Files
orca/config/scripts/ssh-hostile-hosts-workflow.test.mjs
T
OrcaWinandm4air f9940d5354 ci(ssh): macOS SSH-host lane for the pinned relay; fix uploads under a symlinked root (#24179)
* test(ssh): upload a root reached through a symlinked parent

The upload-root realpath fix landed with #24180; this keeps macoshost's case
where the root is passed explicitly beneath a symlinked parent.

* ci(ssh): macOS hostile-host lane on a loopback user-level sshd

Adds local-sshd cells for darwin-arm64 (macos-14) and darwin-x64
(macos-15-intel): a non-root sshd on 127.0.0.1 logs in as the runner user
with SetEnv PATH=<shims>:/usr/bin:/bin:/usr/sbin:/sbin and an empty HOME, so
no rc file restores Homebrew. The driver asserts rung A, terminal echo,
cached runtime reuse, GC keeping the in-use runtime, no toolchain or xattr
calls, and that the SFTP-uploaded Node carries no quarantine and runs as
uploaded. Docker cells are unchanged; each machine runs only cells it can host.

* test(ssh): fail a hostile-host run that would skip every named or hostable cell

A cell named for the wrong OS or arch was silently skipped, so a macOS job on a
mismatched runner went green having deployed nothing. Named cells must now be
hostable here, and a gated run must select at least one cell.

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-10-01 04:43:46 -07:00

78 lines
3.8 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import { readFileSync } from 'node:fs'
import { join, resolve } from 'node:path'
import { describe, expect, it } from 'vitest'
import { parse } from 'yaml'
import { NODE_RUNTIME_PIN } from '../../src/shared/node-runtime-pin.ts'
import { HOSTILE_HOST_CELLS } from '../../src/main/ssh/ssh-hostile-host-cells.ts'
const projectDir = resolve(import.meta.dirname, '../..')
const readText = (name) => readFileSync(join(projectDir, '.github/workflows', name), 'utf8')
const workflow = parse(readText('ssh-hostile-hosts.yml'))
function imageRefs(text, pattern) {
return [...new Set(text.match(pattern) ?? [])]
}
describe('SSH hostile-host workflow', () => {
it('runs on demand and on path-filtered, non-draft pull requests only', () => {
expect(Object.keys(workflow.on).sort()).toEqual(['pull_request', 'workflow_dispatch'])
expect(workflow.on.pull_request.paths).toContain('src/main/ssh/ssh-relay-*')
expect(workflow.jobs.glibc_slot.if).toContain('github.event.pull_request.draft != true')
expect(workflow.jobs.musl_slot.needs).toBe('glibc_slot')
expect(workflow.jobs.hosts.needs).toBe('musl_slot')
})
// Why: the slots must come from the same builders the headless-server lanes qualify, so a
// NODE_RUNTIME_PIN or builder move cannot leave this matrix testing a stale runtime.
it('builds the slots on the headless-server lanes’ pinned builder images', () => {
const nodeServer = readText('node-server-tests.yml')
const hostile = readText('ssh-hostile-hosts.yml')
const alpine = /node:[0-9.]+-alpine@sha256:[0-9a-f]{64}/g
const manylinux = /quay\.io\/pypa\/manylinux_2_28_x86_64@sha256:[0-9a-f]{64}/g
expect(imageRefs(hostile, alpine)).toEqual(imageRefs(nodeServer, alpine))
expect(imageRefs(hostile, alpine)).toEqual([
expect.stringMatching(new RegExp(`^node:${NODE_RUNTIME_PIN.version.replaceAll('.', '\\.')}-`))
])
expect(imageRefs(hostile, manylinux)).toEqual(imageRefs(nodeServer, manylinux))
expect(imageRefs(hostile, manylinux)).toHaveLength(1)
})
it('opts the matrix in and runs it against both x64 Linux slots', () => {
const steps = workflow.jobs.hosts.steps
const matrix = steps.find((step) => step.name === 'Run the hostile-host matrix')
expect(matrix.env.ORCA_RUN_SSH_HOSTILE_HOSTS).toBe('1')
expect(matrix.run).toBe('pnpm test src/main/ssh/ssh-relay-hostile-hosts.docker.test.ts')
expect(steps.map((step) => step.run ?? '').join('\n')).toContain(
'--targets linux-x64-glibc,linux-x64-musl'
)
})
// Why: each macOS cell expects its runner's own slot, so the runner, template target and cell
// must agree or the cell would test a slot the template never packaged.
it('runs each macOS cell on the runner and template target it expects', () => {
const job = workflow.jobs.macos_hosts
expect(job.if).toContain('github.event.pull_request.draft != true')
expect(job.needs).toBeUndefined()
const runners = { 'darwin-arm64': 'macos-14', 'darwin-x64': 'macos-15-intel' }
const macCells = HOSTILE_HOST_CELLS.filter((cell) => cell.host === 'local-sshd')
expect(
job.strategy.matrix.include.map(({ os, target, cell }) => ({ os, target, cell }))
).toEqual(
macCells.map((cell) => ({
os: runners[cell.expect.target],
target: cell.expect.target,
cell: cell.id
}))
)
const run = job.steps.map((step) => step.run ?? '').join('\n')
expect(run).toContain('--targets ${{ matrix.target }}')
expect(run).toContain('--require-slots ${{ matrix.target }}')
const cellStep = job.steps.find((step) => step.name === 'Run the macOS hostile-host cell')
expect(cellStep.env).toEqual({
ORCA_RUN_SSH_HOSTILE_HOSTS: '1',
ORCA_SSH_HOSTILE_HOST_CELLS: '${{ matrix.cell }}'
})
expect(cellStep.run).toBe('pnpm test src/main/ssh/ssh-relay-hostile-hosts.docker.test.ts')
})
})