fix(ci): sweep stale root-owned coverage workspaces on the OpenCode runner - #2517
Conversation
…unner The coverage sandbox writes $RUNNER_TEMP/opencode-coverage-<run>-<attempt> as root, so the runner's per-job temp cleanup cannot remove them; about a dozen accumulated on cwlab-s1-04 again after the 2026-09-29 cleanup. #2491 removes the current run's workspace at job end, but runs dispatched before it, or jobs that never reach cleanup, leave theirs behind. The "Reclaim stale coverage images" step now also removes, with the sudo the job already uses, only run-numbered opencode-coverage-<n>-<n> and opencode-coverage-tool-build-<n>-<n> directories older than two hours, never this run's and never shared directories (artifact, source, sandbox-result, tool-build). Failure warns and does not block measurement. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW
|
Bypass merge record (coordinator-authorized, 🤖 Generated with Claude Code |
|
Warning Review limit reachedNext included review available in 5 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Why
The coverage sandbox writes
$RUNNER_TEMP/opencode-coverage-<run>-<attempt>as root, so the runner's per-job temp cleanup can't remove it. After the 2026-09-29 cleanup, about a dozen of these piled up oncwlab-s1-04again; the coordinator saw "dubious ownership" on the host. #2491 removes the current run's workspace at job end, but runs dispatched before #2491, and jobs that never reach cleanup, leave theirs behind.Change
The
Reclaim stale coverage imagesstep (from #2514) now also removes directories matchingopencode-coverage-[0-9]*-[0-9]*oropencode-coverage-tool-build-[0-9]*-[0-9]*that are older than 2 h, usingsudo rm -rf --(the same privilege the job already uses at L634/667/921 and in #2491's cleanup).opencode-coverage-{artifact,source,sandbox-result,tool-build}directories. The coordinator pointed out that a broader pattern would match them.Dropping the sandbox to
--userwould change its isolation boundary and is left for a separate review.Tests
test_reclaim_removes_only_old_coverage_workspacesruns the step script with a fakesudo/dockeragainst a temp tree containing old, fresh, current-run, unrelated and shared directories. It was red on main, red again with the first (broad) pattern, and green now. The 26 dispatch-workflow test files: 872 passed plain and withGITHUB_ACTIONS=true(the one failure is the environment-only maturin test, same on main). actionlint passed; the blob pin is updated.🤖 Generated with Claude Code
https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW