Task 60521891665

security: harden CI actions and subprocess calls

2026-01-15 13:30:39 completed security-hardening-ci-scripts cb4f2b3b5b8d1a4c1acd46a5434c018e3af34975


Commands that took longer than 1 second (total 22m38s)
linedurationpercentagecommand
2323s1%LSan + UBSan + integer
98126s1%docker buildx build --file=/home/admin/actions-runner/_work/bitcoin/bitcoin/ci/test_imagefile --build-arg=CI_IMAGE_NAME_TAG=mirror.gcr.io/ubuntu:24.04 --build-arg=FILE_ENV=./ci/test/00_setup_env_native_asan.sh --build-arg=BASE_ROOT_DIR=/home/admin/actions-runner/_work/_temp --platform=linux --label=bitcoin-ci-test --tag=ci_native_asan --cache-from type=gha,url=http://127.0.0.1:12321/,url_v2=http://127.0.0.1:12321/,scope=ci_native_asan --load /home/admin/actions-runner/_work/bitcoin/bitcoin
10681s0%docker run --rm --interactive --detach --tty --cap-add=LINUX_IMMUTABLE --privileged -v /sys/kernel:/sys/kernel:rw --mount=type=bind,src=/home/admin/actions-runner/_work/bitcoin/bitcoin,dst=/home/admin/actions-runner/_work/bitcoin/bitcoin,readonly --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/ccache_dir,dst=/home/admin/actions-runner/_work/_temp/ccache_dir --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/depends/built,dst=/home/admin/actions-runner/_work/_temp/depends/built --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/depends/sources,dst=/home/admin/actions-runner/_work/_temp/depends/sources --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/previous_releases,dst=/home/admin/actions-runner/_work/_temp/previous_releases --mount=type=bind,src=/home/admin/actions-runner/_work/_temp/build,dst=/home/admin/actions-runner/_work/_temp/build --env-file=/tmp/env-admin-cinativeasan --name=ci_native_asan --network=ci-ip6net --platform=linux ci_native_asan
11661s0%retry -- apt-get update
133810s0%- skipped
16821m40s7%cmake --build /home/admin/actions-runner/_work/_temp/build -j8 --target all install
29043m16s14%ctest --test-dir /home/admin/actions-runner/_work/_temp/build --stop-on-failure -j8 --timeout 2400
322116m27s72%/home/admin/actions-runner/_work/_temp/build/test/functional/test_runner.py -j8 --tmpdirprefix /home/admin/actions-runner/_work/_temp/ci/scratch/test_runner/ --ansi --combinedlogslen=99999999 --timeout-factor=40 --quiet --failfast
46026s0%docker container kill 5181e7830c542624b39d0f920ea890d316963972f2a2aa281e4cb4f2f148554d
Tags
  • ASan + LSan + UBSan + integer
  • security-hardening-ci-scripts
  • COMPLETED