ci(install-e2e): retire the bubblewrap sandbox - git redirect everywhere, macos legs live
The fake Internet (bubblewrap + slirp4netns + MITM proxy +
upload-pack shim, 883 lines across dev-sandbox.sh, stage2-run.sh,
proxy.py, ssh-shim.sh, openssl.cnf, install-update-e2e.sh) existed to
isolate install.sh's network. The GIT_CONFIG_GLOBAL insteadOf redirect
the windows driver introduced does the same job with a gitconfig file
and works on any OS, so:
* install-e2e-run.yml now runs tests/install/installer-script-e2e.sh
directly on the bare runner - no sandbox deps, no userns sysctls -
and takes a runner input;
* the macos matrix calls the SAME workflow on macos-latest, deleting
install-e2e-macos-run.yml: installer-script -> installer-script /
hermes-update flip from grey to live, app-update pairs stay TODO
inside the shared gate;
* install.sh is no longer curl'd through a fake CA - each leg runs
the copy from the ref a user of that version actually executed;
* scripts/dev-sandbox.sh becomes the minimal isolation sandbox from
ab6b9492f (separate HERMES_HOME / Electron userData / app name,
same CLI surface: --persistent, --from, --delete), keeping its
.hermes-sandbox dir name so gitignore and docs hold;
* nix/sandbox.nix drops the bwrap/proxy closure and keeps only the
Electron runtime LD_LIBRARY_PATH the desktop app needs.
Verified: nix build .#sandbox + smoke run (isolated HERMES_HOME
created, ephemeral cleanup), shellcheck/bash -n on both scripts,
actionlint on all three workflows, and the new driver ran the full
v0.20.2 -> HEAD hermes-update pass locally before this commit.
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
{
|
||||
# electron deps
|
||||
# Electron needs its native runtime libraries on LD_LIBRARY_PATH when the
|
||||
# sandboxed command launches the desktop app (`sandbox hermes desktop`,
|
||||
# `sandbox npm run dev`); nothing else in the sandbox is nix-specific.
|
||||
alsa-lib,
|
||||
at-spi2-atk,
|
||||
atk,
|
||||
@@ -29,28 +31,6 @@
|
||||
libXtst,
|
||||
libxcb,
|
||||
|
||||
# sandbox deps
|
||||
bash,
|
||||
bubblewrap,
|
||||
cacert,
|
||||
coreutils,
|
||||
curl,
|
||||
gawk,
|
||||
git,
|
||||
glibc,
|
||||
gnumake,
|
||||
gnugrep,
|
||||
gnused,
|
||||
gzip,
|
||||
nodejs_22,
|
||||
openssl,
|
||||
python3,
|
||||
slirp4netns,
|
||||
stdenv,
|
||||
gnutar,
|
||||
util-linux,
|
||||
|
||||
# etc
|
||||
writeShellApplication,
|
||||
lib,
|
||||
}:
|
||||
@@ -88,37 +68,8 @@ let
|
||||
in
|
||||
writeShellApplication {
|
||||
name = "sandbox";
|
||||
runtimeInputs = [
|
||||
bash
|
||||
bubblewrap
|
||||
cacert
|
||||
coreutils
|
||||
curl
|
||||
gawk
|
||||
git
|
||||
glibc.bin
|
||||
gnumake
|
||||
gnugrep
|
||||
gnused
|
||||
gzip
|
||||
nodejs_22
|
||||
openssl
|
||||
python3
|
||||
slirp4netns
|
||||
stdenv.cc
|
||||
gnutar
|
||||
util-linux
|
||||
]
|
||||
++ electronRuntime;
|
||||
text = ''
|
||||
export DEV_SANDBOX_REAL_CA_CERT=${cacert}/etc/ssl/certs/ca-bundle.crt
|
||||
export DEV_SANDBOX_DYNAMIC_LINKER=${stdenv.cc.bintools.dynamicLinker}
|
||||
export DEV_SANDBOX_NODE_DIR=${nodejs_22}
|
||||
export DEV_SANDBOX_ELECTRON_LD_LIBRARY_PATH=${lib.makeLibraryPath electronRuntime}
|
||||
# The script is imported into the store as a single file, so its own
|
||||
# directory has no scripts/sandbox/ beside it. Point it at the assets
|
||||
# (fake-internet proxy, ssh shim) explicitly.
|
||||
export DEV_SANDBOX_ASSETS=${../scripts/sandbox}
|
||||
export LD_LIBRARY_PATH=${lib.makeLibraryPath electronRuntime}''${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}
|
||||
exec ${../scripts/dev-sandbox.sh} "$@"
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user