ci: run test suite under a hostile git configuration

The hostile-config run that validated the init.defaultBranch=main fix
was manual, so nothing stopped the next ambient-config assumption from
landing silently. Install a deliberately hostile global gitconfig
(init.defaultBranch=main, a failing pre-commit hook delivered through
both core.hooksPath and init.templateDir, commit.gpgsign=true,
core.autocrlf=true) before the test steps, so every CI run exercises
it at no extra cost.

The suite runs once, under the hostile config only: the hermetic git
helpers make the tests config-blind, so a green hostile run implies
the unset-config case as well (additionally verified by the
grasp-audit regression unit test, which proves neutralisation against
this same config in-process). The hostile settings reach only
test-side git: the relay under test never runs `git commit`, so hooks
and gpgsign cannot fire server-side, while init.defaultBranch
deliberately does affect the relay's bare-repo HEAD - the exact
regression this guards.

Validated locally by running the full workspace suite with the global
config masked and the git-heavy subset under this hostile config.
This commit is contained in:
DanConwayDev
2026-08-01 16:28:34 +00:00
parent 8722ab6641
commit a8964bbee8
+20
View File
@@ -11,6 +11,26 @@ jobs:
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
# The suite must be hermetic with respect to ambient git configuration,
# so CI always runs it under a deliberately hostile global config: a
# failing pre-commit hook delivered via both core.hooksPath and
# init.templateDir, plus the settings that have bitten before. The
# settings target test-side git only: the relay never runs `git commit`,
# so its server-side operations are unaffected except for
# init.defaultBranch, which is exactly the regression being guarded.
# (The hermetic helpers make the tests themselves config-blind, so this
# single run also covers hosts where these settings are unset.)
- name: Install hostile git configuration
run: |
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
git config --global init.defaultBranch main
git config --global core.hooksPath /tmp/hostile-git/hooks
git config --global init.templateDir /tmp/hostile-git/template
git config --global commit.gpgsign true
git config --global core.autocrlf true
- run: nix develop --command cargo fmt --all -- --check
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
- run: nix develop --command cargo test --locked