archlinux-s390x/scripts/check-private.sh

101 lines
4.5 KiB
Bash
Raw Normal View History

[ADD] upstream.lock, and keep the machine out of the repository Until now the honest description of this port was: it worked once, on one machine. Every PKGBUILD comes from a `git clone --depth 1` of gitlab.archlinux.org, and the 63 hooks assert exact strings -- deliberately, and several have caught their own mistakes that way. But it means the port is written against a moving target: someone starting over today gets what Arch has today, not what these hooks were written against. What closes that is not the 18 GB of build output -- regenerable packages, a chroot wiped on every run, state files derived from the repository by design. It is one commit per checkout: 155 lines. build_package now pins a fresh clone to the locked commit, and says so when a package is NOT in the lock, because that is how a lock quietly stops covering what it claims to. RELAIS.md joins the repository, written without the build machine's alias, address or account -- a successor needs the shape of the access, not its coordinates. check-private.sh keeps it that way, and .env.example loses its literal account name. Three of its patterns had to go on their first runs: they flagged a systemd unit template, upstream maintainer headers, the localhost lines of a generated /etc/hosts, and its own explanatory comment. A check that fails on correct files is one somebody stops running. --- FR --- Jusqu'ici la description honnête de ce portage était : il a fonctionné une fois, sur une machine. Chaque PKGBUILD vient d'un `git clone --depth 1` de gitlab.archlinux.org, et les 63 hooks affirment des chaînes exactes — à dessein, et plusieurs y ont attrapé leurs propres erreurs. Mais le portage est donc écrit contre une cible mouvante : qui recommence aujourd'hui obtient l'Arch du jour. Ce qui comble ce trou n'est pas les 18 Go de production — paquets régénérables, chroot effacé à chaque passage, registres dérivés du dépôt par conception. C'est un commit par arbre : 155 lignes. build_package épingle un nouveau clone sur le commit verrouillé, et le DIT quand un paquet n'y figure pas, car c'est ainsi qu'un verrou cesse discrètement de couvrir ce qu'il prétend. RELAIS.md entre dans le dépôt, écrit sans l'alias, l'adresse ni le compte de la machine — un successeur a besoin de la forme de l'accès, pas de ses coordonnées. check-private.sh l'y maintient, et .env.example perd son nom de compte littéral. Trois de ses motifs ont dû partir dès les premiers passages : ils signalaient un gabarit d'unité systemd, des en-têtes de mainteneurs amont, les lignes localhost d'un /etc/hosts généré, et son propre commentaire explicatif. Un contrôle qui échoue sur des fichiers justes est un contrôle qu'on cesse de lancer. Assisted-by: Claude Opus 5
2026-08-22 22:52:04 -04:00
#!/usr/bin/env bash
# Refuse to carry the developer's machine in the repository.
#
# WHY THIS EXISTS. RELAIS.md was written with the build machine's ssh alias, the
# guest's IP address, and the author's name and e-mail in the body of the text.
# None of it was needed: a successor needs the SHAPE of the access, not its
# coordinates, and the commit identity is already in the author field of every
# commit.
#
# It is a check rather than a one-time cleanup because the leak arrives by
# accident. Every path in this port gets pasted from a terminal at some point --
# error messages carry absolute paths, and absolute paths carry usernames.
#
# Run over the TRACKED files only. Build output under work/ is nobody's business
# here and is not versioned; see scripts/upstream-lock.sh for what is.
set -uo pipefail
cd "$(dirname "${BASH_SOURCE[0]}")/.." || exit 2
# Deliberately narrow. A pattern that fires on ordinary prose gets disabled, and
# a disabled check is worse than none.
#
# - RFC1918 addresses and any dotted quad
# - /home/<name>, which is how a username travels
# - an e-mail address
declare -a PATTERNS=(
'\b10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\b'
'\b192\.168\.[0-9]{1,3}\.[0-9]{1,3}\b'
'\b172\.(1[6-9]|2[0-9]|3[01])\.[0-9]{1,3}\.[0-9]{1,3}\b'
'/home/[a-z][a-z0-9_-]*'
)
# 127.0.0.0/8 is NOT here. It was, and it flagged
#
# scripts/create-rootfs.sh:152 127.0.0.1 localhost
# scripts/create-rootfs.sh:154 127.0.1.1 archlinux-s390x.localdomain
#
# which is the content an /etc/hosts is supposed to have. Loopback says nothing
# about whose machine this is -- that is the whole point of loopback -- and a
# check that fails on a correct file is a check somebody will stop running.
declare -a NAMES=(
'address'
'private address'
'private address'
'home directory with a username'
)
# NO GENERIC E-MAIL PATTERN. There was one, and it had to go on its first run:
#
# scripts/create-rootfs.sh:302 .../etc/systemd/system/getty@tty1.service
# CODEOWNERS:4 * @Morganamilo morganamilo@archlinux.org
# arch-kernel/PKGBUILD-s390x:1 # Maintainer: ... <heftig@archlinux.org>
#
# A systemd unit template contains an @, and upstream maintainer headers are
# supposed to carry addresses -- they are Arch's, publicly published, and a
# PKGBUILD without them would be the anomaly. Six of nine findings were noise,
# which is how a check gets switched off and stops protecting anything.
#
# The author's own address is not covered here either, deliberately: it is in the
# author field of all 89 commits by the project's own convention, so calling it a
# leak in prose while requiring it in metadata would be incoherent. What this
# checks is the machine -- addresses and usernames -- which nothing needs.
# Files that are examples ON PURPOSE. Named one by one, with the reason, because
# a wildcard exclusion is how a real leak gets waved through.
#
# EMPTY, and that is the intended state. .env.example was listed here, exempted
# for carrying a home directory with a literal account name -- then its values
# were made neutral and the exemption had nothing left to excuse. An exemption
# that outlives its reason is how a file stops being checked without anyone
# deciding that it should.
#
# And the first version of this very comment quoted the path it was describing,
# so the check flagged its own source. A redaction tool must not spell out what
# it redacts; there is no reason to name the account to explain why it is gone.
declare -a ALLOW=()
hits=0
for i in "${!PATTERNS[@]}"; do
while IFS=: read -r file line rest; do
[ -n "$file" ] || continue
skip=0
for a in "${ALLOW[@]}"; do [ "$file" = "$a" ] && skip=1; done
[ "$skip" -eq 1 ] && continue
printf ' %-28s %s:%s %s\n' "${NAMES[$i]}" "$file" "$line" \
"$(printf '%s' "$rest" | cut -c1-60)"
hits=$((hits + 1))
done < <(git grep -nIE "${PATTERNS[$i]}" -- . 2>/dev/null)
done
# Commit messages too. The working tree can be cleaned with an edit; a message
# needs history rewritten, so it is worth knowing early rather than late.
msg=$(git log --all --format='%B' 2>/dev/null |
grep -cE '\b(192\.168|10|172\.(1[6-9]|2[0-9]|3[01]))\.[0-9]{1,3}\.[0-9]{1,3}\b|/home/[a-z]' || true)
if [ "$hits" -eq 0 ] && [ "${msg:-0}" -eq 0 ]; then
echo "no machine identity, address or username in the tracked files"
exit 0
fi
[ "${msg:-0}" -gt 0 ] && printf ' %s line(s) in COMMIT MESSAGES -- needs history rewriting\n' "$msg"
printf '%s finding(s)\n' "$((hits + ${msg:-0}))"
exit 1