Skip to content

g1t/crates/runner/src/actions/mod.rs

747 lines32,688 bytesCodeBlameRaw
1//! Runs one GitHub Actions job, as GitHub's runner would: its steps in
2//! order, each `run` in a shell and each `uses` as the action it names,
3//! with the `${{ }}` contexts, the `GITHUB_*` variables and files, and the
4//! workflow commands steps print. It reports every step and the log to
5//! g1t as it goes.
6//!
7//! Configuration comes from the environment: `G1T_API`, and `ACTIONS_JOB`
8//! and `ACTIONS_TOKEN`, the job and its own token. Everything else, the
9//! job's definition, its contexts and its secrets, is fetched with them.
10
11mod blobs;
12mod containers;
13mod files;
14mod glob;
15mod paths;
16mod process;
17mod report;
18mod uses;
19mod zip;
20
21use std::collections::{BTreeMap, BTreeSet};
22use std::path::{Path, PathBuf};
23use std::process::Command;
24use std::time::{Duration, Instant};
25
26use anyhow::{Context, Result};
27use g1t_actions::events::WORKSPACE;
28use g1t_actions::expr::{self, Scope, Status};
29use serde_json::{Map, Value, json};
30
31use files::StepFiles;
32use process::{Commands, Ended};
33use report::{Api, Log};
34
35const TEMP: &str = "/home/runner/_temp";
36
37/// Who is running steps: the job itself, or a composite action inside it.
38#[derive(Clone, Default)]
39pub(crate) struct Frame {
40 /// The `steps` context.
41 pub(crate) steps: Map<String, Value>,
42 /// A composite action's `inputs`, in place of the workflow's.
43 pub(crate) inputs: Option<Value>,
44 /// A composite action's folder, for `github.action_path`.
45 pub(crate) action_path: Option<String>,
46 /// Variables a composite action's caller set for its steps.
47 pub(crate) env: BTreeMap<String, String>,
48}
49
50/// A step run when the job's steps are done: an action's `post`, or
51/// saving the cache.
52pub(crate) struct Post {
53 pub(crate) name: String,
54 pub(crate) condition: String,
55 pub(crate) env: BTreeMap<String, String>,
56 pub(crate) run: PostRun,
57}
58
59pub(crate) enum PostRun {
60 Node { action_dir: PathBuf, script: String },
61 CacheSave { key: String, paths: Vec<String>, version: String },
62 /// A Docker action's `post-entrypoint`.
63 Docker(containers::DockerRun),
64}
65
66pub(crate) struct Job {
67 pub(crate) log: Log,
68 pub(crate) spec: Value,
69 pub(crate) workspace: PathBuf,
70 pub(crate) temp: PathBuf,
71 /// This process's own variables, less its credentials, and GitHub's.
72 base_env: BTreeMap<String, String>,
73 /// Written to `GITHUB_ENV` by earlier steps.
74 added_env: BTreeMap<String, String>,
75 /// Written to `GITHUB_PATH` by earlier steps, newest first.
76 path_prepend: Vec<String>,
77 workflow_env: BTreeMap<String, String>,
78 job_env: BTreeMap<String, String>,
79 /// github, vars, secrets, inputs, matrix, needs, strategy, runner.
80 pub(crate) contexts: Map<String, Value>,
81 pub(crate) failed: bool,
82 pub(crate) posts: Vec<Post>,
83 step_names: Vec<String>,
84 deadline: Instant,
85 debug: bool,
86 /// What the last Node process left, for the step that ran it.
87 pub(crate) last_node_outputs: BTreeMap<String, String>,
88 pub(crate) last_node_state: BTreeMap<String, String>,
89 /// The names of the sandbox's own variables, which a container does
90 /// not get.
91 host_env: BTreeSet<String>,
92 /// Whether this job has a Docker Engine of its own (g1t's machines).
93 pub(crate) docker_hosted: bool,
94 /// The job's network, once its containers have one.
95 pub(crate) network: Option<String>,
96 /// `services:`, by their names, and their containers' names.
97 pub(crate) services: Vec<(String, String)>,
98 /// `container:`, once started.
99 pub(crate) container: Option<containers::JobContainer>,
100 /// The `job` context's `container` and `services`.
101 pub(crate) job_context: Map<String, Value>,
102 /// Docker actions' images built in this job.
103 pub(crate) built_actions: containers::Built,
104}
105
106fn text_map(value: Option<&Value>) -> BTreeMap<String, String> {
107 value
108 .and_then(Value::as_object)
109 .map(|map| map.iter().map(|(k, v)| (k.clone(), expr::to_text(v))).collect())
110 .unwrap_or_default()
111}
112
113/// A step's title when it has no name, as GitHub shows it.
114fn default_title(step: &Map<String, Value>) -> String {
115 if let Some(uses) = step.get("uses").and_then(Value::as_str) {
116 return format!("Run {uses}");
117 }
118 let run = step.get("run").map(expr::to_text).unwrap_or_default();
119 let first = run.lines().find(|line| !line.trim().is_empty()).unwrap_or_default().trim();
120 format!("Run {first}")
121}
122
123impl Job {
124 pub(crate) fn base_env_value(&self, name: &str) -> Option<String> {
125 self.base_env.get(name).cloned()
126 }
127
128 /// What earlier steps added to `PATH`, newest first.
129 pub(crate) fn path_prepend_entries(&self) -> &[String] {
130 &self.path_prepend
131 }
132
133 fn status(&self) -> Status {
134 if self.failed { Status::Failure } else { Status::Success }
135 }
136
137 /// The contexts an expression in a step can use.
138 pub(crate) fn contexts_for(&self, frame: &Frame, env: &BTreeMap<String, String>) -> Map<String, Value> {
139 let mut contexts = self.contexts.clone();
140 contexts.insert("env".into(), Value::Object(env.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect()));
141 contexts.insert("steps".into(), Value::Object(frame.steps.clone()));
142 contexts.insert("job".into(), containers::job_context(if self.failed { "failure" } else { "success" }, &self.job_context));
143 if let Some(inputs) = &frame.inputs {
144 contexts.insert("inputs".into(), inputs.clone());
145 }
146 if let Some(path) = &frame.action_path
147 && let Some(github) = contexts.get_mut("github")
148 {
149 github["action_path"] = Value::String(path.clone());
150 }
151 contexts
152 }
153
154 /// Runs `f` with a scope over these contexts.
155 pub(crate) fn with_scope<T>(&self, contexts: &Map<String, Value>, f: impl FnOnce(&Scope) -> T) -> T {
156 let workspace = self.workspace.clone();
157 let hash = move |patterns: &[String]| files::hash_files(&workspace, patterns);
158 let scope = Scope {
159 contexts,
160 status: self.status(),
161 hash_files: Some(&hash),
162 };
163 f(&scope)
164 }
165
166 /// The `env` context for a step: the workflow's, the job's, what earlier
167 /// steps wrote to `GITHUB_ENV`, and the frame's.
168 pub(crate) fn env_context(&self, frame: &Frame) -> BTreeMap<String, String> {
169 let mut env = self.added_env.clone();
170 env.extend(self.workflow_env.clone());
171 env.extend(self.job_env.clone());
172 env.extend(frame.env.clone());
173 env
174 }
175
176 /// What a process for a step is given.
177 pub(crate) fn process_env(&self, env: &BTreeMap<String, String>, files: &StepFiles) -> BTreeMap<String, String> {
178 let mut out = self.base_env.clone();
179 out.extend(env.clone());
180 for (name, value) in files.variables() {
181 out.insert(name.to_owned(), value);
182 }
183 if !self.path_prepend.is_empty() {
184 let current = out.get("PATH").cloned().unwrap_or_default();
185 let separator = paths::PATH_SEPARATOR;
186 out.insert("PATH".into(), format!("{}{separator}{current}", self.path_prepend.join(separator)));
187 }
188 out
189 }
190
191 /// Takes in what a step wrote to its files. Returns its outputs.
192 pub(crate) fn absorb(&mut self, files: &StepFiles, commands: &Commands) -> (BTreeMap<String, String>, BTreeMap<String, String>) {
193 let mut outputs: BTreeMap<String, String> = commands.outputs.clone();
194 match files::key_values(&StepFiles::read(&files.output)) {
195 Ok(values) => outputs.extend(values),
196 Err(problem) => self.log.line(&format!("##[error]$GITHUB_OUTPUT: {problem}")),
197 }
198 match files::key_values(&StepFiles::read(&files.env)) {
199 Ok(values) => {
200 for (name, value) in values {
201 if name.starts_with("GITHUB_") || name == "NODE_OPTIONS" {
202 self.log.line(&format!("##[warning]{name} cannot be set through $GITHUB_ENV."));
203 continue;
204 }
205 self.added_env.insert(name, value);
206 }
207 }
208 Err(problem) => self.log.line(&format!("##[error]$GITHUB_ENV: {problem}")),
209 }
210 for line in StepFiles::read(&files.path).lines().map(str::trim).filter(|l| !l.is_empty()) {
211 self.path_prepend.insert(0, line.to_owned());
212 }
213 let mut state = commands.state.clone();
214 if let Ok(values) = files::key_values(&StepFiles::read(&files.state)) {
215 state.extend(values);
216 }
217 let summary = StepFiles::read(&files.summary);
218 if !summary.trim().is_empty() {
219 self.log.line("##[group]Step summary");
220 for line in summary.lines() {
221 self.log.line(line);
222 }
223 self.log.line("##[endgroup]");
224 }
225 (outputs, state)
226 }
227
228 pub(crate) fn remaining_time(&self) -> Duration {
229 self.remaining()
230 }
231
232 fn remaining(&self) -> Duration {
233 self.deadline.saturating_duration_since(Instant::now())
234 }
235
236 /// Runs a shell script for a `run` step.
237 pub(crate) fn run_script(
238 &mut self,
239 script: &str,
240 shell: Option<&str>,
241 working_directory: Option<&str>,
242 env: &BTreeMap<String, String>,
243 timeout: Duration,
244 ) -> (bool, BTreeMap<String, String>, BTreeMap<String, String>) {
245 crate::abuse::touch();
246 // Mining is never a workflow's job (abuse.rs).
247 if let Some(miner) = crate::abuse::miner_in(script) {
248 self.log.line(&format!("##[error]g1t does not run cryptocurrency miners ({miner}). This step was not run."));
249 return (false, BTreeMap::new(), BTreeMap::new());
250 }
251 let id = format!("{:x}", rand_id());
252 let shell = shell.map(str::trim).filter(|s| !s.is_empty());
253 let (program, args, extension): (String, Vec<String>, &str) = match shell {
254 // A self-hosted Windows runner, as GitHub's: PowerShell.
255 None if cfg!(windows) => (windows_powershell(), powershell_args(), "ps1"),
256 // A job container without bash, as GitHub's runner does.
257 None if self.container.as_ref().is_some_and(|c| c.shell == "sh") => ("sh".into(), vec!["-e".into(), "{0}".into()], "sh"),
258 None => ("bash".into(), vec!["-e".into(), "{0}".into()], "sh"),
259 Some("bash") => ("bash".into(), vec!["--noprofile".into(), "--norc".into(), "-eo".into(), "pipefail".into(), "{0}".into()], "sh"),
260 Some("sh") => ("sh".into(), vec!["-e".into(), "{0}".into()], "sh"),
261 Some("python") => ("python3".into(), vec!["{0}".into()], "py"),
262 Some("pwsh") if cfg!(windows) || program_exists("pwsh") => ("pwsh".into(), powershell_args(), "ps1"),
263 Some("powershell") if cfg!(windows) => ("powershell".into(), powershell_args(), "ps1"),
264 Some("cmd") if cfg!(windows) => (
265 "cmd".into(),
266 vec!["/D".into(), "/E:ON".into(), "/V:OFF".into(), "/S".into(), "/C".into(), "CALL \"{0}\"".into()],
267 "cmd",
268 ),
269 Some(other @ ("pwsh" | "powershell" | "cmd")) => {
270 self.log.line(&format!(
271 "##[error]`shell: {other}` needs Windows or PowerShell, which g1t's Linux runners do not have. A self-hosted Windows runner can run it: `runs-on: [self-hosted, windows]`."
272 ));
273 return (false, BTreeMap::new(), BTreeMap::new());
274 }
275 Some(custom) => {
276 let mut parts = custom.split_whitespace().map(str::to_owned);
277 let program = parts.next().unwrap_or_default();
278 let mut args: Vec<String> = parts.collect();
279 if !args.iter().any(|a| a.contains("{0}")) {
280 args.push("{0}".into());
281 }
282 (program, args, "sh")
283 }
284 };
285 let script_path = self.temp.join(format!("{id}.{extension}"));
286 if let Err(error) = std::fs::write(&script_path, script) {
287 self.log.line(&format!("##[error]Could not write the script: {error}"));
288 return (false, BTreeMap::new(), BTreeMap::new());
289 }
290 let files = match StepFiles::new(&self.temp, &id) {
291 Ok(files) => files,
292 Err(error) => {
293 self.log.line(&format!("##[error]Could not make the step's files: {error}"));
294 return (false, BTreeMap::new(), BTreeMap::new());
295 }
296 };
297 let args: Vec<String> = args.iter().map(|a| a.replace("{0}", &paths::shown(&script_path))).collect();
298 self.log.line(&format!("shell: {program} {}", args.join(" ")));
299 let dir = match working_directory {
300 Some(dir) if Path::new(dir).is_absolute() => PathBuf::from(dir),
301 Some(dir) => self.workspace.join(dir),
302 None => self.workspace.clone(),
303 };
304 let full = self.process_env(env, &files);
305 let in_container = self.container.as_ref().map(|c| c.path.clone()).and_then(|image_path| {
306 let inside = self.container_env(env, full.clone(), &image_path);
307 self.in_container(&program, &args, &dir, inside)
308 });
309 let command = match in_container {
310 Some(command) => command,
311 None => {
312 let mut command = Command::new(&program);
313 command.args(&args).current_dir(&dir).env_clear().envs(full);
314 command
315 }
316 };
317 let mut commands = Commands {
318 debug: self.debug,
319 ..Commands::default()
320 };
321 let ended = process::run(command, timeout.min(self.remaining()), &mut self.log, &mut commands);
322 let ok = match ended {
323 Ok(Ended::Exited(0)) => true,
324 Ok(Ended::Exited(code)) => {
325 self.log.line(&format!("##[error]Process completed with exit code {code}."));
326 false
327 }
328 Ok(Ended::TimedOut) => {
329 self.log.line("##[error]The step ran past its time limit and was stopped.");
330 false
331 }
332 Err(error) => {
333 self.log.line(&format!("##[error]{program} could not be started: {error}"));
334 false
335 }
336 };
337 let (outputs, state) = self.absorb(&files, &commands);
338 (ok, outputs, state)
339 }
340
341 /// Runs one step of a frame. Returns whether it succeeded (its
342 /// conclusion). `number` is the step the log belongs to.
343 pub(crate) fn step(&mut self, frame: &mut Frame, step: &Map<String, Value>, number: u32, report: bool, defaults: &Map<String, Value>) -> bool {
344 let env_before = self.env_context(frame);
345 let contexts = self.contexts_for(frame, &env_before);
346 let title = match step.get("name").map(expr::to_text) {
347 Some(name) => self.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name),
348 None => default_title(step),
349 };
350 let condition = step.get("if").map(expr::to_text).unwrap_or_default();
351 let run_it = match self.with_scope(&contexts, |scope| expr::condition(&condition, scope)) {
352 Ok(run_it) => run_it,
353 Err(problem) => {
354 self.log.line(&format!("##[error]The step's `if` does not read: {problem}"));
355 self.failed = true;
356 if report {
357 self.log.step_state(number, &title, "completed", Some("failure"));
358 }
359 return false;
360 }
361 };
362 let id = step.get("id").map(expr::to_text);
363 if !run_it {
364 if let Some(id) = &id {
365 frame.steps.insert(id.clone(), json!({ "outputs": {}, "outcome": "skipped", "conclusion": "skipped" }));
366 }
367 if report {
368 self.log.step_state(number, &title, "completed", Some("skipped"));
369 }
370 return true;
371 }
372 if report {
373 self.log.step(number);
374 self.log.step_state(number, &title, "in_progress", None);
375 }
376
377 // The step's own env, read with the contexts before it.
378 let mut env = env_before.clone();
379 if let Some(Value::Object(step_env)) = step.get("env") {
380 for (name, value) in step_env {
381 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
382 env.insert(name.clone(), expr::to_text(&value));
383 }
384 }
385 let timeout = step
386 .get("timeout-minutes")
387 .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok())
388 .and_then(|v| v.as_f64().or_else(|| expr::to_text(&v).parse().ok()))
389 .map_or(Duration::from_secs(6 * 3600), |minutes| Duration::from_secs_f64(minutes * 60.0));
390 let continue_on_error = step
391 .get("continue-on-error")
392 .and_then(|v| self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).ok())
393 .is_some_and(|v| expr::truthy(&v));
394
395 let (ok, outputs) = if let Some(run) = step.get("run").map(expr::to_text) {
396 let script = match self.with_scope(&contexts, |scope| expr::interpolate(&run, scope)) {
397 Ok(script) => script,
398 Err(problem) => {
399 self.log.line(&format!("##[error]The script does not read: {problem}"));
400 String::new()
401 }
402 };
403 self.log.line(&format!("##[group]{title}"));
404 for line in script.lines() {
405 self.log.line(line);
406 }
407 self.log.line("##[endgroup]");
408 let shell = step
409 .get("shell")
410 .map(expr::to_text)
411 .or_else(|| defaults.get("shell").map(expr::to_text));
412 if frame.action_path.is_some() && shell.is_none() {
413 self.log.line("##[error]A composite action's `run` steps need a `shell`.");
414 (false, BTreeMap::new())
415 } else {
416 let working_directory = step
417 .get("working-directory")
418 .or_else(|| defaults.get("working-directory"))
419 .map(|v| self.with_scope(&contexts, |scope| expr::interpolate(&expr::to_text(v), scope)).unwrap_or_else(|_| expr::to_text(v)));
420 let mut env = env;
421 if let Some(path) = &frame.action_path {
422 env.insert("GITHUB_ACTION_PATH".into(), path.clone());
423 }
424 let (ok, outputs, _) = self.run_script(&script, shell.as_deref(), working_directory.as_deref(), &env, timeout);
425 (ok, outputs)
426 }
427 } else if let Some(uses) = step.get("uses").map(expr::to_text) {
428 let with: BTreeMap<String, String> = match step.get("with") {
429 Some(Value::Object(with)) => with
430 .iter()
431 .map(|(k, v)| {
432 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(v, scope)).unwrap_or(Value::Null);
433 (k.clone(), expr::to_text(&value))
434 })
435 .collect(),
436 _ => BTreeMap::new(),
437 };
438 self.uses(&uses, &with, &env, frame, &title, id.as_deref(), timeout)
439 } else {
440 self.log.line("##[error]A step needs `run` or `uses`.");
441 (false, BTreeMap::new())
442 };
443
444 let outcome = if ok { "success" } else { "failure" };
445 let conclusion = if ok || continue_on_error { "success" } else { "failure" };
446 if !ok && continue_on_error {
447 self.log.line("##[warning]The step failed, and `continue-on-error` lets the job go on.");
448 }
449 if let Some(id) = &id {
450 let outputs: Map<String, Value> = outputs.iter().map(|(k, v)| (k.clone(), Value::String(v.clone()))).collect();
451 frame.steps.insert(id.clone(), json!({ "outputs": outputs, "outcome": outcome, "conclusion": conclusion }));
452 }
453 if conclusion == "failure" {
454 self.failed = true;
455 }
456 if report {
457 self.log.step_state(number, &title, "completed", Some(conclusion));
458 }
459 conclusion == "success"
460 }
461
462 fn report_steps(&self) {
463 self.log.steps(&self.step_names);
464 }
465}
466
467/// PowerShell on Windows: `pwsh` (PowerShell 7) if it is installed, as on
468/// GitHub's Windows runners, else Windows PowerShell.
469fn windows_powershell() -> String {
470 if program_exists("pwsh") { "pwsh".into() } else { "powershell".into() }
471}
472
473/// How GitHub runs a PowerShell step: the script, stopping at the first error.
474fn powershell_args() -> Vec<String> {
475 vec!["-NoLogo".into(), "-NoProfile".into(), "-NonInteractive".into(), "-Command".into(), ". '{0}'".into()]
476}
477
478/// Whether `program` is on `PATH`.
479fn program_exists(program: &str) -> bool {
480 Command::new(program)
481 .arg(if program == "cmd" { "/C" } else { "-Version" })
482 .stdout(std::process::Stdio::null())
483 .stderr(std::process::Stdio::null())
484 .status()
485 .is_ok()
486}
487
488/// An id for files, unique enough within one job.
489fn rand_id() -> u64 {
490 use std::sync::atomic::{AtomicU64, Ordering};
491 static NEXT: AtomicU64 = AtomicU64::new(1);
492 let nanos = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH).map(|d| d.as_nanos() as u64).unwrap_or(0);
493 nanos ^ (NEXT.fetch_add(1, Ordering::Relaxed) << 48)
494}
495
496fn interpolated_map(job: &Job, value: Option<&Value>, contexts: &Map<String, Value>) -> BTreeMap<String, String> {
497 let mut out = BTreeMap::new();
498 if let Some(Value::Object(map)) = value {
499 for (name, value) in map {
500 let value = job.with_scope(contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
501 out.insert(name.clone(), expr::to_text(&value));
502 }
503 }
504 out
505}
506
507fn setup(mut spec: Value, api: Api) -> Result<Job> {
508 let masks: Vec<String> = spec["masks"].as_array().map(|m| m.iter().filter_map(|v| v.as_str().map(str::to_owned)).collect()).unwrap_or_default();
509 let log = Log::new(api, masks);
510 // On a self-hosted runner's own machine, GitHub's layout lives in a
511 // folder of the runner's (paths.rs).
512 for part in ["variables", "github"] {
513 paths::relocate(&mut spec[part]);
514 }
515 paths::relocate(&mut spec["contexts"]["runner"]);
516 let workspace = paths::under_home(WORKSPACE);
517 let temp = paths::under_home(TEMP);
518 std::fs::create_dir_all(&workspace).context("could not make the workspace")?;
519 std::fs::create_dir_all(&temp).context("could not make the temporary folder")?;
520 std::fs::write(temp.join("event.json"), serde_json::to_string_pretty(&spec["event"])?)?;
521
522 let host_env: BTreeSet<String> = std::env::vars().map(|(name, _)| name).collect();
523 // Docker of the job's own, on g1t's machines (crate::docker).
524 let docker_hosted = cfg!(target_os = "linux")
525 && std::env::var("G1T_DOCKER").as_deref() == Ok("on")
526 && spec["variables"]["RUNNER_ENVIRONMENT"].as_str() != Some("self-hosted");
527 // This process's environment, less what only it should see.
528 let mut base_env: BTreeMap<String, String> =
529 std::env::vars().filter(|(name, _)| !matches!(name.as_str(), "ACTIONS_TOKEN" | "ACTIONS_JOB" | "MODE") && !name.starts_with("G1T_")).collect();
530 base_env.insert("HOME".into(), std::env::var("HOME").unwrap_or_else(|_| "/home/node".into()));
531 base_env.extend(text_map(spec.get("variables")));
532 base_env.insert("GITHUB_EVENT_PATH".into(), paths::shown(&temp.join("event.json")));
533
534 let mut contexts: Map<String, Value> = spec["contexts"].as_object().cloned().unwrap_or_default();
535 contexts.insert("github".into(), spec["github"].clone());
536 let debug = contexts
537 .get("secrets")
538 .and_then(|s| s.get("ACTIONS_STEP_DEBUG"))
539 .or_else(|| contexts.get("vars").and_then(|v| v.get("ACTIONS_STEP_DEBUG")))
540 .is_some_and(|v| expr::to_text(v) == "true");
541
542 // `timeoutMinutes` is how the API spelled it before its bodies were
543 // `snake_case`.
544 let timeout = spec["timeout_minutes"]
545 .as_u64()
546 .or_else(|| spec["timeoutMinutes"].as_u64())
547 .unwrap_or(60);
548 let mut job = Job {
549 log,
550 spec,
551 workspace,
552 temp,
553 base_env,
554 added_env: BTreeMap::new(),
555 path_prepend: Vec::new(),
556 workflow_env: BTreeMap::new(),
557 job_env: BTreeMap::new(),
558 contexts,
559 failed: false,
560 posts: Vec::new(),
561 step_names: Vec::new(),
562 deadline: Instant::now() + Duration::from_secs(timeout * 60),
563 debug,
564 last_node_outputs: BTreeMap::new(),
565 last_node_state: BTreeMap::new(),
566 host_env,
567 docker_hosted,
568 network: None,
569 services: Vec::new(),
570 container: None,
571 job_context: Map::new(),
572 built_actions: containers::Built::new(),
573 };
574
575 // The workflow's env reads github, secrets, inputs and vars; the job's
576 // also its matrix, needs and strategy.
577 let mut contexts = job.contexts.clone();
578 contexts.insert("env".into(), json!({}));
579 job.workflow_env = interpolated_map(&job, job.spec["workflow"].get("env"), &contexts);
580 contexts.insert("env".into(), Value::Object(job.workflow_env.iter().map(|(k, v)| (k.clone(), json!(v))).collect()));
581 job.job_env = interpolated_map(&job, job.spec["spec"].get("env"), &contexts);
582 Ok(job)
583}
584
585/// The job's `defaults.run`, its own over the workflow's.
586fn run_defaults(spec: &Value) -> Map<String, Value> {
587 let mut defaults = spec["workflow"]["defaults"]["run"].as_object().cloned().unwrap_or_default();
588 if let Some(own) = spec["spec"]["defaults"]["run"].as_object() {
589 defaults.extend(own.clone());
590 }
591 defaults
592}
593
594fn run_job(job: &mut Job) {
595 let steps: Vec<Map<String, Value>> = job.spec["spec"]["steps"]
596 .as_array()
597 .map(|steps| steps.iter().filter_map(|s| s.as_object().cloned()).collect())
598 .unwrap_or_default();
599 let defaults = run_defaults(&job.spec);
600
601 // Step names as they read before anything has run.
602 let frame = Frame::default();
603 let env = job.env_context(&frame);
604 let contexts = job.contexts_for(&frame, &env);
605 job.step_names = steps
606 .iter()
607 .map(|step| match step.get("name").map(expr::to_text) {
608 Some(name) => job.with_scope(&contexts, |scope| expr::interpolate(&name, scope)).unwrap_or(name),
609 None => default_title(step),
610 })
611 .collect();
612 job.report_steps();
613
614 job.log.step(0);
615 job.log.line(&format!("Job: {}", job.spec["name"].as_str().unwrap_or_default()));
616 let variables = &job.spec["variables"];
617 if variables["RUNNER_ENVIRONMENT"] == "self-hosted" {
618 let text = |name: &str| variables[name].as_str().unwrap_or_default().to_owned();
619 job.log.line(&format!("Runner: {}, self-hosted, {} {}", text("RUNNER_NAME"), text("RUNNER_OS"), text("RUNNER_ARCH")));
620 } else {
621 job.log.line("Runner: g1t, Linux X64 (Debian bookworm, Node 24, Python 3, Go, Rust)");
622 }
623 if let Some(Value::Object(matrix)) = job.contexts.get("matrix")
624 && !matrix.is_empty()
625 {
626 job.log.line(&format!("Matrix: {}", serde_json::to_string(matrix).unwrap_or_default()));
627 }
628 // What its G1T_TOKEN may do, as its `permissions:` gave it.
629 if let Some(Value::Object(permissions)) = job.spec.get("permissions").cloned() {
630 job.log.line("##[group]G1T_TOKEN permissions");
631 for (name, access) in &permissions {
632 if access.as_str() != Some("none") {
633 job.log.line(&format!("{name}: {}", access.as_str().unwrap_or_default()));
634 }
635 }
636 job.log.line("##[endgroup]");
637 }
638 if job.docker_hosted {
639 let registry = job.contexts["github"]["server_url"].as_str().and_then(crate::docker::engine::registry_host);
640 let token = job.contexts.get("secrets").and_then(|s| s.get("G1T_TOKEN")).map(expr::to_text).filter(|t| !t.is_empty());
641 let options = crate::docker::engine::Options { registry: registry.zip(token) };
642 if let Err(problem) = crate::docker::engine::enable(options) {
643 job.log.line(&format!("##[warning]Docker is not available in this job: {problem}"));
644 job.docker_hosted = false;
645 }
646 }
647 let containers_started = job.start_containers();
648 job.log.flush();
649
650 let mut frame = Frame::default();
651 if !containers_started {
652 job.failed = true;
653 for (index, name) in job.step_names.clone().iter().enumerate() {
654 job.log.step_state(index as u32 + 1, name, "completed", Some("skipped"));
655 }
656 }
657 for (index, step) in steps.iter().enumerate().filter(|_| containers_started) {
658 job.step(&mut frame, step, index as u32 + 1, true, &defaults);
659 job.log_docker_notes();
660 if job.remaining().is_zero() {
661 job.log.line("##[error]The job ran past its time limit.");
662 job.failed = true;
663 break;
664 }
665 }
666
667 // Post steps, last registered first.
668 let posts: Vec<Post> = std::mem::take(&mut job.posts);
669 for post in posts.into_iter().rev() {
670 let number = job.step_names.len() as u32 + 1;
671 job.step_names.push(post.name.clone());
672 job.report_steps();
673 let contexts = job.contexts_for(&frame, &job.env_context(&frame));
674 let run_it = job.with_scope(&contexts, |scope| expr::condition(&post.condition, scope)).unwrap_or(true);
675 if !run_it {
676 job.log.step_state(number, &post.name, "completed", Some("skipped"));
677 continue;
678 }
679 job.log.step(number);
680 job.log.step_state(number, &post.name, "in_progress", None);
681 let ok = match &post.run {
682 PostRun::Node { action_dir, script } => job.run_node(action_dir, script, &post.env),
683 PostRun::CacheSave { key, paths, version } => job.cache_save(key, paths, version),
684 PostRun::Docker(run) => job.run_docker(run).0,
685 };
686 job.log.step_state(number, &post.name, "completed", Some(if ok { "success" } else { "failure" }));
687 if !ok {
688 job.failed = true;
689 }
690 }
691
692 // GitHub's "Stop containers": services' logs, and everything removed.
693 if job.has_containers() {
694 let number = job.step_names.len() as u32 + 1;
695 job.step_names.push("Stop containers".into());
696 job.report_steps();
697 job.log.step(number);
698 job.log.step_state(number, "Stop containers", "in_progress", None);
699 job.stop_containers();
700 job.log.step_state(number, "Stop containers", "completed", Some("success"));
701 }
702
703 // The job's outputs, read now that every step has run.
704 let env = job.env_context(&frame);
705 let contexts = job.contexts_for(&frame, &env);
706 let mut outputs = Map::new();
707 if let Some(Value::Object(declared)) = job.spec["spec"].get("outputs") {
708 for (name, value) in declared {
709 let value = job.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
710 outputs.insert(name.clone(), Value::String(expr::to_text(&value)));
711 }
712 }
713 let conclusion = if job.failed { "failure" } else { "success" };
714 job.log.done(conclusion, &outputs, None);
715}
716
717pub(crate) fn main() -> i32 {
718 let api = match (crate::env("G1T_API"), crate::env("ACTIONS_JOB"), crate::env("ACTIONS_TOKEN")) {
719 (Ok(base), Ok(job), Ok(token)) => Api { base, job, token },
720 _ => {
721 eprintln!("g1t-runner: G1T_API, ACTIONS_JOB and ACTIONS_TOKEN are needed");
722 return 2;
723 }
724 };
725 let spec = match api.spec() {
726 Ok(spec) => spec,
727 Err(error) => {
728 eprintln!("g1t-runner: could not fetch the job: {error:#}");
729 api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not fetch the job: {error}") }));
730 return 1;
731 }
732 };
733 let reporter = Api {
734 base: api.base.clone(),
735 job: api.job.clone(),
736 token: api.token.clone(),
737 };
738 let mut job = match setup(spec, reporter) {
739 Ok(job) => job,
740 Err(error) => {
741 api.report(json!({ "kind": "done", "conclusion": "failure", "reason": format!("The runner could not set up: {error:#}") }));
742 return 1;
743 }
744 };
745 run_job(&mut job);
746 if job.failed { 1 } else { 0 }
747}