Skip to content

Probe inside the engine sandbox too #2

Probe inside the engine sandbox too

Probe inside the engine sandbox too #2

Workflow file for this run

# Temporary diagnostic for #119. Reproduces the worktree the loop creates and
# reports what git and Go actually see inside it, because the failure does not
# reproduce on a developer machine.
#
# DELETE THIS FILE once #119 is understood. It exists to answer one question.
name: probe-worktree
on:
workflow_dispatch:
push:
branches: [probe-worktree-git]
permissions:
contents: read
jobs:
probe:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
with:
go-version-file: go.mod
- name: Create the worktree the loop would create
run: |
set -x
# Same layout as the product: os.TempDir()/simplycubed/worktrees/<branch>
BASE=/tmp/simplycubed/worktrees
mkdir -p "${BASE}"
git worktree add -B probe/119 "${BASE}/probe-119" HEAD
echo "WT=${BASE}/probe-119" >> "$GITHUB_ENV"
- name: What does git see inside it
run: |
cd "${WT}"
echo "--- .git ---"; ls -la .git; cat .git
echo "--- toplevel ---"; git rev-parse --show-toplevel || echo "EXIT=$?"
echo "--- common dir ---"; git rev-parse --git-common-dir || echo "EXIT=$?"
echo "--- status ---"; git status --porcelain || echo "EXIT=$?"
echo "--- status pathspec ---"; git status --porcelain -- .github/workflows || echo "EXIT=$?"
echo "--- ownership ---"; stat -c '%U %G %n' . .git
echo "--- safe.directory ---"; git config --get-all safe.directory || echo "none"
echo "--- whoami ---"; id
- name: What does Go see inside it
run: |
cd "${WT}"
echo "--- build with VCS stamping (the gate's default) ---"
go build ./... && echo "BUILD OK" || echo "BUILD FAILED exit=$?"
echo "--- build without stamping ---"
GOFLAGS=-buildvcs=false go build ./... && echo "BUILD OK (no vcs)" || echo "FAILED exit=$?"
- name: The gate itself
run: |
cd "${WT}"
make check && echo "GATE PASS" || echo "GATE FAIL exit=$?"
- name: Same commands, but inside the engine sandbox
env:
AZURE_OPENAI_ENDPOINT: ${{ vars.AZURE_OPENAI_ENDPOINT }}
AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }}
run: |
# The loop runs the engine inside Codex's bubblewrap sandbox, rooted at
# the worktree. The worktree's gitdir lives under the main checkout,
# outside that root. If the sandbox cannot see it, git fails there and
# nowhere else, which is exactly the asymmetry #119 is chasing.
sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
npm install -g @openai/codex@0.146.0 >/dev/null 2>&1
cd "${WT}"
codex exec --skip-git-repo-check -s workspace-write -C . \
'Run these and report the exact output of each, changing nothing: (1) git rev-parse --show-toplevel (2) git status --porcelain (3) ls -la /home/runner/work/code/code/.git/worktrees/ (4) go build ./...' \
2>&1 | tail -40