Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,13 @@ githooks/pre-push text eol=lf
*.yaml text eol=lf
*.toml text eol=lf
*.tsv text eol=lf

# The Docker producer audit compares these extensionless sources byte-for-byte
# after the shared CRLF normalization boundary. Keep the live inputs and
# independent snapshots coordinated with
# `tools/zc/src/planned_adapter/image.rs` and the explicit attribute test in
# `tools/zc/src/ci.rs`.
.github/ci-image/.dockerignore text eol=lf
.github/ci-image/Dockerfile text eol=lf
tools/zc/testdata/ci-image.Dockerfile text eol=lf
tools/zc/testdata/ci-image.dockerignore text eol=lf
5 changes: 5 additions & 0 deletions .github/actions/setup-docker-with-retry/action.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
# `build_docker_env` executes this mutable local action before producing the CI
# image. Keep this complete file coordinated with
# `tools/zc/testdata/setup-docker-with-retry.action.yml` and the source list in
# `tools/zc/src/planned_adapter/image.rs`; the typed adapter intentionally
# rejects a one-sided edit.
name: Set up Docker with retry
description: Set up Buildx and authenticate to a registry, retrying transient failures

Expand Down
5 changes: 5 additions & 0 deletions .github/actions/upload-file-artifact/action.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
# `build_docker_env` uses this mutable local action to publish the CI image.
# Keep this complete file coordinated with
# `tools/zc/testdata/upload-file-artifact.action.yml` and the source list in
# `tools/zc/src/planned_adapter/image.rs`. Other callers share the same exact
# implementation, so a behavior change requires deliberate adapter review.
name: Upload file artifact
description: Publish one exact file for jobs in this workflow run

Expand Down
14 changes: 14 additions & 0 deletions .github/ci-image/.dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Copyright 2026 The Fuchsia Authors
#
# Licensed under the 2-Clause BSD License <LICENSE-BSD or
# https://opensource.org/license/bsd-2-clause>, Apache License, Version 2.0
# <LICENSE-APACHE or https://www.apache.org/licenses/LICENSE-2.0>, or the MIT
# license <LICENSE-MIT or https://opensource.org/licenses/MIT>, at your option.
# This file may not be copied, modified, or distributed except according to
# those terms.

# The CI image must not receive repository files as build-context inputs. This
# isolated directory and its complete entry set are audited by
# `tools/zc/src/planned_adapter/image.rs`; Docker still receives its Dockerfile
# and this ignore file for the build, but neither is available to COPY.
*
35 changes: 24 additions & 11 deletions .github/workflows/Dockerfile → .github/ci-image/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,14 @@
# This file may not be copied, modified, or distributed except according to
# those terms.

# `build_docker_env` builds this file as the runtime for typed matrix cells.
# This directory is the complete, isolated Docker context; the producer audit
# rejects any entry other than this file and `.dockerignore`. Keep the complete
# source coordinated with
# `tools/zc/testdata/ci-image.Dockerfile` and
# `tools/zc/src/planned_adapter/image.rs`; the producer audit rejects a
# one-sided change before matrix fan-out.

FROM ubuntu:24.04

# These are the same bounded, download-only retry counts configured in
Expand Down Expand Up @@ -42,19 +50,24 @@ RUN cargo install cargo-nextest --locked && \
cargo install --locked action-validator --version 0.8.0 && \
rm -rf /root/.cargo/registry /root/.cargo/git

WORKDIR /setup

COPY zerocopy/Cargo.toml ./zerocopy/Cargo.toml
COPY zerocopy/cargo.sh ./zerocopy/cargo.sh
COPY tools ./tools

ENV CARGO_ZEROCOPY_AUTO_INSTALL_TOOLCHAIN=1
WORKDIR /setup/zerocopy
RUN ./cargo.sh +stable --version && \
./cargo.sh +nightly --version && \
./cargo.sh +msrv --version && \
# Install the three high-traffic toolchains without executing code from the
# checkout. The build previously copied and ran cargo-zerocopy, which made the
# image depend on the entire mutable `tools` tree and allowed a change there to
# replace Cargo before matrix execution. `planned_adapter/image.rs` checks
# these defaults against the validated toolchain inventory, so changing a pin
# in `zerocopy/Cargo.toml` fails CI until this cache seed is updated too.
ARG ZC_MSRV_TOOLCHAIN=1.56.0
ARG ZC_STABLE_TOOLCHAIN=1.93.1
ARG ZC_NIGHTLY_TOOLCHAIN=nightly-2026-01-25
RUN rustup toolchain install "$ZC_MSRV_TOOLCHAIN" \
-c rust-src -c rustfmt -c clippy && \
rustup toolchain install "$ZC_STABLE_TOOLCHAIN" \
-c rust-src -c rustfmt -c clippy && \
rustup toolchain install "$ZC_NIGHTLY_TOOLCHAIN" \
-c rust-src -c rustfmt -c clippy -c miri && \
# Remove large intermediate artifacts to ensure that this step doesn't bloat
# the Docker image cache.
rm -rf /root/.cargo/registry /root/.cargo/git /root/.rustup/toolchains/*/share/doc

ENV CARGO_ZEROCOPY_AUTO_INSTALL_TOOLCHAIN=1
WORKDIR /workspace
Loading
Loading