Commit 3ce0a2b
ci: run the integration tests against a real gVisor daemon (#21)
* ci: run the integration tests against a real gVisor daemon
Closes #3.
CI compiled the integration suite and never ran it, so a green run graded
pkg/docker at 17.7% unit coverage while the engine's actual verification —
containment, blocked egress, the reaper, the resource caps under attack —
ran only when someone remembered to do it locally.
The blocker was assumed to be gVisor needing hardware a hosted runner does
not have. It does not: the systrap platform uses seccomp and needs neither
KVM nor nested virtualisation, so ubuntu-latest can register runsc. That
also keeps the suite off a self-hosted runner, which on a public repo would
mean executing a stranger's pull request on our own hardware.
Registration is asserted in its own step, and asserted by booting a guest
rather than by reading the runtime list: openblox refuses to fall back to
runc, so an absent or broken runtime would otherwise surface as fifty
identical ErrRuntimeUnavailable failures instead of one legible message.
Per the issue, it fails loudly rather than skipping — a silent skip would
rebuild exactly the false confidence being removed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* ci: register runsc explicitly instead of trusting the postinst
The gVisor package's postinst registers the runtime on some hosts and did
not on the ubuntu-latest runner image, so docker info never listed runsc
and the verify step failed. Run runsc install directly — it is idempotent
and merges into daemon.json — and restart rather than reload, since a CI
runner has no containers worth preserving.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent a032502 commit 3ce0a2b
2 files changed
Lines changed: 72 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | 84 | | |
88 | 85 | | |
89 | 86 | | |
| |||
124 | 121 | | |
125 | 122 | | |
126 | 123 | | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| |||
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
121 | | - | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
122 | 124 | | |
123 | | - | |
124 | | - | |
125 | | - | |
126 | | - | |
127 | | - | |
| 125 | + | |
| 126 | + | |
128 | 127 | | |
129 | 128 | | |
130 | 129 | | |
| |||
0 commit comments