mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
CI runs the suite under a deliberately hostile global git configuration
and inside an act container whose PID 1 does not reap orphans. Seven
lib tests relied on a friendly environment and failed there:
Five tests built git fixtures with bare Command::new("git"), so the
hostile failing pre-commit hook (core.hooksPath) broke fixture commits;
most fixture steps also ignored exit status, so the tests failed later
at an unrelated assertion. Fixtures now go through
grasp_audit::git_command(), which masks user and system git config, and
every step asserts success with stderr in the failure message. The
now-redundant local gpgsign toggles are dropped: hermetic fixtures see
no signing config at all.
Two process-group tests probed descendant death with kill(pid, 0),
which still succeeds for an unreaped zombie. The group kill orphans the
descendant, and without a reaping ancestor it stays a zombie forever,
so the probes timed out. The probe now reads /proc/<pid>/stat and also
treats state Z as terminated; the group-kill behaviour under test is
unchanged.
Both failure modes were reproduced locally with the workflow's hostile
git config (via GIT_CONFIG_GLOBAL) and a non-reaping
PR_SET_CHILD_SUBREAPER wrapper, matching the CI panics exactly; with
these changes the seven tests pass under both conditions, and cargo
fmt, clippy -D warnings, the full workspace suite, and the grasp-audit
suite pass. Four tests/sync.rs timing flakes seen under full parallel
local load pass in isolation and predate this change; they are out of
scope.