#!/usr/bin/env bash set -euo pipefail # Pin the multi-platform official image, not a moving tag. Tests run on Linux # filesystems rather than the source bind mount, whose permission semantics vary. repo_root=$(cd "$(dirname "$0")/.." && pwd) platform=${1:-linux/$(docker version --format '{{.Server.Arch}}')} case "$platform" in linux/arm64|linux/amd64) ;; *) printf 'Usage: %s [linux/arm64|linux/amd64]\n' "$0" >&2; exit 2 ;; esac image=${SIZED_LINUX_IMAGE:-rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0} check_image="sized-linux-check:${platform#linux/}" mkdir -p "$repo_root/target/linux-checks" log_file="$repo_root/target/linux-checks/${platform#linux/}.log" docker build --platform "$platform" --build-arg "BASE_IMAGE=$image" \ --tag "$check_image" - < "$repo_root/scripts/linux-check.Dockerfile" docker run --rm --platform "$platform" \ --user 65532:65532 --cap-drop ALL --security-opt no-new-privileges \ --mount "type=bind,src=$repo_root,dst=/source,readonly" \ --tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \ --tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \ --env CARGO_HOME=/tmp/sized-cargo \ --env CARGO_BUILD_JOBS="${SIZED_LINUX_JOBS:-2}" \ --env SIZED_TEST_MOUNT_ROOT=/tmp/sized-mount-test \ "$check_image" bash /source/scripts/check-linux-container.sh 2>&1 | tee "$log_file"