From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id 2d1DBmAIOWpgOBMAWB0awg (envelope-from ) for ; Mon, 22 Jun 2026 06:03:12 -0400 Authentication-Results: simark.ca; dkim=pass (1024-bit key; unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=dzqsLuhp; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=DCel2VKd; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=cIVY8cok; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oVVdGOVP; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id 1477E1E024; Mon, 22 Jun 2026 06:03:12 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=unavailable autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [IPv6:2620:52:6:3111::32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 42ACB1E024 for ; Mon, 22 Jun 2026 06:03:11 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E73B84BA2E22 for ; Mon, 22 Jun 2026 10:03:09 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E73B84BA2E22 Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=dzqsLuhp; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=DCel2VKd; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=cIVY8cok; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oVVdGOVP Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) by sourceware.org (Postfix) with ESMTPS id 4158B4BA2E08 for ; Mon, 22 Jun 2026 10:02:44 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 4158B4BA2E08 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=suse.de ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 4158B4BA2E08 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782122564; cv=none; b=Mscvclh16aylHuN+GvUlZVXAYCY6Xrrt+IpnujwZgeIFRL3m1PYcrCEXYUmWkwakegcpkxpQRCpEOuqe638EheufLhUS2w0C+WRiANPtHWQsvsGxLxoAndnhsZ1fF2vjZcZkLIx9Pa3yqkFke5NrG8L19c9YlS4ltQwNCp9i2kA= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782122564; c=relaxed/simple; bh=Eab47YtKkZQFNQATYvO99XFWftxTZnyccT6lrzM1Ha0=; h=DKIM-Signature:DKIM-Signature:DKIM-Signature:DKIM-Signature: Message-ID:Date:MIME-Version:Subject:To:From; b=V7yXztV9Ku+pvIWIMr8XM7URRnAb8sPKWnSB3yfZGYVdInk61PfGbM3vzC5sOPpfMMfyX/sBRMGe3QQKtFugubsLYqUtsQNJlpFpJ7Dvk/b3Kd/9G+7E2ljwKKrtiGE+mGprGT41pX37CpqB8kAfYpv9kN068lC/zeCrDvsGPnk= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=dzqsLuhp; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=DCel2VKd; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=cIVY8cok; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oVVdGOVP DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 4158B4BA2E08 Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 1B6027059D; Mon, 22 Jun 2026 10:02:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1782122563; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6Y9GpbDAyYm4YFWTF6QDUJbY1Pqh+kkcKj5cMFrDAaY=; b=dzqsLuhpVbADvlrNRr9DTLL3rlq2Kc3K9SqnND5lLzBYlDqaokMGgfIVbuTna4JA1Y3bbR s4svahnb2ubU+LRgj+NDU7y9Em3T3AnwrhXFIz74f3EVQdyB6JXgOgfAz4KNQViZXS1G4T rVCc2EgfdwaOIO2TDdpWeB+6WMspz84= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1782122563; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6Y9GpbDAyYm4YFWTF6QDUJbY1Pqh+kkcKj5cMFrDAaY=; b=DCel2VKdDzKvuar4tUrUaqd8pJsSsd4XVw8yZ1wtzdP61GL7y1rFlVDKGa+mRlBJiGcaiW F4fBhqp1Y0NNdkAQ== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1782122562; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6Y9GpbDAyYm4YFWTF6QDUJbY1Pqh+kkcKj5cMFrDAaY=; b=cIVY8cokUXAca8u0rw42I/Jc9Z+sbP1R0WHl/xQybY6Rs/pffTAjcAIp+N40zwKJ/IsNt8 BWt7VuHGUrdeU/5MMh05l3rVfYpug8TWy3dYl1E1NtpNq8P1zD0W1HEYvd6X4s78MAlGk3 YUQXoCIMN2tjJgvQBSkJNXozlrs11wY= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1782122562; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6Y9GpbDAyYm4YFWTF6QDUJbY1Pqh+kkcKj5cMFrDAaY=; b=oVVdGOVP1e7arUSAcQsHVYXN9x7U4EgDcnvMayBib6etsq2peXVsJLnfEsXTOUDzG9gcCY gpBAqvX+Z8bjcHBw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 0004A779A8; Mon, 22 Jun 2026 10:02:41 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id SnY5OkEIOWq1VwAAD6G6ig (envelope-from ); Mon, 22 Jun 2026 10:02:41 +0000 Message-ID: <6174eca4-a189-4f38-bd69-a6312c361d20@suse.de> Date: Mon, 22 Jun 2026 12:02:41 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] [pre-commit] Add shellcheck To: Thiago Jung Bauermann , Simon Marchi Cc: gdb-patches@sourceware.org References: <20260618151957.76500-1-tdevries@suse.de> <874iivunvq.fsf@linaro.org> Content-Language: en-US From: Tom de Vries In-Reply-To: <874iivunvq.fsf@linaro.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spamd-Result: default: False [-4.30 / 50.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-0.999]; MIME_GOOD(-0.10)[text/plain]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FUZZY_RATELIMITED(0.00)[rspamd.com]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; TO_DN_SOME(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; DBL_BLOCKED_OPENRESOLVER(0.00)[pypi.org:url, sourceware.org:url, simark.ca:email, imap1.dmz-prg2.suse.org:helo, suse.de:mid] X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org On 6/22/26 7:48 AM, Thiago Jung Bauermann wrote: > Simon Marchi writes: > >> On 2026-06-18 11:19, Tom de Vries wrote: >>> I found a pure python implementation of shellcheck [1]. >>> >>> Use it to run shellcheck on scripts in the repo. >>> >>> Exclude any scripts that are not currently clean. >>> >>> Running it seems reasonably fast: >>> ... >>> $ pre-commit run shellcheck --all-files -v >>> shellcheck...............................................................Passed >>> - hook id: shellcheck >>> - duration: 0.06s >>> ... >>> >>> For information on other solutions, see this RFC [2]. >>> >>> [1] https://pypi.org/project/pureshellcheck/0.2.2/ >>> [2] https://sourceware.org/pipermail/gdb-patches/2024-November/213400.html >> >> While I'm sympathetic to the use of pre-commit (I added the first >> hooks), I'm starting to get a bit worried that we kind of blindly pull >> hooks from random places without paying much attention. This is going >> to get executed on the machines of many GDB devs, and probably some CI >> too. >> >> I had this thought because this one has the "random project on github >> vibes" (it appears to be a vibe coded project started a week ago). More >> established projects (like black) are not immune to being compromised, >> but they are easier to trust I guess. > > I have the same kind of concern, but I'm more paranoid. As a general > principle I prefer to install distro packages rather than > language-specific packages (such as the ones from PyPI), on the > assumption that distros tend to be more careful about incorporating > packages and updating them (it's a weak assumption though). > > Because of that, in order to run the pre-commit checks I created a > script (attached) that parses .pre-commit-config.yaml and runs the hooks > with the tools that are already installed on the system. It doesn't try > to download anything. > > Today I added support for running each hook in an isolated container > with access only to the binutils-gdb repo, and in read-only mode at > that. It uses Guix to set up the containers so when Guix isn't installed > you need to pass the --no-container option. > > Also when using containers the script can only use the tools packaged in > Guix, which currently doesn't have some of the tools referenced by our > .pre-commit-config.yaml, or has older versions of them. > > Another bad news is that the script is in Scheme. :) > > But you get the idea. :) > Hi Thiago, thanks for sharing your point of view and the script. My take on this is as follows. The benefit of git hooks is automation. The benefit of using the pre-commit framework to manage those hooks is: - version pinning, and - seamless installation in other words, making it easy that everybody does the same check. That comes with the drawback of a download-heavy approach, but that's the trade-off. Your approach has a different trade-off. We could do something similar (no downloading) for shellcheck: ... diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 9910bbb82f2..92c56d95977 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -130,3 +130,10 @@ repos: language: unsupported_script entry: gdb/contrib/check-file-mode.sh files: '^(gdb|gdbserver|gdbsupport)/.*$' + - id: &id5 shellcheck + name: *id5 + language: unsupported + entry: shellcheck + files: '^(gdb|gdbsupport|gdbserver)/' + types: ['shell'] + exclude: '^(gdb/config/djgpp/(djcheck.sh|djconfig.sh)|gdb/contrib/ari/(create-web-ari- in-src.sh|gdb_ari.sh|update-web-ari.sh)|gdb/contrib/(cc-with-tweaks.sh|gdb-add-index.sh)|gdb/gdb_builda ll.sh|gdb/gdb_mbuild.sh|gdb/regformats/regdat.sh|gdb/po/gdbtext|gdb/testsuite/lib/pdtrace.in)$|/configu re$' ... This means there's no easy installation, people have to install it themselves. There's also no version pinning. We could add a script that does a version check though, and check for version 0.11.0. My laptop runs Leap 16.0, which has shellcheck 0.10.0, so I would have to run pre-commit in a tumbleweed container. Or build shellcheck from source and add it to my path. But yeah, I'd prefer to not have to bother with that, and pureshellcheck does provide an easy solution. Thanks, - Tom