Files
sized/scripts/check-linux.sh

28 lines
1.4 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
# Pin the multi-platform official image, not a moving tag. Tests run on Linux
# filesystems rather than the source bind mount, whose permission semantics vary.
repo_root=$(cd "$(dirname "$0")/.." && pwd)
platform=${1:-linux/$(docker version --format '{{.Server.Arch}}')}
case "$platform" in
linux/arm64|linux/amd64) ;;
*) printf 'Usage: %s [linux/arm64|linux/amd64]\n' "$0" >&2; exit 2 ;;
esac
image=${SIZED_LINUX_IMAGE:-rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0}
check_image="sized-linux-check:${platform#linux/}"
mkdir -p "$repo_root/target/linux-checks"
log_file="$repo_root/target/linux-checks/${platform#linux/}.log"
docker build --platform "$platform" --build-arg "BASE_IMAGE=$image" \
--tag "$check_image" - < "$repo_root/scripts/linux-check.Dockerfile"
docker run --rm --platform "$platform" \
--user 65532:65532 --cap-drop ALL --security-opt no-new-privileges \
--mount "type=bind,src=$repo_root,dst=/source,readonly" \
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
--env CARGO_HOME=/tmp/sized-cargo \
--env CARGO_BUILD_JOBS="${SIZED_LINUX_JOBS:-2}" \
--env SIZED_TEST_MOUNT_ROOT=/tmp/sized-mount-test \
"$check_image" bash /source/scripts/check-linux-container.sh 2>&1 | tee "$log_file"