ci: hw: run the permission debugging script even if uhubctl fails
What changed, and why it matters
This change only affects Trezor's internal continuous-integration (CI) hardware-testing workflow. It tells the CI runner to keep going even if the 'uhubctl' USB power-control tool fails, so a follow-up permission-debugging script still runs. It does not change the firmware, wallet application, or any code that end users run, and it does not create a security vulnerability.
No security action needed. Review as a normal CI reliability improvement.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit modifies .github/workflows/core-hw.yml, adding ‘|| true’ to two shell commands that invoke ‘nix-shell –arg hardwareTest true –run uhubctl’. This makes the step succeed regardless of uhubctl’s exit code, ensuring the subsequent check-usb-permissions.py script executes and logs USB permission state. The change is purely CI pipeline robustness; no firmware, cryptographic, or user-facing code is altered.
Changed components
.github/workflows/core-hw.ymlInspect captured patch +2 / −2
### .github/workflows/core-hw.yml
@@ -94,7 +94,7 @@ jobs:
- uses: ./.github/actions/environment
- name: uhubctl
run: |
- nix-shell --arg hardwareTest true --run uhubctl
+ nix-shell --arg hardwareTest true --run uhubctl || true
nix-shell --arg hardwareTest true --run "uv run core/tools/check-usb-permissions.py" |& tee check-usb-permissions.log
- run: nix-shell --run "uv run make -C core build_firmware"
- run: nix-shell --arg hardwareTest true --run "uv run python ci/hardware_tests/bootstrap.py \"$TREZOR_MODEL\" core/build-xtask/artifacts/latest/firmware.bin"
@@ -191,7 +191,7 @@ jobs:
- uses: ./.github/actions/environment
- name: uhubctl
run: |
- nix-shell --arg hardwareTest true --run uhubctl
+ nix-shell --arg hardwareTest true --run uhubctl || true
nix-shell --arg hardwareTest true --run "uv run core/tools/check-usb-permissions.py" |& tee check-usb-permissions.log
- run: nix-shell --run "uv run legacy/script/setup"
- run: nix-shell --run "export PRODUCTION=0 && uv run legacy/script/cibuild"Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.