mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The dns-resolver suite's end-to-end scenarios compiled fips and fips-gateway themselves, in a Debian 12 image with whatever Rust was current. On GitHub that was a second release build on every run, with no cache, and it was neither the toolchain nor the build that ships. And every GitHub package build assembled its builder image from scratch on a fresh runner: apt, rustup and a source compile of cargo-deb, on both legs of the release workflow and in CI's package job. The suite now takes --deb PATH and unpacks the two binaries from the package with dpkg-deb. The package is built in the pinned floor container, so its binaries start on all five e2e distributions. Without --deb the suite builds the package through build-deb-container.sh, the same fallback the install suite uses, so the inline Debian 12 builder is gone rather than kept as a second path. A missing --deb file is refused before any scenario runs, and a missing dpkg-deb is a named error. In the workflow the dns-resolver leg moves to a job of its own that downloads the package the install legs use, keeping its displayed check name. In local CI a shared helper builds the package once for both the dns-resolver and deb-install suites. build-deb-container.sh gains --print-image-tag, which prints the image tag without needing docker, and --image-archive PATH: when the image is absent and the archive exists it is loaded from there, and when the run builds the image it is saved there, through a temporary file renamed into place. An archive that fails to load, or does not hold the expected tag, is a warning and a rebuild rather than a failed build, since the archive only saves time. Both workflows restore the archive from the Actions cache under a key made from the image tag, so any change that rebuilds the image locally also misses the cache. Only pushes to maint, master and next save an entry, so pull requests and topic branches read the default branch's entry instead of each storing a copy that nothing else can read. A restored image is not refreshed from apt or the base image until one of the tag's inputs changes, as was already the case locally.