Skip to content

fix: canonicalize relative OpenWrt work directories - #19

Merged
tifycloud merged 1 commit into
mainfrom
codex/fix-package-repository-workdir
Jul 22, 2026
Merged

tifycloud merged 1 commit into
mainfrom
codex/fix-package-repository-workdir

Conversation

@tifycloud

Copy link
Copy Markdown
Owner

Cause

The package repository workflow passes WORK_DIR=.work/package-repository. prepare.sh changed into that directory and then reused the same relative path with git -C, resolving it twice and falsely rejecting the correct locked OpenWrt origin.

Fix

  • anchor a relative WORK_DIR to the physical invocation directory before any cd
  • preserve the strict exact-origin and no-pushurl checks
  • add a regression test that prepares through a repository-relative work directory and verifies the pinned commit, exact origin, absence of pushurl, patched source, and revision

Verification

  • bash tests/test_source_fetch_policy.sh
  • bash tests/test_package_repository_policy.sh
  • complete bash tests/test_static.sh
  • actionlint for the repository/Pages workflows
  • shellcheck for the changed scripts
  • independent review confirmed the root cause and that this fix does not weaken remote or credential protections

The failed publish run stopped before the signing key was materialized, so no release/tag was created and package-repository-v25.12.5-r1 remains reusable.

@tifycloud
tifycloud merged commit 67154e3 into main Jul 22, 2026
6 checks passed
@tifycloud
tifycloud deleted the codex/fix-package-repository-workdir branch July 22, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant