install.sh: skip hook activation on a clone this user cannot configure
activate_hooks assumed SCRIPT_DIR is a clone the caller owns. pi-devbox bakes
this repo root-owned under /opt/pi-extensions and runs install.sh as
`developer` on every boot: git refuses the repo ("dubious ownership"),
`config --local` fails (silenced), `cur` is empty, and the unguarded
`git config core.hooksPath hooks` exits 128 -- under set -euo pipefail that
aborted the installer and the entrypoint printed
"WARN: pi-extensions install.sh failed (continuing)" on every boot of every
device. Damage was nil (activate_hooks is the last real step; all symlinks
were already created) but a WARN that always fires is a WARN nobody reads.
Now: resolve the git dir and require .git/config to be writable; otherwise
print one note and return 0. Hooks are for clones you commit from, and a
vendored read-only copy is not one.
Measured (function extracted, run under set -euo pipefail, 8 cases):
old fn /opt/pi-extensions as developer rc=128 "not in a git directory"
old fn root-owned throwaway clone rc=128
new fn /opt/pi-extensions, root-owned throwaway, no .git, .git/config 444
rc=0 NOTE "Repo hooks skipped"
new fn writable clone, hooksPath unset rc=0 activated, config reads "hooks"
new fn writable clone, hooksPath=hooks rc=0 "already active"
neither root-owned config was modified. shellcheck: only the pre-existing
SC2155 at line 170.
This commit is contained in:
+13
@@ -193,6 +193,19 @@ do_install() {
|
|||||||
activate_hooks() {
|
activate_hooks() {
|
||||||
[[ -d "${SCRIPT_DIR}/hooks" ]] || return 0
|
[[ -d "${SCRIPT_DIR}/hooks" ]] || return 0
|
||||||
|
|
||||||
|
# Hooks are for clones you COMMIT from. A vendored copy (pi-devbox bakes
|
||||||
|
# this repo root-owned under /opt and runs install.sh as an unprivileged
|
||||||
|
# user on every boot) is not one: git refuses the repo as "dubious
|
||||||
|
# ownership", `config --local` fails, and the unguarded `git config` below
|
||||||
|
# then aborted the whole installer under set -e -- one WARN per boot, on
|
||||||
|
# every device, for a step that had nothing to do there. Skip, don't fail.
|
||||||
|
local gitdir
|
||||||
|
if ! gitdir="$(git -C "$SCRIPT_DIR" rev-parse --absolute-git-dir 2>/dev/null)" \
|
||||||
|
|| [[ ! -w "$gitdir/config" ]]; then
|
||||||
|
note "Repo hooks skipped: ${SCRIPT_DIR} is not a git clone this user can configure (vendored/read-only copy)"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
local cur
|
local cur
|
||||||
cur="$(git -C "$SCRIPT_DIR" config --local core.hooksPath 2>/dev/null || true)"
|
cur="$(git -C "$SCRIPT_DIR" config --local core.hooksPath 2>/dev/null || true)"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user