fix(ci): isolate generated smoke evidence
This commit is contained in:
@@ -159,10 +159,16 @@ jobs:
|
||||
- name: Reclaim unused hosted-runner space
|
||||
run: bash scripts/prepare-linux-docker-runner.sh
|
||||
- name: Run unified deployment smoke
|
||||
env:
|
||||
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
|
||||
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/unified-deployment-smoke.sh
|
||||
- name: Run tht update smoke
|
||||
env:
|
||||
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
|
||||
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/tht-update-smoke.sh
|
||||
- name: Run Linux server deployment smoke
|
||||
env:
|
||||
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
|
||||
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/server-deployment-smoke.sh
|
||||
|
||||
windows-clone:
|
||||
|
||||
@@ -2474,6 +2474,7 @@ task13_self_test_source_contract() {
|
||||
local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection
|
||||
local application_secret_bind application_secret_mount application_secret_projection
|
||||
local application_secret_parent_owner application_secret_file_owner
|
||||
local image_evidence_environment image_evidence_initialization
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
workflow="$root/.github/workflows/deployment.yml"
|
||||
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
|
||||
@@ -2494,6 +2495,8 @@ task13_self_test_source_contract() {
|
||||
application_secret_projection='task13_prepare_local_application_''secrets'
|
||||
application_secret_parent_owner='chown 0:''0 /target'
|
||||
application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password'
|
||||
image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json'
|
||||
image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"'
|
||||
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
||||
"$root/scripts/unified-deployment-smoke.sh" \
|
||||
"$root/scripts/tht-update-smoke.sh" \
|
||||
@@ -2547,6 +2550,10 @@ task13_self_test_source_contract() {
|
||||
|| task13_fail "CI lacks an outer timeout for the tht update smoke"
|
||||
grep -Fq 'bash scripts/prepare-linux-docker-runner.sh' "$workflow" \
|
||||
|| task13_fail "CI must reclaim unused hosted-runner toolchains before the Docker release smoke"
|
||||
[[ "$(grep -Fc -- "$image_evidence_environment" "$workflow")" -eq 3 ]] \
|
||||
|| task13_fail "CI must write generated Docker image evidence outside the trusted checkout"
|
||||
grep -Fq -- "$image_evidence_initialization" "$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "the Docker image evidence output must honor an explicit CI path"
|
||||
[[ -x "$runner_preparation" ]] \
|
||||
|| task13_fail "the Linux Docker runner preparation must be executable"
|
||||
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
|
||||
@@ -2681,7 +2688,9 @@ task13_initialize() {
|
||||
[[ -z "$source_status" ]] || task13_fail "source must be clean for image traceability"
|
||||
TASK13_IMAGE_EVIDENCE_RECORDS="$TASK13_TMP/image-evidence.tsv"
|
||||
: >"$TASK13_IMAGE_EVIDENCE_RECORDS"
|
||||
TASK13_IMAGE_EVIDENCE_OUTPUT="$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json"
|
||||
TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json}"
|
||||
[[ "$TASK13_IMAGE_EVIDENCE_OUTPUT" = /* ]] \
|
||||
|| task13_fail "Docker image evidence output must be an absolute path"
|
||||
rm -f "$TASK13_IMAGE_EVIDENCE_OUTPUT"
|
||||
TASK13_PROFILE="local"
|
||||
TASK13_INSTALLATION="$TASK13_TMP/thothii-installation.yaml"
|
||||
|
||||
Reference in New Issue
Block a user