From dcf36a221085d08245aac5ff05c2f0dcfd685895 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Tue, 29 Sep 2026 09:15:12 +0000 Subject: [PATCH] test(git): select the rejection fixture hook explicitly Ambient core.hooksPath can bypass the update hook that rejection tests install. Select the repository's hooks directory locally so those tests exercise actual rejected pushes even under hostile global configuration. Assume repository-local configuration overrides global hooksPath. Production hook policy and push authorization are intentionally unchanged. Validation: nix develop -c env GIT_CONFIG_GLOBAL= cargo test --test git_push_promotion_race passed all ten tests with hooksPath=/dev/null. Assisted-by: GPT-6 --- tests/git_push_promotion_race.rs | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tests/git_push_promotion_race.rs b/tests/git_push_promotion_race.rs index 13c497e..10c3d1f 100644 --- a/tests/git_push_promotion_race.rs +++ b/tests/git_push_promotion_race.rs @@ -279,6 +279,9 @@ async fn mixed_deletion_push(atomic: bool, reject_branch: bool, include_deletion let bad = oid.clone(); if reject_branch { use std::os::unix::fs::PermissionsExt; + // The server inherits ambient Git config, including CI's hostile + // hooksPath. Explicitly select this fixture's intentional rejection hook. + git(&repo, &["config", "--local", "core.hooksPath", "hooks"]); let hook = repo.join("hooks/update"); std::fs::write(&hook, b"#!/bin/sh\n[ \"$1\" != refs/heads/unavailable ]\n").unwrap(); std::fs::set_permissions(hook, std::fs::Permissions::from_mode(0o755)).unwrap();