mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
The hostile-config run that validated the init.defaultBranch=main fix was manual, so nothing stopped the next ambient-config assumption from landing silently. Install a deliberately hostile global gitconfig (init.defaultBranch=main, a failing pre-commit hook delivered through both core.hooksPath and init.templateDir, commit.gpgsign=true, core.autocrlf=true) before the test steps, so every CI run exercises it at no extra cost. The suite runs once, under the hostile config only: the hermetic git helpers make the tests config-blind, so a green hostile run implies the unset-config case as well (additionally verified by the grasp-audit regression unit test, which proves neutralisation against this same config in-process). The hostile settings reach only test-side git: the relay under test never runs `git commit`, so hooks and gpgsign cannot fire server-side, while init.defaultBranch deliberately does affect the relay's bare-repo HEAD - the exact regression this guards. Validated locally by running the full workspace suite with the global config masked and the git-heavy subset under this hostile config.
38 lines
1.9 KiB
YAML
38 lines
1.9 KiB
YAML
on: push
|
|
|
|
name: Rust CI
|
|
|
|
jobs:
|
|
ci:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- uses: cachix/install-nix-action@v31
|
|
with:
|
|
nix_path: nixpkgs=channel:nixos-unstable
|
|
# The suite must be hermetic with respect to ambient git configuration,
|
|
# so CI always runs it under a deliberately hostile global config: a
|
|
# failing pre-commit hook delivered via both core.hooksPath and
|
|
# init.templateDir, plus the settings that have bitten before. The
|
|
# settings target test-side git only: the relay never runs `git commit`,
|
|
# so its server-side operations are unaffected except for
|
|
# init.defaultBranch, which is exactly the regression being guarded.
|
|
# (The hermetic helpers make the tests themselves config-blind, so this
|
|
# single run also covers hosts where these settings are unset.)
|
|
- name: Install hostile git configuration
|
|
run: |
|
|
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
|
|
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
|
|
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
|
|
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
|
|
git config --global init.defaultBranch main
|
|
git config --global core.hooksPath /tmp/hostile-git/hooks
|
|
git config --global init.templateDir /tmp/hostile-git/template
|
|
git config --global commit.gpgsign true
|
|
git config --global core.autocrlf true
|
|
- run: nix develop --command cargo fmt --all -- --check
|
|
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
|
|
- run: nix develop --command cargo test --locked
|
|
- run: nix develop --command cargo test -p grasp-audit --locked
|