From 74c685b9605396c9e04a3b483b50c9d881d751ab Mon Sep 17 00:00:00 2001 From: Nim G Date: Thu, 2 Jul 2026 00:11:59 -0300 Subject: [PATCH 1/3] ci: harden cargo-component install in live canary --- .github/actionlint.yaml | 5 ++++ .github/workflows/live-canary.yml | 42 ++++++++++++++++++++----------- 2 files changed, 33 insertions(+), 14 deletions(-) create mode 100644 .github/actionlint.yaml diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 00000000000..9aebcd3d27d --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,5 @@ +self-hosted-runner: + labels: + - ironclaw-live + +config-variables: null diff --git a/.github/workflows/live-canary.yml b/.github/workflows/live-canary.yml index 456ef0d79ca..a15b05eff55 100644 --- a/.github/workflows/live-canary.yml +++ b/.github/workflows/live-canary.yml @@ -423,7 +423,7 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: ./.github/actions/install-cargo-component - name: Build WASM channels run: ./scripts/build-wasm-extensions.sh --channels - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 @@ -471,7 +471,7 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: ./.github/actions/install-cargo-component - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Run deterministic replay lane @@ -525,7 +525,9 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 + with: + tool: cargo-component@0.21.1 - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Pre-install zizmor @@ -1263,7 +1265,9 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 + with: + tool: cargo-component@0.21.1 - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Run rotating persona lane @@ -1319,7 +1323,9 @@ jobs: with: targets: wasm32-wasip2 - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 + with: + tool: cargo-component@0.21.1 - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Run private OAuth lane @@ -1383,7 +1389,9 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 + with: + tool: cargo-component@0.21.1 - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Configure Anthropic provider @@ -1392,9 +1400,11 @@ jobs: LIVE_ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }} LIVE_ANTHROPIC_MODEL: ${{ vars.LIVE_ANTHROPIC_MODEL || 'claude-sonnet-4-6' }} run: | - echo "LLM_BACKEND=anthropic" >> "${GITHUB_ENV}" - echo "ANTHROPIC_MODEL=${LIVE_ANTHROPIC_MODEL}" >> "${GITHUB_ENV}" - echo "ANTHROPIC_API_KEY=${LIVE_ANTHROPIC_API_KEY}" >> "${GITHUB_ENV}" + { + echo "LLM_BACKEND=anthropic" + echo "ANTHROPIC_MODEL=${LIVE_ANTHROPIC_MODEL}" + echo "ANTHROPIC_API_KEY=${LIVE_ANTHROPIC_API_KEY}" + } >> "${GITHUB_ENV}" - name: Configure OpenAI-compatible provider if: matrix.provider == 'openai-compatible' env: @@ -1402,10 +1412,12 @@ jobs: LIVE_OPENAI_COMPATIBLE_BASE_URL: ${{ vars.LIVE_OPENAI_COMPATIBLE_BASE_URL }} LIVE_OPENAI_COMPATIBLE_MODEL: ${{ vars.LIVE_OPENAI_COMPATIBLE_MODEL }} run: | - echo "LLM_BACKEND=openai_compatible" >> "${GITHUB_ENV}" - echo "LLM_API_KEY=${LIVE_OPENAI_COMPATIBLE_API_KEY}" >> "${GITHUB_ENV}" - echo "LLM_BASE_URL=${LIVE_OPENAI_COMPATIBLE_BASE_URL}" >> "${GITHUB_ENV}" - echo "LLM_MODEL=${LIVE_OPENAI_COMPATIBLE_MODEL}" >> "${GITHUB_ENV}" + { + echo "LLM_BACKEND=openai_compatible" + echo "LLM_API_KEY=${LIVE_OPENAI_COMPATIBLE_API_KEY}" + echo "LLM_BASE_URL=${LIVE_OPENAI_COMPATIBLE_BASE_URL}" + echo "LLM_MODEL=${LIVE_OPENAI_COMPATIBLE_MODEL}" + } >> "${GITHUB_ENV}" - name: Run provider matrix lane env: LANE: provider-matrix @@ -1458,7 +1470,9 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Install cargo-component - run: cargo install cargo-component --locked || true + uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 + with: + tool: cargo-component@0.21.1 - name: Build WASM extensions run: ./scripts/build-wasm-extensions.sh - name: Pre-install zizmor From 79158f92e9d072c49bd0f0759c10705dbc671d5a Mon Sep 17 00:00:00 2001 From: Nim G Date: Tue, 4 Aug 2026 19:30:45 -0300 Subject: [PATCH 2/3] ci: resolve setup-sccache-dist from a canonical checkout in prepare-reborn-webui-v2-live-qa The Setup OVH sccache step in prepare-reborn-webui-v2-live-qa runs after a checkout pinned to steps.target.outputs.checkout_ref, which can be a validated same-repo PR head SHA. Resolving the secrets-touching ./.github/actions/setup-sccache-dist composite from that ref let a same-repo branch swap in malicious composite-action code that would run with SCCACHE_DIST_AUTH_TOKEN and the OVH Redis SSH key in scope. Add a second checkout pinned to the repository default branch at a dedicated path and resolve the composite action from there instead, matching the canonical-checkout idiom already used to restore the Reborn WebUI v2 live QA harness in the reborn-webui-v2-live-qa job. --- .github/workflows/live-canary.yml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/.github/workflows/live-canary.yml b/.github/workflows/live-canary.yml index a15b05eff55..6404eed1d88 100644 --- a/.github/workflows/live-canary.yml +++ b/.github/workflows/live-canary.yml @@ -796,9 +796,16 @@ jobs: with: key: live-canary-reborn-webui-v2-live-qa + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 + if: steps.lookup.outputs.found != '1' + with: + persist-credentials: false + ref: ${{ github.event.repository.default_branch }} + path: .canonical-live-canary-actions + - name: Setup OVH sccache if: steps.lookup.outputs.found != '1' - uses: ./.github/actions/setup-sccache-dist + uses: ./.canonical-live-canary-actions/.github/actions/setup-sccache-dist with: scheduler-url: ${{ vars.SCCACHE_DIST_SCHEDULER_URL }} auth-token: ${{ secrets.SCCACHE_DIST_AUTH_TOKEN }} @@ -809,6 +816,11 @@ jobs: cache-ssh-known-hosts: ${{ secrets.SCCACHE_CACHE_SSH_KNOWN_HOSTS }} redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} + - name: Remove canonical action checkout + if: steps.lookup.outputs.found != '1' + shell: bash + run: rm -rf .canonical-live-canary-actions + - name: Build fallback Reborn WebUI v2 binary once if: steps.lookup.outputs.found != '1' env: From f62d9e7d3ca6d82203e169d432eec2cc0d58a686 Mon Sep 17 00:00:00 2001 From: Nim G Date: Wed, 5 Aug 2026 22:54:56 -0300 Subject: [PATCH 3/3] fix(ci): make canonical-checkout cleanup crash-safe with if: always() The Remove canonical action checkout step in prepare-reborn-webui-v2-live-qa lacked always(), so a failed Setup OVH sccache step would skip cleanup of .canonical-live-canary-actions. Low-impact on ephemeral ubuntu-latest today, but latent fragility given the workflow also has a persistent self-hosted runner elsewhere with no build-state cleanup between jobs. --- .github/workflows/live-canary.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/live-canary.yml b/.github/workflows/live-canary.yml index 6404eed1d88..d28c7c80933 100644 --- a/.github/workflows/live-canary.yml +++ b/.github/workflows/live-canary.yml @@ -817,7 +817,7 @@ jobs: redis-password: ${{ secrets.SCCACHE_REDIS_PASSWORD }} - name: Remove canonical action checkout - if: steps.lookup.outputs.found != '1' + if: always() && steps.lookup.outputs.found != '1' shell: bash run: rm -rf .canonical-live-canary-actions