Skip to content

Quality sweep: build integrity, script robustness and stale defaults - #1134

Merged
frenck merged 1 commit into
mainfrom
quality-sweep
Aug 28, 2026
Merged

frenck merged 1 commit into
mainfrom
quality-sweep

Conversation

@frenck

@frenck frenck commented Aug 28, 2026 •

Copy link
Copy Markdown
Member

Proposed Changes

(Describe the changes and rationale behind them)

A full pass over the app: Dockerfile, S6 scripts, defaults, docs and Renovate configuration. Everything below was verified against a local amd64 build rather than read off the page.

Bugs

init-mosquitto failed on any restart of a container with MQTT available. The two convenience links were created with a bare ln -s, which fails once they exist. Bashio runs with errexit, so the oneshot exited 1 and s6 could not bring the bundle up. This is the same class of failure #922 fixed for the home folder links, and it did not reach this script. Both links now use -f and log a warning, matching the rest of the script.

before: first run exit=0, second run -> ln: File exists, exit=1
after:  first, second and third run all exit=0

Downloads could not fail. No curl in the Dockerfile used --fail, so an HTTP error wrote the error body to the target path. The Home Assistant CLI was the bad one:

$ curl -L -s -o /tmp/ha_test ".../releases/download/99.99.99/ha_amd64"
curl exit=0 ; chmod exit=0 ; contents: "Not Found"

A wrong HA_CLI_VERSION shipped a 404 page as /usr/bin/ha, executable, and the build passed. All four downloads now use --fail.

The cleanup pass never deleted a directory. In find, -a binds tighter than -o, so the expression parsed as GROUP1 -o (GROUP2 -a -exec) and the -exec was reachable only through the .pyc branch. The -type d also applied to test alone, so files named tests or __pycache__ would have matched.

before after
test/tests/__pycache__ directories 1450 0
.pyc files 0 0
/usr/local 995M 986M

Stale defaults

settings.json had not been touched since 2022-11-09 and had drifted:

  • terminal.integrated.shell.linux was removed from VS Code. It appears in 0 files of the bundled 1.135, against 5 for terminal.integrated.defaultProfile.linux. The intended zsh terminal was coming only from the shell recorded in /etc/passwd. Replaced with the profile settings.
  • telemetry.enableTelemetry is the deprecated alias for telemetry.telemetryLevel.
  • The two vsicons.* entries are inert, as the icons extension is not bundled.

The outgoing default's hash is added to PREVIOUS_DEFAULT_CONFIG_HASHES, so existing installs receive the change. Verified both directions:

user on the previous default -> upgraded (dead key gone, new key present)
user with customised settings -> left untouched

Renovate

Two of the eight bundled extensions had no manager and had silently stopped being updated, and there was a manager for netcorext.uuid-generator, which is not bundled.

redhat.vscode-yaml gains a manager. It also moves from 1.25.2026082008 to 1.24.0: that version string is a pre-release build, upstream's newest release is 1.24.0, and the pin before it (1.11.10112022) followed the same pattern, so this app has been shipping that extension's pre-release channel for years. 1.24.0 is on the Marketplace and needs ^1.63.0, satisfied by Code 1.135.

oderwat.indent-rainbow stays manual and cannot be automated: its repository has no tags and no releases, and Renovate has no Open VSX or Marketplace datasource. 8.3.1 is current, and upstream has not been pushed to since August 2024.

Smaller items

  • The documentation described the packages option as taking Ubuntu packages and linked packages.ubuntu.com; the base is Debian. The failure message in init-user said the same. Both corrected, and apt update became apt-get update, which is the interface meant for scripts.
  • init-mysql created /root/.config but wrote to /etc/mysql/conf.d. Harmless today because mariadb-client ships that folder, but it was protecting nothing. Verified the script now succeeds with the folder removed beforehand.
  • workspaces.json was referenced by nothing. Removed.
  • The readme template was titled "Visual Studio Code" while the app is "Studio Code Server".
  • The extension loop set extension and vendor in a single statement, which worked only because bash evaluates assignments left to right, and $? was tested instead of the command. Both straightened out, along with the extention and Confiure typos.
  • # hadolint ignore=SC2181, DL3008 no longer applied to anything: SC2181 covered the $? test that is gone, and every apt package is pinned. Verified hadolint is clean with no ignores, so the line is removed and the linter enforces pinned versions again.

Verification

Full amd64 build, plus Shellcheck, Prettier, YAMLLint, Hadolint and renovate-config-validator, all clean. The ha binary in the built image is a real ELF and runs, all eight extensions install at the expected versions, and the S6 scripts were exercised directly for the behaviour described above.

Related Issues

(Github link to related issues or pull requests)

Follows the .ssh link fix in #1098 and the guarded links added in #922.

Summary by CodeRabbit

  • New Features

    • Added support for the latest Code Server configuration format, including an off telemetry setting and default Zsh terminal profile.
    • Updated YAML extension tracking and version selection.
  • Bug Fixes

    • Improved reliability when downloading components and creating service configuration links.
    • Corrected MySQL client configuration setup and Debian package repository handling.
    • Automatically refreshes settings when replacing older default configurations.
  • Documentation

    • Updated product naming and clarified Debian package installation guidance.

Three real bugs, plus the configuration drift that came with them.

`init-mosquitto` linked mosquitto_pub and mosquitto_rr with a bare
`ln -s`, which fails once the links exist. Bashio runs with errexit, so
the second start of a container that has MQTT available failed the
oneshot outright. This is the same class of failure #922 fixed for the
home folder links and did not cover here. Both links now use `-f` and
carry a warning, matching the rest of the script.

None of the downloads in the Dockerfile used `--fail`, so an HTTP error
produced a file rather than an error. The Home Assistant CLI was the bad
case: a wrong version wrote the 404 body to /usr/bin/ha, marked it
executable, and the build passed. All four downloads now fail loudly.

The cleanup pass never removed a single directory. In `find`, `-a` binds
tighter than `-o`, so the expression parsed as "first group, or second
group and delete", leaving the `-exec` reachable only through the second
branch. The name tests are now grouped so it applies to both. This drops
1450 leftover test, tests and __pycache__ directories from the image.

The default settings had drifted since 2022. VS Code removed
`terminal.integrated.shell.linux` entirely, so the intended zsh terminal
was coming only from the shell recorded in /etc/passwd; it is replaced by
the profile settings. `telemetry.enableTelemetry` gives way to
`telemetry.telemetryLevel`, and the vsicons entries went, as the icons
extension is not installed. The outgoing default is recorded in
PREVIOUS_DEFAULT_CONFIG_HASHES so existing installs pick this up.

Two of the eight bundled extensions had no Renovate manager, and there
was one manager for an extension that is not bundled at all.
`redhat.vscode-yaml` gains a manager and moves from a pre-release build
onto the stable line it tracks. `oderwat.indent-rainbow` stays manual, as
its repository publishes no tags or releases and Renovate has no
registry datasource that covers it.

The rest is smaller: the documentation and the package install message
said Ubuntu while the base is Debian, `init-mysql` created a folder it
never wrote to, the readme template carried the old name, the unused
workspaces.json is gone, and the hadolint ignores no longer applied to
anything, so the linter now enforces pinned apt versions again.
@frenck frenck added bugfix Inconsistencies or issues which will cause a problem for users or implementors. maintenance Generic maintenance tasks. labels Aug 28, 2026
@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2741210f-796c-4574-ba82-7f5dc6dcf067

📥 Commits

Reviewing files that changed from the base of the PR and between 8c48e14 and 88d4e66.

📒 Files selected for processing (11)
  • .github/renovate.json
  • vscode/.README.j2
  • vscode/DOCS.md
  • vscode/Dockerfile
  • vscode/rootfs/etc/s6-overlay/s6-rc.d/init-code-server/run
  • vscode/rootfs/etc/s6-overlay/s6-rc.d/init-mosquitto/run
  • vscode/rootfs/etc/s6-overlay/s6-rc.d/init-mysql/run
  • vscode/rootfs/etc/s6-overlay/s6-rc.d/init-user/run
  • vscode/rootfs/root/.code-server/settings.json
  • vscode/rootfs/root/.code-server/workspaces.json
  • vscode/vscode.extensions
💤 Files with no reviewable changes (1)
  • vscode/rootfs/root/.code-server/workspaces.json

Included review availability: Your plan provides up to 4 included reviews per hour; 2 remain after this review.


Walkthrough

The PR updates VS Code Server image downloads, extension tracking, runtime initialization scripts, editor defaults, and documentation. It also removes the Code Server workspace state file and aligns package references with Debian.

Changes

VS Code Server maintenance

Layer / File(s) Summary
Image build and extension tracking
.github/renovate.json, vscode/Dockerfile, vscode/vscode.extensions
The build uses fail-fast downloads, corrected extension extraction handling, grouped cleanup predicates, and updated YAML extension tracking.
Runtime initialization and editor defaults
vscode/rootfs/etc/s6-overlay/s6-rc.d/*, vscode/rootfs/root/.code-server/settings.json
Initialization scripts update default settings detection, service links, MySQL configuration paths, and Debian package commands. Code Server settings use current telemetry and zsh configuration keys.
Documentation naming and package references
vscode/.README.j2, vscode/DOCS.md
The README uses the Studio Code Server title. Package documentation now references Debian packages.

Estimated code review effort: 2 (Simple) | ~15 minutes

Merge Risk: 🔵 Low · up to 88d4e

The PR now writes database credentials in a system-wide MySQL configuration directory without explicitly defining restrictive access permissions. It is mergeable with owner awareness or follow-up to confirm that only intended processes can read the file.

Poem

A rabbit checks each curl with care
YAML hops through tracked software air
Debian paths replace old names
Zsh profiles light terminal flames
Clean links and settings settle there

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the pull request as a quality sweep covering build integrity, script robustness, and stale defaults. It is concise and related to the main changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (10 skipped: 10 unsupported.)

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch quality-sweep

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@frenck
frenck merged commit bb44b28 into main Aug 28, 2026
14 of 15 checks passed
@frenck
frenck deleted the quality-sweep branch August 28, 2026 22:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Inconsistencies or issues which will cause a problem for users or implementors. maintenance Generic maintenance tasks.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant