Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 0 additions & 3 deletions .cargo/config.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,4 @@
[env]
# libkrun embeds a Linux guest init. Native Linux builds use cc; macOS builds
# cross-compile that init with Zig instead of accidentally using Apple clang.
CC_LINUX = { value = "scripts/libkrun-linux-cc", relative = true }
# Debug DataFusion/Lance projection uses more than the default 2MiB test-thread
# stack, which overflowed canonical event import on Linux CI.
RUST_MIN_STACK = "8388608"
2 changes: 1 addition & 1 deletion .github/actions/setup-build-env/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ inputs:
install-zig:
description: "Install Zig for the macOS-to-Linux guest init cross-build"
required: false
default: "true"
default: "false"

runs:
using: "composite"
Expand Down
218 changes: 30 additions & 188 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -127,48 +127,15 @@ jobs:
packages: >-
persisting-agentctl
persisting-events
persisting-overlay-core
persisting-overlayfs
persisting-overlaynet
persisting-replay
event_control: true
prepare_pvisor: false
prepare_runtime: false
smoke_pvisor: false
smoke_ppilot: false
smoke_pchronicle: false
install_zig: false
- platform: Linux
os: ubuntu-latest
shard: gateway
packages: persisting-gateway
event_control: false
prepare_pvisor: false
prepare_runtime: false
smoke_pvisor: false
smoke_ppilot: false
smoke_pchronicle: false
install_zig: false
- platform: Linux
os: ubuntu-latest
shard: pvisor
packages: persisting-pvisor
event_control: false
prepare_pvisor: true
prepare_runtime: false
smoke_pvisor: true
smoke_ppilot: false
smoke_pchronicle: false
install_zig: false
- platform: Linux
os: ubuntu-latest
shard: ppilot
packages: persisting-ppilot
event_control: false
prepare_pvisor: false
prepare_runtime: true
smoke_pvisor: false
smoke_ppilot: true
smoke_pchronicle: false
install_zig: false
- platform: Linux
Expand All @@ -178,54 +145,26 @@ jobs:
persisting-pchronicle
persisting-pchronicle-cli
event_control: false
prepare_pvisor: false
prepare_runtime: false
smoke_pvisor: false
smoke_ppilot: false
smoke_pchronicle: true
install_zig: false
- platform: macOS
os: macos-latest
shard: agent-runtime
shard: capture
packages: >-
persisting-agentctl
persisting-events
persisting-gateway
persisting-overlay-core
persisting-overlayfs
persisting-overlaynet
persisting-ppilot
persisting-pvisor
persisting-replay
event_control: false
prepare_pvisor: false
prepare_runtime: true
smoke_pvisor: true
smoke_ppilot: true
smoke_pchronicle: false
install_zig: true
- platform: macOS
os: macos-latest
shard: pvisor
packages: persisting-pvisor
event_control: false
prepare_pvisor: true
prepare_runtime: false
smoke_pvisor: true
smoke_ppilot: false
smoke_pchronicle: false
install_zig: true
install_zig: false
- platform: macOS
os: macos-latest
shard: pchronicle
packages: >-
persisting-pchronicle
persisting-pchronicle-cli
event_control: false
prepare_pvisor: false
prepare_runtime: false
smoke_pvisor: false
smoke_ppilot: false
smoke_pchronicle: true
install_zig: false
steps:
Expand All @@ -241,39 +180,13 @@ jobs:
with:
shared-key: ci-rust-${{ matrix.shard }}

# macOS needs the Hypervisor entitlement on the product binary. Running
# the same recipe on Linux also keeps the smoke-test setup identical.
- name: Build pVisor product binary
if: matrix.prepare_pvisor
run: just pvisor debug

# pPilot's integration tests resolve the real pVisor and pChronicle
# executables from PATH. Build them once in this shard before nextest.
- name: Build Agent runtime component set
if: matrix.prepare_runtime
run: |
just build-agent-runtime debug
echo "${GITHUB_WORKSPACE}/target/debug" >> "${GITHUB_PATH}"

- name: Run ${{ matrix.shard }} tests
env:
# GitHub-hosted Linux runners may disable unprivileged user
# namespaces. The dedicated isolation job remains strict.
PERSISTING_TEST_ALLOW_NO_USERNS: "1"
run: just ci-nextest ${{ matrix.packages }}

- name: Test shared event control contract
if: matrix.event_control
run: just test-events-control

- name: Smoke pVisor CLI
if: matrix.smoke_pvisor
run: just smoke-pvisor-cli

- name: Smoke pPilot CLI
if: matrix.smoke_ppilot
run: just smoke-ppilot-cli

- name: Smoke pChronicle CLI
if: matrix.smoke_pchronicle
run: just smoke-pchronicle-cli
Expand Down Expand Up @@ -321,47 +234,6 @@ jobs:
- name: Build and test Web crate
run: just test-pchronicle-web

pvisor-isolation-regression:
name: pVisor Isolation Regression / Linux
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4

- name: Setup Build Environment
uses: ./.github/actions/setup-build-env
with:
install-zig: "false"
components: ""

- uses: Swatinem/rust-cache@v2
with:
shared-key: ci-pvisor-isolation

- name: Enable rootless isolation primitives
shell: bash
run: |
sudo apt-get update -qq
sudo apt-get install -y -qq --no-install-recommends fuse3 jq util-linux
if sysctl kernel.unprivileged_userns_clone >/dev/null 2>&1; then
sudo sysctl -w kernel.unprivileged_userns_clone=1
fi
if sysctl kernel.apparmor_restrict_unprivileged_userns >/dev/null 2>&1; then
sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
fi
test -c /dev/fuse
unshare --user --map-root-user --mount --net /bin/true

- name: Run strict pVisor isolation regressions
env:
PERSISTING_RUN_HOME: ${{ runner.temp }}/pvisor-isolation-runs
run: just test-pvisor-isolation

- name: Run pVisor filesystem examples
env:
WORK_ROOT: ${{ runner.temp }}/pvisor-filesystem-examples
run: just examples-pvisor-filesystem

s3-contract:
name: pChronicle S3 Contract / MinIO
runs-on: ubuntu-latest
Expand All @@ -379,28 +251,41 @@ jobs:
with:
shared-key: ci-pchronicle-s3

- uses: actions/setup-go@v5
with:
go-version: "1.24.2"
cache: false

# Upstream no longer distributes the public container images or binaries.
- name: Build pinned MinIO tools from source
env:
GOBIN: ${{ runner.temp }}/minio-bin
run: |
go install github.com/minio/minio@RELEASE.2025-07-23T15-54-02Z
go install github.com/minio/mc@RELEASE.2025-08-13T08-35-41Z
echo "$GOBIN" >> "$GITHUB_PATH"

- name: Start pinned MinIO server
env:
MINIO_ROOT_USER: minioadmin
MINIO_ROOT_PASSWORD: minioadmin123
run: |
docker run --detach --name persisting-minio-contract \
--publish 9000:9000 \
--env MINIO_ROOT_USER=minioadmin \
--env MINIO_ROOT_PASSWORD=minioadmin123 \
quay.io/minio/minio:RELEASE.2025-07-23T15-54-02Z \
server /data
nohup minio server "$RUNNER_TEMP/minio-data" --address 127.0.0.1:9000 \
> "$RUNNER_TEMP/minio.log" 2>&1 &
echo $! > "$RUNNER_TEMP/minio.pid"
for attempt in $(seq 1 30); do
if curl --fail --silent http://127.0.0.1:9000/minio/health/live >/dev/null; then
exit 0
fi
sleep 1
done
docker logs persisting-minio-contract
cat "$RUNNER_TEMP/minio.log"
exit 1

- name: Create isolated test bucket
run: |
docker run --rm --network host --entrypoint /bin/sh \
quay.io/minio/mc:RELEASE.2025-08-13T08-35-41Z -c \
'mc alias set local http://127.0.0.1:9000 minioadmin minioadmin123 && mc mb --ignore-existing local/persisting-tests'
mc alias set local http://127.0.0.1:9000 minioadmin minioadmin123
mc mb --ignore-existing local/persisting-tests

- name: Run real S3 storage contract
env:
Expand All @@ -416,11 +301,14 @@ jobs:

- name: Show MinIO logs after failure
if: failure()
run: docker logs persisting-minio-contract
run: cat "$RUNNER_TEMP/minio.log"

- name: Stop MinIO
if: always()
run: docker rm --force persisting-minio-contract || true
run: |
if [ -f "$RUNNER_TEMP/minio.pid" ]; then
kill "$(cat "$RUNNER_TEMP/minio.pid")" || true
fi

python-test:
name: Python Test
Expand All @@ -441,57 +329,13 @@ jobs:
- name: Pytest
run: just test-py

pvisor-cases:
name: pVisor case checklist
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Setup Build Environment
uses: ./.github/actions/setup-build-env
with:
install-nextest: "false"
install-zig: "false"
components: ""

- uses: Swatinem/rust-cache@v2
with:
shared-key: ci-pvisor-cases

- name: Run documented cases
run: |
just cases pvisor \
--case A01,A02,A03,A04,A05,A06 \
--case B01,B02,B03,B04 \
--case C02,C03,C04 \
--case D01,D03 \
--case F01,F02,F03 \
--case G01,G02,G03,G06 \
--case H01,H02 \
--case I01,I02,I03 \
--case J03

- name: Upload case report
if: always()
uses: actions/upload-artifact@v4
with:
name: pvisor-case-report
path: target/pvisor-case-report.md
if-no-files-found: ignore

examples:
name: Examples / ${{ matrix.shard }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- shard: pvisor
command: |
just test-pvisor-benchmark
just examples-pvisor-portable
- shard: ppilot
command: just examples-ppilot
- shard: pchronicle
command: just examples-pchronicle
steps:
Expand Down Expand Up @@ -535,10 +379,8 @@ jobs:
- rust-test
- rust-proptest
- pchronicle-web-test
- pvisor-isolation-regression
- s3-contract
- python-test
- pvisor-cases
- examples
runs-on: ubuntu-latest
steps:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -129,7 +129,7 @@ jobs:
curl -fsSL https://raw.githubusercontent.com/${{ github.repository }}/main/scripts/install-nightly.sh | bash
```

The wheel includes the matched `pchronicle`, `pvisor`, and `ppilot` CLI component set. Built with local version `+${{ needs.meta.outputs.local_version }}` (base version from `pyproject.toml`).
The wheel includes the `pchronicle` CLI. Built with local version `+${{ needs.meta.outputs.local_version }}` (base version from `pyproject.toml`).

publish-benchmark-readme:
name: Publish benchmark summary to README
Expand Down
Loading
Loading