From 3781d9c38241fb150f6d1e2a8226fa1bee3d0cab Mon Sep 17 00:00:00 2001 From: yeasy Date: Wed, 22 Jul 2026 15:34:52 -0700 Subject: [PATCH] ci: fix a latent false negative and cut Identity Guard runtime 50s to 1s MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 两处都是本地实测发现的,不是推测。 1) 漏判(正确性):尾注预筛写成 `git log --format=%B "$RANGE" | grep -qiE`, 在 `set -o pipefail` 下 grep -q 命中即退出,左侧 git log 收到 SIGPIPE, 整条管道返回非 0,if 判定为"没命中"从而跳过整个尾注检查。 实测:沙箱里 8 条应报错误只报出 6 条,两个带 AI 尾注的提交被静默放过。 改为 here-string(不再有管道),身份预筛同样改掉以杜绝这一类问题。 2) 性能:全量审计路径(新建分支推送、workflow_dispatch)原先为每个提交 各起一个 git 子进程,docker_practice 1,592 个提交实测 50 秒。 现在先用一次 git log 流式预筛,只有命中时才逐个提交定位; 同一仓库实测降到 1 秒,且不改变任何判定结果。 回归验证:被删分支的真实 4 个提交在 push / pull_request / 新建分支三种 形态下仍全部拦下;专门构造的 2,502 提交仓库(身份流 258KB,远超管道缓冲区) 中埋在末尾的 AI 提交能被检出;14 个仓库完整历史仍然零误报; 范围解析失败仍 fail closed,删除分支仍正确放行。 --- .github/workflows/identity-guard.yaml | 33 +++++++++++++++++++-------- 1 file changed, 23 insertions(+), 10 deletions(-) diff --git a/.github/workflows/identity-guard.yaml b/.github/workflows/identity-guard.yaml index ffcbb2f..cc650fe 100644 --- a/.github/workflows/identity-guard.yaml +++ b/.github/workflows/identity-guard.yaml @@ -78,12 +78,19 @@ jobs: BAD_EMAIL='@([a-z0-9.-]+\.)?(anthropic|openai)\.com$' BAD_NAME='^(claude([ ._-]?code)?|codex|chatgpt|copilot|anthropic|openai)(\[bot\])?$' BAD_TRAILER='^[[:space:]]*co-authored-by:.*(claude|anthropic|codex|copilot|openai)' + # 粗筛:BAD_EMAIL 与 BAD_NAME 命中的行必然含下列词之一, + # 因此它是二者的超集,用来跳过绝大多数干净提交,不会漏判。 + BAD_ANY='(claude|anthropic|codex|chatgpt|copilot|openai)' failed=0 # 身份检查。命令替换先落地,set -e 才能捕获 git 失败; # while 循环用 here-string 喂数据,避免管道子 shell 吞掉 failed 赋值。 IDENTS="$(git log --format="%H${US}%an${US}%ae${US}%cn${US}%ce" "$RANGE")" + # 用 here-string 而不是管道:set -o pipefail 下 grep -q 命中即退出会让 + # 左侧进程收到 SIGPIPE,整条管道返回非 0,if 就会跳过检查—— + # 而且只在输入大到写不进管道缓冲区时才发生,是典型的隐性漏判。 + if grep -qiE "$BAD_ANY" <<< "$IDENTS"; then while IFS="$US" read -r sha an ae cn ce; do [ -n "$sha" ] || continue for role in author committer; do @@ -97,17 +104,23 @@ jobs: fi done done <<< "$IDENTS" + fi - # Co-authored-by 尾注检查(行首锚定并要求冒号,避免匹配正文叙述) - while read -r sha; do - [ -n "$sha" ] || continue - body="$(git log -1 --format='%B' "$sha")" - if printf '%s' "$body" | grep -qiE "$BAD_TRAILER"; then - echo "::error::${sha} has a Co-authored-by trailer referencing an AI assistant" - printf '%s' "$body" | grep -iE "$BAD_TRAILER" | sed 's/^/ /' - failed=1 - fi - done <<< "$COMMITS" + # Co-authored-by 尾注检查(行首锚定并要求冒号,避免匹配正文叙述)。 + # 先用一次 git log 流式扫全部正文;只有确实命中时才逐个提交定位, + # 否则全量审计要为每个提交起一个 git 子进程(1500+ 提交约 50 秒)。 + BODIES="$(git log --format='%B' "$RANGE")" + if grep -qiE "$BAD_TRAILER" <<< "$BODIES"; then + while read -r sha; do + [ -n "$sha" ] || continue + body="$(git log -1 --format='%B' "$sha")" + if printf '%s' "$body" | grep -qiE "$BAD_TRAILER"; then + echo "::error::${sha} has a Co-authored-by trailer referencing an AI assistant" + printf '%s' "$body" | grep -iE "$BAD_TRAILER" | sed 's/^/ /' + failed=1 + fi + done <<< "$COMMITS" + fi if [ "$failed" -ne 0 ]; then echo ""