Task 60032533833

security: harden CI actions and subprocess calls

2026-01-11 06:14:39 completed security-hardening-ci-scripts a60858a820c15a7f07d39501add6de2b1618936b


Commands that took longer than 1 second (total 58m49s)
linedurationpercentagecommand
9787s0%docker buildx build --file=/home/admin/actions-runner/_work/bitcoin/bitcoin/ci/test_imagefile --build-arg=CI_IMAGE_NAME_TAG=mirror.gcr.io/ubuntu:24.04 --build-arg=FILE_ENV=./ci/test/00_setup_env_native_fuzz_with_msan.sh --build-arg=BASE_ROOT_DIR=/home/admin/actions-runner/_work/_temp --platform=linux --label=bitcoin-ci-test --tag=ci_native_fuzz_msan --cache-from type=gha,url=http://127.0.0.1:12321/,url_v2=http://127.0.0.1:12321/,scope=ci_native_fuzz_msan --load /home/admin/actions-runner/_work/bitcoin/bitcoin
11421s0%retry -- apt-get update
11635s0%retry -- apt-get install curl -y
14622s0%g++-13 g++-13-x86-64-linux-gnu
15734s0%amd64 4:13.2.0-7ubuntu1 [1100 B]
19215s0%(4:13.2.0-7ubuntu1) ...
225242s1%retry -- git clone --depth=1 https://github.com/llvm/llvm-project -b llvmorg-21.1.5 /llvm-project
23833s0%- skipped
25151s0%testing configuration: /llvm-project/libcxx/test/configs/llvm-libc++-shared.cfg.in
255123s0%ninja -C /cxx_build/ -j8
45523s0%rm -rf /llvm-project
455739s1%echo -n done
45871s0%docker run --rm --interactive --detach --tty --cap-add=LINUX_IMMUTABLE --mount=type=bind,src=/home/admin/actions-runner/_work/bitcoin/bitcoin,dst=/home/admin/actions-runner/_work/bitcoin/bitcoin,readonly --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/ccache_dir,dst=/home/admin/actions-runner/_work/_temp/ccache_dir --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/depends/built,dst=/home/admin/actions-runner/_work/_temp/depends/built --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/depends/sources,dst=/home/admin/actions-runner/_work/_temp/depends/sources --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/previous_releases,dst=/home/admin/actions-runner/_work/_temp/previous_releases --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/build,dst=/home/admin/actions-runner/_work/_temp/build --env-file=/tmp/env-admin-ci_native_fuzz_msan --name=ci_native_fuzz_msan --network=ci-ip6net --platform=linux ci_native_fuzz_msan
476752s1%1].Add(stats);
51542m18s3%-
529511s0%- skipped
561117s0%cmake --build /home/admin/actions-runner/_work/_temp/build -j8 --target all
614751m23s87%/home/admin/actions-runner/_work/_temp/build/test/fuzz/test_runner.py -j8 -l DEBUG /home/admin/actions-runner/_work/_temp/ci/scratch/qa-assets/fuzz_corpora/ --empty_min_time=60
66009s0%docker container kill 0981de5a35f9aeacd739b7991f55ecc699a2f5147e7156d385f8eaf0972d9734
Tags
  • MSan, fuzz
  • security-hardening-ci-scripts
  • COMPLETED