting it to its own named required check is a separate, more sensitive branch-protection change and out of scope here.Verification
Ran the new guard locally (
npm ci --ignore-scripts && node .github/ci/lint-deploy-paths-filter.mjs):Deploy path-filter coverage OK: every COPY/ADD source across 14 Dockerfiles under deploy/docker/ is covered...deploy-demo-box.ymlchange and reran: fails loud, namingvendor/open-webui/package.json,vendor/open-webui/package-lock.json, andvendor/open-webuiitself as uncovered. Confirms the guard would have caught the original bug.lint-workflow-check-names.mjs: still passes, no regression (23 check names, 6 required contexts).Deploy note
Merging this PR changes
.github/workflows/deploy-demo-box.ymlitself, which is already in its own filter, so the merge will trigger a real deploy to the demo box. That deploy will also carry every other merged-but-undeployed change currently sitting onmain(including PR #971). Given the open P0 on the shared Supabase connection pool, hold this merge for explicit go-ahead rather than merging on green CI alone.Buglog entry
Second instance of the same defect class in the same file (first: PR #786,
apps/web-console).{"error_message":"vendor/open-webui had no entry in deploy-demo-box.yml's push.paths filter; a change under that tree merged to main and triggered no deploy","root_cause":"the paths filter is a hand-maintained allowlist and the fork's frontend source tree (added when the chat frontend was forked to compile from source) was never added to it, so PR #971 (nav fixes touching only vendor/open-webui) merged clean with zero deploy run","fix":"added vendor/open-webui/** to the filter; added .github/ci/lint-deploy-paths-filter.mjs (wired into ci.yml's repo-policy-lints required check) which parses every deploy/docker/Dockerfile.*'s COPY/ADD sources against the filter and fails loud on the next missing entry instead of silently never deploying","tags":["ci","deploy","paths-filter","open-webui","recurring"]}