Fix the defects found by the live end-to-end run, add RC-017

- Close stdin for ssh, git, curl and the framework scripts, so a real ssh
  no longer swallows answers meant for later prompts.
- Count LICENSE and LICENSE + README.md (what Gitea creates) as content
  the script made, so a partly created repository can be reused.
- Document the observed token scopes (write:user for user-owned Gitea
  repositories) and the Gitea README.md in the README.
- Correct criterion 2 of MIL-002 (new Proposed version row).
- Record the run and the final security review as RC-017.
- Tests: stdin regression, initial_only reuse, other files count as
  content, example config needs its address edited.

Task: MIL-003#6
Task: MIL-002#1
Refs #20

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-05 21:41:47 +08:00
co-authored by Claude Sonnet 5.5
parent 0030334e5e
commit 613a288dea
13 changed files with 203 additions and 33 deletions
+10 -6
View File
@@ -28,7 +28,8 @@ check_gitea_license() {
}
# inspect_repository HOST: record in STATE[HOST_repo] whether the repository
# is free (does not exist), empty, license_only or not_empty.
# is free (does not exist), empty, initial_only (just the LICENSE and the
# README.md Gitea adds) or not_empty.
inspect_repository() {
local host="$1" owner name names
owner="$(repo_owner "$host")"
@@ -45,10 +46,13 @@ inspect_repository() {
return 0
fi
expect_status "cannot read the contents of the $(host_label "$host") repository $owner/$name" 200
names="$(json_values "$HTTP_BODY_FILE" name)"
case "$names" in
# Gitea adds a README.md of its own next to the LICENSE when it creates a
# repository with a license (seen on a real server), so both count as the
# content this script creates.
names="$(json_values "$HTTP_BODY_FILE" name | sort | tr '\n' ' ')"
case "${names% }" in
"") STATE[${host}_repo]="empty" ;;
LICENSE) STATE[${host}_repo]="license_only" ;;
"LICENSE" | "LICENSE README.md") STATE[${host}_repo]="initial_only" ;;
*) STATE[${host}_repo]="not_empty" ;;
esac
}
@@ -117,7 +121,7 @@ test_gitea_ssh() {
return 0
fi
output="$(ssh -p "$port" -o BatchMode=yes -o ConnectTimeout=5 \
-o StrictHostKeyChecking=yes -T "git@$host" 2>&1)" || status=$?
-o StrictHostKeyChecking=yes -T "git@$host" </dev/null 2>&1)" || status=$?
if ((status == 0)) || [[ $output == *"successfully authenticated"* ]]; then
STATE[is_ssh_ok]=1
STATE[ssh_note]="passed"
@@ -138,7 +142,7 @@ decide_existing_repositories() {
case "$state" in
free) ;;
empty) STATE[reuse_$host]=1 ;;
license_only)
initial_only)
if [[ $host == gitea ]] && ((PROJECT[has_github])); then
STATE[reuse_$host]=1
else