Public Access
Compare commits
8
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
012f0979ce | ||
|
|
62412755cb | ||
|
|
25f00335df | ||
|
|
fa32df2f22 | ||
|
|
2d7b4bdac3 | ||
|
|
5986b5b9ed | ||
|
|
34c7f3782c | ||
|
|
e123d7050f |
@@ -77,6 +77,9 @@ jobs:
|
||||
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
|
||||
PYTHONPATH: src
|
||||
# Serialize blob uploads to avoid Gitea registry race condition
|
||||
# (BlobUploader.Append offset mismatch — see DEVX-162).
|
||||
DOCKER_MAX_CONCURRENT_UPLOADS: "1"
|
||||
run: |
|
||||
. .venv/bin/activate
|
||||
export PATH="$HOME/.local/bin:$PATH"
|
||||
|
||||
@@ -2,6 +2,22 @@
|
||||
|
||||
All notable changes to this project will be documented in this file.
|
||||
|
||||
## [0.51.5] - 2026-08-26
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
- Check stdout for HTTP 500 in _run_push (docker sends to stdout)
|
||||
|
||||
## [0.51.4] - 2026-08-26
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
- Serialize registry uploads and retry on HTTP 500
|
||||
|
||||
### Refactor
|
||||
|
||||
- Remove cross-repo contract tests from devx
|
||||
|
||||
## [0.51.3] - 2026-08-26
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
@@ -16,12 +16,12 @@ quality badges.
|
||||
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||
[](https://www.python.org/downloads/)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||
[](https://www.python.org/downloads/)
|
||||
|
||||
## Why devx?
|
||||
|
||||
@@ -87,7 +87,7 @@ extra index and list devx in your dependencies:
|
||||
```toml
|
||||
[project]
|
||||
dependencies = [
|
||||
"devx>=0.51.3",
|
||||
"devx>=0.51.5",
|
||||
]
|
||||
|
||||
[tool.pip]
|
||||
@@ -101,8 +101,8 @@ pip install -e .
|
||||
```
|
||||
|
||||
> **Note:** If your project requires a specific devx version, pin it in
|
||||
> `dependencies` (for example, `"devx==0.51.3"`) or use a version constraint
|
||||
> (for example, `"devx>=0.51.3,<0.52"`).
|
||||
> `dependencies` (for example, `"devx==0.51.5"`) or use a version constraint
|
||||
> (for example, `"devx>=0.51.5,<0.52"`).
|
||||
|
||||
### Optional extras
|
||||
|
||||
|
||||
+8
-8
@@ -12,12 +12,12 @@ project to be reusable across all oblachno-oss repositories.
|
||||
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||
[](https://www.python.org/downloads/)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||
[](https://www.python.org/downloads/)
|
||||
|
||||
## Overview
|
||||
|
||||
@@ -74,14 +74,14 @@ Add devx to your `pyproject.toml` dependencies and configure the registry:
|
||||
```toml
|
||||
[project]
|
||||
dependencies = [
|
||||
"devx>=0.51.3",
|
||||
"devx>=0.51.5",
|
||||
]
|
||||
|
||||
[tool.pip]
|
||||
extra-index-url = "https://git.oblachno.oblachno.fyi/api/packages/oblachno-oss/pypi/simple"
|
||||
```
|
||||
|
||||
Pin a specific version if needed: `"devx==0.51.3"` or `"devx>=0.51.3,<0.52"`.
|
||||
Pin a specific version if needed: `"devx==0.51.5"` or `"devx>=0.51.5,<0.52"`.
|
||||
|
||||
### Optional extras
|
||||
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
# DEVX-162: Fix registry push race condition: serialize uploads + retry on HTTP 500
|
||||
|
||||
## Problem
|
||||
The Gitea container registry (v1.27.2) has a known race condition in
|
||||
`BlobUploader.Append()` where concurrent blob uploads cause the file
|
||||
offset and DB model to get out of sync, producing HTTP 500 "offset
|
||||
mismatch between file and model" errors. This causes the build-images
|
||||
workflow to fail intermittently when pushing runner images.
|
||||
|
||||
The `package_blob_upload` table accumulates stale entries from failed
|
||||
uploads that worsen the problem over time.
|
||||
|
||||
## Approach
|
||||
Two fixes in devx (a third fix — scheduled cleanup — is tracked
|
||||
separately as OBL-INFRA-537):
|
||||
|
||||
1. Set `DOCKER_MAX_CONCURRENT_UPLOADS=1` in the build-images workflow
|
||||
to serialize blob uploads and avoid the race condition.
|
||||
|
||||
2. Add HTTP 500 retry logic to `push_image` in `build_image.py`.
|
||||
When a push fails with HTTP 500 (not "already exists"), retry up
|
||||
to 3 times with exponential backoff (5s, 10s, 20s).
|
||||
|
||||
REQ-1: Build-images workflow sets DOCKER_MAX_CONCURRENT_UPLOADS=1
|
||||
REQ-2: push_image retries on HTTP 500 with exponential backoff
|
||||
REQ-3: All existing tests pass with 100% coverage
|
||||
|
||||
## Test Plan
|
||||
- Unit tests for retry logic (mock subprocess)
|
||||
- Manual: trigger build-images workflow and verify push succeeds
|
||||
|
||||
## Deploy Plan
|
||||
- Merge to master
|
||||
|
||||
## Rollback Plan
|
||||
- Revert the merge commit
|
||||
|
||||
## Acceptance Criteria
|
||||
- [x] REQ-1: Build-images workflow sets DOCKER_MAX_CONCURRENT_UPLOADS=1
|
||||
- [x] REQ-2: push_image retries on HTTP 500 with exponential backoff
|
||||
- [x] REQ-3: All existing tests pass with 100% coverage
|
||||
@@ -0,0 +1,33 @@
|
||||
# DEVX-163: Fix _run_push to check stdout for HTTP 500
|
||||
|
||||
## Problem
|
||||
`_run_push` only checked `result.stderr` for HTTP 500, but docker push
|
||||
sends the "received unexpected HTTP status: 500 Internal Server Error"
|
||||
message to **stdout**, not stderr. This means the tenacity retry logic
|
||||
added in DEVX-162 never triggered — the push failed immediately without
|
||||
retrying.
|
||||
|
||||
## Approach
|
||||
Check both `result.stdout` and `result.stderr` for the "500" status code.
|
||||
Also update the "already exists" check in `push_image` to check both
|
||||
streams, since docker may send that message to stdout as well.
|
||||
|
||||
REQ-1: _run_push checks both stdout and stderr for HTTP 500
|
||||
REQ-2: push_image "already exists" check uses combined stdout+stderr
|
||||
REQ-3: All existing tests pass with 100% coverage
|
||||
|
||||
## Test Plan
|
||||
- Unit tests for stdout 500 detection
|
||||
- Unit tests for stderr 500 detection
|
||||
- Manual: trigger build-images workflow and verify retry works
|
||||
|
||||
## Deploy Plan
|
||||
- Merge to master
|
||||
|
||||
## Rollback Plan
|
||||
- Revert the merge commit
|
||||
|
||||
## Acceptance Criteria
|
||||
- [x] REQ-1: _run_push checks both stdout and stderr for HTTP 500
|
||||
- [x] REQ-2: push_image "already exists" check uses combined stdout+stderr
|
||||
- [x] REQ-3: All existing tests pass with 100% coverage
|
||||
@@ -48,12 +48,12 @@ Add devx to your `pyproject.toml`:
|
||||
```toml
|
||||
[project]
|
||||
dependencies = [
|
||||
"devx>=0.51.3",
|
||||
"devx>=0.51.5",
|
||||
]
|
||||
|
||||
[project.optional-dependencies]
|
||||
dev = [
|
||||
"devx>=0.51.3",
|
||||
"devx>=0.51.5",
|
||||
]
|
||||
```
|
||||
|
||||
|
||||
@@ -6,4 +6,4 @@ create_dependency_pr, auto_merge, release, publish), developer tooling
|
||||
molecule testing helpers for Ansible projects.
|
||||
"""
|
||||
|
||||
__version__ = "0.51.3"
|
||||
__version__ = "0.51.5"
|
||||
|
||||
@@ -50,6 +50,7 @@ from dataclasses import dataclass, field
|
||||
from pathlib import Path
|
||||
|
||||
import click
|
||||
from tenacity import retry, retry_if_exception_type, stop_after_attempt, wait_exponential
|
||||
|
||||
from devx.i18n import _
|
||||
from devx.tokens import get_developer_token
|
||||
@@ -254,6 +255,34 @@ def delete_remote_manifest(
|
||||
return True
|
||||
|
||||
|
||||
class PushHTTP500Error(Exception):
|
||||
"""Raised when docker push fails with an HTTP 500 from the registry."""
|
||||
|
||||
|
||||
def _run_push(cmd: list[str]) -> subprocess.CompletedProcess[str]:
|
||||
"""Run a docker push command, raising PushHTTP500Error on registry 500.
|
||||
|
||||
The Gitea container registry (v1.27.x) has a race condition in
|
||||
BlobUploader.Append that causes intermittent HTTP 500 "offset
|
||||
mismatch" errors during concurrent blob uploads. Retrying the
|
||||
push gives the registry time to recover.
|
||||
|
||||
Docker sends push progress/errors to both stdout and stderr depending
|
||||
on the error type, so both streams are checked for the 500 status.
|
||||
"""
|
||||
result = subprocess.run( # nosec B603
|
||||
cmd,
|
||||
capture_output=True,
|
||||
text=True,
|
||||
check=False,
|
||||
)
|
||||
if result.returncode != 0:
|
||||
combined = f"{result.stderr}\n{result.stdout}"
|
||||
if "500" in combined:
|
||||
raise PushHTTP500Error(combined.strip())
|
||||
return result
|
||||
|
||||
|
||||
def push_image(
|
||||
spec: ImageSpec,
|
||||
registry: str,
|
||||
@@ -270,6 +299,9 @@ def push_image(
|
||||
with Gitea #31964 ("package version already exists") do we delete
|
||||
the old manifest and retry. This avoids losing the existing tag
|
||||
when the push fails for unrelated reasons (e.g. HTTP 500).
|
||||
|
||||
HTTP 500 errors from the Gitea registry race condition are retried
|
||||
up to 3 times with exponential backoff (5s, 10s) via tenacity.
|
||||
"""
|
||||
full_tags = [build_full_tag(registry, spec.name, t) for t in spec.tags]
|
||||
all_ok = True
|
||||
@@ -279,19 +311,33 @@ def push_image(
|
||||
click.echo(f"[dry-run] {' '.join(cmd)}")
|
||||
continue
|
||||
click.echo(f"Pushing {ft}...")
|
||||
result = subprocess.run( # nosec B603
|
||||
cmd,
|
||||
capture_output=True,
|
||||
text=True,
|
||||
check=False,
|
||||
|
||||
@retry(
|
||||
stop=stop_after_attempt(3),
|
||||
wait=wait_exponential(multiplier=5, min=5, max=20),
|
||||
retry=retry_if_exception_type(PushHTTP500Error),
|
||||
reraise=True,
|
||||
)
|
||||
def _attempt(_cmd: list[str] = cmd) -> subprocess.CompletedProcess[str]:
|
||||
return _run_push(_cmd)
|
||||
|
||||
try:
|
||||
result = _attempt()
|
||||
except PushHTTP500Error as e:
|
||||
click.echo(
|
||||
_("Push failed for {tag}: {error}", tag=ft, error=str(e)),
|
||||
err=True,
|
||||
)
|
||||
all_ok = False
|
||||
continue
|
||||
|
||||
if result.returncode == 0:
|
||||
click.echo(f"Pushed {ft}")
|
||||
continue
|
||||
stderr = result.stderr.strip()
|
||||
combined_output = f"{result.stderr}\n{result.stdout}".strip()
|
||||
# Gitea #31964: push fails because tag already exists.
|
||||
# Delete the old manifest and retry once.
|
||||
if username and token and "already exists" in stderr.lower():
|
||||
if username and token and "already exists" in combined_output.lower():
|
||||
click.echo(" Tag exists (Gitea #31964), deleting old manifest and retrying...")
|
||||
delete_remote_manifest(
|
||||
registry,
|
||||
@@ -311,9 +357,9 @@ def push_image(
|
||||
if result.returncode == 0:
|
||||
click.echo(f"Pushed {ft} (after retry)")
|
||||
continue
|
||||
stderr = result.stderr.strip()
|
||||
combined_output = f"{result.stderr}\n{result.stdout}".strip()
|
||||
click.echo(
|
||||
_("Push failed for {tag}: {error}", tag=ft, error=stderr),
|
||||
_("Push failed for {tag}: {error}", tag=ft, error=combined_output),
|
||||
err=True,
|
||||
)
|
||||
all_ok = False
|
||||
|
||||
@@ -13,6 +13,7 @@ from click.testing import CliRunner
|
||||
import devx.tools.build_image as build_image
|
||||
from devx.tools.build_image import (
|
||||
ImageSpec,
|
||||
PushHTTP500Error,
|
||||
build_full_tag,
|
||||
delete_remote_manifest,
|
||||
load_manifest,
|
||||
@@ -242,7 +243,7 @@ class TestPushImage:
|
||||
"""Gitea #31964: push fails with 'already exists', delete + retry."""
|
||||
spec = ImageSpec(name="ci-base", dockerfile="Dockerfile", tags=["latest"])
|
||||
results = [
|
||||
MagicMock(returncode=1, stderr="500 Internal Server Error: already exists", stdout=""),
|
||||
MagicMock(returncode=1, stderr="package version already exists", stdout=""),
|
||||
MagicMock(returncode=0, stderr="", stdout=""),
|
||||
]
|
||||
with (
|
||||
@@ -260,11 +261,9 @@ class TestPushImage:
|
||||
)
|
||||
|
||||
def test_no_delete_on_non_already_exists_failure(self) -> None:
|
||||
"""Push fails for other reasons (HTTP 500) — old manifest preserved."""
|
||||
"""Push fails for other reasons (non-500) — old manifest preserved."""
|
||||
spec = ImageSpec(name="ci-base", dockerfile="Dockerfile", tags=["latest"])
|
||||
mock_result = MagicMock(
|
||||
returncode=1, stderr="received unexpected HTTP status: 500 Internal Server Error", stdout=""
|
||||
)
|
||||
mock_result = MagicMock(returncode=1, stderr="denied: requested access to the resource is denied", stdout="")
|
||||
with (
|
||||
patch("devx.tools.build_image.subprocess.run", return_value=mock_result),
|
||||
patch("devx.tools.build_image.delete_remote_manifest") as mock_del,
|
||||
@@ -276,7 +275,7 @@ class TestPushImage:
|
||||
"""Gitea #31964 retry also fails — both pushes fail."""
|
||||
spec = ImageSpec(name="ci-base", dockerfile="Dockerfile", tags=["latest"])
|
||||
results = [
|
||||
MagicMock(returncode=1, stderr="500 Internal Server Error: already exists", stdout=""),
|
||||
MagicMock(returncode=1, stderr="package version already exists", stdout=""),
|
||||
MagicMock(returncode=1, stderr="push failed again", stdout=""),
|
||||
]
|
||||
with (
|
||||
@@ -285,6 +284,73 @@ class TestPushImage:
|
||||
):
|
||||
assert push_image(spec, "git.example.com", username="user", token="tok") is False
|
||||
|
||||
def test_http_500_retries_then_succeeds(self) -> None:
|
||||
"""HTTP 500 from registry race condition — retry succeeds."""
|
||||
spec = ImageSpec(name="ci-base", dockerfile="Dockerfile", tags=["latest"])
|
||||
results = [
|
||||
MagicMock(returncode=1, stderr="", stdout="received unexpected HTTP status: 500 Internal Server Error"),
|
||||
MagicMock(returncode=0, stderr="", stdout=""),
|
||||
]
|
||||
with (
|
||||
patch("devx.tools.build_image.subprocess.run", side_effect=results),
|
||||
patch("devx.tools.build_image.delete_remote_manifest") as mock_del,
|
||||
patch("time.sleep"),
|
||||
):
|
||||
assert push_image(spec, "git.example.com", username="user", token="tok") is True
|
||||
mock_del.assert_not_called()
|
||||
|
||||
def test_http_500_retries_all_fail(self) -> None:
|
||||
"""HTTP 500 retries exhausted — push fails, no delete attempted."""
|
||||
spec = ImageSpec(name="ci-base", dockerfile="Dockerfile", tags=["latest"])
|
||||
mock_result = MagicMock(
|
||||
returncode=1, stderr="", stdout="received unexpected HTTP status: 500 Internal Server Error"
|
||||
)
|
||||
with (
|
||||
patch("devx.tools.build_image.subprocess.run", return_value=mock_result),
|
||||
patch("devx.tools.build_image.delete_remote_manifest") as mock_del,
|
||||
patch("time.sleep"),
|
||||
):
|
||||
assert push_image(spec, "git.example.com", username="user", token="tok") is False
|
||||
mock_del.assert_not_called()
|
||||
|
||||
def test_run_push_raises_on_500_stderr(self) -> None:
|
||||
"""_run_push raises PushHTTP500Error when stderr contains 500."""
|
||||
from devx.tools.build_image import _run_push
|
||||
|
||||
mock_result = MagicMock(returncode=1, stderr="HTTP 500 Internal Server Error", stdout="")
|
||||
with patch("devx.tools.build_image.subprocess.run", return_value=mock_result):
|
||||
with pytest.raises(PushHTTP500Error, match="HTTP 500"):
|
||||
_run_push(["docker", "push", "img:latest"])
|
||||
|
||||
def test_run_push_raises_on_500_stdout(self) -> None:
|
||||
"""_run_push raises PushHTTP500Error when stdout contains 500 (docker sends to stdout)."""
|
||||
from devx.tools.build_image import _run_push
|
||||
|
||||
mock_result = MagicMock(
|
||||
returncode=1, stderr="", stdout="received unexpected HTTP status: 500 Internal Server Error"
|
||||
)
|
||||
with patch("devx.tools.build_image.subprocess.run", return_value=mock_result):
|
||||
with pytest.raises(PushHTTP500Error, match="500"):
|
||||
_run_push(["docker", "push", "img:latest"])
|
||||
|
||||
def test_run_push_no_raise_on_non_500(self) -> None:
|
||||
"""_run_push returns result when stderr has no 500."""
|
||||
from devx.tools.build_image import _run_push
|
||||
|
||||
mock_result = MagicMock(returncode=1, stderr="denied: access denied", stdout="")
|
||||
with patch("devx.tools.build_image.subprocess.run", return_value=mock_result):
|
||||
result = _run_push(["docker", "push", "img:latest"])
|
||||
assert result.returncode == 1
|
||||
|
||||
def test_run_push_no_raise_on_success(self) -> None:
|
||||
"""_run_push returns result on success."""
|
||||
from devx.tools.build_image import _run_push
|
||||
|
||||
mock_result = MagicMock(returncode=0, stderr="", stdout="")
|
||||
with patch("devx.tools.build_image.subprocess.run", return_value=mock_result):
|
||||
result = _run_push(["docker", "push", "img:latest"])
|
||||
assert result.returncode == 0
|
||||
|
||||
|
||||
class TestDeleteRemoteManifest:
|
||||
def test_dry_run(self) -> None:
|
||||
|
||||
Reference in New Issue
Block a user