Skip to content
660 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

GitHub Actions on g1t, part two: running workflows1//! Runs one GitHub Actions job, as GitHub's runner would: its steps in
2//! order, each `run` in a shell and each `uses` as the action it names,
3//! with the `${{ }}` contexts, the `GITHUB_*` variables and files, and the
4//! workflow commands steps print. It reports every step and the log to
5//! g1t as it goes.
6//!
7//! Configuration comes from the environment: `G1T_API`, and `ACTIONS_JOB`
8//! and `ACTIONS_TOKEN`, the job and its own token. Everything else, the
9//! job's definition, its contexts and its secrets, is fetched with them.
10
A repository has its own sidebar, as settings do11mod blobs;
GitHub Actions on g1t, part two: running workflows12mod files;
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R213mod glob;
Fast pages, required checks on the branch, self-hosted runners, honest incidents14mod paths;
GitHub Actions on g1t, part two: running workflows15mod process;
16mod report;
17mod uses;
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R218mod zip;
GitHub Actions on g1t, part two: running workflows19
20use std::collections::BTreeMap;
21use std::path::{Path, PathBuf};
22use std::process::Command;
23use std::time::{Duration, Instant};
24
25use anyhow::{Context, Result};
26use g1t_actions::events::WORKSPACE;
27use g1t_actions::expr::{self, Scope, Status};
28use serde_json::{Map, Value, json};
29
30use files::StepFiles;
31use process::{Commands, Ended};
32use report::{Api, Log};
33
34const TEMP: &str = "/home/runner/_temp";
35
36/// Who is running steps: the job itself, or a composite action inside it.
37#[derive(Clone, Default)]
38pub(crate) struct Frame {
39 /// The `steps` context.
40 pub(crate) steps: Map<String, Value>,
41 /// A composite action's `inputs`, in place of the workflow's.
42 pub(crate) inputs: Option<Value>,
43 /// A composite action's folder, for `github.action_path`.
44 pub(crate) action_path: Option<String>,
45 /// Variables a composite action's caller set for its steps.
46 pub(crate) env: BTreeMap<String, String>,
47}
48
A repository has its own sidebar, as settings do49/// A step run when the job's steps are done: an action's `post`, or
50/// saving the cache.
GitHub Actions on g1t, part two: running workflows51pub(crate) struct Post {
52 pub(crate) name: String,
53 pub(crate) condition: String,
54 pub(crate) env: BTreeMap<String, String>,
A repository has its own sidebar, as settings do55 pub(crate) run: PostRun,
GitHub Actions on g1t, part two: running workflows56}
57
A repository has its own sidebar, as settings do58pub(crate) enum PostRun {
59 Node { action_dir: PathBuf, script: String },
60 CacheSave { key: String, paths: Vec<String> },
61}
62
GitHub Actions on g1t, part two: running workflows63pub(crate) struct Job {
64 pub(crate) log: Log,
65 pub(crate) spec: Value,
66 pub(crate) workspace: PathBuf,
67 pub(crate) temp: PathBuf,
68 /// This process's own variables, less its credentials, and GitHub's.
69 base_env: BTreeMap<String, String>,
70 /// Written to `GITHUB_ENV` by earlier steps.
71 added_env: BTreeMap<String, String>,
72 /// Written to `GITHUB_PATH` by earlier steps, newest first.
73 path_prepend: Vec<String>,
74 workflow_env: BTreeMap<String, String>,
75 job_env: BTreeMap<String, String>,
76 /// github, vars, secrets, inputs, matrix, needs, strategy, runner.
77 pub(crate) contexts: Map<String, Value>,
78 pub(crate) failed: bool,
79 pub(crate) posts: Vec<Post>,
80 step_names: Vec<String>,
81 deadline: Instant,
82 debug: bool,
83 /// What the last Node process left, for the step that ran it.
84 pub(crate) last_node_outputs: BTreeMap<String, String>,
85 pub(crate) last_node_state: BTreeMap<String, String>,
86}
87
88fn text_map(value: Option<&Value>) -> BTreeMap<String, String> {
89 value
90 .and_then(Value::as_object)
91 .map(|map| map.iter().map(|(k, v)| (k.clone(), expr::to_text(v))).collect())
92 .unwrap_or_default()
93}
94
95/// A step's title when it has no name, as GitHub shows it.
96fn default_title(step: &Map<String, Value>) -> String {
97 if let Some(uses) = step.get("uses").and_then(Value::as_str) {
98 return format!("Run {uses}");
99 }
100 let run = step.get("run").map(expr::to_text).unwrap_or_default();
101 let first = run.lines().find(|line| !line.trim().is_empty()).unwrap_or_default().trim();
102 format!("Run {first}")
103}
104
105impl Job {
A repository has its own sidebar, as settings do106 pub(crate) fn base_env_value(&self, name: &str) -> Option<String> {
107 self.base_env.get(name).cloned()
108 }
109
GitHub Actions on g1t, part two: running workflows110 fn status(&self) -> Status {
111 if self.failed { Status::Failure } else { Status::Success }
112 }
113
114 /// The contexts an expression in a step can use.
115 pub(crate) fn contexts_for(&self, frame: &Frame, env: &BTreeMap<String, String>) -> Map<String, Value> {
116 let mut contexts = self.contexts.clone();
117 contexts.insert("env".into(), Value::Object(env.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect()));
118 contexts.insert("steps".into(), Value::Object(frame.steps.clone()));
119 contexts.insert("job".into(), json!({ "status": if self.failed { "failure" } else { "success" } }));
120 if let Some(inputs) = &frame.inputs {
121 contexts.insert("inputs".into(), inputs.clone());
122 }
123 if let Some(path) = &frame.action_path
124 && let Some(github) = contexts.get_mut("github")
125 {
126 github["action_path"] = Value::String(path.clone());
127 }
128 contexts
129 }
130
131 /// Runs `f` with a scope over these contexts.
132 pub(crate) fn with_scope<T>(&self, contexts: &Map<String, Value>, f: impl FnOnce(&Scope) -> T) -> T {
133 let workspace = self.workspace.clone();
134 let hash = move |patterns: &[String]| files::hash_files(&workspace, patterns);
135 let scope = Scope {
136 contexts,
137 status: self.status(),
138 hash_files: Some(&hash),
139 };
140 f(&scope)
141 }
142
143 /// The `env` context for a step: the workflow's, the job's, what earlier
144 /// steps wrote to `GITHUB_ENV`, and the frame's.
145 fn env_context(&self, frame: &Frame) -> BTreeMap<String, String> {
146 let mut env = self.added_env.clone();
147 env.extend(self.workflow_env.clone());
148 env.extend(self.job_env.clone());
149 env.extend(frame.env.clone());
150 env
151 }
152
153 /// What a process for a step is given.
154 pub(crate) fn process_env(&self, env: &BTreeMap<String, String>, files: &StepFiles) -> BTreeMap<String, String> {
155 let mut out = self.base_env.clone();
156 out.extend(env.clone());
157 for (name, value) in files.variables() {
158 out.insert(name.to_owned(), value);
159 }
160 if !self.path_prepend.is_empty() {
161 let current = out.get("PATH").cloned().unwrap_or_default();
Fast pages, required checks on the branch, self-hosted runners, honest incidents162 let separator = paths::PATH_SEPARATOR;
163 out.insert("PATH".into(), format!("{}{separator}{current}", self.path_prepend.join(separator)));
GitHub Actions on g1t, part two: running workflows164 }
165 out
166 }
167
168 /// Takes in what a step wrote to its files. Returns its outputs.
169 pub(crate) fn absorb(&mut self, files: &StepFiles, commands: &Commands) -> (BTreeMap<String, String>, BTreeMap<String, String>) {
170 let mut outputs: BTreeMap<String, String> = commands.outputs.clone();
171 match files::key_values(&StepFiles::read(&files.output)) {
172 Ok(values) => outputs.extend(values),
173 Err(problem) => self.log.line(&format!("##[error]$GITHUB_OUTPUT: {problem}")),
174 }
175 match files::key_values(&StepFiles::read(&files.env)) {
176 Ok(values) => {
177 for (name, value) in values {
178 if name.starts_with("GITHUB_") || name == "NODE_OPTIONS" {
179 self.log.line(&format!("##[warning]{name} cannot be set through $GITHUB_ENV."));
180 continue;
181 }
182 self.added_env.insert(name, value);
183 }
184 }
185 Err(problem) => self.log.line(&format!("##[error]$GITHUB_ENV: {problem}")),
186 }
187 for line in StepFiles::read(&files.path).lines().map(str::trim).filter(|l| !l.is_empty()) {
188 self.path_prepend.insert(0, line.to_owned());
189 }
190 let mut state = commands.state.clone();
191 if let Ok(values) = files::key_values(&StepFiles::read(&files.state)) {
192 state.extend(values);
193 }
194 let summary = StepFiles::read(&files.summary);
195 if !summary.trim().is_empty() {
196 self.log.line("##[group]Step summary");
197 for line in summary.lines() {
198 self.log.line(line);
199 }
200 self.log.line("##[endgroup]");
201 }
202 (outputs, state)
203 }
204
205 pub(crate) fn remaining_time(&self) -> Duration {
206 self.remaining()
207 }
208
209 fn remaining(&self) -> Duration {
210 self.deadline.saturating_duration_since(Instant::now())
211 }
212
213 /// Runs a shell script for a `run` step.
214 pub(crate) fn run_script(
215 &mut self,
216 script: &str,
217 shell: Option<&str>,
218 working_directory: Option<&str>,
219 env: &BTreeMap<String, String>,
220 timeout: Duration,
221 ) -> (bool, BTreeMap<String, String>, BTreeMap<String, String>) {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look222 crate::abuse::touch();
223 // Mining is never a workflow's job (abuse.rs).
224 if let Some(miner) = crate::abuse::miner_in(script) {
225 self.log.line(&format!("##[error]g1t does not run cryptocurrency miners ({miner}). This step was not run."));
226 return (false, BTreeMap::new(), BTreeMap::new());
227 }
GitHub Actions on g1t, part two: running workflows228 let id = format!("{:x}", rand_id());
229 let shell = shell.map(str::trim).filter(|s| !s.is_empty());
230 let (program, args, extension): (String, Vec<String>, &str) = match shell {
Fast pages, required checks on the branch, self-hosted runners, honest incidents231 // A self-hosted Windows runner, as GitHub's: PowerShell.
232 None if cfg!(windows) => (windows_powershell(), powershell_args(), "ps1"),
GitHub Actions on g1t, part two: running workflows233 None => ("bash".into(), vec!["-e".into(), "{0}".into()], "sh"),
234 Some("bash") => ("bash".into(), vec!["--noprofile".into(), "--norc".into(), "-eo".into(), "pipefail".into(), "{0}".into()], "sh"),
235 Some("sh") => ("sh".into(), vec!["-e".into(), "{0}".into()], "sh"),
236 Some("python") => ("python3".into(), vec!["{0}".into()], "py"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents237 Some("pwsh") if cfg!(windows) || program_exists("pwsh") => ("pwsh".into(), powershell_args(), "ps1"),
238 Some("powershell") if cfg!(windows) => ("powershell".into(), powershell_args(), "ps1"),
239 Some("cmd") if cfg!(windows) => (
240 "cmd".into(),
241 vec!["/D".into(), "/E:ON".into(), "/V:OFF".into(), "/S".into(), "/C".into(), "CALL \"{0}\"".into()],
242 "cmd",
243 ),
GitHub Actions on g1t, part two: running workflows244 Some(other @ ("pwsh" | "powershell" | "cmd")) => {
Fast pages, required checks on the branch, self-hosted runners, honest incidents245 self.log.line(&format!(
246 "##[error]`shell: {other}` needs Windows or PowerShell, which g1t's Linux runners do not have. A self-hosted Windows runner can run it: `runs-on: [self-hosted, windows]`."
247 ));
GitHub Actions on g1t, part two: running workflows248 return (false, BTreeMap::new(), BTreeMap::new());
249 }
250 Some(custom) => {
251 let mut parts = custom.split_whitespace().map(str::to_owned);
252 let program = parts.next().unwrap_or_default();
253 let mut args: Vec<String> = parts.collect();
254 if !args.iter().any(|a| a.contains("{0}")) {
255 args.push("{0}".into());
256 }
257 (program, args, "sh")
258 }
259 };
260 let script_path = self.temp.join(format!("{id}.{extension}"));
261 if let Err(error) = std::fs::write(&script_path, script) {
262 self.log.line(&format!("##[error]Could not write the script: {error}"));
263 return (false, BTreeMap::new(), BTreeMap::new());
264 }
265 let files = match StepFiles::new(&self.temp, &id) {
266 Ok(files) => files,
267 Err(error) => {
268 self.log.line(&format!("##[error]Could not make the step's files: {error}"));
269 return (false, BTreeMap::new(), BTreeMap::new());
270 }
271 };
Fast pages, required checks on the branch, self-hosted runners, honest incidents272 let args: Vec<String> = args.iter().map(|a| a.replace("{0}", &paths::shown(&script_path))).collect();
GitHub Actions on g1t, part two: running workflows273 self.log.line(&format!("shell: {program} {}", args.join(" ")));
274 let dir = match working_directory {
275 Some(dir) if Path::new(dir).is_absolute() => PathBuf::from(dir),
276 Some(dir) => self.workspace.join(dir),
277 None => self.workspace.clone(),
278 };
279 let mut command = Command::new(&program);
280 command.args(&args).current_dir(&dir).env_clear().envs(self.process_env(env, &files));
281 let mut commands = Commands {
282 debug: self.debug,
283 ..Commands::default()
284 };
285 let ended = process::run(command, timeout.min(self.remaining()), &mut self.log, &mut commands);
286 let ok = match ended {
287 Ok(Ended::Exited(0)) => true,
288 Ok(Ended::Exited(code)) => {
289 self.log.line(&format!("##[error]Process completed with exit code {code}."));
290 false
291 }
292 Ok(Ended::TimedOut) => {
293 self.log.line("##[error]The step ran past its time limit and was stopped.");
294 false
295 }
296 Err(error) => {
297 self.log.line(&format!("##[error]{program} could not be started: {error}"));
298 false
299 }
300 };
301 let (outputs, state) = self.absorb(&files, &commands);
302 (ok, outputs, state)
303 }
304
305 /// Runs one step of a frame. Returns whether it succeeded (its
306 /// conclusion). `number` is the step the log belongs to.
307 pub(crate) fn step(&mut self, frame: &mut Frame, step: &Map<String, Value>, number: u32, report: bool, defaults: &Map<String, Value>) -> bool {
308 let env_before = self.env_context(frame);
309 let contexts = self.contexts_for(frame, &env_before);
310 let title = match step.get("name").map(expr::to_text) {
311 Some(name) => self.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name),
312 None => default_title(step),
313 };
314 let condition = step.get("if").map(expr::to_text).unwrap_or_default();
315 let run_it = match self.with_scope(&contexts, |scope| expr::condition(&condition, scope)) {
316 Ok(run_it) => run_it,
317 Err(problem) => {
318 self.log.line(&format!("##[error]The step's `if` does not read: {problem}"));
319 self.failed = true;
320 if report {
321 self.log.step_state(number, &title, "completed", Some("failure"));
322 }
323 return false;
324 }
325 };
326 let id = step.get("id").map(expr::to_text);
327 if !run_it {
328 if let Some(id) = &id {
329 frame.steps.insert(id.clone(), json!({ "outputs": {}, "outcome": "skipped", "conclusion": "skipped" }));
330 }
331 if report {
332 self.log.step_state(number, &title, "completed", Some("skipped"));
333 }
334 return true;
335 }
336 if report {
337 self.log.step(number);
338 self.log.step_state(number, &title, "in_progress", None);
339 }
340
341 // The step's own env, read with the contexts before it.
342 let mut env = env_before.clone();
343 if let Some(Value::Object(step_env)) = step.get("env") {
344 for (name, value) in step_env {
345 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
346 env.insert(name.clone(), expr::to_text(&value));
347 }
348 }
349 let timeout = step
350 .get("timeout-minutes")
351 .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok())
352 .and_then(|v| v.as_f64().or_else(|| expr::to_text(&v).parse().ok()))
353 .map_or(Duration::from_secs(6 * 3600), |minutes| Duration::from_secs_f64(minutes * 60.0));
354 let continue_on_error = step
355 .get("continue-on-error")
356 .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok())
357 .is_some_and(|v| expr::truthy(&v));
358
359 let (ok, outputs) = if let Some(run) = step.get("run").map(expr::to_text) {
360 let script = match self.with_scope(&contexts, |scope| expr::interpolate(&run, scope)) {
361 Ok(script) => script,
362 Err(problem) => {
363 self.log.line(&format!("##[error]The script does not read: {problem}"));
364 String::new()
365 }
366 };
367 self.log.line(&format!("##[group]{title}"));
368 for line in script.lines() {
369 self.log.line(line);
370 }
371 self.log.line("##[endgroup]");
372 let shell = step
373 .get("shell")
374 .map(expr::to_text)
375 .or_else(|| defaults.get("shell").map(expr::to_text));
376 if frame.action_path.is_some() && shell.is_none() {
377 self.log.line("##[error]A composite action's `run` steps need a `shell`.");
378 (false, BTreeMap::new())
379 } else {
380 let working_directory = step
381 .get("working-directory")
382 .or_else(|| defaults.get("working-directory"))
383 .map(|v| self.with_scope(&contexts, |scope| expr::interpolate(&expr::to_text(v), scope)).unwrap_or_else(|_| expr::to_text(v)));
384 let mut env = env;
385 if let Some(path) = &frame.action_path {
386 env.insert("GITHUB_ACTION_PATH".into(), path.clone());
387 }
388 let (ok, outputs, _) = self.run_script(&script, shell.as_deref(), working_directory.as_deref(), &env, timeout);
389 (ok, outputs)
390 }
391 } else if let Some(uses) = step.get("uses").map(expr::to_text) {
392 let with: BTreeMap<String, String> = match step.get("with") {
393 Some(Value::Object(with)) => with
394 .iter()
395 .map(|(k, v)| {
396 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).unwrap_or(Value::Null);
397 (k.clone(), expr::to_text(&value))
398 })
399 .collect(),
400 _ => BTreeMap::new(),
401 };
402 self.uses(&uses, &with, &env, frame, &title, id.as_deref(), timeout)
403 } else {
404 self.log.line("##[error]A step needs `run` or `uses`.");
405 (false, BTreeMap::new())
406 };
407
408 let outcome = if ok { "success" } else { "failure" };
409 let conclusion = if ok || continue_on_error { "success" } else { "failure" };
410 if !ok && continue_on_error {
411 self.log.line("##[warning]The step failed, and `continue-on-error` lets the job go on.");
412 }
413 if let Some(id) = &id {
414 let outputs: Map<String, Value> = outputs.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect();
415 frame.steps.insert(id.clone(), json!({ "outputs": outputs, "outcome": outcome, "conclusion": conclusion }));
416 }
417 if conclusion == "failure" {
418 self.failed = true;
419 }
420 if report {
421 self.log.step_state(number, &title, "completed", Some(conclusion));
422 }
423 conclusion == "success"
424 }
425
426 fn report_steps(&self) {
427 self.log.steps(&self.step_names);
428 }
429}
430
Fast pages, required checks on the branch, self-hosted runners, honest incidents431/// PowerShell on Windows: `pwsh` (PowerShell 7) if it is installed, as on
432/// GitHub's Windows runners, else Windows PowerShell.
433fn windows_powershell() -> String {
434 if program_exists("pwsh") { "pwsh".into() } else { "powershell".into() }
435}
436
437/// How GitHub runs a PowerShell step: the script, stopping at the first error.
438fn powershell_args() -> Vec<String> {
439 vec!["-NoLogo".into(), "-NoProfile".into(), "-NonInteractive".into(), "-Command".into(), ". '{0}'".into()]
440}
441
442/// Whether `program` is on `PATH`.
443fn program_exists(program: &str) -> bool {
444 Command::new(program)
445 .arg(if program == "cmd" { "/C" } else { "-Version" })
446 .stdout(std::process::Stdio::null())
447 .stderr(std::process::Stdio::null())
448 .status()
449 .is_ok()
450}
451
GitHub Actions on g1t, part two: running workflows452/// An id for files, unique enough within one job.
453fn rand_id() -> u64 {
454 use std::sync::atomic::{AtomicU64, Ordering};
455 static NEXT: AtomicU64 = AtomicU64::new(1);
456 let nanos = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH).map(|d| d.as_nanos() as u64).unwrap_or(0);
457 nanos ^ (NEXT.fetch_add(1, Ordering::Relaxed) << 48)
458}
459
460fn interpolated_map(job: &Job, value: Option<&Value>, contexts: &Map<String, Value>) -> BTreeMap<String, String> {
461 let mut out = BTreeMap::new();
462 if let Some(Value::Object(map)) = value {
463 for (name, value) in map {
464 let value = job.with_scope(contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
465 out.insert(name.clone(), expr::to_text(&value));
466 }
467 }
468 out
469}
470
Fast pages, required checks on the branch, self-hosted runners, honest incidents471fn setup(mut spec: Value, api: Api) -> Result<Job> {
GitHub Actions on g1t, part two: running workflows472 let masks: Vec<String> = spec["masks"].as_array().map(|m| m.iter().filter_map(|v| v.as_str().map(str::to_owned)).collect()).unwrap_or_default();
473 let log = Log::new(api, masks);
Fast pages, required checks on the branch, self-hosted runners, honest incidents474 // On a self-hosted runner's own machine, GitHub's layout lives in a
475 // folder of the runner's (paths.rs).
476 for part in ["variables", "github"] {
477 paths::relocate(&mut spec[part]);
478 }
479 paths::relocate(&mut spec["contexts"]["runner"]);
480 let workspace = paths::under_home(WORKSPACE);
481 let temp = paths::under_home(TEMP);
GitHub Actions on g1t, part two: running workflows482 std::fs::create_dir_all(&workspace).context("could not make the workspace")?;
483 std::fs::create_dir_all(&temp).context("could not make the temporary folder")?;
484 std::fs::write(temp.join("event.json"), serde_json::to_string_pretty(&spec["event"])?)?;
485
486 // This process's environment, less what only it should see.
487 let mut base_env: BTreeMap<String, String> =
488 std::env::vars().filter(|(name, _)| !matches!(name.as_str(), "ACTIONS_TOKEN" | "ACTIONS_JOB" | "MODE") && !name.starts_with("G1T_")).collect();
489 base_env.insert("HOME".into(), std::env::var("HOME").unwrap_or_else(|_| "/home/node".into()));
490 base_env.extend(text_map(spec.get("variables")));
Fast pages, required checks on the branch, self-hosted runners, honest incidents491 base_env.insert("GITHUB_EVENT_PATH".into(), paths::shown(&temp.join("event.json")));
GitHub Actions on g1t, part two: running workflows492
493 let mut contexts: Map<String, Value> = spec["contexts"].as_object().cloned().unwrap_or_default();
494 contexts.insert("github".into(), spec["github"].clone());
495 let debug = contexts
496 .get("secrets")
497 .and_then(|s| s.get("ACTIONS_STEP_DEBUG"))
498 .or_else(|| contexts.get("vars").and_then(|v| v.get("ACTIONS_STEP_DEBUG")))
499 .is_some_and(|v| expr::to_text(v) == "true");
500
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API501 // `timeoutMinutes` is how the API spelled it before its bodies were
502 // `snake_case`.
503 let timeout = spec["timeout_minutes"]
504 .as_u64()
505 .or_else(|| spec["timeoutMinutes"].as_u64())
506 .unwrap_or(60);
GitHub Actions on g1t, part two: running workflows507 let mut job = Job {
508 log,
509 spec,
510 workspace,
511 temp,
512 base_env,
513 added_env: BTreeMap::new(),
514 path_prepend: Vec::new(),
515 workflow_env: BTreeMap::new(),
516 job_env: BTreeMap::new(),
517 contexts,
518 failed: false,
519 posts: Vec::new(),
520 step_names: Vec::new(),
521 deadline: Instant::now() + Duration::from_secs(timeout * 60),
522 debug,
523 last_node_outputs: BTreeMap::new(),
524 last_node_state: BTreeMap::new(),
525 };
526
527 // The workflow's env reads github, secrets, inputs and vars; the job's
528 // also its matrix, needs and strategy.
529 let mut contexts = job.contexts.clone();
530 contexts.insert("env".into(), json!({}));
531 job.workflow_env = interpolated_map(&job, job.spec["workflow"].get("env"), &contexts);
532 contexts.insert("env".into(), Value::Object(job.workflow_env.iter().map(|(k, v)| (k.clone(), json!(v))).collect()));
533 job.job_env = interpolated_map(&job, job.spec["spec"].get("env"), &contexts);
534 Ok(job)
535}
536
537/// The job's `defaults.run`, its own over the workflow's.
538fn run_defaults(spec: &Value) -> Map<String, Value> {
539 let mut defaults = spec["workflow"]["defaults"]["run"].as_object().cloned().unwrap_or_default();
540 if let Some(own) = spec["spec"]["defaults"]["run"].as_object() {
541 defaults.extend(own.clone());
542 }
543 defaults
544}
545
546fn run_job(job: &mut Job) {
547 let steps: Vec<Map<String, Value>> = job.spec["spec"]["steps"]
548 .as_array()
549 .map(|steps| steps.iter().filter_map(|s| s.as_object().cloned()).collect())
550 .unwrap_or_default();
551 let defaults = run_defaults(&job.spec);
552
553 // Step names as they read before anything has run.
554 let frame = Frame::default();
555 let env = job.env_context(&frame);
556 let contexts = job.contexts_for(&frame, &env);
557 job.step_names = steps
558 .iter()
559 .map(|step| match step.get("name").map(expr::to_text) {
560 Some(name) => job.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name),
561 None => default_title(step),
562 })
563 .collect();
564 job.report_steps();
565
566 job.log.step(0);
567 job.log.line(&format!("Job: {}", job.spec["name"].as_str().unwrap_or_default()));
Fast pages, required checks on the branch, self-hosted runners, honest incidents568 let variables = &job.spec["variables"];
569 if variables["RUNNER_ENVIRONMENT"] == "self-hosted" {
570 let text = |name: &str| variables[name].as_str().unwrap_or_default().to_owned();
571 job.log.line(&format!("Runner: {}, self-hosted, {} {}", text("RUNNER_NAME"), text("RUNNER_OS"), text("RUNNER_ARCH")));
572 } else {
573 job.log.line("Runner: g1t, Linux X64 (Debian bookworm, Node 24, Python 3, Go, Rust)");
574 }
GitHub Actions on g1t, part two: running workflows575 if let Some(Value::Object(matrix)) = job.contexts.get("matrix")
576 && !matrix.is_empty()
577 {
578 job.log.line(&format!("Matrix: {}", serde_json::to_string(matrix).unwrap_or_default()));
579 }
580 job.log.flush();
581
582 let mut frame = Frame::default();
583 for (index, step) in steps.iter().enumerate() {
584 job.step(&mut frame, step, index as u32 + 1, true, &defaults);
585 if job.remaining().is_zero() {
586 job.log.line("##[error]The job ran past its time limit.");
587 job.failed = true;
588 break;
589 }
590 }
591
592 // Post steps, last registered first.
593 let posts: Vec<Post> = std::mem::take(&mut job.posts);
594 for post in posts.into_iter().rev() {
595 let number = job.step_names.len() as u32 + 1;
596 job.step_names.push(post.name.clone());
597 job.report_steps();
598 let contexts = job.contexts_for(&frame, &job.env_context(&frame));
599 let run_it = job.with_scope(&contexts, |scope| expr::condition(&post.condition, scope)).unwrap_or(true);
600 if !run_it {
601 job.log.step_state(number, &post.name, "completed", Some("skipped"));
602 continue;
603 }
604 job.log.step(number);
605 job.log.step_state(number, &post.name, "in_progress", None);
A repository has its own sidebar, as settings do606 let ok = match &post.run {
607 PostRun::Node { action_dir, script } => job.run_node(action_dir, script, &post.env),
608 PostRun::CacheSave { key, paths } => job.cache_save(key, paths),
609 };
GitHub Actions on g1t, part two: running workflows610 job.log.step_state(number, &post.name, "completed", Some(if ok { "success" } else { "failure" }));
611 if !ok {
612 job.failed = true;
613 }
614 }
615
616 // The job's outputs, read now that every step has run.
617 let env = job.env_context(&frame);
618 let contexts = job.contexts_for(&frame, &env);
619 let mut outputs = Map::new();
620 if let Some(Value::Object(declared)) = job.spec["spec"].get("outputs") {
621 for (name, value) in declared {
622 let value = job.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
623 outputs.insert(name.clone(), Value::String(expr::to_text(&value)));
624 }
625 }
626 let conclusion = if job.failed { "failure" } else { "success" };
627 job.log.done(conclusion, &outputs, None);
628}
629
630pub(crate) fn main() -> i32 {
631 let api = match (crate::env("G1T_API"), crate::env("ACTIONS_JOB"), crate::env("ACTIONS_TOKEN")) {
632 (Ok(base), Ok(job), Ok(token)) => Api { base, job, token },
633 _ => {
634 eprintln!("g1t-runner: G1T_API, ACTIONS_JOB and ACTIONS_TOKEN are needed");
635 return 2;
636 }
637 };
638 let spec = match api.spec() {
639 Ok(spec) => spec,
640 Err(error) => {
641 eprintln!("g1t-runner: could not fetch the job: {error:#}");
642 api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not fetch the job: {error}") }));
643 return 1;
644 }
645 };
646 let reporter = Api {
647 base: api.base.clone(),
648 job: api.job.clone(),
649 token: api.token.clone(),
650 };
651 let mut job = match setup(spec, reporter) {
652 Ok(job) => job,
653 Err(error) => {
654 api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not set up: {error:#}") }));
655 return 1;
656 }
657 };
658 run_job(&mut job);
659 if job.failed { 1 } else { 0 }
660}