fix(ci): project private runtime fixtures

This commit is contained in:
2026-08-25 18:04:13 +02:00
parent abfcfb0e06
commit 2c2bf1940b
3 changed files with 123 additions and 15 deletions
+33 -9
View File
@@ -126,23 +126,47 @@ if (runtimePasswordMounts.length !== 1 || runtimePasswordMounts[0].type !== "bin
throw new Error("runtime fixture lacks one readable, read-only password-file bind");
}
accessSync(runtimePasswordMounts[0].source, constants.R_OK);
for (const target of [
const piTargets = [
"/home/thoth/.pi/agent/auth.json",
"/home/thoth/.pi/agent/models.json",
"/home/thoth/.pi/agent/settings.json",
]) {
] as const;
const piParent = mounts.filter((mount: any) => mount.target === "/home/thoth/.pi");
if (piParent.length !== 1) throw new Error("core lacks exactly one Pi state mount");
for (const target of piTargets) {
const selected = mounts.filter((mount: any) => mount.target === target);
if (selected.length !== 1 || selected[0].type !== "bind" || !selected[0].read_only) {
throw new Error(`Pi fixture mount is not one read-only bind: ${target}`);
}
accessSync(selected[0].source, constants.R_OK);
if (profile === "server") {
const parent = mounts.find((mount: any) => mount.target === "/home/thoth/.pi");
const hidden = join(parent.source, "agent", basename(target));
if (profile === "local") {
if (piParent[0].type !== "volume" || selected.length !== 0) {
throw new Error(`local Pi fixture must come only from the projected state volume: ${target}`);
}
} else {
if (selected.length !== 1 || selected[0].type !== "bind" || !selected[0].read_only) {
throw new Error(`Pi fixture mount is not one read-only bind: ${target}`);
}
accessSync(selected[0].source, constants.R_OK);
const hidden = join(piParent[0].source, "agent", basename(target));
if (!statSync(hidden).isFile()) throw new Error(`server parent root lacks ${hidden}`);
}
}
for (const [target, localVolume] of [
["/run/thothii-auth", "auth-runtime"],
["/fixtures/remote.git", "registry-remote"],
] as const) {
const selected = mounts.filter((mount: any) => mount.target === target);
if (selected.length !== 1 || !selected[0].read_only) {
throw new Error(`core lacks exactly one read-only runtime mount: ${target}`);
}
if (profile === "local") {
if (selected[0].type !== "volume"
|| (selected[0].source !== localVolume && !selected[0].source.endsWith(`_${localVolume}`))) {
throw new Error(`local runtime fixture is not projected through ${localVolume}`);
}
} else if (selected[0].type !== "bind") {
throw new Error(`server runtime fixture is not one read-only bind: ${target}`);
}
}
const resolverEnvironment = { ...core.environment };
const runtimePasswordSource = realpathSync(runtimePasswordMounts[0].source);
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = runtimePasswordSource;