From 0e58bd09d02af2e5e0f31f3b0c933e901395bb4b Mon Sep 17 00:00:00 2001 From: hector <42570491+majinghe@users.noreply.github.com> Date: Tue, 29 Sep 2026 16:09:31 +0800 Subject: [PATCH] fix(ci): run security chain evidence from the lane's own checkout (#8229) The security workflow checks the repository out into rustfs-repo/ (#7212) but its chain evidence steps still invoke scripts/functional_chain_evidence.py relative to the workspace root, which on the persistent shared runner resolves to a stale checkout left by another job. The evidence gate then compares that checkout's HEAD against the chain workflow_sha and rejects the lane before any case runs ("lane checkout differs from chain workflow source"). Run the evidence script from the lane's own checkout so ROOT resolves to rustfs-repo/, whose HEAD is exactly the chain-pinned workflow_sha. --- .github/workflows/rustfs-security-test.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/rustfs-security-test.yml b/.github/workflows/rustfs-security-test.yml index f4d5aca2b..771e24aa0 100644 --- a/.github/workflows/rustfs-security-test.yml +++ b/.github/workflows/rustfs-security-test.yml @@ -106,7 +106,7 @@ jobs: if: ${{ inputs.chain_manifest != '' }} env: CHAIN_MANIFEST: ${{ inputs.chain_manifest }} - run: python3 scripts/functional_chain_evidence.py consume + run: python3 rustfs-repo/scripts/functional_chain_evidence.py consume - name: Checkout auto-testing scripts uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 @@ -389,7 +389,7 @@ jobs: CHAIN_TEST_OUTCOME: ${{ steps.test.outcome }} CHAIN_REPORT_OUTCOME: ${{ steps.report.outcome }} run: >- - python3 scripts/functional_chain_evidence.py record --suite security + python3 rustfs-repo/scripts/functional_chain_evidence.py record --suite security --report "${SECURITY_ARTIFACTS_DIR}/suite-report.md" --output "${RUNNER_TEMP}/chain-security-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}/security.json"