Two checks proved a good --version got through validation by asserting the
NEXT gate down, 'must run as root'. That gate only exists for a non-root
caller. The Forgejo runner runs job containers as uid 0 — GitHub's runner is
the unprivileged 'runner' user — so on this forge both checks failed, and
'ci / check' stayed red after the shellcheck cause was fixed. #136's class,
in a place its sweep did not reach.
Both gates are equally good evidence that validation is behind us, so accept
either, and keep requiring exit 1 so a validation refusal (exit 2) still
fails the check.
Refs #144
rig's own `ci / check` failed 9 times out of 27 ci.yml tasks on the first
Forgejo runner, every one on `shellcheck: command not found`. `ubuntu-latest`
maps to catthehacker's SLIM act image, and workflows written for GitHub
reasonably assume GitHub's tool surface.
Measured before choosing (2026-08-01, streaming ghcr layer blobs rather than
pulling): the parity image is 18.67 GB on the wire and 54.52 GB extracted,
against a box-class ci tenant with ~34-40 GB free. There is no cheap middle —
runner-22.04 is the same slim class, tool for tool, and ships no shellcheck
either. `apt-get install -y shellcheck` costs 7s and yields the same
ShellCheck 0.8.0 that full-22.04 carries.
So the slim default stays and the workflow equips itself. The `command -v`
short-circuit keeps either forge from paying for the other; the sudo is a
no-op on the act path and load-bearing on GitHub's.
`ubuntu-latest-full` ships in the default map beside it: a mapping pulls
nothing until a job matches it, and Forgejo freezes labels at registration,
so a label absent then cannot be added without re-registering.
A plain converge now warns when a runner carries a SUPERSEDED default —
matched against the exact strings rig has shipped, so a map the operator
chose stays silent. The message says plainly that nothing is broken.
Refs #144