Skip to content

Move the devcontainer pin when the matrix moves the lockfile - #78

Merged
tamnd merged 1 commit into
mainfrom
devcontainer-follows-the-lockfile
Sep 6, 2026
Merged

tamnd merged 1 commit into
mainfrom
devcontainer-follows-the-lockfile

Conversation

@tamnd

@tamnd tamnd commented Sep 6, 2026

Copy link
Copy Markdown
Owner

main is red. The build matrix published ten new digests in 23c16c5, containers/images.lock.json moved, and .devcontainer/devcontainer.json did not, so tests/test_devcontainer.py::test_the_digest_is_one_the_build_matrix_published fails on every branch since. The failure has nothing to do with the branch it shows up on, which is how it was found.

The lockfile and the devcontainer name one fact, so one command writes both.

  • tools.matrix.repin rewrites the "image" line from the lockfile row for the image the file already names, at PIN_ARCH, which is amd64 because Codespaces is. It is a pattern over the text and not a JSON round trip: eighteen lines of that file are a comment explaining the pin to a reader.
  • matrix record calls it, so the workflow step that folds the published digests in also moves the pin.
  • The workflow's commit it if it moved step now diffs and adds both files. Adding only the lockfile is the bug that produced this.
  • Eight tests, including one that asserts the committed pin is the one repin would write, which is the regression itself.

The stale pin is updated to sha256:65e31a4f..., the current rel:amd64 row.

matrix digests --check still reports the two missing boot rows. That is the M2 second gate (#21) and not this.

@tamnd
tamnd merged commit 185468b into main Sep 6, 2026
9 checks passed
@tamnd
tamnd deleted the devcontainer-follows-the-lockfile branch September 6, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant