mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
fix(ci): avoid tar|grep -q SIGPIPE false-failure in package-artifacts (#20)
Some checks are pending
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
Some checks are pending
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
`tar -tzf app.tar.gz | grep -qx` under set -o pipefail fails the pipeline when grep -q matches and exits early (SIGPIPEs tar -> 'write error' -> non-zero), a false 'missing agent/server.py'. List the archive once into a var, then grep the var. Same fix for the secret-guard pipe (which was also silently broken).
This commit is contained in:
parent
2765b65acd
commit
9e2b215f08
1 changed files with 9 additions and 3 deletions
12
.github/scripts/package-artifacts.sh
vendored
12
.github/scripts/package-artifacts.sh
vendored
|
|
@ -21,10 +21,16 @@ echo "==> app.tar.gz from source (git archive HEAD)"
|
||||||
git archive --format=tar.gz -o app.tar.gz HEAD \
|
git archive --format=tar.gz -o app.tar.gz HEAD \
|
||||||
agent deploy langgraph.json pyproject.toml uv.lock README.md
|
agent deploy langgraph.json pyproject.toml uv.lock README.md
|
||||||
|
|
||||||
|
# List the archive ONCE into a variable. (`tar -tzf ... | grep -q ...` is unsafe
|
||||||
|
# under `set -o pipefail`: grep -q exits on first match, SIGPIPEs tar -> "write
|
||||||
|
# error" -> the pipeline reports non-zero even though grep succeeded, a false
|
||||||
|
# failure. Listing once avoids the pipe entirely.)
|
||||||
|
APP_LIST="$(tar -tzf app.tar.gz)"
|
||||||
|
|
||||||
# Sanity: the box's `uv sync --frozen` needs pyproject.toml + uv.lock at the root,
|
# Sanity: the box's `uv sync --frozen` needs pyproject.toml + uv.lock at the root,
|
||||||
# and the package itself (agent/). Fail loudly here rather than on the box.
|
# and the package itself (agent/). Fail loudly here rather than on the box.
|
||||||
for required in pyproject.toml uv.lock agent/server.py langgraph.json; do
|
for required in pyproject.toml uv.lock agent/server.py langgraph.json; do
|
||||||
tar -tzf app.tar.gz | grep -qx "${required}" || {
|
printf '%s\n' "${APP_LIST}" | grep -qx "${required}" || {
|
||||||
echo "ERROR: app.tar.gz is missing ${required}" >&2
|
echo "ERROR: app.tar.gz is missing ${required}" >&2
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|
@ -36,9 +42,9 @@ done
|
||||||
# extensions so credential-handling *source* (e.g. team_credentials.py) is not a
|
# extensions so credential-handling *source* (e.g. team_credentials.py) is not a
|
||||||
# false positive.
|
# false positive.
|
||||||
SECRET_RE='(^|/)(\.env(\..+)?|id_rsa|.*\.(pem|key|p12|pfx)|.*(secret|credential|password|token)s?\.(json|ya?ml|txt|env|ini|cfg))$'
|
SECRET_RE='(^|/)(\.env(\..+)?|id_rsa|.*\.(pem|key|p12|pfx)|.*(secret|credential|password|token)s?\.(json|ya?ml|txt|env|ini|cfg))$'
|
||||||
if tar -tzf app.tar.gz | grep -qiE "${SECRET_RE}"; then
|
if printf '%s\n' "${APP_LIST}" | grep -qiE "${SECRET_RE}"; then
|
||||||
echo "ERROR: app.tar.gz contains a secret-shaped file — refusing to publish:" >&2
|
echo "ERROR: app.tar.gz contains a secret-shaped file — refusing to publish:" >&2
|
||||||
tar -tzf app.tar.gz | grep -iE "${SECRET_RE}" >&2
|
printf '%s\n' "${APP_LIST}" | grep -iE "${SECRET_RE}" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue