Documentation contents

GitLab CI

Run the gate on merge requests with the example job from the repository.

OpenHarnX 0.1.1

ohx gate is a plain command, so any CI that runs a shell on Linux can run it: make the base commit available, install a pinned OpenHarnX, run the gate, keep ohx-gate/.

The job#

Copy this job into your .gitlab-ci.yml. It is the repository file, shown as is:

# OpenHarnX gate for GitLab merge requests (example, T79).
#
# Copy this job into your .gitlab-ci.yml. The job image is built from OpenHarnX's
# ci/linux/Dockerfile (Python 3.12, Node 22, srt, bubblewrap); push it to your
# registry and set OHX_IMAGE. The runner must allow user namespaces for the
# sandbox: see docs/ci/README.md. Exit code 0 is READY; anything else fails the job.
ohx-gate:
  image: $OHX_IMAGE
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"
  variables:
    GIT_DEPTH: "0"
    OHX_SOURCE: "git+https://github.com/rupeshpoojary9/OpenHarnX"
    OHX_VERSION: "<commit SHA of the OpenHarnX version you trust>"
    OHX_BASE: $CI_MERGE_REQUEST_DIFF_BASE_SHA
  timeout: 30m
  script:
    - |
      # ohx-gate commands: start
      base="$OHX_BASE"
      git rev-parse --verify -q "$base^{commit}" >/dev/null || { git fetch --no-tags origin "$base"; base=FETCH_HEAD; }
      python3 -m venv "$HOME/ohx"
      "$HOME/ohx/bin/pip" install -q uv "openharnx @ $OHX_SOURCE@$OHX_VERSION"
      OHX_SIGNING_KEY=none "$HOME/ohx/bin/ohx" gate --base "$base" --sandbox srt --out ohx-gate
      # ohx-gate commands: end
  artifacts:
    when: always
    paths:
      - ohx-gate/
    expire_in: 30 days

Set two things:

  • OHX_IMAGE: an image built from the repository's ci/linux/Dockerfile (Python 3.12, Node 22, srt, bubblewrap), pushed to your registry.
  • OHX_VERSION: the commit SHA of the OpenHarnX version you trust. For 0.1.1 that is 2ea714cffcf425d0220d03d5d6802a32707acb05.

Runner requirements#

The sandbox creates user namespaces.

  • On a virtual machine runner (a shell executor) that works as is, except on Ubuntu 24.04, which needs sysctl -w kernel.apparmor_restrict_unprivileged_userns=0.
  • In a container it needs --security-opt seccomp=unconfined --security-opt apparmor=unconfined --security-opt systempaths=unconfined.
  • Shared container runners that do not allow these options cannot run the sandbox. The gate then reports every check unavailable, never READY.

Approvals#

GitLab has no ohx-approve-tests label. A maintainer approves intended test changes with a signed ohx approve-tests, and the job fetches the notes before the gate. See approve intentional test changes.

Trust#

GitLab runs fork pipelines in the fork's project unless a maintainer starts one in the parent. Use throwaway runners for merge requests from outside the team, and make the job required with "Pipelines must succeed". See trusted base and required checks.

Esc
Try verify, STALE, approve-tests or GitLab. Common pages: