mirror of
https://github.com/stablyai/orca.git
synced 2026-10-03 16:02:11 +00:00
* test(ssh): upload a root reached through a symlinked parent The upload-root realpath fix landed with #24180; this keeps macoshost's case where the root is passed explicitly beneath a symlinked parent. * ci(ssh): macOS hostile-host lane on a loopback user-level sshd Adds local-sshd cells for darwin-arm64 (macos-14) and darwin-x64 (macos-15-intel): a non-root sshd on 127.0.0.1 logs in as the runner user with SetEnv PATH=<shims>:/usr/bin:/bin:/usr/sbin:/sbin and an empty HOME, so no rc file restores Homebrew. The driver asserts rung A, terminal echo, cached runtime reuse, GC keeping the in-use runtime, no toolchain or xattr calls, and that the SFTP-uploaded Node carries no quarantine and runs as uploaded. Docker cells are unchanged; each machine runs only cells it can host. * test(ssh): fail a hostile-host run that would skip every named or hostable cell A cell named for the wrong OS or arch was silently skipped, so a macOS job on a mismatched runner went green having deployed nothing. Named cells must now be hostable here, and a gated run must select at least one cell. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
78 lines
3.8 KiB
JavaScript
78 lines
3.8 KiB
JavaScript
import { readFileSync } from 'node:fs'
|
||
import { join, resolve } from 'node:path'
|
||
import { describe, expect, it } from 'vitest'
|
||
import { parse } from 'yaml'
|
||
import { NODE_RUNTIME_PIN } from '../../src/shared/node-runtime-pin.ts'
|
||
import { HOSTILE_HOST_CELLS } from '../../src/main/ssh/ssh-hostile-host-cells.ts'
|
||
|
||
const projectDir = resolve(import.meta.dirname, '../..')
|
||
const readText = (name) => readFileSync(join(projectDir, '.github/workflows', name), 'utf8')
|
||
const workflow = parse(readText('ssh-hostile-hosts.yml'))
|
||
|
||
function imageRefs(text, pattern) {
|
||
return [...new Set(text.match(pattern) ?? [])]
|
||
}
|
||
|
||
describe('SSH hostile-host workflow', () => {
|
||
it('runs on demand and on path-filtered, non-draft pull requests only', () => {
|
||
expect(Object.keys(workflow.on).sort()).toEqual(['pull_request', 'workflow_dispatch'])
|
||
expect(workflow.on.pull_request.paths).toContain('src/main/ssh/ssh-relay-*')
|
||
expect(workflow.jobs.glibc_slot.if).toContain('github.event.pull_request.draft != true')
|
||
expect(workflow.jobs.musl_slot.needs).toBe('glibc_slot')
|
||
expect(workflow.jobs.hosts.needs).toBe('musl_slot')
|
||
})
|
||
|
||
// Why: the slots must come from the same builders the headless-server lanes qualify, so a
|
||
// NODE_RUNTIME_PIN or builder move cannot leave this matrix testing a stale runtime.
|
||
it('builds the slots on the headless-server lanes’ pinned builder images', () => {
|
||
const nodeServer = readText('node-server-tests.yml')
|
||
const hostile = readText('ssh-hostile-hosts.yml')
|
||
const alpine = /node:[0-9.]+-alpine@sha256:[0-9a-f]{64}/g
|
||
const manylinux = /quay\.io\/pypa\/manylinux_2_28_x86_64@sha256:[0-9a-f]{64}/g
|
||
expect(imageRefs(hostile, alpine)).toEqual(imageRefs(nodeServer, alpine))
|
||
expect(imageRefs(hostile, alpine)).toEqual([
|
||
expect.stringMatching(new RegExp(`^node:${NODE_RUNTIME_PIN.version.replaceAll('.', '\\.')}-`))
|
||
])
|
||
expect(imageRefs(hostile, manylinux)).toEqual(imageRefs(nodeServer, manylinux))
|
||
expect(imageRefs(hostile, manylinux)).toHaveLength(1)
|
||
})
|
||
|
||
it('opts the matrix in and runs it against both x64 Linux slots', () => {
|
||
const steps = workflow.jobs.hosts.steps
|
||
const matrix = steps.find((step) => step.name === 'Run the hostile-host matrix')
|
||
expect(matrix.env.ORCA_RUN_SSH_HOSTILE_HOSTS).toBe('1')
|
||
expect(matrix.run).toBe('pnpm test src/main/ssh/ssh-relay-hostile-hosts.docker.test.ts')
|
||
expect(steps.map((step) => step.run ?? '').join('\n')).toContain(
|
||
'--targets linux-x64-glibc,linux-x64-musl'
|
||
)
|
||
})
|
||
|
||
// Why: each macOS cell expects its runner's own slot, so the runner, template target and cell
|
||
// must agree or the cell would test a slot the template never packaged.
|
||
it('runs each macOS cell on the runner and template target it expects', () => {
|
||
const job = workflow.jobs.macos_hosts
|
||
expect(job.if).toContain('github.event.pull_request.draft != true')
|
||
expect(job.needs).toBeUndefined()
|
||
const runners = { 'darwin-arm64': 'macos-14', 'darwin-x64': 'macos-15-intel' }
|
||
const macCells = HOSTILE_HOST_CELLS.filter((cell) => cell.host === 'local-sshd')
|
||
expect(
|
||
job.strategy.matrix.include.map(({ os, target, cell }) => ({ os, target, cell }))
|
||
).toEqual(
|
||
macCells.map((cell) => ({
|
||
os: runners[cell.expect.target],
|
||
target: cell.expect.target,
|
||
cell: cell.id
|
||
}))
|
||
)
|
||
const run = job.steps.map((step) => step.run ?? '').join('\n')
|
||
expect(run).toContain('--targets ${{ matrix.target }}')
|
||
expect(run).toContain('--require-slots ${{ matrix.target }}')
|
||
const cellStep = job.steps.find((step) => step.name === 'Run the macOS hostile-host cell')
|
||
expect(cellStep.env).toEqual({
|
||
ORCA_RUN_SSH_HOSTILE_HOSTS: '1',
|
||
ORCA_SSH_HOSTILE_HOST_CELLS: '${{ matrix.cell }}'
|
||
})
|
||
expect(cellStep.run).toBe('pnpm test src/main/ssh/ssh-relay-hostile-hosts.docker.test.ts')
|
||
})
|
||
})
|