fix(bootstrap): fail a tokenless private clone instead of prompting

A source build against a private repository with no FELIS_GITHUB_TOKEN,
or a wrong one, made git ask for a username on /dev/tty, and a piped
install sat there waiting.

git_auth now runs git with GIT_TERMINAL_PROMPT=0 on both arms, so git
fails at once with "terminal prompts disabled". Both fetch_source
failures name FELIS_GITHUB_TOKEN in their message: the fresh clone,
and the fetch into an existing checkout, which had no message of its
own before.
This commit is contained in:
flyemoji committed 2026-09-22 13:53:03 +09:00
1 parent 34f73ba19f
commit 6794e66c4d
2 files changed
+52 -4

No files matched your search

+9 -4
View File
@@ -988,12 +988,16 @@ download_release_binary() {
# approve that follows a successful auth, so it outlives the install after all. An empty # approve that follows a successful auth, so it outlives the install after all. An empty
# value is git's documented list reset. Verified on Fedora: with store configured the single # value is git's documented list reset. Verified on Fedora: with store configured the single
# -c form persists the token to disk, the reset form writes nothing. # -c form persists the token to disk, the reset form writes nothing.
#
# GIT_TERMINAL_PROMPT=0 on both arms: GitHub answers a private repo with no or a bad token
# by asking for credentials, and git would put that prompt on /dev/tty, where a piped
# install sits waiting instead of failing with the FELIS_GITHUB_TOKEN hint.
git_auth() { git_auth() {
if [ -n "$FELIS_GITHUB_TOKEN" ]; then if [ -n "$FELIS_GITHUB_TOKEN" ]; then
git -c 'credential.helper=' \ GIT_TERMINAL_PROMPT=0 git -c 'credential.helper=' \
-c 'credential.helper=!f() { printf "username=x-access-token\npassword=%s\n" "$FELIS_GITHUB_TOKEN"; }; f' "$@" -c 'credential.helper=!f() { printf "username=x-access-token\npassword=%s\n" "$FELIS_GITHUB_TOKEN"; }; f' "$@"
else else
git "$@" GIT_TERMINAL_PROMPT=0 git "$@"
fi fi
} }
@@ -1070,7 +1074,8 @@ fetch_source() {
resolve_install_ref resolve_install_ref
if [ -d "${SRC_DIR}/.git" ]; then if [ -d "${SRC_DIR}/.git" ]; then
log "updating source in ${SRC_DIR}" log "updating source in ${SRC_DIR}"
git_auth -C "$SRC_DIR" fetch --depth 1 origin "$FELIS_REF" git_auth -C "$SRC_DIR" fetch --depth 1 origin "$FELIS_REF" \
|| die "could not fetch ${FELIS_REF} from ${FELIS_REPO_URL}; if the repository is private, set FELIS_GITHUB_TOKEN to a token with read access to it"
git -C "$SRC_DIR" checkout -f FETCH_HEAD git -C "$SRC_DIR" checkout -f FETCH_HEAD
else else
log "cloning ${FELIS_REPO_URL} (${FELIS_REF})" log "cloning ${FELIS_REPO_URL} (${FELIS_REF})"
@@ -1082,7 +1087,7 @@ fetch_source() {
git_auth clone --depth 1 --branch "$FELIS_REF" "$FELIS_REPO_URL" "$SRC_DIR" 2>/dev/null \ git_auth clone --depth 1 --branch "$FELIS_REF" "$FELIS_REPO_URL" "$SRC_DIR" 2>/dev/null \
|| { git_auth clone "$FELIS_REPO_URL" "$SRC_DIR" \ || { git_auth clone "$FELIS_REPO_URL" "$SRC_DIR" \
&& git_auth -C "$SRC_DIR" checkout -f "$FELIS_REF"; } \ && git_auth -C "$SRC_DIR" checkout -f "$FELIS_REF"; } \
|| die "could not check out ${FELIS_REF} from ${FELIS_REPO_URL}" || die "could not check out ${FELIS_REF} from ${FELIS_REPO_URL}; if the repository is private, set FELIS_GITHUB_TOKEN to a token with read access to it"
fi fi
stamp_version stamp_version
ok "source ready at ${SRC_DIR}" ok "source ready at ${SRC_DIR}"
+43
View File
@@ -426,6 +426,49 @@ gtmp="$(printf '%s\n' "$out" | sed -n 's/^TEMP: //p')"
expect "the Go download is staged in a directory the cleanup removes" \ expect "the Go download is staged in a directory the cleanup removes" \
"CURL: ${gtmp:-<none>}/go1.26.4.linux-amd64.tar.gz" "$out" "CURL: ${gtmp:-<none>}/go1.26.4.linux-amd64.tar.gz" "$out"
# --- a private repo without a token fails with the hint instead of prompting -------------
# git asks for credentials on /dev/tty, where a piped install would sit waiting. Every
# network git call goes through git_auth, so the switch belongs there.
gablock="$(awk '/^git_auth\(\) \{/,/^}/' "$BS")"
[ -n "$gablock" ] || { echo "FAIL: no git_auth found in $BS"; exit 1; }
[ "$(printf '%s\n' "$gablock" | wc -l)" -lt 15 ] \
|| { echo "FAIL: the extracted block is not the function -- did its closing brace move?"; exit 1; }
run_git_auth() { # token
FELIS_GITHUB_TOKEN="$1" bash -c '
unset GIT_TERMINAL_PROMPT # whatever runs this harness may have set it already
git() { printf "GIT: prompt=%s\n" "${GIT_TERMINAL_PROMPT:-<unset>}"; }
'"$gablock"'
git_auth clone https://example.invalid/felis.git'
}
expect "git never prompts without a token" "GIT: prompt=0" "$(run_git_auth '')"
expect "git never prompts with a token" "GIT: prompt=0" "$(run_git_auth ghp_example)"
fblock="$(awk '/^fetch_source\(\) \{/,/^}/' "$BS")"
[ -n "$fblock" ] || { echo "FAIL: no fetch_source found in $BS"; exit 1; }
[ "$(printf '%s\n' "$fblock" | wc -l)" -lt 40 ] \
|| { echo "FAIL: the extracted block is not the function -- did its closing brace move?"; exit 1; }
run_fetch() { # src-dir
SRC_DIR="$1" FELIS_REF=main FELIS_REPO_URL=https://example.invalid/felis.git bash -c '
die() { printf "DIE: %s\n" "$*"; exit 1; }
log() { :; }
ok() { :; }
resolve_install_ref() { :; }
stamp_version() { :; }
git_auth() { return 128; }
git() { :; }
'"$fblock"'
fetch_source'
}
expect "a failed clone names the token" "set FELIS_GITHUB_TOKEN" "$(run_fetch "$sdir/src")"
mkdir -p "$sdir/src/.git"
expect "a failed fetch into an existing checkout names the token" "set FELIS_GITHUB_TOKEN" \
"$(run_fetch "$sdir/src")"
# --------------------------------------------------------------------------------------- # ---------------------------------------------------------------------------------------
if [ "$fails" -eq 0 ]; then if [ "$fails" -eq 0 ]; then
echo "ALL PASS" echo "ALL PASS"