Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 1 | //! Artifacts and the cache: `actions/upload-artifact`, its `merge`, |
| A repository has its own sidebar, as settings do | 2 | //! `actions/download-artifact` and `actions/cache`, done natively against |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 3 | //! g1t. Artifacts belong to the run; cache entries to the repository, found |
| 4 | //! by exact key or by the newest under a `restore-keys` prefix. | |
| 5 | //! | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 6 | //! An artifact is a ZIP file, as GitHub's v4 actions make it (zip.rs), of |
| 7 | //! the files its `path` finds (glob.rs): uploaded in parts with its SHA-256, | |
| 8 | //! and downloaded straight to a file before it is unpacked. | |
| 9 | //! | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 10 | //! A cache entry is a tar archive, compressed with zstd where the machine |
| 11 | //! has it (gzip otherwise), of up to 2 GB: uploaded in parts, and | |
| 12 | //! downloaded straight to a file. Its `path` takes globs (`**` included) | |
| 13 | //! and `!` patterns that leave paths out, as `actions/cache` does. | |
| A repository has its own sidebar, as settings do | 14 | |
| 15 | use std::collections::BTreeMap; | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 16 | use std::io::{Read, Write}; |
| A repository has its own sidebar, as settings do | 17 | use std::path::Path; |
| 18 | use std::process::Command; | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 19 | use std::time::{Duration, Instant}; |
| A repository has its own sidebar, as settings do | 20 | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 21 | use sha2::{Digest, Sha256}; |
| 22 | ||
| A repository has its own sidebar, as settings do | 23 | use super::process::{self, Commands, Ended}; |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 24 | use super::{Job, Post, PostRun, glob, zip}; |
| A repository has its own sidebar, as settings do | 25 | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 26 | /// The largest cache entry, compressed (`g1t_contracts::actions::CACHE_MAX_ENTRY_BYTES`). |
| 27 | const MAX_CACHE_ENTRY: u64 = 2 * 1024 * 1024 * 1024; | |
| A repository has its own sidebar, as settings do | 28 | |
| 29 | fn lines(text: &str) -> Vec<String> { | |
| 30 | text.lines().map(str::trim).filter(|line| !line.is_empty() && !line.starts_with('#')).map(str::to_owned).collect() | |
| 31 | } | |
| 32 | ||
| 33 | fn quote(text: &str) -> String { | |
| 34 | format!("'{}'", text.replace('\'', "'\\''")) | |
| 35 | } | |
| 36 | ||
| 37 | impl Job { | |
| 38 | fn url(&self, rest: &str) -> String { | |
| 39 | format!("{}/actions/jobs/{}/{rest}", self.log.api.base, self.log.api.job) | |
| 40 | } | |
| 41 | ||
| 42 | fn auth(&self) -> String { | |
| 43 | format!("Bearer {}", self.log.api.token) | |
| 44 | } | |
| 45 | ||
| 46 | /// Runs a shell line, logging its output; whether it succeeded. | |
| 47 | fn shell(&mut self, script: &str) -> bool { | |
| 48 | let mut command = Command::new("bash"); | |
| 49 | command.args(["-c", script]).current_dir(&self.workspace); | |
| 50 | let mut commands = Commands::default(); | |
| 51 | matches!(process::run(command, Duration::from_secs(1800), &mut self.log, &mut commands), Ok(Ended::Exited(0))) | |
| 52 | } | |
| 53 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 54 | /// Downloads into `file`, as it comes; `Ok(None)` when there is |
| 55 | /// nothing there. | |
| A repository has its own sidebar, as settings do | 56 | fn download(&mut self, rest: &str, file: &Path) -> Result<Option<String>, String> { |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 57 | let response = match ureq::get(&self.url(rest)).set("authorization", &self.auth()).timeout(Duration::from_secs(1800)).call() { |
| A repository has its own sidebar, as settings do | 58 | Ok(response) => response, |
| 59 | Err(ureq::Error::Status(404, _)) => return Ok(None), | |
| 60 | Err(error) => return Err(error.to_string()), | |
| 61 | }; | |
| 62 | let matched = response.header("x-g1t-key").map(str::to_owned).unwrap_or_default(); | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 63 | let mut out = std::fs::File::create(file).map_err(|e| e.to_string())?; |
| 64 | std::io::copy(&mut response.into_reader().take(MAX_CACHE_ENTRY + 1024), &mut out).map_err(|e| e.to_string())?; | |
| A repository has its own sidebar, as settings do | 65 | Ok(Some(matched)) |
| 66 | } | |
| 67 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 68 | /// Saves `file` as the cache entry `key`, in parts. `Ok(false)` when |
| 69 | /// the key is already cached. | |
| 70 | fn upload_cache(&mut self, key: &str, file: &Path) -> Result<bool, String> { | |
| 71 | let size = std::fs::metadata(file).map_err(|e| e.to_string())?.len(); | |
| 72 | if size > MAX_CACHE_ENTRY { | |
| 73 | return Err(format!("it is {} MB, more than a cache entry may be ({} MB)", size / 1_048_576, MAX_CACHE_ENTRY / 1_048_576)); | |
| 74 | } | |
| 75 | let started = match ureq::post(&self.url(&format!("cache/uploads?key={}&size={size}", urlencode(key)))) | |
| 76 | .set("authorization", &self.auth()) | |
| 77 | .timeout(Duration::from_secs(60)) | |
| 78 | .call() | |
| 79 | { | |
| 80 | Ok(response) => response.into_json::<serde_json::Value>().map_err(|e| e.to_string())?, | |
| 81 | Err(ureq::Error::Status(409, _)) => return Ok(false), | |
| 82 | Err(ureq::Error::Status(_, response)) => return Err(refusal(response)), | |
| 83 | Err(error) => return Err(error.to_string()), | |
| 84 | }; | |
| 85 | let id = started["id"].as_str().unwrap_or_default().to_owned(); | |
| 86 | let upload = started["upload"].as_str().unwrap_or_default().to_owned(); | |
| 87 | let part_bytes = started["part_bytes"].as_u64().filter(|n| *n > 0).unwrap_or(32 * 1024 * 1024); | |
| 88 | let base = format!("cache/uploads/{}", urlencode(&id)); | |
| 89 | let sent = self.send_parts(&base, &upload, file, part_bytes); | |
| 90 | let parts = match sent { | |
| 91 | Ok(parts) => parts, | |
| 92 | Err(error) => { | |
| 93 | let _ = ureq::delete(&self.url(&format!("{base}?upload={}", urlencode(&upload)))).set("authorization", &self.auth()).call(); | |
| 94 | return Err(error); | |
| 95 | } | |
| 96 | }; | |
| 97 | ureq::post(&self.url(&format!("{base}/complete?upload={}", urlencode(&upload)))) | |
| 98 | .set("authorization", &self.auth()) | |
| 99 | .timeout(Duration::from_secs(120)) | |
| 100 | .send_json(serde_json::json!({ "size": size, "parts": parts })) | |
| 101 | .map_err(|e| match e { | |
| 102 | ureq::Error::Status(_, response) => refusal(response), | |
| 103 | other => other.to_string(), | |
| 104 | })?; | |
| 105 | Ok(true) | |
| 106 | } | |
| 107 | ||
| 108 | /// Sends `file` in parts of `part_bytes`; each part's number and etag. | |
| 109 | fn send_parts(&mut self, base: &str, upload: &str, file: &Path, part_bytes: u64) -> Result<Vec<serde_json::Value>, String> { | |
| 110 | let mut reader = std::fs::File::open(file).map_err(|e| e.to_string())?; | |
| 111 | let mut parts = Vec::new(); | |
| 112 | let mut buffer = vec![0u8; part_bytes as usize]; | |
| 113 | for number in 1u32.. { | |
| 114 | let mut filled = 0; | |
| 115 | while filled < buffer.len() { | |
| 116 | let read = reader.read(&mut buffer[filled..]).map_err(|e| e.to_string())?; | |
| 117 | if read == 0 { | |
| 118 | break; | |
| 119 | } | |
| 120 | filled += read; | |
| 121 | } | |
| 122 | if filled == 0 && number > 1 { | |
| 123 | break; | |
| 124 | } | |
| 125 | let url = self.url(&format!("{base}/{number}?upload={}", urlencode(upload))); | |
| 126 | // A part that fails is sent again, twice at most. | |
| 127 | let mut tries = 0; | |
| 128 | let answer = loop { | |
| 129 | tries += 1; | |
| 130 | match ureq::put(&url).set("authorization", &self.auth()).timeout(Duration::from_secs(600)).send_bytes(&buffer[..filled]) { | |
| 131 | Ok(response) => break response.into_json::<serde_json::Value>().map_err(|e| e.to_string())?, | |
| 132 | Err(ureq::Error::Status(status, response)) if status < 500 => return Err(refusal(response)), | |
| 133 | Err(error) if tries >= 3 => return Err(error.to_string()), | |
| 134 | Err(_) => std::thread::sleep(Duration::from_secs(2 * tries)), | |
| 135 | } | |
| 136 | }; | |
| 137 | parts.push(serde_json::json!({ "part": number, "etag": answer["etag"] })); | |
| 138 | if filled < buffer.len() { | |
| 139 | break; | |
| 140 | } | |
| 141 | } | |
| 142 | Ok(parts) | |
| 143 | } | |
| 144 | ||
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 145 | /// A value of the `github` context, as text. |
| 146 | fn github_value(&self, key: &str) -> String { | |
| 147 | match self.contexts.get("github").and_then(|github| github.get(key)) { | |
| 148 | Some(serde_json::Value::String(text)) => text.clone(), | |
| 149 | Some(serde_json::Value::Null) | None => String::new(), | |
| 150 | Some(other) => other.to_string(), | |
| 151 | } | |
| 152 | } | |
| 153 | ||
| 154 | fn home(&self) -> String { | |
| 155 | self.base_env_value("HOME").unwrap_or_else(|| "/home/node".into()) | |
| 156 | } | |
| 157 | ||
| 158 | /// `actions/upload-artifact`: the files `path` names, packed into one | |
| 159 | /// ZIP and uploaded in parts. | |
| A repository has its own sidebar, as settings do | 160 | pub(crate) fn upload_artifact(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) { |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 161 | let name = input(with, "name").unwrap_or("artifact").to_owned(); |
| 162 | let missing = input(with, "if-no-files-found").unwrap_or("warn").to_ascii_lowercase(); | |
| 163 | let checked = check_name(&name) | |
| 164 | .and_then(|()| keep(with, true)) | |
| 165 | .and_then(|keep| if matches!(missing.as_str(), "warn" | "error" | "ignore") { Ok(keep) } else { Err(format!("`if-no-files-found` is `{missing}`; it takes warn, error or ignore.")) }); | |
| 166 | let keep = match checked { | |
| 167 | Ok(keep) => keep, | |
| 168 | Err(message) => { | |
| 169 | self.log.line(&format!("##[error]{message}")); | |
| 170 | return (false, BTreeMap::new()); | |
| A repository has its own sidebar, as settings do | 171 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 172 | }; |
| 173 | let paths = lines(input(with, "path").unwrap_or_default()); | |
| 174 | let found = glob::find(&paths, &self.workspace.display().to_string(), &self.home(), keep.hidden); | |
| 175 | if found.files.is_empty() { | |
| 176 | let message = format!("No files were found with the provided path: {}. No artifacts will be uploaded.", paths.join(", ")); | |
| 177 | return match missing.as_str() { | |
| 178 | "error" => { | |
| 179 | self.log.line(&format!("##[error]{message}")); | |
| 180 | (false, BTreeMap::new()) | |
| 181 | } | |
| 182 | "ignore" => { | |
| 183 | self.log.line(&message); | |
| 184 | (true, BTreeMap::new()) | |
| 185 | } | |
| 186 | _ => { | |
| 187 | self.log.line(&format!("##[warning]{message}")); | |
| 188 | (true, BTreeMap::new()) | |
| 189 | } | |
| 190 | }; | |
| 191 | } | |
| 192 | self.log.line(&format!("Found {} with the provided path, stored relative to {}.", count(found.files.len(), "file"), found.root)); | |
| 193 | self.send_artifact(&name, &found.files, &keep) | |
| 194 | } | |
| 195 | ||
| 196 | /// Packs `files` into a ZIP and uploads it as the artifact `name`; | |
| 197 | /// whether it worked, and the outputs `upload-artifact` sets. | |
| 198 | fn send_artifact(&mut self, name: &str, files: &[(String, std::path::PathBuf)], keep: &Keep) -> (bool, BTreeMap<String, String>) { | |
| 199 | let archive = self.temp.join(format!("artifact-{}.zip", super::rand_id())); | |
| 200 | let sent = zip::write(&archive, files, keep.level) | |
| 201 | .map_err(|e| format!("The files could not be packed: {e}")) | |
| 202 | .and_then(|packed| self.post_artifact(name, &archive, keep).map(|done| (packed, done))); | |
| 203 | let _ = std::fs::remove_file(&archive); | |
| 204 | let (packed, done) = match sent { | |
| 205 | Ok(sent) => sent, | |
| 206 | Err(error) => { | |
| 207 | self.log.line(&format!("##[error]{error}")); | |
| A repository has its own sidebar, as settings do | 208 | return (false, BTreeMap::new()); |
| 209 | } | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 210 | }; |
| 211 | let kept = done.retention.map(|days| format!(" It is kept for {}.", count(days as usize, "day"))).unwrap_or_default(); | |
| 212 | self.log.line(&format!("Uploaded artifact {name} ({}, {}).{kept}", megabytes(packed.size), count(packed.files, "file"))); | |
| 213 | let url = format!( | |
| 214 | "{}/{}/actions/runs/{}/artifacts/{}", | |
| 215 | self.github_value("server_url").trim_end_matches('/'), | |
| 216 | self.github_value("repository"), | |
| 217 | self.github_value("run_id"), | |
| 218 | done.id | |
| 219 | ); | |
| 220 | self.log.line(&format!("Artifact download URL: {url}")); | |
| 221 | let mut outputs = BTreeMap::new(); | |
| 222 | outputs.insert("artifact-id".into(), done.id.to_string()); | |
| 223 | outputs.insert("artifact-url".into(), url); | |
| 224 | outputs.insert("artifact-digest".into(), done.digest); | |
| 225 | (true, outputs) | |
| 226 | } | |
| 227 | ||
| 228 | /// Uploads the ZIP file `archive` as the artifact `name`, in parts, | |
| 229 | /// giving the upload up when a part or the end fails. | |
| 230 | fn post_artifact(&mut self, name: &str, archive: &Path, keep: &Keep) -> Result<Sent, String> { | |
| 231 | let size = std::fs::metadata(archive).map_err(|e| e.to_string())?.len(); | |
| 232 | let digest = sha256_file(archive).map_err(|e| e.to_string())?; | |
| 233 | let query = format!( | |
| 234 | "artifacts/uploads?name={}&size={size}&retention_days={}&overwrite={}&format=zip", | |
| 235 | urlencode(name), | |
| 236 | keep.retention, | |
| 237 | keep.overwrite | |
| 238 | ); | |
| 239 | let failed = |e: ureq::Error| match e { | |
| 240 | ureq::Error::Status(_, response) => format!("The artifact could not be uploaded: {}", refusal(response)), | |
| 241 | other => format!("The artifact could not be uploaded: {other}"), | |
| 242 | }; | |
| 243 | let started = ureq::post(&self.url(&query)) | |
| 244 | .set("authorization", &self.auth()) | |
| 245 | .timeout(Duration::from_secs(60)) | |
| 246 | .call() | |
| 247 | .map_err(failed)? | |
| 248 | .into_json::<serde_json::Value>() | |
| 249 | .map_err(|e| e.to_string())?; | |
| 250 | let id = number(&started["id"]).ok_or("g1t did not say which artifact the upload is")?; | |
| 251 | let upload = started["upload"].as_str().unwrap_or_default().to_owned(); | |
| 252 | let part_bytes = started["part_bytes"].as_u64().filter(|n| *n > 0).unwrap_or(32 * 1024 * 1024); | |
| 253 | let retention = started["retention_days"].as_u64(); | |
| 254 | if let Some(applied) = retention | |
| 255 | && keep.retention != 0 | |
| 256 | && applied != u64::from(keep.retention) | |
| 257 | { | |
| 258 | self.log.line(&format!( | |
| 259 | "##[notice]The artifact is kept for {}, not the {} asked for: the most this repository keeps artifacts.", | |
| 260 | count(applied as usize, "day"), | |
| 261 | keep.retention | |
| 262 | )); | |
| A repository has its own sidebar, as settings do | 263 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 264 | let base = format!("artifacts/uploads/{id}"); |
| 265 | let give_up = |job: &Job| { | |
| 266 | let _ = ureq::delete(&job.url(&format!("{base}?upload={}", urlencode(&upload)))).set("authorization", &job.auth()).call(); | |
| 267 | }; | |
| 268 | let parts = match self.send_parts(&base, &upload, archive, part_bytes) { | |
| 269 | Ok(parts) => parts, | |
| 270 | Err(error) => { | |
| 271 | give_up(self); | |
| 272 | return Err(format!("The artifact could not be uploaded: {error}")); | |
| A repository has its own sidebar, as settings do | 273 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 274 | }; |
| 275 | let done = ureq::post(&self.url(&format!("{base}/complete?upload={}", urlencode(&upload)))) | |
| 276 | .set("authorization", &self.auth()) | |
| 277 | .timeout(Duration::from_secs(120)) | |
| 278 | .send_json(serde_json::json!({ "size": size, "parts": parts, "digest": format!("sha256:{digest}") })); | |
| 279 | let done = match done { | |
| 280 | Ok(response) => response.into_json::<serde_json::Value>().unwrap_or_default(), | |
| A repository has its own sidebar, as settings do | 281 | Err(error) => { |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 282 | give_up(self); |
| 283 | return Err(failed(error)); | |
| 284 | } | |
| 285 | }; | |
| 286 | Ok(Sent { id: number(&done["id"]).unwrap_or(id), digest, retention: retention.map(|d| d as u32).or((keep.retention != 0).then_some(keep.retention)) }) | |
| 287 | } | |
| 288 | ||
| 289 | /// The artifacts of this run, or of the run `run_id` of this | |
| 290 | /// repository; one per name, the newest. | |
| 291 | fn list_artifacts(&mut self, run_id: Option<&str>) -> Result<Vec<Listed>, String> { | |
| 292 | let rest = match run_id { | |
| 293 | Some(run) => format!("artifacts?run_id={}", urlencode(run)), | |
| 294 | None => "artifacts".to_owned(), | |
| 295 | }; | |
| 296 | let listed = ureq::get(&self.url(&rest)) | |
| 297 | .set("authorization", &self.auth()) | |
| 298 | .timeout(Duration::from_secs(60)) | |
| 299 | .call() | |
| 300 | .map_err(|e| match e { | |
| 301 | ureq::Error::Status(_, response) => refusal(response), | |
| 302 | other => other.to_string(), | |
| 303 | })? | |
| 304 | .into_json::<Vec<serde_json::Value>>() | |
| 305 | .map_err(|e| e.to_string())?; | |
| 306 | Ok(newest(listed.iter().filter_map(Listed::from_json).collect())) | |
| 307 | } | |
| 308 | ||
| 309 | /// Downloads an artifact to a file, as it comes, and unpacks it into | |
| 310 | /// `into`. | |
| 311 | fn fetch_artifact(&mut self, artifact: &Listed, into: &Path) -> Result<(), String> { | |
| 312 | let file = self.temp.join(format!("download-{}.zip", super::rand_id())); | |
| 313 | let fetched = self.fetch_to(artifact, &file).and_then(|format| { | |
| 314 | if format == "tgz" { | |
| 315 | std::fs::create_dir_all(into).map_err(|e| e.to_string())?; | |
| 316 | let script = format!("tar -xzf {} -C {}", quote(&file.display().to_string()), quote(&into.display().to_string())); | |
| 317 | if self.shell(&script) { Ok(()) } else { Err("it could not be unpacked".into()) } | |
| 318 | } else { | |
| 319 | zip::extract(&file, into).map(|_| ()).map_err(|e| format!("it could not be unpacked: {e}")) | |
| 320 | } | |
| 321 | }); | |
| 322 | let _ = std::fs::remove_file(&file); | |
| 323 | fetched | |
| 324 | } | |
| 325 | ||
| 326 | /// Downloads an artifact into `file`, checking its digest; how it is | |
| 327 | /// packed, `zip` or `tgz`. | |
| 328 | fn fetch_to(&mut self, artifact: &Listed, file: &Path) -> Result<String, String> { | |
| 329 | let response = match ureq::get(&self.url(&format!("artifacts/{}/download", artifact.id))) | |
| 330 | .set("authorization", &self.auth()) | |
| 331 | .timeout(Duration::from_secs(4 * 3600)) | |
| 332 | .call() | |
| 333 | { | |
| 334 | Ok(response) => response, | |
| 335 | Err(ureq::Error::Status(404, _)) => return Err("it is gone: it expired or was deleted".into()), | |
| 336 | Err(ureq::Error::Status(_, response)) => return Err(refusal(response)), | |
| 337 | Err(error) => return Err(error.to_string()), | |
| 338 | }; | |
| 339 | let format = response.header("x-g1t-format").map(str::to_owned).unwrap_or_else(|| artifact.format.clone()); | |
| 340 | let mut reader = response.into_reader(); | |
| 341 | let mut out = std::io::BufWriter::new(std::fs::File::create(file).map_err(|e| e.to_string())?); | |
| 342 | let mut hasher = Sha256::new(); | |
| 343 | let mut buffer = vec![0u8; 256 * 1024]; | |
| 344 | loop { | |
| 345 | let n = reader.read(&mut buffer).map_err(|e| e.to_string())?; | |
| 346 | if n == 0 { | |
| 347 | break; | |
| A repository has its own sidebar, as settings do | 348 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 349 | hasher.update(&buffer[..n]); |
| 350 | out.write_all(&buffer[..n]).map_err(|e| e.to_string())?; | |
| A repository has its own sidebar, as settings do | 351 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 352 | out.flush().map_err(|e| e.to_string())?; |
| 353 | let got = hex::encode(hasher.finalize()); | |
| 354 | if let Some(expected) = artifact.digest.as_deref().map(|d| d.trim_start_matches("sha256:")) | |
| 355 | && !expected.is_empty() | |
| 356 | && !expected.eq_ignore_ascii_case(&got) | |
| 357 | { | |
| 358 | self.log.line(&format!("##[warning]Artifact {} does not match its digest (sha256:{got}, not sha256:{expected}): it may have been changed since it was uploaded.", artifact.name)); | |
| 359 | } | |
| 360 | Ok(format) | |
| A repository has its own sidebar, as settings do | 361 | } |
| 362 | ||
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 363 | /// Where artifacts are downloaded: `path`, under the workspace unless |
| 364 | /// absolute, `~` the home folder. | |
| 365 | fn download_dir(&self, path: Option<&str>) -> std::path::PathBuf { | |
| 366 | match path { | |
| 367 | None => self.workspace.clone(), | |
| 368 | Some(path) => { | |
| 369 | let home = self.home(); | |
| 370 | let path = if path == "~" { | |
| 371 | home | |
| 372 | } else if let Some(rest) = path.strip_prefix("~/") { | |
| 373 | format!("{}/{rest}", home.trim_end_matches('/')) | |
| 374 | } else { | |
| 375 | path.to_owned() | |
| 376 | }; | |
| 377 | self.workspace.join(path) | |
| A repository has its own sidebar, as settings do | 378 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 379 | } |
| 380 | } | |
| 381 | ||
| 382 | /// `actions/download-artifact`: one artifact by name straight into | |
| 383 | /// `path`, or the run's artifacts (by `pattern` or `artifact-ids`) each | |
| 384 | /// into a folder of its name, or all into `path` with `merge-multiple`. | |
| 385 | pub(crate) fn download_artifact(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) { | |
| 386 | let fail = |job: &mut Job, message: &str| { | |
| 387 | job.log.line(&format!("##[error]{message}")); | |
| 388 | (false, BTreeMap::new()) | |
| 389 | }; | |
| 390 | let name = input(with, "name"); | |
| 391 | let ids = match artifact_ids(input(with, "artifact-ids").unwrap_or_default()) { | |
| 392 | Ok(ids) => ids, | |
| 393 | Err(message) => return fail(self, &message), | |
| 394 | }; | |
| 395 | if name.is_some() && !ids.is_empty() { | |
| 396 | return fail(self, "Inputs 'name' and 'artifact-ids' cannot be used together. Please specify only one."); | |
| 397 | } | |
| 398 | let merge = match flag(with, "merge-multiple", false) { | |
| 399 | Ok(merge) => merge, | |
| 400 | Err(message) => return fail(self, &message), | |
| A repository has its own sidebar, as settings do | 401 | }; |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 402 | let dest = self.download_dir(input(with, "path")); |
| 403 | // Another run's artifacts, as v4 has it: with a token and a run id. | |
| 404 | let run_id = match (input(with, "github-token"), input(with, "run-id")) { | |
| 405 | (Some(_), Some(run)) => { | |
| 406 | let own = self.github_value("repository"); | |
| 407 | let repository = input(with, "repository").unwrap_or(&own); | |
| 408 | if !repository.eq_ignore_ascii_case(&own) { | |
| 409 | return fail(self, &format!("g1t downloads artifacts from other runs of the same repository only; {repository} is not this run's repository, {own}.")); | |
| A repository has its own sidebar, as settings do | 410 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 411 | Some(run.to_owned()) |
| A repository has its own sidebar, as settings do | 412 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 413 | _ => None, |
| 414 | }; | |
| 415 | let listed = match self.list_artifacts(run_id.as_deref()) { | |
| 416 | Ok(listed) => listed, | |
| 417 | Err(error) => return fail(self, &format!("The artifacts could not be listed: {error}")), | |
| 418 | }; | |
| 419 | let chosen: Vec<Listed> = if let Some(name) = name { | |
| 420 | match listed.into_iter().find(|a| a.name == name) { | |
| 421 | Some(artifact) => vec![artifact], | |
| 422 | None => return fail(self, &format!("Unable to download artifact(s): Artifact not found for name: {name}")), | |
| A repository has its own sidebar, as settings do | 423 | } |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 424 | } else if !ids.is_empty() { |
| 425 | let chosen: Vec<Listed> = listed.into_iter().filter(|a| ids.contains(&a.id)).collect(); | |
| 426 | if chosen.is_empty() { | |
| 427 | return fail(self, "Unable to download artifact(s): None of the provided artifact IDs were found."); | |
| 428 | } | |
| 429 | if chosen.len() < ids.len() { | |
| 430 | self.log.line(&format!("##[warning]Could only find {} of {} artifact IDs.", chosen.len(), ids.len())); | |
| 431 | } | |
| 432 | chosen | |
| 433 | } else { | |
| 434 | match input(with, "pattern") { | |
| 435 | Some(pattern) => listed.into_iter().filter(|a| glob::matches_part(pattern, &a.name)).collect(), | |
| 436 | None => listed, | |
| 437 | } | |
| 438 | }; | |
| A repository has its own sidebar, as settings do | 439 | let mut outputs = BTreeMap::new(); |
| 440 | outputs.insert("download-path".into(), dest.display().to_string()); | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 441 | if chosen.is_empty() { |
| 442 | match input(with, "pattern") { | |
| 443 | Some(pattern) => self.log.line(&format!("No artifacts matched the pattern {pattern}; nothing was downloaded.")), | |
| 444 | None => self.log.line("The run has no artifacts; nothing was downloaded."), | |
| 445 | } | |
| 446 | return (true, outputs); | |
| 447 | } | |
| 448 | let targets = download_targets(&dest, &chosen, name.is_some(), !ids.is_empty(), merge); | |
| 449 | for (artifact, target) in chosen.iter().zip(targets) { | |
| 450 | let Some(target) = target else { | |
| 451 | return fail(self, &format!("The artifact {} cannot be downloaded into a folder of its name.", artifact.name)); | |
| 452 | }; | |
| 453 | if let Err(error) = self.fetch_artifact(artifact, &target) { | |
| 454 | return fail(self, &format!("The artifact {} could not be downloaded: {error}", artifact.name)); | |
| 455 | } | |
| 456 | self.log.line(&format!("Downloaded artifact {} ({}) into {}", artifact.name, megabytes(artifact.size), target.display())); | |
| 457 | } | |
| 458 | if chosen.len() > 1 { | |
| 459 | self.log.line(&format!("Downloaded {}.", count(chosen.len(), "artifact"))); | |
| 460 | } | |
| A repository has its own sidebar, as settings do | 461 | (true, outputs) |
| 462 | } | |
| 463 | ||
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 464 | /// `actions/upload-artifact/merge`: the run's artifacts matching |
| 465 | /// `pattern`, downloaded together and uploaded again as one. | |
| 466 | pub(crate) fn merge_artifacts(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) { | |
| 467 | let fail = |job: &mut Job, message: &str| { | |
| 468 | job.log.line(&format!("##[error]{message}")); | |
| 469 | (false, BTreeMap::new()) | |
| 470 | }; | |
| 471 | let name = input(with, "name").unwrap_or("merged-artifacts").to_owned(); | |
| 472 | let pattern = input(with, "pattern").unwrap_or("*").to_owned(); | |
| 473 | let options = check_name(&name).and_then(|()| { | |
| 474 | let keep = keep(with, false)?; | |
| 475 | Ok((keep, flag(with, "separate-directories", false)?, flag(with, "delete-merged", false)?)) | |
| 476 | }); | |
| 477 | let (keep, separate, delete) = match options { | |
| 478 | Ok(options) => options, | |
| 479 | Err(message) => return fail(self, &message), | |
| 480 | }; | |
| 481 | let listed = match self.list_artifacts(None) { | |
| 482 | Ok(listed) => listed, | |
| 483 | Err(error) => return fail(self, &format!("The artifacts could not be listed: {error}")), | |
| 484 | }; | |
| 485 | let chosen: Vec<Listed> = listed.into_iter().filter(|a| glob::matches_part(&pattern, &a.name)).collect(); | |
| 486 | if chosen.is_empty() { | |
| 487 | return fail(self, &format!("No artifacts found matching pattern '{pattern}'.")); | |
| 488 | } | |
| 489 | self.log.line(&format!("Merging {}: {}", count(chosen.len(), "artifact"), chosen.iter().map(|a| a.name.as_str()).collect::<Vec<_>>().join(", "))); | |
| 490 | let folder = self.temp.join(format!("merge-{}", super::rand_id())); | |
| 491 | let targets = download_targets(&folder, &chosen, false, false, !separate); | |
| 492 | let mut result = None; | |
| 493 | for (artifact, target) in chosen.iter().zip(targets) { | |
| 494 | let Some(target) = target else { | |
| 495 | result = Some(fail(self, &format!("The artifact {} cannot be merged into a folder of its name.", artifact.name))); | |
| 496 | break; | |
| 497 | }; | |
| 498 | if let Err(error) = self.fetch_artifact(artifact, &target) { | |
| 499 | result = Some(fail(self, &format!("The artifact {} could not be downloaded: {error}", artifact.name))); | |
| 500 | break; | |
| 501 | } | |
| 502 | } | |
| 503 | let result = result.unwrap_or_else(|| { | |
| 504 | let root = folder.display().to_string(); | |
| 505 | let found = glob::find(std::slice::from_ref(&root), &root, &self.home(), keep.hidden); | |
| 506 | if found.files.is_empty() { | |
| 507 | fail(self, "The artifacts matched hold no files to merge.") | |
| 508 | } else { | |
| 509 | self.send_artifact(&name, &found.files, &keep) | |
| 510 | } | |
| 511 | }); | |
| 512 | let _ = std::fs::remove_dir_all(&folder); | |
| 513 | if result.0 && delete { | |
| 514 | for artifact in &chosen { | |
| 515 | match ureq::delete(&self.url(&format!("artifacts/{}", artifact.id))).set("authorization", &self.auth()).timeout(Duration::from_secs(60)).call() { | |
| 516 | Ok(_) => self.log.line(&format!("Deleted artifact {}.", artifact.name)), | |
| 517 | Err(ureq::Error::Status(_, response)) => self.log.line(&format!("##[warning]Artifact {} could not be deleted: {}", artifact.name, refusal(response))), | |
| 518 | Err(error) => self.log.line(&format!("##[warning]Artifact {} could not be deleted: {error}", artifact.name)), | |
| 519 | } | |
| 520 | } | |
| 521 | } | |
| 522 | result | |
| 523 | } | |
| 524 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 525 | /// The cache's `path`, each made absolute (`~/` is the home folder, |
| 526 | /// anything else is under the workspace), `!` patterns kept as they | |
| 527 | /// came, with their `!`. | |
| A repository has its own sidebar, as settings do | 528 | fn cache_paths(&self, with: &BTreeMap<String, String>) -> Vec<String> { |
| 529 | let home = self.base_env_value("HOME").unwrap_or_else(|| "/home/node".into()); | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 530 | let workspace = self.workspace.display().to_string(); |
| 531 | cache_patterns(with.get("path").map(String::as_str).unwrap_or_default(), &home, &workspace) | |
| A repository has its own sidebar, as settings do | 532 | } |
| 533 | ||
| 534 | /// `actions/cache` and `actions/cache/restore`: restores what it can, | |
| 535 | /// and for `actions/cache`, saves at the end of the job on a miss. | |
| 536 | pub(crate) fn cache(&mut self, with: &BTreeMap<String, String>, save_after: bool, title: &str) -> (bool, BTreeMap<String, String>) { | |
| 537 | let key = with.get("key").cloned().unwrap_or_default(); | |
| 538 | if key.is_empty() { | |
| 539 | self.log.line("##[error]The cache needs a `key`."); | |
| 540 | return (false, BTreeMap::new()); | |
| 541 | } | |
| 542 | let paths = self.cache_paths(with); | |
| 543 | let restore = lines(with.get("restore-keys").map(String::as_str).unwrap_or_default()); | |
| 544 | let query = format!( | |
| 545 | "cache?key={}&restore={}", | |
| 546 | urlencode(&key), | |
| 547 | urlencode(&restore.join("\n")) | |
| 548 | ); | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 549 | let archive = self.temp.join("cache-restore.tar"); |
| 550 | let started = Instant::now(); | |
| A repository has its own sidebar, as settings do | 551 | let mut outputs = BTreeMap::new(); |
| 552 | let exact = match self.download(&query, &archive) { | |
| 553 | Ok(Some(matched)) => { | |
| 554 | let lookup_only = with.get("lookup-only").is_some_and(|v| v == "true"); | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 555 | let size = std::fs::metadata(&archive).map(|m| m.len()).unwrap_or(0); |
| 556 | // tar finds out from the archive whether it is zstd or gzip. | |
| 557 | if !lookup_only && !self.shell(&format!("tar -xPf {}", quote(&archive.display().to_string()))) { | |
| A repository has its own sidebar, as settings do | 558 | self.log.line("##[warning]The cache was found but could not be unpacked."); |
| 559 | } | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 560 | let _ = std::fs::remove_file(&archive); |
| 561 | self.log.line(&format!("Cache restored from key: {matched} ({} in {:.1}s)", megabytes(size), started.elapsed().as_secs_f64())); | |
| A repository has its own sidebar, as settings do | 562 | outputs.insert("cache-matched-key".into(), matched.clone()); |
| 563 | matched == key | |
| 564 | } | |
| 565 | Ok(None) => { | |
| 566 | self.log.line(&format!("Cache not found for input keys: {}", std::iter::once(key.clone()).chain(restore).collect::<Vec<_>>().join(", "))); | |
| 567 | if with.get("fail-on-cache-miss").is_some_and(|v| v == "true") { | |
| 568 | self.log.line("##[error]The cache missed, and `fail-on-cache-miss` is set."); | |
| 569 | return (false, outputs); | |
| 570 | } | |
| 571 | false | |
| 572 | } | |
| 573 | Err(error) => { | |
| 574 | self.log.line(&format!("##[warning]The cache could not be read: {error}")); | |
| 575 | false | |
| 576 | } | |
| 577 | }; | |
| 578 | outputs.insert("cache-hit".into(), exact.to_string()); | |
| 579 | outputs.insert("cache-primary-key".into(), key.clone()); | |
| 580 | if save_after && !exact { | |
| 581 | self.posts.push(Post { | |
| 582 | name: format!("Post {title}"), | |
| 583 | condition: "success()".into(), | |
| 584 | env: BTreeMap::new(), | |
| 585 | run: PostRun::CacheSave { key, paths }, | |
| 586 | }); | |
| 587 | } | |
| 588 | (true, outputs) | |
| 589 | } | |
| 590 | ||
| 591 | /// Saves paths under a key, unless the key is taken. | |
| 592 | pub(crate) fn cache_save(&mut self, key: &str, paths: &[String]) -> bool { | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 593 | if paths.iter().all(|p| p.starts_with('!')) { |
| A repository has its own sidebar, as settings do | 594 | self.log.line("##[warning]Nothing to cache: no `path`."); |
| 595 | return true; | |
| 596 | } | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 597 | let archive = self.temp.join("cache-save.tar"); |
| 598 | let started = Instant::now(); | |
| 599 | match self.run_shell(&pack_script(paths, &archive.display().to_string())) { | |
| 600 | Some(0) => {} | |
| 601 | Some(3) => { | |
| 602 | self.log.line("##[warning]None of the cache's paths exist; nothing was saved."); | |
| 603 | return true; | |
| 604 | } | |
| 605 | _ => { | |
| 606 | self.log.line("##[warning]The cache could not be packed; nothing was saved."); | |
| 607 | return true; | |
| 608 | } | |
| A repository has its own sidebar, as settings do | 609 | } |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 610 | let size = std::fs::metadata(&archive).map(|m| m.len()).unwrap_or(0); |
| 611 | let packed = started.elapsed().as_secs_f64(); | |
| 612 | match self.upload_cache(key, &archive) { | |
| 613 | Ok(true) => self.log.line(&format!( | |
| 614 | "Cache saved with key: {key} ({}, packed in {packed:.1}s, sent in {:.1}s)", | |
| 615 | megabytes(size), | |
| 616 | started.elapsed().as_secs_f64() - packed | |
| 617 | )), | |
| 618 | Ok(false) => self.log.line(&format!("Cache not saved: {key} is already cached.")), | |
| A repository has its own sidebar, as settings do | 619 | // A cache that cannot be saved does not fail the job, as on GitHub. |
| 620 | Err(error) => self.log.line(&format!("##[warning]The cache could not be saved: {error}")), | |
| 621 | } | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 622 | let _ = std::fs::remove_file(&archive); |
| A repository has its own sidebar, as settings do | 623 | true |
| 624 | } | |
| 625 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 626 | /// Runs a shell line, logging its output; its exit code. |
| 627 | fn run_shell(&mut self, script: &str) -> Option<i32> { | |
| 628 | let mut command = Command::new("bash"); | |
| 629 | command.args(["-c", script]).current_dir(&self.workspace); | |
| 630 | let mut commands = Commands::default(); | |
| 631 | match process::run(command, Duration::from_secs(1800), &mut self.log, &mut commands) { | |
| 632 | Ok(Ended::Exited(code)) => Some(code), | |
| 633 | _ => None, | |
| 634 | } | |
| 635 | } | |
| 636 | ||
| A repository has its own sidebar, as settings do | 637 | /// `actions/cache/save`. |
| 638 | pub(crate) fn cache_save_now(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) { | |
| 639 | let key = with.get("key").cloned().unwrap_or_default(); | |
| 640 | let paths = self.cache_paths(with); | |
| 641 | (self.cache_save(&key, &paths), BTreeMap::new()) | |
| 642 | } | |
| 643 | } | |
| 644 | ||
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 645 | /// An input, trimmed; `None` when empty. |
| 646 | fn input<'a>(with: &'a BTreeMap<String, String>, key: &str) -> Option<&'a str> { | |
| 647 | with.get(key).map(|v| v.trim()).filter(|v| !v.is_empty()) | |
| 648 | } | |
| 649 | ||
| 650 | /// A true-or-false input, as `core.getBooleanInput` reads it. | |
| 651 | fn flag(with: &BTreeMap<String, String>, key: &str, default: bool) -> Result<bool, String> { | |
| 652 | match input(with, key) { | |
| 653 | None => Ok(default), | |
| 654 | Some("true" | "True" | "TRUE") => Ok(true), | |
| 655 | Some("false" | "False" | "FALSE") => Ok(false), | |
| 656 | Some(other) => Err(format!("`{key}` is `{other}`; it takes true or false.")), | |
| 657 | } | |
| 658 | } | |
| 659 | ||
| 660 | /// `1 file`, `3 files`. | |
| 661 | fn count(n: usize, what: &str) -> String { | |
| 662 | if n == 1 { format!("1 {what}") } else { format!("{n} {what}s") } | |
| 663 | } | |
| 664 | ||
| 665 | /// An id that came as a number or as text. | |
| 666 | fn number(value: &serde_json::Value) -> Option<u64> { | |
| 667 | value.as_u64().or_else(|| value.as_str().and_then(|s| s.parse().ok())) | |
| 668 | } | |
| 669 | ||
| 670 | /// Whether a name is one GitHub takes for an artifact: not empty, at most | |
| 671 | /// 256 characters, none of `" : < > | * ? \ /` or a line break. | |
| 672 | fn check_name(name: &str) -> Result<(), String> { | |
| 673 | if name.is_empty() { | |
| 674 | return Err("The artifact needs a name.".into()); | |
| 675 | } | |
| 676 | if name.chars().count() > 256 { | |
| 677 | return Err(format!("The artifact name `{name}` is longer than 256 characters.")); | |
| 678 | } | |
| 679 | if let Some(bad) = name.chars().find(|c| matches!(c, '"' | ':' | '<' | '>' | '|' | '*' | '?' | '\r' | '\n' | '\\' | '/')) { | |
| 680 | let shown = match bad { | |
| 681 | '\r' => "a carriage return".to_owned(), | |
| 682 | '\n' => "a line break".to_owned(), | |
| 683 | c => format!("`{c}`"), | |
| 684 | }; | |
| 685 | return Err(format!("The artifact name `{name}` is not valid: it contains {shown}. A name may not contain \" : < > | * ? \\ / or line breaks.")); | |
| 686 | } | |
| 687 | Ok(()) | |
| 688 | } | |
| 689 | ||
| 690 | /// How an artifact is packed and kept, from the inputs `upload-artifact` | |
| 691 | /// and its merge share. | |
| 692 | #[derive(Debug, PartialEq)] | |
| 693 | struct Keep { | |
| 694 | /// Days; 0 for the repository's own setting. | |
| 695 | retention: u32, | |
| 696 | /// 0 (stored) to 9. | |
| 697 | level: u32, | |
| 698 | overwrite: bool, | |
| 699 | /// Whether files and folders whose names start with `.` are taken. | |
| 700 | hidden: bool, | |
| 701 | } | |
| 702 | ||
| 703 | fn keep(with: &BTreeMap<String, String>, takes_overwrite: bool) -> Result<Keep, String> { | |
| 704 | let retention = match input(with, "retention-days") { | |
| 705 | None => 0, | |
| 706 | Some(text) => match text.parse::<u32>() { | |
| 707 | Ok(days @ 0..=90) => days, | |
| 708 | _ => return Err(format!("`retention-days` is `{text}`; it takes a number of days from 1 to 90, or nothing for the repository's setting.")), | |
| 709 | }, | |
| 710 | }; | |
| 711 | let level = match input(with, "compression-level") { | |
| 712 | None => 6, | |
| 713 | Some(text) => match text.parse::<u32>() { | |
| 714 | Ok(level @ 0..=9) => level, | |
| 715 | _ => return Err(format!("`compression-level` is `{text}`; it takes 0 (no compression) to 9.")), | |
| 716 | }, | |
| 717 | }; | |
| 718 | Ok(Keep { | |
| 719 | retention, | |
| 720 | level, | |
| 721 | overwrite: takes_overwrite && flag(with, "overwrite", false)?, | |
| 722 | hidden: flag(with, "include-hidden-files", false)?, | |
| 723 | }) | |
| 724 | } | |
| 725 | ||
| 726 | /// What finishing an upload gave: the artifact's id, the ZIP's SHA-256 in | |
| 727 | /// hex, and the days it is kept, when known. | |
| 728 | struct Sent { | |
| 729 | id: u64, | |
| 730 | digest: String, | |
| 731 | retention: Option<u32>, | |
| 732 | } | |
| 733 | ||
| 734 | /// An artifact as g1t lists it. | |
| 735 | #[derive(Debug, Clone, PartialEq)] | |
| 736 | struct Listed { | |
| 737 | id: u64, | |
| 738 | name: String, | |
| 739 | size: u64, | |
| 740 | digest: Option<String>, | |
| 741 | /// `zip`, or `tgz` for an artifact an older runner stored. | |
| 742 | format: String, | |
| 743 | } | |
| 744 | ||
| 745 | impl Listed { | |
| 746 | fn from_json(value: &serde_json::Value) -> Option<Listed> { | |
| 747 | Some(Listed { | |
| 748 | id: number(&value["id"])?, | |
| 749 | name: value["name"].as_str()?.to_owned(), | |
| 750 | size: value["size"].as_u64().unwrap_or(0), | |
| 751 | digest: value["digest"].as_str().map(str::to_owned), | |
| 752 | format: value["format"].as_str().unwrap_or("zip").to_owned(), | |
| 753 | }) | |
| 754 | } | |
| 755 | } | |
| 756 | ||
| 757 | /// One artifact per name, the newest (highest id), in name order. | |
| 758 | fn newest(listed: Vec<Listed>) -> Vec<Listed> { | |
| 759 | let mut by_name: BTreeMap<String, Listed> = BTreeMap::new(); | |
| 760 | for artifact in listed { | |
| 761 | if by_name.get(&artifact.name).is_none_or(|kept| kept.id < artifact.id) { | |
| 762 | by_name.insert(artifact.name.clone(), artifact); | |
| 763 | } | |
| 764 | } | |
| 765 | by_name.into_values().collect() | |
| 766 | } | |
| 767 | ||
| 768 | /// `artifact-ids`: numbers, separated by commas. | |
| 769 | fn artifact_ids(text: &str) -> Result<Vec<u64>, String> { | |
| 770 | text.split(',') | |
| 771 | .map(str::trim) | |
| 772 | .filter(|id| !id.is_empty()) | |
| 773 | .map(|id| id.parse::<u64>().map_err(|_| format!("`artifact-ids` takes artifact ids, numbers separated by commas; `{id}` is not one."))) | |
| 774 | .collect() | |
| 775 | } | |
| 776 | ||
| 777 | /// The folder each artifact is unpacked into: `dest` itself for one | |
| 778 | /// artifact by name, for `merge-multiple`, and for a single artifact by | |
| 779 | /// id; otherwise a folder of the artifact's name in `dest`. `None` for a | |
| 780 | /// name that cannot be a folder. | |
| 781 | fn download_targets(dest: &Path, chosen: &[Listed], by_name: bool, by_ids: bool, merge: bool) -> Vec<Option<std::path::PathBuf>> { | |
| 782 | let straight = by_name || merge || (by_ids && chosen.len() == 1); | |
| 783 | chosen | |
| 784 | .iter() | |
| 785 | .map(|artifact| { | |
| 786 | if straight { | |
| 787 | Some(dest.to_path_buf()) | |
| 788 | } else if artifact.name.is_empty() || artifact.name == "." || artifact.name == ".." || artifact.name.contains(['/', '\\']) { | |
| 789 | None | |
| 790 | } else { | |
| 791 | Some(dest.join(&artifact.name)) | |
| 792 | } | |
| 793 | }) | |
| 794 | .collect() | |
| 795 | } | |
| 796 | ||
| 797 | /// The SHA-256 of a file, in hex, read as it comes. | |
| 798 | fn sha256_file(path: &Path) -> std::io::Result<String> { | |
| 799 | let mut file = std::fs::File::open(path)?; | |
| 800 | let mut hasher = Sha256::new(); | |
| 801 | let mut buffer = vec![0u8; 256 * 1024]; | |
| 802 | loop { | |
| 803 | let n = file.read(&mut buffer)?; | |
| 804 | if n == 0 { | |
| 805 | break; | |
| 806 | } | |
| 807 | hasher.update(&buffer[..n]); | |
| 808 | } | |
| 809 | Ok(hex::encode(hasher.finalize())) | |
| 810 | } | |
| 811 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 812 | /// The message of a refused request, from its JSON body. |
| 813 | fn refusal(response: ureq::Response) -> String { | |
| 814 | let status = response.status(); | |
| 815 | let body: serde_json::Value = response.into_json().unwrap_or_default(); | |
| 816 | body["error"]["message"].as_str().map_or_else(|| format!("g1t answered {status}"), str::to_owned) | |
| 817 | } | |
| 818 | ||
| 819 | fn megabytes(bytes: u64) -> String { | |
| 820 | if bytes < 1_048_576 { format!("{} KB", bytes.div_ceil(1024)) } else { format!("{:.1} MB", bytes as f64 / 1_048_576.0) } | |
| 821 | } | |
| 822 | ||
| 823 | /// The lines of a cache's `path`, absolute: `~/` is `home`, a relative | |
| 824 | /// path is under `workspace`. A `!` pattern keeps its `!`. | |
| 825 | fn cache_patterns(path: &str, home: &str, workspace: &str) -> Vec<String> { | |
| 826 | lines(path) | |
| 827 | .into_iter() | |
| 828 | .map(|line| { | |
| 829 | let (bang, p) = match line.strip_prefix('!') { | |
| 830 | Some(rest) => ("!", rest.trim().to_owned()), | |
| 831 | None => ("", line), | |
| 832 | }; | |
| 833 | let p = if p == "~" { | |
| 834 | home.to_owned() | |
| 835 | } else if let Some(rest) = p.strip_prefix("~/") { | |
| 836 | format!("{home}/{rest}") | |
| 837 | } else { | |
| 838 | p | |
| 839 | }; | |
| 840 | let p = if p.starts_with('/') { p } else { format!("{}/{}", workspace.trim_end_matches('/'), p.trim_start_matches("./")) }; | |
| 841 | format!("{bang}{}", p.trim_end_matches('/')) | |
| 842 | }) | |
| 843 | .collect() | |
| 844 | } | |
| 845 | ||
| 846 | /// A path pattern as a word bash expands as a glob: everything but `*`, | |
| 847 | /// `?` and `[...]` escaped, so spaces and quotes stay literal. | |
| 848 | fn glob_word(pattern: &str) -> String { | |
| 849 | let mut out = String::new(); | |
| 850 | for c in pattern.chars() { | |
| 851 | if c.is_ascii_alphanumeric() || matches!(c, '*' | '?' | '[' | ']' | '/' | '.' | '-' | '_' | '~' | '+' | ',' | '=' | '@' | ':') { | |
| 852 | out.push(c); | |
| 853 | } else { | |
| 854 | out.push('\\'); | |
| 855 | out.push(c); | |
| 856 | } | |
| 857 | } | |
| 858 | out | |
| 859 | } | |
| 860 | ||
| 861 | /// The script that packs a cache: its patterns expanded (`**` reaching | |
| 862 | /// any depth), `!` patterns left out, into a tar archive compressed with | |
| 863 | /// zstd where there is one, else gzip. Exits 3 when nothing matched. | |
| 864 | fn pack_script(patterns: &[String], archive: &str) -> String { | |
| 865 | let includes: Vec<String> = patterns.iter().filter(|p| !p.starts_with('!')).map(|p| glob_word(p)).collect(); | |
| 866 | let excludes: Vec<String> = patterns | |
| 867 | .iter() | |
| 868 | .filter_map(|p| p.strip_prefix('!')) | |
| 869 | // tar's patterns: `*` already crosses `/`, so `**` is the same. | |
| 870 | .map(|p| format!("--exclude={}", quote(&p.replace("**", "*")))) | |
| 871 | .collect(); | |
| 872 | format!( | |
| 873 | "set -o pipefail; shopt -s globstar nullglob dotglob; found=( {} ); files=(); \ | |
| 874 | for f in \"${{found[@]}}\"; do if [ -e \"$f\" ]; then files+=(\"$f\"); fi; done; \ | |
| 875 | if [ ${{#files[@]}} -eq 0 ]; then exit 3; fi; \ | |
| 876 | if command -v zstd >/dev/null; then compress='zstd -T0 -3'; else compress=gzip; fi; \ | |
| 877 | tar -cPf {} -I \"$compress\" {} -- \"${{files[@]}}\"", | |
| 878 | includes.join(" "), | |
| 879 | quote(archive), | |
| 880 | excludes.join(" ") | |
| 881 | ) | |
| 882 | } | |
| 883 | ||
| A repository has its own sidebar, as settings do | 884 | fn urlencode(text: &str) -> String { |
| 885 | let mut out = String::new(); | |
| 886 | for byte in text.bytes() { | |
| 887 | if byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'_' | b'.' | b'~') { | |
| 888 | out.push(byte as char); | |
| 889 | } else { | |
| 890 | out.push_str(&format!("%{byte:02X}")); | |
| 891 | } | |
| 892 | } | |
| 893 | out | |
| 894 | } | |
| 895 | ||
| 896 | #[cfg(test)] | |
| 897 | mod tests { | |
| 898 | use super::*; | |
| 899 | ||
| 900 | #[test] | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 901 | fn cache_paths_take_home_globs_and_exclusions() { |
| 902 | let paths = cache_patterns("~/.cargo/registry/cache\ntarget/*/release/\n!target/**/incremental\n./dist\n/abs/x\n~", "/home/node", "/w/repo/"); | |
| 903 | assert_eq!( | |
| 904 | paths, | |
| 905 | ["/home/node/.cargo/registry/cache", "/w/repo/target/*/release", "!/w/repo/target/**/incremental", "/w/repo/dist", "/abs/x", "/home/node"] | |
| 906 | ); | |
| 907 | assert_eq!(glob_word("/w/my repo/target/**/*.rlib"), "/w/my\\ repo/target/**/*.rlib"); | |
| 908 | assert_eq!(glob_word("/w/a'b"), "/w/a\\'b"); | |
| 909 | } | |
| 910 | ||
| 911 | #[test] | |
| 912 | fn packing_expands_globs_and_leaves_exclusions_out() { | |
| 913 | let script = pack_script(&["/w/target/*/release".into(), "!/w/target/**/incremental".into()], "/t/c.tar"); | |
| 914 | assert!(script.contains("found=( /w/target/*/release )"), "{script}"); | |
| 915 | assert!(script.contains("--exclude='/w/target/*/incremental'"), "{script}"); | |
| 916 | assert!(script.contains("zstd -T0"), "{script}"); | |
| 917 | assert!(script.contains("exit 3"), "{script}"); | |
| 918 | } | |
| 919 | ||
| 920 | /// Packs and unpacks for real, where bash and tar are (not on Windows). | |
| 921 | #[test] | |
| 922 | #[cfg(unix)] | |
| 923 | fn a_packed_cache_unpacks_without_what_was_left_out() { | |
| 924 | let dir = std::env::temp_dir().join(format!("g1t-cache-test-{}", std::process::id())); | |
| 925 | let _ = std::fs::remove_dir_all(&dir); | |
| 926 | for file in ["target/release/deps/a.rlib", "target/release/incremental/x.bin", "target/wasm/release/deps/b.rlib", "src/main.rs"] { | |
| 927 | let path = dir.join(file); | |
| 928 | std::fs::create_dir_all(path.parent().unwrap()).unwrap(); | |
| 929 | std::fs::write(&path, file).unwrap(); | |
| 930 | } | |
| 931 | let root = dir.display().to_string(); | |
| 932 | let patterns = cache_patterns("target/**/deps\ntarget/release/incremental\n!target/**/incremental", "/home/node", &root); | |
| 933 | let archive = dir.join("c.tar").display().to_string(); | |
| 934 | let status = Command::new("bash").args(["-c", &pack_script(&patterns, &archive)]).status().unwrap(); | |
| 935 | assert!(status.success()); | |
| 936 | let listed = Command::new("tar").args(["-tPf", &archive]).output().unwrap(); | |
| 937 | let listed = String::from_utf8_lossy(&listed.stdout); | |
| 938 | assert!(listed.contains("deps/a.rlib") && listed.contains("deps/b.rlib"), "{listed}"); | |
| 939 | assert!(!listed.contains("incremental") && !listed.contains("main.rs"), "{listed}"); | |
| 940 | let none = Command::new("bash").args(["-c", &pack_script(&[format!("{root}/nothing/*")], &archive)]).status().unwrap(); | |
| 941 | assert_eq!(none.code(), Some(3)); | |
| 942 | let _ = std::fs::remove_dir_all(&dir); | |
| 943 | } | |
| 944 | ||
| 945 | #[test] | |
| A repository has its own sidebar, as settings do | 946 | fn keys_are_encoded_and_names_checked() { |
| 947 | assert_eq!(urlencode("Linux-node-abc/1 2"), "Linux-node-abc%2F1%202"); | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 948 | assert!(check_name("coverage report").is_ok()); |
| 949 | assert!(check_name("dist-linux_x64.1 (debug)").is_ok()); | |
| 950 | assert!(check_name("ünïcødé").is_ok()); | |
| 951 | assert!(check_name(&"a".repeat(256)).is_ok()); | |
| 952 | assert!(check_name(&"a".repeat(257)).is_err()); | |
| 953 | assert!(check_name("").is_err()); | |
| 954 | for bad in ["a/b", "a\\b", "a:b", "a*b", "a?b", "a\"b", "a<b", "a>b", "a|b", "a\nb", "a\rb"] { | |
| 955 | assert!(check_name(bad).is_err(), "{bad}"); | |
| 956 | } | |
| A repository has its own sidebar, as settings do | 957 | assert_eq!(lines("dist/\n\n# note\n coverage \n"), ["dist/", "coverage"]); |
| 958 | } | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 959 | |
| 960 | fn with(pairs: &[(&str, &str)]) -> BTreeMap<String, String> { | |
| 961 | pairs.iter().map(|(k, v)| (k.to_string(), v.to_string())).collect() | |
| 962 | } | |
| 963 | ||
| 964 | #[test] | |
| 965 | fn upload_inputs_are_read_as_v4_reads_them() { | |
| 966 | assert_eq!(keep(&with(&[]), true).unwrap(), Keep { retention: 0, level: 6, overwrite: false, hidden: false }); | |
| 967 | let set = with(&[("retention-days", "14"), ("compression-level", "0"), ("overwrite", "true"), ("include-hidden-files", "True")]); | |
| 968 | assert_eq!(keep(&set, true).unwrap(), Keep { retention: 14, level: 0, overwrite: true, hidden: true }); | |
| 969 | // The merge takes no `overwrite`. | |
| 970 | assert!(!keep(&set, false).unwrap().overwrite); | |
| 971 | assert_eq!(keep(&with(&[("retention-days", "0")]), true).unwrap().retention, 0); | |
| 972 | assert!(keep(&with(&[("retention-days", "91")]), true).is_err()); | |
| 973 | assert!(keep(&with(&[("retention-days", "-1")]), true).is_err()); | |
| 974 | assert!(keep(&with(&[("retention-days", "two")]), true).is_err()); | |
| 975 | assert!(keep(&with(&[("compression-level", "10")]), true).is_err()); | |
| 976 | assert!(keep(&with(&[("overwrite", "yes")]), true).is_err()); | |
| 977 | assert_eq!(artifact_ids(" 12, 34 ,,").unwrap(), [12, 34]); | |
| 978 | assert!(artifact_ids("12,abc").is_err()); | |
| 979 | assert_eq!(count(1, "file"), "1 file"); | |
| 980 | assert_eq!(count(37, "file"), "37 files"); | |
| 981 | } | |
| 982 | ||
| 983 | fn listed(id: u64, name: &str) -> Listed { | |
| 984 | Listed { id, name: name.into(), size: 0, digest: None, format: "zip".into() } | |
| 985 | } | |
| 986 | ||
| 987 | #[test] | |
| 988 | fn listings_read_and_keep_the_newest_of_a_name() { | |
| 989 | let json = serde_json::json!([ | |
| 990 | { "id": 1, "name": "dist", "size": 10, "digest": null, "format": "tgz", "created_at": "x", "expires_at": "y" }, | |
| 991 | { "id": "3", "name": "dist", "size": 30, "digest": "sha256:ab", "format": "zip" }, | |
| 992 | { "id": 2, "name": "logs", "size": 5 }, | |
| 993 | { "name": "no id" } | |
| 994 | ]); | |
| 995 | let all: Vec<Listed> = json.as_array().unwrap().iter().filter_map(Listed::from_json).collect(); | |
| 996 | assert_eq!(all.len(), 3); | |
| 997 | assert_eq!(all[0].format, "tgz"); | |
| 998 | let kept = newest(all); | |
| 999 | assert_eq!(kept.iter().map(|a| (a.id, a.name.as_str())).collect::<Vec<_>>(), [(3, "dist"), (2, "logs")]); | |
| 1000 | assert_eq!(kept[0].digest.as_deref(), Some("sha256:ab")); | |
| 1001 | } | |
| 1002 | ||
| 1003 | #[test] | |
| 1004 | fn downloads_land_where_v4_puts_them() { | |
| 1005 | let dest = Path::new("/w/out"); | |
| 1006 | let one = [listed(1, "dist")]; | |
| 1007 | let two = [listed(1, "dist"), listed(2, "logs")]; | |
| 1008 | let at = |targets: Vec<Option<std::path::PathBuf>>| targets.into_iter().map(|t| t.unwrap()).collect::<Vec<_>>(); | |
| 1009 | // By name: straight into `path`. | |
| 1010 | assert_eq!(at(download_targets(dest, &one, true, false, false)), [dest.to_path_buf()]); | |
| 1011 | // Every artifact, or by pattern: a folder each. | |
| 1012 | assert_eq!(at(download_targets(dest, &two, false, false, false)), [dest.join("dist"), dest.join("logs")]); | |
| 1013 | assert_eq!(at(download_targets(dest, &one, false, false, false)), [dest.join("dist")]); | |
| 1014 | // merge-multiple: all into `path`. | |
| 1015 | assert_eq!(at(download_targets(dest, &two, false, false, true)), [dest.to_path_buf(), dest.to_path_buf()]); | |
| 1016 | // By id: one straight into `path`, several a folder each. | |
| 1017 | assert_eq!(at(download_targets(dest, &one, false, true, false)), [dest.to_path_buf()]); | |
| 1018 | assert_eq!(at(download_targets(dest, &two, false, true, false)), [dest.join("dist"), dest.join("logs")]); | |
| 1019 | // A name that is no folder is refused. | |
| 1020 | assert!(download_targets(dest, &[listed(1, ".."), listed(2, "x")], false, false, false)[0].is_none()); | |
| 1021 | assert!(glob::matches_part("dist-*", "dist-linux")); | |
| 1022 | assert!(!glob::matches_part("dist-*", "logs")); | |
| 1023 | } | |
| A repository has its own sidebar, as settings do | 1024 | } |