From 8961aee0de33ea5cbdacc9f331c5512985b68fc4 Mon Sep 17 00:00:00 2001 From: Dotta Date: Thu, 3 Sep 2026 22:35:46 -0500 Subject: [PATCH] ci(runner): skip Daytona setup for local cells --- .github/workflows/runner-full-stack-e2e.yml | 5 ++++- tests/runner-e2e/workflow-security.test.ts | 23 +++++++++++++++++++++ 2 files changed, 27 insertions(+), 1 deletion(-) diff --git a/.github/workflows/runner-full-stack-e2e.yml b/.github/workflows/runner-full-stack-e2e.yml index 7ba868651a..1e49688578 100644 --- a/.github/workflows/runner-full-stack-e2e.yml +++ b/.github/workflows/runner-full-stack-e2e.yml @@ -351,18 +351,21 @@ jobs: source_revision: ${{ steps.image.outputs.source_revision }} content_id: ${{ steps.image.outputs.content_id }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - if: needs.catalog.outputs.needs_daytona == 'true' + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: ref: ${{ needs.authorize.outputs.target_sha }} persist-credentials: false - name: Download resolved target lockfile + if: needs.catalog.outputs.needs_daytona == 'true' uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 with: artifact-ids: ${{ needs.target_lock.outputs.artifact_id }} path: ${{ runner.temp }}/runner-e2e-target-lock - name: Restore resolved target lockfile + if: needs.catalog.outputs.needs_daytona == 'true' env: TARGET_SHA: ${{ needs.authorize.outputs.target_sha }} EXPECTED_LOCK_SHA256: ${{ needs.target_lock.outputs.lock_sha256 }} diff --git a/tests/runner-e2e/workflow-security.test.ts b/tests/runner-e2e/workflow-security.test.ts index 927dd4c4de..240a59cc5d 100644 --- a/tests/runner-e2e/workflow-security.test.ts +++ b/tests/runner-e2e/workflow-security.test.ts @@ -186,6 +186,10 @@ describe("public repository paid workflow security", () => { fullStack.indexOf(" target_lock:"), fullStack.indexOf(" catalog:"), ); + const daytonaImageJob = fullStack.slice( + fullStack.indexOf(" daytona_image:"), + fullStack.indexOf(" build_runner_artifacts:"), + ); expect(authorizeJob).toContain( "aws_runner='runs-on/fleet=paperclip-public-pr-x64/env=public-ci'", ); @@ -287,6 +291,25 @@ describe("public repository paid workflow security", () => { expect(fullStack).toContain( "cancel-in-progress: ${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch }}", ); + expect(daytonaImageJob).toMatch( + /- if: needs\.catalog\.outputs\.needs_daytona == 'true'\n\s+uses: actions\/checkout@[0-9a-f]{40}/u, + ); + for (const stepName of [ + "Download resolved target lockfile", + "Restore resolved target lockfile", + ]) { + expect(daytonaImageJob).toMatch( + new RegExp( + `- name: ${stepName}\\n\\s+if: needs\\.catalog\\.outputs\\.needs_daytona == 'true'`, + "u", + ), + ); + } + expect(daytonaImageJob).toMatch( + /- name: No Daytona image needed\n\s+id: local_only\n\s+if: needs\.catalog\.outputs\.needs_daytona != 'true'/u, + ); + expect(daytonaImageJob).toContain('echo "source_revision="'); + expect(daytonaImageJob).toContain('echo "content_id="'); const targetCodeJobs = [ fullStack.slice( fullStack.indexOf(" catalog:"),