From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id oby6M0L5OGpzKhMAWB0awg (envelope-from ) for ; Mon, 22 Jun 2026 04:58:42 -0400 Authentication-Results: simark.ca; dkim=pass (1024-bit key; unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=isebiGbO; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=hLdv3rgT; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=O9p24Wil; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oH8VLp8j; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id CEA6E1E098; Mon, 22 Jun 2026 04:58:42 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=unavailable autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [IPv6:2620:52:6:3111::32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 1B08E1E024 for ; Mon, 22 Jun 2026 04:58:42 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 346E04BA2E0E for ; Mon, 22 Jun 2026 08:58:40 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 346E04BA2E0E Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=isebiGbO; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=hLdv3rgT; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=O9p24Wil; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oH8VLp8j Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) by sourceware.org (Postfix) with ESMTPS id EEAD54BA5439 for ; Mon, 22 Jun 2026 08:58:11 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org EEAD54BA5439 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=suse.de ARC-Filter: OpenARC Filter v1.0.0 sourceware.org EEAD54BA5439 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782118692; cv=none; b=N8tzKaar3N+j4508W7oKF1fXDPofYAGwGGk/pIhok+z0kLFHO3dPY45qIv4dqFFeSYiRebtFNsD9MO3lUTnxPWkUxXGc4Wp6vIm7kUMJ3eWvBeh05+K+ROe0XiMEVv5UY4eip0HPyW0PL7T5ZVkaVRS39uUkxex4WDUyBnD4i1Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782118692; c=relaxed/simple; bh=73h9xl95feD7NuXLOv1XMhV5/M5cpQSFabNnIjoBxOQ=; h=DKIM-Signature:DKIM-Signature:DKIM-Signature:DKIM-Signature: Message-ID:Date:MIME-Version:Subject:To:From; b=qUC9YriwU5vC1T4Ypus9xJ4hFcoRdNjqr0NMEDXy/MO9mkspq3CzrnMhVM7+pfV3XI9Ur6zVYQuZkCNj7oum0+g/e3pLdT0b2Gn+1F/SbGvXOSy+55gbEZAIWWkHOOUsRiHTDFXoaRAlped3t/WsjS7HEYo1jv1+nwegSMONCJ8= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=isebiGbO; dkim=pass header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=hLdv3rgT; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.a=rsa-sha256 header.s=susede2_rsa header.b=O9p24Wil; dkim=neutral header.d=suse.de header.i=@suse.de header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=oH8VLp8j DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org EEAD54BA5439 Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id A724970530; Mon, 22 Jun 2026 08:58:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1782118691; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OHlPcP7AaA+mR2J41ZgaKSwMbkv0cJTOMwCwXn+Kac0=; b=isebiGbOUs/H99+T+IZABT0j68S68ElLFfUmhEiB8kLJD0evaeBJ64jbn3P0tAQP2bjvRI NOYTdaqgeqsLLEdu11zQcZToEmSP7NfYa2wUh1N4fI1krjBI4iX0kNCer/SxFzBuQqTcVM VshzED9cNe7xXMpQVIRgeCzSf/naDLc= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1782118691; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OHlPcP7AaA+mR2J41ZgaKSwMbkv0cJTOMwCwXn+Kac0=; b=hLdv3rgT9kEA9UO6H86Z0RiS/hxj07cvkFIbUPtII3KLB8UWLvSfI++biUZwJMvvtc9J4p 5gJlE0CHDhrJDCCQ== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1782118689; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OHlPcP7AaA+mR2J41ZgaKSwMbkv0cJTOMwCwXn+Kac0=; b=O9p24WilK6N4iqUWCyssNo8wlg3Z9zXUMuu2WQSHyJllXnTm0oCD0auI71T6M8EQFXzusS 7F1rzNx3JgIRtFm3DcT7vovG2i2QoH5rISiTui0eZRkytatLgB/kJrFQNA4x91bzdI+eCf +SPf0RpdHHq6d7OnrRWH1dgW+Oehuaw= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1782118689; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OHlPcP7AaA+mR2J41ZgaKSwMbkv0cJTOMwCwXn+Kac0=; b=oH8VLp8jDDeF3TmAraYECKjF3U/9yg6Zx977cVs2Zc0qDiyu0dGo+ZjyNU6XXUY3oB0H60 o5kwxmY7UR5QlQAQ== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 90064779AB; Mon, 22 Jun 2026 08:58:09 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id LIbDISH5OGoYGQAAD6G6ig (envelope-from ); Mon, 22 Jun 2026 08:58:09 +0000 Message-ID: Date: Mon, 22 Jun 2026 10:58:09 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] [pre-commit] Add shellcheck To: Simon Marchi , gdb-patches@sourceware.org References: <20260618151957.76500-1-tdevries@suse.de> Content-Language: en-US From: Tom de Vries In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spamd-Result: default: False [-4.30 / 50.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; FUZZY_RATELIMITED(0.00)[rspamd.com]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; MID_RHS_MATCH_FROM(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[imap1.dmz-prg2.suse.org:helo,suse.de:mid] X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org On 6/19/26 7:56 PM, Simon Marchi wrote: > > > On 2026-06-19 07:19, Tom de Vries wrote: >> On 6/18/26 7:05 PM, Simon Marchi wrote: >>> >>> >>> On 2026-06-18 11:19, Tom de Vries wrote: >>>> I found a pure python implementation of shellcheck [1]. >>>> >>>> Use it to run shellcheck on scripts in the repo. >>>> >>>> Exclude any scripts that are not currently clean. >>>> >>>> Running it seems reasonably fast: >>>> ... >>>> $ pre-commit run shellcheck --all-files -v >>>> shellcheck...............................................................Passed >>>> - hook id: shellcheck >>>> - duration: 0.06s >>>> ... >>>> >>>> For information on other solutions, see this RFC [2]. >>>> >>>> [1] https://pypi.org/project/pureshellcheck/0.2.2/ >>>> [2] https://sourceware.org/pipermail/gdb-patches/2024-November/213400.html >>> >>> While I'm sympathetic to the use of pre-commit (I added the first >>> hooks), I'm starting to get a bit worried that we kind of blindly pull >>> hooks from random places without paying much attention. This is going >>> to get executed on the machines of many GDB devs, and probably some CI >>> too. >>> >>> I had this thought because this one has the "random project on github >>> vibes" (it appears to be a vibe coded project started a week ago). More >>> established projects (like black) are not immune to being compromised, >>> but they are easier to trust I guess. >>> >>> Assuming you gave a quick look at the code of this project and judge >>> that it's fine, >> >> Yeah, I did, that is, I cloned the github repository, checked it out at main/v0.2.2, and asked claude code to review it on safety aspects. > > Cool, thanks. > >>> how can we ensure that whatever pre-commit pulls is what >>> you reviewed? >> >> The mechanism to get the tool proposed in this patch is via pip. The pypi index mentions the github repo as source, so I'm relying on that. > > Ok I didn't get this at first. You specify the tool (and exact version) > using additional_dependencies, that downloads it in the venv, and then > it runs "pureshellcheck" since it's specified as the entry point. > > I previously thought it would get it from the github repo directly, but > no (the github repo URL isn't even mentioned anywhere in the hook). > > Getting a specific version from pypi seems safe-ish, in that it's not > possible (from what I've read) to swap a file with another, keeping the > same name. Although I read that it might be possible for someone to > upload a source package at first, and then only later upload a binary > one for the same version (which could differ and contain something > nasty). pip would then prefer the binary one as soon as it's uploaded. > > From what I understand, with hooks like flake8, pre-commit clones the > specified ref, then does "pip install" in it to install it in the venv. > So we use the flake8 code as specified by that ref, but its dependencies > are still downloaded from pypi, we can't get around that. > >>> We use a git tag, but is that sufficient? Could a >>> (malicious or compromised) project publish a tag, and then replaced that >>> tag with something else later? >> >> I suppose it's possible. > > I found out about > > $ pre-commit autoupdate --freeze > > it transforms: > > rev: 26.5.1 > > into > > rev: 4160603246a6b365d4a2af661c6d71b0a0f50478 # frozen: 26.5.1 > > It won't solve all the integrity concerns, but we might as well use > that, I don't see a downside. > Ack, that's what I proposed to use in v2. Note that the --freeze only works until the next autoupdate without freeze. So we'll likely need an autoupdate script that skips pureshellcheck, along the lines of: ... $ cat contrib/pre-commit-autoupdate.sh #!/bin/bash repos=($(grep "\- repo: " .pre-commit-config.yaml \ | awk '{print $3}')) for repo in "${repos[@]}"; do if [ "$repo" = local ]; then continue fi pre-commit autoupdate \ --repo "$repo" done ... >>> An alternative could be to point to a specific commit hash. A more >>> radical alternative would be to vendor (put in our repo) the code of the >>> hooks we use. >>> >> >> Yeah, that is safer. It would mean though using github as the source. But the repo as is doesn't have pre-commit hooks. I worked around that before by using my own github account (see commit 7f6c7a5bb37 ("[pre-commit] Add tclint hook")). I'll submit a v2 shortly that uses this approach. >> >> FWIW, I'm open to any other solutions. > > Could you maybe submit a .pre-commit-hooks.yaml to that project? And > then we can point to a specific tag/hash of that repo. If we don't hear > anything from them after a few weeks then we could consider your fork, > but if we can have the hooks upstream from the start it's less > maintenance. > I've done that, and submitted fixes for two problems. If that doesn't work out, perhaps some setup on our local sourceware forge owned by the gdb project rather than my personal github account would be better. Not sure how to get that setup though, I haven't used it yet. Thanks, - Tom > Simon