fix: deplace le venv semgrep hors de /tmp (fs noexec du runner) BUG-091
This commit is contained in:
+10
-10
@@ -149,8 +149,8 @@ jobs:
|
|||||||
pip install -U pip setuptools
|
pip install -U pip setuptools
|
||||||
pip install bandit pip-audit
|
pip install bandit pip-audit
|
||||||
pip install -r backend/requirements.txt
|
pip install -r backend/requirements.txt
|
||||||
python -m venv /tmp/semgrep-venv
|
python -m venv "$HOME/semgrep-venv"
|
||||||
/tmp/semgrep-venv/bin/pip install --quiet semgrep==1.157.0
|
"$HOME/semgrep-venv/bin/pip" install --quiet semgrep==1.157.0
|
||||||
|
|
||||||
- name: Bandit (SAST, bloquant — #87)
|
- name: Bandit (SAST, bloquant — #87)
|
||||||
# B105 est exclu (aligné avec [tool.bandit] de pyproject.toml :
|
# B105 est exclu (aligné avec [tool.bandit] de pyproject.toml :
|
||||||
@@ -159,10 +159,10 @@ jobs:
|
|||||||
run: bandit -r backend/ --skip B101,B105,B110,B310
|
run: bandit -r backend/ --skip B101,B105,B110,B310
|
||||||
|
|
||||||
- name: Diagnostic semgrep-core (BUG-091)
|
- name: Diagnostic semgrep-core (BUG-091)
|
||||||
# Le core est un exécutable natif : sur un CPU trop ancien il sort en
|
# Le core est un exécutable natif : selon le runner il sort en 127,
|
||||||
# 127 sans message exploitable. On trace CPU, taille/permissions du
|
# soit avec un message ISA (CPU trop ancien), soit sans message
|
||||||
# core et exécution brute pour distinguer un refus ISA/libc d'un
|
# (fs noexec, fichier absent, permissions). On trace CPU, options de
|
||||||
# simple fichier absent ou non exécutable.
|
# montage, taille/permissions du core et exécution brute.
|
||||||
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
|
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
|
||||||
run: |
|
run: |
|
||||||
echo "== CPU =="
|
echo "== CPU =="
|
||||||
@@ -172,10 +172,10 @@ jobs:
|
|||||||
if grep -qm1 " $f " /proc/cpuinfo; then echo -n "$f "; fi
|
if grep -qm1 " $f " /proc/cpuinfo; then echo -n "$f "; fi
|
||||||
done
|
done
|
||||||
echo
|
echo
|
||||||
echo "== disque =="
|
echo "== montages (noexec ?) =="
|
||||||
df -h /tmp | tail -1 || true
|
findmnt -no TARGET,OPTIONS / /tmp "$HOME" 2>/dev/null || cat /proc/mounts
|
||||||
echo "== core =="
|
echo "== core =="
|
||||||
CORE=$(/tmp/semgrep-venv/bin/python -c "import semgrep,os;print(os.path.join(os.path.dirname(semgrep.__file__),'bin','semgrep-core'))")
|
CORE=$("$HOME/semgrep-venv/bin/python" -c "import semgrep,os;print(os.path.join(os.path.dirname(semgrep.__file__),'bin','semgrep-core'))")
|
||||||
echo "chemin : $CORE"
|
echo "chemin : $CORE"
|
||||||
ls -l "$CORE" || echo "core absent"
|
ls -l "$CORE" || echo "core absent"
|
||||||
file "$CORE" || true
|
file "$CORE" || true
|
||||||
@@ -186,7 +186,7 @@ jobs:
|
|||||||
# Règles 100 % locales (semgrep-rules/, 8 règles) : aucun
|
# Règles 100 % locales (semgrep-rules/, 8 règles) : aucun
|
||||||
# téléchargement de registre (runner au réseau fragile).
|
# téléchargement de registre (runner au réseau fragile).
|
||||||
# Venv isolé (BUG-091) : cf. l'étape « Install dependencies ».
|
# Venv isolé (BUG-091) : cf. l'étape « Install dependencies ».
|
||||||
run: /tmp/semgrep-venv/bin/semgrep --config semgrep-rules/ backend/
|
run: $HOME/semgrep-venv/bin/semgrep --config semgrep-rules/ backend/
|
||||||
|
|
||||||
- name: Pip-audit (bloquant — #87)
|
- name: Pip-audit (bloquant — #87)
|
||||||
# Bloquant depuis T6 (#87) : dépendances qualifiées (mistune 3.3.3,
|
# Bloquant depuis T6 (#87) : dépendances qualifiées (mistune 3.3.3,
|
||||||
|
|||||||
+16
-1
@@ -6,7 +6,7 @@ Format basé sur [Keep a Changelog](https://keepachangelog.com/fr/1.1.0/),
|
|||||||
et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||||
|
|
||||||
> **En cours de développement** : les changements à venir sont listés dans la section
|
> **En cours de développement** : les changements à venir sont listés dans la section
|
||||||
> [Unreleased](#unreleased). La dernière version livrée est **2.39.5**.
|
> [Unreleased](#unreleased). La dernière version livrée est **2.39.6**.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -14,6 +14,21 @@ et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## [2.39.6] — 2026-09-29
|
||||||
|
|
||||||
|
### Correction
|
||||||
|
|
||||||
|
- **BUG-091 (suite) — semgrep-core s'exécutait depuis un venv sous `/tmp`.**
|
||||||
|
Le binaire natif de semgrep sortait en 127 sans message, alors que sa
|
||||||
|
version était bien compatible avec le CPU du runner (core statique,
|
||||||
|
baseline x86-64 v1) : le filesystem `/tmp` du runner est monté `noexec`
|
||||||
|
et le noyau refuse l'exécution sans message exploitable. Le venv isolé
|
||||||
|
est donc créé dans `$HOME`, et l'étape de diagnostic du job security
|
||||||
|
trace désormais CPU, options de montage, taille/permissions du core et
|
||||||
|
exécution brute.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## [2.39.5] — 2026-09-29
|
## [2.39.5] — 2026-09-29
|
||||||
|
|
||||||
### Correction
|
### Correction
|
||||||
|
|||||||
+3
-3
@@ -4,7 +4,7 @@
|
|||||||
|
|
||||||
**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.
|
**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.
|
||||||
|
|
||||||
[]()
|
[]()
|
||||||
[](https://opensource.org/licenses/MIT)
|
[](https://opensource.org/licenses/MIT)
|
||||||
[](https://www.docker.com/)
|
[](https://www.docker.com/)
|
||||||
[](https://www.python.org/)
|
[](https://www.python.org/)
|
||||||
@@ -976,8 +976,8 @@ Ce projet est sous licence **MIT** — voir le fichier [LICENSE](LICENSE) pour l
|
|||||||
|
|
||||||
## 📝 Changelog
|
## 📝 Changelog
|
||||||
|
|
||||||
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.5).
|
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.6).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
*Projet : ObsiGate | Version : 2.39.5 | Dernière mise à jour : Septembre 2026*
|
*Projet : ObsiGate | Version : 2.39.6 | Dernière mise à jour : Septembre 2026*
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
**Ultra-light web gateway for your Obsidian vaults** — Access, browse, and search all your Obsidian notes from any device via a modern, responsive web interface.
|
**Ultra-light web gateway for your Obsidian vaults** — Access, browse, and search all your Obsidian notes from any device via a modern, responsive web interface.
|
||||||
|
|
||||||
[]()
|
[]()
|
||||||
[](https://opensource.org/licenses/MIT)
|
[](https://opensource.org/licenses/MIT)
|
||||||
[](https://www.docker.com/)
|
[](https://www.docker.com/)
|
||||||
[](https://www.python.org/)
|
[](https://www.python.org/)
|
||||||
@@ -1151,8 +1151,8 @@ This project is licensed under the **MIT License** - see the [LICENSE](LICENSE)
|
|||||||
|
|
||||||
## 📝 Changelog
|
## 📝 Changelog
|
||||||
|
|
||||||
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.5).
|
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.6).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
*Project: ObsiGate | Version: 2.39.5 | Last updated: September 2026*
|
*Project: ObsiGate | Version: 2.39.6 | Last updated: September 2026*
|
||||||
|
|||||||
Generated
+1
-1
@@ -2626,7 +2626,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "obsigate-desktop"
|
name = "obsigate-desktop"
|
||||||
version = "2.39.5"
|
version = "2.39.6"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"chrono",
|
"chrono",
|
||||||
"env_logger",
|
"env_logger",
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "obsigate-desktop"
|
name = "obsigate-desktop"
|
||||||
version = "2.39.5"
|
version = "2.39.6"
|
||||||
description = "ObsiGate Desktop — Porte d'entrée native pour vos vaults Obsidian"
|
description = "ObsiGate Desktop — Porte d'entrée native pour vos vaults Obsidian"
|
||||||
authors = ["Bruno Charest"]
|
authors = ["Bruno Charest"]
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"$schema": "https://raw.githubusercontent.com/nicedoc/obsigate/main/desktop/tauri.conf.schema.json",
|
"$schema": "https://raw.githubusercontent.com/nicedoc/obsigate/main/desktop/tauri.conf.schema.json",
|
||||||
"productName": "ObsiGate",
|
"productName": "ObsiGate",
|
||||||
"version": "2.39.5",
|
"version": "2.39.6",
|
||||||
"identifier": "com.obsigate.desktop",
|
"identifier": "com.obsigate.desktop",
|
||||||
"build": {
|
"build": {
|
||||||
"frontendDist": "../frontend",
|
"frontendDist": "../frontend",
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
# ObsiGate — Roadmap
|
# ObsiGate — Roadmap
|
||||||
|
|
||||||
> **Version :** 2.39.5 | **Dernière mise à jour :** 2026-09-29
|
> **Version :** 2.39.6 | **Dernière mise à jour :** 2026-09-29
|
||||||
> **Ce fichier ne contient que le travail à venir** (🔵 En cours + ⚪ Backlog) et un index compact
|
> **Ce fichier ne contient que le travail à venir** (🔵 En cours + ⚪ Backlog) et un index compact
|
||||||
> vers les fonctionnalités livrées.
|
> vers les fonctionnalités livrées.
|
||||||
> - **Méthode de livraison à appliquer pour toute tâche : [DELIVERY_WORKFLOW.md](./DELIVERY_WORKFLOW.md)**
|
> - **Méthode de livraison à appliquer pour toute tâche : [DELIVERY_WORKFLOW.md](./DELIVERY_WORKFLOW.md)**
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "obsigate",
|
"name": "obsigate",
|
||||||
"version": "2.39.5",
|
"version": "2.39.6",
|
||||||
"description": "**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.",
|
"description": "**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.",
|
||||||
"main": "patch.js",
|
"main": "patch.js",
|
||||||
"directories": {
|
"directories": {
|
||||||
|
|||||||
Reference in New Issue
Block a user