test(git): select the rejection fixture hook explicitly

Ambient core.hooksPath can bypass the update hook that rejection tests
install. Select the repository's hooks directory locally so those tests
exercise actual rejected pushes even under hostile global configuration.

Assume repository-local configuration overrides global hooksPath. Production
hook policy and push authorization are intentionally unchanged.

Validation: nix develop -c env GIT_CONFIG_GLOBAL=<hostile fixture> cargo test
--test git_push_promotion_race passed all ten tests with hooksPath=/dev/null.

Assisted-by: GPT-6
This commit is contained in:
DanConwayDev
2026-09-29 09:15:12 +00:00
parent 0edc7b834e
commit dcf36a2210
+3
View File
@@ -279,6 +279,9 @@ async fn mixed_deletion_push(atomic: bool, reject_branch: bool, include_deletion
let bad = oid.clone(); let bad = oid.clone();
if reject_branch { if reject_branch {
use std::os::unix::fs::PermissionsExt; use std::os::unix::fs::PermissionsExt;
// The server inherits ambient Git config, including CI's hostile
// hooksPath. Explicitly select this fixture's intentional rejection hook.
git(&repo, &["config", "--local", "core.hooksPath", "hooks"]);
let hook = repo.join("hooks/update"); let hook = repo.join("hooks/update");
std::fs::write(&hook, b"#!/bin/sh\n[ \"$1\" != refs/heads/unavailable ]\n").unwrap(); std::fs::write(&hook, b"#!/bin/sh\n[ \"$1\" != refs/heads/unavailable ]\n").unwrap();
std::fs::set_permissions(hook, std::fs::Permissions::from_mode(0o755)).unwrap(); std::fs::set_permissions(hook, std::fs::Permissions::from_mode(0o755)).unwrap();