diff --git a/agents/hermes/Dockerfile b/agents/hermes/Dockerfile index a2c1162c1bd..9e07ac5f263 100644 --- a/agents/hermes/Dockerfile +++ b/agents/hermes/Dockerfile @@ -1191,6 +1191,7 @@ RUN check_metadata() { \ && check_absent /root/.npm \ && check_absent /root/.cache/electron \ && check_absent /root/.cache/node-gyp \ + && check_absent /root/.cache/uv \ && check_absent /sandbox/.cache \ && check_metadata /scripts/patch-bundled-npm-brace-expansion.mts 'root:root 444' \ && check_metadata /scripts/patch-bundled-npm-tar.mts 'root:root 444' \ diff --git a/agents/hermes/Dockerfile.base b/agents/hermes/Dockerfile.base index ef5da59a5ed..023c808ace0 100644 --- a/agents/hermes/Dockerfile.base +++ b/agents/hermes/Dockerfile.base @@ -523,6 +523,8 @@ RUN set -eu; \ # differential. Keep this hash-verified downstream override at the first stable # release that fixes those issues plus GHSA-v9pg-7xvm-68hf. Re-review the # version and both hashes on every Hermes version bump. +# uv creates a phony .git cache marker even with --no-cache. Remove the cache +# after the final uv command because the root cache is not used at runtime. # hadolint ignore=DL3059 RUN printf '%s\n' \ "python-multipart==0.0.32 \\" \ @@ -533,7 +535,8 @@ RUN printf '%s\n' \ --no-deps --no-cache --require-hashes -r /tmp/multipart-req.txt \ && rm -f /tmp/multipart-req.txt \ && /opt/hermes/.venv/bin/python -c \ - "import multipart; assert multipart.__version__ == '0.0.32', multipart.__version__" + "import multipart; assert multipart.__version__ == '0.0.32', multipart.__version__" \ + && rm -rf /root/.cache/uv ENV PATH="/usr/local/bin:/opt/hermes/.venv/bin:${PATH}" \ HERMES_TUI_DIR="/opt/hermes/ui-tui" \ @@ -561,7 +564,7 @@ RUN chmod -R a+rX /opt/hermes/.venv \ # Gate the exact completed base filesystem before it can be published. COPY scripts/checks/node-tar-image-scan.mts /scripts/checks/node-tar-image-scan.mts RUN set -eu; \ - for build_only_path in /opt/hermes/tests /root/.npm /root/.cache/electron /root/.cache/node-gyp; do \ + for build_only_path in /opt/hermes/tests /root/.npm /root/.cache/electron /root/.cache/node-gyp /root/.cache/uv; do \ if [ -e "$build_only_path" ] || [ -L "$build_only_path" ]; then \ echo "ERROR: build-only Hermes path leaked into the base image: $build_only_path" >&2; \ exit 1; \ diff --git a/test/e2e/live/hermes-root-entrypoint-smoke.test.ts b/test/e2e/live/hermes-root-entrypoint-smoke.test.ts index 60f4270a350..5aa62770fb1 100644 --- a/test/e2e/live/hermes-root-entrypoint-smoke.test.ts +++ b/test/e2e/live/hermes-root-entrypoint-smoke.test.ts @@ -243,7 +243,7 @@ async function assertBuildOnlyPathsAbsent(probe: DockerProbe, container: string) probe, container, "build-only Hermes paths are present in the runtime image", - 'for path in /opt/hermes/tests /root/.npm /root/.cache/electron /root/.cache/node-gyp; do test ! -e "$path" && test ! -L "$path"; done', + 'for path in /opt/hermes/tests /root/.npm /root/.cache/electron /root/.cache/node-gyp /root/.cache/uv; do test ! -e "$path" && test ! -L "$path"; done', ); }