diff --git a/.github/workflows/deployment.yml b/.github/workflows/deployment.yml index cea37e79..735f0207 100644 --- a/.github/workflows/deployment.yml +++ b/.github/workflows/deployment.yml @@ -159,10 +159,16 @@ jobs: - name: Reclaim unused hosted-runner space run: bash scripts/prepare-linux-docker-runner.sh - name: Run unified deployment smoke + env: + TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json run: timeout --signal=TERM --kill-after=45s 32m bash scripts/unified-deployment-smoke.sh - name: Run tht update smoke + env: + TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json run: timeout --signal=TERM --kill-after=45s 32m bash scripts/tht-update-smoke.sh - name: Run Linux server deployment smoke + env: + TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json run: timeout --signal=TERM --kill-after=45s 32m bash scripts/server-deployment-smoke.sh windows-clone: diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index 244f5365..1d682614 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -2474,6 +2474,7 @@ task13_self_test_source_contract() { local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection local application_secret_bind application_secret_mount application_secret_projection local application_secret_parent_owner application_secret_file_owner + local image_evidence_environment image_evidence_initialization root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" workflow="$root/.github/workflows/deployment.yml" runner_preparation="$root/scripts/prepare-linux-docker-runner.sh" @@ -2494,6 +2495,8 @@ task13_self_test_source_contract() { application_secret_projection='task13_prepare_local_application_''secrets' application_secret_parent_owner='chown 0:''0 /target' application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password' + image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json' + image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"' if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \ "$root/scripts/unified-deployment-smoke.sh" \ "$root/scripts/tht-update-smoke.sh" \ @@ -2547,6 +2550,10 @@ task13_self_test_source_contract() { || task13_fail "CI lacks an outer timeout for the tht update smoke" grep -Fq 'bash scripts/prepare-linux-docker-runner.sh' "$workflow" \ || task13_fail "CI must reclaim unused hosted-runner toolchains before the Docker release smoke" + [[ "$(grep -Fc -- "$image_evidence_environment" "$workflow")" -eq 3 ]] \ + || task13_fail "CI must write generated Docker image evidence outside the trusted checkout" + grep -Fq -- "$image_evidence_initialization" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "the Docker image evidence output must honor an explicit CI path" [[ -x "$runner_preparation" ]] \ || task13_fail "the Linux Docker runner preparation must be executable" for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do @@ -2681,7 +2688,9 @@ task13_initialize() { [[ -z "$source_status" ]] || task13_fail "source must be clean for image traceability" TASK13_IMAGE_EVIDENCE_RECORDS="$TASK13_TMP/image-evidence.tsv" : >"$TASK13_IMAGE_EVIDENCE_RECORDS" - TASK13_IMAGE_EVIDENCE_OUTPUT="$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json" + TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json}" + [[ "$TASK13_IMAGE_EVIDENCE_OUTPUT" = /* ]] \ + || task13_fail "Docker image evidence output must be an absolute path" rm -f "$TASK13_IMAGE_EVIDENCE_OUTPUT" TASK13_PROFILE="local" TASK13_INSTALLATION="$TASK13_TMP/thothii-installation.yaml"