fix(ci): run server compose through privileged surface

This commit is contained in:
2026-08-26 03:53:06 +02:00
parent dfc605da78
commit 9a62fce1ad
2 changed files with 26 additions and 4 deletions
+16 -4
View File
@@ -321,16 +321,24 @@ task13_compose_files() {
fi
}
task13_compose_invoke() {
if [[ "${TASK13_PROFILE:-local}" == server ]]; then
sudo -n -- "$@"
else
"$@"
fi
}
task13_compose() {
task13_compose_files
"${TASK13_COMPOSE[@]}" "$@"
task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@"
}
task13_compose_logged() {
local label="$1"
shift
task13_compose_files
task13_run_logged "$label" "${TASK13_COMPOSE[@]}" "$@"
task13_run_logged "$label" task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@"
}
task13_report_core_startup_failure() {
@@ -362,7 +370,7 @@ task13_compose_start_logged() {
shift
task13_compose_files
if task13_bounded "$TASK13_COMMAND_TIMEOUT" "$label" \
"${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then
task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then
return 0
fi
TASK13_FAILURE_LOGGED=1
@@ -2008,7 +2016,7 @@ task13_cleanup() {
if task13_assert_project_ownership >>"${TASK13_LOG:-/dev/null}" 2>&1; then
task13_compose_files
if ! task13_bounded "$TASK13_CLEANUP_TIMEOUT" "stop owned Compose project" \
"${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
task13_compose_invoke "${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
>>"${TASK13_LOG:-/dev/null}" 2>&1; then
cleanup_rc=1
fi
@@ -2584,6 +2592,7 @@ task13_self_test_source_contract() {
local server_runtime_projection_status_contract
local server_rollback_sentinel_read server_control_dir_reclamation
local server_checkpoint_lookup
local server_compose_privileged
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
workflow="$root/.github/workflows/deployment.yml"
@@ -2623,6 +2632,7 @@ task13_self_test_source_contract() {
server_rollback_sentinel_read='sudo -n -- cat -- "$rollback_''sentinel"'
server_control_dir_reclamation='"$TASK13_TMP" "$TASK13_CONTROL_''DIR"'
server_checkpoint_lookup='task13_server_checkpoint_''leftover'
server_compose_privileged='sudo -n -- "$''@"'
server_secret_source_preparation='task13_prepare_server_secret_''sources'
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
server_tht_wrapper='task13_server_''tht'
@@ -2719,6 +2729,8 @@ task13_self_test_source_contract() {
[[ "$(grep -Ec "^${server_checkpoint_lookup}\\(\\)|${server_checkpoint_lookup}" \
"$root/scripts/unified-deployment-smoke.sh")" -eq 3 ]] \
|| task13_fail "server restore must inspect root-owned checkpoints through one privileged helper"
grep -Fq -- "$server_compose_privileged" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "server Compose operations must use the privileged host surface"
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the server workspace fixture must be readable by the container UID"
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \