diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index b3f9451e3..e412d1455 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -144,6 +144,40 @@ jobs: with: cache-on-failure: true - uses: taiki-e/install-action@773334c0e05d7e699e4d78234494308223f3a2cf # nextest + # Every Petri run takes its scope through a sandbox-driver plugin + # executable that Petri finds on PATH: `sandbox-driver-host` for the + # `local` provider, `sandbox-driver-docker` for `docker`. Installed + # at the rev the workspace pins, so the plugins and the in-process + # driver are one build; a from-source build, so the two executables + # are cached by OS and rev and only rebuilt when the pin moves. + - name: Read the sandbox-driver rev the workspace pins + id: sandbox-driver + run: | + rev="$(sed -n 's/^sandbox-driver = { git = "[^"]*", rev = "\([0-9a-f]*\)" }$/\1/p' Cargo.toml)" + test -n "$rev" + echo "rev=$rev" >> "$GITHUB_OUTPUT" + - name: Restore the sandbox-driver plugin executables + id: sandbox-driver-cache + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + with: + path: | + ~/.cargo/bin/sandbox-driver-host + ~/.cargo/bin/sandbox-driver-docker + key: sandbox-driver-plugins-${{ runner.os }}-${{ steps.sandbox-driver.outputs.rev }} + - name: Install the sandbox-driver plugin executables + if: steps.sandbox-driver-cache.outputs.cache-hit != 'true' + run: cargo install --locked --git https://github.com/lithoscomputer/sandbox-driver --rev "${{ steps.sandbox-driver.outputs.rev }}" sandbox-driver-host sandbox-driver-docker + # The Docker scenarios in the suite leave the image to Petri, whose + # Docker scope runs on its default runner image; the plugin pulls it + # on first use, but a 1 GiB pull inside a run's timeout is a flake. + # Pull it here, at the pin the checked-out Petri names, so a registry + # problem reads as one. + - name: Pull Petri's default runner image + run: | + backend="$(dirname "$(cargo metadata --locked --format-version 1 | jq -r '.packages[] | select(.name == "petri-executor-sandbox") | .manifest_path')")/src/backend.rs" + pin="$(sed -n 's/^const RUNNER_PIN: &str = "\([0-9a-f]*\)";$/\1/p' "$backend")" + test -n "$pin" + docker pull "ghcr.io/lithoscomputer/ubuntu-24.04:slim-$pin" - run: cargo nextest run --locked --workspace --status-level slow --profile ci # The twin-mode ignored suites this job once ran belonged to fabro-agent, # which pebble's coding agent replaced; the agent loop's workflow-level @@ -151,14 +185,14 @@ jobs: # Re-add a `--run-ignored only -E 'package(...)'` step here when a # package has ignored suites that are fully green in twin mode. - sandbox-plugins: - name: Sandbox plugins (stdio) + sandbox-docker: + name: Sandbox providers (Docker) runs-on: ubuntu-24.04-x86-32-cores permissions: contents: read env: - # The plugin scenarios skip when an executable or daemon is missing; - # in CI a skip is a failure. + # The Docker scenarios skip when the executable, the daemon or the + # image is missing; in CI a skip is a failure. FABRO_REQUIRE_SANDBOX_PLUGINS: "1" steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 @@ -171,28 +205,38 @@ jobs: with: cache-on-failure: true - uses: taiki-e/install-action@773334c0e05d7e699e4d78234494308223f3a2cf # nextest + # The image the Docker scenarios' environment names. - run: docker pull buildpack-deps:noble - # The driver's own Host and Docker executables, installed at the rev the - # workspace pins so the plugins and the in-process providers are one - # build; the CLI scenarios find them on PATH and launch them over stdio. - - name: Install the sandbox-driver plugin executables + # Every Petri run takes its scope through a sandbox-driver plugin + # executable that Petri finds on PATH: `sandbox-driver-host` for the + # `local` provider, `sandbox-driver-docker` for `docker`. Installed + # at the rev the workspace pins, so the plugins and the in-process + # driver are one build; a from-source build, so the two executables + # are cached by OS and rev and only rebuilt when the pin moves. + - name: Read the sandbox-driver rev the workspace pins + id: sandbox-driver run: | rev="$(sed -n 's/^sandbox-driver = { git = "[^"]*", rev = "\([0-9a-f]*\)" }$/\1/p' Cargo.toml)" test -n "$rev" - cargo install --locked --git https://github.com/lithoscomputer/sandbox-driver --rev "$rev" sandbox-driver-host sandbox-driver-docker - # Host and Docker served as plugins through the workflow scenarios. The - # scenarios are e2e tests (ignored by default); the key-free ones run - # here, the LLM-backed ones self-skip without credentials. - - run: cargo nextest run --locked --profile ci --status-level slow --run-ignored only -p fabro-cli --test it -E 'test(/host_plugin_|docker_plugin_/)' - # The stdio plugin proof (not ignored: it skips without the executable, - # which the environment above forbids) and the driver-backed Docker - # integration tests. - - run: cargo nextest run --locked --profile ci --status-level slow -p fabro-sandbox --test plugin_provider - - run: cargo nextest run --locked --profile ci --status-level slow --run-ignored only -p fabro-sandbox --test docker_streaming + echo "rev=$rev" >> "$GITHUB_OUTPUT" + - name: Restore the sandbox-driver plugin executables + id: sandbox-driver-cache + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + with: + path: | + ~/.cargo/bin/sandbox-driver-host + ~/.cargo/bin/sandbox-driver-docker + key: sandbox-driver-plugins-${{ runner.os }}-${{ steps.sandbox-driver.outputs.rev }} + - name: Install the sandbox-driver plugin executables + if: steps.sandbox-driver-cache.outputs.cache-hit != 'true' + run: cargo install --locked --git https://github.com/lithoscomputer/sandbox-driver --rev "${{ steps.sandbox-driver.outputs.rev }}" sandbox-driver-host sandbox-driver-docker + # The workflow scenarios on the Docker provider. The scenarios are e2e + # tests (ignored by default); the key-free ones run here, the + # LLM-backed ones self-skip without credentials. + - run: cargo nextest run --locked --profile ci --status-level slow --run-ignored only -p fabro-cli --test it -E 'test(/::docker_/)' # The Petri runs (not ignored: they skip without the host plugin, which # the environment above forbids). - run: cargo nextest run --locked --profile ci --status-level slow -p fabro-petri - - run: cargo nextest run --locked --profile ci --status-level slow --run-ignored only -p fabro-workflow --test it -E 'test(asset_collection_docker_sandbox)' test-macos: name: Test (macOS) @@ -211,4 +255,28 @@ jobs: with: cache-on-failure: true - uses: taiki-e/install-action@773334c0e05d7e699e4d78234494308223f3a2cf # nextest + # Every Petri run takes its scope through a sandbox-driver plugin + # executable that Petri finds on PATH: `sandbox-driver-host` for the + # `local` provider, `sandbox-driver-docker` for `docker`. Installed + # at the rev the workspace pins, so the plugins and the in-process + # driver are one build; a from-source build, so the two executables + # are cached by OS and rev and only rebuilt when the pin moves. + - name: Read the sandbox-driver rev the workspace pins + id: sandbox-driver + run: | + rev="$(sed -n 's/^sandbox-driver = { git = "[^"]*", rev = "\([0-9a-f]*\)" }$/\1/p' Cargo.toml)" + test -n "$rev" + echo "rev=$rev" >> "$GITHUB_OUTPUT" + - name: Restore the sandbox-driver plugin executables + id: sandbox-driver-cache + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + with: + path: | + ~/.cargo/bin/sandbox-driver-host + ~/.cargo/bin/sandbox-driver-docker + key: sandbox-driver-plugins-${{ runner.os }}-${{ steps.sandbox-driver.outputs.rev }} + - name: Install the sandbox-driver plugin executables + if: steps.sandbox-driver-cache.outputs.cache-hit != 'true' + run: cargo install --locked --git https://github.com/lithoscomputer/sandbox-driver --rev "${{ steps.sandbox-driver.outputs.rev }}" sandbox-driver-host sandbox-driver-docker + # No Docker daemon on the macOS runner: the Docker tests skip there. - run: cargo nextest run --locked --workspace --status-level slow --profile ci diff --git a/lib/apps/fabro-cli/tests/it/workflow/plugin.rs b/lib/apps/fabro-cli/tests/it/workflow/docker.rs similarity index 100% rename from lib/apps/fabro-cli/tests/it/workflow/plugin.rs rename to lib/apps/fabro-cli/tests/it/workflow/docker.rs