Commit f8856437fb

f8856437fbc3d303d39829b06bcde2e254db0d85

parent: 4e67adb664

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-19 16:25 UTC

smoke-account.sh: ignore the ssh config, rerunnable, unattended gpg

ssh -i alone still offered the admin's identity from ~/.ssh/config, so
profile set ran as the admin; -F /dev/null isolates the account's key.
gpg needs a loopback empty passphrase to generate without a pinentry.
Each step now skips what exists, so a failed run is rerun as is.

Layout: unified · split

README.org +1 −1
@@ -86,7 +86,7 @@ account's SSH key to =~/.ssh/gitbay-ios-smoke=. The token above is minted with
8686that key:
8787
8888#+begin_src sh
89ssh -i ~/.ssh/gitbay-ios-smoke -o IdentitiesOnly=yes -o ControlPath=none \
89ssh -F /dev/null -i ~/.ssh/gitbay-ios-smoke -o IdentitiesOnly=yes \
9090 git@gitbay.org token create --name ui-smoke --scope full --ttl 30d
9191#+end_src
9292
gitbayUITests/smoke-account.sh +28 −18
@@ -1,11 +1,11 @@
11#!/bin/sh
2# Provision the ios-smoke account the live UI smoke suite runs as. Run
3# once, as an instance admin, where the gitbay CLI is signed in. It
4# creates the account with a fresh SSH key (~/.ssh/gitbay-ios-smoke),
5# makes it a krz admin, sets its profile description, registers a PGP
6# key, and pushes the ios-smoke/ui-smoke-edit fixture that
7# testBlameAndEditFlows edits. LiveSmokeUITests asserts on the same
8# values, so keep the two in step.
2# Provision the ios-smoke account the live UI smoke suite runs as. Run as
3# an instance admin where the gitbay CLI is signed in; every step skips
4# what already exists, so a failed run is rerun as is. It creates the
5# account with a fresh SSH key (~/.ssh/gitbay-ios-smoke), makes it a krz
6# admin, sets its profile description, registers a PGP key, and pushes
7# the ios-smoke/ui-smoke-edit fixture that testBlameAndEditFlows edits.
8# LiveSmokeUITests asserts on the same values, so keep the two in step.
99set -eu
1010
1111user=ios-smoke
@@ -15,24 +15,34 @@ pgp_email="$user+pgp@gitbay.org"
1515
1616[ -f "$key" ] || ssh-keygen -q -t ed25519 -N '' -C "$user" -f "$key"
1717
18gitbay admin user create "$user" --email "$user@gitbay.org" --verified --key - < "$key.pub"
18if ! gitbay admin user show "$user" --json > /dev/null 2>&1; then
19 gitbay admin user create "$user" --email "$user@gitbay.org" --verified --key - < "$key.pub"
20fi
1921gitbay org members add krz "$user" --role admin
2022
21# Everything below runs as the account. No multiplexing: the CLI's
22# control socket would otherwise answer as the admin.
23# Everything below runs as the account. The user's ssh config is ignored:
24# its identities and control socket would answer as the admin.
25smoke_ssh="ssh -F /dev/null -i $key -o IdentitiesOnly=yes"
2326as_smoke() {
24 ssh -i "$key" -o IdentitiesOnly=yes -o ControlPath=none git@gitbay.org "$@"
27 $smoke_ssh git@gitbay.org "$@"
2528}
2629
2730as_smoke profile set --description "'$description'"
2831
2932# The PGP key is a display fixture; its private half is discarded.
30gnupg=$(mktemp -d /tmp/pgp.XXXXXX)
31GNUPGHOME=$gnupg gpg --batch --quiet --quick-generate-key "$user <$pgp_email>" ed25519 sign never
32GNUPGHOME=$gnupg gpg --armor --export "$pgp_email" | as_smoke pgp add
33GNUPGHOME=$gnupg gpgconf --kill all
34rm -rf "$gnupg"
33if ! as_smoke pgp list --json | grep -q "$pgp_email"; then
34 gnupg=$(mktemp -d /tmp/pgp.XXXXXX)
35 GNUPGHOME=$gnupg gpg --batch --quiet --pinentry-mode loopback --passphrase '' \
36 --quick-generate-key "$user <$pgp_email>" ed25519 sign never
37 GNUPGHOME=$gnupg gpg --armor --export "$pgp_email" | as_smoke pgp add
38 GNUPGHOME=$gnupg gpgconf --kill all
39 rm -rf "$gnupg"
40fi
3541
42if as_smoke repo show "$user/ui-smoke-edit" --json > /dev/null 2>&1; then
43 echo "$user/ui-smoke-edit exists"
44 exit 0
45fi
3646as_smoke repo create "$user/ui-smoke-edit"
3747work=$(mktemp -d)
3848git -C "$work" init -q -b main
@@ -57,9 +67,9 @@ EOF
5767git -C "$work" add -A
5868git -C "$work" -c user.name="$user" -c user.email="$user@gitbay.org" -c commit.gpgsign=false \
5969 commit -q -m 'fixture repo for the live smoke suite'
60GIT_SSH_COMMAND="ssh -i $key -o IdentitiesOnly=yes -o ControlPath=none" \
70GIT_SSH_COMMAND="$smoke_ssh" \
6171 git -C "$work" push -q "ssh://git@gitbay.org/$user/ui-smoke-edit.git" main
6272rm -rf "$work"
6373
6474echo "Mint the suite's token with:"
65echo " ssh -i $key -o IdentitiesOnly=yes -o ControlPath=none git@gitbay.org token create --name ui-smoke --scope full --ttl 30d"
75echo " $smoke_ssh git@gitbay.org token create --name ui-smoke --scope full --ttl 30d"