fix(deploy): make server workspace fixture readable
This commit is contained in:
@@ -688,7 +688,7 @@ roots:
|
|||||||
indexes: indexes
|
indexes: indexes
|
||||||
sessions: sessions
|
sessions: sessions
|
||||||
EOF
|
EOF
|
||||||
chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG"
|
chmod 0644 "$TASK13_SERVER_WORKSPACE_CONFIG"
|
||||||
|
|
||||||
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
||||||
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
|
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
|
||||||
@@ -1564,7 +1564,7 @@ task13_assert_server_runtime() {
|
|||||||
|| task13_fail "server core did not use the smoke-built core image"
|
|| task13_fail "server core did not use the smoke-built core image"
|
||||||
[[ "$(docker inspect --format '{{.Image}}' "$frontend_id")" == "$expected_frontend_image" ]] \
|
[[ "$(docker inspect --format '{{.Image}}' "$frontend_id")" == "$expected_frontend_image" ]] \
|
||||||
|| task13_fail "server frontend did not use the smoke-built frontend image"
|
|| task13_fail "server frontend did not use the smoke-built frontend image"
|
||||||
task13_compose exec -T core sh -ceu '
|
task13_compose_logged "verify server runtime configuration and secret readability" exec -T core sh -ceu '
|
||||||
test -r /run/thothii-auth/auth.yaml
|
test -r /run/thothii-auth/auth.yaml
|
||||||
test -d /data/auth
|
test -d /data/auth
|
||||||
test -z "${AUTH_MODE+x}"
|
test -z "${AUTH_MODE+x}"
|
||||||
@@ -2529,7 +2529,7 @@ task13_self_test_source_contract() {
|
|||||||
local image_evidence_environment image_evidence_initialization
|
local image_evidence_environment image_evidence_initialization
|
||||||
local server_auth_projection_override server_auth_projection_descriptor
|
local server_auth_projection_override server_auth_projection_descriptor
|
||||||
local server_auth_projection_environment server_auth_privileged_configure
|
local server_auth_projection_environment server_auth_privileged_configure
|
||||||
local server_fixture_reclamation
|
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
|
||||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
workflow="$root/.github/workflows/deployment.yml"
|
workflow="$root/.github/workflows/deployment.yml"
|
||||||
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
|
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
|
||||||
@@ -2560,6 +2560,8 @@ task13_self_test_source_contract() {
|
|||||||
server_auth_projection_environment='THT_AUTH_RUNTIME_''ROOT=%s'
|
server_auth_projection_environment='THT_AUTH_RUNTIME_''ROOT=%s'
|
||||||
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
|
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
|
||||||
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
|
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
|
||||||
|
server_runtime_config_probe='task13_compose_''logged "verify server runtime configuration and secret readability"'
|
||||||
|
server_workspace_config_permission='chmod 0644 "$TASK13_SERVER_''WORKSPACE_CONFIG"'
|
||||||
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
||||||
"$root/scripts/unified-deployment-smoke.sh" \
|
"$root/scripts/unified-deployment-smoke.sh" \
|
||||||
"$root/scripts/tht-update-smoke.sh" \
|
"$root/scripts/tht-update-smoke.sh" \
|
||||||
@@ -2635,6 +2637,10 @@ task13_self_test_source_contract() {
|
|||||||
[[ "$(grep -Ec "^${server_fixture_reclamation}\\(\\)|^[[:space:]]+${server_fixture_reclamation}$" \
|
[[ "$(grep -Ec "^${server_fixture_reclamation}\\(\\)|^[[:space:]]+${server_fixture_reclamation}$" \
|
||||||
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
||||||
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
|
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
|
||||||
|
grep -Fq -- "$server_runtime_config_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server runtime preconditions must emit a named diagnostic"
|
||||||
|
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
||||||
[[ -x "$runner_preparation" ]] \
|
[[ -x "$runner_preparation" ]] \
|
||||||
|| task13_fail "the Linux Docker runner preparation must be executable"
|
|| task13_fail "the Linux Docker runner preparation must be executable"
|
||||||
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
|
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
|
||||||
|
|||||||
Reference in New Issue
Block a user