Run Sized Linux checks on the existing Gitea runner
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (push) Failing after 5s

This commit is contained in:
2026-10-09 18:46:33 -04:00
parent a1b40d1826
commit 67fe175ec7
6 changed files with 95 additions and 5 deletions
+40
View File
@@ -0,0 +1,40 @@
name: Sized Linux checks
on:
push:
branches: [main, sizequeen-scan-hardening]
paths: ['Cargo.toml', 'Cargo.lock', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
pull_request:
branches: [main]
paths: ['Cargo.toml', 'Cargo.lock', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
workflow_dispatch:
permissions:
contents: read
jobs:
linux-amd64:
name: Linux AMD64 / Rust 1.88.0
# Keep the existing shared runner limited to owner-triggered, same-repo code.
if: ${{ gitea.actor == 'gamertan' && (gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository) }}
runs-on: himesan-node24
timeout-minutes: 20
container:
image: sha256:514512270649a85769c2b8ecfcc3a860d3a7da67c29b9b7b1cfe4c75de41d322
options: >-
--user 65532:65532
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
env:
CARGO_HOME: /tmp/sized-cargo
CARGO_BUILD_JOBS: '2'
SIZED_TEST_SOURCE: ${{ gitea.workspace }}
SIZED_TEST_MOUNT_ROOT: /tmp/sized-mount-test
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
persist-credentials: false
- name: Unprivileged Linux tests, real mount boundary, Clippy and release smoke
run: ./scripts/check-linux-container.sh
- name: Require an unchanged checkout
run: test -z "$(git status --porcelain=v1 --untracked-files=all)"
+7
View File
@@ -170,6 +170,13 @@ removed on exit. Docker retains the reusable check images/build cache.
can select a different toolchain image for an explicit compatibility check. can select a different toolchain image for an explicit compatibility check.
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen. These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
Gitea's `Sized Linux checks` workflow runs the same checks natively on cliff-mads
for main/review-branch source changes and owner-triggered, same-repository PRs.
It uses a pinned Rust job image, UID 65532 and real tmpfs boundaries without
Docker access inside the job. Fork contributions can run the local script;
maintainers can bring reviewed changes onto a repository branch for CI.
See SHIPMENT for runner-image setup. Documentation-only pushes skip builds.
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md). See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
## License ## License
+24 -3
View File
@@ -23,9 +23,30 @@ in a separate PR so reviewers can distinguish behaviour changes from packaging.
use the release steps below when explicitly authorized. Reconcile legacy use the release steps below when explicitly authorized. Reconcile legacy
GitLab download/package links before announcing a Gitea release. GitLab download/package links before announcing a Gitea release.
Use the same Linux check script in Gitea CI when a Docker-capable runner is ### Gitea Linux CI
configured. The current branch provides the local entry point; it does not
configure a runner or enable automatic publishing. `.gitea/workflows/linux.yml` uses the existing `himesan-node24` label on
cliff-mads, overriding the job image with the pinned Sized Rust runtime.
The runner itself launches the two tmpfs mounts. Jobs have no Docker socket
and run `scripts/check-linux-container.sh` as UID 65532, using the checked-out
workspace as `SIZED_TEST_SOURCE`. Its tests, strict Clippy, formatting and
optimized-binary smoke test are the same as the local Docker workflow.
The runtime contains Rust 1.88.0, rustfmt/Clippy and Node for the pinned checkout
action. On cliff-mads, rebuild it explicitly with:
```bash
ssh cliff-mads 'docker build --platform linux/amd64 --tag local/gamertan-ci:sized-rust188 -' < scripts/gitea-linux.Dockerfile
ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-rust188 --format "{{.Id}}"'
```
Review and update the workflow's image ID after an intentional rebuild; images
stay local to the runner host. No runner labels, global isolation settings or
publishing credentials are required. Repository Actions must be enabled.
Only owner-triggered, same-repository code runs on this shared homelab runner.
Source changes on main/the review branch and PRs to main trigger checks;
documentation-only pushes skip builds. Manual dispatch is also available.
This workflow does not publish or tag releases.
## 1. Versioning and Tagging ## 1. Versioning and Tagging
+11
View File
@@ -19,6 +19,9 @@ Keep the existing CLI useful and preserve the GPL-3.0-only license.
- [x] Commit the scanner hardening and Linux check tooling; push the existing - [x] Commit the scanner hardening and Linux check tooling; push the existing
`sizequeen-scan-hardening` review branch. Remote equality is verified. `sizequeen-scan-hardening` review branch. Remote equality is verified.
Open a PR when ready; release/tag/package publication remains separate. Open a PR when ready; release/tag/package publication remains separate.
- [ ] Enable repository Actions and run the same Linux checks on the existing
cliff-mads runner. Keep its container isolation and other jobs unchanged;
verify a real workflow result before treating CI as proven.
## Proposed next work ## Proposed next work
@@ -36,6 +39,14 @@ authorized; see `SHIPMENT.md` for source review and the separate release process
## Resume note ## Resume note
Current CI checkpoint: repository Actions is enabled. The existing cliff-mads
runner is healthy (`gitea-runner v3.1.0`, native AMD64). The workflow reuses its
`himesan-node24` label and a separately built Rust/Node image; runner configuration,
other jobs and repository visibility are unchanged. The image bootstrap probe
verified UID 65532, workspace-volume ownership, Rust 1.88.0/Node 24.19.0 and
distinct tmpfs devices. Actual Gitea checkout/check execution is still pending;
do not call CI proven until the real workflow completes.
Linux validation and the requested remote review branch are complete. Linux validation and the requested remote review branch are complete.
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
interpolations are `988aad9`. Both implementation commits are pushed to interpolations are `988aad9`. Both implementation commits are pushed to
+3 -2
View File
@@ -10,8 +10,9 @@ cargo --version
# Only source inputs are copied. Cargo output and all fixtures disappear with # Only source inputs are copied. Cargo output and all fixtures disappear with
# the container; the host checkout is read-only and no personal tree is scanned. # the container; the host checkout is read-only and no personal tree is scanned.
check_root=$(mktemp -d /tmp/sized-check.XXXXXX) check_root=$(mktemp -d /tmp/sized-check.XXXXXX)
cp /source/Cargo.toml /source/Cargo.lock "$check_root/" source_root=${SIZED_TEST_SOURCE:-/source}
cp -R /source/src /source/tests /source/benches "$check_root/" cp "$source_root/Cargo.toml" "$source_root/Cargo.lock" "$check_root/"
cp -R "$source_root/src" "$source_root/tests" "$source_root/benches" "$check_root/"
cd "$check_root" cd "$check_root"
cargo fmt --all -- --check cargo fmt --all -- --check
cargo test --locked cargo test --locked
+10
View File
@@ -0,0 +1,10 @@
# Node supports the pinned checkout action; application code remains Rust.
FROM node:24-bookworm@sha256:934240a162082fd8b8a2f90cd5114446443f1eba1c5378f6687167ca405e6584 AS node-runtime
FROM rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0
RUN rustup component add rustfmt clippy
COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node
# A new runner workspace volume inherits this ownership. No setuid step or
# Docker socket is needed in jobs, even with all capabilities dropped.
RUN mkdir -p /workspace && chown 65532:65532 /workspace
USER 65532:65532
WORKDIR /workspace