Commit f8856437fb

f8856437fbc3d303d39829b06bcde2e254db0d85

parent: 4e67adb664

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-19 16:25 UTC

smoke-account.sh: ignore the ssh config, rerunnable, unattended gpg

ssh -i alone still offered the admin's identity from ~/.ssh/config, so
profile set ran as the admin; -F /dev/null isolates the account's key.
gpg needs a loopback empty passphrase to generate without a pinentry.
Each step now skips what exists, so a failed run is rerun as is.

Layout: unified · split

README.org +1 −1
@@ -86,7 +86,7 @@ account's SSH key to =~/.ssh/gitbay-ios-smoke=. The token above is minted with
86that key: 86that key:
87 87
88#+begin_src sh 88#+begin_src sh
89ssh -i ~/.ssh/gitbay-ios-smoke -o IdentitiesOnly=yes -o ControlPath=none \ 89ssh -F /dev/null -i ~/.ssh/gitbay-ios-smoke -o IdentitiesOnly=yes \
90 git@gitbay.org token create --name ui-smoke --scope full --ttl 30d 90 git@gitbay.org token create --name ui-smoke --scope full --ttl 30d
91#+end_src 91#+end_src
92 92
gitbayUITests/smoke-account.sh +28 −18
@@ -1,11 +1,11 @@
1#!/bin/sh 1#!/bin/sh
2# Provision the ios-smoke account the live UI smoke suite runs as. Run 2# Provision the ios-smoke account the live UI smoke suite runs as. Run as
3# once, as an instance admin, where the gitbay CLI is signed in. It 3# an instance admin where the gitbay CLI is signed in; every step skips
4# creates the account with a fresh SSH key (~/.ssh/gitbay-ios-smoke), 4# what already exists, so a failed run is rerun as is. It creates the
5# makes it a krz admin, sets its profile description, registers a PGP 5# account with a fresh SSH key (~/.ssh/gitbay-ios-smoke), makes it a krz
6# key, and pushes the ios-smoke/ui-smoke-edit fixture that 6# admin, sets its profile description, registers a PGP key, and pushes
7# testBlameAndEditFlows edits. LiveSmokeUITests asserts on the same 7# the ios-smoke/ui-smoke-edit fixture that testBlameAndEditFlows edits.
8# values, so keep the two in step. 8# LiveSmokeUITests asserts on the same values, so keep the two in step.
9set -eu 9set -eu
10 10
11user=ios-smoke 11user=ios-smoke
@@ -15,24 +15,34 @@ pgp_email="$user+pgp@gitbay.org"
15 15
16[ -f "$key" ] || ssh-keygen -q -t ed25519 -N '' -C "$user" -f "$key" 16[ -f "$key" ] || ssh-keygen -q -t ed25519 -N '' -C "$user" -f "$key"
17 17
18gitbay admin user create "$user" --email "$user@gitbay.org" --verified --key - < "$key.pub" 18if ! gitbay admin user show "$user" --json > /dev/null 2>&1; then
19 gitbay admin user create "$user" --email "$user@gitbay.org" --verified --key - < "$key.pub"
20fi
19gitbay org members add krz "$user" --role admin 21gitbay org members add krz "$user" --role admin
20 22
21# Everything below runs as the account. No multiplexing: the CLI's 23# Everything below runs as the account. The user's ssh config is ignored:
22# control socket would otherwise answer as the admin. 24# its identities and control socket would answer as the admin.
25smoke_ssh="ssh -F /dev/null -i $key -o IdentitiesOnly=yes"
23as_smoke() { 26as_smoke() {
24 ssh -i "$key" -o IdentitiesOnly=yes -o ControlPath=none git@gitbay.org "$@" 27 $smoke_ssh git@gitbay.org "$@"
25} 28}
26 29
27as_smoke profile set --description "'$description'" 30as_smoke profile set --description "'$description'"
28 31
29# The PGP key is a display fixture; its private half is discarded. 32# The PGP key is a display fixture; its private half is discarded.
30gnupg=$(mktemp -d /tmp/pgp.XXXXXX) 33if ! as_smoke pgp list --json | grep -q "$pgp_email"; then
31GNUPGHOME=$gnupg gpg --batch --quiet --quick-generate-key "$user <$pgp_email>" ed25519 sign never 34 gnupg=$(mktemp -d /tmp/pgp.XXXXXX)
32GNUPGHOME=$gnupg gpg --armor --export "$pgp_email" | as_smoke pgp add 35 GNUPGHOME=$gnupg gpg --batch --quiet --pinentry-mode loopback --passphrase '' \
33GNUPGHOME=$gnupg gpgconf --kill all 36 --quick-generate-key "$user <$pgp_email>" ed25519 sign never
34rm -rf "$gnupg" 37 GNUPGHOME=$gnupg gpg --armor --export "$pgp_email" | as_smoke pgp add
38 GNUPGHOME=$gnupg gpgconf --kill all
39 rm -rf "$gnupg"
40fi
35 41
42if as_smoke repo show "$user/ui-smoke-edit" --json > /dev/null 2>&1; then
43 echo "$user/ui-smoke-edit exists"
44 exit 0
45fi
36as_smoke repo create "$user/ui-smoke-edit" 46as_smoke repo create "$user/ui-smoke-edit"
37work=$(mktemp -d) 47work=$(mktemp -d)
38git -C "$work" init -q -b main 48git -C "$work" init -q -b main
@@ -57,9 +67,9 @@ EOF
57git -C "$work" add -A 67git -C "$work" add -A
58git -C "$work" -c user.name="$user" -c user.email="$user@gitbay.org" -c commit.gpgsign=false \ 68git -C "$work" -c user.name="$user" -c user.email="$user@gitbay.org" -c commit.gpgsign=false \
59 commit -q -m 'fixture repo for the live smoke suite' 69 commit -q -m 'fixture repo for the live smoke suite'
60GIT_SSH_COMMAND="ssh -i $key -o IdentitiesOnly=yes -o ControlPath=none" \ 70GIT_SSH_COMMAND="$smoke_ssh" \
61 git -C "$work" push -q "ssh://git@gitbay.org/$user/ui-smoke-edit.git" main 71 git -C "$work" push -q "ssh://git@gitbay.org/$user/ui-smoke-edit.git" main
62rm -rf "$work" 72rm -rf "$work"
63 73
64echo "Mint the suite's token with:" 74echo "Mint the suite's token with:"
65echo " ssh -i $key -o IdentitiesOnly=yes -o ControlPath=none git@gitbay.org token create --name ui-smoke --scope full --ttl 30d" 75echo " $smoke_ssh git@gitbay.org token create --name ui-smoke --scope full --ttl 30d"