mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH] test: check-security-policies: mark the source tree safe for git
@ 2026-09-23  7:30 Sascha Hauer
  2026-09-23  8:17 ` Ahmad Fatoum
  2026-09-24  7:41 ` Sascha Hauer
  0 siblings, 2 replies; 3+ messages in thread
From: Sascha Hauer @ 2026-09-23  7:30 UTC (permalink / raw)
  To: Barebox List

The labgrid-pytest job runs the container as root, while the checkout
belongs to the user of the GitHub runner. git refuses a repository owned
by someone else, and the final

	git diff --exit-code -- '*.sconfig'

then never compares anything. Instead of failing with the ownership
error, git diff treats the tree as no repository at all, falls back to
--no-index and exits 129 with its usage message, which fails the job:

	Check security policy configurator
	Process completed with exit code 129.

Pass safe.directory on the command line, where it still counts as
protected configuration, and check up front that we are in a work tree
at all, so a future breakage of the repository lookup is reported
instead of being mistaken for modified policies.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>
---
 test/check-security-policies.sh | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/test/check-security-policies.sh b/test/check-security-policies.sh
index 09b5301590..946a1ccdde 100755
--- a/test/check-security-policies.sh
+++ b/test/check-security-policies.sh
@@ -71,5 +71,18 @@ for O in "" "$builddir"; do
 	make O="$O" mrproper
 done
 
+# The CI container runs as root, while the checkout belongs to the user
+# the runner uses, so git refuses the repository over its ownership. git
+# diff doesn't fail loudly in that case: it falls back to --no-index and
+# exits 129 with a usage message instead of comparing anything.
+srctree_git() {
+	git -c safe.directory="$PWD" "$@"
+}
+
+if ! srctree_git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+	echo >&2 "$0: not a git work tree, cannot look for modified policies"
+	exit 1
+fi
+
 # Catches security_oldconfig rewriting a committed policy.
-git diff --exit-code -- '*.sconfig'
+srctree_git diff --exit-code -- '*.sconfig'
-- 
2.47.3




^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] test: check-security-policies: mark the source tree safe for git
  2026-09-23  7:30 [PATCH] test: check-security-policies: mark the source tree safe for git Sascha Hauer
@ 2026-09-23  8:17 ` Ahmad Fatoum
  2026-09-24  7:41 ` Sascha Hauer
  1 sibling, 0 replies; 3+ messages in thread
From: Ahmad Fatoum @ 2026-09-23  8:17 UTC (permalink / raw)
  To: Sascha Hauer, Barebox List



On 9/23/26 9:30 AM, Sascha Hauer wrote:
> The labgrid-pytest job runs the container as root, while the checkout
> belongs to the user of the GitHub runner. git refuses a repository owned
> by someone else, and the final
> 
> 	git diff --exit-code -- '*.sconfig'
> 
> then never compares anything. Instead of failing with the ownership
> error, git diff treats the tree as no repository at all, falls back to
> --no-index and exits 129 with its usage message, which fails the job:
> 
> 	Check security policy configurator
> 	Process completed with exit code 129.
> 
> Pass safe.directory on the command line, where it still counts as
> protected configuration, and check up front that we are in a work tree
> at all, so a future breakage of the repository lookup is reported
> instead of being mistaken for modified policies.
> 
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>

Acked-by: Ahmad Fatoum <a.fatoum@pengutronix.de>

> ---
>  test/check-security-policies.sh | 15 ++++++++++++++-
>  1 file changed, 14 insertions(+), 1 deletion(-)
> 
> diff --git a/test/check-security-policies.sh b/test/check-security-policies.sh
> index 09b5301590..946a1ccdde 100755
> --- a/test/check-security-policies.sh
> +++ b/test/check-security-policies.sh
> @@ -71,5 +71,18 @@ for O in "" "$builddir"; do
>  	make O="$O" mrproper
>  done
>  
> +# The CI container runs as root, while the checkout belongs to the user
> +# the runner uses, so git refuses the repository over its ownership. git
> +# diff doesn't fail loudly in that case: it falls back to --no-index and
> +# exits 129 with a usage message instead of comparing anything.
> +srctree_git() {
> +	git -c safe.directory="$PWD" "$@"
> +}
> +
> +if ! srctree_git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
> +	echo >&2 "$0: not a git work tree, cannot look for modified policies"
> +	exit 1
> +fi
> +
>  # Catches security_oldconfig rewriting a committed policy.
> -git diff --exit-code -- '*.sconfig'
> +srctree_git diff --exit-code -- '*.sconfig'

-- 
Pengutronix e.K.                  |                             |
Steuerwalder Str. 21              | http://www.pengutronix.de/  |
31137 Hildesheim, Germany         | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686  | Fax:   +49-5121-206917-5555 |




^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] test: check-security-policies: mark the source tree safe for git
  2026-09-23  7:30 [PATCH] test: check-security-policies: mark the source tree safe for git Sascha Hauer
  2026-09-23  8:17 ` Ahmad Fatoum
@ 2026-09-24  7:41 ` Sascha Hauer
  1 sibling, 0 replies; 3+ messages in thread
From: Sascha Hauer @ 2026-09-24  7:41 UTC (permalink / raw)
  To: Barebox List, Sascha Hauer


On Wed, 23 Sep 2026 09:30:00 +0200, Sascha Hauer wrote:
> The labgrid-pytest job runs the container as root, while the checkout
> belongs to the user of the GitHub runner. git refuses a repository owned
> by someone else, and the final
> 
> 	git diff --exit-code -- '*.sconfig'
> 
> then never compares anything. Instead of failing with the ownership
> error, git diff treats the tree as no repository at all, falls back to
> --no-index and exits 129 with its usage message, which fails the job:
> 
> [...]

Applied, thanks!

[1/1] test: check-security-policies: mark the source tree safe for git
      https://git.pengutronix.de/cgit/barebox/commit/?id=0734b8afb94f (link may not be stable)

Best regards,
-- 
Sascha Hauer <s.hauer@pengutronix.de>




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-24  7:41 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23  7:30 [PATCH] test: check-security-policies: mark the source tree safe for git Sascha Hauer
2026-09-23  8:17 ` Ahmad Fatoum
2026-09-24  7:41 ` Sascha Hauer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox