fix(ci): isolate generated smoke evidence

This commit is contained in:
2026-08-25 20:30:17 +02:00
parent 97c6788f16
commit 6afb5d242b
2 changed files with 16 additions and 1 deletions
+6
View File
@@ -159,10 +159,16 @@ jobs:
- name: Reclaim unused hosted-runner space
run: bash scripts/prepare-linux-docker-runner.sh
- name: Run unified deployment smoke
env:
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/unified-deployment-smoke.sh
- name: Run tht update smoke
env:
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/tht-update-smoke.sh
- name: Run Linux server deployment smoke
env:
TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}/task13-images.json
run: timeout --signal=TERM --kill-after=45s 32m bash scripts/server-deployment-smoke.sh
windows-clone:
+10 -1
View File
@@ -2474,6 +2474,7 @@ task13_self_test_source_contract() {
local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection
local application_secret_bind application_secret_mount application_secret_projection
local application_secret_parent_owner application_secret_file_owner
local image_evidence_environment image_evidence_initialization
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
workflow="$root/.github/workflows/deployment.yml"
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
@@ -2494,6 +2495,8 @@ task13_self_test_source_contract() {
application_secret_projection='task13_prepare_local_application_''secrets'
application_secret_parent_owner='chown 0:''0 /target'
application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password'
image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json'
image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"'
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
"$root/scripts/unified-deployment-smoke.sh" \
"$root/scripts/tht-update-smoke.sh" \
@@ -2547,6 +2550,10 @@ task13_self_test_source_contract() {
|| task13_fail "CI lacks an outer timeout for the tht update smoke"
grep -Fq 'bash scripts/prepare-linux-docker-runner.sh' "$workflow" \
|| task13_fail "CI must reclaim unused hosted-runner toolchains before the Docker release smoke"
[[ "$(grep -Fc -- "$image_evidence_environment" "$workflow")" -eq 3 ]] \
|| task13_fail "CI must write generated Docker image evidence outside the trusted checkout"
grep -Fq -- "$image_evidence_initialization" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the Docker image evidence output must honor an explicit CI path"
[[ -x "$runner_preparation" ]] \
|| task13_fail "the Linux Docker runner preparation must be executable"
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
@@ -2681,7 +2688,9 @@ task13_initialize() {
[[ -z "$source_status" ]] || task13_fail "source must be clean for image traceability"
TASK13_IMAGE_EVIDENCE_RECORDS="$TASK13_TMP/image-evidence.tsv"
: >"$TASK13_IMAGE_EVIDENCE_RECORDS"
TASK13_IMAGE_EVIDENCE_OUTPUT="$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json"
TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/.artifacts/task-15/unified-docker-images.json}"
[[ "$TASK13_IMAGE_EVIDENCE_OUTPUT" = /* ]] \
|| task13_fail "Docker image evidence output must be an absolute path"
rm -f "$TASK13_IMAGE_EVIDENCE_OUTPUT"
TASK13_PROFILE="local"
TASK13_INSTALLATION="$TASK13_TMP/thothii-installation.yaml"