From 8c83fb372bb21c1cbe77abcc7de5a6ca40a0b90a Mon Sep 17 00:00:00 2001 From: claude-bot Date: Tue, 18 Aug 2026 22:54:54 +0200 Subject: [PATCH] feat(runner): install the build toolchain compiled languages need The runner is host-mode, so there is no image bringing tools along: what is not on this LXC, no job has. Measured on l.kirchner/patchmgr, a Go project, where all six CI jobs were assigned and every one of them died in the first seconds: make all make: command not found go test -race go: -race requires cgo; enable cgo by setting CGO_ENABLED=1 make proto sudo: command not found Four packages, each for a reason: make the gate commands are make targets gcc Go turns CGO_ENABLED off when it finds no C compiler, and the race detector cannot be built without cgo protobuf-compiler protoc itself libprotobuf-dev the well-known .proto includes under /usr/include/google/protobuf; without them protoc fails even though the binary is there sudo stays absent on purpose. A workflow must not be able to install anything on this runner -- what is needed is declared here, in the script, and not in somebody's pipeline. That also keeps the security note at the top of this file honest: the LXC owns nothing, and it gains nothing at a workflow's request. Go is not in the list. Projects fetch it through actions/setup-go, because CI matrices run more than one version. Applied to the running LXC (301 on pve-gamer) while the runner was idle, then verified: make 4.3, gcc 12.2.0, libprotoc 3.21.12, 11 .proto includes present. The service PATH already contains /usr/bin, so no restart was needed. --- install/runner-install.sh | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/install/runner-install.sh b/install/runner-install.sh index a326549..57dfda7 100644 --- a/install/runner-install.sh +++ b/install/runner-install.sh @@ -63,8 +63,26 @@ valid_token_word "$RUNNER_LABELS" || { msg_err "RUNNER_LABELS enthält unzuläss # der unprivilegierte User darf dort nicht schreiben. run_user() { runuser -u "$APP_USER" -- env -C "$RUNNER_DIR" HOME="$APP_HOME" "$@"; } -# ── Pakete: git/rsync, Node (checkout-Action), Docker (Test-Container) ──────── -setup_base_apt git rsync ca-certificates curl +# ── Pakete: git/rsync, Node (checkout-Action), Docker (Test-Container), +# Build-Werkzeuge (Compiler-Sprachen in CI) ───────────────────────────────── +# +# make/gcc/protobuf: Der Runner faehrt Host-Mode, also gibt es kein Image, das +# Werkzeuge mitbringt — was hier nicht liegt, hat kein Job. Konkret gemessen an +# l.kirchner/patchmgr (Go): +# make "make: command not found" in jedem Gate-Job +# gcc ohne C-Compiler setzt Go CGO_ENABLED=0, und +# "go test -race" ist dann gar nicht baubar +# protobuf-compiler protoc fuer die Codegenerierung +# libprotobuf-dev liefert /usr/include/google/protobuf/*.proto; ohne die +# Includes scheitert protoc trotz vorhandenem Binary +# +# Bewusst NICHT installiert: sudo. Ein Workflow soll auf diesem Runner nichts +# nachinstallieren koennen — was gebraucht wird, steht hier. +# +# Go selbst gehoert nicht hierher: Projekte holen es ueber actions/setup-go, +# weil CI-Matrizen mehrere Fassungen fahren. +setup_base_apt git rsync ca-certificates curl \ + make gcc protobuf-compiler libprotobuf-dev NODE_HAVE="$(command -v node >/dev/null 2>&1 && node -v | sed -E 's/^v([0-9]+).*/\1/' || echo 0)" if [[ "$NODE_HAVE" != "$NODE_MAJOR" ]]; then