diff --git a/deny.toml b/deny.toml index f50351d0..444c1952 100644 --- a/deny.toml +++ b/deny.toml @@ -73,6 +73,9 @@ ignore = [ { id = "RUSTSEC-2024-0436", reason = "paste is a transitive dep of wgpu→metal; no alternative available upstream" }, { id = "RUSTSEC-2025-0141", reason = "bincode 1.3.3 is considered complete by its authors; used for scene serialization" }, { id = "RUSTSEC-2026-0049", reason = "rustls-webpki CRL matching issue; limited impact, requires compromised CA; transitive dep of rustls via tungstenite" }, + { id = "RUSTSEC-2026-0097", reason = "rand unsoundness only triggers when a custom global logger calls rand::rng(); engine does not set one" }, + { id = "RUSTSEC-2026-0098", reason = "rustls-webpki URI-name constraint issue; transitive via tungstenite; mitigated upstream path" }, + { id = "RUSTSEC-2026-0099", reason = "rustls-webpki wildcard name-constraint issue; same transitive path as 2026-0098" }, { crate = "core2@0.4.0", reason = "yanked upstream; transitive via image→ravif→rav1e→bitstream-io. No replacement version published." }, ] # If this is true, then cargo deny will use the git executable to fetch advisory database. diff --git a/scripts/codex-setup.sh b/scripts/codex-setup.sh new file mode 100755 index 00000000..f581dd6d --- /dev/null +++ b/scripts/codex-setup.sh @@ -0,0 +1,115 @@ +#!/usr/bin/env bash +# Codex Cloud environment setup for GoudEngine. +# +# Runs once during the Codex "setup" phase (internet is available) on the +# codex-universal base image (Ubuntu 24.04, root user). Installs everything +# the CI lanes need so the agent phase can build, test, and run codegen +# without network access. +# +# This script is the single source of truth: edit it here, not in the Codex +# UI. The Codex environment just invokes `bash scripts/codex-setup.sh`. + +set -euo pipefail + +log() { printf '\n\033[1;34m▶ %s\033[0m\n' "$*"; } + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +REPO_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)" +cd "$REPO_ROOT" + +# --- System packages (graphics, audio, build tooling) ----------------------- +# Pulled from .github/workflows/ci.yml — keep in sync with Ubuntu CI lanes. +log "Installing apt packages" +export DEBIAN_FRONTEND=noninteractive +apt-get update -y +apt-get install -y --no-install-recommends \ + cmake \ + pkg-config \ + libgl1-mesa-dev libglu1-mesa-dev \ + libxrandr-dev libxinerama-dev libxcursor-dev libxi-dev libxxf86vm-dev \ + libxkbcommon-x11-dev \ + libasound2-dev libudev-dev \ + libvulkan-dev mesa-vulkan-drivers \ + lua5.4 liblua5.4-dev \ + xvfb \ + ca-certificates wget gnupg + +# --- .NET 8 SDK (not pre-installed in codex-universal) ---------------------- +if ! command -v dotnet >/dev/null 2>&1; then + log "Installing .NET 8 SDK" + # shellcheck disable=SC1091 + . /etc/os-release + wget -qO /tmp/packages-microsoft-prod.deb \ + "https://packages.microsoft.com/config/ubuntu/${VERSION_ID}/packages-microsoft-prod.deb" + dpkg -i /tmp/packages-microsoft-prod.deb + apt-get update -y + apt-get install -y dotnet-sdk-8.0 + rm -f /tmp/packages-microsoft-prod.deb +fi + +# --- Rust toolchain --------------------------------------------------------- +# codex-universal ships rustup + multiple pinned versions. Pin the working +# toolchain via CODEX_ENV_RUST_VERSION in the environment settings; this +# block just ensures components/targets we need are present. +if ! command -v rustup >/dev/null 2>&1; then + log "Installing rustup" + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \ + | sh -s -- -y --default-toolchain stable --profile minimal + # shellcheck disable=SC1091 + . "$HOME/.cargo/env" +fi +export PATH="$HOME/.cargo/bin:$PATH" +rustup component add rustfmt clippy +rustup target add wasm32-unknown-unknown + +# --- wasm-pack (pinned to CI version) --------------------------------------- +WASM_PACK_VERSION="0.13.1" +if ! command -v wasm-pack >/dev/null 2>&1 \ + || [[ "$(wasm-pack --version 2>/dev/null || true)" != *"${WASM_PACK_VERSION}"* ]]; then + log "Installing wasm-pack ${WASM_PACK_VERSION}" + curl -sSfL \ + "https://github.com/rustwasm/wasm-pack/releases/download/v${WASM_PACK_VERSION}/wasm-pack-v${WASM_PACK_VERSION}-x86_64-unknown-linux-musl.tar.gz" \ + -o /tmp/wasm-pack.tar.gz + tar -xzf /tmp/wasm-pack.tar.gz -C /tmp + install "/tmp/wasm-pack-v${WASM_PACK_VERSION}-x86_64-unknown-linux-musl/wasm-pack" \ + /usr/local/bin/wasm-pack + rm -rf /tmp/wasm-pack* +fi + +# --- Python tooling --------------------------------------------------------- +log "Priming Python tooling" +python3 -m pip install --quiet --upgrade pip + +# --- Node dependencies for TypeScript SDK ----------------------------------- +if [[ -f sdks/typescript/package-lock.json ]]; then + log "Installing TypeScript SDK npm deps" + (cd sdks/typescript && npm ci --no-audit --no-fund) +fi + +# --- Environment variables that must persist into the agent phase ----------- +# Setup-phase `export`s do NOT carry into the agent shell — write them to +# ~/.bashrc so they're available when the agent runs. +BASHRC_MARKER="# >>> goudengine codex env >>>" +BASHRC_END_MARKER="# <<< goudengine codex env <<<" +if ! grep -qF "$BASHRC_MARKER" "$HOME/.bashrc" 2>/dev/null; then + log "Persisting env vars into ~/.bashrc" + cat >> "$HOME/.bashrc" <