From efcda9d6cf492b78e0e068f31de04d38562ee7dd Mon Sep 17 00:00:00 2001 From: Amaury Chamayou Date: Thu, 1 Oct 2026 10:50:33 +0100 Subject: [PATCH] Restore workspace ownership before Cross-platform LTS upgrade checkout The test-upgrade job runs directly on a reused VMSS runner. When it lands on the VM that just ran the Azure Linux 3 build-install job of the same run, which checks out CCF as root inside its container, actions/checkout fails with permission errors on the root-owned workspace. This broke the last two weekly runs on main. Restore ownership of the workspace to the runner user before checking out. The step is identical to the one in #8282, where it was validated. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/README.md | 2 ++ .github/workflows/cross-platform-lts.yml | 6 ++++++ 2 files changed, 8 insertions(+) diff --git a/.github/workflows/README.md b/.github/workflows/README.md index f2b8a047c92..1d35823621f 100644 --- a/.github/workflows/README.md +++ b/.github/workflows/README.md @@ -60,6 +60,8 @@ File: `ci-al4.yml` Builds configurable CCF release install trees on Azure Linux 3 and Azure Linux 4 in parallel, then runs the LTS live-upgrade test directly on a VMSS runner. By default, it upgrades from the previous stable CCF release to the latest stable release; both versions can be overridden using the manual inputs in [`cross-platform-lts.yml`](cross-platform-lts.yml). Separate runtime images install only the required shared-library packages and copy in the matching install tree. Each CCF node runs in the container matching the distribution on which its binary was built, while the existing Python test infrastructure orchestrates the rolling upgrade over host networking. Runs weekly and manually, but not on pull requests because both full builds and the compatibility test are expensive. +Because the upgrade job runs directly on the runner rather than in a container, it first restores ownership of the workspace with `sudo chown`. VMSS runners are reused across jobs, and `--user root` container jobs, including the Azure Linux 3 build in the same run, can leave root-owned files in the shared workspace that would otherwise make `actions/checkout` fail with permission errors. + Shared workflow environment values define the Python version, base images, runner pool labels, install archive filename, and test workspace. File: `cross-platform-lts.yml` diff --git a/.github/workflows/cross-platform-lts.yml b/.github/workflows/cross-platform-lts.yml index 5ac9803e9aa..3588648057b 100644 --- a/.github/workflows/cross-platform-lts.yml +++ b/.github/workflows/cross-platform-lts.yml @@ -160,6 +160,12 @@ jobs: runs-on: [*azl3_pool] steps: + - name: "Restore workspace ownership" + shell: bash + run: | + set -euo pipefail + sudo chown -R "$(id -u):$(id -g)" "$GITHUB_WORKSPACE" + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0