[ci] Audit typed matrix execution - #3594
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## G347jsgltowjlm4i3umxjtudzc57bjmde #3594 +/- ##
==================================================================
Coverage 91.85% 91.85%
==================================================================
Files 20 20
Lines 6093 6093
==================================================================
Hits 5597 5597
Misses 496 496 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
348b0f9 to
d0ff708
Compare
3143da8 to
89b8771
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
89b8771 to
f9ea695
Compare
f9ea695 to
438d2d3
Compare
665458f to
0949141
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
0949141 to
e96e0b4
Compare
438d2d3 to
135f323
Compare
Require reviewed planned roles to equal build_test and miri. Audit their exact top-level shapes, display names, hosted runners, read-only permissions, plan_ci and build_docker_env dependencies, and build run defaults. Reject unreviewed job controls and strategy fields. Require exact matrix gates and fan-out expressions. Include every Miri selector, including toolchain, in its display name. Bind one named executor step to each job steps mapping, with the exact selector environment and checked CLI argv for its role. Audit privileged custom shells and explicit absolute Docker bridges. Require the fixed Bash entrypoint, no-startup privileged arguments, and Docker option terminator, with every run line treated as load-bearing. Tests: offline zc tests Tests: zc clippy with warnings denied Tests: ci/check_actions.sh Tests: ci/check_fmt.sh Tests: git diff --check *Authored by an agent, posting via joshlf's account* gherrit-pr-id: Gcl7ijadfh2m7eft4ucy5czoaghddreiq
e96e0b4 to
9d34d33
Compare
135f323 to
104d5a2
Compare
Require reviewed planned roles to equal build_test and miri. Audit
their exact top-level shapes, display names, hosted runners, read-only
permissions, plan_ci and build_docker_env dependencies, and build run
defaults. Reject unreviewed job controls and strategy fields.
Require exact matrix gates and fan-out expressions. Include every
Miri selector, including toolchain, in its display name. Bind one named
executor step to each job steps mapping, with the exact selector
environment and checked CLI argv for its role.
Audit privileged custom shells and explicit absolute Docker bridges.
Require the fixed Bash entrypoint, no-startup privileged arguments, and
Docker option terminator, with every run line treated as load-bearing.
Tests: offline zc tests
Tests: zc clippy with warnings denied
Tests: ci/check_actions.sh
Tests: ci/check_fmt.sh
Tests: git diff --check
Authored by an agent, posting via joshlf's account
Latest Update: v9 — Compare vs v8
📚 Full Patch History
Links show the diff between the row version and the column version.
⬇️ Download this PR
Branch
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git checkout -b pr-Gcl7ijadfh2m7eft4ucy5czoaghddreiq FETCH_HEADCheckout
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git checkout FETCH_HEADCherry Pick
git fetch origin refs/heads/Gcl7ijadfh2m7eft4ucy5czoaghddreiq && git cherry-pick FETCH_HEADPull
Stacked PRs enabled by GHerrit.