Skip to content
1,024 linesCodeBlameRaw
1//! Artifacts and the cache: `actions/upload-artifact`, its `merge`,
2//! `actions/download-artifact` and `actions/cache`, done natively against
3//! g1t. Artifacts belong to the run; cache entries to the repository, found
4//! by exact key or by the newest under a `restore-keys` prefix.
5//!
6//! An artifact is a ZIP file, as GitHub's v4 actions make it (zip.rs), of
7//! the files its `path` finds (glob.rs): uploaded in parts with its SHA-256,
8//! and downloaded straight to a file before it is unpacked.
9//!
10//! A cache entry is a tar archive, compressed with zstd where the machine
11//! has it (gzip otherwise), of up to 2 GB: uploaded in parts, and
12//! downloaded straight to a file. Its `path` takes globs (`**` included)
13//! and `!` patterns that leave paths out, as `actions/cache` does.
14
15use std::collections::BTreeMap;
16use std::io::{Read, Write};
17use std::path::Path;
18use std::process::Command;
19use std::time::{Duration, Instant};
20
21use sha2::{Digest, Sha256};
22
23use super::process::{self, Commands, Ended};
24use super::{Job, Post, PostRun, glob, zip};
25
26/// The largest cache entry, compressed (`g1t_contracts::actions::CACHE_MAX_ENTRY_BYTES`).
27const MAX_CACHE_ENTRY: u64 = 2 * 1024 * 1024 * 1024;
28
29fn lines(text: &str) -> Vec<String> {
30 text.lines().map(str::trim).filter(|line| !line.is_empty() && !line.starts_with('#')).map(str::to_owned).collect()
31}
32
33fn quote(text: &str) -> String {
34 format!("'{}'", text.replace('\'', "'\\''"))
35}
36
37impl Job {
38 fn url(&self, rest: &str) -> String {
39 format!("{}/actions/jobs/{}/{rest}", self.log.api.base, self.log.api.job)
40 }
41
42 fn auth(&self) -> String {
43 format!("Bearer {}", self.log.api.token)
44 }
45
46 /// Runs a shell line, logging its output; whether it succeeded.
47 fn shell(&mut self, script: &str) -> bool {
48 let mut command = Command::new("bash");
49 command.args(["-c", script]).current_dir(&self.workspace);
50 let mut commands = Commands::default();
51 matches!(process::run(command, Duration::from_secs(1800), &mut self.log, &mut commands), Ok(Ended::Exited(0)))
52 }
53
54 /// Downloads into `file`, as it comes; `Ok(None)` when there is
55 /// nothing there.
56 fn download(&mut self, rest: &str, file: &Path) -> Result<Option<String>, String> {
57 let response = match ureq::get(&self.url(rest)).set("authorization", &self.auth()).timeout(Duration::from_secs(1800)).call() {
58 Ok(response) => response,
59 Err(ureq::Error::Status(404, _)) => return Ok(None),
60 Err(error) => return Err(error.to_string()),
61 };
62 let matched = response.header("x-g1t-key").map(str::to_owned).unwrap_or_default();
63 let mut out = std::fs::File::create(file).map_err(|e| e.to_string())?;
64 std::io::copy(&mut response.into_reader().take(MAX_CACHE_ENTRY + 1024), &mut out).map_err(|e| e.to_string())?;
65 Ok(Some(matched))
66 }
67
68 /// Saves `file` as the cache entry `key`, in parts. `Ok(false)` when
69 /// the key is already cached.
70 fn upload_cache(&mut self, key: &str, file: &Path) -> Result<bool, String> {
71 let size = std::fs::metadata(file).map_err(|e| e.to_string())?.len();
72 if size > MAX_CACHE_ENTRY {
73 return Err(format!("it is {} MB, more than a cache entry may be ({} MB)", size / 1_048_576, MAX_CACHE_ENTRY / 1_048_576));
74 }
75 let started = match ureq::post(&self.url(&format!("cache/uploads?key={}&size={size}", urlencode(key))))
76 .set("authorization", &self.auth())
77 .timeout(Duration::from_secs(60))
78 .call()
79 {
80 Ok(response) => response.into_json::<serde_json::Value>().map_err(|e| e.to_string())?,
81 Err(ureq::Error::Status(409, _)) => return Ok(false),
82 Err(ureq::Error::Status(_, response)) => return Err(refusal(response)),
83 Err(error) => return Err(error.to_string()),
84 };
85 let id = started["id"].as_str().unwrap_or_default().to_owned();
86 let upload = started["upload"].as_str().unwrap_or_default().to_owned();
87 let part_bytes = started["part_bytes"].as_u64().filter(|n| *n > 0).unwrap_or(32 * 1024 * 1024);
88 let base = format!("cache/uploads/{}", urlencode(&id));
89 let sent = self.send_parts(&base, &upload, file, part_bytes);
90 let parts = match sent {
91 Ok(parts) => parts,
92 Err(error) => {
93 let _ = ureq::delete(&self.url(&format!("{base}?upload={}", urlencode(&upload)))).set("authorization", &self.auth()).call();
94 return Err(error);
95 }
96 };
97 ureq::post(&self.url(&format!("{base}/complete?upload={}", urlencode(&upload))))
98 .set("authorization", &self.auth())
99 .timeout(Duration::from_secs(120))
100 .send_json(serde_json::json!({ "size": size, "parts": parts }))
101 .map_err(|e| match e {
102 ureq::Error::Status(_, response) => refusal(response),
103 other => other.to_string(),
104 })?;
105 Ok(true)
106 }
107
108 /// Sends `file` in parts of `part_bytes`; each part's number and etag.
109 fn send_parts(&mut self, base: &str, upload: &str, file: &Path, part_bytes: u64) -> Result<Vec<serde_json::Value>, String> {
110 let mut reader = std::fs::File::open(file).map_err(|e| e.to_string())?;
111 let mut parts = Vec::new();
112 let mut buffer = vec![0u8; part_bytes as usize];
113 for number in 1u32.. {
114 let mut filled = 0;
115 while filled < buffer.len() {
116 let read = reader.read(&mut buffer[filled..]).map_err(|e| e.to_string())?;
117 if read == 0 {
118 break;
119 }
120 filled += read;
121 }
122 if filled == 0 && number > 1 {
123 break;
124 }
125 let url = self.url(&format!("{base}/{number}?upload={}", urlencode(upload)));
126 // A part that fails is sent again, twice at most.
127 let mut tries = 0;
128 let answer = loop {
129 tries += 1;
130 match ureq::put(&url).set("authorization", &self.auth()).timeout(Duration::from_secs(600)).send_bytes(&buffer[..filled]) {
131 Ok(response) => break response.into_json::<serde_json::Value>().map_err(|e| e.to_string())?,
132 Err(ureq::Error::Status(status, response)) if status < 500 => return Err(refusal(response)),
133 Err(error) if tries >= 3 => return Err(error.to_string()),
134 Err(_) => std::thread::sleep(Duration::from_secs(2 * tries)),
135 }
136 };
137 parts.push(serde_json::json!({ "part": number, "etag": answer["etag"] }));
138 if filled < buffer.len() {
139 break;
140 }
141 }
142 Ok(parts)
143 }
144
145 /// A value of the `github` context, as text.
146 fn github_value(&self, key: &str) -> String {
147 match self.contexts.get("github").and_then(|github| github.get(key)) {
148 Some(serde_json::Value::String(text)) => text.clone(),
149 Some(serde_json::Value::Null) | None => String::new(),
150 Some(other) => other.to_string(),
151 }
152 }
153
154 fn home(&self) -> String {
155 self.base_env_value("HOME").unwrap_or_else(|| "/home/node".into())
156 }
157
158 /// `actions/upload-artifact`: the files `path` names, packed into one
159 /// ZIP and uploaded in parts.
160 pub(crate) fn upload_artifact(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
161 let name = input(with, "name").unwrap_or("artifact").to_owned();
162 let missing = input(with, "if-no-files-found").unwrap_or("warn").to_ascii_lowercase();
163 let checked = check_name(&name)
164 .and_then(|()| keep(with, true))
165 .and_then(|keep| if matches!(missing.as_str(), "warn" | "error" | "ignore") { Ok(keep) } else { Err(format!("`if-no-files-found` is `{missing}`; it takes warn, error or ignore.")) });
166 let keep = match checked {
167 Ok(keep) => keep,
168 Err(message) => {
169 self.log.line(&format!("##[error]{message}"));
170 return (false, BTreeMap::new());
171 }
172 };
173 let paths = lines(input(with, "path").unwrap_or_default());
174 let found = glob::find(&paths, &self.workspace.display().to_string(), &self.home(), keep.hidden);
175 if found.files.is_empty() {
176 let message = format!("No files were found with the provided path: {}. No artifacts will be uploaded.", paths.join(", "));
177 return match missing.as_str() {
178 "error" => {
179 self.log.line(&format!("##[error]{message}"));
180 (false, BTreeMap::new())
181 }
182 "ignore" => {
183 self.log.line(&message);
184 (true, BTreeMap::new())
185 }
186 _ => {
187 self.log.line(&format!("##[warning]{message}"));
188 (true, BTreeMap::new())
189 }
190 };
191 }
192 self.log.line(&format!("Found {} with the provided path, stored relative to {}.", count(found.files.len(), "file"), found.root));
193 self.send_artifact(&name, &found.files, &keep)
194 }
195
196 /// Packs `files` into a ZIP and uploads it as the artifact `name`;
197 /// whether it worked, and the outputs `upload-artifact` sets.
198 fn send_artifact(&mut self, name: &str, files: &[(String, std::path::PathBuf)], keep: &Keep) -> (bool, BTreeMap<String, String>) {
199 let archive = self.temp.join(format!("artifact-{}.zip", super::rand_id()));
200 let sent = zip::write(&archive, files, keep.level)
201 .map_err(|e| format!("The files could not be packed: {e}"))
202 .and_then(|packed| self.post_artifact(name, &archive, keep).map(|done| (packed, done)));
203 let _ = std::fs::remove_file(&archive);
204 let (packed, done) = match sent {
205 Ok(sent) => sent,
206 Err(error) => {
207 self.log.line(&format!("##[error]{error}"));
208 return (false, BTreeMap::new());
209 }
210 };
211 let kept = done.retention.map(|days| format!(" It is kept for {}.", count(days as usize, "day"))).unwrap_or_default();
212 self.log.line(&format!("Uploaded artifact {name} ({}, {}).{kept}", megabytes(packed.size), count(packed.files, "file")));
213 let url = format!(
214 "{}/{}/actions/runs/{}/artifacts/{}",
215 self.github_value("server_url").trim_end_matches('/'),
216 self.github_value("repository"),
217 self.github_value("run_id"),
218 done.id
219 );
220 self.log.line(&format!("Artifact download URL: {url}"));
221 let mut outputs = BTreeMap::new();
222 outputs.insert("artifact-id".into(), done.id.to_string());
223 outputs.insert("artifact-url".into(), url);
224 outputs.insert("artifact-digest".into(), done.digest);
225 (true, outputs)
226 }
227
228 /// Uploads the ZIP file `archive` as the artifact `name`, in parts,
229 /// giving the upload up when a part or the end fails.
230 fn post_artifact(&mut self, name: &str, archive: &Path, keep: &Keep) -> Result<Sent, String> {
231 let size = std::fs::metadata(archive).map_err(|e| e.to_string())?.len();
232 let digest = sha256_file(archive).map_err(|e| e.to_string())?;
233 let query = format!(
234 "artifacts/uploads?name={}&size={size}&retention_days={}&overwrite={}&format=zip",
235 urlencode(name),
236 keep.retention,
237 keep.overwrite
238 );
239 let failed = |e: ureq::Error| match e {
240 ureq::Error::Status(_, response) => format!("The artifact could not be uploaded: {}", refusal(response)),
241 other => format!("The artifact could not be uploaded: {other}"),
242 };
243 let started = ureq::post(&self.url(&query))
244 .set("authorization", &self.auth())
245 .timeout(Duration::from_secs(60))
246 .call()
247 .map_err(failed)?
248 .into_json::<serde_json::Value>()
249 .map_err(|e| e.to_string())?;
250 let id = number(&started["id"]).ok_or("g1t did not say which artifact the upload is")?;
251 let upload = started["upload"].as_str().unwrap_or_default().to_owned();
252 let part_bytes = started["part_bytes"].as_u64().filter(|n| *n > 0).unwrap_or(32 * 1024 * 1024);
253 let retention = started["retention_days"].as_u64();
254 if let Some(applied) = retention
255 && keep.retention != 0
256 && applied != u64::from(keep.retention)
257 {
258 self.log.line(&format!(
259 "##[notice]The artifact is kept for {}, not the {} asked for: the most this repository keeps artifacts.",
260 count(applied as usize, "day"),
261 keep.retention
262 ));
263 }
264 let base = format!("artifacts/uploads/{id}");
265 let give_up = |job: &Job| {
266 let _ = ureq::delete(&job.url(&format!("{base}?upload={}", urlencode(&upload)))).set("authorization", &job.auth()).call();
267 };
268 let parts = match self.send_parts(&base, &upload, archive, part_bytes) {
269 Ok(parts) => parts,
270 Err(error) => {
271 give_up(self);
272 return Err(format!("The artifact could not be uploaded: {error}"));
273 }
274 };
275 let done = ureq::post(&self.url(&format!("{base}/complete?upload={}", urlencode(&upload))))
276 .set("authorization", &self.auth())
277 .timeout(Duration::from_secs(120))
278 .send_json(serde_json::json!({ "size": size, "parts": parts, "digest": format!("sha256:{digest}") }));
279 let done = match done {
280 Ok(response) => response.into_json::<serde_json::Value>().unwrap_or_default(),
281 Err(error) => {
282 give_up(self);
283 return Err(failed(error));
284 }
285 };
286 Ok(Sent { id: number(&done["id"]).unwrap_or(id), digest, retention: retention.map(|d| d as u32).or((keep.retention != 0).then_some(keep.retention)) })
287 }
288
289 /// The artifacts of this run, or of the run `run_id` of this
290 /// repository; one per name, the newest.
291 fn list_artifacts(&mut self, run_id: Option<&str>) -> Result<Vec<Listed>, String> {
292 let rest = match run_id {
293 Some(run) => format!("artifacts?run_id={}", urlencode(run)),
294 None => "artifacts".to_owned(),
295 };
296 let listed = ureq::get(&self.url(&rest))
297 .set("authorization", &self.auth())
298 .timeout(Duration::from_secs(60))
299 .call()
300 .map_err(|e| match e {
301 ureq::Error::Status(_, response) => refusal(response),
302 other => other.to_string(),
303 })?
304 .into_json::<Vec<serde_json::Value>>()
305 .map_err(|e| e.to_string())?;
306 Ok(newest(listed.iter().filter_map(Listed::from_json).collect()))
307 }
308
309 /// Downloads an artifact to a file, as it comes, and unpacks it into
310 /// `into`.
311 fn fetch_artifact(&mut self, artifact: &Listed, into: &Path) -> Result<(), String> {
312 let file = self.temp.join(format!("download-{}.zip", super::rand_id()));
313 let fetched = self.fetch_to(artifact, &file).and_then(|format| {
314 if format == "tgz" {
315 std::fs::create_dir_all(into).map_err(|e| e.to_string())?;
316 let script = format!("tar -xzf {} -C {}", quote(&file.display().to_string()), quote(&into.display().to_string()));
317 if self.shell(&script) { Ok(()) } else { Err("it could not be unpacked".into()) }
318 } else {
319 zip::extract(&file, into).map(|_| ()).map_err(|e| format!("it could not be unpacked: {e}"))
320 }
321 });
322 let _ = std::fs::remove_file(&file);
323 fetched
324 }
325
326 /// Downloads an artifact into `file`, checking its digest; how it is
327 /// packed, `zip` or `tgz`.
328 fn fetch_to(&mut self, artifact: &Listed, file: &Path) -> Result<String, String> {
329 let response = match ureq::get(&self.url(&format!("artifacts/{}/download", artifact.id)))
330 .set("authorization", &self.auth())
331 .timeout(Duration::from_secs(4 * 3600))
332 .call()
333 {
334 Ok(response) => response,
335 Err(ureq::Error::Status(404, _)) => return Err("it is gone: it expired or was deleted".into()),
336 Err(ureq::Error::Status(_, response)) => return Err(refusal(response)),
337 Err(error) => return Err(error.to_string()),
338 };
339 let format = response.header("x-g1t-format").map(str::to_owned).unwrap_or_else(|| artifact.format.clone());
340 let mut reader = response.into_reader();
341 let mut out = std::io::BufWriter::new(std::fs::File::create(file).map_err(|e| e.to_string())?);
342 let mut hasher = Sha256::new();
343 let mut buffer = vec![0u8; 256 * 1024];
344 loop {
345 let n = reader.read(&mut buffer).map_err(|e| e.to_string())?;
346 if n == 0 {
347 break;
348 }
349 hasher.update(&buffer[..n]);
350 out.write_all(&buffer[..n]).map_err(|e| e.to_string())?;
351 }
352 out.flush().map_err(|e| e.to_string())?;
353 let got = hex::encode(hasher.finalize());
354 if let Some(expected) = artifact.digest.as_deref().map(|d| d.trim_start_matches("sha256:"))
355 && !expected.is_empty()
356 && !expected.eq_ignore_ascii_case(&got)
357 {
358 self.log.line(&format!("##[warning]Artifact {} does not match its digest (sha256:{got}, not sha256:{expected}): it may have been changed since it was uploaded.", artifact.name));
359 }
360 Ok(format)
361 }
362
363 /// Where artifacts are downloaded: `path`, under the workspace unless
364 /// absolute, `~` the home folder.
365 fn download_dir(&self, path: Option<&str>) -> std::path::PathBuf {
366 match path {
367 None => self.workspace.clone(),
368 Some(path) => {
369 let home = self.home();
370 let path = if path == "~" {
371 home
372 } else if let Some(rest) = path.strip_prefix("~/") {
373 format!("{}/{rest}", home.trim_end_matches('/'))
374 } else {
375 path.to_owned()
376 };
377 self.workspace.join(path)
378 }
379 }
380 }
381
382 /// `actions/download-artifact`: one artifact by name straight into
383 /// `path`, or the run's artifacts (by `pattern` or `artifact-ids`) each
384 /// into a folder of its name, or all into `path` with `merge-multiple`.
385 pub(crate) fn download_artifact(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
386 let fail = |job: &mut Job, message: &str| {
387 job.log.line(&format!("##[error]{message}"));
388 (false, BTreeMap::new())
389 };
390 let name = input(with, "name");
391 let ids = match artifact_ids(input(with, "artifact-ids").unwrap_or_default()) {
392 Ok(ids) => ids,
393 Err(message) => return fail(self, &message),
394 };
395 if name.is_some() && !ids.is_empty() {
396 return fail(self, "Inputs 'name' and 'artifact-ids' cannot be used together. Please specify only one.");
397 }
398 let merge = match flag(with, "merge-multiple", false) {
399 Ok(merge) => merge,
400 Err(message) => return fail(self, &message),
401 };
402 let dest = self.download_dir(input(with, "path"));
403 // Another run's artifacts, as v4 has it: with a token and a run id.
404 let run_id = match (input(with, "github-token"), input(with, "run-id")) {
405 (Some(_), Some(run)) => {
406 let own = self.github_value("repository");
407 let repository = input(with, "repository").unwrap_or(&own);
408 if !repository.eq_ignore_ascii_case(&own) {
409 return fail(self, &format!("g1t downloads artifacts from other runs of the same repository only; {repository} is not this run's repository, {own}."));
410 }
411 Some(run.to_owned())
412 }
413 _ => None,
414 };
415 let listed = match self.list_artifacts(run_id.as_deref()) {
416 Ok(listed) => listed,
417 Err(error) => return fail(self, &format!("The artifacts could not be listed: {error}")),
418 };
419 let chosen: Vec<Listed> = if let Some(name) = name {
420 match listed.into_iter().find(|a| a.name == name) {
421 Some(artifact) => vec![artifact],
422 None => return fail(self, &format!("Unable to download artifact(s): Artifact not found for name: {name}")),
423 }
424 } else if !ids.is_empty() {
425 let chosen: Vec<Listed> = listed.into_iter().filter(|a| ids.contains(&a.id)).collect();
426 if chosen.is_empty() {
427 return fail(self, "Unable to download artifact(s): None of the provided artifact IDs were found.");
428 }
429 if chosen.len() < ids.len() {
430 self.log.line(&format!("##[warning]Could only find {} of {} artifact IDs.", chosen.len(), ids.len()));
431 }
432 chosen
433 } else {
434 match input(with, "pattern") {
435 Some(pattern) => listed.into_iter().filter(|a| glob::matches_part(pattern, &a.name)).collect(),
436 None => listed,
437 }
438 };
439 let mut outputs = BTreeMap::new();
440 outputs.insert("download-path".into(), dest.display().to_string());
441 if chosen.is_empty() {
442 match input(with, "pattern") {
443 Some(pattern) => self.log.line(&format!("No artifacts matched the pattern {pattern}; nothing was downloaded.")),
444 None => self.log.line("The run has no artifacts; nothing was downloaded."),
445 }
446 return (true, outputs);
447 }
448 let targets = download_targets(&dest, &chosen, name.is_some(), !ids.is_empty(), merge);
449 for (artifact, target) in chosen.iter().zip(targets) {
450 let Some(target) = target else {
451 return fail(self, &format!("The artifact {} cannot be downloaded into a folder of its name.", artifact.name));
452 };
453 if let Err(error) = self.fetch_artifact(artifact, &target) {
454 return fail(self, &format!("The artifact {} could not be downloaded: {error}", artifact.name));
455 }
456 self.log.line(&format!("Downloaded artifact {} ({}) into {}", artifact.name, megabytes(artifact.size), target.display()));
457 }
458 if chosen.len() > 1 {
459 self.log.line(&format!("Downloaded {}.", count(chosen.len(), "artifact")));
460 }
461 (true, outputs)
462 }
463
464 /// `actions/upload-artifact/merge`: the run's artifacts matching
465 /// `pattern`, downloaded together and uploaded again as one.
466 pub(crate) fn merge_artifacts(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
467 let fail = |job: &mut Job, message: &str| {
468 job.log.line(&format!("##[error]{message}"));
469 (false, BTreeMap::new())
470 };
471 let name = input(with, "name").unwrap_or("merged-artifacts").to_owned();
472 let pattern = input(with, "pattern").unwrap_or("*").to_owned();
473 let options = check_name(&name).and_then(|()| {
474 let keep = keep(with, false)?;
475 Ok((keep, flag(with, "separate-directories", false)?, flag(with, "delete-merged", false)?))
476 });
477 let (keep, separate, delete) = match options {
478 Ok(options) => options,
479 Err(message) => return fail(self, &message),
480 };
481 let listed = match self.list_artifacts(None) {
482 Ok(listed) => listed,
483 Err(error) => return fail(self, &format!("The artifacts could not be listed: {error}")),
484 };
485 let chosen: Vec<Listed> = listed.into_iter().filter(|a| glob::matches_part(&pattern, &a.name)).collect();
486 if chosen.is_empty() {
487 return fail(self, &format!("No artifacts found matching pattern '{pattern}'."));
488 }
489 self.log.line(&format!("Merging {}: {}", count(chosen.len(), "artifact"), chosen.iter().map(|a| a.name.as_str()).collect::<Vec<_>>().join(", ")));
490 let folder = self.temp.join(format!("merge-{}", super::rand_id()));
491 let targets = download_targets(&folder, &chosen, false, false, !separate);
492 let mut result = None;
493 for (artifact, target) in chosen.iter().zip(targets) {
494 let Some(target) = target else {
495 result = Some(fail(self, &format!("The artifact {} cannot be merged into a folder of its name.", artifact.name)));
496 break;
497 };
498 if let Err(error) = self.fetch_artifact(artifact, &target) {
499 result = Some(fail(self, &format!("The artifact {} could not be downloaded: {error}", artifact.name)));
500 break;
501 }
502 }
503 let result = result.unwrap_or_else(|| {
504 let root = folder.display().to_string();
505 let found = glob::find(std::slice::from_ref(&root), &root, &self.home(), keep.hidden);
506 if found.files.is_empty() {
507 fail(self, "The artifacts matched hold no files to merge.")
508 } else {
509 self.send_artifact(&name, &found.files, &keep)
510 }
511 });
512 let _ = std::fs::remove_dir_all(&folder);
513 if result.0 && delete {
514 for artifact in &chosen {
515 match ureq::delete(&self.url(&format!("artifacts/{}", artifact.id))).set("authorization", &self.auth()).timeout(Duration::from_secs(60)).call() {
516 Ok(_) => self.log.line(&format!("Deleted artifact {}.", artifact.name)),
517 Err(ureq::Error::Status(_, response)) => self.log.line(&format!("##[warning]Artifact {} could not be deleted: {}", artifact.name, refusal(response))),
518 Err(error) => self.log.line(&format!("##[warning]Artifact {} could not be deleted: {error}", artifact.name)),
519 }
520 }
521 }
522 result
523 }
524
525 /// The cache's `path`, each made absolute (`~/` is the home folder,
526 /// anything else is under the workspace), `!` patterns kept as they
527 /// came, with their `!`.
528 fn cache_paths(&self, with: &BTreeMap<String, String>) -> Vec<String> {
529 let home = self.base_env_value("HOME").unwrap_or_else(|| "/home/node".into());
530 let workspace = self.workspace.display().to_string();
531 cache_patterns(with.get("path").map(String::as_str).unwrap_or_default(), &home, &workspace)
532 }
533
534 /// `actions/cache` and `actions/cache/restore`: restores what it can,
535 /// and for `actions/cache`, saves at the end of the job on a miss.
536 pub(crate) fn cache(&mut self, with: &BTreeMap<String, String>, save_after: bool, title: &str) -> (bool, BTreeMap<String, String>) {
537 let key = with.get("key").cloned().unwrap_or_default();
538 if key.is_empty() {
539 self.log.line("##[error]The cache needs a `key`.");
540 return (false, BTreeMap::new());
541 }
542 let paths = self.cache_paths(with);
543 let restore = lines(with.get("restore-keys").map(String::as_str).unwrap_or_default());
544 let query = format!(
545 "cache?key={}&restore={}",
546 urlencode(&key),
547 urlencode(&restore.join("\n"))
548 );
549 let archive = self.temp.join("cache-restore.tar");
550 let started = Instant::now();
551 let mut outputs = BTreeMap::new();
552 let exact = match self.download(&query, &archive) {
553 Ok(Some(matched)) => {
554 let lookup_only = with.get("lookup-only").is_some_and(|v| v == "true");
555 let size = std::fs::metadata(&archive).map(|m| m.len()).unwrap_or(0);
556 // tar finds out from the archive whether it is zstd or gzip.
557 if !lookup_only && !self.shell(&format!("tar -xPf {}", quote(&archive.display().to_string()))) {
558 self.log.line("##[warning]The cache was found but could not be unpacked.");
559 }
560 let _ = std::fs::remove_file(&archive);
561 self.log.line(&format!("Cache restored from key: {matched} ({} in {:.1}s)", megabytes(size), started.elapsed().as_secs_f64()));
562 outputs.insert("cache-matched-key".into(), matched.clone());
563 matched == key
564 }
565 Ok(None) => {
566 self.log.line(&format!("Cache not found for input keys: {}", std::iter::once(key.clone()).chain(restore).collect::<Vec<_>>().join(", ")));
567 if with.get("fail-on-cache-miss").is_some_and(|v| v == "true") {
568 self.log.line("##[error]The cache missed, and `fail-on-cache-miss` is set.");
569 return (false, outputs);
570 }
571 false
572 }
573 Err(error) => {
574 self.log.line(&format!("##[warning]The cache could not be read: {error}"));
575 false
576 }
577 };
578 outputs.insert("cache-hit".into(), exact.to_string());
579 outputs.insert("cache-primary-key".into(), key.clone());
580 if save_after && !exact {
581 self.posts.push(Post {
582 name: format!("Post {title}"),
583 condition: "success()".into(),
584 env: BTreeMap::new(),
585 run: PostRun::CacheSave { key, paths },
586 });
587 }
588 (true, outputs)
589 }
590
591 /// Saves paths under a key, unless the key is taken.
592 pub(crate) fn cache_save(&mut self, key: &str, paths: &[String]) -> bool {
593 if paths.iter().all(|p| p.starts_with('!')) {
594 self.log.line("##[warning]Nothing to cache: no `path`.");
595 return true;
596 }
597 let archive = self.temp.join("cache-save.tar");
598 let started = Instant::now();
599 match self.run_shell(&pack_script(paths, &archive.display().to_string())) {
600 Some(0) => {}
601 Some(3) => {
602 self.log.line("##[warning]None of the cache's paths exist; nothing was saved.");
603 return true;
604 }
605 _ => {
606 self.log.line("##[warning]The cache could not be packed; nothing was saved.");
607 return true;
608 }
609 }
610 let size = std::fs::metadata(&archive).map(|m| m.len()).unwrap_or(0);
611 let packed = started.elapsed().as_secs_f64();
612 match self.upload_cache(key, &archive) {
613 Ok(true) => self.log.line(&format!(
614 "Cache saved with key: {key} ({}, packed in {packed:.1}s, sent in {:.1}s)",
615 megabytes(size),
616 started.elapsed().as_secs_f64() - packed
617 )),
618 Ok(false) => self.log.line(&format!("Cache not saved: {key} is already cached.")),
619 // A cache that cannot be saved does not fail the job, as on GitHub.
620 Err(error) => self.log.line(&format!("##[warning]The cache could not be saved: {error}")),
621 }
622 let _ = std::fs::remove_file(&archive);
623 true
624 }
625
626 /// Runs a shell line, logging its output; its exit code.
627 fn run_shell(&mut self, script: &str) -> Option<i32> {
628 let mut command = Command::new("bash");
629 command.args(["-c", script]).current_dir(&self.workspace);
630 let mut commands = Commands::default();
631 match process::run(command, Duration::from_secs(1800), &mut self.log, &mut commands) {
632 Ok(Ended::Exited(code)) => Some(code),
633 _ => None,
634 }
635 }
636
637 /// `actions/cache/save`.
638 pub(crate) fn cache_save_now(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
639 let key = with.get("key").cloned().unwrap_or_default();
640 let paths = self.cache_paths(with);
641 (self.cache_save(&key, &paths), BTreeMap::new())
642 }
643}
644
645/// An input, trimmed; `None` when empty.
646fn input<'a>(with: &'a BTreeMap<String, String>, key: &str) -> Option<&'a str> {
647 with.get(key).map(|v| v.trim()).filter(|v| !v.is_empty())
648}
649
650/// A true-or-false input, as `core.getBooleanInput` reads it.
651fn flag(with: &BTreeMap<String, String>, key: &str, default: bool) -> Result<bool, String> {
652 match input(with, key) {
653 None => Ok(default),
654 Some("true" | "True" | "TRUE") => Ok(true),
655 Some("false" | "False" | "FALSE") => Ok(false),
656 Some(other) => Err(format!("`{key}` is `{other}`; it takes true or false.")),
657 }
658}
659
660/// `1 file`, `3 files`.
661fn count(n: usize, what: &str) -> String {
662 if n == 1 { format!("1 {what}") } else { format!("{n} {what}s") }
663}
664
665/// An id that came as a number or as text.
666fn number(value: &serde_json::Value) -> Option<u64> {
667 value.as_u64().or_else(|| value.as_str().and_then(|s| s.parse().ok()))
668}
669
670/// Whether a name is one GitHub takes for an artifact: not empty, at most
671/// 256 characters, none of `" : < > | * ? \ /` or a line break.
672fn check_name(name: &str) -> Result<(), String> {
673 if name.is_empty() {
674 return Err("The artifact needs a name.".into());
675 }
676 if name.chars().count() > 256 {
677 return Err(format!("The artifact name `{name}` is longer than 256 characters."));
678 }
679 if let Some(bad) = name.chars().find(|c| matches!(c, '"' | ':' | '<' | '>' | '|' | '*' | '?' | '\r' | '\n' | '\\' | '/')) {
680 let shown = match bad {
681 '\r' => "a carriage return".to_owned(),
682 '\n' => "a line break".to_owned(),
683 c => format!("`{c}`"),
684 };
685 return Err(format!("The artifact name `{name}` is not valid: it contains {shown}. A name may not contain \" : < > | * ? \\ / or line breaks."));
686 }
687 Ok(())
688}
689
690/// How an artifact is packed and kept, from the inputs `upload-artifact`
691/// and its merge share.
692#[derive(Debug, PartialEq)]
693struct Keep {
694 /// Days; 0 for the repository's own setting.
695 retention: u32,
696 /// 0 (stored) to 9.
697 level: u32,
698 overwrite: bool,
699 /// Whether files and folders whose names start with `.` are taken.
700 hidden: bool,
701}
702
703fn keep(with: &BTreeMap<String, String>, takes_overwrite: bool) -> Result<Keep, String> {
704 let retention = match input(with, "retention-days") {
705 None => 0,
706 Some(text) => match text.parse::<u32>() {
707 Ok(days @ 0..=90) => days,
708 _ => return Err(format!("`retention-days` is `{text}`; it takes a number of days from 1 to 90, or nothing for the repository's setting.")),
709 },
710 };
711 let level = match input(with, "compression-level") {
712 None => 6,
713 Some(text) => match text.parse::<u32>() {
714 Ok(level @ 0..=9) => level,
715 _ => return Err(format!("`compression-level` is `{text}`; it takes 0 (no compression) to 9.")),
716 },
717 };
718 Ok(Keep {
719 retention,
720 level,
721 overwrite: takes_overwrite && flag(with, "overwrite", false)?,
722 hidden: flag(with, "include-hidden-files", false)?,
723 })
724}
725
726/// What finishing an upload gave: the artifact's id, the ZIP's SHA-256 in
727/// hex, and the days it is kept, when known.
728struct Sent {
729 id: u64,
730 digest: String,
731 retention: Option<u32>,
732}
733
734/// An artifact as g1t lists it.
735#[derive(Debug, Clone, PartialEq)]
736struct Listed {
737 id: u64,
738 name: String,
739 size: u64,
740 digest: Option<String>,
741 /// `zip`, or `tgz` for an artifact an older runner stored.
742 format: String,
743}
744
745impl Listed {
746 fn from_json(value: &serde_json::Value) -> Option<Listed> {
747 Some(Listed {
748 id: number(&value["id"])?,
749 name: value["name"].as_str()?.to_owned(),
750 size: value["size"].as_u64().unwrap_or(0),
751 digest: value["digest"].as_str().map(str::to_owned),
752 format: value["format"].as_str().unwrap_or("zip").to_owned(),
753 })
754 }
755}
756
757/// One artifact per name, the newest (highest id), in name order.
758fn newest(listed: Vec<Listed>) -> Vec<Listed> {
759 let mut by_name: BTreeMap<String, Listed> = BTreeMap::new();
760 for artifact in listed {
761 if by_name.get(&artifact.name).is_none_or(|kept| kept.id < artifact.id) {
762 by_name.insert(artifact.name.clone(), artifact);
763 }
764 }
765 by_name.into_values().collect()
766}
767
768/// `artifact-ids`: numbers, separated by commas.
769fn artifact_ids(text: &str) -> Result<Vec<u64>, String> {
770 text.split(',')
771 .map(str::trim)
772 .filter(|id| !id.is_empty())
773 .map(|id| id.parse::<u64>().map_err(|_| format!("`artifact-ids` takes artifact ids, numbers separated by commas; `{id}` is not one.")))
774 .collect()
775}
776
777/// The folder each artifact is unpacked into: `dest` itself for one
778/// artifact by name, for `merge-multiple`, and for a single artifact by
779/// id; otherwise a folder of the artifact's name in `dest`. `None` for a
780/// name that cannot be a folder.
781fn download_targets(dest: &Path, chosen: &[Listed], by_name: bool, by_ids: bool, merge: bool) -> Vec<Option<std::path::PathBuf>> {
782 let straight = by_name || merge || (by_ids && chosen.len() == 1);
783 chosen
784 .iter()
785 .map(|artifact| {
786 if straight {
787 Some(dest.to_path_buf())
788 } else if artifact.name.is_empty() || artifact.name == "." || artifact.name == ".." || artifact.name.contains(['/', '\\']) {
789 None
790 } else {
791 Some(dest.join(&artifact.name))
792 }
793 })
794 .collect()
795}
796
797/// The SHA-256 of a file, in hex, read as it comes.
798fn sha256_file(path: &Path) -> std::io::Result<String> {
799 let mut file = std::fs::File::open(path)?;
800 let mut hasher = Sha256::new();
801 let mut buffer = vec![0u8; 256 * 1024];
802 loop {
803 let n = file.read(&mut buffer)?;
804 if n == 0 {
805 break;
806 }
807 hasher.update(&buffer[..n]);
808 }
809 Ok(hex::encode(hasher.finalize()))
810}
811
812/// The message of a refused request, from its JSON body.
813fn refusal(response: ureq::Response) -> String {
814 let status = response.status();
815 let body: serde_json::Value = response.into_json().unwrap_or_default();
816 body["error"]["message"].as_str().map_or_else(|| format!("g1t answered {status}"), str::to_owned)
817}
818
819fn megabytes(bytes: u64) -> String {
820 if bytes < 1_048_576 { format!("{} KB", bytes.div_ceil(1024)) } else { format!("{:.1} MB", bytes as f64 / 1_048_576.0) }
821}
822
823/// The lines of a cache's `path`, absolute: `~/` is `home`, a relative
824/// path is under `workspace`. A `!` pattern keeps its `!`.
825fn cache_patterns(path: &str, home: &str, workspace: &str) -> Vec<String> {
826 lines(path)
827 .into_iter()
828 .map(|line| {
829 let (bang, p) = match line.strip_prefix('!') {
830 Some(rest) => ("!", rest.trim().to_owned()),
831 None => ("", line),
832 };
833 let p = if p == "~" {
834 home.to_owned()
835 } else if let Some(rest) = p.strip_prefix("~/") {
836 format!("{home}/{rest}")
837 } else {
838 p
839 };
840 let p = if p.starts_with('/') { p } else { format!("{}/{}", workspace.trim_end_matches('/'), p.trim_start_matches("./")) };
841 format!("{bang}{}", p.trim_end_matches('/'))
842 })
843 .collect()
844}
845
846/// A path pattern as a word bash expands as a glob: everything but `*`,
847/// `?` and `[...]` escaped, so spaces and quotes stay literal.
848fn glob_word(pattern: &str) -> String {
849 let mut out = String::new();
850 for c in pattern.chars() {
851 if c.is_ascii_alphanumeric() || matches!(c, '*' | '?' | '[' | ']' | '/' | '.' | '-' | '_' | '~' | '+' | ',' | '=' | '@' | ':') {
852 out.push(c);
853 } else {
854 out.push('\\');
855 out.push(c);
856 }
857 }
858 out
859}
860
861/// The script that packs a cache: its patterns expanded (`**` reaching
862/// any depth), `!` patterns left out, into a tar archive compressed with
863/// zstd where there is one, else gzip. Exits 3 when nothing matched.
864fn pack_script(patterns: &[String], archive: &str) -> String {
865 let includes: Vec<String> = patterns.iter().filter(|p| !p.starts_with('!')).map(|p| glob_word(p)).collect();
866 let excludes: Vec<String> = patterns
867 .iter()
868 .filter_map(|p| p.strip_prefix('!'))
869 // tar's patterns: `*` already crosses `/`, so `**` is the same.
870 .map(|p| format!("--exclude={}", quote(&p.replace("**", "*"))))
871 .collect();
872 format!(
873 "set -o pipefail; shopt -s globstar nullglob dotglob; found=( {} ); files=(); \
874 for f in \"${{found[@]}}\"; do if [ -e \"$f\" ]; then files+=(\"$f\"); fi; done; \
875 if [ ${{#files[@]}} -eq 0 ]; then exit 3; fi; \
876 if command -v zstd >/dev/null; then compress='zstd -T0 -3'; else compress=gzip; fi; \
877 tar -cPf {} -I \"$compress\" {} -- \"${{files[@]}}\"",
878 includes.join(" "),
879 quote(archive),
880 excludes.join(" ")
881 )
882}
883
884fn urlencode(text: &str) -> String {
885 let mut out = String::new();
886 for byte in text.bytes() {
887 if byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'_' | b'.' | b'~') {
888 out.push(byte as char);
889 } else {
890 out.push_str(&format!("%{byte:02X}"));
891 }
892 }
893 out
894}
895
896#[cfg(test)]
897mod tests {
898 use super::*;
899
900 #[test]
901 fn cache_paths_take_home_globs_and_exclusions() {
902 let paths = cache_patterns("~/.cargo/registry/cache\ntarget/*/release/\n!target/**/incremental\n./dist\n/abs/x\n~", "/home/node", "/w/repo/");
903 assert_eq!(
904 paths,
905 ["/home/node/.cargo/registry/cache", "/w/repo/target/*/release", "!/w/repo/target/**/incremental", "/w/repo/dist", "/abs/x", "/home/node"]
906 );
907 assert_eq!(glob_word("/w/my repo/target/**/*.rlib"), "/w/my\\ repo/target/**/*.rlib");
908 assert_eq!(glob_word("/w/a'b"), "/w/a\\'b");
909 }
910
911 #[test]
912 fn packing_expands_globs_and_leaves_exclusions_out() {
913 let script = pack_script(&["/w/target/*/release".into(), "!/w/target/**/incremental".into()], "/t/c.tar");
914 assert!(script.contains("found=( /w/target/*/release )"), "{script}");
915 assert!(script.contains("--exclude='/w/target/*/incremental'"), "{script}");
916 assert!(script.contains("zstd -T0"), "{script}");
917 assert!(script.contains("exit 3"), "{script}");
918 }
919
920 /// Packs and unpacks for real, where bash and tar are (not on Windows).
921 #[test]
922 #[cfg(unix)]
923 fn a_packed_cache_unpacks_without_what_was_left_out() {
924 let dir = std::env::temp_dir().join(format!("g1t-cache-test-{}", std::process::id()));
925 let _ = std::fs::remove_dir_all(&dir);
926 for file in ["target/release/deps/a.rlib", "target/release/incremental/x.bin", "target/wasm/release/deps/b.rlib", "src/main.rs"] {
927 let path = dir.join(file);
928 std::fs::create_dir_all(path.parent().unwrap()).unwrap();
929 std::fs::write(&path, file).unwrap();
930 }
931 let root = dir.display().to_string();
932 let patterns = cache_patterns("target/**/deps\ntarget/release/incremental\n!target/**/incremental", "/home/node", &root);
933 let archive = dir.join("c.tar").display().to_string();
934 let status = Command::new("bash").args(["-c", &pack_script(&patterns, &archive)]).status().unwrap();
935 assert!(status.success());
936 let listed = Command::new("tar").args(["-tPf", &archive]).output().unwrap();
937 let listed = String::from_utf8_lossy(&listed.stdout);
938 assert!(listed.contains("deps/a.rlib") && listed.contains("deps/b.rlib"), "{listed}");
939 assert!(!listed.contains("incremental") && !listed.contains("main.rs"), "{listed}");
940 let none = Command::new("bash").args(["-c", &pack_script(&[format!("{root}/nothing/*")], &archive)]).status().unwrap();
941 assert_eq!(none.code(), Some(3));
942 let _ = std::fs::remove_dir_all(&dir);
943 }
944
945 #[test]
946 fn keys_are_encoded_and_names_checked() {
947 assert_eq!(urlencode("Linux-node-abc/1 2"), "Linux-node-abc%2F1%202");
948 assert!(check_name("coverage report").is_ok());
949 assert!(check_name("dist-linux_x64.1 (debug)").is_ok());
950 assert!(check_name("ünïcødé").is_ok());
951 assert!(check_name(&"a".repeat(256)).is_ok());
952 assert!(check_name(&"a".repeat(257)).is_err());
953 assert!(check_name("").is_err());
954 for bad in ["a/b", "a\\b", "a:b", "a*b", "a?b", "a\"b", "a<b", "a>b", "a|b", "a\nb", "a\rb"] {
955 assert!(check_name(bad).is_err(), "{bad}");
956 }
957 assert_eq!(lines("dist/\n\n# note\n coverage \n"), ["dist/", "coverage"]);
958 }
959
960 fn with(pairs: &[(&str, &str)]) -> BTreeMap<String, String> {
961 pairs.iter().map(|(k, v)| (k.to_string(), v.to_string())).collect()
962 }
963
964 #[test]
965 fn upload_inputs_are_read_as_v4_reads_them() {
966 assert_eq!(keep(&with(&[]), true).unwrap(), Keep { retention: 0, level: 6, overwrite: false, hidden: false });
967 let set = with(&[("retention-days", "14"), ("compression-level", "0"), ("overwrite", "true"), ("include-hidden-files", "True")]);
968 assert_eq!(keep(&set, true).unwrap(), Keep { retention: 14, level: 0, overwrite: true, hidden: true });
969 // The merge takes no `overwrite`.
970 assert!(!keep(&set, false).unwrap().overwrite);
971 assert_eq!(keep(&with(&[("retention-days", "0")]), true).unwrap().retention, 0);
972 assert!(keep(&with(&[("retention-days", "91")]), true).is_err());
973 assert!(keep(&with(&[("retention-days", "-1")]), true).is_err());
974 assert!(keep(&with(&[("retention-days", "two")]), true).is_err());
975 assert!(keep(&with(&[("compression-level", "10")]), true).is_err());
976 assert!(keep(&with(&[("overwrite", "yes")]), true).is_err());
977 assert_eq!(artifact_ids(" 12, 34 ,,").unwrap(), [12, 34]);
978 assert!(artifact_ids("12,abc").is_err());
979 assert_eq!(count(1, "file"), "1 file");
980 assert_eq!(count(37, "file"), "37 files");
981 }
982
983 fn listed(id: u64, name: &str) -> Listed {
984 Listed { id, name: name.into(), size: 0, digest: None, format: "zip".into() }
985 }
986
987 #[test]
988 fn listings_read_and_keep_the_newest_of_a_name() {
989 let json = serde_json::json!([
990 { "id": 1, "name": "dist", "size": 10, "digest": null, "format": "tgz", "created_at": "x", "expires_at": "y" },
991 { "id": "3", "name": "dist", "size": 30, "digest": "sha256:ab", "format": "zip" },
992 { "id": 2, "name": "logs", "size": 5 },
993 { "name": "no id" }
994 ]);
995 let all: Vec<Listed> = json.as_array().unwrap().iter().filter_map(Listed::from_json).collect();
996 assert_eq!(all.len(), 3);
997 assert_eq!(all[0].format, "tgz");
998 let kept = newest(all);
999 assert_eq!(kept.iter().map(|a| (a.id, a.name.as_str())).collect::<Vec<_>>(), [(3, "dist"), (2, "logs")]);
1000 assert_eq!(kept[0].digest.as_deref(), Some("sha256:ab"));
1001 }
1002
1003 #[test]
1004 fn downloads_land_where_v4_puts_them() {
1005 let dest = Path::new("/w/out");
1006 let one = [listed(1, "dist")];
1007 let two = [listed(1, "dist"), listed(2, "logs")];
1008 let at = |targets: Vec<Option<std::path::PathBuf>>| targets.into_iter().map(|t| t.unwrap()).collect::<Vec<_>>();
1009 // By name: straight into `path`.
1010 assert_eq!(at(download_targets(dest, &one, true, false, false)), [dest.to_path_buf()]);
1011 // Every artifact, or by pattern: a folder each.
1012 assert_eq!(at(download_targets(dest, &two, false, false, false)), [dest.join("dist"), dest.join("logs")]);
1013 assert_eq!(at(download_targets(dest, &one, false, false, false)), [dest.join("dist")]);
1014 // merge-multiple: all into `path`.
1015 assert_eq!(at(download_targets(dest, &two, false, false, true)), [dest.to_path_buf(), dest.to_path_buf()]);
1016 // By id: one straight into `path`, several a folder each.
1017 assert_eq!(at(download_targets(dest, &one, false, true, false)), [dest.to_path_buf()]);
1018 assert_eq!(at(download_targets(dest, &two, false, true, false)), [dest.join("dist"), dest.join("logs")]);
1019 // A name that is no folder is refused.
1020 assert!(download_targets(dest, &[listed(1, ".."), listed(2, "x")], false, false, false)[0].is_none());
1021 assert!(glob::matches_part("dist-*", "dist-linux"));
1022 assert!(!glob::matches_part("dist-*", "logs"));
1023 }
1024}