Skip to content

fix(docker): fix image build failures in engine Dockerfile and release workflows - #656

Merged
slin1237 merged 4 commits into
mainfrom
wei/fix-image-build
Mar 6, 2026
Merged

slin1237 merged 4 commits into
mainfrom
wei/fix-image-build

Conversation

@gongwei-130

@gongwei-130 gongwei-130 commented Mar 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Fix typo in Dockerfile.engine: engine-sr → engine-src caused cd to fail after clone
  • Fix --depth 1 checkout failure: shallow clone cannot checkout a specific commit SHA; now uses full clone when a specific commit is given, --depth 1 only for latest
  • Add progressive build status to job summaries: image tag is written to summary immediately after resolution (before build starts), so failures mid-build are still observable; build/push milestones also written inline

Changes

docker/Dockerfile.engine

  • Fix directory name typo (engine-sr → engine-src)
  • Split clone logic: latest uses --depth 1, specific commit/ref uses full clone + git checkout

.github/workflows/release-{vllm,sglang,trtllm}-docker.yml

  • Write resolved image tag to summary right after it is computed
  • Write Build image: done and Push image: <name> milestones to summary as steps complete
  • vLLM workflow: extract tag resolution into a dedicated Resolve image tag step (was embedded in the build+push step), align with sglang/trtllm structure
  • trtllm workflow: add Build base image: done summary line after optional base image build step
  • All three workflows: add if: always() to Summary step and add Clean up local images step

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated Docker build workflows with improved logging throughout build and push processes
    • Enhanced cleanup processes for intermediate Docker images
    • Updated default version references in release configurations
    • Refined build parameter handling and image tagging logic

Signed-off-by: gongwei-130 <weigong28@gmail.com>
Signed-off-by: gongwei-130 <weigong28@gmail.com>
Signed-off-by: gongwei-130 <weigong28@gmail.com>
@github-actions github-actions Bot added ci CI/CD configuration changes docker Docker configuration changes labels Mar 6, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the reliability of Docker image builds and improves the observability of the CI/CD pipeline. By addressing critical issues in the Dockerfile and refining the GitHub Actions workflows, it ensures more stable image creation and provides clearer, real-time feedback on build processes.

Highlights

  • Dockerfile Typo Fix: Corrected a typo in Dockerfile.engine where engine-sr was mistakenly used instead of engine-src, which caused build failures.
  • Improved Git Clone Logic: Modified the Dockerfile to handle Git cloning more robustly. Shallow clones (--depth 1) are now only used for the 'latest' commit, while specific commit SHAs trigger a full clone followed by a checkout, resolving issues with shallow clones failing on specific commits.
  • Enhanced Build Status Reporting: Integrated progressive build status updates into GitHub Actions job summaries. The resolved image tag is now written immediately, and build/push milestones are added inline, providing better visibility into build progress and failures.
Changelog
  • docker/Dockerfile.engine
    • Corrected a typo in the engine source directory name from engine-sr to engine-src.
    • Modified the Git clone logic to perform a shallow clone (--depth 1) only when the commit is "latest", otherwise, a full clone followed by a specific commit checkout is performed.
Ignored Files
  • Ignored by pattern: .github/workflows/** (3)
    • .github/workflows/release-sglang-docker.yml
    • .github/workflows/release-trtllm-docker.yml
    • .github/workflows/release-vllm-docker.yml
Activity
  • No human activity has been recorded on this pull request yet.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@coderabbitai

coderabbitai Bot commented Mar 6, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Updates GitHub Actions release workflows for SGLang, TRT-LLM, and vLLM Docker image builds with refined tag resolution logic, improved summary logging, default SMG commit version bump to 'v1.1.0', and cleanup steps. Dockerfile.engine refactored with explicit branching for clone/checkout operations.

Changes

Cohort / File(s) Summary
Release Workflow Updates
.github/workflows/release-sglang-docker.yml, .github/workflows/release-trtllm-docker.yml, .github/workflows/release-vllm-docker.yml
Default SMG commit changed from 'latest' to 'v1.1.0'. Tag resolution logic enhanced with improved logging to workflow summary. Build and push steps now emit status updates to summary. New cleanup step removes local intermediate images. vLLM workflow significantly refactored to separate tag resolution from build/push operations with dedicated action steps.
Dockerfile Engine Logic
docker/Dockerfile.engine
Clone and checkout operations refactored with explicit branching: shallow clone performed when commit equals 'latest', otherwise full clone followed by checkout. Applied to both ENGINE_REPO/ENGINE_COMMIT and SMG_REPO/SMG_COMMIT. Fixes destination path from /opt/engine-sr to /opt/engine-src.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • #651: Updates the same release workflows and Dockerfile.engine with similar tag resolution, logging, and cleanup improvements.
  • #604: Modifies identical GitHub Actions workflows and Dockerfile.engine with related clone/checkout logic refinements.

Suggested reviewers

  • slin1237
  • key4ng
  • XinyueZhang369

Poem

🐰 A rabbit hops through workflows bright,
With tag resolution shining right,
Build and push in perfect dance,
Cleanup sweeping—no spurious branch!
Docker images clean and neat,
Release automation's quite a treat! 🐳

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'fix(docker): fix image build failures in engine Dockerfile and release workflows' directly and clearly summarizes the main changes across the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch wei/fix-image-build

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request fixes a typo and improves the build logic in Dockerfile.engine to handle specific commit checkouts more reliably. However, the direct use of build arguments in shell commands within the Dockerfile introduces a potential command injection vulnerability if these arguments are sourced from untrusted user input. I recommend implementing strict validation for these build arguments in the CI/CD pipeline. Additionally, I've provided suggestions to further improve the shell script logic within the Dockerfile for better robustness and readability by using git -C and adding protective checks for environment variables.

Comment thread docker/Dockerfile.engine
Comment on lines +13 to +25
if [ "${ENGINE_COMMIT}" = "latest" ]; then \
git clone --depth 1 "${ENGINE_REPO}" /opt/engine-src; \
else \
git clone "${ENGINE_REPO}" /opt/engine-src \
&& ( cd /opt/engine-src && git checkout "${ENGINE_COMMIT}" ); \
fi; \
else mkdir -p /opt/engine-src; fi \
&& git clone --depth 1 "${SMG_REPO}" /tmp/smg-src \
&& ( cd /tmp/smg-src && ( [ "${SMG_COMMIT}" = "latest" ] || git checkout "${SMG_COMMIT}" ) )
&& if [ "${SMG_COMMIT}" = "latest" ]; then \
git clone --depth 1 "${SMG_REPO}" /tmp/smg-src; \
else \
git clone "${SMG_REPO}" /tmp/smg-src \
&& ( cd /tmp/smg-src && git checkout "${SMG_COMMIT}" ); \
fi

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-high high

The RUN instruction uses several build arguments (ENGINE_REPO, ENGINE_COMMIT, SMG_REPO, SMG_COMMIT) directly within a shell command. This introduces a potential command injection vulnerability, as an attacker controlling these arguments could inject arbitrary shell commands. For example, setting ENGINE_COMMIT to latest" ]; touch /tmp/pwned; if [ "1" = "1 could lead to arbitrary code execution during the build. To mitigate this, ensure strict validation of these build arguments in the CI/CD pipeline. Additionally, for improved robustness and clarity, consider using git -C instead of ( cd ... && git ... ) and adding protective checks for environment variables like SMG_REPO and SMG_COMMIT before use.

    && if [ -n "${ENGINE_REPO}" ] && [ -n "${ENGINE_COMMIT}" ]; then \
         if [ "${ENGINE_COMMIT}" = "latest" ]; then \
           git clone --depth 1 "${ENGINE_REPO}" /opt/engine-src; \
         else \
           git clone "${ENGINE_REPO}" /opt/engine-src \
           && git -C /opt/engine-src checkout "${ENGINE_COMMIT}"; \
         fi; \
       else mkdir -p /opt/engine-src; fi \
    && if [ -n "${SMG_REPO}" ] && [ -n "${SMG_COMMIT}" ]; then \
         if [ "${SMG_COMMIT}" = "latest" ]; then \
           git clone --depth 1 "${SMG_REPO}" /tmp/smg-src; \
         else \
           git clone "${SMG_REPO}" /tmp/smg-src \
           && git -C /tmp/smg-src checkout "${SMG_COMMIT}"; \
         fi; \
       else mkdir -p /tmp/smg-src; fi

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release-vllm-docker.yml:
- Line 142: The workflow uses the wrong step output for the image tag: change
the reference from steps.push-ghcr.outputs.image_tag to the step that actually
exposes image_tag (steps.resolve-tag.outputs.image_tag); update the summary echo
to read the image_tag from resolve-tag so it prints the resolved image tag
instead of an empty value, keeping the push-ghcr step as-is which only exposes
image_name.

In `@docker/Dockerfile.engine`:
- Around line 11-25: The SMG clone block lacks a guard for empty
SMG_REPO/SMG_COMMIT and can run git clone "" causing build failures; update the
SMG handling to mirror the ENGINE logic: check if [ -n "${SMG_REPO}" ] && [ -n
"${SMG_COMMIT}" ] before attempting any git operations, and if not present
create the destination directory (e.g., /tmp/smg-src); when present, keep the
existing behavior of using depth=1 for SMG_COMMIT="latest" and full clone +
checkout otherwise.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 1cdb10a2-74c5-41a4-b7d7-91731ba5dd43

📥 Commits

Reviewing files that changed from the base of the PR and between 4386de0 and f7a1d6d.

📒 Files selected for processing (4)
  • .github/workflows/release-sglang-docker.yml
  • .github/workflows/release-trtllm-docker.yml
  • .github/workflows/release-vllm-docker.yml
  • docker/Dockerfile.engine

run: |
echo "## Image" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Image tag:** \`${{ steps.push-ghcr.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor

Bug: Incorrect step output reference will produce empty image tag.

Line 142 references steps.push-ghcr.outputs.image_tag, but the push-ghcr step (lines 113-124) only sets image_name as an output (line 121), not image_tag.

This should use steps.resolve-tag.outputs.image_tag like the sglang and trtllm workflows do.

🐛 Proposed fix
-          echo "**Image tag:** \`${{ steps.push-ghcr.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY
+          echo "**Image tag:** \`${{ steps.resolve-tag.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
echo "**Image tag:** \`${{ steps.push-ghcr.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY
echo "**Image tag:** \`${{ steps.resolve-tag.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/release-vllm-docker.yml at line 142, The workflow uses the
wrong step output for the image tag: change the reference from
steps.push-ghcr.outputs.image_tag to the step that actually exposes image_tag
(steps.resolve-tag.outputs.image_tag); update the summary echo to read the
image_tag from resolve-tag so it prints the resolved image tag instead of an
empty value, keeping the push-ghcr step as-is which only exposes image_name.

Comment thread docker/Dockerfile.engine
Comment on lines 11 to +25
RUN apk add --no-cache git \
&& if [ -n "${ENGINE_REPO}" ] && [ -n "${ENGINE_COMMIT}" ]; then \
git clone --depth 1 "${ENGINE_REPO}" /opt/engine-sr \
&& ( cd /opt/engine-src && ( [ "${ENGINE_COMMIT}" = "latest" ] || git checkout "${ENGINE_COMMIT}" ) ); \
if [ "${ENGINE_COMMIT}" = "latest" ]; then \
git clone --depth 1 "${ENGINE_REPO}" /opt/engine-src; \
else \
git clone "${ENGINE_REPO}" /opt/engine-src \
&& ( cd /opt/engine-src && git checkout "${ENGINE_COMMIT}" ); \
fi; \
else mkdir -p /opt/engine-src; fi \
&& git clone --depth 1 "${SMG_REPO}" /tmp/smg-src \
&& ( cd /tmp/smg-src && ( [ "${SMG_COMMIT}" = "latest" ] || git checkout "${SMG_COMMIT}" ) )
&& if [ "${SMG_COMMIT}" = "latest" ]; then \
git clone --depth 1 "${SMG_REPO}" /tmp/smg-src; \
else \
git clone "${SMG_REPO}" /tmp/smg-src \
&& ( cd /tmp/smg-src && git checkout "${SMG_COMMIT}" ); \
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Missing guard for empty SMG_REPO could cause build failures.

The ENGINE_REPO block (lines 12-19) properly guards against empty values with if [ -n "${ENGINE_REPO}" ] && [ -n "${ENGINE_COMMIT}" ]. However, the SMG_REPO block (lines 20-25) directly attempts to clone without verifying that SMG_REPO is non-empty.

Although workflows define a default for smg_repo, the input is required: false, meaning an empty value could be passed. If SMG_REPO is empty, git clone "" /tmp/smg-src will fail.

🐛 Proposed fix to guard SMG_REPO
-    && if [ "${SMG_COMMIT}" = "latest" ]; then \
-         git clone --depth 1 "${SMG_REPO}" /tmp/smg-src; \
-       else \
-         git clone "${SMG_REPO}" /tmp/smg-src \
-         && ( cd /tmp/smg-src && git checkout "${SMG_COMMIT}" ); \
-       fi
+    && if [ -n "${SMG_REPO}" ]; then \
+         if [ "${SMG_COMMIT}" = "latest" ]; then \
+           git clone --depth 1 "${SMG_REPO}" /tmp/smg-src; \
+         else \
+           git clone "${SMG_REPO}" /tmp/smg-src \
+           && ( cd /tmp/smg-src && git checkout "${SMG_COMMIT}" ); \
+         fi; \
+       else \
+         echo "SMG_REPO is required" && exit 1; \
+       fi
🧰 Tools
🪛 Hadolint (2.14.0)

[warning] 11-11: Use WORKDIR to switch to a directory

(DL3003)


[warning] 11-11: Pin versions in apk add. Instead of apk add <package> use apk add <package>=<version>

(DL3018)

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@docker/Dockerfile.engine` around lines 11 - 25, The SMG clone block lacks a
guard for empty SMG_REPO/SMG_COMMIT and can run git clone "" causing build
failures; update the SMG handling to mirror the ENGINE logic: check if [ -n
"${SMG_REPO}" ] && [ -n "${SMG_COMMIT}" ] before attempting any git operations,
and if not present create the destination directory (e.g., /tmp/smg-src); when
present, keep the existing behavior of using depth=1 for SMG_COMMIT="latest" and
full clone + checkout otherwise.

@slin1237
slin1237 merged commit ae6b424 into main Mar 6, 2026
22 checks passed
@slin1237
slin1237 deleted the wei/fix-image-build branch March 6, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes docker Docker configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants