jk8e8mgq84enbs5459vll1tdj95oj4qe · 58 rows
| id | issue_id | event_type | actor | old_value | new_value | comment | created_at |
|---|---|---|---|---|---|---|---|
| 019f95fc-b75e-7b00-979a-510d501bbb9f | spec-ejq.2 | created | Eugene Blikh | NULL | 2026-07-25T00:16:35Z | ||
| 019f9913-3831-7bd7-8876-d352b2460c79 | spec-by6.3.5 | created | Eugene Blikh | NULL | 2026-07-25T14:40:01Z | ||
| 019fcf65-3a8e-744d-9748-ad204c4a6fcd | spec-by6.4 | created | Eugene Blikh | NULL | 2026-08-05T03:49:05Z | ||
| 019fcf78-95f1-756a-8df8-b30a581fbdc2 | spec-by6.5 | created | Eugene Blikh | NULL | 2026-08-05T04:10:14Z | ||
| 019fcf79-fe91-74f9-aa65-e68d2fe89309 | spec-by6.3.5 | closed | Eugene Blikh | Closed | NULL | 2026-08-05T04:11:46Z | |
| 019fcf84-5f2f-7c77-84e3-c66b4e77685c | spec-by6.5 | closed | Eugene Blikh | Closed | NULL | 2026-08-05T04:23:06Z | |
| 019fcf84-a887-7c5c-aa82-d7c11c7fd387 | spec-by6.4 | closed | Eugene Blikh | Closed | NULL | 2026-08-05T04:23:25Z | |
| 019fcfe1-a1db-7d94-a36f-7dbeac40c1bc | spec-ejq.2 | updated | Eugene Blikh | {"id":"spec-ejq.2","title":"CI publish task fails: build secret apk-ci-s3 is missing","description":"Every recent builds.sr.ht run fails at the publish task while every other task passes. Confirmed on jobs #244 (e97532c), #245 (2dc6b71) and #246 (c2dd1ef): 'scss keygen version build' all SUCCESS, 'publish' FAILED. Pre-existing — #244 and #245 predate the Phase 5b work, so no code change caused it. Consequence: the apk never reaches the Garage repo bucket, so apk-mirror on phoebe has nothing new to re-index and the deployed service cannot be upgraded from CI output.","design":"EVIDENCE. .build.yml declares 'secrets: [apk-ci-s3]', documented as a File secret installed at ~/.apk-ci.env carrying APK_CI_S3_ACCESS_KEY / APK_CI_S3_SECRET_KEY for the Garage repo bucket. The publish task's first real line is '. ~/.apk-ci.env'. But 'hut builds secret list' returns exactly four secrets and none is apk-ci-s3: agent1-deploy (SSH key), bencher-api-key, s3-cache-key-secret, s3-cache-key-id. So the file the task sources is never installed.\n\nNOT VERIFIED: the exact failure text. The raw log endpoint (https://builds.srht.bigb.es/query/log/246/publish/log) needs a Bearer token, and reading hut's credential file was correctly refused, so the diagnosis rests on the secret list plus the manifest rather than on the log line itself. Read the log to confirm before acting.\n\nTWO POSSIBILITIES, needs the owner to distinguish:\n1. The secret was deleted or never created — fix is to create a File secret named apk-ci-s3 at ~/.apk-ci.env (mode 600) holding the two S3 keys.\n2. builds.sr.ht resolves manifest secrets by UUID, not by name — fix is to replace the name with the secret's UUID in .build.yml.\n\nSAME BUG IN THE SIBLING: ~/data/home/sourcehut-compare/.build.yml carries a byte-identical secrets block, so compare.sr.ht's publish is broken the same way and both fix together.","acceptance_criteria":"A push to master produces a build whose publish task succeeds and uploads the .apk to the Garage repo bucket; apk-mirror on phoebe re-indexes it within 15 minutes.","status":"open","priority":2,"issue_type":"bug","owner":"bigbes@gmail.com","created_at":"2026-07-24T21:16:35Z","created_by":"Eugene Blikh","updated_at":"2026-07-24T21:16:35Z"} | {"notes":"DIAGNOSIS RESOLVED 2026-08-05, still blocked on the owner.\n\nPossibility 2 (builds.sr.ht resolves manifest secrets by UUID only) is RULED OUT. buildsrht/manifest.py parses each secrets: entry as a UUID first and, on failure, treats it as a 3-512 character name and looks it up by name. So '- apk-ci-s3' in the manifest is valid as written; nothing in .build.yml needs changing.\n\nPossibility 1 confirmed: 'hut builds secret list' still returns exactly four secrets (agent1-deploy, bencher-api-key, s3-cache-key-secret, s3-cache-key-id) and none is apk-ci-s3. The secret was never created or was deleted.\n\nFailure mechanism, derived rather than read from the log: the task preamble is 'set -xe' and publish's first real line is '. ~/.apk-ci.env'. A missing file makes '.' exit non-zero and set -e kills the task. That reproduces the observed signature exactly - scss/keygen/version/build green, publish red - and matches build #250 (cc90b4a) as well as #247 (61515a5), so the port to the line-numbered diff did not change it.\n\nFIX, both steps need the owner:\n1. Garage, on the host that has the CLI: 'garage key create apk-ci' then 'garage bucket allow --read --write repo --key apk-ci'. No --owner: publish only uploads and never deletes. Check first whether the key behind the existing s3-cache-key-* secrets already has write on the repo bucket.\n2. Register a File secret on builds.srht.bigb.es (web form or GraphQL - 'hut builds secret' is list/share only, it cannot create): name apk-ci-s3, path /home/build/.apk-ci.env, mode 600, contents two lines APK_CI_S3_ACCESS_KEY=... and APK_CI_S3_SECRET_KEY=... . Absolute path rather than ~/.apk-ci.env because the worker writes the literal string it was given; /home/build is the build user's home, so the manifest's '. ~/.apk-ci.env' still resolves. Mode 600 rather than the 644 the existing s3-cache-key-* secrets use: this is a key, not an identifier.\n\nSecrets are account-level, so the same one also fixes sourcehut-compare, whose manifest carries the identical block."} | NULL | 2026-08-05T06:04:58Z |