From 9f771a61cf17c19ff27d23d3e30ea047cc8e4f8a Mon Sep 17 00:00:00 2001 From: Jens Date: Sun, 30 Aug 2026 13:25:37 +0200 Subject: [PATCH 1/2] fix(ci): cap Syft heap inside DinD --- backend/tests/test_rc6_supply_chain.py | 2 ++ scripts/generate_container_sbom.sh | 11 +++++++---- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/backend/tests/test_rc6_supply_chain.py b/backend/tests/test_rc6_supply_chain.py index 2b870466..09df93a2 100644 --- a/backend/tests/test_rc6_supply_chain.py +++ b/backend/tests/test_rc6_supply_chain.py @@ -123,6 +123,8 @@ def test_scanner_images_are_versioned_and_digest_pinned() -> None: assert 'docker save "$IMAGE_ID"' in sbom assert '"docker-archive:$WORKDIR/$IMAGE_ARCHIVE"' in sbom assert 'SYFT_PARALLELISM=${SYFT_PARALLELISM:-1}' in sbom + assert 'GOMEMLIMIT=${SYFT_GOMEMLIMIT:-4GiB}' in sbom + assert 'GOGC=${SYFT_GOGC:-25}' in sbom assert "--select-catalogers=-binary" in sbom assert '--volumes-from "$HOSTNAME"' in sbom assert 'ARCHIVE_ID_FILE="${IMAGE_ARCHIVE}.image-id"' in sbom diff --git a/scripts/generate_container_sbom.sh b/scripts/generate_container_sbom.sh index 11be2c6a..38e5e459 100644 --- a/scripts/generate_container_sbom.sh +++ b/scripts/generate_container_sbom.sh @@ -57,13 +57,16 @@ if [[ -n "${HOSTNAME:-}" ]] && docker inspect --type container "$HOSTNAME" >/dev WORKSPACE_ARGS=(--volumes-from "$HOSTNAME") fi -# CUDA and PyTorch ship several gigabytes of native binaries. Syft's heuristic -# binary catalogers exceed the isolated runner's 8 GiB limit on that content. -# Authoritative dpkg, Python, npm and other installed-package catalogers remain -# enabled; Trivy still scans the complete immutable archive independently. +# CUDA and PyTorch ship several gigabytes of native binaries. Keep Syft's Go +# heap below the isolated runner's 8 GiB limit and collect garbage proactively; +# otherwise the Docker-in-Docker job can be OOM-killed even with one cataloger +# worker. Authoritative dpkg, Python, npm and other installed-package catalogers +# remain enabled; Trivy still scans the complete immutable archive independently. docker run --rm \ --user 0:0 \ -e "SYFT_PARALLELISM=${SYFT_PARALLELISM:-1}" \ + -e "GOMEMLIMIT=${SYFT_GOMEMLIMIT:-4GiB}" \ + -e "GOGC=${SYFT_GOGC:-25}" \ "${WORKSPACE_ARGS[@]}" \ -w "$WORKDIR" \ "$SYFT_IMAGE" \ From bf5e1b7e0655407643b29eca679e29b8059aeffb Mon Sep 17 00:00:00 2001 From: Jens Date: Sun, 30 Aug 2026 13:32:22 +0200 Subject: [PATCH 2/2] fix(deploy): ignore parent Git checkout in backup binding --- backend/tests/test_rc_backup_restore_scripts.py | 2 ++ scripts/backup_release_state.sh | 5 ++++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/backend/tests/test_rc_backup_restore_scripts.py b/backend/tests/test_rc_backup_restore_scripts.py index 62340d85..9752eb21 100644 --- a/backend/tests/test_rc_backup_restore_scripts.py +++ b/backend/tests/test_rc_backup_restore_scripts.py @@ -45,6 +45,8 @@ def test_backup_binds_prepared_source_without_requiring_dot_git() -> None: optional_git_fallback = script.index('if command -v git >/dev/null 2>&1') docker_access = script.index("docker inspect -f '{{.State.Running}}'") assert controller_resolution < optional_git_fallback < docker_access + assert 'git -C "$ROOT" rev-parse --show-toplevel' in script + assert '"$(cd "$git_top" && pwd -P)" = "$(cd "$ROOT" && pwd -P)"' in script assert 'SOURCE_REVISION="$explicit_sha"' in script assert '"backup_tool_revision": ${SOURCE_REVISION@Q}' in script assert '"running_image_revision": ${RUNNING_IMAGE_REVISION@Q}' in script diff --git a/scripts/backup_release_state.sh b/scripts/backup_release_state.sh index 32d26aa3..f69ba993 100644 --- a/scripts/backup_release_state.sh +++ b/scripts/backup_release_state.sh @@ -70,7 +70,7 @@ done resolve_source_revision() { local controller_sha="" explicit_sha="${GEOINTEL_BUILD_SHA:-}" local gitea_sha="${GITEA_COMMIT_SHA:-}" github_sha="${GITHUB_SHA:-}" - local git_head="" git_dirty="false" source="" + local git_head="" git_top="" git_dirty="false" source="" if [ -n "$gitea_sha" ]; then if ! [[ "$gitea_sha" =~ ^[0-9A-Fa-f]{40}$ ]]; then @@ -115,6 +115,9 @@ resolve_source_revision() { fi if command -v git >/dev/null 2>&1 && git -C "$ROOT" rev-parse --git-dir >/dev/null 2>&1; then + git_top="$(git -C "$ROOT" rev-parse --show-toplevel 2>/dev/null || true)" + fi + if [ -n "$git_top" ] && [ "$(cd "$git_top" && pwd -P)" = "$(cd "$ROOT" && pwd -P)" ]; then git_head="$(git -C "$ROOT" rev-parse HEAD 2>/dev/null || true)" git_head="${git_head,,}" if ! [[ "$git_head" =~ ^[0-9a-f]{40}$ ]]; then