Repository navigation
task image: remove git history after HEAD so the upstream fix is not on disk - #46
Merged
ArjunS07 merged 3 commits intoOct 8, 2026
Merged
Conversation
…on disk; fix the ref check that never failed
…nftest' into fix/prune-git-history # Conflicts: # src/datasmith/harbor_adapter/template/environment/Dockerfile
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Task images keep the upstream history after the base commit.
lock_repo_to_current_commitdeletes branches but never prunes, sogit fsck --unreachableshows the fix commit (networkx 8138:2573bd3b, numpy 21464:cfbbde8ae7). This PR removes that history as the last step of the task image build, and fails the build if any remains.How it works
Changes
scrub_git.shin the task image.Effect: it deletes refs that are not ancestors of HEAD, expires reflogs, and runs
gc --prune=now. It keeps ancestor tags, sogit describe(and versioneer) gives the same version. It pinscore.abbrev, so the short hash keeps its length. The build fails if HEAD, tree, describe or status change, or if any later commit or ref remains.Before: 144 to 29,479 commits newer than HEAD in every image checked (59 of 59).
docker_build_run.sh.Effect: a ref ahead of HEAD now makes
lock_repo_to_current_commitreturn 1.Before:
exit 0inside the check loop ended the whole build script with success, so the check could never fail. Later steps in the script were skipped.Verification
pytest tests/docker/test_scrub_git.py: 2 passed. The test makes a repo with a later fix commit and tag, runs the script, and checks that HEAD and describe are equal, the later tag is gone, and the fix object is gone.scrub_git.shon real images (docker run --network none): networkx 8138, numpy 21464, and dask 11754 all printscrub_git: ok. numpy 21464 keepsv1.23.0.dev0-1185-g7987557291.tests/dockerand the adapter tests: 7 failures, the same 7 as on 5c3b08e without this change.Notes
render_source_sha256, so images need a rebuild to pick this up. Existing images get the same scrub as a thin layer fromscripts/scrub_image_git.py(formulacode-verified-rl #72).originURL stays:lsv_init.pyandrun-tests.shget the package name from it. Trials need no network for it to be harmless (separate PR).