fix(release-agent): restore go's hermetic HOME, and record what #440 excluded #486
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!486
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/release-agent-hermetic-go"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two corrections to #440, both mine, found by a post-merge review.
1. Restore
env -u HOMEaround the go build#434 ran go as
nix shell nixpkgs#go_1_25 -c env -u HOME go build …specifically so go could not read$HOME/.config/go/env— a strayGOFLAGSorGOPROXYon the runner host would otherwise reach release binaries.Collapsing the three per-arch shells into one dropped that flag silently. Nothing broke (GOPATH/GOMODCACHE/GOCACHE are pinned explicitly and 0.1.61 built clean), but the hermeticity was deliberate and was not meant to go. It now wraps the whole build block, so it covers all three targets rather than a single invocation.
Checked before restoring it: nothing inside that block reads
HOME, so it is safe underset -u, and the Go cache vars are exported before the shell, soenv -u HOMEleaves them intact.2. Record that tag-via-git-push was deliberately excluded
#440 carried a fourth commit (
425448ef) replacing the tags REST call withgit push https://${GIT_API_TOKEN}@…. It was dropped during the rebase as superseded — but the squashed merge title on main still names it. A commit message advertising a change that is not in the tree is exactly how a future session re-derives it believing it was lost.The comment now records why it was refused:
psand git's own error output echoing the remote can leak itRUN_TOKENfallback with a single un-fallback-ed pathAnd the empirical part: the REST route has tagged 0.1.58, 0.1.59, 0.1.60 and 0.1.61 without once reaching the fallback, so
425448ef's premise ("the tags API returns 401 for it") no longer holds.Worth knowing separately
Main's
RUN_TOKENfallback has never executed in production — the primary path has won every release since it landed. It is untested insurance ifGIT_API_TOKENever expires.Also unaddressed here (harmless, left alone deliberately): the Build step now exports
HOMEtwice, at lines 75 and 80. The first wins, so the/tmp/forgegraph-release-homefallback is dead code and its explanatory comment describes a line that does nothing. Tidying it would be churn in a hot path for no behavioural gain.Preview environment is live: https://pr-486-forgegraph.forgegraf.com
Deployed
a784f9e7with the beta stage's environment. It redeploys on every push and is destroyed when this PR closes.