Fix build workflow conditionals that always evaluated true - #4203
Conversation
itzg
left a comment
There was a problem hiding this comment.
Thanks. I look at that reference material so often but apparently the subtlety of false vs "false" didn't catch my eye.
Yes, I would be interested in putting them back if their builds work again. |
… ➔ 2026.8.0) (#267) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/itzg/minecraft-server](https://github.com/itzg/docker-minecraft-server) | minor | `2026.7.2-java25` → `2026.8.0-java25` | --- >⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2) for more information. --- ### Release Notes <details> <summary>itzg/docker-minecraft-server (ghcr.io/itzg/minecraft-server)</summary> ### [`v2026.8.0`](https://github.com/itzg/docker-minecraft-server/releases/tag/2026.8.0) [Compare Source](itzg/docker-minecraft-server@2026.7.2...2026.8.0) <!-- Release notes generated using configuration in .github/release.yml at 1e2d375dba72a0730365c29dd5f1990f9764da5a --> ##### What's Changed ##### Enhancements - Implement GTNH daily build support by [@​SgtMate](https://github.com/SgtMate) in [#​4190](itzg/docker-minecraft-server#4190) ##### Bug Fixes - Update dependency itzg/mc-image-helper to v1.63.1 by [@​renovate](https://github.com/renovate)\[bot] in [#​4189](itzg/docker-minecraft-server#4189) - Move knockd config out of /tmp by [@​itzg](https://github.com/itzg) in [#​4193](itzg/docker-minecraft-server#4193) - Use Metalcape knockd by default for java25 by [@​itzg](https://github.com/itzg) in [#​4194](itzg/docker-minecraft-server#4194) - Fix NanoLimbo port not applying to an existing settings.yml by [@​OowhitecatoO](https://github.com/OowhitecatoO) in [#​4201](itzg/docker-minecraft-server#4201) - Ensure debugging starts after loading CF\_API\_KEY\_FILE by [@​itzg](https://github.com/itzg) in [#​4208](itzg/docker-minecraft-server#4208) ##### Documentation - build(deps): bump the patches group in /docs with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​4187](itzg/docker-minecraft-server#4187) - Add daily build options to gtnh example by [@​SgtMate](https://github.com/SgtMate) in [#​4191](itzg/docker-minecraft-server#4191) - docs: add seedloaf sponsor by [@​jasperchess](https://github.com/jasperchess) in [#​4197](itzg/docker-minecraft-server#4197) - Enhance SECURITY.md with automated scan information by [@​itzg](https://github.com/itzg) in [#​4212](itzg/docker-minecraft-server#4212) ##### Other Changes - Update dependency itzg/mc-image-helper to v1.63.0 by [@​renovate](https://github.com/renovate)\[bot] in [#​4184](itzg/docker-minecraft-server#4184) - build(deps): bump actions/stale from 10 to 11 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​4196](itzg/docker-minecraft-server#4196) - build(deps): bump docker/login-action from 4.4.0 to 4.5.2 in the updates group by [@​dependabot](https://github.com/dependabot)\[bot] in [#​4195](itzg/docker-minecraft-server#4195) - Update dependency itzg/mc-image-helper to v1.63.2 by [@​renovate](https://github.com/renovate)\[bot] in [#​4198](itzg/docker-minecraft-server#4198) - Fix build workflow conditionals that always evaluated true by [@​OowhitecatoO](https://github.com/OowhitecatoO) in [#​4203](itzg/docker-minecraft-server#4203) - Update dependency itzg/mc-image-helper to v1.64.0 by [@​renovate](https://github.com/renovate)\[bot] in [#​4202](itzg/docker-minecraft-server#4202) - Fix GraalVM flag selection when USE\_MEOWICE\_FLAGS is not set by [@​OowhitecatoO](https://github.com/OowhitecatoO) in [#​4204](itzg/docker-minecraft-server#4204) - Add SECURITY.md for security policy and reporting by [@​itzg](https://github.com/itzg) in [#​4207](itzg/docker-minecraft-server#4207) - Restore the GraalVM image variants by [@​OowhitecatoO](https://github.com/OowhitecatoO) in [#​4205](itzg/docker-minecraft-server#4205) - Update dependency itzg/mc-monitor to v0.17.0 by [@​renovate](https://github.com/renovate)\[bot] in [#​4209](itzg/docker-minecraft-server#4209) - Enable compact object headers on Java 24+ by [@​OowhitecatoO](https://github.com/OowhitecatoO) in [#​4211](itzg/docker-minecraft-server#4211) - Update dependency itzg/mc-image-helper to v1.64.1 by [@​renovate](https://github.com/renovate)\[bot] in [#​4213](itzg/docker-minecraft-server#4213) ##### New Contributors - [@​OowhitecatoO](https://github.com/OowhitecatoO) made their first contribution in [#​4201](itzg/docker-minecraft-server#4201) **Full Changelog**: <itzg/docker-minecraft-server@2026.7.2...2026.8.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41LjMiLCJ1cGRhdGVkSW5WZXIiOiI0NC41LjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=--> Reviewed-on: https://git.xcd.dev/gabrielcosi/home-ops/pulls/267
On a fork without Docker Hub secrets,
build.ymlfails at "Login to DockerHub" withUsername and password required, which fails the job and skips everything after it, so a fork cannot complete a build. The guard is there —if: env.HAS_IMAGE_REPO_ACCESS— butenvvalues are always strings and only the empty string is falsy, so"false"is truthy and the step runs anyway. The same applies toenv.PUSH &&in thepush:expression:&&returns an operand rather than a boolean, so the clause reduces to the rest of the condition and guards nothing.This compares the four boolean-valued
envreferences with== 'true'. It is a no-op on this repo, where both values aretrueand the expressions already produced the intended result; only fork behaviour changes. Example run: https://github.com/OowhitecatoO/docker-minecraft-server/actions/runs/30648142051 — the step log printsHAS_IMAGE_REPO_ACCESS: falsedirectly above the step running and failing. That run had the matrix trimmed to one variant to save CI time; the login steps themselves are unmodified.I hit this while trying to build the GraalVM variants on a fork. Along the way I found that current
masterbuildsjava21-graalvmfor both amd64 and arm64, and that thetar: Cannot open: Invalid argumentfailure behind #3899 no longer reproduces — including with the knockd retrieval that #3893 stubbed out restored: https://github.com/OowhitecatoO/docker-minecraft-server/actions/runs/30649087679. I have not opened anything for that. Is there still interest in those variants, or have you settled on dropping them?Details, if useful
The rule is in the expressions reference, under Literals:
The only falsy string is the empty string, so the string
"false"is truthy. That values read back out ofenvare strings is documented in theenvcontext, whereenv.<env_name>is typedstring, and GitHub's ownfromJSONexample notes that anenv:entry written ascontinue: truehas to be passed throughfromJSON()to become a boolean again.I compared with
== 'true'rather than moving the check into theif:directly, because the context availability table does not listsecretsforjobs.<job_id>.steps.if— it is the only step-level key that omits it — so theenvindirection forHAS_IMAGE_REPO_ACCESShas to stay. Using the same idiom forPUSHkeeps all four sites reading alike, and a note above theenv:block records why. Thepush:half is reasoned from the documented&&semantics rather than observed, since the failing login aborts the job before that step runs.Sites changed, all in
.github/workflows/build.yml:if: env.HAS_IMAGE_REPO_ACCESS(Login to DockerHub)if: env.HAS_IMAGE_REPO_ACCESS(Login to GHCR)github.tokenenv.PUSH &&inpush:&& env.HAS_IMAGE_REPO_ACCESSinpush:build.ymlhas nopull_requesttriggerThe DockerHub guard dates to #1645 and the GHCR one to #2051;
env.PUSHcame in with #4179. The other uses ofenvin this file —matrix.variant == env.MAIN_VARIANTand the plain string interpolations — are fine, since they compare or interpolate strings rather than relying on truthiness. The notification workflows guarded in #4179 are also fine, as they comparegithub.repository_ownerdirectly in expression context.