g1t/crates/runner/src/actions/mod.rs
| 1 | //! Runs one GitHub Actions job, as GitHub's runner would: its steps in |
| 2 | //! order, each `run` in a shell and each `uses` as the action it names, |
| 3 | //! with the `${{ }}` contexts, the `GITHUB_*` variables and files, and the |
| 4 | //! workflow commands steps print. It reports every step and the log to |
| 5 | //! g1t as it goes. |
| 6 | //! |
| 7 | //! Configuration comes from the environment: `G1T_API`, and `ACTIONS_JOB` |
| 8 | //! and `ACTIONS_TOKEN`, the job and its own token. Everything else, the |
| 9 | //! job's definition, its contexts and its secrets, is fetched with them. |
| 10 | |
| 11 | mod blobs; |
| 12 | mod files; |
| 13 | mod process; |
| 14 | mod report; |
| 15 | mod uses; |
| 16 | |
| 17 | use std::collections::BTreeMap; |
| 18 | use std::path::{Path, PathBuf}; |
| 19 | use std::process::Command; |
| 20 | use std::time::{Duration, Instant}; |
| 21 | |
| 22 | use anyhow::{Context, Result}; |
| 23 | use g1t_actions::events::WORKSPACE; |
| 24 | use g1t_actions::expr::{self, Scope, Status}; |
| 25 | use serde_json::{Map, Value, json}; |
| 26 | |
| 27 | use files::StepFiles; |
| 28 | use process::{Commands, Ended}; |
| 29 | use report::{Api, Log}; |
| 30 | |
| 31 | const TEMP: &str = "/home/runner/_temp"; |
| 32 | |
| 33 | /// Who is running steps: the job itself, or a composite action inside it. |
| 34 | #[derive(Clone, Default)] |
| 35 | pub(crate) struct Frame { |
| 36 | /// The `steps` context. |
| 37 | pub(crate) steps: Map<String, Value>, |
| 38 | /// A composite action's `inputs`, in place of the workflow's. |
| 39 | pub(crate) inputs: Option<Value>, |
| 40 | /// A composite action's folder, for `github.action_path`. |
| 41 | pub(crate) action_path: Option<String>, |
| 42 | /// Variables a composite action's caller set for its steps. |
| 43 | pub(crate) env: BTreeMap<String, String>, |
| 44 | } |
| 45 | |
| 46 | /// A step run when the job's steps are done: an action's `post`, or |
| 47 | /// saving the cache. |
| 48 | pub(crate) struct Post { |
| 49 | pub(crate) name: String, |
| 50 | pub(crate) condition: String, |
| 51 | pub(crate) env: BTreeMap<String, String>, |
| 52 | pub(crate) run: PostRun, |
| 53 | } |
| 54 | |
| 55 | pub(crate) enum PostRun { |
| 56 | Node { action_dir: PathBuf, script: String }, |
| 57 | CacheSave { key: String, paths: Vec<String> }, |
| 58 | } |
| 59 | |
| 60 | pub(crate) struct Job { |
| 61 | pub(crate) log: Log, |
| 62 | pub(crate) spec: Value, |
| 63 | pub(crate) workspace: PathBuf, |
| 64 | pub(crate) temp: PathBuf, |
| 65 | /// This process's own variables, less its credentials, and GitHub's. |
| 66 | base_env: BTreeMap<String, String>, |
| 67 | /// Written to `GITHUB_ENV` by earlier steps. |
| 68 | added_env: BTreeMap<String, String>, |
| 69 | /// Written to `GITHUB_PATH` by earlier steps, newest first. |
| 70 | path_prepend: Vec<String>, |
| 71 | workflow_env: BTreeMap<String, String>, |
| 72 | job_env: BTreeMap<String, String>, |
| 73 | /// github, vars, secrets, inputs, matrix, needs, strategy, runner. |
| 74 | pub(crate) contexts: Map<String, Value>, |
| 75 | pub(crate) failed: bool, |
| 76 | pub(crate) posts: Vec<Post>, |
| 77 | step_names: Vec<String>, |
| 78 | deadline: Instant, |
| 79 | debug: bool, |
| 80 | /// What the last Node process left, for the step that ran it. |
| 81 | pub(crate) last_node_outputs: BTreeMap<String, String>, |
| 82 | pub(crate) last_node_state: BTreeMap<String, String>, |
| 83 | } |
| 84 | |
| 85 | fn text_map(value: Option<&Value>) -> BTreeMap<String, String> { |
| 86 | value |
| 87 | .and_then(Value::as_object) |
| 88 | .map(|map| map.iter().map(|(k, v)| (k.clone(), expr::to_text(v))).collect()) |
| 89 | .unwrap_or_default() |
| 90 | } |
| 91 | |
| 92 | /// A step's title when it has no name, as GitHub shows it. |
| 93 | fn default_title(step: &Map<String, Value>) -> String { |
| 94 | if let Some(uses) = step.get("uses").and_then(Value::as_str) { |
| 95 | return format!("Run {uses}"); |
| 96 | } |
| 97 | let run = step.get("run").map(expr::to_text).unwrap_or_default(); |
| 98 | let first = run.lines().find(|line| !line.trim().is_empty()).unwrap_or_default().trim(); |
| 99 | format!("Run {first}") |
| 100 | } |
| 101 | |
| 102 | impl Job { |
| 103 | pub(crate) fn base_env_value(&self, name: &str) -> Option<String> { |
| 104 | self.base_env.get(name).cloned() |
| 105 | } |
| 106 | |
| 107 | fn status(&self) -> Status { |
| 108 | if self.failed { Status::Failure } else { Status::Success } |
| 109 | } |
| 110 | |
| 111 | /// The contexts an expression in a step can use. |
| 112 | pub(crate) fn contexts_for(&self, frame: &Frame, env: &BTreeMap<String, String>) -> Map<String, Value> { |
| 113 | let mut contexts = self.contexts.clone(); |
| 114 | contexts.insert("env".into(), Value::Object(env.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect())); |
| 115 | contexts.insert("steps".into(), Value::Object(frame.steps.clone())); |
| 116 | contexts.insert("job".into(), json!({ "status": if self.failed { "failure" } else { "success" } })); |
| 117 | if let Some(inputs) = &frame.inputs { |
| 118 | contexts.insert("inputs".into(), inputs.clone()); |
| 119 | } |
| 120 | if let Some(path) = &frame.action_path |
| 121 | && let Some(github) = contexts.get_mut("github") |
| 122 | { |
| 123 | github["action_path"] = Value::String(path.clone()); |
| 124 | } |
| 125 | contexts |
| 126 | } |
| 127 | |
| 128 | /// Runs `f` with a scope over these contexts. |
| 129 | pub(crate) fn with_scope<T>(&self, contexts: &Map<String, Value>, f: impl FnOnce(&Scope) -> T) -> T { |
| 130 | let workspace = self.workspace.clone(); |
| 131 | let hash = move |patterns: &[String]| files::hash_files(&workspace, patterns); |
| 132 | let scope = Scope { |
| 133 | contexts, |
| 134 | status: self.status(), |
| 135 | hash_files: Some(&hash), |
| 136 | }; |
| 137 | f(&scope) |
| 138 | } |
| 139 | |
| 140 | /// The `env` context for a step: the workflow's, the job's, what earlier |
| 141 | /// steps wrote to `GITHUB_ENV`, and the frame's. |
| 142 | fn env_context(&self, frame: &Frame) -> BTreeMap<String, String> { |
| 143 | let mut env = self.added_env.clone(); |
| 144 | env.extend(self.workflow_env.clone()); |
| 145 | env.extend(self.job_env.clone()); |
| 146 | env.extend(frame.env.clone()); |
| 147 | env |
| 148 | } |
| 149 | |
| 150 | /// What a process for a step is given. |
| 151 | pub(crate) fn process_env(&self, env: &BTreeMap<String, String>, files: &StepFiles) -> BTreeMap<String, String> { |
| 152 | let mut out = self.base_env.clone(); |
| 153 | out.extend(env.clone()); |
| 154 | for (name, value) in files.variables() { |
| 155 | out.insert(name.to_owned(), value); |
| 156 | } |
| 157 | if !self.path_prepend.is_empty() { |
| 158 | let current = out.get("PATH").cloned().unwrap_or_default(); |
| 159 | out.insert("PATH".into(), format!("{}:{current}", self.path_prepend.join(":"))); |
| 160 | } |
| 161 | out |
| 162 | } |
| 163 | |
| 164 | /// Takes in what a step wrote to its files. Returns its outputs. |
| 165 | pub(crate) fn absorb(&mut self, files: &StepFiles, commands: &Commands) -> (BTreeMap<String, String>, BTreeMap<String, String>) { |
| 166 | let mut outputs: BTreeMap<String, String> = commands.outputs.clone(); |
| 167 | match files::key_values(&StepFiles::read(&files.output)) { |
| 168 | Ok(values) => outputs.extend(values), |
| 169 | Err(problem) => self.log.line(&format!("##[error]$GITHUB_OUTPUT: {problem}")), |
| 170 | } |
| 171 | match files::key_values(&StepFiles::read(&files.env)) { |
| 172 | Ok(values) => { |
| 173 | for (name, value) in values { |
| 174 | if name.starts_with("GITHUB_") || name == "NODE_OPTIONS" { |
| 175 | self.log.line(&format!("##[warning]{name} cannot be set through $GITHUB_ENV.")); |
| 176 | continue; |
| 177 | } |
| 178 | self.added_env.insert(name, value); |
| 179 | } |
| 180 | } |
| 181 | Err(problem) => self.log.line(&format!("##[error]$GITHUB_ENV: {problem}")), |
| 182 | } |
| 183 | for line in StepFiles::read(&files.path).lines().map(str::trim).filter(|l| !l.is_empty()) { |
| 184 | self.path_prepend.insert(0, line.to_owned()); |
| 185 | } |
| 186 | let mut state = commands.state.clone(); |
| 187 | if let Ok(values) = files::key_values(&StepFiles::read(&files.state)) { |
| 188 | state.extend(values); |
| 189 | } |
| 190 | let summary = StepFiles::read(&files.summary); |
| 191 | if !summary.trim().is_empty() { |
| 192 | self.log.line("##[group]Step summary"); |
| 193 | for line in summary.lines() { |
| 194 | self.log.line(line); |
| 195 | } |
| 196 | self.log.line("##[endgroup]"); |
| 197 | } |
| 198 | (outputs, state) |
| 199 | } |
| 200 | |
| 201 | pub(crate) fn remaining_time(&self) -> Duration { |
| 202 | self.remaining() |
| 203 | } |
| 204 | |
| 205 | fn remaining(&self) -> Duration { |
| 206 | self.deadline.saturating_duration_since(Instant::now()) |
| 207 | } |
| 208 | |
| 209 | /// Runs a shell script for a `run` step. |
| 210 | pub(crate) fn run_script( |
| 211 | &mut self, |
| 212 | script: &str, |
| 213 | shell: Option<&str>, |
| 214 | working_directory: Option<&str>, |
| 215 | env: &BTreeMap<String, String>, |
| 216 | timeout: Duration, |
| 217 | ) -> (bool, BTreeMap<String, String>, BTreeMap<String, String>) { |
| 218 | crate::abuse::touch(); |
| 219 | // Mining is never a workflow's job (abuse.rs). |
| 220 | if let Some(miner) = crate::abuse::miner_in(script) { |
| 221 | self.log.line(&format!("##[error]g1t does not run cryptocurrency miners ({miner}). This step was not run.")); |
| 222 | return (false, BTreeMap::new(), BTreeMap::new()); |
| 223 | } |
| 224 | let id = format!("{:x}", rand_id()); |
| 225 | let shell = shell.map(str::trim).filter(|s| !s.is_empty()); |
| 226 | let (program, args, extension): (String, Vec<String>, &str) = match shell { |
| 227 | None => ("bash".into(), vec!["-e".into(), "{0}".into()], "sh"), |
| 228 | Some("bash") => ("bash".into(), vec!["--noprofile".into(), "--norc".into(), "-eo".into(), "pipefail".into(), "{0}".into()], "sh"), |
| 229 | Some("sh") => ("sh".into(), vec!["-e".into(), "{0}".into()], "sh"), |
| 230 | Some("python") => ("python3".into(), vec!["{0}".into()], "py"), |
| 231 | Some(other @ ("pwsh" | "powershell" | "cmd")) => { |
| 232 | self.log.line(&format!("##[error]`shell: {other}` needs Windows or PowerShell, which g1t's Linux runners do not have.")); |
| 233 | return (false, BTreeMap::new(), BTreeMap::new()); |
| 234 | } |
| 235 | Some(custom) => { |
| 236 | let mut parts = custom.split_whitespace().map(str::to_owned); |
| 237 | let program = parts.next().unwrap_or_default(); |
| 238 | let mut args: Vec<String> = parts.collect(); |
| 239 | if !args.iter().any(|a| a.contains("{0}")) { |
| 240 | args.push("{0}".into()); |
| 241 | } |
| 242 | (program, args, "sh") |
| 243 | } |
| 244 | }; |
| 245 | let script_path = self.temp.join(format!("{id}.{extension}")); |
| 246 | if let Err(error) = std::fs::write(&script_path, script) { |
| 247 | self.log.line(&format!("##[error]Could not write the script: {error}")); |
| 248 | return (false, BTreeMap::new(), BTreeMap::new()); |
| 249 | } |
| 250 | let files = match StepFiles::new(&self.temp, &id) { |
| 251 | Ok(files) => files, |
| 252 | Err(error) => { |
| 253 | self.log.line(&format!("##[error]Could not make the step's files: {error}")); |
| 254 | return (false, BTreeMap::new(), BTreeMap::new()); |
| 255 | } |
| 256 | }; |
| 257 | let args: Vec<String> = args.iter().map(|a| a.replace("{0}", &script_path.display().to_string())).collect(); |
| 258 | self.log.line(&format!("shell: {program} {}", args.join(" "))); |
| 259 | let dir = match working_directory { |
| 260 | Some(dir) if Path::new(dir).is_absolute() => PathBuf::from(dir), |
| 261 | Some(dir) => self.workspace.join(dir), |
| 262 | None => self.workspace.clone(), |
| 263 | }; |
| 264 | let mut command = Command::new(&program); |
| 265 | command.args(&args).current_dir(&dir).env_clear().envs(self.process_env(env, &files)); |
| 266 | let mut commands = Commands { |
| 267 | debug: self.debug, |
| 268 | ..Commands::default() |
| 269 | }; |
| 270 | let ended = process::run(command, timeout.min(self.remaining()), &mut self.log, &mut commands); |
| 271 | let ok = match ended { |
| 272 | Ok(Ended::Exited(0)) => true, |
| 273 | Ok(Ended::Exited(code)) => { |
| 274 | self.log.line(&format!("##[error]Process completed with exit code {code}.")); |
| 275 | false |
| 276 | } |
| 277 | Ok(Ended::TimedOut) => { |
| 278 | self.log.line("##[error]The step ran past its time limit and was stopped."); |
| 279 | false |
| 280 | } |
| 281 | Err(error) => { |
| 282 | self.log.line(&format!("##[error]{program} could not be started: {error}")); |
| 283 | false |
| 284 | } |
| 285 | }; |
| 286 | let (outputs, state) = self.absorb(&files, &commands); |
| 287 | (ok, outputs, state) |
| 288 | } |
| 289 | |
| 290 | /// Runs one step of a frame. Returns whether it succeeded (its |
| 291 | /// conclusion). `number` is the step the log belongs to. |
| 292 | pub(crate) fn step(&mut self, frame: &mut Frame, step: &Map<String, Value>, number: u32, report: bool, defaults: &Map<String, Value>) -> bool { |
| 293 | let env_before = self.env_context(frame); |
| 294 | let contexts = self.contexts_for(frame, &env_before); |
| 295 | let title = match step.get("name").map(expr::to_text) { |
| 296 | Some(name) => self.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name), |
| 297 | None => default_title(step), |
| 298 | }; |
| 299 | let condition = step.get("if").map(expr::to_text).unwrap_or_default(); |
| 300 | let run_it = match self.with_scope(&contexts, |scope| expr::condition(&condition, scope)) { |
| 301 | Ok(run_it) => run_it, |
| 302 | Err(problem) => { |
| 303 | self.log.line(&format!("##[error]The step's `if` does not read: {problem}")); |
| 304 | self.failed = true; |
| 305 | if report { |
| 306 | self.log.step_state(number, &title, "completed", Some("failure")); |
| 307 | } |
| 308 | return false; |
| 309 | } |
| 310 | }; |
| 311 | let id = step.get("id").map(expr::to_text); |
| 312 | if !run_it { |
| 313 | if let Some(id) = &id { |
| 314 | frame.steps.insert(id.clone(), json!({ "outputs": {}, "outcome": "skipped", "conclusion": "skipped" })); |
| 315 | } |
| 316 | if report { |
| 317 | self.log.step_state(number, &title, "completed", Some("skipped")); |
| 318 | } |
| 319 | return true; |
| 320 | } |
| 321 | if report { |
| 322 | self.log.step(number); |
| 323 | self.log.step_state(number, &title, "in_progress", None); |
| 324 | } |
| 325 | |
| 326 | // The step's own env, read with the contexts before it. |
| 327 | let mut env = env_before.clone(); |
| 328 | if let Some(Value::Object(step_env)) = step.get("env") { |
| 329 | for (name, value) in step_env { |
| 330 | let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null); |
| 331 | env.insert(name.clone(), expr::to_text(&value)); |
| 332 | } |
| 333 | } |
| 334 | let timeout = step |
| 335 | .get("timeout-minutes") |
| 336 | .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok()) |
| 337 | .and_then(|v| v.as_f64().or_else(|| expr::to_text(&v).parse().ok())) |
| 338 | .map_or(Duration::from_secs(6 * 3600), |minutes| Duration::from_secs_f64(minutes * 60.0)); |
| 339 | let continue_on_error = step |
| 340 | .get("continue-on-error") |
| 341 | .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok()) |
| 342 | .is_some_and(|v| expr::truthy(&v)); |
| 343 | |
| 344 | let (ok, outputs) = if let Some(run) = step.get("run").map(expr::to_text) { |
| 345 | let script = match self.with_scope(&contexts, |scope| expr::interpolate(&run, scope)) { |
| 346 | Ok(script) => script, |
| 347 | Err(problem) => { |
| 348 | self.log.line(&format!("##[error]The script does not read: {problem}")); |
| 349 | String::new() |
| 350 | } |
| 351 | }; |
| 352 | self.log.line(&format!("##[group]{title}")); |
| 353 | for line in script.lines() { |
| 354 | self.log.line(line); |
| 355 | } |
| 356 | self.log.line("##[endgroup]"); |
| 357 | let shell = step |
| 358 | .get("shell") |
| 359 | .map(expr::to_text) |
| 360 | .or_else(|| defaults.get("shell").map(expr::to_text)); |
| 361 | if frame.action_path.is_some() && shell.is_none() { |
| 362 | self.log.line("##[error]A composite action's `run` steps need a `shell`."); |
| 363 | (false, BTreeMap::new()) |
| 364 | } else { |
| 365 | let working_directory = step |
| 366 | .get("working-directory") |
| 367 | .or_else(|| defaults.get("working-directory")) |
| 368 | .map(|v| self.with_scope(&contexts, |scope| expr::interpolate(&expr::to_text(v), scope)).unwrap_or_else(|_| expr::to_text(v))); |
| 369 | let mut env = env; |
| 370 | if let Some(path) = &frame.action_path { |
| 371 | env.insert("GITHUB_ACTION_PATH".into(), path.clone()); |
| 372 | } |
| 373 | let (ok, outputs, _) = self.run_script(&script, shell.as_deref(), working_directory.as_deref(), &env, timeout); |
| 374 | (ok, outputs) |
| 375 | } |
| 376 | } else if let Some(uses) = step.get("uses").map(expr::to_text) { |
| 377 | let with: BTreeMap<String, String> = match step.get("with") { |
| 378 | Some(Value::Object(with)) => with |
| 379 | .iter() |
| 380 | .map(|(k, v)| { |
| 381 | let value = self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).unwrap_or(Value::Null); |
| 382 | (k.clone(), expr::to_text(&value)) |
| 383 | }) |
| 384 | .collect(), |
| 385 | _ => BTreeMap::new(), |
| 386 | }; |
| 387 | self.uses(&uses, &with, &env, frame, &title, id.as_deref(), timeout) |
| 388 | } else { |
| 389 | self.log.line("##[error]A step needs `run` or `uses`."); |
| 390 | (false, BTreeMap::new()) |
| 391 | }; |
| 392 | |
| 393 | let outcome = if ok { "success" } else { "failure" }; |
| 394 | let conclusion = if ok || continue_on_error { "success" } else { "failure" }; |
| 395 | if !ok && continue_on_error { |
| 396 | self.log.line("##[warning]The step failed, and `continue-on-error` lets the job go on."); |
| 397 | } |
| 398 | if let Some(id) = &id { |
| 399 | let outputs: Map<String, Value> = outputs.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect(); |
| 400 | frame.steps.insert(id.clone(), json!({ "outputs": outputs, "outcome": outcome, "conclusion": conclusion })); |
| 401 | } |
| 402 | if conclusion == "failure" { |
| 403 | self.failed = true; |
| 404 | } |
| 405 | if report { |
| 406 | self.log.step_state(number, &title, "completed", Some(conclusion)); |
| 407 | } |
| 408 | conclusion == "success" |
| 409 | } |
| 410 | |
| 411 | fn report_steps(&self) { |
| 412 | self.log.steps(&self.step_names); |
| 413 | } |
| 414 | } |
| 415 | |
| 416 | /// An id for files, unique enough within one job. |
| 417 | fn rand_id() -> u64 { |
| 418 | use std::sync::atomic::{AtomicU64, Ordering}; |
| 419 | static NEXT: AtomicU64 = AtomicU64::new(1); |
| 420 | let nanos = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH).map(|d| d.as_nanos() as u64).unwrap_or(0); |
| 421 | nanos ^ (NEXT.fetch_add(1, Ordering::Relaxed) << 48) |
| 422 | } |
| 423 | |
| 424 | fn interpolated_map(job: &Job, value: Option<&Value>, contexts: &Map<String, Value>) -> BTreeMap<String, String> { |
| 425 | let mut out = BTreeMap::new(); |
| 426 | if let Some(Value::Object(map)) = value { |
| 427 | for (name, value) in map { |
| 428 | let value = job.with_scope(contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null); |
| 429 | out.insert(name.clone(), expr::to_text(&value)); |
| 430 | } |
| 431 | } |
| 432 | out |
| 433 | } |
| 434 | |
| 435 | fn setup(spec: Value, api: Api) -> Result<Job> { |
| 436 | let masks: Vec<String> = spec["masks"].as_array().map(|m| m.iter().filter_map(|v| v.as_str().map(str::to_owned)).collect()).unwrap_or_default(); |
| 437 | let log = Log::new(api, masks); |
| 438 | let workspace = PathBuf::from(WORKSPACE); |
| 439 | let temp = PathBuf::from(TEMP); |
| 440 | std::fs::create_dir_all(&workspace).context("could not make the workspace")?; |
| 441 | std::fs::create_dir_all(&temp).context("could not make the temporary folder")?; |
| 442 | std::fs::write(temp.join("event.json"), serde_json::to_string_pretty(&spec["event"])?)?; |
| 443 | |
| 444 | // This process's environment, less what only it should see. |
| 445 | let mut base_env: BTreeMap<String, String> = |
| 446 | std::env::vars().filter(|(name, _)| !matches!(name.as_str(), "ACTIONS_TOKEN" | "ACTIONS_JOB" | "MODE") && !name.starts_with("G1T_")).collect(); |
| 447 | base_env.insert("HOME".into(), std::env::var("HOME").unwrap_or_else(|_| "/home/node".into())); |
| 448 | base_env.extend(text_map(spec.get("variables"))); |
| 449 | base_env.insert("GITHUB_EVENT_PATH".into(), temp.join("event.json").display().to_string()); |
| 450 | |
| 451 | let mut contexts: Map<String, Value> = spec["contexts"].as_object().cloned().unwrap_or_default(); |
| 452 | contexts.insert("github".into(), spec["github"].clone()); |
| 453 | let debug = contexts |
| 454 | .get("secrets") |
| 455 | .and_then(|s| s.get("ACTIONS_STEP_DEBUG")) |
| 456 | .or_else(|| contexts.get("vars").and_then(|v| v.get("ACTIONS_STEP_DEBUG"))) |
| 457 | .is_some_and(|v| expr::to_text(v) == "true"); |
| 458 | |
| 459 | // `timeoutMinutes` is how the API spelled it before its bodies were |
| 460 | // `snake_case`. |
| 461 | let timeout = spec["timeout_minutes"] |
| 462 | .as_u64() |
| 463 | .or_else(|| spec["timeoutMinutes"].as_u64()) |
| 464 | .unwrap_or(60); |
| 465 | let mut job = Job { |
| 466 | log, |
| 467 | spec, |
| 468 | workspace, |
| 469 | temp, |
| 470 | base_env, |
| 471 | added_env: BTreeMap::new(), |
| 472 | path_prepend: Vec::new(), |
| 473 | workflow_env: BTreeMap::new(), |
| 474 | job_env: BTreeMap::new(), |
| 475 | contexts, |
| 476 | failed: false, |
| 477 | posts: Vec::new(), |
| 478 | step_names: Vec::new(), |
| 479 | deadline: Instant::now() + Duration::from_secs(timeout * 60), |
| 480 | debug, |
| 481 | last_node_outputs: BTreeMap::new(), |
| 482 | last_node_state: BTreeMap::new(), |
| 483 | }; |
| 484 | |
| 485 | // The workflow's env reads github, secrets, inputs and vars; the job's |
| 486 | // also its matrix, needs and strategy. |
| 487 | let mut contexts = job.contexts.clone(); |
| 488 | contexts.insert("env".into(), json!({})); |
| 489 | job.workflow_env = interpolated_map(&job, job.spec["workflow"].get("env"), &contexts); |
| 490 | contexts.insert("env".into(), Value::Object(job.workflow_env.iter().map(|(k, v)| (k.clone(), json!(v))).collect())); |
| 491 | job.job_env = interpolated_map(&job, job.spec["spec"].get("env"), &contexts); |
| 492 | Ok(job) |
| 493 | } |
| 494 | |
| 495 | /// The job's `defaults.run`, its own over the workflow's. |
| 496 | fn run_defaults(spec: &Value) -> Map<String, Value> { |
| 497 | let mut defaults = spec["workflow"]["defaults"]["run"].as_object().cloned().unwrap_or_default(); |
| 498 | if let Some(own) = spec["spec"]["defaults"]["run"].as_object() { |
| 499 | defaults.extend(own.clone()); |
| 500 | } |
| 501 | defaults |
| 502 | } |
| 503 | |
| 504 | fn run_job(job: &mut Job) { |
| 505 | let steps: Vec<Map<String, Value>> = job.spec["spec"]["steps"] |
| 506 | .as_array() |
| 507 | .map(|steps| steps.iter().filter_map(|s| s.as_object().cloned()).collect()) |
| 508 | .unwrap_or_default(); |
| 509 | let defaults = run_defaults(&job.spec); |
| 510 | |
| 511 | // Step names as they read before anything has run. |
| 512 | let frame = Frame::default(); |
| 513 | let env = job.env_context(&frame); |
| 514 | let contexts = job.contexts_for(&frame, &env); |
| 515 | job.step_names = steps |
| 516 | .iter() |
| 517 | .map(|step| match step.get("name").map(expr::to_text) { |
| 518 | Some(name) => job.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name), |
| 519 | None => default_title(step), |
| 520 | }) |
| 521 | .collect(); |
| 522 | job.report_steps(); |
| 523 | |
| 524 | job.log.step(0); |
| 525 | job.log.line(&format!("Job: {}", job.spec["name"].as_str().unwrap_or_default())); |
| 526 | job.log.line("Runner: g1t, Linux X64 (Debian bookworm, Node 24, Python 3, Go, Rust)"); |
| 527 | if let Some(Value::Object(matrix)) = job.contexts.get("matrix") |
| 528 | && !matrix.is_empty() |
| 529 | { |
| 530 | job.log.line(&format!("Matrix: {}", serde_json::to_string(matrix).unwrap_or_default())); |
| 531 | } |
| 532 | job.log.flush(); |
| 533 | |
| 534 | let mut frame = Frame::default(); |
| 535 | for (index, step) in steps.iter().enumerate() { |
| 536 | job.step(&mut frame, step, index as u32 + 1, true, &defaults); |
| 537 | if job.remaining().is_zero() { |
| 538 | job.log.line("##[error]The job ran past its time limit."); |
| 539 | job.failed = true; |
| 540 | break; |
| 541 | } |
| 542 | } |
| 543 | |
| 544 | // Post steps, last registered first. |
| 545 | let posts: Vec<Post> = std::mem::take(&mut job.posts); |
| 546 | for post in posts.into_iter().rev() { |
| 547 | let number = job.step_names.len() as u32 + 1; |
| 548 | job.step_names.push(post.name.clone()); |
| 549 | job.report_steps(); |
| 550 | let contexts = job.contexts_for(&frame, &job.env_context(&frame)); |
| 551 | let run_it = job.with_scope(&contexts, |scope| expr::condition(&post.condition, scope)).unwrap_or(true); |
| 552 | if !run_it { |
| 553 | job.log.step_state(number, &post.name, "completed", Some("skipped")); |
| 554 | continue; |
| 555 | } |
| 556 | job.log.step(number); |
| 557 | job.log.step_state(number, &post.name, "in_progress", None); |
| 558 | let ok = match &post.run { |
| 559 | PostRun::Node { action_dir, script } => job.run_node(action_dir, script, &post.env), |
| 560 | PostRun::CacheSave { key, paths } => job.cache_save(key, paths), |
| 561 | }; |
| 562 | job.log.step_state(number, &post.name, "completed", Some(if ok { "success" } else { "failure" })); |
| 563 | if !ok { |
| 564 | job.failed = true; |
| 565 | } |
| 566 | } |
| 567 | |
| 568 | // The job's outputs, read now that every step has run. |
| 569 | let env = job.env_context(&frame); |
| 570 | let contexts = job.contexts_for(&frame, &env); |
| 571 | let mut outputs = Map::new(); |
| 572 | if let Some(Value::Object(declared)) = job.spec["spec"].get("outputs") { |
| 573 | for (name, value) in declared { |
| 574 | let value = job.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null); |
| 575 | outputs.insert(name.clone(), Value::String(expr::to_text(&value))); |
| 576 | } |
| 577 | } |
| 578 | let conclusion = if job.failed { "failure" } else { "success" }; |
| 579 | job.log.done(conclusion, &outputs, None); |
| 580 | } |
| 581 | |
| 582 | pub(crate) fn main() -> i32 { |
| 583 | let api = match (crate::env("G1T_API"), crate::env("ACTIONS_JOB"), crate::env("ACTIONS_TOKEN")) { |
| 584 | (Ok(base), Ok(job), Ok(token)) => Api { base, job, token }, |
| 585 | _ => { |
| 586 | eprintln!("g1t-runner: G1T_API, ACTIONS_JOB and ACTIONS_TOKEN are needed"); |
| 587 | return 2; |
| 588 | } |
| 589 | }; |
| 590 | let spec = match api.spec() { |
| 591 | Ok(spec) => spec, |
| 592 | Err(error) => { |
| 593 | eprintln!("g1t-runner: could not fetch the job: {error:#}"); |
| 594 | api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not fetch the job: {error}") })); |
| 595 | return 1; |
| 596 | } |
| 597 | }; |
| 598 | let reporter = Api { |
| 599 | base: api.base.clone(), |
| 600 | job: api.job.clone(), |
| 601 | token: api.token.clone(), |
| 602 | }; |
| 603 | let mut job = match setup(spec, reporter) { |
| 604 | Ok(job) => job, |
| 605 | Err(error) => { |
| 606 | api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not set up: {error:#}") })); |
| 607 | return 1; |
| 608 | } |
| 609 | }; |
| 610 | run_job(&mut job); |
| 611 | if job.failed { 1 } else { 0 } |
| 612 | } |