mirror of
https://github.com/rustfs/rustfs.git
synced 2026-10-04 12:31:36 +00:00
fix(ci): run security chain evidence from the lane's own checkout (#8229)
The security workflow checks the repository out into rustfs-repo/ (#7212) but its chain evidence steps still invoke scripts/functional_chain_evidence.py relative to the workspace root, which on the persistent shared runner resolves to a stale checkout left by another job. The evidence gate then compares that checkout's HEAD against the chain workflow_sha and rejects the lane before any case runs ("lane checkout differs from chain workflow source"). Run the evidence script from the lane's own checkout so ROOT resolves to rustfs-repo/, whose HEAD is exactly the chain-pinned workflow_sha.
This commit is contained in:
@@ -106,7 +106,7 @@ jobs:
|
||||
if: ${{ inputs.chain_manifest != '' }}
|
||||
env:
|
||||
CHAIN_MANIFEST: ${{ inputs.chain_manifest }}
|
||||
run: python3 scripts/functional_chain_evidence.py consume
|
||||
run: python3 rustfs-repo/scripts/functional_chain_evidence.py consume
|
||||
|
||||
- name: Checkout auto-testing scripts
|
||||
uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7
|
||||
@@ -389,7 +389,7 @@ jobs:
|
||||
CHAIN_TEST_OUTCOME: ${{ steps.test.outcome }}
|
||||
CHAIN_REPORT_OUTCOME: ${{ steps.report.outcome }}
|
||||
run: >-
|
||||
python3 scripts/functional_chain_evidence.py record --suite security
|
||||
python3 rustfs-repo/scripts/functional_chain_evidence.py record --suite security
|
||||
--report "${SECURITY_ARTIFACTS_DIR}/suite-report.md"
|
||||
--output "${RUNNER_TEMP}/chain-security-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}/security.json"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user