ci: fix a latent false negative and cut Identity Guard runtime 50s to 1s

两处都是本地实测发现的,不是推测。

1) 漏判(正确性):尾注预筛写成 `git log --format=%B "$RANGE" | grep -qiE`,
   在 `set -o pipefail` 下 grep -q 命中即退出,左侧 git log 收到 SIGPIPE,
   整条管道返回非 0,if 判定为"没命中"从而跳过整个尾注检查。
   实测:沙箱里 8 条应报错误只报出 6 条,两个带 AI 尾注的提交被静默放过。
   改为 here-string(不再有管道),身份预筛同样改掉以杜绝这一类问题。

2) 性能:全量审计路径(新建分支推送、workflow_dispatch)原先为每个提交
   各起一个 git 子进程,docker_practice 1,592 个提交实测 50 秒。
   现在先用一次 git log 流式预筛,只有命中时才逐个提交定位;
   同一仓库实测降到 1 秒,且不改变任何判定结果。

回归验证:被删分支的真实 4 个提交在 push / pull_request / 新建分支三种
形态下仍全部拦下;专门构造的 2,502 提交仓库(身份流 258KB,远超管道缓冲区)
中埋在末尾的 AI 提交能被检出;14 个仓库完整历史仍然零误报;
范围解析失败仍 fail closed,删除分支仍正确放行。
This commit is contained in:
yeasy
2026-07-22 15:34:52 -07:00
parent f82e13017d
commit 3781d9c382
+23 -10
View File
@@ -78,12 +78,19 @@ jobs:
BAD_EMAIL='@([a-z0-9.-]+\.)?(anthropic|openai)\.com$'
BAD_NAME='^(claude([ ._-]?code)?|codex|chatgpt|copilot|anthropic|openai)(\[bot\])?$'
BAD_TRAILER='^[[:space:]]*co-authored-by:.*(claude|anthropic|codex|copilot|openai)'
# 粗筛BAD_EMAIL BAD_NAME 命中的行必然含下列词之一
# 因此它是二者的超集用来跳过绝大多数干净提交不会漏判
BAD_ANY='(claude|anthropic|codex|chatgpt|copilot|openai)'
failed=0
# 身份检查命令替换先落地set -e 才能捕获 git 失败
# while 循环用 here-string 喂数据避免管道子 shell 吞掉 failed 赋值
IDENTS="$(git log --format="%H${US}%an${US}%ae${US}%cn${US}%ce" "$RANGE")"
# here-string 而不是管道set -o pipefail grep -q 命中即退出会让
# 左侧进程收到 SIGPIPE整条管道返回非 0if 就会跳过检查
# 而且只在输入大到写不进管道缓冲区时才发生是典型的隐性漏判
if grep -qiE "$BAD_ANY" <<< "$IDENTS"; then
while IFS="$US" read -r sha an ae cn ce; do
[ -n "$sha" ] || continue
for role in author committer; do
@@ -97,17 +104,23 @@ jobs:
fi
done
done <<< "$IDENTS"
fi
# Co-authored-by 尾注检查行首锚定并要求冒号避免匹配正文叙述
while read -r sha; do
[ -n "$sha" ] || continue
body="$(git log -1 --format='%B' "$sha")"
if printf '%s' "$body" | grep -qiE "$BAD_TRAILER"; then
echo "::error::${sha} has a Co-authored-by trailer referencing an AI assistant"
printf '%s' "$body" | grep -iE "$BAD_TRAILER" | sed 's/^/ /'
failed=1
fi
done <<< "$COMMITS"
# Co-authored-by 尾注检查行首锚定并要求冒号避免匹配正文叙述
# 先用一次 git log 流式扫全部正文只有确实命中时才逐个提交定位
# 否则全量审计要为每个提交起一个 git 子进程1500+ 提交约 50
BODIES="$(git log --format='%B' "$RANGE")"
if grep -qiE "$BAD_TRAILER" <<< "$BODIES"; then
while read -r sha; do
[ -n "$sha" ] || continue
body="$(git log -1 --format='%B' "$sha")"
if printf '%s' "$body" | grep -qiE "$BAD_TRAILER"; then
echo "::error::${sha} has a Co-authored-by trailer referencing an AI assistant"
printf '%s' "$body" | grep -iE "$BAD_TRAILER" | sed 's/^/ /'
failed=1
fi
done <<< "$COMMITS"
fi
if [ "$failed" -ne 0 ]; then
echo ""