Repository navigation
Probe inside the engine sandbox too #2
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Temporary diagnostic for #119. Reproduces the worktree the loop creates and | |
| # reports what git and Go actually see inside it, because the failure does not | |
| # reproduce on a developer machine. | |
| # | |
| # DELETE THIS FILE once #119 is understood. It exists to answer one question. | |
| name: probe-worktree | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [probe-worktree-git] | |
| permissions: | |
| contents: read | |
| jobs: | |
| probe: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0 | |
| with: | |
| go-version-file: go.mod | |
| - name: Create the worktree the loop would create | |
| run: | | |
| set -x | |
| # Same layout as the product: os.TempDir()/simplycubed/worktrees/<branch> | |
| BASE=/tmp/simplycubed/worktrees | |
| mkdir -p "${BASE}" | |
| git worktree add -B probe/119 "${BASE}/probe-119" HEAD | |
| echo "WT=${BASE}/probe-119" >> "$GITHUB_ENV" | |
| - name: What does git see inside it | |
| run: | | |
| cd "${WT}" | |
| echo "--- .git ---"; ls -la .git; cat .git | |
| echo "--- toplevel ---"; git rev-parse --show-toplevel || echo "EXIT=$?" | |
| echo "--- common dir ---"; git rev-parse --git-common-dir || echo "EXIT=$?" | |
| echo "--- status ---"; git status --porcelain || echo "EXIT=$?" | |
| echo "--- status pathspec ---"; git status --porcelain -- .github/workflows || echo "EXIT=$?" | |
| echo "--- ownership ---"; stat -c '%U %G %n' . .git | |
| echo "--- safe.directory ---"; git config --get-all safe.directory || echo "none" | |
| echo "--- whoami ---"; id | |
| - name: What does Go see inside it | |
| run: | | |
| cd "${WT}" | |
| echo "--- build with VCS stamping (the gate's default) ---" | |
| go build ./... && echo "BUILD OK" || echo "BUILD FAILED exit=$?" | |
| echo "--- build without stamping ---" | |
| GOFLAGS=-buildvcs=false go build ./... && echo "BUILD OK (no vcs)" || echo "FAILED exit=$?" | |
| - name: The gate itself | |
| run: | | |
| cd "${WT}" | |
| make check && echo "GATE PASS" || echo "GATE FAIL exit=$?" | |
| - name: Same commands, but inside the engine sandbox | |
| env: | |
| AZURE_OPENAI_ENDPOINT: ${{ vars.AZURE_OPENAI_ENDPOINT }} | |
| AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }} | |
| run: | | |
| # The loop runs the engine inside Codex's bubblewrap sandbox, rooted at | |
| # the worktree. The worktree's gitdir lives under the main checkout, | |
| # outside that root. If the sandbox cannot see it, git fails there and | |
| # nowhere else, which is exactly the asymmetry #119 is chasing. | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 | |
| npm install -g @openai/codex@0.146.0 >/dev/null 2>&1 | |
| cd "${WT}" | |
| codex exec --skip-git-repo-check -s workspace-write -C . \ | |
| 'Run these and report the exact output of each, changing nothing: (1) git rev-parse --show-toplevel (2) git status --porcelain (3) ls -la /home/runner/work/code/code/.git/worktrees/ (4) go build ./...' \ | |
| 2>&1 | tail -40 |