From: Sascha Hauer <s.hauer@pengutronix.de>
To: Barebox List <barebox@lists.infradead.org>
Subject: [PATCH] test: check-security-policies: mark the source tree safe for git
Date: Wed, 23 Sep 2026 09:30:00 +0200 [thread overview]
Message-ID: <20260923073000.4124447-1-s.hauer@pengutronix.de> (raw)
The labgrid-pytest job runs the container as root, while the checkout
belongs to the user of the GitHub runner. git refuses a repository owned
by someone else, and the final
git diff --exit-code -- '*.sconfig'
then never compares anything. Instead of failing with the ownership
error, git diff treats the tree as no repository at all, falls back to
--no-index and exits 129 with its usage message, which fails the job:
Check security policy configurator
Process completed with exit code 129.
Pass safe.directory on the command line, where it still counts as
protected configuration, and check up front that we are in a work tree
at all, so a future breakage of the repository lookup is reported
instead of being mistaken for modified policies.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>
---
test/check-security-policies.sh | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
diff --git a/test/check-security-policies.sh b/test/check-security-policies.sh
index 09b5301590..946a1ccdde 100755
--- a/test/check-security-policies.sh
+++ b/test/check-security-policies.sh
@@ -71,5 +71,18 @@ for O in "" "$builddir"; do
make O="$O" mrproper
done
+# The CI container runs as root, while the checkout belongs to the user
+# the runner uses, so git refuses the repository over its ownership. git
+# diff doesn't fail loudly in that case: it falls back to --no-index and
+# exits 129 with a usage message instead of comparing anything.
+srctree_git() {
+ git -c safe.directory="$PWD" "$@"
+}
+
+if ! srctree_git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+ echo >&2 "$0: not a git work tree, cannot look for modified policies"
+ exit 1
+fi
+
# Catches security_oldconfig rewriting a committed policy.
-git diff --exit-code -- '*.sconfig'
+srctree_git diff --exit-code -- '*.sconfig'
--
2.47.3
next reply other threads:[~2026-09-23 7:31 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 7:30 Sascha Hauer [this message]
2026-09-23 8:17 ` Ahmad Fatoum
2026-09-24 7:41 ` Sascha Hauer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923073000.4124447-1-s.hauer@pengutronix.de \
--to=s.hauer@pengutronix.de \
--cc=barebox@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox