From 3c2d95501dba9511c71044335cedf089ea09bd67 Mon Sep 17 00:00:00 2001 From: Xore Date: Mon, 14 Sep 2026 20:00:51 +0200 Subject: [PATCH 1/2] fix(dashboard): keyboard-operable CardTag details toggle (#3183) Non-href card variant was mouse-only and its toggle rendered 0x0 with no focus target (WCAG 2.4.7/2.5.8). Replace with a real inner button: visible caret reflecting expanded state, aria-expanded/aria-label, closest() guard on the card click keeps nested interactives on native Enter/Space. Closes #3183 --- .../src/components/Investigate.tsx | 26 ++++++++++++++++--- 1 file changed, 23 insertions(+), 3 deletions(-) diff --git a/arcane/home/honeypot-dashboard/frontend-next/src/components/Investigate.tsx b/arcane/home/honeypot-dashboard/frontend-next/src/components/Investigate.tsx index ff67ad349..632566883 100644 --- a/arcane/home/honeypot-dashboard/frontend-next/src/components/Investigate.tsx +++ b/arcane/home/honeypot-dashboard/frontend-next/src/components/Investigate.tsx @@ -338,6 +338,9 @@ export function MasterDetailTable({ const desc = cardDesc?.(row) const CardTag = href ? 'a' : 'div' const cardProps = href ? { href } : { onClick: onRowClick(index) } + const titleClassName = primaryColumn?.className + ? `project-card__title ${primaryColumn.className}` + : 'project-card__title' return (
@@ -346,9 +349,26 @@ export function MasterDetailTable({ {icon} ) : null} - - {primaryColumn?.render(row)} - + {primaryColumn?.render(row)} + {!href && ( + + )} {badges ?
{badges}
: null}
{desc ?

{desc}

: null} From 9110463737424412bd9023c023136500d824b6a7 Mon Sep 17 00:00:00 2001 From: Xore Date: Fri, 25 Sep 2026 15:08:59 +0200 Subject: [PATCH 2/2] fix(ci): keep buildx cache group-writable across runner users The cache dir is shared by seven runner users, any of which can take any matrix row. The workflow's `umask 002` governs only its own shell; BuildKit writes index.json, oci-layout and blobs from inside its buildkitd container, so those files inherit that container's umask and land group-read-only. The default ACL on /var/buildx-cache is ANDed with it, collapsing the mask to r-- and leaving every runner except the last writer with: ERROR: failed to build: open /var/buildx-cache//oci-layout: permission denied Re-grant group write at the end of the prune step, which already runs unconditionally on every job (`if: always()`), so the invariant is repaired on the same run that would otherwise poison the next one. --- scripts/prune-buildx-cache.sh | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/scripts/prune-buildx-cache.sh b/scripts/prune-buildx-cache.sh index e898c09c0..fd613a133 100755 --- a/scripts/prune-buildx-cache.sh +++ b/scripts/prune-buildx-cache.sh @@ -63,3 +63,22 @@ fi after=$(du -sb "$dir" 2>/dev/null | cut -f1) echo "prune-buildx-cache: $dir after: ${after:-0} bytes" + +# Re-grant group write across the whole cache dir. The workflow sets +# umask 002 before mkdir, but that only governs the workflow's own shell: +# BuildKit writes index.json / oci-layout / blobs from inside its +# buildkitd container under that container's umask, so the files land +# group-read-only. /var/buildx-cache carries a default ACL +# (group:github-ci-runner:rwx), but an inherited entry is still ANDed with +# the creating process's umask, which collapses the ACL mask to r-- and +# leaves every runner user except the one that wrote the file unable to +# build the next image that shares this cache dir: +# +# ERROR: failed to build: open /var/buildx-cache//oci-layout: permission denied +# +# Seven runner users share this directory and any of them can take any +# matrix row, so the last writer must not own it exclusively. chmod is +# idempotent and cheap next to the du -sb passes above; without it the +# cache is poisoned for whichever runner does not happen to build next. +chmod -R g+rwX "$dir" 2>/dev/null || true +find "$dir" -type d -exec chmod g+s {} + 2>/dev/null || true