added potion-polyglot worker folder w/o repos

This commit is contained in:
2026-09-08 21:58:19 -04:00
parent f10303b8c2
commit a16a457669
211 changed files with 41614 additions and 0 deletions

View File

@@ -0,0 +1,171 @@
# Per-repo harbor task Dockerfile for potion-wp-site (potion-polyglot PHP member).
#
# HAND-AUTHORED, not generated: PHP is not a runtime kind gen-harbor-dockerfiles.ts knows,
# and adding one for a single member would be a larger change than it earns. The generator
# gets a new kind when a second first-party PHP member turns up; the other estates'
# members are Rust/JVM/.NET/Node. Precedent: strongsuit-client and strongsuit-server are also
# hand-authored and sit outside MEMBERS.
#
# The repo is a full WordPress 5.9.2 checkout, but the first-party code is one directory:
# wp-content/themes/potion, an Automattic _s derivative with real templates, an SCSS
# pipeline and JS. WordPress core and the stock plugins around it are vendored.
#
# What makes this member gradable without a test suite is that the theme ships genuine
# deterministic offline checks, and they are the reason to bake the toolchain rather than
# just the source:
# composer lint:php -> php-parallel-lint across the theme
# composer lint:wpcs -> phpcs against the WordPress-theme ruleset the repo commits
# itself in phpcs.xml.dist
# npm run lint:js -> wp-scripts lint-js over js/*.js
# npm run lint:scss -> wp-scripts lint-style over sass/**/*.scss
#
# No database. Grading needs none: every check above is static. *Running* the site would
# need MySQL plus an import of one of the two committed SQL dumps — a documented run-app
# limitation, the same shape as potion-api needing Mongo, and why this member is
# runtime:'none' in TOOLKIT_GROUPS rather than bootable in Explore.
FROM php:8.1-cli-bookworm
ARG TOOLKIT_BUILD_ID=dev
# Node 16 for the theme's node-sass/wp-scripts toolchain. node-sass builds native bindings
# against a specific ABI and has no prebuilt binary for current Node, so a modern major
# would fail to install rather than merely warn.
ENV NODE_VERSION=16.20.2
RUN apt-get update && apt-get install -y --no-install-recommends \
git curl unzip ca-certificates xz-utils libzip-dev \
&& rm -rf /var/lib/apt/lists/* \
&& curl -fsSL "https://nodejs.org/dist/v${NODE_VERSION}/node-v${NODE_VERSION}-linux-arm64.tar.xz" \
-o /tmp/node.tar.xz \
&& tar -xJf /tmp/node.tar.xz -C /usr/local --strip-components=1 \
&& rm /tmp/node.tar.xz \
&& node --version && npm --version
# Python >=3.10 for the reduced-toolset agent's str_replace_editor (dataclass kw_only).
# This block used to ASSERT the base already had it, on the claim that php:8.1-bookworm
# ships python3.11. It does not — the assertion failed with exit 127 (python3: not found),
# so the image could not build and this member could not be graded. Install a managed
# interpreter via uv, the same way every generated per-member Dockerfile does.
RUN curl -fsSL https://astral.sh/uv/install.sh | env UV_INSTALL_DIR=/usr/local/bin sh \
&& uv python install 3.10 \
&& ln -sf "$(uv python find 3.10)" /usr/local/bin/python3 \
&& python3 --version
# composer, pinned by installer checksum rather than piping the web to php.
RUN curl -fsSL https://getcomposer.org/installer -o /tmp/composer-setup.php \
&& php /tmp/composer-setup.php --install-dir=/usr/local/bin --filename=composer \
&& rm /tmp/composer-setup.php \
&& composer --version
# --- Playwright + Chromium, when the task opts in ----------------------------
# Installed only when task.toml sets `[metadata] browser = true`. A Dockerfile cannot read
# task.toml, so build-workspace.sh writes that answer to environment/browser-optin.
# Self-contained under /opt — the member's own runtime is untouched.
ENV PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright
COPY browser-optin /tmp/browser-optin
RUN set -eu; \
if [ "$(cat /tmp/browser-optin)" != "1" ]; then echo "browser: task did not opt in; skipping Playwright"; exit 0; fi; \
set -x; \
apt-get update -qq; \
apt-get install -y -qq --no-install-recommends \
xz-utils \
libxcomposite1 \
libxdamage1 \
libxfixes3 \
libxrandr2 \
libasound2 \
libatk1.0-0 \
libatk-bridge2.0-0 \
libatspi2.0-0 \
libcups2 \
libdbus-1-3 \
libgbm1 \
libnspr4 \
libnss3 \
libxkbcommon0 \
libpango-1.0-0 \
libcairo2 \
libxshmfence1 \
libx11-xcb1 \
libxcb-dri3-0 \
libdrm2; \
rm -rf /var/lib/apt/lists/*; \
arch="$(dpkg --print-architecture)"; \
case "$arch" in amd64) nodearch=x64;; arm64) nodearch=arm64;; *) echo "unsupported arch: $arch" >&2; exit 1;; esac; \
curl -fsSL "https://nodejs.org/dist/v20.19.5/node-v20.19.5-linux-${nodearch}.tar.xz" -o /tmp/pw-node.tar.xz; \
mkdir -p /opt/pw-node; \
tar -xJf /tmp/pw-node.tar.xz -C /opt/pw-node --strip-components=1; \
rm /tmp/pw-node.tar.xz; \
export npm_config_prefix=/opt/pw-node PATH="/opt/pw-node/bin:$PATH"; \
/opt/pw-node/bin/npm install -g playwright@1.56.0; \
test -d /opt/pw-node/lib/node_modules/playwright; \
/opt/pw-node/bin/node /opt/pw-node/lib/node_modules/playwright/cli.js install chromium; \
printf '#!/bin/sh\nNODE_PATH=/opt/pw-node/lib/node_modules exec /opt/pw-node/bin/node "$@"\n' > /usr/local/bin/pw; \
chmod +x /usr/local/bin/pw; \
printf 'const{chromium}=require("playwright");(async()=>{const b=await chromium.launch();const p=await b.newPage();await p.setContent("<h1 id=t>ok</h1>");if(await p.textContent("#t")!=="ok")throw new Error("bad render");await b.close();console.log("chromium OK");})()\n' > /tmp/pw-check.js; \
pw /tmp/pw-check.js; \
rm -f /tmp/pw-check.js
WORKDIR /workspace
# `COPY workspace/ .`, matching every generated per-member Dockerfile: build-workspace.sh
# materialises the task tree at environment/workspace/, so a `COPY repo ...` here cannot
# resolve and the image fails to build with "/repo: not found" — i.e. the member could not
# be graded at all. Caught by authoring a task against this member rather than only
# against the default one.
COPY workspace/ .
# Bake the theme's dev dependencies so the checks run offline. Both are best-effort: the
# source plus a working toolchain is the substrate, and a registry hiccup at build time
# must not make the whole member ungradable.
# composer >=2.9 refuses by default to install any package carrying a security advisory,
# and the theme's own linter (wp-coding-standards/wpcs 2.x, via wptrt/wpthemereview) is
# flagged — so `composer install` resolved to nothing, vendor/bin stayed empty, and BOTH
# deterministic checks failed with "Could not open input file" rather than with a verdict.
# The advisory is on a dev-only linter that runs offline against this repo's own source, so
# the block is turned off for this vendored toolchain rather than pinning the checks away.
# Second half of the same story: composer 2 ABORTS a non-interactive install unless the
# phpcodesniffer-composer-installer plugin is explicitly allowed, which is why the vendor
# tree came out half-populated (packages downloaded, none installed, no vendor/bin entries).
# That plugin is also what registers the WordPress standard with phpcs, so lint:wpcs cannot
# work without it.
RUN cd /workspace/wp-content/themes/potion \
&& composer config --no-plugins policy.advisories.block false \
&& composer config --no-plugins allow-plugins.dealerdirect/phpcodesniffer-composer-installer true \
&& (composer install --no-interaction --no-progress || \
echo "warning: composer install incomplete — lint:php / lint:wpcs may be unavailable") \
&& (npm install --no-audit --no-fund || \
echo "warning: npm install incomplete — lint:js / lint:scss may be unavailable")
ENV TOOLKIT_BUILD_ID=${TOOLKIT_BUILD_ID}
# Install the Codex CLI at BUILD time, for the same reason claude is: the agent-setup
# install needs the network, which the trial DNS jail blocks. Hard-fail rather than let a
# codex-less image cache and break every trial on that repo at agent-setup.
RUN for i in 1 2 3; do \
if curl -fsSL https://chatgpt.com/codex/install.sh -o /tmp/codex-install.sh \
&& CODEX_INSTALL_DIR=/usr/local/bin CODEX_NON_INTERACTIVE=true sh /tmp/codex-install.sh; then break; fi; \
echo "WARNING: codex install attempt $i failed; retrying in 5s" >&2; sleep 5; \
done; \
rm -f /tmp/codex-install.sh; \
if ! command -v codex >/dev/null 2>&1 && [ -x "$HOME/.local/bin/codex" ]; then \
ln -sf "$HOME/.local/bin/codex" /usr/local/bin/codex; \
fi; \
if ! command -v codex >/dev/null 2>&1 && command -v npm >/dev/null 2>&1; then \
npm install -g @openai/codex@latest || true; \
fi; \
command -v codex >/dev/null 2>&1 \
&& echo "codex installed at $(command -v codex)" \
|| echo "WARNING: codex CLI not installed (see the install output above)" >&2
# Resolver for the trial DNS allowlist (scripts/lib/dns-jail.sh); if this
# does not land, trials just run unjailed.
RUN (command -v apk >/dev/null 2>&1 && apk add --no-cache dnsmasq bind-tools) \
|| (apt-get update && apt-get install -y --no-install-recommends dnsmasq-base dnsutils \
&& rm -rf /var/lib/apt/lists/*) \
|| true
# Restrict DNS to the model endpoint when DNSJAIL_ALLOW is set (the agent supplies it).
# Source: scripts/lib/dns-jail-container.sh, staged here by build-workspace.sh.
COPY dns-jail/ /opt/raccoon-dns-jail/
RUN if [ -f /opt/raccoon-dns-jail/dns-jail-container.sh ]; then \
install -m 0755 /opt/raccoon-dns-jail/dns-jail-container.sh /usr/local/bin/raccoon-dns-jail \
&& sh -n /usr/local/bin/raccoon-dns-jail; \
else echo "NOTE: no DNS jail script staged; trials on this image run unjailed" >&2; fi