Watch
2
fix(ci): rebuild the image when a build input outside docker/ changes #1094
Closed
coilyco-ops
wants to merge 1 commit from
aos/claude/wt57-image-inputs-filter into main
pull from: aos/claude/wt57-image-inputs-filter
merge into: coilyco-flight-deck:main
coilyco-flight-deck:main
coilyco-flight-deck:release
coilyco-flight-deck:aos/claude/zc49-sound-optin
coilyco-flight-deck:aos/claude/zc49-creature-gentle
coilyco-flight-deck:aos/claude/zc49-creature-glare
coilyco-flight-deck:aos/claude/md68
coilyco-flight-deck:aos/claude/zc49-creature-numbers
coilyco-flight-deck:aos/claude/zc49-creature-background
coilyco-flight-deck:chore/full-name-attribution
coilyco-flight-deck:aos/claude/mt75-bundle-tag
coilyco-flight-deck:aos/claude/ad84-revert-voice
coilyco-flight-deck:aos/claude/ad84-voice
coilyco-flight-deck:aos/claude/tc69-abspath
coilyco-flight-deck:aos/claude/mt75-quiet-plan
coilyco-flight-deck:voice-no-rarity-statements
coilyco-flight-deck:aos/claude/mt75-netlify-remove
coilyco-flight-deck:aos/claude/ad84-titles
coilyco-flight-deck:aos/claude/ad84
coilyco-flight-deck:aos/claude/mt75-aterm-fullscreen
coilyco-flight-deck:aos/claude/mt75-netlify-wrap
coilyco-flight-deck:aos/claude/mt75-kubectl-context
coilyco-flight-deck:aos/claude/mt75
coilyco-flight-deck:aos/claude/mt75-ward-cut
coilyco-flight-deck:aos/claude/eb77
coilyco-flight-deck:aos/claude/fp87-ward-schema
coilyco-flight-deck:aos/claude/fp87-ward-posture
coilyco-flight-deck:aos/claude/fp87
coilyco-flight-deck:aos/claude/vt77
coilyco-flight-deck:aos/1105-require-issue-labels
coilyco-flight-deck:aos/claude/kb87-native-arch
coilyco-flight-deck:aos/claude/kb87-window-identity
coilyco-flight-deck:aos/claude/kb87
coilyco-flight-deck:aos/claude/tg69
coilyco-flight-deck:aos/claude/ff54-retire-issue-refs
coilyco-flight-deck:aos/claude/ff54
coilyco-flight-deck:aos/claude/rc44-bundle-version
coilyco-flight-deck:aos/claude/mu55-contract-tests
coilyco-flight-deck:aos/claude/mu55-sound-mark
coilyco-flight-deck:aos/claude/rc44
coilyco-flight-deck:aos/claude/mu55-identity-card
coilyco-flight-deck:aos/claude/mu55-doctor
coilyco-flight-deck:aos/claude/mu55-shadow-reap
coilyco-flight-deck:aos/claude/mu55-drop-windows
coilyco-flight-deck:aos/claude/mu55-dryrun-exits
coilyco-flight-deck:aos/claude/mu55-list-json
coilyco-flight-deck:aos/claude/mu55-title-order
coilyco-flight-deck:aos/claude/mu55-overlay-contract
coilyco-flight-deck:aos/claude/qu74
coilyco-flight-deck:aos/claude/ue86
coilyco-flight-deck:aos/claude/yq86
coilyco-flight-deck:aos/claude/vk48-harness-set
coilyco-flight-deck:aos/claude/vk48-default-agent
coilyco-flight-deck:aos/claude/vk48-completion
coilyco-flight-deck:aos/claude/vk48-release-fix
coilyco-flight-deck:aos/claude/vk48
coilyco-flight-deck:aos/claude/yb89
coilyco-flight-deck:aos/claude/sb46
coilyco-flight-deck:fix/agent-compose-pin-v3-roster
coilyco-flight-deck:aos/claude/ve67-defer
coilyco-flight-deck:aos/claude/ve67
coilyco-flight-deck:aos/claude/ur54
coilyco-flight-deck:aos/claude/tj49
coilyco-flight-deck:feat/acompose-v3-roster
coilyco-flight-deck:ops/393-retire-doc-size-alias
coilyco-flight-deck:ops/393-drop-em-dash-check
coilyco-flight-deck:feat/vendored-tree-exclude
coilyco-flight-deck:aos/claude/xlarge-band
coilyco-flight-deck:aos/claude/ue65
coilyco-flight-deck:aos/claude/identity-color-wins
coilyco-flight-deck:aos/claude/ap47
coilyco-flight-deck:aos/claude/zr44
coilyco-flight-deck:aos/claude/xk58
coilyco-flight-deck:aos/claude/aw85-skill-size-owner
coilyco-flight-deck:aos/claude/ym96-docs-bands
coilyco-flight-deck:aos/claude/wt57-pin-aos-bundle
coilyco-flight-deck:aos/claude/ym96-label-taxonomy
coilyco-flight-deck:ops/dev-base-pin-rust-1.90.0
coilyco-flight-deck:aos/claude/mg96-clean
coilyco-flight-deck:aos/claude/mg96
coilyco-flight-deck:backup/fix/bake-precommit-hooks
coilyco-flight-deck:rescue/aos-test-timeout
coilyco-flight-deck:aos/claude/issues-977-979-agents-base
coilyco-flight-deck:aos/claude/sx87
coilyco-flight-deck:refactor/remove-context-budget-json
coilyco-flight-deck:issue-946
coilyco-flight-deck:aos/codex/20260806t050901z-50407-6291ab0a
coilyco-flight-deck:aos/codex/standalone-shadow-workspace
coilyco-flight-deck:backup/aos/codex/20260806t061240z-10127-754d7de2
coilyco-flight-deck:aos/codex/standalone-local-service-route
coilyco-flight-deck:aos/codex/aosterm-aoscompose-wrapper
coilyco-flight-deck:aos/codex/agents-launch-profile-source
coilyco-flight-deck:aos/codex/launch-profiles-yaml
coilyco-flight-deck:aos/codex/20260806t031603z-7731-c76c17f2
coilyco-flight-deck:backup/aos/codex/20260805t183628z-5916-617bb239
coilyco-flight-deck:backup/aos/codex/20260805t025242z-30811-fbb135ff
coilyco-flight-deck:aos/codex/aos-v2-roster-852
coilyco-flight-deck:aos/codex/20260801t164712z-64119-69ee8bb6
coilyco-flight-deck:backup/aos/codex/20260801t164900z-67616-2ad2d0e3
coilyco-flight-deck:issue-834
coilyco-flight-deck:aos/codex/pr-829-1130
coilyco-flight-deck:issue-824-agent-proxy-model-routing
coilyco-flight-deck:task-merge-pr818
coilyco-flight-deck:fix/aos-ci-20260730
coilyco-flight-deck:issue-671
coilyco-flight-deck:issue-734
coilyco-flight-deck:issue-484
coilyco-flight-deck:issue-498
coilyco-flight-deck:issue-622
coilyco-flight-deck:issue-512
coilyco-flight-deck:issue-679
coilyco-flight-deck:issue-454
coilyco-flight-deck:backup/issue-785-first-person
coilyco-flight-deck:issue-785-first-person
coilyco-flight-deck:director-pr784
coilyco-flight-deck:restore-language-images
coilyco-flight-deck:recovery/2026-07-28-triaged-branch-archive
coilyco-flight-deck:recovery/2026-07-27-local-work
coilyco-flight-deck:recovery/aos-local-build-20260727
coilyco-flight-deck:codex/land-pr-733
coilyco-flight-deck:codex/aos-ci-watch
coilyco-flight-deck:issue-642
coilyco-flight-deck:issue-682-goose-yaml
coilyco-flight-deck:issue-656-goose-context
coilyco-flight-deck:safety/aos-local-main-09347d0
coilyco-flight-deck:issue-611-specialist-images
coilyco-flight-deck:fix-action-run-list-page
coilyco-flight-deck:issue-454-v2
coilyco-flight-deck:experiment/no-ops-forgejo
coilyco-flight-deck:feat/dev-base-image
No reviewers
Labels
Clear labels
burndown-2026-06
Backlog burndown June 2026
burndown-2026-08
Closed in the 2026-08-26 backlog burn-down. Reopen freely: state:closed label:burndown-2026-08 recovers the whole set.
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
coherence-core
Core review set for the warded control plane coherence milestone. These issues form the release spine; adjacent milestone issues are stretch or supporting work.
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
qa-fixture
Disposable issue admitted to the bounded Ward QA verification lane.
role/advocate
requires work from the Developer Advocate seat
role/director
requires work from the Portfolio Director seat
role/exec
requires work from the exec role
role/frontend
requires work from the Frontend Engineer seat
role/gamedev
requires work from the Game Developer seat
role/human
requires a person, and specifically not an agent seat
role/platform
requires work from the Platform Engineer seat
role/qa
requires work from the QA role
role/science
requires work from the Applied Scientist seat
role/sysadmin
requires work from the Systems Administrator seat
state
ambient
ambient and ephemeral work, held as a maintained document rather than a queue
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/agentic-os!1094
Loading…
Reference in a new issue
No description provided.
Delete branch "aos/claude/wt57-image-inputs-filter"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The verb you just merged in #1093 cannot reach a runner. Found while checking
what happens after the merge.
What is wrong
The dev-base path filters watch only
docker/**, butdocker-bake.hclpullsthree build contexts from elsewhere in the repo:
promote.ymlis unfiltered, so a change to any of them reaches thereleasebranch and looks landed.
dev-base-publishthen matches none of its watchedpaths and never fires, so
:releasekeeps the older binary.The failure is silent in both directions. No job fails, and the change appears
released. #1093 is on main and on release right now, and
aosguard ops telegram alertexists in neither the published image nor any runner.This is not specific to #1093. It covers every past guardfile edit and every
change to the embedded Python package.
dev-base-pr.ymlcarried the identical filter, so PR-time image validationskipped these inputs too. #1093 was never image-validated before merge either.
The fix
Both filters now watch every build context. The test derives the expected paths
from
docker-bake.hcl's owncontextsblocks rather than restating them, so anew context outside
docker/fails the check until its path is watched.Verified by mutation: dropping
.specgen/**from the filter fails the test withbuild contexts absent from the path filter: ['dev-base-publish.yml: .specgen'].Full file passes 12/12.
Still needed after this merges
This repairs the trigger going forward. #1093 already landed under the old
filter, so it needs one
dev-base-publishdispatch to reach the registry.Say the word and I will fire it, or you can, since it republishes the image
every CI job in the fleet pulls.
The dev-base path filters watched only `docker/**`, but docker-bake.hcl pulls three build contexts from elsewhere in the repo: aosguard-spec = ".specgen" aosguard-python = "agentic_os" repo-lists = "aos-cli/repositories" So a change to any of them promoted from main to release and never rebuilt the image that ships it. `promote.yml` is unfiltered, so the commit reaches `release` and looks landed, while `dev-base-publish` skips it and `:release` keeps the older binary. The failure is silent in both directions: no job fails, and the change appears released. Found immediately after #1093 landed `aosguard ops telegram alert`. That verb is on main and in the release branch right now, and no runner can call it, because a guardfile-only change matches none of the watched paths. The same hole covers every past guardfile edit and every change to the embedded Python package. `dev-base-pr.yml` carried the identical filter, so PR-time image validation skipped these inputs too. A guardfile change was never image-validated before merge either. The test derives the expected paths from docker-bake.hcl's own `contexts` blocks rather than restating them, so a new context outside docker/ fails the check until its path is watched. Verified by mutation: dropping `.specgen/**` from the filter fails the test. This fixes the trigger going forward. The already-merged #1093 still needs one `dev-base-publish` dispatch to reach the registry. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Kai Siren <coilysiren@gmail.com> Co-authored-by: Claude <noreply@anthropic.com>Pull request closed