Prepare repository workspace for unprivileged Gitea checkout
Sized Linux checks / Linux AMD64 / Rust 1.88.0 (push) Successful in 3m30s

This commit is contained in:
2026-10-09 18:47:58 -04:00
parent 67fe175ec7
commit 74b30bbf75
3 changed files with 5 additions and 3 deletions
+1 -1
View File
@@ -20,7 +20,7 @@ jobs:
runs-on: himesan-node24 runs-on: himesan-node24
timeout-minutes: 20 timeout-minutes: 20
container: container:
image: sha256:514512270649a85769c2b8ecfcc3a860d3a7da67c29b9b7b1cfe4c75de41d322 image: sha256:271ca1d26057c95a6fd30df7ccc0c053ab394c0e81cd1e4efa182b5b0b60ee97
options: >- options: >-
--user 65532:65532 --user 65532:65532
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 --tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
+3 -1
View File
@@ -41,7 +41,9 @@ ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-rust188 --format "{
``` ```
Review and update the workflow's image ID after an intentional rebuild; images Review and update the workflow's image ID after an intentional rebuild; images
stay local to the runner host. No runner labels, global isolation settings or stay local to the runner host. The image pre-owns `/workspace/gamertan/sized`
for UID 65532 so the runner's workspace setup permits unprivileged checkout.
No runner labels, global isolation settings or
publishing credentials are required. Repository Actions must be enabled. publishing credentials are required. Repository Actions must be enabled.
Only owner-triggered, same-repository code runs on this shared homelab runner. Only owner-triggered, same-repository code runs on this shared homelab runner.
Source changes on main/the review branch and PRs to main trigger checks; Source changes on main/the review branch and PRs to main trigger checks;
+1 -1
View File
@@ -5,6 +5,6 @@ RUN rustup component add rustfmt clippy
COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node
# A new runner workspace volume inherits this ownership. No setuid step or # A new runner workspace volume inherits this ownership. No setuid step or
# Docker socket is needed in jobs, even with all capabilities dropped. # Docker socket is needed in jobs, even with all capabilities dropped.
RUN mkdir -p /workspace && chown 65532:65532 /workspace RUN mkdir -p /workspace/gamertan/sized && chown -R 65532:65532 /workspace
USER 65532:65532 USER 65532:65532
WORKDIR /workspace WORKDIR /workspace