Add reproducible unprivileged Linux build and mount checks
This commit is contained in:
@@ -149,6 +149,29 @@ for each request. Clones of the control expose progress and cancellation;
|
||||
cancellation is cooperative between filesystem calls. `build_tree` remains as
|
||||
a convenience helper, while `scan_tree` retains structured diagnostics.
|
||||
|
||||
## Development checks
|
||||
|
||||
Run `cargo test --locked` locally as an unprivileged user. For Linux build,
|
||||
permission, filesystem-boundary and release smoke checks with Docker:
|
||||
|
||||
```bash
|
||||
./scripts/check-linux.sh linux/arm64
|
||||
./scripts/check-linux.sh linux/amd64
|
||||
```
|
||||
|
||||
The script pins the official Rust 1.88.0 Bookworm image by digest, adds rustfmt
|
||||
and Clippy, then runs as UID 65532 with dropped capabilities. Source is mounted
|
||||
read-only and copied into the temporary container. Fixtures live on Linux
|
||||
filesystems, including two distinct tmpfs mounts; no privileged container or
|
||||
host directory scan is required. AMD64 on an ARM64 host requires emulation.
|
||||
Logs are saved in `target/linux-checks/`; containers and their build output are
|
||||
removed on exit. Docker retains the reusable check images/build cache.
|
||||
`SIZED_LINUX_JOBS` changes the default two build workers; `SIZED_LINUX_IMAGE`
|
||||
can select a different toolchain image for an explicit compatibility check.
|
||||
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
|
||||
|
||||
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
|
||||
|
||||
## License
|
||||
|
||||
This project is licensed under the **GNU General Public License v3.0 (GPL-3.0)**.
|
||||
|
||||
Reference in New Issue
Block a user