fix(ci): run server compose through privileged surface
This commit is contained in:
@@ -321,16 +321,24 @@ task13_compose_files() {
|
||||
fi
|
||||
}
|
||||
|
||||
task13_compose_invoke() {
|
||||
if [[ "${TASK13_PROFILE:-local}" == server ]]; then
|
||||
sudo -n -- "$@"
|
||||
else
|
||||
"$@"
|
||||
fi
|
||||
}
|
||||
|
||||
task13_compose() {
|
||||
task13_compose_files
|
||||
"${TASK13_COMPOSE[@]}" "$@"
|
||||
task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@"
|
||||
}
|
||||
|
||||
task13_compose_logged() {
|
||||
local label="$1"
|
||||
shift
|
||||
task13_compose_files
|
||||
task13_run_logged "$label" "${TASK13_COMPOSE[@]}" "$@"
|
||||
task13_run_logged "$label" task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@"
|
||||
}
|
||||
|
||||
task13_report_core_startup_failure() {
|
||||
@@ -362,7 +370,7 @@ task13_compose_start_logged() {
|
||||
shift
|
||||
task13_compose_files
|
||||
if task13_bounded "$TASK13_COMMAND_TIMEOUT" "$label" \
|
||||
"${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then
|
||||
task13_compose_invoke "${TASK13_COMPOSE[@]}" "$@" >>"$TASK13_LOG" 2>&1; then
|
||||
return 0
|
||||
fi
|
||||
TASK13_FAILURE_LOGGED=1
|
||||
@@ -2008,7 +2016,7 @@ task13_cleanup() {
|
||||
if task13_assert_project_ownership >>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
||||
task13_compose_files
|
||||
if ! task13_bounded "$TASK13_CLEANUP_TIMEOUT" "stop owned Compose project" \
|
||||
"${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
|
||||
task13_compose_invoke "${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
|
||||
>>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
||||
cleanup_rc=1
|
||||
fi
|
||||
@@ -2584,6 +2592,7 @@ task13_self_test_source_contract() {
|
||||
local server_runtime_projection_status_contract
|
||||
local server_rollback_sentinel_read server_control_dir_reclamation
|
||||
local server_checkpoint_lookup
|
||||
local server_compose_privileged
|
||||
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
workflow="$root/.github/workflows/deployment.yml"
|
||||
@@ -2623,6 +2632,7 @@ task13_self_test_source_contract() {
|
||||
server_rollback_sentinel_read='sudo -n -- cat -- "$rollback_''sentinel"'
|
||||
server_control_dir_reclamation='"$TASK13_TMP" "$TASK13_CONTROL_''DIR"'
|
||||
server_checkpoint_lookup='task13_server_checkpoint_''leftover'
|
||||
server_compose_privileged='sudo -n -- "$''@"'
|
||||
server_secret_source_preparation='task13_prepare_server_secret_''sources'
|
||||
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
|
||||
server_tht_wrapper='task13_server_''tht'
|
||||
@@ -2719,6 +2729,8 @@ task13_self_test_source_contract() {
|
||||
[[ "$(grep -Ec "^${server_checkpoint_lookup}\\(\\)|${server_checkpoint_lookup}" \
|
||||
"$root/scripts/unified-deployment-smoke.sh")" -eq 3 ]] \
|
||||
|| task13_fail "server restore must inspect root-owned checkpoints through one privileged helper"
|
||||
grep -Fq -- "$server_compose_privileged" "$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "server Compose operations must use the privileged host surface"
|
||||
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
||||
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \
|
||||
|
||||
Reference in New Issue
Block a user