Skip to content

fix(ci): sweep stale root-owned coverage workspaces on the OpenCode runner - #2517

Merged
seonghobae merged 1 commit into
mainfrom
seonghobae/coverage-workspace-reclaim
Sep 29, 2026
Merged

seonghobae merged 1 commit into
mainfrom
seonghobae/coverage-workspace-reclaim

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Why

The coverage sandbox writes $RUNNER_TEMP/opencode-coverage-<run>-<attempt> as root, so the runner's per-job temp cleanup can't remove it. After the 2026-09-29 cleanup, about a dozen of these piled up on cwlab-s1-04 again; the coordinator saw "dubious ownership" on the host. #2491 removes the current run's workspace at job end, but runs dispatched before #2491, and jobs that never reach cleanup, leave theirs behind.

Change

The Reclaim stale coverage images step (from #2514) now also removes directories matching opencode-coverage-[0-9]*-[0-9]* or opencode-coverage-tool-build-[0-9]*-[0-9]* that are older than 2 h, using sudo rm -rf -- (the same privilege the job already uses at L634/667/921 and in #2491's cleanup).

  • It never touches this run's directories.
  • It never touches the shared opencode-coverage-{artifact,source,sandbox-result,tool-build} directories. The coordinator pointed out that a broader pattern would match them.
  • A failure only warns.

Dropping the sandbox to --user would change its isolation boundary and is left for a separate review.

Tests

test_reclaim_removes_only_old_coverage_workspaces runs the step script with a fake sudo/docker against a temp tree containing old, fresh, current-run, unrelated and shared directories. It was red on main, red again with the first (broad) pattern, and green now. The 26 dispatch-workflow test files: 872 passed plain and with GITHUB_ACTIONS=true (the one failure is the environment-only maturin test, same on main). actionlint passed; the blob pin is updated.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW

…unner

The coverage sandbox writes $RUNNER_TEMP/opencode-coverage-<run>-<attempt>
as root, so the runner's per-job temp cleanup cannot remove them; about a
dozen accumulated on cwlab-s1-04 again after the 2026-09-29 cleanup.
#2491 removes the current run's workspace at job end, but runs dispatched
before it, or jobs that never reach cleanup, leave theirs behind.

The "Reclaim stale coverage images" step now also removes, with the sudo
the job already uses, only run-numbered opencode-coverage-<n>-<n> and
opencode-coverage-tool-build-<n>-<n> directories older than two hours,
never this run's and never shared directories (artifact, source,
sandbox-result, tool-build). Failure warns and does not block measurement.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW
@seonghobae

Copy link
Copy Markdown
Contributor Author

Bypass merge record (coordinator-authorized, .github only): the author reviewed the diff at head 3958fc02. It adds one bounded find ... | sudo rm -rf sweep to an existing pre-measurement step, limited to run-numbered names, older than 2 h, and excluding this run, plus the test, blob pin and changelog fragment. Local tests are listed in the PR body. This keeps the s1-04 disk from refilling while hosted checks are stuck behind the org queue, so it's merged with the bypass.

🤖 Generated with Claude Code

@seonghobae
seonghobae merged commit 2639d7c into main Sep 29, 2026
3 of 8 checks passed
@seonghobae
seonghobae deleted the seonghobae/coverage-workspace-reclaim branch September 29, 2026 15:08
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 5 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c1da41d1-1be8-48de-89e7-cad4676d5e78

📥 Commits

Reviewing files that changed from the base of the PR and between 7bfb51e and 3958fc0.

📒 Files selected for processing (4)
  • .github/workflows/opencode-review-dispatch.yml
  • CHANGELOG.d/20260930-coverage-workspace-reclaim.md
  • tests/test_opencode_coverage_runner_hygiene.py
  • tests/test_pr_review_autofix_nvidia_nim_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant