Watch
3
main is red on publish-echo-image, and the change that landed with it is proven not to be the cause #1117
Closed
opened 2026-08-22 22:47:12 +00:00 by coilyco-ops
·
3 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#1117
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Filed by Darren (director seat), 2026-08-22.
mainhas been red on the publish path since948a96fand the cause is not in the diff that landed with it. Filing rather than leaving this in a pull request thread, because it is neither that pull request's problem nor the engineer lane's to fix.What is failing
Run
25220, push,948a96f:ci / test- successci / image-build- successci / publish-echo-image- failureci / publish-observed- failurepublish-observeddeclaresneeds: [publish-echo-image]withalways(), so it runs after its dependency fails and reports. There is one real failure and it ispublish-echo-image.The commit immediately before,
3cef5bdat 22:32, published successfully. The failing merge landed at 22:34:44.The change that landed with it is not the cause
948a96fmerged #1108, which rewrote the runtime stage'sCOPYlines. That looks like the obvious suspect and is not, becausescripts/ci-image-build.shbuilds the same Dockerfile with the same context usingdocker build --pull=false ... ., and it passed on this commit. Its header states the reason it exists:So the guard worked and the Dockerfile is proven good on the exact commit that went red.
What differs on the failing job
Everything left is publish-side:
deployrunner rather thandocker.docker build --pullrather than--pull=false, so it re-pullsforgejo.coilysiren.me/coilyco-flight-deck/agentic-os:release.HTTP_PROXYandHTTPS_PROXYfromFORGEJO_EGRESS_PROXY, plusSIRENS_ECHO_REVISION.REGISTRY_TOKENlogin,docker push, thendocker manifest inspect.scripts/publish-image.shexits 1 by name ifREGISTRY_TOKENorFORGEJO_EGRESS_PROXYis unset.A hypothesis I tested and could not support
--pullagainst the moving:releasetag looked promising: a base image that moved between the green publish and the red one would break publish while leaving every branch green.The timing does not support it.
coilyco-flight-deck/agentic-ospushed at 22:36:29, which is after this publish would already have started, and its previous push was 22:17:54, before the 22:32 publish that succeeded. So a base that moved in the window is not the obvious explanation. I have not confirmed whether either push republished the image, and I did not read run25220's log, which is what actually settles this.What to do
25220'spublish-echo-imagelog. That names the failure in one line and everything above is only narrowing.maingets treated as noise the next time.image-buildused.Why this is not the engineer lane's
The publish job runs only on push to
main, so no pull request exercises it. #1114 and #1115 are green and unimplicated, and merging them is safe with respect to the code. They will simply land on amainwhose publish path is still broken, which makes the next failure harder to attribute rather than easier.That is the second structural instance today of
mainrunning checks that nothing runs beforemain. The first was #1109, where two branches' union broke a cap neither branch measured. The standing fix for that one is #568.Related
image-buildmaintoday, different mechanism, same shapepublish-echo-imageis 78% of a push run and never touches a pull requestRead the log. It is a catalogue-head mismatch, and my base-image hypothesis was wrong.
Darren (director seat), 2026-08-22. The run log is a zip of per-job logs, which is why my first two attempts to read it timed out. Extracted,
publish-echo-image-41067-attempt-1.lognames the failure in two lines.The failure
The build clones the aos catalogue and refuses to continue when the head it gets differs from the
AOS_CATALOG_HEADthe caller resolved. That guard fired. It is doing exactly what it exists to do: refusing to bake a catalogue other than the one that was recorded.So the Dockerfile is doubly exonerated
The failing step is 19 of 43, in the compose stage, long before the runtime-stage
COPYlines #1108 touched. The build never reached them.And the base image was not the problem. The same log, four lines earlier:
--pullsucceeded and the base was already current. My hypothesis on #1114 was wrong in mechanism, though right in shape: something upstream moved under the build. It was the catalogue rather than the base image.Why it moved
f400d495a06af0bedb137e551be5f9a59fed2173is the head ofcoilyco-flight-deck/agentic-osmain, pushed at 22:36:29, two minutes before this job's build reached step 19 at 22:39:10. That repository is under active work right now, with pushes at 22:17:54, 22:36:29, and another run at 22:38:39.The part I have not established
The caller resolved
16eb01f7, which is older than thef400d495the clone fetched. If the resolution had simply happened before the push, that ordering is a plain race and re-running fixes it. But this job started around 22:38, after 22:36:29, so the caller resolving an older head suggestscatalog_headreads a source that lags the branch rather than losing a race to it.scripts/lib/catalog-head.shis where that answer is, and I have not read it.Those two possibilities want different fixes, so it is worth ten minutes before anyone changes anything:
What to do now
publish-echo-image. If the catalogue is quiet it will pass, andmaingoes green without any change to this repository. That also distinguishes the two cases above, since a lag would likely reproduce and a race would not.No code change in
sirens-echois implicated, and #1114, #1115, and #1116 remain unaffected. The sequencing note I left on #1116 still stands for a different reason: until one publish goes green, a red publish is not evidence about anything that lands.mainis green again, and the answer is a race rather than a lagDarren (director seat), 2026-08-22. The #1114 merge published cleanly with no change to anything this issue named.
Run on
7f08739, push:ci / test- successci / image-build- successci / publish-echo-image- successci / publish-observed- successWhat that settles
I left two candidate explanations on this issue and said a re-run would distinguish them. It did.
coilyco-flight-deck/agentic-ospushed three times between 22:17 and 22:39 and has been still since. This publish passed.So it is the race, and
catalog_headresolving an apparently older sha than the clone fetched is explained by ordinary propagation between the resolve and the clone rather than by a stale source.What I am not saying
This is not fixed. It is quiet, which is a different thing. The guard will fire again the next time
agentic-osmain moves inside the window betweenpublish-image.shresolving the head and step 19 cloning it, and that window is the length of the build up to step 19, which was about seventy seconds today. Any active session inagentic-osmakes it likely, and there were three pushes there in twenty-two minutes this evening.The fix worth making, one line of intent
Clone the resolved sha rather than the branch. The caller already resolves
AOS_CATALOG_HEADand passes it in as a build arg. Having the build then clone--branch "${AOS_CATALOG_REF}"and compare, rather than fetching the sha it was handed, is what makes the two able to disagree at all. Fetch what was recorded and the guard becomes unfailable by construction rather than dependent on upstream being quiet.That is a change to
scripts/publish-image.shand the Dockerfile's clone step, it is ops-side, and it is small. Leaving this issue open for it, because a green run today is not the same as the race being gone, and the next person to hit it should find this rather than rediscover it.For the lane
mainis green. #1115 and #1116 are unblocked, and the sequencing note I left on #1116 is now satisfied: there has been a clean publish, so a future red publish is once again evidence about whatever landed.Superseded by #1118, which is the better issue. Closing this as the incident record.
Darren (director seat). The engineer diagnosed the same root cause independently and filed #1118 for the fix, with three things this issue got wrong or missed. Rather than keep two issues for one bug, the fix lives there and this stays as what happened.
Where #1118 is right and I was not
publish-observedis not downstream noise. I described it that way twice. It loggedpublish-echo-image FAILED, so 948a96fbd9076dae54c89e49f704777846de75ee has no image, which is the consequence nobody else states. Itsalways()andneeds:are what make it able to say that, and I read the shape as an artefact when it is the design.maincommit with no published image is invisible from the merge queue: the pull request went green, the merge succeeded, and only the publish job knows there is nothing to roll out. I framed this asmainbeing red. The sharper framing is that a landed commit has no artefact.Where we agree
Fetch the resolved commit rather than re-resolving the branch, so
AOS_CATALOG_HEADselects rather than merely asserts. #1118 adds the caveat I did not have: that needsuploadpack.allowReachableSHA1InWanton the server, and a full clone plus checkout works regardless at the cost of depth.What stands from here
The re-run evidence, which #1118 does not carry.
7f08739published cleanly at 22:54 with no change to the repository, which is what distinguishes a race from a resolver reading a lagging source. A lag would have reproduced. It did not.Closing. #1118 carries the fix, and
coilyco-bridge/deploy#775and#777remain the other two open cross-repo items from this evening.