Scope each run's cache-to writes to its own tag suffix - #63
Merged
Merged
Conversation
This was referenced Sep 22, 2026
bartgol
force-pushed
the
claude/cache-suffix-isolation
branch
from
September 22, 2026 22:02
e9f3410 to
24a016e
Compare
mahf708
previously approved these changes
Sep 22, 2026
Even with the previous commit's fix, a non-fork PR (or merge_group run) that touches ghci/base or ghci/compiler still overwrote the shared, unsuffixed buildcache-<tag>-<arch> registry tag on every build. That tag is what main and every other PR read from, so an in-progress PR's not-yet-reviewed Dockerfile change could silently become the cache basis for unrelated concurrent PRs (and for main itself, if the PR never merges) -- forcing them into a cold rebuild the next time they imported it. Add a tag_suffix input to build-multiarch.yaml (the same -pr-<N> / -mg-<sha> value ghci.yaml already computes in its `suffix` job and threads through BASE_TAG build-args) and use it to separate reads from writes: - cache-to only ever writes buildcache-<tag><tag_suffix>-<arch>, this run's own cache scope. It never touches the plain buildcache-<tag>-<arch> tag unless tag_suffix is empty, i.e. a push to main. - cache-from reads both: this run's own suffixed tag first (empty until a later push to the same PR/merge_group run has written it), then the plain tag as a fallback, so a PR's first build still benefits from whatever main last cached. A cache-from source that doesn't exist yet is a soft error buildx logs and skips, not a build failure. This creates a new kind of registry tag -- buildcache-<tag>-pr-<N>- <arch> and buildcache-<tag>-mg-<sha>-<arch> -- that needs the same lifecycle as the real -pr-<N>/-mg-<sha> image tags, or it would leak forever now that live buildcache tags are otherwise never swept by age. Extend cleanup-ghcr-packages.yaml's existing tag patterns (delete-pr-images' PR-close sweep, and cleanup-untagged's merge_group-ephemeral age sweep) to also match an optional trailing arch, so these new tags are cleaned up exactly like their non-cache counterparts already are. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U1ni5gYuf7PVCbLikoveMK
bartgol
force-pushed
the
claude/cache-suffix-isolation
branch
from
September 25, 2026 15:19
24a016e to
f09cd8c
Compare
bartgol
enabled auto-merge
September 25, 2026 15:21
mahf708
approved these changes
Sep 25, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to no response for status checks
Sep 25, 2026
mahf708
enabled auto-merge
September 25, 2026 21:56
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 25, 2026
bartgol
enabled auto-merge
September 25, 2026 22:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Recreated after E3SM-Project/containers#62 was accidentally merged (base was mistakenly re-fast-forwarded, mixing both fixes into one branch). Same commit, same content — GitHub doesn't allow reopening a merged PR, so this is a fresh PR number.
Stacked on E3SM-Project/containers#61 (base branch is that PR's branch, so this diff only shows the new changes; merge/rebase #61 first).
Even with #61's fix, a non-fork PR (or
merge_grouprun) that touchesghci/baseorghci/compilerstill overwrote the shared, unsuffixedbuildcache-<tag>-<arch>registry tag on every build — the same tag main and every other PR reads from. An in-progress PR's not-yet-reviewed Dockerfile change could silently become the cache basis for unrelated concurrent PRs (and for main itself, if the PR never merges), forcing a cold rebuild the next time they imported it.tag_suffixinput tobuild-multiarch.yaml(the same-pr-<N>/-mg-<sha>valueghci.yaml'ssuffixjob already computes and threads throughBASE_TAGbuild-args).cache-tonow only ever writes this run's ownbuildcache-<tag><tag_suffix>-<arch>tag, never the plain one, unlesstag_suffixis empty (a push to main).cache-fromreads both: this run's own suffixed tag first, then the plain tag as a fallback — so a PR's first build still benefits from whatever main last cached, and a missing cache-from source is a soft error buildx logs and skips, not a build failure.buildcache-<tag>-pr-<N>-<arch>,buildcache-<tag>-mg-<sha>-<arch>) that needs the same lifecycle as the real-pr-<N>/-mg-<sha>image tags, socleanup-ghcr-packages.yaml's existing PR-close and merge_group-ephemeral patterns were extended to also match an optional trailing arch.Test plan
node --checkon the extractedactions/github-scriptbodies (syntax only)python3 -c "import yaml; yaml.safe_load(...)"on all three changed workflow filesbase/compilerimporting cache from the plain tag on first push, and from its own-pr-<N>tag on a second pushdelete-pr-imagesshould also remove that PR'sbuildcache-*-pr-<N>-<arch>tags🤖 Generated with Claude Code
https://claude.ai/code/session_01U1ni5gYuf7PVCbLikoveMK
Generated by Claude Code