Sync public tree to 9233b1e

This commit is contained in:
Michel Paulissen 2026-07-04 16:57:52 +02:00
parent 58e7fb9ebb
commit 9f76e3e70a
5 changed files with 77 additions and 21 deletions

View file

@ -1,7 +1,7 @@
{ {
"kind": "disasmer-filtered-public-tree", "kind": "disasmer-filtered-public-tree",
"source_commit": "17dcc0b92ebee00867a5d6521d214d3ed52b0ece", "source_commit": "9233b1eb4743de23a6837eb0108d08feb1231676",
"release_name": "dryrun-17dcc0b92ebe", "release_name": "dryrun-9233b1eb4743",
"filtered_out": [ "filtered_out": [
"private/**", "private/**",
"experiments/**", "experiments/**",

View file

@ -32,13 +32,15 @@ const publicBinaries = [
function commandOutput(command, args, options = {}) { function commandOutput(command, args, options = {}) {
try { try {
const execOptions = {
cwd: repo,
encoding: "utf8",
stdio: ["ignore", "pipe", "ignore"],
...options,
};
execOptions.env = commandEnv(command, options.env);
return cp return cp
.execFileSync(command, args, { .execFileSync(command, args, execOptions)
cwd: repo,
encoding: "utf8",
stdio: ["ignore", "pipe", "ignore"],
...options,
})
.trim(); .trim();
} catch (_) { } catch (_) {
return null; return null;
@ -46,11 +48,33 @@ function commandOutput(command, args, options = {}) {
} }
function run(command, args, options = {}) { function run(command, args, options = {}) {
cp.execFileSync(command, args, { const execOptions = {
cwd: repo, cwd: repo,
stdio: "inherit", stdio: "inherit",
...options, ...options,
}); };
execOptions.env = commandEnv(command, options.env);
cp.execFileSync(command, args, execOptions);
}
function nonInteractiveGitEnv(extra = {}) {
return {
...process.env,
GIT_TERMINAL_PROMPT: "0",
GIT_ASKPASS: process.env.GIT_ASKPASS || "/bin/false",
SSH_ASKPASS: process.env.SSH_ASKPASS || "/bin/false",
GIT_SSH_COMMAND:
process.env.GIT_SSH_COMMAND ||
"ssh -o BatchMode=yes -o NumberOfPasswordPrompts=0",
...extra,
};
}
function commandEnv(command, env) {
if (command !== "git") {
return env;
}
return nonInteractiveGitEnv(env);
} }
function ensureDir(dir) { function ensureDir(dir) {

View file

@ -146,7 +146,7 @@ for (const [name, pattern] of [
for (const [name, pattern] of [ for (const [name, pattern] of [
["preflight rejects stale release manifests", /manifest\.source_commit[\s\S]*currentSourceCommit/], ["preflight rejects stale release manifests", /manifest\.source_commit[\s\S]*currentSourceCommit/],
["preflight disables interactive remote prompts", /function nonInteractiveEnv[\s\S]*GIT_TERMINAL_PROMPT[\s\S]*GIT_ASKPASS[\s\S]*SSH_ASKPASS[\s\S]*git", \["ls-remote"[\s\S]*timeout/], ["preflight disables interactive remote prompts", /function nonInteractiveEnv[\s\S]*GIT_TERMINAL_PROMPT[\s\S]*GIT_ASKPASS[\s\S]*SSH_ASKPASS[\s\S]*GIT_SSH_COMMAND[\s\S]*BatchMode=yes[\s\S]*NumberOfPasswordPrompts=0[\s\S]*git", \["ls-remote"[\s\S]*timeout/],
["preflight accepts external public tree push", /function publicTreeAlreadyPushed\(manifest\)[\s\S]*DISASMER_PUBLIC_TREE_ALREADY_PUSHED/], ["preflight accepts external public tree push", /function publicTreeAlreadyPushed\(manifest\)[\s\S]*DISASMER_PUBLIC_TREE_ALREADY_PUSHED/],
["preflight verifies public branch commit", /remoteMain[\s\S]*publicTreeCommit/], ["preflight verifies public branch commit", /remoteMain[\s\S]*publicTreeCommit/],
["preflight verifies local asset checksums", /parseSha256Sums[\s\S]*checksum mismatch/], ["preflight verifies local asset checksums", /parseSha256Sums[\s\S]*checksum mismatch/],
@ -160,6 +160,7 @@ for (const [name, pattern] of [
for (const [name, pattern] of [ for (const [name, pattern] of [
["e2e runner requires explicit opt-in", /DISASMER_PUBLIC_RELEASE_DRYRUN_E2E=1/], ["e2e runner requires explicit opt-in", /DISASMER_PUBLIC_RELEASE_DRYRUN_E2E=1/],
["e2e runner rejects stale release manifests", /manifest\.source_commit[\s\S]*expectedSourceCommit\(\)/], ["e2e runner rejects stale release manifests", /manifest\.source_commit[\s\S]*expectedSourceCommit\(\)/],
["e2e runner disables interactive git prompts", /function nonInteractiveGitEnv[\s\S]*GIT_TERMINAL_PROMPT[\s\S]*GIT_ASKPASS[\s\S]*SSH_ASKPASS[\s\S]*GIT_SSH_COMMAND[\s\S]*BatchMode=yes[\s\S]*NumberOfPasswordPrompts=0[\s\S]*function commandEnv/],
["e2e runner accepts external public tree push", /function publicTreeAlreadyPushed\(manifest\)[\s\S]*DISASMER_PUBLIC_TREE_ALREADY_PUSHED/], ["e2e runner accepts external public tree push", /function publicTreeAlreadyPushed\(manifest\)[\s\S]*DISASMER_PUBLIC_TREE_ALREADY_PUSHED/],
["e2e runner downloads Forgejo Release assets", /downloadReleaseAssets/], ["e2e runner downloads Forgejo Release assets", /downloadReleaseAssets/],
["e2e runner verifies SHA256SUMS", /verifyChecksums/], ["e2e runner verifies SHA256SUMS", /verifyChecksums/],
@ -237,6 +238,12 @@ if (workflow) {
} }
} }
expect(
prepScript,
"public tree prep disables interactive git prompts",
/function nonInteractiveGitEnv[\s\S]*GIT_TERMINAL_PROMPT[\s\S]*GIT_ASKPASS[\s\S]*SSH_ASKPASS[\s\S]*GIT_SSH_COMMAND[\s\S]*BatchMode=yes[\s\S]*NumberOfPasswordPrompts=0[\s\S]*function commandEnv/
);
for (const [scriptName, script] of [ for (const [scriptName, script] of [
["public acceptance", publicAcceptance], ["public acceptance", publicAcceptance],
["public split", publicSplit], ["public split", publicSplit],

View file

@ -64,13 +64,15 @@ function ensureDir(dir) {
function run(command, args, options = {}) { function run(command, args, options = {}) {
const commandLine = [command, ...args].join(" "); const commandLine = [command, ...args].join(" ");
commands.push(commandLine); commands.push(commandLine);
return cp.execFileSync(command, args, { const execOptions = {
cwd: repo, cwd: repo,
encoding: "utf8", encoding: "utf8",
stdio: ["ignore", "pipe", "pipe"], stdio: ["ignore", "pipe", "pipe"],
timeout: 15 * 60 * 1000, timeout: 15 * 60 * 1000,
...options, ...options,
}); };
execOptions.env = commandEnv(command, options.env);
return cp.execFileSync(command, args, execOptions);
} }
function runJson(command, args, options = {}) { function runJson(command, args, options = {}) {
@ -89,19 +91,39 @@ function runJson(command, args, options = {}) {
function commandOutput(command, args, options = {}) { function commandOutput(command, args, options = {}) {
try { try {
return cp const execOptions = {
.execFileSync(command, args, { cwd: repo,
cwd: repo, encoding: "utf8",
encoding: "utf8", stdio: ["ignore", "pipe", "ignore"],
stdio: ["ignore", "pipe", "ignore"], ...options,
...options, };
}) execOptions.env = commandEnv(command, options.env);
.trim(); return cp.execFileSync(command, args, execOptions).trim();
} catch (_) { } catch (_) {
return null; return null;
} }
} }
function nonInteractiveGitEnv(extra = {}) {
return {
...process.env,
GIT_TERMINAL_PROMPT: "0",
GIT_ASKPASS: process.env.GIT_ASKPASS || "/bin/false",
SSH_ASKPASS: process.env.SSH_ASKPASS || "/bin/false",
GIT_SSH_COMMAND:
process.env.GIT_SSH_COMMAND ||
"ssh -o BatchMode=yes -o NumberOfPasswordPrompts=0",
...extra,
};
}
function commandEnv(command, env) {
if (command !== "git") {
return env;
}
return nonInteractiveGitEnv(env);
}
function expectedSourceCommit() { function expectedSourceCommit() {
return ( return (
process.env.DISASMER_ACCEPTANCE_COMMIT || process.env.DISASMER_ACCEPTANCE_COMMIT ||

View file

@ -40,6 +40,9 @@ function nonInteractiveEnv(extra = {}) {
GIT_TERMINAL_PROMPT: "0", GIT_TERMINAL_PROMPT: "0",
GIT_ASKPASS: process.env.GIT_ASKPASS || "/bin/false", GIT_ASKPASS: process.env.GIT_ASKPASS || "/bin/false",
SSH_ASKPASS: process.env.SSH_ASKPASS || "/bin/false", SSH_ASKPASS: process.env.SSH_ASKPASS || "/bin/false",
GIT_SSH_COMMAND:
process.env.GIT_SSH_COMMAND ||
"ssh -o BatchMode=yes -o NumberOfPasswordPrompts=0",
...extra, ...extra,
}; };
} }