Skip to content

mz960: don't squash a base stage that declares ONBUILD - #964

Merged
mzihlmann merged 1 commit into
mainfrom
mz960-onbuild-squash-key-divergence
Aug 1, 2026
Merged

mz960: don't squash a base stage that declares ONBUILD#964
mzihlmann merged 1 commit into
mainfrom
mz960-onbuild-squash-key-divergence

Conversation

@mzihlmann

Copy link
Copy Markdown
Collaborator

Fixes #960

Squashing filters the base stage's ONBUILD declaration out of the merged command list. That is fine for the squash in MakeKanikoStages, which runs before any cache key exists, but the stage elimination behind FF_KANIKO_SKIP_CACHED_STAGES squashes after the lookahead has already hashed the unsquashed chain. The merged chain then hashes one command fewer, so every key after the ONBUILD diverges from the precomputed one. On a cache-consume build the inferred cross-stage key misses, the COPY --from falls back to hashing its source files, and the build aborts because the stage it reads from was eliminated and never wrote /kaniko/deps/N. So we leave a base stage that declares an ONBUILD unsquashed, it stays alive and writes its deps like it does with the flag off.

@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@mzihlmann, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 0ba4cb6e-457f-48bc-bda9-298be64d56dc

📥 Commits

Reviewing files that changed from the base of the PR and between 93be5ff and 687c2ab.

📒 Files selected for processing (3)
  • integration/dockerfiles/Dockerfile_test_issue_mz960
  • integration/images.go
  • pkg/executor/build.go

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mzihlmann mzihlmann added the bug Something isn't working label Jul 31, 2026
@mzihlmann
mzihlmann force-pushed the mz960-onbuild-squash-key-divergence branch from 2c12076 to 687c2ab Compare July 31, 2026 23:29
@codecov

codecov Bot commented Jul 31, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@mzihlmann
mzihlmann requested review from 0hlov3, BobDu, babs and nejch August 1, 2026 07:14
@mzihlmann
mzihlmann merged commit f9ebae6 into main Aug 1, 2026
13 checks passed
@mzihlmann
mzihlmann deleted the mz960-onbuild-squash-key-divergence branch August 1, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cache-consume build aborts on cross-stage COPY --from to a skipped cached stage (SKIP_CACHED_STAGES + CACHE_LOOKAHEAD + INFER_CROSS_STAGE_CACHE_KEY)

1 participant