Resolve Gitea Docker gateway without iproute2
All checks were successful
Candidate compatibility / prepare (push) Successful in 30s
Candidate compatibility / image ${{ matrix.id }} (push) Has been skipped
Candidate compatibility / fixture-contract (push) Successful in 1m9s
Candidate compatibility / lockstep clients Ruby 3.3 (push) Successful in 1m15s
Candidate compatibility / repository (push) Successful in 1m50s
Candidate compatibility / lockstep clients Ruby 3.4 (push) Successful in 1m49s
Candidate compatibility / Gitea full exact image matrix (push) Successful in 1m53s
Candidate compatibility / lockstep clients Ruby 4.0 (push) Successful in 2m16s
Candidate compatibility / lockstep clients Ruby 3.2 (push) Successful in 2m20s

This commit is contained in:
2026-07-20 00:30:05 -07:00
parent bf20a84a94
commit 328fa39c55
4 changed files with 58 additions and 6 deletions

View File

@@ -4,11 +4,13 @@ require "fileutils"
require "json"
require "minitest/autorun"
require "open3"
require "rbconfig"
require "tmpdir"
class ImageContractEvidenceTest < Minitest::Test
ROOT = File.expand_path("..", __dir__)
RUNNER = File.join(ROOT, "scripts/run_image_contract.sh")
GATEWAY_RESOLVER = File.join(ROOT, "scripts/private_default_gateway.rb")
VALID_IMAGE = "ghcr.io/anomalyco/opencode@sha256:#{'a' * 64}"
def setup
@@ -125,6 +127,32 @@ class ImageContractEvidenceTest < Minitest::Test
end
end
def test_resolves_a_private_default_gateway_from_linux_route_hex
route_path = File.join(@tmp, "route")
File.write(route_path, <<~ROUTES)
Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT
eth0 00000000 010011AC 0003 0 0 10 00000000 0 0 0
ROUTES
output, error, status = Open3.capture3(RbConfig.ruby, GATEWAY_RESOLVER, route_path)
assert status.success?, error
assert_equal "172.17.0.1\n", output
end
def test_gateway_resolver_rejects_a_public_default_gateway
route_path = File.join(@tmp, "public-route")
File.write(route_path, <<~ROUTES)
Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT
eth0 00000000 08080808 0003 0 0 10 00000000 0 0 0
ROUTES
_output, error, status = Open3.capture3(RbConfig.ruby, GATEWAY_RESOLVER, route_path)
refute status.success?
assert_match(/no private IPv4 default-route gateway found/, error)
end
private
def base_environment(checkout, commit, evidence_path)

View File

@@ -287,8 +287,7 @@ class RepositoryTest < Minitest::Test
assert_includes workflow, "exact-image-contract-gitea:"
assert_includes workflow, "if: github.server_url != 'https://github.com'"
assert_includes workflow, "run: scripts/run_image_matrix_contract.sh"
assert_includes workflow, "ip -4 route show default"
assert_includes workflow, "address.ipv4? && address.private?"
assert_includes workflow, 'probe_host="$(ruby scripts/private_default_gateway.rb)"'
assert_includes workflow, 'echo "OPENCODE_PROBE_HOST=$probe_host" >> "$GITHUB_ENV"'
assert_operator workflow.scan('BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile').length, :>=, 2
assert_operator workflow.scan("generated JSON is transient and is not review evidence").length, :>=, 3