From a8964bbee83388050cf8d444a08af4ebd1e8a178 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Sat, 1 Aug 2026 16:21:10 +0000 Subject: [PATCH] ci: run test suite under a hostile git configuration The hostile-config run that validated the init.defaultBranch=main fix was manual, so nothing stopped the next ambient-config assumption from landing silently. Install a deliberately hostile global gitconfig (init.defaultBranch=main, a failing pre-commit hook delivered through both core.hooksPath and init.templateDir, commit.gpgsign=true, core.autocrlf=true) before the test steps, so every CI run exercises it at no extra cost. The suite runs once, under the hostile config only: the hermetic git helpers make the tests config-blind, so a green hostile run implies the unset-config case as well (additionally verified by the grasp-audit regression unit test, which proves neutralisation against this same config in-process). The hostile settings reach only test-side git: the relay under test never runs `git commit`, so hooks and gpgsign cannot fire server-side, while init.defaultBranch deliberately does affect the relay's bare-repo HEAD - the exact regression this guards. Validated locally by running the full workspace suite with the global config masked and the git-heavy subset under this hostile config. --- .ngit/act/workflows/rust_ci.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/.ngit/act/workflows/rust_ci.yaml b/.ngit/act/workflows/rust_ci.yaml index 0e2c021..8ac6b0e 100644 --- a/.ngit/act/workflows/rust_ci.yaml +++ b/.ngit/act/workflows/rust_ci.yaml @@ -11,6 +11,26 @@ jobs: - uses: cachix/install-nix-action@v31 with: nix_path: nixpkgs=channel:nixos-unstable + # The suite must be hermetic with respect to ambient git configuration, + # so CI always runs it under a deliberately hostile global config: a + # failing pre-commit hook delivered via both core.hooksPath and + # init.templateDir, plus the settings that have bitten before. The + # settings target test-side git only: the relay never runs `git commit`, + # so its server-side operations are unaffected except for + # init.defaultBranch, which is exactly the regression being guarded. + # (The hermetic helpers make the tests themselves config-blind, so this + # single run also covers hosts where these settings are unset.) + - name: Install hostile git configuration + run: | + mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks + printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \ + | tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit + chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit + git config --global init.defaultBranch main + git config --global core.hooksPath /tmp/hostile-git/hooks + git config --global init.templateDir /tmp/hostile-git/template + git config --global commit.gpgsign true + git config --global core.autocrlf true - run: nix develop --command cargo fmt --all -- --check - run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings - run: nix develop --command cargo test --locked