Run Sized Linux checks on the existing Gitea runner
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (push) Failing after 5s
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (push) Failing after 5s
This commit is contained in:
@@ -0,0 +1,40 @@
|
|||||||
|
name: Sized Linux checks
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main, sizequeen-scan-hardening]
|
||||||
|
paths: ['Cargo.toml', 'Cargo.lock', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
paths: ['Cargo.toml', 'Cargo.lock', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
linux-amd64:
|
||||||
|
name: Linux AMD64 / Rust 1.88.0
|
||||||
|
# Keep the existing shared runner limited to owner-triggered, same-repo code.
|
||||||
|
if: ${{ gitea.actor == 'gamertan' && (gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository) }}
|
||||||
|
runs-on: himesan-node24
|
||||||
|
timeout-minutes: 20
|
||||||
|
container:
|
||||||
|
image: sha256:514512270649a85769c2b8ecfcc3a860d3a7da67c29b9b7b1cfe4c75de41d322
|
||||||
|
options: >-
|
||||||
|
--user 65532:65532
|
||||||
|
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
|
||||||
|
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
|
||||||
|
env:
|
||||||
|
CARGO_HOME: /tmp/sized-cargo
|
||||||
|
CARGO_BUILD_JOBS: '2'
|
||||||
|
SIZED_TEST_SOURCE: ${{ gitea.workspace }}
|
||||||
|
SIZED_TEST_MOUNT_ROOT: /tmp/sized-mount-test
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
- name: Unprivileged Linux tests, real mount boundary, Clippy and release smoke
|
||||||
|
run: ./scripts/check-linux-container.sh
|
||||||
|
- name: Require an unchanged checkout
|
||||||
|
run: test -z "$(git status --porcelain=v1 --untracked-files=all)"
|
||||||
@@ -170,6 +170,13 @@ removed on exit. Docker retains the reusable check images/build cache.
|
|||||||
can select a different toolchain image for an explicit compatibility check.
|
can select a different toolchain image for an explicit compatibility check.
|
||||||
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
|
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
|
||||||
|
|
||||||
|
Gitea's `Sized Linux checks` workflow runs the same checks natively on cliff-mads
|
||||||
|
for main/review-branch source changes and owner-triggered, same-repository PRs.
|
||||||
|
It uses a pinned Rust job image, UID 65532 and real tmpfs boundaries without
|
||||||
|
Docker access inside the job. Fork contributions can run the local script;
|
||||||
|
maintainers can bring reviewed changes onto a repository branch for CI.
|
||||||
|
See SHIPMENT for runner-image setup. Documentation-only pushes skip builds.
|
||||||
|
|
||||||
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
|
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|||||||
+24
-3
@@ -23,9 +23,30 @@ in a separate PR so reviewers can distinguish behaviour changes from packaging.
|
|||||||
use the release steps below when explicitly authorized. Reconcile legacy
|
use the release steps below when explicitly authorized. Reconcile legacy
|
||||||
GitLab download/package links before announcing a Gitea release.
|
GitLab download/package links before announcing a Gitea release.
|
||||||
|
|
||||||
Use the same Linux check script in Gitea CI when a Docker-capable runner is
|
### Gitea Linux CI
|
||||||
configured. The current branch provides the local entry point; it does not
|
|
||||||
configure a runner or enable automatic publishing.
|
`.gitea/workflows/linux.yml` uses the existing `himesan-node24` label on
|
||||||
|
cliff-mads, overriding the job image with the pinned Sized Rust runtime.
|
||||||
|
The runner itself launches the two tmpfs mounts. Jobs have no Docker socket
|
||||||
|
and run `scripts/check-linux-container.sh` as UID 65532, using the checked-out
|
||||||
|
workspace as `SIZED_TEST_SOURCE`. Its tests, strict Clippy, formatting and
|
||||||
|
optimized-binary smoke test are the same as the local Docker workflow.
|
||||||
|
|
||||||
|
The runtime contains Rust 1.88.0, rustfmt/Clippy and Node for the pinned checkout
|
||||||
|
action. On cliff-mads, rebuild it explicitly with:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh cliff-mads 'docker build --platform linux/amd64 --tag local/gamertan-ci:sized-rust188 -' < scripts/gitea-linux.Dockerfile
|
||||||
|
ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-rust188 --format "{{.Id}}"'
|
||||||
|
```
|
||||||
|
|
||||||
|
Review and update the workflow's image ID after an intentional rebuild; images
|
||||||
|
stay local to the runner host. No runner labels, global isolation settings or
|
||||||
|
publishing credentials are required. Repository Actions must be enabled.
|
||||||
|
Only owner-triggered, same-repository code runs on this shared homelab runner.
|
||||||
|
Source changes on main/the review branch and PRs to main trigger checks;
|
||||||
|
documentation-only pushes skip builds. Manual dispatch is also available.
|
||||||
|
This workflow does not publish or tag releases.
|
||||||
|
|
||||||
## 1. Versioning and Tagging
|
## 1. Versioning and Tagging
|
||||||
|
|
||||||
|
|||||||
@@ -19,6 +19,9 @@ Keep the existing CLI useful and preserve the GPL-3.0-only license.
|
|||||||
- [x] Commit the scanner hardening and Linux check tooling; push the existing
|
- [x] Commit the scanner hardening and Linux check tooling; push the existing
|
||||||
`sizequeen-scan-hardening` review branch. Remote equality is verified.
|
`sizequeen-scan-hardening` review branch. Remote equality is verified.
|
||||||
Open a PR when ready; release/tag/package publication remains separate.
|
Open a PR when ready; release/tag/package publication remains separate.
|
||||||
|
- [ ] Enable repository Actions and run the same Linux checks on the existing
|
||||||
|
cliff-mads runner. Keep its container isolation and other jobs unchanged;
|
||||||
|
verify a real workflow result before treating CI as proven.
|
||||||
|
|
||||||
## Proposed next work
|
## Proposed next work
|
||||||
|
|
||||||
@@ -36,6 +39,14 @@ authorized; see `SHIPMENT.md` for source review and the separate release process
|
|||||||
|
|
||||||
## Resume note
|
## Resume note
|
||||||
|
|
||||||
|
Current CI checkpoint: repository Actions is enabled. The existing cliff-mads
|
||||||
|
runner is healthy (`gitea-runner v3.1.0`, native AMD64). The workflow reuses its
|
||||||
|
`himesan-node24` label and a separately built Rust/Node image; runner configuration,
|
||||||
|
other jobs and repository visibility are unchanged. The image bootstrap probe
|
||||||
|
verified UID 65532, workspace-volume ownership, Rust 1.88.0/Node 24.19.0 and
|
||||||
|
distinct tmpfs devices. Actual Gitea checkout/check execution is still pending;
|
||||||
|
do not call CI proven until the real workflow completes.
|
||||||
|
|
||||||
Linux validation and the requested remote review branch are complete.
|
Linux validation and the requested remote review branch are complete.
|
||||||
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
|
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
|
||||||
interpolations are `988aad9`. Both implementation commits are pushed to
|
interpolations are `988aad9`. Both implementation commits are pushed to
|
||||||
|
|||||||
@@ -10,8 +10,9 @@ cargo --version
|
|||||||
# Only source inputs are copied. Cargo output and all fixtures disappear with
|
# Only source inputs are copied. Cargo output and all fixtures disappear with
|
||||||
# the container; the host checkout is read-only and no personal tree is scanned.
|
# the container; the host checkout is read-only and no personal tree is scanned.
|
||||||
check_root=$(mktemp -d /tmp/sized-check.XXXXXX)
|
check_root=$(mktemp -d /tmp/sized-check.XXXXXX)
|
||||||
cp /source/Cargo.toml /source/Cargo.lock "$check_root/"
|
source_root=${SIZED_TEST_SOURCE:-/source}
|
||||||
cp -R /source/src /source/tests /source/benches "$check_root/"
|
cp "$source_root/Cargo.toml" "$source_root/Cargo.lock" "$check_root/"
|
||||||
|
cp -R "$source_root/src" "$source_root/tests" "$source_root/benches" "$check_root/"
|
||||||
cd "$check_root"
|
cd "$check_root"
|
||||||
cargo fmt --all -- --check
|
cargo fmt --all -- --check
|
||||||
cargo test --locked
|
cargo test --locked
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
# Node supports the pinned checkout action; application code remains Rust.
|
||||||
|
FROM node:24-bookworm@sha256:934240a162082fd8b8a2f90cd5114446443f1eba1c5378f6687167ca405e6584 AS node-runtime
|
||||||
|
FROM rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0
|
||||||
|
RUN rustup component add rustfmt clippy
|
||||||
|
COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node
|
||||||
|
# A new runner workspace volume inherits this ownership. No setuid step or
|
||||||
|
# Docker socket is needed in jobs, even with all capabilities dropped.
|
||||||
|
RUN mkdir -p /workspace && chown 65532:65532 /workspace
|
||||||
|
USER 65532:65532
|
||||||
|
WORKDIR /workspace
|
||||||
Reference in New Issue
Block a user