Skip to content
201 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

GitHub Actions on g1t, part two: running workflows1//! Telling g1t how a job is going: its steps, its log in batches, its
2//! annotations, and how it ended. Every report carries the job's token.
3
4use std::time::{Duration, Instant};
5
6use anyhow::Result;
Merge branch 'worktree-agent-a3abfcce648e87dca'7use g1t_actions::mask;
GitHub Actions on g1t, part two: running workflows8use serde_json::{Value, json};
9
10/// How long log lines wait before they are sent.
11const FLUSH_EVERY: Duration = Duration::from_millis(1500);
12/// How much log is sent at once.
13const FLUSH_BYTES: usize = 64 * 1024;
14
15pub(crate) struct Api {
16 pub(crate) base: String,
17 pub(crate) job: String,
18 pub(crate) token: String,
19}
20
21impl Api {
22 pub(crate) fn spec(&self) -> Result<Value> {
23 let response = ureq::post(&format!("{}/actions/jobs/{}/spec", self.base, self.job))
24 .timeout(Duration::from_secs(60))
25 .send_json(json!({ "token": self.token }))?;
26 Ok(response.into_json()?)
27 }
28
29 pub(crate) fn report(&self, report: Value) {
30 // A report that cannot be sent is tried a few times, then dropped:
31 // the job goes on, and g1t notices a silent job by itself.
32 for attempt in 0..3 {
33 let sent = ureq::post(&format!("{}/actions/jobs/{}", self.base, self.job))
34 .timeout(Duration::from_secs(30))
35 .send_json(json!({ "token": self.token, "report": report }));
36 match sent {
37 Ok(_) => return,
38 // Refused: the job was cancelled or finished; nothing to retry.
39 Err(ureq::Error::Status(code, _)) if (400..500).contains(&code) => return,
40 Err(_) => std::thread::sleep(Duration::from_millis(500 * (attempt + 1))),
41 }
42 }
43 }
44}
45
Merge branch 'worktree-agent-a3abfcce648e87dca'46/// The job's log, masked, sent in batches. `masks` holds every form of
47/// every secret (`g1t_actions::mask`), longest first.
GitHub Actions on g1t, part two: running workflows48pub(crate) struct Log {
49 pub(crate) api: Api,
50 pub(crate) masks: Vec<String>,
51 step: u32,
52 buffer: String,
53 last: Instant,
54}
55
56impl Log {
Merge branch 'worktree-agent-a3abfcce648e87dca'57 pub(crate) fn new(api: Api, mut masks: Vec<String>) -> Log {
58 masks.retain(|mask| !mask.is_empty());
59 masks.sort_by_key(|mask| std::cmp::Reverse(mask.len()));
GitHub Actions on g1t, part two: running workflows60 Log {
61 api,
62 masks,
63 step: 0,
64 buffer: String::new(),
65 last: Instant::now(),
66 }
67 }
68
69 /// Starts writing to step `number` (0 for the job's setup).
70 pub(crate) fn step(&mut self, number: u32) {
71 self.flush();
72 self.step = number;
73 }
74
75 pub(crate) fn mask(&self, text: &str) -> String {
Merge branch 'worktree-agent-a3abfcce648e87dca'76 mask::apply(text, &self.masks)
77 }
78
79 /// `::add-mask::`: masks `value` from here on, in every form it can
80 /// take (each line, base64, JSON-escaped), as a secret is.
81 pub(crate) fn add_mask(&mut self, value: &str) {
82 let mut added = false;
83 for variant in mask::variants(value) {
84 if !self.masks.contains(&variant) {
85 self.masks.push(variant);
86 added = true;
GitHub Actions on g1t, part two: running workflows87 }
88 }
Merge branch 'worktree-agent-a3abfcce648e87dca'89 if added {
90 self.masks.sort_by_key(|mask| std::cmp::Reverse(mask.len()));
91 }
GitHub Actions on g1t, part two: running workflows92 }
93
94 pub(crate) fn line(&mut self, text: &str) {
95 let masked = self.mask(text);
96 self.buffer.push_str(&masked);
97 self.buffer.push('\n');
98 if self.buffer.len() >= FLUSH_BYTES || self.last.elapsed() >= FLUSH_EVERY {
99 self.flush();
100 }
101 }
102
103 /// Sends what is waiting if it has waited long enough.
104 pub(crate) fn tick(&mut self) {
105 if !self.buffer.is_empty() && self.last.elapsed() >= FLUSH_EVERY {
106 self.flush();
107 }
108 }
109
110 pub(crate) fn flush(&mut self) {
111 self.last = Instant::now();
112 if self.buffer.is_empty() {
113 return;
114 }
115 let text = std::mem::take(&mut self.buffer);
116 self.api.report(json!({ "kind": "log", "step": self.step, "text": text }));
117 }
118
119 pub(crate) fn steps(&self, names: &[String]) {
120 self.api.report(json!({ "kind": "steps", "steps": names }));
121 }
122
123 pub(crate) fn step_state(&mut self, number: u32, name: &str, status: &str, conclusion: Option<&str>) {
124 self.flush();
125 let name = self.mask(name);
126 self.api.report(json!({ "kind": "step", "number": number, "name": name, "status": status, "conclusion": conclusion }));
127 }
128
129 pub(crate) fn annotation(&mut self, level: &str, message: &str, properties: &serde_json::Map<String, Value>) {
130 let message = self.mask(message);
Merge branch 'worktree-agent-a3abfcce648e87dca'131 let title = properties.get("title").and_then(Value::as_str).map(|title| self.mask(title));
GitHub Actions on g1t, part two: running workflows132 self.api.report(json!({
133 "kind": "annotation",
134 "level": level,
135 "message": message,
Merge branch 'worktree-agent-a3abfcce648e87dca'136 "title": title,
GitHub Actions on g1t, part two: running workflows137 "file": properties.get("file"),
138 "line": properties.get("line").and_then(|l| l.as_str()).and_then(|l| l.parse::<u32>().ok()),
139 }));
140 }
141
142 pub(crate) fn done(&mut self, conclusion: &str, outputs: &serde_json::Map<String, Value>, reason: Option<&str>) {
Merge branch 'worktree-agent-a3abfcce648e87dca'143 let outputs = self.withhold_secrets(outputs);
GitHub Actions on g1t, part two: running workflows144 self.flush();
145 self.api.report(json!({ "kind": "done", "conclusion": conclusion, "outputs": outputs, "reason": reason }));
146 }
Merge branch 'worktree-agent-a3abfcce648e87dca'147
148 /// The job's outputs without any that hold a secret, as on GitHub: an
149 /// output goes to other jobs and to the run's page, where no mask
150 /// reaches. Each one left out is warned of in the log.
151 pub(crate) fn withhold_secrets(&mut self, outputs: &serde_json::Map<String, Value>) -> serde_json::Map<String, Value> {
152 let mut kept = serde_json::Map::new();
153 for (name, value) in outputs {
154 let text = match value {
155 Value::String(text) => text.clone(),
156 other => other.to_string(),
157 };
158 if mask::reveals(&text, &self.masks) {
159 self.line(&format!("##[warning]The output `{name}` was left out: it holds a secret."));
160 continue;
161 }
162 kept.insert(name.clone(), value.clone());
163 }
164 kept
165 }
166}
167
168#[cfg(test)]
169mod tests {
170 use super::*;
171
172 fn log(secrets: &[&str]) -> Log {
173 let api = Api { base: "http://127.0.0.1:9".into(), job: "job_1".into(), token: "t".into() };
174 Log::new(api, mask::all_variants(secrets.iter().copied()))
175 }
176
177 #[test]
178 fn outputs_holding_a_secret_are_left_out() {
179 let mut log = log(&["s3cr3t-token"]);
180 let mut outputs = serde_json::Map::new();
181 outputs.insert("version".into(), json!("1.2.0"));
182 outputs.insert("leak".into(), json!("token=s3cr3t-token"));
183 outputs.insert("encoded".into(), json!("czNjcjN0LXRva2Vu"));
184 let kept = log.withhold_secrets(&outputs);
185 assert_eq!(kept.keys().collect::<Vec<_>>(), ["version"]);
186 assert!(log.buffer.contains("The output `leak` was left out"));
187 assert!(log.buffer.contains("The output `encoded` was left out"));
188 }
189
190 #[test]
191 fn added_masks_cover_every_form() {
192 let mut log = log(&[]);
193 log.add_mask("line one\nline two");
194 assert_eq!(log.mask("first: line one"), "first: ***");
195 assert_eq!(log.mask("then line two"), "then ***");
196 // Longest first: the whole value, not its pieces.
197 log.add_mask("abc");
198 log.add_mask("abcdef");
199 assert_eq!(log.mask("abcdef"), "***");
200 }
GitHub Actions on g1t, part two: running workflows201}

This file's history is long; its oldest lines are credited to the oldest commit read.