aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
-rw-r--r--.gitea/workflows/release.yml2
-rw-r--r--.gitea/workflows/test.yml2
-rw-r--r--internal/workflows/Containerfile14
-rwxr-xr-xinternal/workflows/build.sh5
-rw-r--r--internal/workflows/doc.go5
-rw-r--r--internal/workflows/release.go2
-rw-r--r--internal/workflows/step.go37
-rw-r--r--internal/workflows/test.go27
8 files changed, 26 insertions, 68 deletions
diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml
index a91e3c67..ceee8000 100644
--- a/.gitea/workflows/release.yml
+++ b/.gitea/workflows/release.yml
@@ -1 +1 @@
-{"name":"Release","on":{"push":{"tags":["v*"]}},"jobs":{"release":{"name":"Create release","runs-on":"rosa","steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4","with":{"fetch-depth":0,"fetch-tags":true}},{"name":"Request distribution","id":"dist","run":"/rosa/bin/mbf ci dist -o result . \"$(cat cmd/dist/VERSION)-act\" \u0026\u0026 git tag --list --format='%(contents:body)' \"$(cat cmd/dist/VERSION)\" \u003e\u003e \"/tmp/release-body\""},{"name":"Create release","uses":"https://gitea.com/actions/gitea-release-action@v1.3.7","with":{"files":"result/hakurei-**","body_path":"/tmp/release-body","draft":true}}]}}}
+{"name":"Release","on":{"push":{"tags":["v*"]}},"jobs":{"release":{"name":"Create release","runs-on":"rosa","steps":[{"name":"Checkout","uses":"actions/checkout@v4","with":{"fetch-depth":0,"fetch-tags":true}},{"name":"Request distribution","id":"dist","run":"/rosa/bin/mbf ci dist -o result . \"$(cat cmd/dist/VERSION)-act\" \u0026\u0026 git tag --list --format='%(contents:body)' \"$(cat cmd/dist/VERSION)\" \u003e\u003e \"/tmp/release-body\""},{"name":"Create release","uses":"https://gitea.com/actions/gitea-release-action@v1.3.7","with":{"files":"result/hakurei-**","body_path":"/tmp/release-body","draft":true}}]}}}
diff --git a/.gitea/workflows/test.yml b/.gitea/workflows/test.yml
index 7bef2dd9..4b3a4cfe 100644
--- a/.gitea/workflows/test.yml
+++ b/.gitea/workflows/test.yml
@@ -1 +1 @@
-{"name":"Test","on":["push"],"jobs":{"hakurei-legacy":{"name":"Hakurei (legacy)","runs-on":"nix","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Run NixOS test","run":"nix build --out-link result --print-out-paths --print-build-logs ./cmd/hakurei/testsuite#checks.x86_64-linux.hakurei"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"hakurei-vm-output","path":"result/*","retention-days":1}}]},"hakurei-race-legacy":{"name":"Hakurei (legacy with race instrument)","runs-on":"nix","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Run NixOS test","run":"nix build --out-link result --print-out-paths --print-build-logs ./cmd/hakurei/testsuite#checks.x86_64-linux.race"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"hakurei-race-vm-output","path":"result/*","retention-days":1}}]},"sandbox":{"name":"Sandbox","needs":["dist"],"runs-on":"rosa","steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Set up Go toolchain","uses":"actions/setup-go@v6","with":{"go-version-file":"go.mod"}},{"name":"Install packages","uses":"awalsh128/cache-apt-pkgs-action@v1","with":{"add-repository":"ppa:savoury1/pipewire","packages":"libmount-dev sway xwayland xdg-dbus-proxy pipewire","version":0,"execute_install_scripts":true}},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist.outputs.rev }}","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version \u0026\u0026 mkdir /var/empty"},{"name":"Compile and run test suite","run":"unshare -n go run -tags=testsuite ./cmd/hakurei/testsuite/sandbox"}]},"sandbox-race":{"name":"Sandbox (with race instrument)","needs":["dist-race"],"runs-on":"rosa","steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Set up Go toolchain","uses":"actions/setup-go@v6","with":{"go-version-file":"go.mod"}},{"name":"Install packages","uses":"awalsh128/cache-apt-pkgs-action@v1","with":{"add-repository":"ppa:savoury1/pipewire","packages":"libmount-dev sway xwayland xdg-dbus-proxy pipewire","version":0,"execute_install_scripts":true}},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist-race.outputs.rev }}-race","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version \u0026\u0026 mkdir /var/empty"},{"name":"Compile and run test suite","run":"unshare -n go run -tags=testsuite ./cmd/hakurei/testsuite/sandbox"}]},"sharefs":{"name":"ShareFS","needs":["dist"],"runs-on":"rosa","steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Set up Go toolchain","uses":"actions/setup-go@v6","with":{"go-version-file":"go.mod"}},{"name":"Install packages","uses":"awalsh128/cache-apt-pkgs-action@v1","with":{"add-repository":"","packages":"fuse3 fsmark","version":0,"execute_install_scripts":true}},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist.outputs.rev }}","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version \u0026\u0026 mkdir /var/empty"},{"name":"Mount sharefs","run":"useradd -ru 1023 -md /var/lib/sdcard -k /var/empty -s /sbin/nologin media_rw \u0026\u0026 install -dm0 /sdcard \u0026\u0026 sharefs -o rw,noexec,nosuid,nodev,noatime,allow_other,mkdir,source=/var/lib/sdcard,setuid=1023,setgid=1023 /sdcard"},{"name":"Compile and run test suite","run":"sharefs -V \u0026\u0026 go run -tags=testsuite ./cmd/sharefs/testsuite"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"fs_mark","path":"result/*","retention-days":1}}]},"dist":{"name":"Create distribution","runs-on":"rosa","outputs":{"rev":"${{ steps.dist.outputs.rev }}"},"steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Request distribution","id":"dist","run":"HAKUREI_REV=\"$(git rev-parse --short HEAD)\" \u0026\u0026 /rosa/bin/mbf ci dist -o result . \"$(cat cmd/dist/VERSION)-$HAKUREI_REV\" \u0026\u0026 echo \"rev=$HAKUREI_REV\" \u003e\u003e \"$GITHUB_OUTPUT\""},{"name":"Upload distribution","uses":"actions/upload-artifact@v3","with":{"name":"dist-${{ steps.dist.outputs.rev }}","path":"result/*","retention-days":1}}]},"dist-race":{"name":"Create distribution (with race instrument)","runs-on":"rosa","outputs":{"rev":"${{ steps.dist.outputs.rev }}"},"steps":[{"name":"Fix container filesystem","run":"rm /var/run \u0026\u0026 ln -sf ../run /var"},{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Request distribution","id":"dist","run":"HAKUREI_REV=\"$(git rev-parse --short HEAD)\" \u0026\u0026 /rosa/bin/mbf ci race -o result . \"$(cat cmd/dist/VERSION)-$HAKUREI_REV\" \u0026\u0026 echo \"rev=$HAKUREI_REV\" \u003e\u003e \"$GITHUB_OUTPUT\""},{"name":"Upload distribution","uses":"actions/upload-artifact@v3","with":{"name":"dist-${{ steps.dist.outputs.rev }}-race","path":"result/*","retention-days":1}}]}}}
+{"name":"Test","on":["push"],"jobs":{"hakurei-legacy":{"name":"Hakurei (legacy)","runs-on":"nix","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Run NixOS test","run":"nix build --out-link result --print-out-paths --print-build-logs ./cmd/hakurei/testsuite#checks.x86_64-linux.hakurei"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"hakurei-vm-output","path":"result/*","retention-days":1}}]},"hakurei-race-legacy":{"name":"Hakurei (legacy with race instrument)","runs-on":"nix","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Run NixOS test","run":"nix build --out-link result --print-out-paths --print-build-logs ./cmd/hakurei/testsuite#checks.x86_64-linux.race"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"hakurei-race-vm-output","path":"result/*","retention-days":1}}]},"sandbox":{"name":"Sandbox","needs":["dist"],"runs-on":"rosa","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist.outputs.rev }}","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version"},{"name":"Compile and run test suite","run":"unshare -n go run -tags=testsuite ./cmd/hakurei/testsuite/sandbox"}]},"sandbox-race":{"name":"Sandbox (with race instrument)","needs":["dist-race"],"runs-on":"rosa","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist-race.outputs.rev }}-race","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version"},{"name":"Compile and run test suite","run":"unshare -n go run -tags=testsuite ./cmd/hakurei/testsuite/sandbox"}]},"sharefs":{"name":"ShareFS","needs":["dist"],"runs-on":"rosa","steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Download hakurei distribution","uses":"actions/download-artifact@v3","id":"download","with":{"name":"dist-${{ needs.dist.outputs.rev }}","path":"/tmp/dist"}},{"name":"Install hakurei","run":"HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)\" \u0026\u0026 tar -C /tmp/dist -xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz \u0026\u0026 /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh \u0026\u0026 rm -rf /tmp/dist \u0026\u0026 sudo -u ubuntu hakurei version"},{"name":"Mount sharefs","run":"useradd -ru 1023 -md /var/lib/sdcard -k /var/empty -s /sbin/nologin media_rw \u0026\u0026 install -dm0 /sdcard \u0026\u0026 sharefs -o rw,noexec,nosuid,nodev,noatime,allow_other,mkdir,source=/var/lib/sdcard,setuid=1023,setgid=1023 /sdcard"},{"name":"Compile and run test suite","run":"sharefs -V \u0026\u0026 go run -tags=testsuite ./cmd/sharefs/testsuite"},{"name":"Upload test output","uses":"actions/upload-artifact@v3","with":{"name":"fs_mark","path":"result/*","retention-days":1}}]},"dist":{"name":"Create distribution","runs-on":"rosa","outputs":{"rev":"${{ steps.dist.outputs.rev }}"},"steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Request distribution","id":"dist","run":"HAKUREI_REV=\"$(git rev-parse --short HEAD)\" \u0026\u0026 /rosa/bin/mbf ci dist -o result . \"$(cat cmd/dist/VERSION)-$HAKUREI_REV\" \u0026\u0026 echo \"rev=$HAKUREI_REV\" \u003e\u003e \"$GITHUB_OUTPUT\""},{"name":"Upload distribution","uses":"actions/upload-artifact@v3","with":{"name":"dist-${{ steps.dist.outputs.rev }}","path":"result/*","retention-days":1}}]},"dist-race":{"name":"Create distribution (with race instrument)","runs-on":"rosa","outputs":{"rev":"${{ steps.dist.outputs.rev }}"},"steps":[{"name":"Checkout","uses":"actions/checkout@v4"},{"name":"Request distribution","id":"dist","run":"HAKUREI_REV=\"$(git rev-parse --short HEAD)\" \u0026\u0026 /rosa/bin/mbf ci race -o result . \"$(cat cmd/dist/VERSION)-$HAKUREI_REV\" \u0026\u0026 echo \"rev=$HAKUREI_REV\" \u003e\u003e \"$GITHUB_OUTPUT\""},{"name":"Upload distribution","uses":"actions/upload-artifact@v3","with":{"name":"dist-${{ steps.dist.outputs.rev }}-race","path":"result/*","retention-days":1}}]}}}
diff --git a/internal/workflows/Containerfile b/internal/workflows/Containerfile
new file mode 100644
index 00000000..3b1baeda
--- /dev/null
+++ b/internal/workflows/Containerfile
@@ -0,0 +1,14 @@
+FROM docker.gitea.com/runner-images:ubuntu-latest
+
+RUN rm /var/run && ln -sf ../run /var && mkdir /var/empty
+RUN add-apt-repository -y ppa:savoury1/pipewire && \
+ apt-get update && apt-get install -y \
+ msft-golang \
+ libmount-dev \
+ sway \
+ xwayland \
+ xdg-dbus-proxy \
+ pipewire \
+ fuse3 \
+ fsmark && \
+ apt-get clean && rm -rf /var/lib/apt/lists/*
diff --git a/internal/workflows/build.sh b/internal/workflows/build.sh
new file mode 100755
index 00000000..f7b266a0
--- /dev/null
+++ b/internal/workflows/build.sh
@@ -0,0 +1,5 @@
+#!/bin/sh -e
+
+TAG="git.gensokyo.uk/rosa/runner:latest"
+podman build -t "$TAG" --format docker .
+podman push "$TAG"
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go
index 2227e50f..123bf7c1 100644
--- a/internal/workflows/doc.go
+++ b/internal/workflows/doc.go
@@ -53,7 +53,6 @@ The container can be specified via docker-compose:
environment:
CONFIG_FILE: /config.yaml
GITEA_INSTANCE_URL: "https://git.gensokyo.uk"
- GITEA_RUNNER_LABELS: "rosa:docker://docker.gitea.com/runner-images:ubuntu-latest"
GITEA_RUNNER_REGISTRATION_TOKEN: "${REGISTRATION_TOKEN}"
GITEA_RUNNER_NAME: "${RUNNER_NAME}"
@@ -80,6 +79,10 @@ Before starting the container, configure act_runner via config.yaml:
valid_volumes:
- /var/lib/rosa
+ runner:
+ labels:
+ - 'rosa:docker://git.gensokyo.uk/rosa/runner:latest'
+
where /var/lib/rosa is the absolute pathname of the cache directory in the init
namespace. Setting MBF_POISON_OPEN enables cmd/mbf to run as root. It is also
a good idea here to set runner.capacity to reflect the capacity of the guest, so
diff --git a/internal/workflows/release.go b/internal/workflows/release.go
index f220c0f7..a2f4c687 100644
--- a/internal/workflows/release.go
+++ b/internal/workflows/release.go
@@ -12,8 +12,6 @@ var _ = (&Workflow{
On: "rosa",
Steps: []Step{
- fixup,
-
{
Name: "Checkout",
Uses: "actions/checkout@v4",
diff --git a/internal/workflows/step.go b/internal/workflows/step.go
index d4e9c2d8..b53671b6 100644
--- a/internal/workflows/step.go
+++ b/internal/workflows/step.go
@@ -2,28 +2,9 @@
package main
-import "strings"
-
-// fixup is a step to work around a Podman regression introduced by a bad
-// container escape mitigation.
-var fixup = Step{
- Name: "Fix container filesystem",
- Run: "rm /var/run && ln -sf ../run /var",
-}
-
// checkout is the standard actions/checkout step.
var checkout = Step{Name: "Checkout", Uses: "actions/checkout@v4"}
-// toolchain is a step for setting up the Go toolchain.
-var toolchain = Step{
- Name: "Set up Go toolchain",
- Uses: "actions/setup-go@v6",
-
- With: []KV[any]{
- {"go-version-file", "go.mod"},
- },
-}
-
// newUploadArtifact returns an actions/upload-artifact step uploading
// everything in the result directory as the specified name.
func newUploadArtifact(display, name string) Step {
@@ -85,8 +66,7 @@ var install = Step{
"-xf /tmp/dist/hakurei-$HAKUREI_VERSION*-amd64.tar.gz && " +
"/tmp/dist/hakurei-$HAKUREI_VERSION*-amd64/install.sh && " +
"rm -rf /tmp/dist && " +
- "sudo -u ubuntu hakurei version && " +
- "mkdir /var/empty",
+ "sudo -u ubuntu hakurei version",
}
// newTestsuite returns a step for running an integration test suite.
@@ -97,21 +77,6 @@ func newTestsuite(name, prefix string) Step {
}
}
-// newPackages returns a job for installing the specified packages with
-// best-effort caching. Package names must not contain spaces.
-func newPackages(rev int, repos []string, packages ...string) Step {
- return Step{
- Name: "Install packages",
- Uses: "awalsh128/cache-apt-pkgs-action@v1",
- With: []KV[any]{
- {"add-repository", strings.Join(repos, " ")},
- {"packages", strings.Join(packages, " ")},
- {"version", rev},
- {"execute_install_scripts", true},
- },
- }
-}
-
// newNixOSTest returns a step for running the named NixOS test.
func newNixOSTest(name string) Step {
return Step{
diff --git a/internal/workflows/test.go b/internal/workflows/test.go
index 80fb01e5..6cea7842 100644
--- a/internal/workflows/test.go
+++ b/internal/workflows/test.go
@@ -35,17 +35,7 @@ var _ = (&Workflow{
Needs: []string{"dist"},
Steps: []Step{
- fixup,
checkout,
- toolchain,
- newPackages(0, []string{"ppa:savoury1/pipewire"},
- "libmount-dev",
- "sway",
- "xwayland",
- "xdg-dbus-proxy",
- "pipewire",
- ),
-
download,
install,
newTestsuite("hakurei/testsuite/sandbox", "unshare -n "),
@@ -58,18 +48,7 @@ var _ = (&Workflow{
Needs: []string{"dist-race"},
Steps: []Step{
- fixup,
checkout,
- toolchain,
-
- newPackages(0, []string{"ppa:savoury1/pipewire"},
- "libmount-dev",
- "sway",
- "xwayland",
- "xdg-dbus-proxy",
- "pipewire",
- ),
-
_download,
install,
newTestsuite("hakurei/testsuite/sandbox", "unshare -n "),
@@ -82,11 +61,7 @@ var _ = (&Workflow{
Needs: []string{"dist"},
Steps: []Step{
- fixup,
checkout,
- toolchain,
- newPackages(0, nil, "fuse3", "fsmark"),
-
download,
install,
@@ -118,7 +93,6 @@ var _ = (&Workflow{
},
Steps: []Step{
- fixup,
checkout,
newCIRequest("distribution", "dist -o result", "dist"),
newUploadArtifact(
@@ -137,7 +111,6 @@ var _ = (&Workflow{
},
Steps: []Step{
- fixup,
checkout,
newCIRequest("distribution", "race -o result", "dist"),
newUploadArtifact(