Evan Lezar
c195e23267
test(conformance): remove plan-driven continuity tests ( #3342 )
...
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-15 14:57:07 +00:00
Jesse Jaggars and Drew Newberry
02b664bb0d
refactor(config): normalize and enforce gateway schema v2 ( #2814 )
...
* refactor(config): normalize compute driver field names
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* refactor(config): introduce canonical gateway fields
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* refactor(config): enforce gateway schema version 2
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): preserve compute driver runtime guarantees
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): address schema v2 review regressions
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): complete schema v2 migration safeguards
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(config): expand schema v2 regression coverage
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(config): add schema v2 parity manifest
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): correct parity manifest inventory
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* docs(config): record schema v2 intentional changes
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* docs(config): disposition schema v2 parity gaps
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): add dual schema parity harness
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): establish compute lifecycle parity baseline
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): preserve gateway option compatibility
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): record gateway option parity
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* docs(config): close gateway-wide parity gaps
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(podman): apply configured pids limit
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): validate Podman option parity
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): add Kubernetes option parity harness
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): record Kubernetes option parity
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): disposition VM parity lanes
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): add external driver parity lane
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(e2e): preserve external driver pull policy
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): attest parity artifacts and launches
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): require clean parity build sources
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): bind parity runtime artifacts
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(e2e): use isolated supervisor tags
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(e2e): qualify parity image tags
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(e2e): serve parity supervisor locally
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): isolate parity podman services
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): harden parity evidence provenance
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): pin parity sandbox artifacts
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): attest parity runtime inputs
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): bind parity runtime evidence
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): record compute boundary parity
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(e2e): disposition cross-cutting parity lanes
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(packaging): preflight gateway config upgrades
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): preserve rebase integration guarantees
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(ci): isolate temporary git signing config
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): update remaining schema v2 consumers
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(ci): provide e2fs tools to VM tests
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): align preflight with gateway startup
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(vm): preserve rootfs tar configuration
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* chore(config): adopt duration unit constructors
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(packaging): preflight RPM gateway config
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(config): address driver review findings
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(e2e): require fresh semantic parity evidence
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* fix(docker): update tests for renamed sandbox label
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
* test(gateway): preserve selective driver coverage after rebase
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
Co-authored-by: Drew Newberry <anewberry@nvidia.com >
2026-09-11 05:00:24 +00:00
Simon Scatton
bcf96e4900
chore(nix): unify Linux cross-compilation toolchains ( #3242 )
...
* chore(nix): unify native and cross-compilation toolchains
Replace the separate GNU and musl development shells with one shell that
provides explicit toolchains for x86_64 and aarch64 Linux, plus native
Darwin on macOS. Cargo selects the compiler, assembler, archiver, and
linker through target-specific environment variables.
Build GNU targets against a glibc 2.28 sysroot with static GCC runtimes
and use the musl toolchains for static Linux executables. Build Z3 and
AWS-LC with each target's stdenv and expose AWS-LC libraries and Rust
bindings through its target-specific system directory.
Keep Darwin system libraries on the unprocessed Apple SDK and prevent
the Rust toolchain from propagating replacement libraries into the shell.
Include the compiler and libc fixes needed for Darwin-to-Linux builds.
Share dependency and environment wiring through mkToolchain, keep compiler
wrappers in the Linux and Darwin modules, and group the pinned GNU build
environment under glibc-2.28. Document the toolchain boundaries in the build
architecture overview.
Validation: actionlint and nix fmt pass. The toolchain refactor preserves
the shell derivations for x86_64 Linux, aarch64 Linux, and aarch64 Darwin.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci(nix): use the default shell for binary builds
Remove the dev-shell input and its matrix and workflow plumbing.
Use the host default shell for builds and cache hashing.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci(nix): build release binaries with explicit Cargo targets
Use target-specific artifact paths and rely on the Nix toolchains for
linkage. Remove post-link rewriting, platform linkage checks, and the
unused interpreter input. Update the build architecture documentation.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* refactor(nix): reuse glibc and GCC build recipes
Use a pinned historical Nixpkgs recipe for glibc 2.28 and rebuild GCC 15
against it instead of maintaining separate runtime builds. Keep only
compatibility adjustments needed by the current build tools.
Assemble the sysroot from glibc outputs and static native libraries. Use
standard ELF interpreters and resolve Rust's explicit gcc_s dependency
through the static GCC archives.
Allow 90 minutes for Rust branch checks to accommodate cold toolchain
builds. Validate the Linux release matrix locally; Darwin remains for CI.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(nix): disable obsolete RPC tools in glibc
Avoid building rpcgen against the Darwin SDK, which does not expose stat64.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
---------
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-10 14:27:12 +00:00
Evan Lezar
90a4eb7941
test(test-guest): support rootful Podman gateways ( #3184 )
...
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-07 11:47:35 +00:00
Evan Lezar
b8903fdb2d
feat(test-guest): allow copy mode overrides ( #3091 )
...
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-03 13:30:32 +00:00
Evan Lezar
487b26574d
test(conformance): add plan-driven continuity verification ( #3107 )
...
* refactor(test-guest): compose Ansible provisioner roles
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(conformance): add plan-driven sandbox continuity
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(test-guest): add gateway continuity actions
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(test-guest): add RPM gateway reinstall action
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(test-guest): add RPM gateway upgrade action
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(test-guest): install latest-release RPM baseline
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(test-guest): add gateway upgrade-restart plan
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* ci(conformance): run Fedora gateway upgrade plan
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-03 12:05:59 +00:00
Simon Scatton
b92e9bda4f
ci: add Fedora conformance workflow ( #3086 )
...
* ci: add Fedora conformance workflow
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: enable KVM for Fedora conformance
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: run Fedora conformance with KVM
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: copy Fedora conformance script into guest
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: limit conformance VM setup to KVM
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: streamline Fedora conformance builds
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: use dev supervisor for Fedora conformance
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: pin Fedora RPM build image
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: cache RPM vendoring dependencies
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: clarify Fedora conformance job name
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: make conformance workflow manual only
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci(conformance): use new podman rootless install
* fix(ci): build gateway from renamed package
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
---------
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-02 13:06:32 +00:00
Evan Lezar
06f0aa6fe3
test(guest): consolidate rootless Podman provisioning ( #3125 )
...
* fix(test-guest): support Nix stat on macOS
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(guest): version Ubuntu test guest profiles
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(guest): consolidate rootless Podman provisioning
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-02 09:51:53 +00:00
Simon Scatton
883a1f01ce
fix(ci): preserve VM runtime embedding inputs ( #3040 )
...
Closes #3038
Compress platform runtime inputs in Nix and stage the complete bundle outside
Cargo's target directory. Reject missing or empty embedding artifacts during
the driver build.
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-08-31 16:03:00 +00:00
Simon Scatton
981606d2f8
ci: build release binaries with Nix ( #2977 )
...
* ci: build release binaries with Nix
Refs #1683
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: build VM artifacts with Nix
Refs #1683
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: build images from Nix artifacts
Refs #1683
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(nix): prevent host header leakage
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: parallelize artifact builds
Refs #1683
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: build external driver test artifacts
Refs #1683
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(nix): disable mold in musl shells
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: key Rust cache by Nix shell derivation
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: refactor end-to-end workflows
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: split platform binary workflows
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: remove obsolete native build workflows
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: replace disallowed mise action
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: fix refactored e2e lanes
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: check out local result action
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: cache mise installations
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: run docker builds on host runners
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* ci: disable unstable kubernetes e2e lanes
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(ci): scope binary builds to cargo packages
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(ci): address zizmor template injection findings
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(ci): resolve remaining zizmor annotations
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
---------
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-08-27 17:25:06 +00:00
Evan Lezar
ca61ee3744
feat(test-guest): add snap lifecycle reproduction harness ( #2865 )
...
* feat(test-guest): add snap lifecycle reproduction harness
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(test-guest): preserve cache seal executability
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-08-27 13:56:38 +00:00
Evan Lezar
e2ca9cb890
fix(test-guest): pin HVF runtime dependencies ( #2924 )
...
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-08-25 14:01:29 +00:00
Simon Scatton
905e99aa2a
feat(build): add Nix-native Linux toolchains ( #2875 )
...
* feat(nix): add glibc 2.28 development shell
* feat(nix): add musl development shell
* feat(build): use mold in musl development shell
* feat(flake): add nix remote cache
* feat(build): use mold in default development shell
2026-08-24 12:16:00 +00:00
Evan Lezar
de4c1fecf5
fix(test-guest): support RPM installs with DNF5 ( #2864 )
...
* fix(test-guest): support RPM installs with DNF5
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(test-guest): clarify RPM install arguments
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-08-21 14:40:47 +00:00
Evan Lezar and Drew Newberry
d220d89468
feat(compute): negotiate gateway callback listeners ( #2492 )
...
* feat(compute): query gateway listener requirements
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* feat(compute): add Podman listener requirements
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(docker): use default gateway bind address
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(gateway): avoid wildcard primary listener
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): validate callback listener discovery
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(server): support split dual-stack listeners
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): support legacy rootless listener discovery
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(e2e): accept loopback plaintext rejection
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* docs(agent): add callback listener diagnostics
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(server): restrict compute callback listeners
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): validate local callback port
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(server): clarify callback listener contract
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): require pasta for local callbacks
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* docs(gateway): document RPM listener default
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* refactor(server): keep listener provenance diagnostic-only
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(compute): preserve callback listener isolation
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): remove Podman callback relay
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(packaging): preserve Podman callback loopback
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): run VM smoke on nested-virt runner
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): gate VM smoke on usable KVM
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): probe KVM through VM driver
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): tolerate hosted KVM denial
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(server): close traced futures before assertions
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* revert: remove tracing test stabilization
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
Co-authored-by: Drew Newberry <anewberry@nvidia.com >
2026-07-31 16:41:06 +00:00
Drew Newberry
fe15caa89f
test(e2e): add VM-backed E2E suite runner ( #2473 )
...
* test(vm): add composable QEMU test guests
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* docs(vm): describe test VM directory structure
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(vm): replace shell catalog functions
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(vm): add Fedora release guest support
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(vm): enable rootless Podman socket
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): add OCI-backed image caching
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* perf(test-guest): accelerate cached guest startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): address review feedback
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): verify OCI cache provenance
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): harden cached guest reuse
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): refresh runtime setup state
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): support E2E runner inputs
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): harden runner and OCI reuse
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): prepare Podman E2E artifacts
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(e2e): add host and test VM runner
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): add VM-backed Podman shutdown suite
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): use renamed test guest app
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* chore(e2e): rename runner task
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): make guest smoke examples portable
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): remove Podman shutdown suite
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(e2e): use test guest Podman setup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(e2e): run Rust suites directly
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(e2e): simplify suite runner
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(e2e): isolate runner runtime state
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): prepare Podman VM runtime
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* perf(e2e): speed up cached guest startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* perf(e2e): streamline guest gateway startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
2026-07-29 21:50:44 -07:00
Drew Newberry
1cbfc0d510
test(e2e): add reusable QEMU infrastructure for E2E tests ( #2471 )
...
* test(vm): add composable QEMU test guests
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* docs(vm): describe test VM directory structure
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(vm): replace shell catalog functions
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(vm): add Fedora release guest support
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(vm): enable rootless Podman socket
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): add OCI-backed image caching
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* perf(test-guest): accelerate cached guest startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): address review feedback
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): verify OCI cache provenance
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): harden cached guest reuse
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): refresh runtime setup state
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): support E2E runner inputs
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): harden runner and OCI reuse
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): prepare Podman E2E artifacts
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): address review findings
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* revert(test-guest): remove recent Podman artifact changes
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(test-guest): canonicalize scp source paths
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(test-guest): provision artifacts with Ansible
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* feat(test-guest): populate missing caches on startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
2026-07-29 23:41:29 +00:00