| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132 |
- # Manually-dispatched CI for the landlock-run source of record
- # (native/landlock-run). A separate workflow from ci.yml on purpose: the
- # subtree is a self-contained pnpm workspace with its own gates, exercised on
- # demand — per-architecture native legs (build + behavioral tests + pack
- # rehearsal on real kernels) plus one darwin leg proving the documented
- # degradation on hosts without a platform package. Legs derive from the
- # subtree's checked-in package matrix (scripts/github-matrix.mjs). Packing
- # for npm happens in the release mirror (node-addon-landlock-run) after an
- # export — see native/README.md; this workflow never packs for release.
- name: Landlock Run
- on:
- workflow_dispatch:
- concurrency:
- group: ${{ github.workflow }}-${{ github.ref }}
- cancel-in-progress: true
- permissions:
- contents: read
- env:
- # CI runs must never report to the production telemetry endpoint baked
- # into apps/cli/cordis.yml (AppCLIEntry disables the row when set).
- DSH_TELEMETRY_DISABLED: '1'
- defaults:
- run:
- working-directory: native/landlock-run
- jobs:
- matrix:
- name: Matrix
- runs-on: ubuntu-24.04
- outputs:
- ci: ${{ steps.matrix.outputs.ci }}
- steps:
- - uses: actions/checkout@v4
- - id: matrix
- run: echo "ci=$(node ./scripts/github-matrix.mjs ci)" >> "$GITHUB_OUTPUT"
- native:
- name: ${{ matrix.platform }}
- needs: matrix
- runs-on: ${{ matrix.runner }}
- strategy:
- fail-fast: false
- matrix: ${{ fromJson(needs.matrix.outputs.ci) }}
- steps:
- - uses: actions/checkout@v4
- - uses: pnpm/action-setup@v4
- with:
- package_json_file: native/landlock-run/package.json
- - uses: actions/setup-node@v4
- with:
- node-version: 24
- cache: pnpm
- cache-dependency-path: native/landlock-run/pnpm-lock.yaml
- - name: Install dependencies
- run: pnpm install --frozen-lockfile
- - name: Install musl toolchain
- run: |
- sudo apt-get update -q
- sudo apt-get install -yq musl-tools
- - name: Build TypeScript
- run: pnpm build:ts
- - name: Typecheck
- run: pnpm typecheck
- - name: Build native binaries (this architecture is the builder of record)
- run: pnpm build:native
- - name: Entry tests (keyless)
- run: node ./test/entry.test.js
- # NALR_REQUIRE_LANDLOCK: a self-skip on the very platform that exists to
- # prove enforcement would be a false green, so an unenforcing kernel
- # fails the leg instead of skipping.
- - name: Launcher tests (real kernel enforcement)
- run: node ./test/launcher.test.js
- env:
- NALR_REQUIRE_LANDLOCK: 1
- - name: Pack rehearsal (pack → install → confine, this platform only)
- run: |
- node ./scripts/pack-release.mjs .release/npm --current-platform-only
- node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
- env:
- NALR_REQUIRE_LANDLOCK: 1
- darwin:
- name: darwin (no platform package — degradation proof)
- runs-on: macos-latest
- steps:
- - uses: actions/checkout@v4
- - uses: pnpm/action-setup@v4
- with:
- package_json_file: native/landlock-run/package.json
- - uses: actions/setup-node@v4
- with:
- node-version: 24
- cache: pnpm
- cache-dependency-path: native/landlock-run/pnpm-lock.yaml
- - name: Install dependencies
- run: pnpm install --frozen-lockfile
- - name: Build TypeScript
- run: pnpm build:ts
- - name: Typecheck
- run: pnpm typecheck
- - name: Entry tests (keyless)
- run: node ./test/entry.test.js
- - name: Launcher tests (must self-skip cleanly)
- run: node ./test/launcher.test.js
- - name: Pack rehearsal (entry only — fallback resolution + unusable probe)
- run: |
- node ./scripts/pack-release.mjs .release/npm --current-platform-only
- node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
|