feat(runner): install the build toolchain compiled languages need #10

Merged
l.kirchner merged 2 commits from feat/runner-build-toolchain into main 2026-08-18 23:02:17 +02:00
Owner

Der instanzweite Runner faehrt Host-Mode — es gibt kein Image, das Werkzeuge mitbringt. Was hier nicht liegt, hat kein Job.

Gemessen an l.kirchner/patchmgr (Go): Seit dem Label-Fix werden dort alle sechs CI-Jobs zugeteilt und ausgefuehrt, und jeder stirbt in den ersten Sekunden:

make all         make: command not found
go test -race    go: -race requires cgo; enable cgo by setting CGO_ENABLED=1
make proto       sudo: command not found

Vier Pakete, jedes mit Grund:

Paket wofuer
make die Gate-Kommandos sind make-Targets
gcc Go schaltet CGO_ENABLED ab, wenn es keinen C-Compiler findet; der Race-Detektor ist ohne cgo nicht baubar
protobuf-compiler protoc
libprotobuf-dev die Includes unter /usr/include/google/protobuf — ohne sie scheitert protoc trotz vorhandenem Binary

sudo bleibt bewusst weg. Ein Workflow soll auf diesem Runner nichts nachinstallieren koennen; was gebraucht wird, steht im Skript. Das haelt auch den Sicherheitshinweis am Kopf der Datei ehrlich — der LXC besitzt nichts und bekommt auch auf Zuruf eines Workflows nichts dazu.

Go steht nicht in der Liste, weil Projekte es ueber actions/setup-go holen (CI-Matrizen fahren mehrere Fassungen).

Bereits auf den laufenden LXC angewandt (301 auf pve-gamer), waehrend der Runner idle war (busy=false, keine Kindprozesse). Verifiziert: make 4.3, gcc 12.2.0, libprotoc 3.21.12, 11 .proto-Includes inklusive timestamp.proto. Der PATH des Dienstes enthaelt /usr/bin, ein Neustart war nicht noetig. Dieser PR zieht den Code nach, damit ein Neuaufbau des LXC dieselbe Maschine ergibt.

Lokal geprueft: bash -n, tests/check_ct_source.sh, tests/test_validation.sh — alle gruen. Cross-Review laeuft ueber gate-review.

Der instanzweite Runner faehrt Host-Mode — es gibt kein Image, das Werkzeuge mitbringt. Was hier nicht liegt, hat kein Job. **Gemessen** an l.kirchner/patchmgr (Go): Seit dem Label-Fix werden dort alle sechs CI-Jobs zugeteilt und ausgefuehrt, und jeder stirbt in den ersten Sekunden: ``` make all make: command not found go test -race go: -race requires cgo; enable cgo by setting CGO_ENABLED=1 make proto sudo: command not found ``` **Vier Pakete, jedes mit Grund:** | Paket | wofuer | |---|---| | `make` | die Gate-Kommandos sind make-Targets | | `gcc` | Go schaltet CGO_ENABLED ab, wenn es keinen C-Compiler findet; der Race-Detektor ist ohne cgo nicht baubar | | `protobuf-compiler` | protoc | | `libprotobuf-dev` | die Includes unter /usr/include/google/protobuf — ohne sie scheitert protoc trotz vorhandenem Binary | **`sudo` bleibt bewusst weg.** Ein Workflow soll auf diesem Runner nichts nachinstallieren koennen; was gebraucht wird, steht im Skript. Das haelt auch den Sicherheitshinweis am Kopf der Datei ehrlich — der LXC besitzt nichts und bekommt auch auf Zuruf eines Workflows nichts dazu. **Go steht nicht in der Liste**, weil Projekte es ueber actions/setup-go holen (CI-Matrizen fahren mehrere Fassungen). **Bereits auf den laufenden LXC angewandt** (301 auf pve-gamer), waehrend der Runner idle war (busy=false, keine Kindprozesse). Verifiziert: make 4.3, gcc 12.2.0, libprotoc 3.21.12, 11 .proto-Includes inklusive timestamp.proto. Der PATH des Dienstes enthaelt /usr/bin, ein Neustart war nicht noetig. Dieser PR zieht den Code nach, damit ein Neuaufbau des LXC dieselbe Maschine ergibt. Lokal geprueft: `bash -n`, `tests/check_ct_source.sh`, `tests/test_validation.sh` — alle gruen. Cross-Review laeuft ueber gate-review.
l.kirchner added 1 commit 2026-08-18 22:55:12 +02:00
feat(runner): install the build toolchain compiled languages need
CI / Shell-Lint (bash -n, source-check, Validierungs-Tests) (pull_request) Successful in 2s
8c83fb372b
The runner is host-mode, so there is no image bringing tools along: what is
not on this LXC, no job has. Measured on l.kirchner/patchmgr, a Go project,
where all six CI jobs were assigned and every one of them died in the first
seconds:

    make all         make: command not found
    go test -race    go: -race requires cgo; enable cgo by setting CGO_ENABLED=1
    make proto       sudo: command not found

Four packages, each for a reason:

    make               the gate commands are make targets
    gcc                Go turns CGO_ENABLED off when it finds no C compiler,
                       and the race detector cannot be built without cgo
    protobuf-compiler  protoc itself
    libprotobuf-dev    the well-known .proto includes under
                       /usr/include/google/protobuf; without them protoc fails
                       even though the binary is there

sudo stays absent on purpose. A workflow must not be able to install anything
on this runner -- what is needed is declared here, in the script, and not in
somebody's pipeline. That also keeps the security note at the top of this file
honest: the LXC owns nothing, and it gains nothing at a workflow's request.

Go is not in the list. Projects fetch it through actions/setup-go, because CI
matrices run more than one version.

Applied to the running LXC (301 on pve-gamer) while the runner was idle, then
verified: make 4.3, gcc 12.2.0, libprotoc 3.21.12, 11 .proto includes present.
The service PATH already contains /usr/bin, so no restart was needed.
l.kirchner added 1 commit 2026-08-18 23:01:36 +02:00
docs(runner): name the protoc coupling and fix a mechanism claim
CI / Shell-Lint (bash -n, source-check, Validierungs-Tests) (pull_request) Successful in 2s
3c77d34b7e
Both from the cross-review, both fair.

"Go setzt CGO_ENABLED=0" is right about the effect and wrong about the
mechanism: Go does not set the variable, cgo simply stays off when no C
compiler is found, and go env then reports 0. Reworded.

And protoc on an instance-wide runner ties every repository to the
distribution's version -- 3.21.x on Debian 12. Unlike make and gcc that is a
code generator, so a distro upgrade changes generated code for all users at
once. The comment says so now, and says where a project that needs its own
version should pin it instead of raising it here for everybody.
l.kirchner merged commit 0ab4f98f4e into main 2026-08-18 23:02:17 +02:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: luki-net/proxmox-scripts#10