ci: provision Pi runtime 0.84.1 in the test step (Invariant R)
ci/woodpecker/pr/ci Pipeline was successful
ci/woodpecker/pr/ci Pipeline was successful
invariant_r_unittest.py (landing with the lease-remediation stack, PR #1109) hard-requires an installed `pi` binary pinned to the measured version: it boots Pi's real tool registry and proves the broker's read-only carve-out resolves to real, unshadowed builtins. Absent runtime fails loud by design — so CI must provide it. Install @earendil-works/[email protected].1 (the canonical Pi; @mariozechner/* is embedded-legacy) at step level in the test step. Step-level rather than baked into Dockerfile.ci because ci-image publishes are currently blocked on registry UNAUTHORIZED; baking it in is the follow-up once registry auth is fixed, at which point this line degrades to a fast no-op guard like the openssl line above it. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Dtdjx4Gxude9fwyLezCrhh
This commit is contained in:
co-authored by
Claude Fable 5
parent
9185b0cce4
commit
b79708fdc7
@@ -109,6 +109,16 @@ steps:
|
||||
# `apk add` guarantees openssl is present on PR pipelines too (and is a
|
||||
# fast no-op once the rebuilt image already ships it).
|
||||
- apk add --no-cache openssl
|
||||
# Pi runtime (Invariant R): invariant_r_unittest.py hard-requires an
|
||||
# installed `pi` binary at exactly this measured version — the test
|
||||
# boots Pi's real tool registry to prove the read-only carve-out
|
||||
# resolves to real, unshadowed builtins, and fails loud (by design)
|
||||
# when the runtime is absent or drifts. The canonical Pi is
|
||||
# @earendil-works/[email protected] exactly (@mariozechner/* is
|
||||
# embedded-legacy). Step-level install because ci-base image publishes
|
||||
# are currently blocked on registry auth; fold into Dockerfile.ci once
|
||||
# that is fixed, keeping this as a fast no-op guard.
|
||||
- npm install -g @earendil-works/[email protected]
|
||||
# postgresql-client (pg_isready) is baked into ci-base.
|
||||
# Wait up to 60s for CI postgres to be ready; fail fast if it never comes up.
|
||||
- |
|
||||
|
||||
Reference in New Issue
Block a user