diff --git a/scripts/test-task13-runtime-fixtures.sh b/scripts/test-task13-runtime-fixtures.sh index 582fe272..6052be6b 100755 --- a/scripts/test-task13-runtime-fixtures.sh +++ b/scripts/test-task13-runtime-fixtures.sh @@ -113,7 +113,17 @@ fi rendered="$fixture/rendered.json" docker compose --project-name "$TASK13_PROJECT" --project-directory "$root" \ --env-file "$TASK13_ENV_FILE" "${compose_files[@]}" config --format json >"$rendered" +if [[ "$profile" == server ]]; then + original_task13_compose_invoke="$(declare -f task13_compose_invoke)" + task13_compose_invoke() { + "$@" + } +fi task13_assert_rendered_contract +if [[ "$profile" == server ]]; then + unset -f task13_compose_invoke + eval "$original_task13_compose_invoke" +fi maintenance_rendered="$fixture/maintenance-rendered.json" docker compose --project-name "$TASK13_PROJECT" --project-directory "$root" \ --env-file "$TASK13_ENV_FILE" "${compose_files[@]}" --profile workspace-maintenance \ diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index 6c490687..bbad195c 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -321,16 +321,24 @@ task13_compose_files() { fi } +task13_compose_invoke() { + if [[ "${TASK13_PROFILE:-local}" == server ]]; then + sudo -n -- "$@" + else + "$@" + fi +} + task13_compose() { task13_compose_files - "${TASK13_COMPOSE[@]}" "$@" + task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@" } task13_compose_logged() { local label="$1" shift task13_compose_files - task13_run_logged "$label" "${TASK13_COMPOSE[@]}" "$@" + task13_run_logged "$label" task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@" } task13_report_core_startup_failure() { @@ -362,7 +370,7 @@ task13_compose_start_logged() { shift task13_compose_files if task13_bounded "$TASK13_COMMAND_TIMEOUT" "$label" \ - "${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then + task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then return 0 fi TASK13_FAILURE_LOGGED=1 @@ -2008,7 +2016,7 @@ task13_cleanup() { if task13_assert_project_ownership >>"${TASK13_LOG:-/dev/null}" 2>&1; then task13_compose_files if ! task13_bounded "$TASK13_CLEANUP_TIMEOUT" "stop owned Compose project" \ - "${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \ + task13_compose_invoke "${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \ >>"${TASK13_LOG:-/dev/null}" 2>&1; then cleanup_rc=1 fi @@ -2584,6 +2592,7 @@ task13_self_test_source_contract() { local server_runtime_projection_status_contract local server_rollback_sentinel_read server_control_dir_reclamation local server_checkpoint_lookup + local server_compose_privileged local server_secret_source_owner server_secret_source_preparation server_tht_wrapper root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" workflow="$root/.github/workflows/deployment.yml" @@ -2623,6 +2632,7 @@ task13_self_test_source_contract() { server_rollback_sentinel_read='sudo -n -- cat -- "$rollback_''sentinel"' server_control_dir_reclamation='"$TASK13_TMP" "$TASK13_CONTROL_''DIR"' server_checkpoint_lookup='task13_server_checkpoint_''leftover' + server_compose_privileged='sudo -n -- "$''@"' server_secret_source_preparation='task13_prepare_server_secret_''sources' server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"' server_tht_wrapper='task13_server_''tht' @@ -2719,6 +2729,8 @@ task13_self_test_source_contract() { [[ "$(grep -Ec "^${server_checkpoint_lookup}\\(\\)|${server_checkpoint_lookup}" \ "$root/scripts/unified-deployment-smoke.sh")" -eq 3 ]] \ || task13_fail "server restore must inspect root-owned checkpoints through one privileged helper" + grep -Fq -- "$server_compose_privileged" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "server Compose operations must use the privileged host surface" grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \ || task13_fail "the server workspace fixture must be readable by the container UID" [[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \