Add reproducible unprivileged Linux build and mount checks

This commit is contained in:
2026-10-09 18:32:37 -04:00
parent 8b177e21a0
commit 988aad9951
11 changed files with 212 additions and 10 deletions
+23
View File
@@ -149,6 +149,29 @@ for each request. Clones of the control expose progress and cancellation;
cancellation is cooperative between filesystem calls. `build_tree` remains as
a convenience helper, while `scan_tree` retains structured diagnostics.
## Development checks
Run `cargo test --locked` locally as an unprivileged user. For Linux build,
permission, filesystem-boundary and release smoke checks with Docker:
```bash
./scripts/check-linux.sh linux/arm64
./scripts/check-linux.sh linux/amd64
```
The script pins the official Rust 1.88.0 Bookworm image by digest, adds rustfmt
and Clippy, then runs as UID 65532 with dropped capabilities. Source is mounted
read-only and copied into the temporary container. Fixtures live on Linux
filesystems, including two distinct tmpfs mounts; no privileged container or
host directory scan is required. AMD64 on an ARM64 host requires emulation.
Logs are saved in `target/linux-checks/`; containers and their build output are
removed on exit. Docker retains the reusable check images/build cache.
`SIZED_LINUX_JOBS` changes the default two build workers; `SIZED_LINUX_IMAGE`
can select a different toolchain image for an explicit compatibility check.
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
## License
This project is licensed under the **GNU General Public License v3.0 (GPL-3.0)**.