[Merged by Bors] - ci: Secure proofwidgets fetches on cache get#35463
Closed
marcelolynch wants to merge 3 commits intomasterfrom
Closed
[Merged by Bors] - ci: Secure proofwidgets fetches on cache get#35463marcelolynch wants to merge 3 commits intomasterfrom
marcelolynch wants to merge 3 commits intomasterfrom
Conversation
PR summary ac6e242131Import changes for modified filesNo significant changes to the import graph Import changes for all files
Declarations diff
You can run this locally as follows## summary with just the declaration names:
./scripts/declarations_diff.sh <optional_commit>
## more verbose report:
./scripts/declarations_diff.sh long <optional_commit>The doc-module for No changes to technical debt.You can run this locally as
Workflow documentation reminderThis PR modifies files under Modified workflow files:
|
Contributor
Author
joneugster
approved these changes
Feb 18, 2026
Contributor
joneugster
left a comment
There was a problem hiding this comment.
LGTM, thanks!
maintainer merge
|
🚀 Pull request has been placed on the maintainer queue by joneugster. |
Contributor
|
Thanks! |
mathlib-bors bot
pushed a commit
that referenced
this pull request
Feb 18, 2026
When calling lake exe cache get in the CI we happily say ["only runs cache get from tools-branch, so doesn't need to be inside landrun"](https://github.com/leanprover-community/mathlib4/blob/a90320db82953c5554b9065b7304c10e3b4548a5/.github/workflows/build_template.yml#L293). However, it turns out that cache get is not that innocent: it [performs a full lake -v build proofwidgets:release](https://github.com/leanprover-community/mathlib4/blob/a90320db82953c5554b9065b7304c10e3b4548a5/Cache/Requests.lean#L451) in the PR branch context. This means I can point proofwidgets in the lake-manifest.json to whatever I want, and now run arbitrary code outside of landrun. To protect against this, this PR: - adds an dependency verification for proofwidget, so that it only comes from the 'trusted' source - tries to avoid the build altogether in `cache get`, defaulting to skipping in github actions, but adding a flag so that we can do it if we want
Contributor
|
Pull request successfully merged into master. Build succeeded: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When calling lake exe cache get in the CI we happily say "only runs cache get from tools-branch, so doesn't need to be inside landrun".
However, it turns out that cache get is not that innocent: it performs a full lake -v build proofwidgets:release in the PR branch context. This means I can point proofwidgets in the lake-manifest.json to whatever I want, and now run arbitrary code outside of landrun.
To protect against this, this PR:
cache get, defaulting to skipping in github actions, but adding a flag so that we can do it if we want