From d3f9991e61fffb8d5272365c558deb2e03a8c8ae Mon Sep 17 00:00:00 2001 From: ZhuchkaTriplesix Date: Fri, 9 Oct 2026 11:38:12 +0300 Subject: [PATCH] ci: temporary bubblewrap diagnostics on the runner The sandbox test skips with bwrap installed. This step prints the probe's exit code and the user namespace settings, to see why the probe fails on the runner. It is removed once the sandbox test runs. --- .github/workflows/ci.yml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c99f4525..6fc3dba4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -52,6 +52,18 @@ jobs: # bubblewrap runs the extension sandbox tests; without it they skip. sudo apt-get $APT install -y libsecret-1-dev bubblewrap + # TEMPORARY diagnostics: why the sandbox probe in the extension tests + # cannot run on this runner. Remove once the sandbox test runs. + - name: Diagnose bubblewrap + if: runner.environment == 'github-hosted' + continue-on-error: true + run: | + sudo apt-get install -y bubblewrap >/dev/null 2>&1 || true + bwrap --ro-bind / / /bin/true; echo "bwrap exit=$?" + bwrap --unshare-user --ro-bind / / /bin/true; echo "bwrap userns exit=$?" + sysctl kernel.apparmor_restrict_unprivileged_userns kernel.unprivileged_userns_clone 2>&1 || true + ls /etc/apparmor.d | grep -i bwrap || echo "no bwrap apparmor profile" + - name: Get dependencies run: flutter pub get