install.sh: skip hook activation on a clone this user cannot configure

activate_hooks assumed SCRIPT_DIR is a clone the caller owns. pi-devbox bakes
this repo root-owned under /opt/pi-extensions and runs install.sh as
`developer` on every boot: git refuses the repo ("dubious ownership"),
`config --local` fails (silenced), `cur` is empty, and the unguarded
`git config core.hooksPath hooks` exits 128 -- under set -euo pipefail that
aborted the installer and the entrypoint printed
"WARN: pi-extensions install.sh failed (continuing)" on every boot of every
device. Damage was nil (activate_hooks is the last real step; all symlinks
were already created) but a WARN that always fires is a WARN nobody reads.

Now: resolve the git dir and require .git/config to be writable; otherwise
print one note and return 0. Hooks are for clones you commit from, and a
vendored read-only copy is not one.

Measured (function extracted, run under set -euo pipefail, 8 cases):
  old fn  /opt/pi-extensions as developer   rc=128 "not in a git directory"
  old fn  root-owned throwaway clone        rc=128
  new fn  /opt/pi-extensions, root-owned throwaway, no .git, .git/config 444
                                            rc=0  NOTE "Repo hooks skipped"
  new fn  writable clone, hooksPath unset   rc=0  activated, config reads "hooks"
  new fn  writable clone, hooksPath=hooks   rc=0  "already active"
  neither root-owned config was modified. shellcheck: only the pre-existing
  SC2155 at line 170.
This commit is contained in:
2026-09-22 17:16:28 +02:00
parent 25c1265681
commit 143a2145e1
+13
View File
@@ -193,6 +193,19 @@ do_install() {
activate_hooks() {
[[ -d "${SCRIPT_DIR}/hooks" ]] || return 0
# Hooks are for clones you COMMIT from. A vendored copy (pi-devbox bakes
# this repo root-owned under /opt and runs install.sh as an unprivileged
# user on every boot) is not one: git refuses the repo as "dubious
# ownership", `config --local` fails, and the unguarded `git config` below
# then aborted the whole installer under set -e -- one WARN per boot, on
# every device, for a step that had nothing to do there. Skip, don't fail.
local gitdir
if ! gitdir="$(git -C "$SCRIPT_DIR" rev-parse --absolute-git-dir 2>/dev/null)" \
|| [[ ! -w "$gitdir/config" ]]; then
note "Repo hooks skipped: ${SCRIPT_DIR} is not a git clone this user can configure (vendored/read-only copy)"
return 0
fi
local cur
cur="$(git -C "$SCRIPT_DIR" config --local core.hooksPath 2>/dev/null || true)"