mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
test(git): select the rejection fixture hook explicitly
Ambient core.hooksPath can bypass the update hook that rejection tests install. Select the repository's hooks directory locally so those tests exercise actual rejected pushes even under hostile global configuration. Assume repository-local configuration overrides global hooksPath. Production hook policy and push authorization are intentionally unchanged. Validation: nix develop -c env GIT_CONFIG_GLOBAL=<hostile fixture> cargo test --test git_push_promotion_race passed all ten tests with hooksPath=/dev/null. Assisted-by: GPT-6
This commit is contained in:
@@ -279,6 +279,9 @@ async fn mixed_deletion_push(atomic: bool, reject_branch: bool, include_deletion
|
||||
let bad = oid.clone();
|
||||
if reject_branch {
|
||||
use std::os::unix::fs::PermissionsExt;
|
||||
// The server inherits ambient Git config, including CI's hostile
|
||||
// hooksPath. Explicitly select this fixture's intentional rejection hook.
|
||||
git(&repo, &["config", "--local", "core.hooksPath", "hooks"]);
|
||||
let hook = repo.join("hooks/update");
|
||||
std::fs::write(&hook, b"#!/bin/sh\n[ \"$1\" != refs/heads/unavailable ]\n").unwrap();
|
||||
std::fs::set_permissions(hook, std::fs::Permissions::from_mode(0o755)).unwrap();
|
||||
|
||||
Reference in New Issue
Block a user