ci: locate the auto-testing checkout for lanes that run evidence from a subdirectory

#8229 moved the security lane's evidence steps onto its own rustfs
checkout (rustfs-repo/), which changed what ROOT means for those runs:
record() resolves 'auto-testing' relative to ROOT, so it looked for
rustfs-repo/auto-testing while the lane checks the private scripts out
at the workspace root. The git call exited 128 and the security lane
went red with zero cases in the Sep 29 and Sep 30 overnight chains
(36601455596, 36747961149) - the first failure mode after the checkout
itself stopped being the problem.

Resolve the checkout directory as the first of ROOT/auto-testing and
GITHUB_WORKSPACE/auto-testing that exists; the testing_sha provenance
check is unchanged.
This commit is contained in:
hector
2026-10-01 08:22:13 +08:00
parent 2806a80c91
commit b66129ab9f
+16 -1
View File
@@ -113,12 +113,27 @@ def fault_tolerance_counts(text):
return counts
def auto_testing_dir():
"""Locate the auto-testing checkout. Lanes that run this script from a
subdirectory checkout (security keeps its rustfs clone in rustfs-repo/)
still check auto-testing out at the workspace root, so ROOT alone is not
always the right base."""
candidates = [ROOT / "auto-testing"]
workspace = os.environ.get("GITHUB_WORKSPACE")
if workspace:
candidates.append(Path(workspace) / "auto-testing")
for candidate in candidates:
if (candidate / ".git").exists():
return candidate
return candidates[0]
def record(chain, suite, report, output):
require(suite in SUITES, "unknown suite")
result = {"schema": 1, "suite": suite, "chain": chain, "valid": False, "counts": {}, "report_sha256": None}
error = None
try:
private_head = subprocess.check_output(["git", "-C", "auto-testing", "rev-parse", "HEAD"], cwd=ROOT, text=True).strip()
private_head = subprocess.check_output(["git", "-C", str(auto_testing_dir()), "rev-parse", "HEAD"], cwd=ROOT, text=True).strip()
require(private_head == chain["testing_sha"], "suite used a different private script revision")
require(report.is_file() and 0 < report.stat().st_size <= MAX_REPORT, "missing, empty or oversized report")
data = report.read_bytes()