Record successful cliff-mads Linux CI checkpoint

This commit is contained in:
2026-10-09 18:53:03 -04:00
parent 74b30bbf75
commit 9fd4e905b0
2 changed files with 25 additions and 10 deletions
+18 -10
View File
@@ -19,7 +19,7 @@ Keep the existing CLI useful and preserve the GPL-3.0-only license.
- [x] Commit the scanner hardening and Linux check tooling; push the existing
`sizequeen-scan-hardening` review branch. Remote equality is verified.
Open a PR when ready; release/tag/package publication remains separate.
- [ ] Enable repository Actions and run the same Linux checks on the existing
- [x] Enable repository Actions and run the same Linux checks on the existing
cliff-mads runner. Keep its container isolation and other jobs unchanged;
verify a real workflow result before treating CI as proven.
@@ -39,19 +39,27 @@ authorized; see `SHIPMENT.md` for source review and the separate release process
## Resume note
Current CI checkpoint: repository Actions is enabled. The existing cliff-mads
runner is healthy (`gitea-runner v3.1.0`, native AMD64). The workflow reuses its
`himesan-node24` label and a separately built Rust/Node image; runner configuration,
other jobs and repository visibility are unchanged. The image bootstrap probe
verified UID 65532, workspace-volume ownership, Rust 1.88.0/Node 24.19.0 and
distinct tmpfs devices. Actual Gitea checkout/check execution is still pending;
do not call CI proven until the real workflow completes.
Current CI checkpoint: repository Actions is enabled and a real native AMD64
push run passed on cliff-mads. [Gitea run 1048 (number 2)](https://gitea.speelman.ca/gamertan/sized/actions/runs/1048)
tested `74b30bbf750417121f3b0c26017d2f011a2a8286` on
`cliff-himesan-linux-amd64` (`gitea-runner v3.1.0`): all 23 tests, formatting,
strict Clippy, optimized-binary smoke and unchanged-checkout verification passed
as UID 65532 with Rust 1.88.0. It finished in 3m 30s. Filtered local evidence is
in ignored `target/linux-checks/gitea-run-1048.log`; full logs remain in Gitea.
The initial checkout failed because the repository directory was root-owned;
the corrected runtime pre-owns it for the job user. The workflow reuses the
existing `himesan-node24` label and a local, pinned Rust/Node image. Runner
configuration, other jobs and repository visibility are unchanged. Temporary
setup credentials were revoked and their files removed. Push execution is
proven; PR/manual-dispatch triggers are configured but not independently run.
Linux validation and the requested remote review branch are complete.
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
interpolations are `988aad9`. Both implementation commits are pushed to
`origin/sizequeen-scan-hardening`; SSH verified remote/local equality at
`988aad99510c0424cf0db5a116d9086183da74a5`. Gitea main remains `9c8d1d4`.
`origin/sizequeen-scan-hardening`, followed by CI setup `67fe175` and the
unprivileged checkout fix `74b30bb`. The source checkpoint is verified remotely
at `74b30bbf750417121f3b0c26017d2f011a2a8286`; later documentation-only
checkpoint commits do not rerun the source checks. Gitea main remains `9c8d1d4`.
The repository was already public (`private: false`); visibility is unchanged.
No PR, merge, tag, package publication or release occurred.