after moving all to cipher

This commit is contained in:
2026-08-19 10:19:57 +00:00
parent 4df62d2609
commit 9abade1a81
100 changed files with 1286 additions and 4335 deletions

View File

@@ -52,6 +52,55 @@ RUN for i in 1 2 3; do \
USER root
# --- Playwright + Chromium, when the task opts in ----------------------------
# Installed only when task.toml sets `[metadata] browser = true`. A Dockerfile cannot read
# task.toml, so build-workspace.sh writes that answer to environment/browser-optin.
# Self-contained under /opt — the member's own runtime is untouched.
ENV PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright
COPY browser-optin /tmp/browser-optin
RUN set -eu; \
if [ "$(cat /tmp/browser-optin)" != "1" ]; then echo "browser: task did not opt in; skipping Playwright"; exit 0; fi; \
set -x; \
apt-get update -qq; \
apt-get install -y -qq --no-install-recommends \
xz-utils \
libxcomposite1 \
libxdamage1 \
libxfixes3 \
libxrandr2 \
libasound2 \
libatk1.0-0 \
libatk-bridge2.0-0 \
libatspi2.0-0 \
libcups2 \
libdbus-1-3 \
libgbm1 \
libnspr4 \
libnss3 \
libxkbcommon0 \
libpango-1.0-0 \
libcairo2 \
libxshmfence1 \
libx11-xcb1 \
libxcb-dri3-0 \
libdrm2; \
rm -rf /var/lib/apt/lists/*; \
arch="$(dpkg --print-architecture)"; \
case "$arch" in amd64) nodearch=x64;; arm64) nodearch=arm64;; *) echo "unsupported arch: $arch" >&2; exit 1;; esac; \
curl -fsSL "https://nodejs.org/dist/v20.19.5/node-v20.19.5-linux-${nodearch}.tar.xz" -o /tmp/pw-node.tar.xz; \
mkdir -p /opt/pw-node; \
tar -xJf /tmp/pw-node.tar.xz -C /opt/pw-node --strip-components=1; \
rm /tmp/pw-node.tar.xz; \
export npm_config_prefix=/opt/pw-node PATH="/opt/pw-node/bin:$PATH"; \
/opt/pw-node/bin/npm install -g playwright@1.56.0; \
test -d /opt/pw-node/lib/node_modules/playwright; \
/opt/pw-node/bin/node /opt/pw-node/lib/node_modules/playwright/cli.js install chromium; \
printf '#!/bin/sh\nNODE_PATH=/opt/pw-node/lib/node_modules exec /opt/pw-node/bin/node "$@"\n' > /usr/local/bin/pw; \
chmod +x /usr/local/bin/pw; \
printf 'const{chromium}=require("playwright");(async()=>{const b=await chromium.launch();const p=await b.newPage();await p.setContent("<h1 id=t>ok</h1>");if(await p.textContent("#t")!=="ok")throw new Error("bad render");await b.close();console.log("chromium OK");})()\n' > /tmp/pw-check.js; \
pw /tmp/pw-check.js; \
rm -f /tmp/pw-check.js
WORKDIR /workspace
COPY workspace/ .
@@ -74,6 +123,13 @@ RUN bundle config set --local frozen false \
&& bundle lock --add-platform aarch64-linux \
&& bundle install --jobs 4 --retry 3
# Same command Explore's post-create runs, so the trial renders the app the way its author
# saw it: app/assets/builds/ is gitignored, so without this the app renders unstyled here
# but styled in Explore, and a browser task would be judged against a page its author
# never saw. Not assets:precompile — that bakes a manifest which pins the server to stale
# assets, so an agent's CSS edit would never be served.
RUN bin/rails tailwindcss:build
RUN for t in ruby bundle psql redis-server chromium chromedriver claude python3; do \
command -v "$t" >/dev/null 2>&1 || { echo "FATAL: required tool '$t' missing from image" >&2; exit 1; }; \
done; \