[ci] Audit typed matrix execution path - #3594
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## G347jsgltowjlm4i3umxjtudzc57bjmde #3594 +/- ##
==================================================================
Coverage 91.85% 91.85%
==================================================================
Files 20 20
Lines 6093 6093
==================================================================
Hits 5597 5597
Misses 496 496 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
348b0f9 to
d0ff708
Compare
3143da8 to
89b8771
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
89b8771 to
f9ea695
Compare
231d8b3 to
d0426b3
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
d0426b3 to
c54bc3c
Compare
3cedc1d to
0380172
Compare
c54bc3c to
ffb5cd0
Compare
0380172 to
d220621
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
d220621 to
fcda88a
Compare
ffb5cd0 to
eb2cc83
Compare
fcda88a to
8eb1efb
Compare
eb2cc83 to
3c014ce
Compare
8eb1efb to
d7a4fd1
Compare
3c014ce to
38e0cf2
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
d7a4fd1 to
d0ba440
Compare
7ed08a4 to
bda6d18
Compare
d0ba440 to
a46aedf
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Require reviewed planned roles to equal `build_test` and `miri`. Audit their exact top-level shapes, display names, hosted runners, read-only permissions, `plan_ci` and `build_docker_env` dependencies, and build run defaults. Reject unreviewed job controls and strategy fields. Require exact matrix gates and fan-out expressions. Include every Miri selector, including toolchain, in its display name. Bind one named executor step to each job's `steps` mapping, with the exact selector environment and checked CLI arguments for its role. Audit the image producer's exact fields, permissions, output, and five steps. Derive its artifact output and each consumer input from shared job, output, and upload-step identifiers so a protocol rename cannot silently update only one side. Build the image from an isolated context containing only an audited Dockerfile and an audited ignore file which excludes every context path. Reject any extra context entry. Install the three common Rust toolchains directly instead of executing checkout code, and require their Docker argument defaults to match the validated inventory. This also avoids compiling cargo-zerocopy only to seed the image and prevents ordinary tools-tree changes from invalidating that layer. Expected latency improves through more reliable Docker cache hits and less work when the final image layer does need to rebuild. Audit every mutable local action and image source against an independent compiled snapshot. Open each source once for both its identity and its contents. Reject symbolic links, paths outside the checkout, non-files, and hard-link aliases across the complete reviewed source set. Reintroduce shared YAML anchors only after the complete matrix bridge is audited. Use one central list for the parser allowlist and matrix ownership checks. Require one exact build definition and one exact Miri alias of each of the four setup steps, in the reviewed sequences. Reject all other anchors and aliases, redefinition, reuse, and explicit tags. Preserve comment-looking data beneath every YAML block scalar when comparing exact steps, rather than only beneath run blocks. Run a trusted Git integrity gate after setup. Build a disposable index from the expected commit under an empty Git configuration. Mutable index flags, local attributes, and clean filters cannot hide changes. Reject any changed tracked, untracked, or ignored checkout path before invoking the typed executor. Audit privileged custom shells and explicit absolute Docker bridges. Require the fixed Bash entrypoint, no-startup privileged arguments, and Docker option terminator, with every run line treated as load-bearing. Tests: CARGO_NET_OFFLINE=true ./tools/cargo.sh test --locked -p zc Tests: warning-denied Clippy for all zc targets Tests: CARGO_NET_OFFLINE=true ./zerocopy/cargo.sh ci audit Tests: ./ci/check_actions.sh Tests: ./ci/check_fmt.sh Tests: git diff --check *Authored by an agent, posting via joshlf's account* gherrit-pr-id: Gcl7ijadfh2m7eft4ucy5czoaghddreiq
a46aedf to
e5f21e0
Compare
bda6d18 to
e1eeb8b
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Require reviewed planned roles to equal
build_testandmiri. Audittheir exact top-level shapes, display names, hosted runners, read-only
permissions,
plan_ciandbuild_docker_envdependencies, and buildrun defaults. Reject unreviewed job controls and strategy fields.
Require exact matrix gates and fan-out expressions. Include every Miri
selector, including toolchain, in its display name. Bind one named
executor step to each job's
stepsmapping, with the exact selectorenvironment and checked CLI arguments for its role.
Audit the image producer's exact fields, permissions, output, and five
steps. Derive its artifact output and each consumer input from shared
job, output, and upload-step identifiers so a protocol rename cannot
silently update only one side.
Build the image from an isolated context containing only an audited
Dockerfile and an audited ignore file which excludes every context path.
Reject any extra context entry. Install the three common Rust toolchains
directly instead of executing checkout code, and require their Docker
argument defaults to match the validated inventory.
This also avoids compiling cargo-zerocopy only to seed the image and
prevents ordinary tools-tree changes from invalidating that layer.
Expected latency improves through more reliable Docker cache hits and
less work when the final image layer does need to rebuild.
Audit every mutable local action and image source against an independent
compiled snapshot. Open each source once for both its identity and its
contents. Reject symbolic links, paths outside the checkout, non-files,
and hard-link aliases across the complete reviewed source set.
Reintroduce shared YAML anchors only after the complete matrix bridge is
audited. Use one central list for the parser allowlist and matrix
ownership checks. Require one exact build definition and one exact Miri
alias of each of the four setup steps, in the reviewed sequences. Reject
all other anchors and aliases, redefinition, reuse, and explicit tags.
Preserve comment-looking data beneath every YAML block scalar when
comparing exact steps, rather than only beneath run blocks.
Run a trusted Git integrity gate after setup. Build a disposable index
from the expected commit under an empty Git configuration. Mutable index
flags, local attributes, and clean filters cannot hide changes. Reject
any changed tracked, untracked, or ignored checkout path before invoking
the typed executor.
Audit privileged custom shells and explicit absolute Docker bridges.
Require the fixed Bash entrypoint, no-startup privileged arguments, and
Docker option terminator, with every run line treated as load-bearing.
Tests: CARGO_NET_OFFLINE=true ./tools/cargo.sh test --locked -p zc
Tests: warning-denied Clippy for all zc targets
Tests: CARGO_NET_OFFLINE=true ./zerocopy/cargo.sh ci audit
Tests: ./ci/check_actions.sh
Tests: ./ci/check_fmt.sh
Tests: git diff --check
Authored by an agent, posting via joshlf's account
Latest Update: v29 — Compare vs v28
📚 Full Patch History
Links show the diff between the row version and the column version.
⬇️ Download this PR
Branch
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git checkout -b pr-Gcl7ijadfh2m7eft4ucy5czoaghddreiq FETCH_HEADCheckout
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git checkout FETCH_HEADCherry Pick
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git cherry-pick FETCH_HEADPull
Stacked PRs enabled by GHerrit.