Skip to content

fix(genvm): download GenVM releases instead of building from source - #1706

Merged
MuncleUscles merged 2 commits into
feat/genvm-v03-portfrom
fix/genvm-source-modes
Jul 23, 2026
Merged

MuncleUscles merged 2 commits into
feat/genvm-v03-portfrom
fix/genvm-source-modes

Conversation

@MuncleUscles

Copy link
Copy Markdown
Member

Follow-up to #1697. Targets that PR's branch, so #1697 still merges to v0.123-dev as one unit.

Problem

third_party/genvm/version held the literal string main, and the pin router sends anything not matching ^v[0-9] down the nix path. So every build compiled GenVM from source against a floating ref — the input silently moved (it resolved to 02741163 at CI time, now 12f85fc0).

That nix build fails nondeterministically: FOD mismatch on genvm-bz2-1.0.8 where specified: is constant but got: differs across jobs (sandbox is disabled, so host state leaks in). Bumping the hash does not fix it.

02741163 is exactly the v0.6.0-rc0 tag, and that release ships a self-contained prebuilt bundle. We were compiling something that already exists as a download.

Change

Three explicit acquisition modes, precedence prebuilt > source > release:

Mode Selected by Use
prebuilt .e2e-genvm-prebuilt/ tree present E2E harness injection (pre-existing hook)
source GENVM_SOURCE_MODE=source, or <branch>:<commit> in GENVM_REF GenVM developers (nix, opt-in)
release default Download a pinned genvm-manager release
  • Pin main → v0.6.0-rc0
  • Vendored genlayer-node's download_genvm.sh rather than writing a third implementation — keeps the tree-based split-layout probe (rc1 moved runners/ into a separate genvm-universal.tar.xz; the probe checks the tree, never the tag), chmod -R u+w for rc0's read-only data/, the post-install.py/genvm-post-install rename handling, and the pinned-runner assertion
  • New genvm-runner-pin stage collapses contract pins to a small normalized file, so the ~330MB GenVM layer no longer invalidates on every backend edit
  • Restored the GENVM_TAG/GENVM_REF mutual-exclusion guard
  • Removed GENVM_ARTIFACT_URL — it was half-wired (hardcoded amd64-only default, absent from compose, unreachable -z guard). It silently fetched an amd64 bundle on arm64.
  • Strict pin regex; bare -dev branch pins now rejected with an actionable message instead of 404ing
  • .dockerignore: !docker/scripts/ is load-bearing — without it the new COPY fails and every build breaks in all three modes

GENVM_TAG's ENV is deliberately kept: it is dead at build time but load-bearing at runtime as the precompile cache-key fallback.

Verification

Built locally on arm64. Release mode green; image carries /genvm/version=v0.6.0-rc0, executors v0.2.17+v0.3.0-rc7, and the pinned runner 9b/8kjyda2…tar — the tarball whose absence caused the original lint failure. Arch resolved to arm64 correctly.

Negative cases all behave:

Case Result
explicit prebuilt + unusable tree fails, actionable message
auto-detect + empty tree falls through to release
GENVM_TAG + GENVM_REF both set fails, "mutually exclusive"
GENVM_TAG=v0.6-dev (a branch) rejected before any download

Source mode is untested here — it is the known-broken nix path, now opt-in precisely so nobody hits it by accident.

Not addressed

  • The Lint Intelligent Contracts failure is a separate problem: genvm-linter resolves its bundle from the old genlayerlabs/genvm repo (stops at v0.3.0-rc7), which does not contain the 9b8kjyda2… hash. Needs the linter pointed at a bundle that has it. genvm-lint.yml deliberately untouched.
  • SonarCloud coverage gate (vendored keccak.py, 439 untested lines).
  • @kp2pml30's v0.3↔v0.2 code-slot interop question from Port studio to genvm-manager (v0.3) #1697 — unchanged, still needs his input.

Depends-On: genlayerlabs/genlayer-e2e@fix/studio-genvm-source-mode

Studio always built GenVM from source because the pin file held a
floating "main". That nix build fails nondeterministically on a
fixed-output derivation, so add explicit prebuilt/source/release modes
and default to downloading a pinned genvm-manager release.
@coderabbitai

coderabbitai Bot commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 45fb1b85-3a9a-4f15-b902-ed5b9daacebc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/genvm-source-modes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The genvm-manager bundle carries two executor lines, so precompiling both
on a cold cache overruns the healthcheck window and the container is
reported unhealthy. Precompile in a one-off container first and cache the
result across runs.
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
77.2% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@MuncleUscles
MuncleUscles merged commit be59684 into feat/genvm-v03-port Jul 23, 2026
21 of 22 checks passed
@MuncleUscles
MuncleUscles deleted the fix/genvm-source-modes branch July 23, 2026 15:12
MuncleUscles added a commit that referenced this pull request Jul 23, 2026
…1706) (#1712)

* fix(genvm): acquire GenVM by release download instead of nix build

Studio always built GenVM from source because the pin file held a
floating "main". That nix build fails nondeterministically on a
fixed-output derivation, so add explicit prebuilt/source/release modes
and default to downloading a pinned genvm-manager release.

* fix(ci): precompile GenVM before starting the stack

The genvm-manager bundle carries two executor lines, so precompiling both
on a cold cache overruns the healthcheck window and the container is
reported unhealthy. Precompile in a one-off container first and cache the
result across runs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant