fix(deploy): make server workspace fixture readable

This commit is contained in:
2026-08-26 01:19:53 +02:00
parent 5877adcfac
commit 73efeb7f3d
+9 -3
View File
@@ -688,7 +688,7 @@ roots:
indexes: indexes
sessions: sessions
EOF
chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG"
chmod 0644 "$TASK13_SERVER_WORKSPACE_CONFIG"
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
@@ -1564,7 +1564,7 @@ task13_assert_server_runtime() {
|| task13_fail "server core did not use the smoke-built core image"
[[ "$(docker inspect --format '{{.Image}}' "$frontend_id")" == "$expected_frontend_image" ]] \
|| task13_fail "server frontend did not use the smoke-built frontend image"
task13_compose exec -T core sh -ceu '
task13_compose_logged "verify server runtime configuration and secret readability" exec -T core sh -ceu '
test -r /run/thothii-auth/auth.yaml
test -d /data/auth
test -z "${AUTH_MODE+x}"
@@ -2529,7 +2529,7 @@ task13_self_test_source_contract() {
local image_evidence_environment image_evidence_initialization
local server_auth_projection_override server_auth_projection_descriptor
local server_auth_projection_environment server_auth_privileged_configure
local server_fixture_reclamation
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
workflow="$root/.github/workflows/deployment.yml"
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
@@ -2560,6 +2560,8 @@ task13_self_test_source_contract() {
server_auth_projection_environment='THT_AUTH_RUNTIME_''ROOT=%s'
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
server_runtime_config_probe='task13_compose_''logged "verify server runtime configuration and secret readability"'
server_workspace_config_permission='chmod 0644 "$TASK13_SERVER_''WORKSPACE_CONFIG"'
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
"$root/scripts/unified-deployment-smoke.sh" \
"$root/scripts/tht-update-smoke.sh" \
@@ -2635,6 +2637,10 @@ task13_self_test_source_contract() {
[[ "$(grep -Ec "^${server_fixture_reclamation}\\(\\)|^[[:space:]]+${server_fixture_reclamation}$" \
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
grep -Fq -- "$server_runtime_config_probe" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the server runtime preconditions must emit a named diagnostic"
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the server workspace fixture must be readable by the container UID"
[[ -x "$runner_preparation" ]] \
|| task13_fail "the Linux Docker runner preparation must be executable"
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do