From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id yc4fNV4lNGoZzw0AWB0awg (envelope-from ) for ; Thu, 18 Jun 2026 13:05:34 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=simark.ca; s=mail; t=1781802334; bh=slCJvXESZiJhBrPc1RF/ogwxpU1uZYnfqp9dPkWqaeM=; h=Date:Subject:To:References:From:In-Reply-To:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From; b=cXRMf+swjQdODfuFiKNZYW+UTXjCRGq+vLT0LFIxSZ0VmTrd62MUnviwq69cw9en2 uNPE0ougcFmsiIEa+YSvOmcqERHov8EuB1DBjIWv1knPz38Sj0+dzlzCZTEMFwk1gd TC7VGjRDX6dgX3+HyK01j6GcWPV19UcFD38M5eyo= Received: by simark.ca (Postfix, from userid 112) id D66C61E098; Thu, 18 Jun 2026 13:05:34 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=ham autolearn_force=no version=4.0.1 Authentication-Results: simark.ca; dkim=pass (1024-bit key; unprotected) header.d=simark.ca header.i=@simark.ca header.a=rsa-sha256 header.s=mail header.b=H5yaPfmB; dkim-atps=neutral Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 1E8601E070 for ; Thu, 18 Jun 2026 13:05:34 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 85B0A4BA2E0D for ; Thu, 18 Jun 2026 17:05:32 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 85B0A4BA2E0D Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=simark.ca header.i=@simark.ca header.a=rsa-sha256 header.s=mail header.b=H5yaPfmB Received: from simark.ca (simark.ca [158.69.221.121]) by sourceware.org (Postfix) with ESMTPS id 854744BA2E08 for ; Thu, 18 Jun 2026 17:05:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 854744BA2E08 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=simark.ca Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=simark.ca ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 854744BA2E08 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=158.69.221.121 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1781802306; cv=none; b=kJvZX3Z692UUeWAgyXdyPO+5IwmuQu1UpG9lh4jo4WODb9zCL10DDTWSd/K3axpJXqFivOED2hYM8MfweM/LHrjbNVNIHodQhpwyvGjAiYdxlhgivPWxGPIV2XeD3hHsSe36i5DWzsm8fdKY4ZlqWaApzd56X4ZV6dfbRjeikSY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1781802306; c=relaxed/simple; bh=slCJvXESZiJhBrPc1RF/ogwxpU1uZYnfqp9dPkWqaeM=; h=DKIM-Signature:Message-ID:Date:MIME-Version:Subject:To:From; b=QK+3WUeN6CV4hzwD4+5a1dpZomeDd93JNDPIyyGV9z1R1Qp6PpGqK/MIue680llj0qUF2FTUBiHvzH3Vkn68BYDmAfQ3kWVyhQvYU+C6EX181jcG95ibfpBKA/FPq2kssZsHLEExhgNBrCUZ54t+cPSMMju3K7ZwT2b7JL9T/SA= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=simark.ca header.i=@simark.ca header.a=rsa-sha256 header.s=mail header.b=H5yaPfmB DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 854744BA2E08 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=simark.ca; s=mail; t=1781802304; bh=slCJvXESZiJhBrPc1RF/ogwxpU1uZYnfqp9dPkWqaeM=; h=Date:Subject:To:References:From:In-Reply-To:From; b=H5yaPfmBnpGwCoxXtind6tgwEzHXBLFPNNW+R1WwUG7u9d2tl8huIA3Ro6vpToz5X oKlYt6hDLrX4SQzDvWbWdAoGg3Q7uL7M2jivu0vNttKPYNCG7L+aEvt5aE6p0B4Rad mM5Zxho5Jbs2I0w3uAJ8xw1DXQoo541qXmjDgI7E= Received: by simark.ca (Postfix) id A6D751E070; Thu, 18 Jun 2026 13:05:03 -0400 (EDT) Message-ID: Date: Thu, 18 Jun 2026 13:05:03 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] [pre-commit] Add shellcheck To: Tom de Vries , gdb-patches@sourceware.org References: <20260618151957.76500-1-tdevries@suse.de> Content-Language: en-US From: Simon Marchi In-Reply-To: <20260618151957.76500-1-tdevries@suse.de> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org On 2026-06-18 11:19, Tom de Vries wrote: > I found a pure python implementation of shellcheck [1]. > > Use it to run shellcheck on scripts in the repo. > > Exclude any scripts that are not currently clean. > > Running it seems reasonably fast: > ... > $ pre-commit run shellcheck --all-files -v > shellcheck...............................................................Passed > - hook id: shellcheck > - duration: 0.06s > ... > > For information on other solutions, see this RFC [2]. > > [1] https://pypi.org/project/pureshellcheck/0.2.2/ > [2] https://sourceware.org/pipermail/gdb-patches/2024-November/213400.html While I'm sympathetic to the use of pre-commit (I added the first hooks), I'm starting to get a bit worried that we kind of blindly pull hooks from random places without paying much attention. This is going to get executed on the machines of many GDB devs, and probably some CI too. I had this thought because this one has the "random project on github vibes" (it appears to be a vibe coded project started a week ago). More established projects (like black) are not immune to being compromised, but they are easier to trust I guess. Assuming you gave a quick look at the code of this project and judge that it's fine, how can we ensure that whatever pre-commit pulls is what you reviewed? We use a git tag, but is that sufficient? Could a (malicious or compromised) project publish a tag, and then replaced that tag with something else later? An alternative could be to point to a specific commit hash. A more radical alternative would be to vendor (put in our repo) the code of the hooks we use. I'd like to hear your thoughts on this. Simon