fix(harbor): build the runtime image from a clean clone of HEAD - #587
Merged
ShuxinLin merged 2 commits intoSep 30, 2026
Merged
Conversation
base-image/Dockerfile does `COPY . .`, so building from the working tree baked in whatever sat there. An untracked reports/results_table.csv with a ground_truth column for 56 private scenarios (8 of mini, 41 of lite) reached assetopsbench/runtime:dev that way, readable by any agent running code in `main`, and publish-images.sh would have pushed it. scripts/build-runtime-image.sh now builds from a one-commit clone of HEAD, so only committed files enter the context. The clone keeps a real .git, which StirrupAgent.get_version_command needs for `git rev-parse`; a git worktree's .git pointer would not resolve inside the container. publish-images.sh, run.sh and the docs use the script. .dockerignore stays as the second guard, and the only one for a plain `docker build .`: env files at any depth (a bare `.env` matched only the context root), the open scenarios' answer files, which the verifier never reads from the image, and the local folders reports/, logs/, src/tmp/, .claude/ and the kdd_tutorial work. Signed-off-by: Shuxin Lin <linshuhsin@gmail.com>
Review of #587: the one-commit .git the clean clone kept still held every committed blob, so `git show HEAD:.../groundtruth.txt` returned the open scenarios' answers that .dockerignore had dropped from the tree. Its reflog also recorded the builder's name and email, and its index and reflog changed on every clone, so `COPY . .` never hit the cache and each build re-downloaded the models. build-runtime-image.sh now builds from `git archive HEAD` and passes the commit as the AOB_COMMIT build arg. .dockerignore drops .git. A `commit` stage in base-image/Dockerfile writes /opt/aob/.aob-commit, which StirrupAgent.get_version_command now reads, and fails any build without AOB_COMMIT, so a plain `docker build .` of the working tree stops instead of baking in untracked files. The ARG lives only in that stage, so a new commit invalidates the final layer and nothing else. The script also keeps its default tag and --load when given other flags (e.g. --no-cache), warns about untracked files it leaves out, and checks for docker buildx up front. Signed-off-by: Shuxin Lin <linshuhsin@gmail.com>
Collaborator
Author
|
Second review pass, addressed in 47a806e:
Verification:
Not changed:
|
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
base-image/DockerfiledoesCOPY . ., so building from the working tree baked in whatever was there. That included an untrackedreports/results_table.csvwith aground_truthcolumn for 56 private scenarios (8 of mini's 35, 41 of lite's 76). The file was in/opt/aobofassetopsbench/runtime:dev, where any agent running code inmaincould read it, andpublish-images.shwould have pushed it to Docker Hub.This PR applies two guards:
scripts/build-runtime-image.shbuilds from a clone of HEAD that contains only that commit, so untracked and git-ignored files never enter the build..dockerignore. It is the second guard, and the only one for a plaindocker build ..Fix Details
scripts/build-runtime-image.shdocker buildx build, and deletes the clone.assetopsbench/runtime:dev --load. Any arguments go to buildx unchanged..git, sogit rev-parseinStirrupAgent.get_version_commandstill works. Agit worktreewouldn't work, because its.gitis a pointer that doesn't resolve inside the container.publish-images.shbuilds the runtime image through the script.run.sh's error message,README,QUICKSTART,CODE-SANDBOXand the Dockerfile header now point at the script too..dockerignore**/.env/**/.env.*; the bare.envonly matched at the top of the repo.groundtruth*,rubric.json,reference_answer.jsonandscenario_meta.json. The verifier reads the copies under/tests, never these.reports/,logs/,src/tmp/,.claude/and the kdd_tutorial folders.Depends on #586 for the open profile. On this branch the generator still copies each scenario's
groundtruth.txtinto the task's build folder, so the per-task layer puts it back. #586 stops that. The two branches merge cleanly (checked withgit merge-tree).Impact on Benchmarking
Related Issues
Verification Steps
uv run pytest: not run. No Python changed.Rebuilt
assetopsbench/runtime:devwith the script from b7a7d84. It is 8.79 GB, down from 8.92 GB, and the temp clone was removed afterwards.Old image vs new image:
reports/results_table.csvlogs/,src/tmp/,.claude/, kdd_tutorial folders/opt/aobgit rev-parse --short HEAD0c45322b7a7d84.git.gitsizeharbor run --agent oracleon the open profile with the new image: 3 trials, 0 exceptions, reward 1.000. The verifier scores correctly without answers in the image.With fix(harbor): run.sh mounts only the private suite's shared/ #586's generator and overlay, the tsfm-1019 task container on the new image has no answer-looking file anywhere, and the data load filled all 5 collections.
bash -npasses for all three scripts.publish-images.shwas not run (it pushes).Checklist