Add reproducible unprivileged Linux build and mount checks
This commit is contained in:
Executable
+26
@@ -0,0 +1,26 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
test "$(uname -s)" = Linux
|
||||
test "$(id -u)" != 0
|
||||
printf 'Linux checks: uid=%s architecture=%s\n' "$(id -u)" "$(uname -m)"
|
||||
rustc --version
|
||||
cargo --version
|
||||
|
||||
# Only source inputs are copied. Cargo output and all fixtures disappear with
|
||||
# the container; the host checkout is read-only and no personal tree is scanned.
|
||||
check_root=$(mktemp -d /tmp/sized-check.XXXXXX)
|
||||
cp /source/Cargo.toml /source/Cargo.lock "$check_root/"
|
||||
cp -R /source/src /source/tests /source/benches "$check_root/"
|
||||
cd "$check_root"
|
||||
cargo fmt --all -- --check
|
||||
cargo test --locked
|
||||
cargo test --locked --test linux_mount -- --ignored
|
||||
cargo clippy --locked --all-targets -- -D warnings
|
||||
cargo build --locked --release
|
||||
|
||||
fixture_root=$(mktemp -d /tmp/sized-release.XXXXXX)
|
||||
printf 'Linux release smoke test\n' > "$fixture_root/payload"
|
||||
./target/release/sized --version
|
||||
./target/release/sized "$fixture_root" --threads 2 --one-file-system --apparent --format json
|
||||
printf 'Linux checks passed.\n'
|
||||
Executable
+27
@@ -0,0 +1,27 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
# Pin the multi-platform official image, not a moving tag. Tests run on Linux
|
||||
# filesystems rather than the source bind mount, whose permission semantics vary.
|
||||
repo_root=$(cd "$(dirname "$0")/.." && pwd)
|
||||
platform=${1:-linux/$(docker version --format '{{.Server.Arch}}')}
|
||||
case "$platform" in
|
||||
linux/arm64|linux/amd64) ;;
|
||||
*) printf 'Usage: %s [linux/arm64|linux/amd64]\n' "$0" >&2; exit 2 ;;
|
||||
esac
|
||||
image=${SIZED_LINUX_IMAGE:-rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0}
|
||||
check_image="sized-linux-check:${platform#linux/}"
|
||||
mkdir -p "$repo_root/target/linux-checks"
|
||||
log_file="$repo_root/target/linux-checks/${platform#linux/}.log"
|
||||
|
||||
docker build --platform "$platform" --build-arg "BASE_IMAGE=$image" \
|
||||
--tag "$check_image" - < "$repo_root/scripts/linux-check.Dockerfile"
|
||||
docker run --rm --platform "$platform" \
|
||||
--user 65532:65532 --cap-drop ALL --security-opt no-new-privileges \
|
||||
--mount "type=bind,src=$repo_root,dst=/source,readonly" \
|
||||
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
|
||||
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
|
||||
--env CARGO_HOME=/tmp/sized-cargo \
|
||||
--env CARGO_BUILD_JOBS="${SIZED_LINUX_JOBS:-2}" \
|
||||
--env SIZED_TEST_MOUNT_ROOT=/tmp/sized-mount-test \
|
||||
"$check_image" bash /source/scripts/check-linux-container.sh 2>&1 | tee "$log_file"
|
||||
@@ -0,0 +1,3 @@
|
||||
ARG BASE_IMAGE=rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0
|
||||
FROM ${BASE_IMAGE}
|
||||
RUN rustup component add rustfmt clippy
|
||||
Reference in New Issue
Block a user