From 85807c83b0d9dd4f3c5aead7fe6e20510c5fdbb4 Mon Sep 17 00:00:00 2001 From: Jake Abendroth Date: Thu, 1 Oct 2026 02:14:02 -0700 Subject: [PATCH 1/2] GnuTests.yml: let root tests run the uutils build --- .github/workflows/GnuTests.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/GnuTests.yml b/.github/workflows/GnuTests.yml index f6a370d5a2..b66c141352 100644 --- a/.github/workflows/GnuTests.yml +++ b/.github/workflows/GnuTests.yml @@ -116,6 +116,11 @@ jobs: - name: Run GNU root tests shell: bash run: | + ## Root tests drop to $NON_ROOT_USERNAME via `chroot --user`. /home/runner is + ## 0750, so that user cannot reach our build dir and PATH lookup silently + ## falls back to the runner's own /usr/bin coreutils. Allow traversal. + dir="${GITHUB_WORKSPACE}" + while [ "${dir}" != / ]; do sudo chmod o+x "${dir}"; dir=$(dirname "${dir}"); done ## Run GNU root tests path_GNU='gnu' path_UUTILS='uutils' From a9ffbde1c35abfdc0b5e24938b55bab54f989687 Mon Sep 17 00:00:00 2001 From: Jake Abendroth Date: Thu, 1 Oct 2026 19:14:47 -0700 Subject: [PATCH 2/2] GnuTests.yml: fail if the non-root user cannot run the uutils build --- .github/workflows/GnuTests.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/GnuTests.yml b/.github/workflows/GnuTests.yml index b66c141352..a7ea38961c 100644 --- a/.github/workflows/GnuTests.yml +++ b/.github/workflows/GnuTests.yml @@ -121,6 +121,9 @@ jobs: ## falls back to the runner's own /usr/bin coreutils. Allow traversal. dir="${GITHUB_WORKSPACE}" while [ "${dir}" != / ]; do sudo chmod o+x "${dir}"; dir=$(dirname "${dir}"); done + ## Fail here if that user still cannot run our build, instead of letting the + ## tests pass or fail on whatever coreutils the runner image ships. + sudo -u nobody "${GITHUB_WORKSPACE}/uutils/target/release-small/id" -u ## Run GNU root tests path_GNU='gnu' path_UUTILS='uutils'