From 8c83fb372bb21c1cbe77abcc7de5a6ca40a0b90a Mon Sep 17 00:00:00 2001 From: claude-bot Date: Tue, 18 Aug 2026 22:54:54 +0200 Subject: [PATCH 1/2] feat(runner): install the build toolchain compiled languages need The runner is host-mode, so there is no image bringing tools along: what is not on this LXC, no job has. Measured on l.kirchner/patchmgr, a Go project, where all six CI jobs were assigned and every one of them died in the first seconds: make all make: command not found go test -race go: -race requires cgo; enable cgo by setting CGO_ENABLED=1 make proto sudo: command not found Four packages, each for a reason: make the gate commands are make targets gcc Go turns CGO_ENABLED off when it finds no C compiler, and the race detector cannot be built without cgo protobuf-compiler protoc itself libprotobuf-dev the well-known .proto includes under /usr/include/google/protobuf; without them protoc fails even though the binary is there sudo stays absent on purpose. A workflow must not be able to install anything on this runner -- what is needed is declared here, in the script, and not in somebody's pipeline. That also keeps the security note at the top of this file honest: the LXC owns nothing, and it gains nothing at a workflow's request. Go is not in the list. Projects fetch it through actions/setup-go, because CI matrices run more than one version. Applied to the running LXC (301 on pve-gamer) while the runner was idle, then verified: make 4.3, gcc 12.2.0, libprotoc 3.21.12, 11 .proto includes present. The service PATH already contains /usr/bin, so no restart was needed. --- install/runner-install.sh | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/install/runner-install.sh b/install/runner-install.sh index a326549..57dfda7 100644 --- a/install/runner-install.sh +++ b/install/runner-install.sh @@ -63,8 +63,26 @@ valid_token_word "$RUNNER_LABELS" || { msg_err "RUNNER_LABELS enthält unzuläss # der unprivilegierte User darf dort nicht schreiben. run_user() { runuser -u "$APP_USER" -- env -C "$RUNNER_DIR" HOME="$APP_HOME" "$@"; } -# ── Pakete: git/rsync, Node (checkout-Action), Docker (Test-Container) ──────── -setup_base_apt git rsync ca-certificates curl +# ── Pakete: git/rsync, Node (checkout-Action), Docker (Test-Container), +# Build-Werkzeuge (Compiler-Sprachen in CI) ───────────────────────────────── +# +# make/gcc/protobuf: Der Runner faehrt Host-Mode, also gibt es kein Image, das +# Werkzeuge mitbringt — was hier nicht liegt, hat kein Job. Konkret gemessen an +# l.kirchner/patchmgr (Go): +# make "make: command not found" in jedem Gate-Job +# gcc ohne C-Compiler setzt Go CGO_ENABLED=0, und +# "go test -race" ist dann gar nicht baubar +# protobuf-compiler protoc fuer die Codegenerierung +# libprotobuf-dev liefert /usr/include/google/protobuf/*.proto; ohne die +# Includes scheitert protoc trotz vorhandenem Binary +# +# Bewusst NICHT installiert: sudo. Ein Workflow soll auf diesem Runner nichts +# nachinstallieren koennen — was gebraucht wird, steht hier. +# +# Go selbst gehoert nicht hierher: Projekte holen es ueber actions/setup-go, +# weil CI-Matrizen mehrere Fassungen fahren. +setup_base_apt git rsync ca-certificates curl \ + make gcc protobuf-compiler libprotobuf-dev NODE_HAVE="$(command -v node >/dev/null 2>&1 && node -v | sed -E 's/^v([0-9]+).*/\1/' || echo 0)" if [[ "$NODE_HAVE" != "$NODE_MAJOR" ]]; then -- 2.54.0 From 3c77d34b7ea03c869ea6dcc04427a2db15712e74 Mon Sep 17 00:00:00 2001 From: claude-bot Date: Tue, 18 Aug 2026 23:01:34 +0200 Subject: [PATCH 2/2] docs(runner): name the protoc coupling and fix a mechanism claim Both from the cross-review, both fair. "Go setzt CGO_ENABLED=0" is right about the effect and wrong about the mechanism: Go does not set the variable, cgo simply stays off when no C compiler is found, and go env then reports 0. Reworded. And protoc on an instance-wide runner ties every repository to the distribution's version -- 3.21.x on Debian 12. Unlike make and gcc that is a code generator, so a distro upgrade changes generated code for all users at once. The comment says so now, and says where a project that needs its own version should pin it instead of raising it here for everybody. --- install/runner-install.sh | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/install/runner-install.sh b/install/runner-install.sh index 57dfda7..80751d9 100644 --- a/install/runner-install.sh +++ b/install/runner-install.sh @@ -70,12 +70,20 @@ run_user() { runuser -u "$APP_USER" -- env -C "$RUNNER_DIR" HOME="$APP_HOME" "$@ # Werkzeuge mitbringt — was hier nicht liegt, hat kein Job. Konkret gemessen an # l.kirchner/patchmgr (Go): # make "make: command not found" in jedem Gate-Job -# gcc ohne C-Compiler setzt Go CGO_ENABLED=0, und -# "go test -race" ist dann gar nicht baubar +# gcc ohne gefundenen C-Compiler bleibt cgo aus (go env +# meldet dann CGO_ENABLED=0), und "go test -race" ist +# nicht baubar # protobuf-compiler protoc fuer die Codegenerierung # libprotobuf-dev liefert /usr/include/google/protobuf/*.proto; ohne die # Includes scheitert protoc trotz vorhandenem Binary # +# ACHTUNG protoc: Das bindet jedes Repo der Instanz an die protoc-Fassung der +# Distribution (Debian 12: 3.21.x). Anders als make/gcc ist protoc ein +# Codegenerator — ein Distro-Upgrade aendert erzeugten Code fuer alle Nutzer +# gleichzeitig. Wer eine eigene Fassung braucht, pinnt sie im Projekt +# (Release-Tarball, buf, oder Docker — der Runner hat Docker) statt sie hier +# zu heben. +# # Bewusst NICHT installiert: sudo. Ein Workflow soll auf diesem Runner nichts # nachinstallieren koennen — was gebraucht wird, steht hier. # -- 2.54.0