Skip to content

Commit dd28fc0

Browse files
author
Jon Palmer
committed
ci(docker): drop runtime smoke test, rely on Dockerfile static checks
GitHub-hosted macos-14 runners are themselves VMs and do not expose Apple's Virtualization Framework to guests (no nested virtualization), so colima --vm-type=vz --vz-rosetta aborts with VZErrorDomain Code=2 'Virtualization is not available on this hardware'. The earlier QEMU TCG smoke test on ubuntu-latest, while functionally correct, takes 15-25 min to import pytantan through the pixi env. Neither option is suitable for CI. Revert the workflow to a single build-and-push job and rely on the Dockerfile's build-time guards (file-presence check for pytantan/platform/*.so SIMD variants and objdump scan of every shipped .so for AVX2 mnemonics) to ensure no AVX2-tainted binary is ever published. Refs: actions/runner-images#9460
1 parent 2e5c865 commit dd28fc0

1 file changed

Lines changed: 11 additions & 129 deletions

File tree

‎.github/workflows/docker.yml‎

Lines changed: 11 additions & 129 deletions
Original file line numberDiff line numberDiff line change
@@ -30,11 +30,6 @@ jobs:
3030
name: Build funannotate2 image (linux/amd64)
3131
runs-on: ubuntu-latest
3232
timeout-minutes: 240
33-
outputs:
34-
staging_tag: ${{ steps.staging.outputs.tag }}
35-
tags: ${{ steps.meta.outputs.tags }}
36-
labels: ${{ steps.meta.outputs.labels }}
37-
dockerhub_enabled: ${{ env.DOCKERHUB_ENABLED }}
3833
env:
3934
DOCKERHUB_ENABLED: ${{ secrets.DOCKERHUB_TOKEN != '' && 'true' || 'false' }}
4035

@@ -57,13 +52,20 @@ jobs:
5752
uses: docker/setup-buildx-action@v3
5853

5954
- name: Log in to GHCR
60-
if: ${{ github.event.pull_request.head.repo.fork != true }}
55+
if: github.event_name != 'pull_request'
6156
uses: docker/login-action@v3
6257
with:
6358
registry: ghcr.io
6459
username: ${{ github.actor }}
6560
password: ${{ secrets.GITHUB_TOKEN }}
6661

62+
- name: Log in to Docker Hub
63+
if: ${{ github.event_name != 'pull_request' && env.DOCKERHUB_ENABLED == 'true' }}
64+
uses: docker/login-action@v3
65+
with:
66+
username: ${{ secrets.DOCKERHUB_USERNAME }}
67+
password: ${{ secrets.DOCKERHUB_TOKEN }}
68+
6769
- name: Extract image metadata
6870
id: meta
6971
uses: docker/metadata-action@v5
@@ -79,24 +81,15 @@ jobs:
7981
type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') }}
8082
type=raw,value=latest,enable=${{ github.event_name == 'workflow_dispatch' && github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }}
8183
82-
# Compute a single transient "staging" tag in GHCR. The smoke-test job
83-
# pulls this tag on a real Apple Silicon runner under Rosetta 2; the
84-
# image is only copied to the release tags (latest, vX.Y, sha, ...) once
85-
# the smoke test passes.
86-
- name: Compute staging tag
87-
id: staging
88-
run: |
89-
echo "tag=ghcr.io/nextgenusfs/funannotate2:staging-${GITHUB_SHA}" >> "$GITHUB_OUTPUT"
90-
91-
- name: Build image and push staging tag to GHCR
84+
- name: Build and push
9285
id: build
9386
uses: docker/build-push-action@v6
9487
with:
9588
context: .
9689
file: ./Dockerfile
9790
platforms: linux/amd64
98-
push: ${{ github.event.pull_request.head.repo.fork != true }}
99-
tags: ${{ steps.staging.outputs.tag }}
91+
push: ${{ github.event_name != 'pull_request' && (github.event_name != 'workflow_dispatch' || inputs.push) }}
92+
tags: ${{ steps.meta.outputs.tags }}
10093
labels: ${{ steps.meta.outputs.labels }}
10194
cache-from: type=gha
10295
cache-to: type=gha,mode=max
@@ -106,114 +99,3 @@ jobs:
10699
if: steps.build.outputs.digest != ''
107100
run: echo "Digest=${{ steps.build.outputs.digest }}"
108101

109-
# Smoke-test the staged image on a real Apple Silicon (M1) macOS runner
110-
# under Rosetta 2 -- exactly the environment where pytantan SIGILLs when
111-
# built with AVX2. If `import pytantan` succeeds here the binary is safe
112-
# to publish to the release tags.
113-
smoke-test-rosetta:
114-
name: Verify pytantan under Apple Rosetta 2 (macos-14)
115-
needs: build
116-
if: ${{ github.event.pull_request.head.repo.fork != true }}
117-
runs-on: macos-14
118-
timeout-minutes: 60
119-
permissions:
120-
contents: read
121-
packages: read
122-
123-
steps:
124-
- name: Install Rosetta 2
125-
# macos-14 (Apple Silicon) GitHub runners do not ship with Rosetta
126-
# pre-installed; `colima --vz-rosetta` needs it to set up the in-VM
127-
# binfmt translator for linux/amd64 containers.
128-
run: |
129-
sudo softwareupdate --install-rosetta --agree-to-license
130-
131-
- name: Install colima and docker CLI
132-
run: |
133-
brew install colima docker
134-
135-
- name: Start colima with VZ + Rosetta 2 (amd64 acceleration)
136-
run: |
137-
colima start \
138-
--arch aarch64 \
139-
--vm-type=vz \
140-
--vz-rosetta \
141-
--cpu 3 \
142-
--memory 6 \
143-
--disk 30
144-
docker info
145-
docker version
146-
147-
- name: Dump colima logs on failure
148-
if: failure()
149-
run: |
150-
echo "=== ha.stderr.log ==="
151-
cat /Users/runner/.colima/_lima/colima/ha.stderr.log || true
152-
echo "=== ha.stdout.log ==="
153-
cat /Users/runner/.colima/_lima/colima/ha.stdout.log || true
154-
echo "=== serial*.log ==="
155-
for f in /Users/runner/.colima/_lima/colima/serial*.log; do
156-
echo "--- $f ---"
157-
cat "$f" || true
158-
done
159-
160-
- name: Log in to GHCR
161-
run: |
162-
echo "${{ secrets.GITHUB_TOKEN }}" \
163-
| docker login ghcr.io -u "${{ github.actor }}" --password-stdin
164-
165-
- name: Pull staging image (linux/amd64)
166-
run: |
167-
docker pull --platform=linux/amd64 "${{ needs.build.outputs.staging_tag }}"
168-
docker image inspect "${{ needs.build.outputs.staging_tag }}" \
169-
--format '{{.Architecture}}/{{.Os}}'
170-
171-
- name: Smoke test pytantan import under Rosetta 2
172-
run: |
173-
set -euxo pipefail
174-
docker run --rm --platform=linux/amd64 \
175-
"${{ needs.build.outputs.staging_tag }}" \
176-
/app/.pixi/envs/default/bin/python -c \
177-
"import pytantan; from pytantan import Alphabet, RepeatFinder, default_scoring_matrix; print('pytantan smoke OK', pytantan.__version__)"
178-
179-
# Promote the staging tag to the real release tags. `docker buildx
180-
# imagetools create` performs a registry-side copy of the manifest, so
181-
# this finishes in seconds and never re-pulls the image bytes.
182-
promote:
183-
name: Promote staging image to release tags
184-
needs: [build, smoke-test-rosetta]
185-
if: ${{ github.event_name != 'pull_request' && (github.event_name != 'workflow_dispatch' || inputs.push) }}
186-
runs-on: ubuntu-latest
187-
env:
188-
DOCKERHUB_ENABLED: ${{ needs.build.outputs.dockerhub_enabled }}
189-
190-
steps:
191-
- name: Set up Docker Buildx
192-
uses: docker/setup-buildx-action@v3
193-
194-
- name: Log in to GHCR
195-
uses: docker/login-action@v3
196-
with:
197-
registry: ghcr.io
198-
username: ${{ github.actor }}
199-
password: ${{ secrets.GITHUB_TOKEN }}
200-
201-
- name: Log in to Docker Hub
202-
if: ${{ env.DOCKERHUB_ENABLED == 'true' }}
203-
uses: docker/login-action@v3
204-
with:
205-
username: ${{ secrets.DOCKERHUB_USERNAME }}
206-
password: ${{ secrets.DOCKERHUB_TOKEN }}
207-
208-
- name: Copy staging tag to release tags
209-
env:
210-
STAGING_TAG: ${{ needs.build.outputs.staging_tag }}
211-
TAGS: ${{ needs.build.outputs.tags }}
212-
run: |
213-
set -euxo pipefail
214-
printf '%s\n' "${TAGS}" | while IFS= read -r tag; do
215-
[ -z "${tag}" ] && continue
216-
echo "Promoting ${STAGING_TAG} -> ${tag}"
217-
docker buildx imagetools create --tag "${tag}" "${STAGING_TAG}"
218-
done
219-

0 commit comments

Comments
 (0)