Remove everything a check run by hand leaves, the toolchain's files under its HOME too
This commit is contained in:
@@ -193,8 +193,9 @@ func ownerRepoOf(remote string) (string, string, string) {
|
||||
// when it is not this one.
|
||||
func removeWorkspace(image, workspace, user string) {
|
||||
if image != "" && user != fmt.Sprintf("%d:%d", os.Getuid(), os.Getgid()) {
|
||||
_ = exec.Command("docker", "run", "--rm", "--user", user, "--volume", workspace+":"+workspace, image,
|
||||
"rm", "-rf", workspace+"/check", workspace+"/go-cache", workspace+"/go-modules", workspace+"/git-credentials").Run()
|
||||
// Everything in it — the check's HOME is the workspace, so the toolchain's own files are there too.
|
||||
_ = exec.Command("docker", "run", "--rm", "--user", user, "--volume", workspace+":/workspace", image,
|
||||
"sh", "-c", "rm -rf /workspace/* /workspace/.[!.]*").Run()
|
||||
}
|
||||
_ = os.RemoveAll(workspace)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user