mirror of
https://github.com/rustfs/rustfs.git
synced 2026-10-04 04:21:35 +00:00
0e58bd09d0
The security workflow checks the repository out into rustfs-repo/ (#7212) but its chain evidence steps still invoke scripts/functional_chain_evidence.py relative to the workspace root, which on the persistent shared runner resolves to a stale checkout left by another job. The evidence gate then compares that checkout's HEAD against the chain workflow_sha and rejects the lane before any case runs ("lane checkout differs from chain workflow source"). Run the evidence script from the lane's own checkout so ROOT resolves to rustfs-repo/, whose HEAD is exactly the chain-pinned workflow_sha.