mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-06 15:02:20 +02:00
Merge commit 'refs/phase3/pre-ajax/publication-tip' into integration/pre-ajax-release
# Conflicts: # routes/chat_routes.py # routes/session_routes.py # src/agent_loop.py # src/agent_tools/filesystem_tools.py # src/teacher_escalation.py # src/tool_capabilities.py # src/tool_execution.py # tests/test_mcp_add_server_args_validation.py # tests/test_token_cache_atomic_swap.py
This commit is contained in:
@@ -101,9 +101,19 @@ jobs:
|
||||
done
|
||||
|
||||
python-tests:
|
||||
name: Python tests (pytest)
|
||||
runs-on: ubuntu-latest
|
||||
name: Python tests (pytest ${{ matrix.shard }})
|
||||
# Keep the namespace/AppArmor setup tied to the audited Ubuntu release.
|
||||
runs-on: ubuntu-24.04
|
||||
# Make Python test validation authoritative for the configured scope.
|
||||
strategy:
|
||||
# Report every failing section in one run instead of cancelling the rest
|
||||
# the moment one shard goes red.
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# Shards partition the suite by test file, so the four together run
|
||||
# every test exactly once. tests/_shards.py owns the partition and
|
||||
# tests/test_shards.py pins this list to its DEFAULT_SHARD_COUNT.
|
||||
shard: ["1/4", "2/4", "3/4", "4/4"]
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
@@ -140,7 +150,77 @@ jobs:
|
||||
cache: pip
|
||||
- run: pip install -r requirements.txt
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
with:
|
||||
node-version: "20"
|
||||
cache: npm
|
||||
- run: npm ci
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: npx playwright install --with-deps chromium
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: mkdir -p data # sqlite DB lives at ./data/app.db
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: python -m pytest -q
|
||||
- name: Install FFmpeg for media integration tests
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends ffmpeg
|
||||
command -v ffmpeg
|
||||
ffmpeg -version | head -n 1
|
||||
|
||||
- name: Establish functional bubblewrap containment
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends bubblewrap
|
||||
bwrap --version
|
||||
sysctl kernel.unprivileged_userns_clone user.max_user_namespaces \
|
||||
kernel.apparmor_restrict_unprivileged_userns
|
||||
if [ "$(sysctl -n kernel.unprivileged_userns_clone)" != 1 ] || \
|
||||
[ "$(sysctl -n user.max_user_namespaces)" -eq 0 ]; then
|
||||
echo '::error::The pytest runner must allow unprivileged user namespaces; kernel namespace support is disabled.'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Match containment._bwrap_available(): PID and mount namespaces,
|
||||
# including fresh proc/dev mounts, as the unprivileged runner user.
|
||||
bwrap_probe() {
|
||||
timeout 3s bwrap --die-with-parent --unshare-pid --ro-bind / / \
|
||||
--proc /proc --dev /dev /bin/true
|
||||
}
|
||||
|
||||
if ! bwrap_probe && [ "$(sysctl -n kernel.apparmor_restrict_unprivileged_userns)" = 1 ]; then
|
||||
# Ubuntu 24.04 restricts userns for unconfined applications. Allow
|
||||
# only the distro bwrap entry point on this ephemeral pytest VM;
|
||||
# retain the global restriction and all unrelated AppArmor policy.
|
||||
sudo tee /etc/apparmor.d/odysseus-ci-bwrap > /dev/null <<'PROFILE'
|
||||
abi <abi/4.0>,
|
||||
include <tunables/global>
|
||||
profile odysseus-ci-bwrap /usr/bin/bwrap flags=(unconfined) {
|
||||
userns,
|
||||
}
|
||||
PROFILE
|
||||
sudo apparmor_parser -r /etc/apparmor.d/odysseus-ci-bwrap
|
||||
fi
|
||||
|
||||
if ! bwrap_probe; then
|
||||
echo '::error::Functional bubblewrap PID/mount namespaces are required for pytest; containment setup failed.'
|
||||
exit 1
|
||||
fi
|
||||
# Also gate on the runtime probe so a future requirements change
|
||||
# cannot silently leave this job without real containment coverage.
|
||||
python - <<'PY'
|
||||
from src import containment
|
||||
if not containment._bwrap_available():
|
||||
raise SystemExit("::error::Runtime bubblewrap functionality probe failed; pytest must not start.")
|
||||
print("Runtime bubblewrap PID/mount namespace probe passed.")
|
||||
PY
|
||||
|
||||
- name: pytest (shard ${{ matrix.shard }})
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
env:
|
||||
PYTEST_SHARD: ${{ matrix.shard }}
|
||||
run: python -m pytest -q -rs --shard "$PYTEST_SHARD"
|
||||
|
||||
@@ -62,6 +62,8 @@ jobs:
|
||||
|
||||
- name: Set up Buildx
|
||||
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
|
||||
with:
|
||||
driver: docker
|
||||
|
||||
# Build without pushing so a broken Dockerfile is caught here, and the
|
||||
# exact image we ship is what gets scanned.
|
||||
@@ -73,6 +75,9 @@ jobs:
|
||||
load: true
|
||||
tags: odysseus:ci
|
||||
|
||||
- name: Free build cache before vulnerability database download
|
||||
run: docker builder prune --all --force
|
||||
|
||||
- name: Scan image with Trivy
|
||||
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
|
||||
with:
|
||||
@@ -103,6 +108,8 @@ jobs:
|
||||
|
||||
- name: Set up Buildx
|
||||
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
|
||||
with:
|
||||
driver: docker
|
||||
|
||||
- name: Build image
|
||||
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
|
||||
@@ -112,6 +119,9 @@ jobs:
|
||||
load: true
|
||||
tags: odysseus:ci
|
||||
|
||||
- name: Free build cache before vulnerability database download
|
||||
run: docker builder prune --all --force
|
||||
|
||||
- name: Scan image with Trivy
|
||||
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
|
||||
with:
|
||||
|
||||
@@ -30,7 +30,10 @@ jobs:
|
||||
dependency-review:
|
||||
name: dependency-review (PR gate)
|
||||
# Only meaningful on a pull request -- it needs a base..head diff to review.
|
||||
if: github.event_name == 'pull_request'
|
||||
# dependency-review-action requires GitHub dependency-review support.
|
||||
# Keep the blocking gate on the canonical repository; forks and maintainer
|
||||
# preview mirrors still run the advisory pip-audit job below.
|
||||
if: github.event_name == 'pull_request' && github.repository == 'odysseus-dev/odysseus'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
Reference in New Issue
Block a user