Skip to content

fix(e2e): isolate portable Podman snapshot packages - #12695

Draft
rsliter wants to merge 1 commit into
mainfrom
codex/portable-podman-snapshot-fix
Draft

rsliter wants to merge 1 commit into
mainfrom
codex/portable-podman-snapshot-fix

Conversation

@rsliter

@rsliter rsliter commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Outcome

Makes the trusted Portable Podman 5.7 builder resolve its pinned build packages and transitive dependencies only from the reviewed signed Ubuntu snapshot. A newer GitHub runner package set can no longer override the snapshot with incompatible dependency versions.

Reason

Trusted E2E run 37498354030 failed before the Portable Hermes workload because the runner mixed current Ubuntu indexes and installed newer packages with the exact snapshot pins. The resulting git, AppArmor, GLib, and SQLite version skew made APT reject the build dependency set. This is canonical workflow infrastructure, not a #12244 candidate defect.

Related issues

Part of #11892

Prerequisite for #12244

Changes

  • Write a dedicated deb822 source that addresses only the reviewed Ubuntu snapshot and uses the Ubuntu archive keyring.
  • Isolate APT package indexes and preferences from runner-global sources, pin the snapshot above installed versions, and explicitly permit the required downgrades on the ephemeral builder.
  • Extend the trusted workflow boundary test to protect the source, index, preference, authentication, and downgrade controls.

Verification

  • npx vitest run --project e2e-support test/e2e/support/native-podman-setup-action.test.ts — 25 tests passed.
  • npx vitest run --project e2e-support test/e2e/support/native-podman-setup-action.test.ts test/e2e/support/shared-e2e-workflow-boundary.test.ts test/e2e/support/e2e-host-dependency-workflow-boundary.test.ts — 288 tests passed.
  • npm run test:changed — growth guardrails and 25 selected E2E-support tests passed.
  • npm run checks:repository — all 18 repository checks passed.
  • npm run validate:pr — committed-tree hooks, builds, publication validation, and TypeScript checks passed.
  • Diff review — no secrets, API keys, or credentials added.

Review notes

This changes a sensitive trusted workflow boundary. The failure and repair are limited to the pre-workload Portable Podman builder. After merge, #12244 still requires a fresh trusted portable-hermes-finalization run from canonical main before it can become ready for review.


Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com

Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 8bded97 in the codex/portable-podma... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/portable-podma... 8bded97 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

@wscurran wscurran added area: ci CI workflows, checks, release automation, or GitHub Actions area: security Security controls, permissions, secrets, or hardening platform: container Affects Docker, containerd, Podman, or images platform: ubuntu Affects Ubuntu Linux environments labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci CI workflows, checks, release automation, or GitHub Actions area: security Security controls, permissions, secrets, or hardening platform: container Affects Docker, containerd, Podman, or images platform: ubuntu Affects Ubuntu Linux environments

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants