Skip to content

g1t/crates/runner/src/actions/uses.rs

511 lines25,454 bytesCodeBlame
1//! `uses:` steps: `actions/checkout` done natively against g1t, actions
2//! fetched from GitHub and run as they are (JavaScript, composite and
3//! Docker), `docker://` images, and a few of GitHub's own whose services
4//! g1t does not have yet.
5
6use std::collections::BTreeMap;
7use std::path::{Path, PathBuf};
8use std::process::Command;
9use std::time::Duration;
10
11use base64::Engine;
12use base64::engine::general_purpose::STANDARD;
13use g1t_actions::expr;
14use g1t_actions::workflow::yaml_to_json;
15use serde_json::{Map, Value, json};
16
17use super::containers::{self, DockerRun};
18use super::files::StepFiles;
19use super::process::{self, Commands, Ended};
20use super::{Frame, Job, Post, PostRun};
21
22const ACTIONS_DIR: &str = "/home/runner/_actions";
23
24/// Where an action comes from.
25enum Source {
26 Local(PathBuf),
27 GitHub { owner: String, repo: String, path: String, git_ref: String },
28}
29
30fn safe(part: &str) -> bool {
31 !part.is_empty() && part.chars().all(|c| c.is_ascii_alphanumeric() || matches!(c, '-' | '_' | '.' | '/')) && !part.contains("..")
32}
33
34impl Job {
35 /// Runs a git command, logging it; the credential header is never logged.
36 fn git(&mut self, dir: &Path, args: &[&str], auth: Option<&str>) -> bool {
37 let shown: Vec<&str> = args.to_vec();
38 self.log.line(&format!("[command]git {}", shown.join(" ")));
39 let mut command = Command::new("git");
40 command.current_dir(dir);
41 if let Some(header) = auth {
42 command.args(["-c", &format!("http.extraheader={header}")]);
43 }
44 command.args(args).env("GIT_TERMINAL_PROMPT", "0");
45 let mut commands = Commands::default();
46 matches!(process::run(command, Duration::from_secs(600), &mut self.log, &mut commands), Ok(Ended::Exited(0)))
47 }
48
49 /// A fetch, tried again after a short wait when it fails: a transfer
50 /// cut short on the way ("transfer closed with N bytes remaining") is
51 /// over by the next try. Three tries in all, as actions/checkout does.
52 fn fetch_retrying(&mut self, dir: &Path, args: &[&str], auth: Option<&str>) -> bool {
53 for (attempt, wait) in [0u64, 2, 5].into_iter().enumerate() {
54 if attempt > 0 {
55 self.log.line(&format!("The fetch failed; trying again in {wait} s ({} of 3).", attempt + 1));
56 std::thread::sleep(Duration::from_secs(wait));
57 }
58 if self.git(dir, args, auth) {
59 return true;
60 }
61 }
62 false
63 }
64
65 /// `actions/checkout`, against g1t.
66 fn checkout(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
67 let checkout = self.spec["checkout"].clone();
68 let own = checkout["repository"].as_str().unwrap_or_default().to_owned();
69 let server = self.contexts["github"]["server_url"].as_str().unwrap_or("https://g1t.sh").to_owned();
70 let repository = with.get("repository").filter(|r| !r.is_empty()).cloned().unwrap_or(own.clone());
71 let same = repository.eq_ignore_ascii_case(&own);
72 let token = with.get("token").filter(|t| !t.is_empty()).cloned().or_else(|| checkout["token"].as_str().map(str::to_owned)).unwrap_or_default();
73 let url = if same { checkout["url"].as_str().unwrap_or_default().to_owned() } else { format!("{server}/{repository}.git") };
74 let path = with.get("path").filter(|p| !p.is_empty()).map_or(self.workspace.clone(), |p| self.workspace.join(p));
75 let depth: u32 = with.get("fetch-depth").and_then(|d| d.parse().ok()).unwrap_or(1);
76 let wanted_ref = with.get("ref").filter(|r| !r.is_empty()).cloned();
77 let auth = (!token.is_empty()).then(|| format!("AUTHORIZATION: basic {}", STANDARD.encode(format!("x-access-token:{token}"))));
78
79 self.log.line(&format!("Checking out {repository} into {}", path.display()));
80 if path.exists() {
81 let _ = std::fs::remove_dir_all(&path);
82 }
83 if let Err(error) = std::fs::create_dir_all(&path) {
84 self.log.line(&format!("##[error]Could not make {}: {error}", path.display()));
85 return (false, BTreeMap::new());
86 }
87 let _ = Command::new("git").args(["config", "--global", "--add", "safe.directory", "*"]).status();
88 if !self.git(&path, &["init", "--quiet"], None) || !self.git(&path, &["remote", "add", "origin", &url], None) {
89 return (false, BTreeMap::new());
90 }
91
92 // What to fetch, and which commit to end up on.
93 let run_ref = checkout["ref"].as_str().unwrap_or_default().to_owned();
94 let run_sha = checkout["sha"].as_str().unwrap_or_default().to_owned();
95 let is_sha = |r: &str| r.len() == 40 && r.chars().all(|c| c.is_ascii_hexdigit());
96 let (fetch, sha, branch): (String, Option<String>, Option<String>) = match &wanted_ref {
97 Some(r) if is_sha(r) => ("HEAD".into(), Some(r.clone()), None),
98 Some(r) if r.starts_with("refs/") => (r.clone(), None, r.strip_prefix("refs/heads/").map(str::to_owned)),
99 Some(r) => (r.clone(), None, Some(r.clone())),
100 None if same && run_ref.starts_with("refs/pull/") => ("HEAD".into(), Some(run_sha.clone()), None),
101 None if same => (run_ref.clone(), Some(run_sha.clone()), run_ref.strip_prefix("refs/heads/").map(str::to_owned)),
102 None => ("HEAD".into(), None, None),
103 };
104 let depth_arg = format!("--depth={depth}");
105 let mut args = vec!["fetch", "--no-tags", "--prune", "--quiet"];
106 if depth > 0 {
107 args.push(&depth_arg);
108 }
109 if with.get("fetch-tags").is_some_and(|t| t == "true") {
110 args.retain(|a| *a != "--no-tags");
111 }
112 args.push("origin");
113 args.push(&fetch);
114 if !self.fetch_retrying(&path, &args, auth.as_deref()) {
115 self.log.line(&format!("##[error]Could not fetch {fetch} from {repository}."));
116 return (false, BTreeMap::new());
117 }
118 let target = sha.clone().unwrap_or_else(|| "FETCH_HEAD".into());
119 // The commit may be further back than a shallow fetch reaches: the
120 // branch moved on after the run began, say. Ask for the commit
121 // itself, and failing that the whole history; a plain fetch never
122 // reaches past a shallow boundary.
123 let has = |target: &str| Command::new("git").current_dir(&path).args(["cat-file", "-e", &format!("{target}^{{commit}}")]).status().is_ok_and(|s| s.success());
124 if !has(&target) {
125 let by_sha = sha.as_deref().is_some_and(|sha| {
126 let mut args = vec!["fetch", "--no-tags", "--quiet"];
127 if depth > 0 {
128 args.push(&depth_arg);
129 }
130 args.extend(["origin", sha]);
131 self.git(&path, &args, auth.as_deref()) && has(sha)
132 });
133 let shallow = path.join(".git").join("shallow").exists();
134 let deepen: &[&str] = if shallow { &["fetch", "--no-tags", "--quiet", "--unshallow", "origin"] } else { &["fetch", "--no-tags", "--quiet", "origin"] };
135 if !by_sha && !self.fetch_retrying(&path, deepen, auth.as_deref()) {
136 return (false, BTreeMap::new());
137 }
138 }
139 let checked_out = match &branch {
140 Some(branch) => self.git(&path, &["checkout", "--quiet", "--force", "-B", branch, &target], None),
141 None => self.git(&path, &["checkout", "--quiet", "--force", "--detach", &target], None),
142 };
143 if !checked_out {
144 return (false, BTreeMap::new());
145 }
146 if with.get("persist-credentials").is_none_or(|p| p != "false")
147 && let Some(header) = &auth
148 {
149 let key = format!("http.{server}/.extraheader");
150 let _ = Command::new("git").current_dir(&path).args(["config", "--local", &key, header]).status();
151 }
152 if let Some(submodules) = with.get("submodules").filter(|s| *s == "true" || *s == "recursive") {
153 let mut args = vec!["submodule", "update", "--init", "--quiet"];
154 if submodules == "recursive" {
155 args.push("--recursive");
156 }
157 if !self.git(&path, &args, auth.as_deref()) {
158 self.log.line("##[warning]Submodules could not all be checked out; only those hosted on g1t can be.");
159 }
160 }
161 if with.get("lfs").is_some_and(|l| l == "true") {
162 self.log.line("##[warning]Git LFS files are not fetched on g1t yet.");
163 }
164 let commit = Command::new("git").current_dir(&path).args(["rev-parse", "HEAD"]).output().ok().map(|o| String::from_utf8_lossy(&o.stdout).trim().to_owned()).unwrap_or_default();
165 self.log.line(&format!("Checked out {commit}"));
166 let mut outputs = BTreeMap::new();
167 outputs.insert("ref".into(), wanted_ref.unwrap_or(run_ref));
168 outputs.insert("commit".into(), commit);
169 (true, outputs)
170 }
171
172 /// Fetches an action from GitHub, once per job.
173 fn fetch_action(&mut self, owner: &str, repo: &str, git_ref: &str) -> Option<PathBuf> {
174 let dir = super::paths::under_home(ACTIONS_DIR).join(owner).join(repo).join(git_ref);
175 if dir.join(".g1t-fetched").exists() {
176 return Some(dir);
177 }
178 if !(safe(owner) && safe(repo) && safe(git_ref)) {
179 self.log.line(&format!("##[error]`{owner}/{repo}@{git_ref}` is not a name g1t can fetch."));
180 return None;
181 }
182 self.log.line(&format!("Download action repository '{owner}/{repo}@{git_ref}'"));
183 let _ = std::fs::create_dir_all(&dir);
184 let url = format!("https://codeload.github.com/{owner}/{repo}/tar.gz/{git_ref}");
185 let script = format!("set -o pipefail; curl -fsSL --retry 3 '{url}' | tar -xz -C '{}' --strip-components=1", dir.display());
186 let mut command = Command::new("bash");
187 command.args(["-c", &script]);
188 let mut commands = Commands::default();
189 match process::run(command, Duration::from_secs(300), &mut self.log, &mut commands) {
190 Ok(Ended::Exited(0)) => {
191 let _ = std::fs::write(dir.join(".g1t-fetched"), "");
192 Some(dir)
193 }
194 _ => {
195 self.log.line(&format!("##[error]Could not download {owner}/{repo}@{git_ref} from GitHub."));
196 let _ = std::fs::remove_dir_all(&dir);
197 None
198 }
199 }
200 }
201
202 /// Runs a JavaScript file of an action with Node.
203 pub(crate) fn run_node(&mut self, action_dir: &Path, script: &str, env: &BTreeMap<String, String>) -> bool {
204 let id = format!("node{}", super::rand_id());
205 let Ok(files) = StepFiles::new(&self.temp, &id) else { return false };
206 let full = self.process_env(env, &files);
207 let script_path = action_dir.join(script);
208 // In a job container whose image runs the runner's Node, the action
209 // runs there, as on GitHub.
210 let in_container = self.container.as_ref().filter(|c| c.node).map(|c| c.path.clone()).and_then(|image_path| {
211 let inside = self.container_env(env, full.clone(), &image_path);
212 self.in_container(containers::CONTAINER_NODE, &[script_path.display().to_string()], &self.workspace, inside)
213 });
214 let command = match in_container {
215 Some(command) => command,
216 None => {
217 let mut command = Command::new("node");
218 command.arg(&script_path).current_dir(&self.workspace).env_clear().envs(full);
219 command
220 }
221 };
222 let mut commands = Commands {
223 debug: false,
224 ..Commands::default()
225 };
226 let ended = process::run(command, Duration::from_secs(6 * 3600).min(self.deadline_left()), &mut self.log, &mut commands);
227 let ok = matches!(ended, Ok(Ended::Exited(0)));
228 if let Ok(Ended::Exited(code)) = ended
229 && code != 0
230 {
231 self.log.line(&format!("##[error]The action exited with code {code}."));
232 }
233 let (outputs, state) = self.absorb(&files, &commands);
234 self.last_node_outputs = outputs;
235 self.last_node_state = state;
236 ok
237 }
238
239 fn deadline_left(&self) -> Duration {
240 self.remaining_time()
241 }
242
243 /// Runs a `uses:` step. Returns whether it succeeded, and its outputs.
244 #[allow(clippy::too_many_arguments)]
245 pub(crate) fn uses(
246 &mut self,
247 uses: &str,
248 with: &BTreeMap<String, String>,
249 env: &BTreeMap<String, String>,
250 frame: &Frame,
251 title: &str,
252 id: Option<&str>,
253 _timeout: Duration,
254 ) -> (bool, BTreeMap<String, String>) {
255 let uses = uses.trim();
256 if let Some(image) = uses.strip_prefix("docker://") {
257 // `with.args` and `with.entrypoint` are the container's; every
258 // input is also an `INPUT_` variable, as on GitHub.
259 let mut step_env = env.clone();
260 for (input, value) in with {
261 step_env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
262 }
263 let run = DockerRun {
264 image: image.to_owned(),
265 entrypoint: with.get("entrypoint").filter(|e| !e.is_empty()).cloned(),
266 args: with.get("args").map(|a| containers::split_words(a)).unwrap_or_default(),
267 env: step_env,
268 };
269 let (ok, outputs, _) = self.run_docker(&run);
270 return (ok, outputs);
271 }
272 let (name, git_ref) = uses.split_once('@').unwrap_or((uses, ""));
273 let lower = name.to_ascii_lowercase();
274 if lower == "docker/setup-buildx-action" && self.docker_hosted {
275 return self.setup_buildx(with);
276 }
277 match lower.as_str() {
278 "actions/checkout" => return self.checkout(with),
279 "actions/upload-artifact" => return self.upload_artifact(with),
280 "actions/upload-artifact/merge" => return self.merge_artifacts(with),
281 "actions/download-artifact" => return self.download_artifact(with),
282 "actions/cache" => return self.cache(with, true, title),
283 "actions/cache/restore" => return self.cache(with, false, title),
284 "actions/cache/save" => return self.cache_save_now(with),
285 _ => {}
286 }
287 let source = if let Some(local) = name.strip_prefix("./") {
288 // A repository moved from GitHub renamed `.github` to `.g1t`, but
289 // its workflows still say `./.github/actions/…`.
290 let mut dir = self.workspace.join(local);
291 if let Some(rest) = local.strip_prefix(".github/")
292 && !dir.exists()
293 {
294 dir = self.workspace.join(".g1t").join(rest);
295 }
296 Source::Local(dir)
297 } else {
298 let mut parts = name.splitn(3, '/');
299 let (Some(owner), Some(repo)) = (parts.next(), parts.next()) else {
300 self.log.line(&format!("##[error]`{uses}` is not an action: use owner/repo@ref, owner/repo/path@ref, or ./path."));
301 return (false, BTreeMap::new());
302 };
303 if git_ref.is_empty() {
304 self.log.line(&format!("##[error]`{uses}` needs a version, such as @v4."));
305 return (false, BTreeMap::new());
306 }
307 Source::GitHub {
308 owner: owner.to_owned(),
309 repo: repo.to_owned(),
310 path: parts.next().unwrap_or_default().to_owned(),
311 git_ref: git_ref.to_owned(),
312 }
313 };
314 let (dir, repository) = match &source {
315 Source::Local(dir) => (dir.clone(), String::new()),
316 Source::GitHub { owner, repo, path, git_ref } => match self.fetch_action(owner, repo, git_ref) {
317 Some(root) => (if path.is_empty() { root } else { root.join(path) }, format!("{owner}/{repo}")),
318 None => return (false, BTreeMap::new()),
319 },
320 };
321 let manifest = ["action.yml", "action.yaml"].iter().map(|f| dir.join(f)).find(|p| p.exists());
322 let Some(manifest) = manifest else {
323 self.log.line(&format!("##[error]`{uses}` has no action.yml."));
324 return (false, BTreeMap::new());
325 };
326 let action = match std::fs::read_to_string(&manifest).ok().and_then(|text| serde_yaml::from_str::<serde_yaml::Value>(&text).ok()) {
327 Some(yaml) => yaml_to_json(&yaml),
328 None => {
329 self.log.line(&format!("##[error]`{uses}`: its action.yml does not read."));
330 return (false, BTreeMap::new());
331 }
332 };
333
334 // Inputs: what the step gives, else the action's defaults.
335 let env_context = env.clone();
336 let contexts = self.contexts_for(frame, &env_context);
337 let mut inputs: BTreeMap<String, String> = BTreeMap::new();
338 if let Some(Value::Object(declared)) = action.get("inputs") {
339 for (input, spec) in declared {
340 let given = with.iter().find(|(k, _)| k.eq_ignore_ascii_case(input)).map(|(_, v)| v.clone());
341 let value = match given {
342 Some(value) => value,
343 None => match spec.get("default") {
344 Some(default) => {
345 let default = self.with_scope(&contexts, |scope| expr::interpolate_value(default, scope)).unwrap_or(Value::Null);
346 expr::to_text(&default)
347 }
348 None => String::new(),
349 },
350 };
351 inputs.insert(input.clone(), value);
352 }
353 }
354 for (key, value) in with {
355 if !inputs.keys().any(|k| k.eq_ignore_ascii_case(key)) {
356 inputs.insert(key.clone(), value.clone());
357 }
358 }
359
360 let runs = action.get("runs").cloned().unwrap_or(Value::Null);
361 let using = runs.get("using").map(expr::to_text).unwrap_or_default().to_ascii_lowercase();
362 let mut step_env = env.clone();
363 step_env.insert("GITHUB_ACTION".into(), id.map_or_else(|| format!("__{}", repository.replace('/', "_")), str::to_owned));
364 step_env.insert("GITHUB_ACTION_REPOSITORY".into(), repository.clone());
365 step_env.insert("GITHUB_ACTION_REF".into(), git_ref.to_owned());
366 step_env.insert("GITHUB_ACTION_PATH".into(), dir.display().to_string());
367
368 if using.starts_with("node") {
369 for (input, value) in &inputs {
370 step_env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
371 }
372 let condition_of = |key: &str| runs.get(key).map(expr::to_text).unwrap_or_else(|| "always()".into());
373 if let Some(pre) = runs.get("pre").map(expr::to_text) {
374 let run_pre = self.with_scope(&contexts, |scope| expr::condition(&condition_of("pre-if"), scope)).unwrap_or(true);
375 if run_pre && !self.run_node(&dir, &pre, &step_env) {
376 return (false, BTreeMap::new());
377 }
378 }
379 let Some(main) = runs.get("main").map(expr::to_text) else {
380 self.log.line(&format!("##[error]`{uses}` has no `runs.main`."));
381 return (false, BTreeMap::new());
382 };
383 let ok = self.run_node(&dir, &main, &step_env);
384 let outputs = std::mem::take(&mut self.last_node_outputs);
385 let state = std::mem::take(&mut self.last_node_state);
386 if let Some(post) = runs.get("post").map(expr::to_text) {
387 let mut post_env = step_env.clone();
388 for (name, value) in state {
389 post_env.insert(format!("STATE_{name}"), value);
390 }
391 self.posts.push(Post {
392 name: format!("Post {title}"),
393 condition: condition_of("post-if"),
394 env: post_env,
395 run: PostRun::Node { action_dir: dir.clone(), script: post },
396 });
397 }
398 return (ok, outputs);
399 }
400 if using == "composite" {
401 let mut inner = Frame {
402 steps: Map::new(),
403 inputs: Some(Value::Object(inputs.iter().map(|(k, v)| (k.clone(), json!(v))).collect())),
404 action_path: Some(dir.display().to_string()),
405 env: env.clone(),
406 };
407 let steps: Vec<Map<String, Value>> = runs.get("steps").and_then(Value::as_array).map(|s| s.iter().filter_map(|s| s.as_object().cloned()).collect()).unwrap_or_default();
408 let was_failed = self.failed;
409 // A composite's steps see their own success, not the job's.
410 self.failed = false;
411 let mut ok = true;
412 for step in &steps {
413 if !self.step(&mut inner, step, 0, false, &Map::new()) {
414 ok = false;
415 }
416 }
417 let contexts = self.contexts_for(&inner, &inner.env.clone());
418 let mut outputs = BTreeMap::new();
419 if let Some(Value::Object(declared)) = action.get("outputs") {
420 for (name, spec) in declared {
421 if let Some(value) = spec.get("value") {
422 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
423 outputs.insert(name.clone(), expr::to_text(&value));
424 }
425 }
426 }
427 self.failed = was_failed;
428 return (ok, outputs);
429 }
430 if using == "docker" {
431 return self.docker_action(uses, &dir, &runs, &inputs, &step_env, frame, title);
432 }
433 self.log.line(&format!("##[error]`{uses}` runs with `{using}`, which g1t does not know."));
434 (false, BTreeMap::new())
435 }
436
437 /// A Docker action: its image built from its Dockerfile (or pulled,
438 /// for `docker://`), then run with its `args`, `entrypoint` and `env`,
439 /// its inputs as `INPUT_` variables, and `pre-entrypoint` and
440 /// `post-entrypoint` around it.
441 #[allow(clippy::too_many_arguments)]
442 fn docker_action(
443 &mut self,
444 uses: &str,
445 dir: &Path,
446 runs: &Value,
447 inputs: &BTreeMap<String, String>,
448 step_env: &BTreeMap<String, String>,
449 frame: &Frame,
450 title: &str,
451 ) -> (bool, BTreeMap<String, String>) {
452 let image = runs.get("image").map(expr::to_text).unwrap_or_default();
453 let image = if let Some(pulled) = image.strip_prefix("docker://") {
454 pulled.to_owned()
455 } else if image.is_empty() {
456 self.log.line(&format!("##[error]`{uses}` has no `runs.image`."));
457 return (false, BTreeMap::new());
458 } else {
459 match self.build_action_image(dir, &image, uses) {
460 Some(tag) => tag,
461 None => return (false, BTreeMap::new()),
462 }
463 };
464 // `args` and `env` read with the action's own inputs.
465 let mut env = step_env.clone();
466 for (input, value) in inputs {
467 env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
468 }
469 let mut scope_frame = frame.clone();
470 scope_frame.inputs = Some(Value::Object(inputs.iter().map(|(k, v)| (k.clone(), json!(v))).collect()));
471 let contexts = self.contexts_for(&scope_frame, &env);
472 if let Some(Value::Object(own)) = runs.get("env") {
473 for (name, value) in own {
474 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
475 env.insert(name.clone(), expr::to_text(&value));
476 }
477 }
478 let args: Vec<String> = match runs.get("args") {
479 Some(Value::Array(items)) => items
480 .iter()
481 .map(|item| {
482 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(item, scope)).unwrap_or(Value::Null);
483 expr::to_text(&value)
484 })
485 .collect(),
486 _ => Vec::new(),
487 };
488 let entry = |key: &str| runs.get(key).map(expr::to_text).filter(|e| !e.is_empty());
489 if let Some(pre) = entry("pre-entrypoint") {
490 let run = DockerRun { image: image.clone(), entrypoint: Some(pre), args: Vec::new(), env: env.clone() };
491 if !self.run_docker(&run).0 {
492 return (false, BTreeMap::new());
493 }
494 }
495 let run = DockerRun { image: image.clone(), entrypoint: entry("entrypoint"), args, env: env.clone() };
496 let (ok, outputs, state) = self.run_docker(&run);
497 if let Some(post) = entry("post-entrypoint") {
498 let mut post_env = env;
499 for (name, value) in state {
500 post_env.insert(format!("STATE_{name}"), value);
501 }
502 self.posts.push(Post {
503 name: format!("Post {title}"),
504 condition: runs.get("post-if").map(expr::to_text).unwrap_or_else(|| "always()".into()),
505 env: BTreeMap::new(),
506 run: PostRun::Docker(DockerRun { image, entrypoint: Some(post), args: Vec::new(), env: post_env }),
507 });
508 }
509 (ok, outputs)
510 }
511}