diff --git a/AGENTS.md b/AGENTS.md index 27e305d..83b03c6 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -89,8 +89,10 @@ them. Revisit only if the stated reason stops holding. - **CI docker logins share the runner host's Docker config.** The act_runner is host-mode, so `docker login`/`logout` in the workflows mutate one shared `~/.docker/config.json`: concurrent jobs can race (one job's logout can 401 another's push — recover by re-running), - and tokens sit in that file between login and logout. Accepted for a single-maintainer - cadence; serialize with a workflow `concurrency` group if it ever bites. + and tokens sit in that file between login and logout. Same class: concurrent runs share the + workspace dir, so ci.sh's web-image build races another run's container creation on the + `-web` tag. Accepted for a single-maintainer cadence; serialize with a workflow + `concurrency` group if it ever bites. ## Docker only — no host tooling diff --git a/ci.sh b/ci.sh index f78f8d2..d82cc16 100755 --- a/ci.sh +++ b/ci.sh @@ -40,6 +40,12 @@ pkg=$(grep -oE '"@playwright/test": "[0-9.]+"' e2e-tests/package.json | grep -oE [ -n "$img" ] && [ "$img" = "$pkg" ] || { echo "Playwright pin mismatch/unreadable: image v$img vs @playwright/test $pkg"; exit 1; } echo "ok ($img)" +# Explicit rebuild: without it a stale web image from a previous branch supplies node_modules +# (the source is bind-mounted but deps are baked in), so a dep bump gets typechecked/tested +# against the OLD packages. Cheap when deps are unchanged (npm ci layer is cache-keyed). +step "Build web image" +docker compose build web + step "Typecheck" docker compose run --rm --no-deps web npm run typecheck