From b66129ab9fc94094bd4b059ba2d256cc4452e9c1 Mon Sep 17 00:00:00 2001 From: hector <42570491+majinghe@users.noreply.github.com> Date: Thu, 1 Oct 2026 08:22:13 +0800 Subject: [PATCH] ci: locate the auto-testing checkout for lanes that run evidence from a subdirectory #8229 moved the security lane's evidence steps onto its own rustfs checkout (rustfs-repo/), which changed what ROOT means for those runs: record() resolves 'auto-testing' relative to ROOT, so it looked for rustfs-repo/auto-testing while the lane checks the private scripts out at the workspace root. The git call exited 128 and the security lane went red with zero cases in the Sep 29 and Sep 30 overnight chains (36601455596, 36747961149) - the first failure mode after the checkout itself stopped being the problem. Resolve the checkout directory as the first of ROOT/auto-testing and GITHUB_WORKSPACE/auto-testing that exists; the testing_sha provenance check is unchanged. --- scripts/functional_chain_evidence.py | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/scripts/functional_chain_evidence.py b/scripts/functional_chain_evidence.py index 3f3cbbdb3..77b096ca5 100644 --- a/scripts/functional_chain_evidence.py +++ b/scripts/functional_chain_evidence.py @@ -113,12 +113,27 @@ def fault_tolerance_counts(text): return counts +def auto_testing_dir(): + """Locate the auto-testing checkout. Lanes that run this script from a + subdirectory checkout (security keeps its rustfs clone in rustfs-repo/) + still check auto-testing out at the workspace root, so ROOT alone is not + always the right base.""" + candidates = [ROOT / "auto-testing"] + workspace = os.environ.get("GITHUB_WORKSPACE") + if workspace: + candidates.append(Path(workspace) / "auto-testing") + for candidate in candidates: + if (candidate / ".git").exists(): + return candidate + return candidates[0] + + def record(chain, suite, report, output): require(suite in SUITES, "unknown suite") result = {"schema": 1, "suite": suite, "chain": chain, "valid": False, "counts": {}, "report_sha256": None} error = None try: - private_head = subprocess.check_output(["git", "-C", "auto-testing", "rev-parse", "HEAD"], cwd=ROOT, text=True).strip() + private_head = subprocess.check_output(["git", "-C", str(auto_testing_dir()), "rev-parse", "HEAD"], cwd=ROOT, text=True).strip() require(private_head == chain["testing_sha"], "suite used a different private script revision") require(report.is_file() and 0 < report.stat().st_size <= MAX_REPORT, "missing, empty or oversized report") data = report.read_bytes()