Skip to content
577 linesCodeBlameRaw
1//! `uses:` steps: `actions/checkout` done natively against g1t, actions
2//! fetched from another repository on g1t (or else GitHub) and run as they are (JavaScript, composite and
3//! Docker), `docker://` images, and a few of GitHub's own whose services
4//! g1t does not have yet.
5
6use std::collections::BTreeMap;
7use std::path::{Path, PathBuf};
8use std::process::Command;
9use std::time::Duration;
10
11use base64::Engine;
12use base64::engine::general_purpose::STANDARD;
13use g1t_actions::expr;
14use g1t_actions::workflow::yaml_to_json;
15use serde_json::{Map, Value, json};
16
17use super::containers::{self, DockerRun};
18use super::files::StepFiles;
19use super::process::{self, Commands, Ended};
20use super::{Frame, Job, Post, PostRun};
21
22const ACTIONS_DIR: &str = "/home/runner/_actions";
23
24/// Where an action comes from.
25enum Source {
26 Local(PathBuf),
27 /// Another repository: on g1t when g1t has it and this one may use
28 /// it, otherwise on GitHub.
29 GitHub { owner: String, repo: String, path: String, git_ref: String },
30}
31
32fn safe(part: &str) -> bool {
33 !part.is_empty() && part.chars().all(|c| c.is_ascii_alphanumeric() || matches!(c, '-' | '_' | '.' | '/')) && !part.contains("..")
34}
35
36impl Job {
37 /// Runs a git command, logging it; the credential header is never logged.
38 fn git(&mut self, dir: &Path, args: &[&str], auth: Option<&str>) -> bool {
39 let shown: Vec<&str> = args.to_vec();
40 self.log.line(&format!("[command]git {}", shown.join(" ")));
41 let mut command = Command::new("git");
42 command.current_dir(dir);
43 if let Some(header) = auth {
44 command.args(["-c", &format!("http.extraheader={header}")]);
45 }
46 command.args(args).env("GIT_TERMINAL_PROMPT", "0");
47 let mut commands = Commands::default();
48 matches!(process::run(command, Duration::from_secs(600).min(self.remaining_time()), &mut self.log, &mut commands), Ok(Ended::Exited(0)))
49 }
50
51 /// A fetch, tried again after a short wait when it fails: a transfer
52 /// cut short on the way ("transfer closed with N bytes remaining") is
53 /// over by the next try. Three tries in all, as actions/checkout does.
54 fn fetch_retrying(&mut self, dir: &Path, args: &[&str], auth: Option<&str>) -> bool {
55 for (attempt, wait) in [0u64, 2, 5].into_iter().enumerate() {
56 if attempt > 0 {
57 self.log.line(&format!("The fetch failed; trying again in {wait} s ({} of 3).", attempt + 1));
58 std::thread::sleep(Duration::from_secs(wait));
59 }
60 if self.git(dir, args, auth) {
61 return true;
62 }
63 }
64 false
65 }
66
67 /// `actions/checkout`, against g1t.
68 fn checkout(&mut self, with: &BTreeMap<String, String>) -> (bool, BTreeMap<String, String>) {
69 let checkout = self.spec["checkout"].clone();
70 let own = checkout["repository"].as_str().unwrap_or_default().to_owned();
71 let server = self.contexts["github"]["server_url"].as_str().unwrap_or("https://g1t.sh").to_owned();
72 let repository = with.get("repository").filter(|r| !r.is_empty()).cloned().unwrap_or(own.clone());
73 let same = repository.eq_ignore_ascii_case(&own);
74 let token = with.get("token").filter(|t| !t.is_empty()).cloned().or_else(|| checkout["token"].as_str().map(str::to_owned)).unwrap_or_default();
75 let url = if same { checkout["url"].as_str().unwrap_or_default().to_owned() } else { format!("{server}/{repository}.git") };
76 let path = with.get("path").filter(|p| !p.is_empty()).map_or(self.workspace.clone(), |p| self.workspace.join(p));
77 let depth: u32 = with.get("fetch-depth").and_then(|d| d.parse().ok()).unwrap_or(1);
78 let wanted_ref = with.get("ref").filter(|r| !r.is_empty()).cloned();
79 let auth = (!token.is_empty()).then(|| format!("AUTHORIZATION: basic {}", STANDARD.encode(format!("x-access-token:{token}"))));
80
81 self.log.line(&format!("Checking out {repository} into {}", path.display()));
82 if path.exists() {
83 let _ = std::fs::remove_dir_all(&path);
84 }
85 if let Err(error) = std::fs::create_dir_all(&path) {
86 self.log.line(&format!("##[error]Could not make {}: {error}", path.display()));
87 return (false, BTreeMap::new());
88 }
89 let _ = Command::new("git").args(["config", "--global", "--add", "safe.directory", "*"]).status();
90 if !self.git(&path, &["init", "--quiet"], None) || !self.git(&path, &["remote", "add", "origin", &url], None) {
91 return (false, BTreeMap::new());
92 }
93
94 // What to fetch, and which commit to end up on.
95 let run_ref = checkout["ref"].as_str().unwrap_or_default().to_owned();
96 let run_sha = checkout["sha"].as_str().unwrap_or_default().to_owned();
97 let is_sha = |r: &str| r.len() == 40 && r.chars().all(|c| c.is_ascii_hexdigit());
98 let (fetch, sha, branch): (String, Option<String>, Option<String>) = match &wanted_ref {
99 Some(r) if is_sha(r) => ("HEAD".into(), Some(r.clone()), None),
100 Some(r) if r.starts_with("refs/") => (r.clone(), None, r.strip_prefix("refs/heads/").map(str::to_owned)),
101 Some(r) => (r.clone(), None, Some(r.clone())),
102 // A pull request's merge ref, or no ref at all (a deployment of
103 // a bare commit): the commit itself.
104 None if same && (run_ref.starts_with("refs/pull/") || run_ref.is_empty()) => ("HEAD".into(), Some(run_sha.clone()), None),
105 None if same => (run_ref.clone(), Some(run_sha.clone()), run_ref.strip_prefix("refs/heads/").map(str::to_owned)),
106 None => ("HEAD".into(), None, None),
107 };
108 let depth_arg = format!("--depth={depth}");
109 let mut args = vec!["fetch", "--no-tags", "--prune", "--quiet"];
110 if depth > 0 {
111 args.push(&depth_arg);
112 }
113 if with.get("fetch-tags").is_some_and(|t| t == "true") {
114 args.retain(|a| *a != "--no-tags");
115 }
116 args.push("origin");
117 args.push(&fetch);
118 if !self.fetch_retrying(&path, &args, auth.as_deref()) {
119 self.log.line(&format!("##[error]Could not fetch {fetch} from {repository}."));
120 return (false, BTreeMap::new());
121 }
122 let target = sha.clone().unwrap_or_else(|| "FETCH_HEAD".into());
123 // The commit may be further back than a shallow fetch reaches: the
124 // branch moved on after the run began, say. Ask for the commit
125 // itself, and failing that the whole history; a plain fetch never
126 // reaches past a shallow boundary.
127 let has = |target: &str| Command::new("git").current_dir(&path).args(["cat-file", "-e", &format!("{target}^{{commit}}")]).status().is_ok_and(|s| s.success());
128 if !has(&target) {
129 let by_sha = sha.as_deref().is_some_and(|sha| {
130 let mut args = vec!["fetch", "--no-tags", "--quiet"];
131 if depth > 0 {
132 args.push(&depth_arg);
133 }
134 args.extend(["origin", sha]);
135 self.git(&path, &args, auth.as_deref()) && has(sha)
136 });
137 let shallow = path.join(".git").join("shallow").exists();
138 let deepen: &[&str] = if shallow { &["fetch", "--no-tags", "--quiet", "--unshallow", "origin"] } else { &["fetch", "--no-tags", "--quiet", "origin"] };
139 if !by_sha && !self.fetch_retrying(&path, deepen, auth.as_deref()) {
140 return (false, BTreeMap::new());
141 }
142 }
143 let checked_out = match &branch {
144 Some(branch) => self.git(&path, &["checkout", "--quiet", "--force", "-B", branch, &target], None),
145 None => self.git(&path, &["checkout", "--quiet", "--force", "--detach", &target], None),
146 };
147 if !checked_out {
148 return (false, BTreeMap::new());
149 }
150 if with.get("persist-credentials").is_none_or(|p| p != "false")
151 && let Some(header) = &auth
152 {
153 let key = format!("http.{server}/.extraheader");
154 let _ = Command::new("git").current_dir(&path).args(["config", "--local", &key, header]).status();
155 }
156 if let Some(submodules) = with.get("submodules").filter(|s| *s == "true" || *s == "recursive") {
157 let mut args = vec!["submodule", "update", "--init", "--quiet"];
158 if submodules == "recursive" {
159 args.push("--recursive");
160 }
161 if !self.git(&path, &args, auth.as_deref()) {
162 self.log.line("##[warning]Submodules could not all be checked out; only those hosted on g1t can be.");
163 }
164 }
165 if with.get("lfs").is_some_and(|l| l == "true") {
166 self.log.line("##[warning]Git LFS files are not fetched on g1t yet.");
167 }
168 let commit = Command::new("git").current_dir(&path).args(["rev-parse", "HEAD"]).output().ok().map(|o| String::from_utf8_lossy(&o.stdout).trim().to_owned()).unwrap_or_default();
169 self.log.line(&format!("Checked out {commit}"));
170 let mut outputs = BTreeMap::new();
171 outputs.insert("ref".into(), wanted_ref.unwrap_or(run_ref));
172 outputs.insert("commit".into(), commit);
173 (true, outputs)
174 }
175
176 /// Fetches another repository's action, once per job: from g1t when
177 /// g1t has the repository and this one may use it, otherwise from
178 /// GitHub. A private repository on g1t that may not be used here fails
179 /// the step, saying why, rather than fetching something else by its
180 /// name.
181 fn fetch_remote_action(&mut self, owner: &str, repo: &str, git_ref: &str) -> Option<PathBuf> {
182 let on_g1t = super::paths::under_home(ACTIONS_DIR).join("_g1t").join(owner).join(repo).join(git_ref);
183 let on_github = super::paths::under_home(ACTIONS_DIR).join(owner).join(repo).join(git_ref);
184 for dir in [&on_g1t, &on_github] {
185 if dir.join(".g1t-fetched").exists() {
186 return Some(dir.clone());
187 }
188 }
189 if !(safe(owner) && safe(repo) && safe(git_ref)) {
190 self.log.line(&format!("##[error]`{owner}/{repo}@{git_ref}` is not a name g1t can fetch."));
191 return None;
192 }
193 match self.log.api.action(&format!("{owner}/{repo}"), git_ref) {
194 Ok(found) if found["source"] == "g1t" => self.fetch_g1t_action(&on_g1t, owner, repo, git_ref, &found),
195 Ok(_) => self.fetch_action(owner, repo, git_ref),
196 Err((true, why)) => {
197 self.log.line(&format!("##[error]{why}"));
198 None
199 }
200 Err((false, why)) => {
201 self.log.line(&format!("##[warning]g1t could not say where {owner}/{repo} is ({why}); fetching it from GitHub."));
202 self.fetch_action(owner, repo, git_ref)
203 }
204 }
205 }
206
207 /// Fetches an action from a repository on g1t, at its ref, with the
208 /// read-only token g1t gave for it when it is private.
209 fn fetch_g1t_action(&mut self, dir: &Path, owner: &str, repo: &str, git_ref: &str, found: &Value) -> Option<PathBuf> {
210 let url = found["url"].as_str().unwrap_or_default().to_owned();
211 let token = found["token"].as_str().filter(|token| !token.is_empty()).map(str::to_owned);
212 if let Some(token) = &token {
213 self.log.add_mask(token);
214 }
215 let auth = token.map(|token| format!("AUTHORIZATION: basic {}", STANDARD.encode(format!("x-access-token:{token}"))));
216 self.log.line(&format!("Download action repository '{owner}/{repo}@{git_ref}' from g1t"));
217 let _ = std::fs::remove_dir_all(dir);
218 if std::fs::create_dir_all(dir).is_err() || !self.git(dir, &["init", "--quiet"], None) || !self.git(dir, &["remote", "add", "origin", &url], None) {
219 return None;
220 }
221 // A branch or tag at its tip; a commit may need the history.
222 let shallow = self.fetch_retrying(dir, &["fetch", "--depth=1", "--no-tags", "--quiet", "origin", git_ref], auth.as_deref());
223 let checked_out = if shallow {
224 self.git(dir, &["checkout", "--quiet", "--force", "--detach", "FETCH_HEAD"], None)
225 } else {
226 self.fetch_retrying(dir, &["fetch", "--quiet", "--tags", "origin", "+refs/heads/*:refs/remotes/origin/*"], auth.as_deref())
227 && self.git(dir, &["checkout", "--quiet", "--force", "--detach", git_ref], None)
228 };
229 if !checked_out {
230 self.log.line(&format!("##[error]Could not fetch {owner}/{repo}@{git_ref} from g1t: is {git_ref} a branch, tag or commit there?"));
231 let _ = std::fs::remove_dir_all(dir);
232 return None;
233 }
234 let _ = std::fs::write(dir.join(".g1t-fetched"), "");
235 Some(dir.to_path_buf())
236 }
237
238 /// Fetches an action from GitHub, once per job.
239 fn fetch_action(&mut self, owner: &str, repo: &str, git_ref: &str) -> Option<PathBuf> {
240 let dir = super::paths::under_home(ACTIONS_DIR).join(owner).join(repo).join(git_ref);
241 if dir.join(".g1t-fetched").exists() {
242 return Some(dir);
243 }
244 if !(safe(owner) && safe(repo) && safe(git_ref)) {
245 self.log.line(&format!("##[error]`{owner}/{repo}@{git_ref}` is not a name g1t can fetch."));
246 return None;
247 }
248 self.log.line(&format!("Download action repository '{owner}/{repo}@{git_ref}'"));
249 let _ = std::fs::create_dir_all(&dir);
250 let url = format!("https://codeload.github.com/{owner}/{repo}/tar.gz/{git_ref}");
251 let script = format!("set -o pipefail; curl -fsSL --retry 3 '{url}' | tar -xz -C '{}' --strip-components=1", dir.display());
252 let mut command = Command::new("bash");
253 command.args(["-c", &script]);
254 let mut commands = Commands::default();
255 match process::run(command, Duration::from_secs(300).min(self.remaining_time()), &mut self.log, &mut commands) {
256 Ok(Ended::Exited(0)) => {
257 let _ = std::fs::write(dir.join(".g1t-fetched"), "");
258 Some(dir)
259 }
260 _ => {
261 self.log.line(&format!("##[error]Could not download {owner}/{repo}@{git_ref} from GitHub."));
262 let _ = std::fs::remove_dir_all(&dir);
263 None
264 }
265 }
266 }
267
268 /// Runs a JavaScript file of an action with Node.
269 pub(crate) fn run_node(&mut self, action_dir: &Path, script: &str, env: &BTreeMap<String, String>) -> bool {
270 let id = format!("node{}", super::rand_id());
271 let Ok(files) = StepFiles::new(&self.temp, &id) else { return false };
272 let full = self.process_env(env, &files);
273 let script_path = action_dir.join(script);
274 // In a job container whose image runs the runner's Node, the action
275 // runs there, as on GitHub.
276 let in_container = self.container.as_ref().filter(|c| c.node).map(|c| c.path.clone()).and_then(|image_path| {
277 let inside = self.container_env(env, full.clone(), &image_path);
278 self.in_container(containers::CONTAINER_NODE, &[script_path.display().to_string()], &self.workspace, inside)
279 });
280 let command = match in_container {
281 Some(command) => command,
282 None => {
283 let mut command = Command::new("node");
284 command.arg(&script_path).current_dir(&self.workspace).env_clear().envs(full);
285 command
286 }
287 };
288 let mut commands = Commands {
289 debug: false,
290 ..Commands::default()
291 };
292 let ended = process::run(command, Duration::from_secs(6 * 3600).min(self.deadline_left()), &mut self.log, &mut commands);
293 let ok = matches!(ended, Ok(Ended::Exited(0)));
294 match ended {
295 Ok(Ended::Exited(code)) if code != 0 => self.log.line(&format!("##[error]The action exited with code {code}.")),
296 Ok(Ended::TimedOut) => self.log.line("##[error]The action ran past its time limit and was stopped."),
297 _ => {}
298 }
299 let (outputs, state) = self.absorb(&files, &commands);
300 self.last_node_outputs = outputs;
301 self.last_node_state = state;
302 ok
303 }
304
305 fn deadline_left(&self) -> Duration {
306 self.remaining_time()
307 }
308
309 /// Runs a `uses:` step. Returns whether it succeeded, and its outputs.
310 #[allow(clippy::too_many_arguments)]
311 pub(crate) fn uses(
312 &mut self,
313 uses: &str,
314 with: &BTreeMap<String, String>,
315 env: &BTreeMap<String, String>,
316 frame: &Frame,
317 title: &str,
318 id: Option<&str>,
319 _timeout: Duration,
320 ) -> (bool, BTreeMap<String, String>) {
321 let uses = uses.trim();
322 if let Some(image) = uses.strip_prefix("docker://") {
323 // `with.args` and `with.entrypoint` are the container's; every
324 // input is also an `INPUT_` variable, as on GitHub.
325 let mut step_env = env.clone();
326 for (input, value) in with {
327 step_env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
328 }
329 let run = DockerRun {
330 image: image.to_owned(),
331 entrypoint: with.get("entrypoint").filter(|e| !e.is_empty()).cloned(),
332 args: with.get("args").map(|a| containers::split_words(a)).unwrap_or_default(),
333 env: step_env,
334 };
335 let (ok, outputs, _) = self.run_docker(&run);
336 return (ok, outputs);
337 }
338 let (name, git_ref) = uses.split_once('@').unwrap_or((uses, ""));
339 let lower = name.to_ascii_lowercase();
340 if lower == "docker/setup-buildx-action" && self.docker_hosted {
341 return self.setup_buildx(with);
342 }
343 match lower.as_str() {
344 "actions/checkout" => return self.checkout(with),
345 "actions/upload-artifact" => return self.upload_artifact(with),
346 "actions/upload-artifact/merge" => return self.merge_artifacts(with),
347 "actions/download-artifact" => return self.download_artifact(with),
348 "actions/cache" => return self.cache(with, true, title),
349 "actions/cache/restore" => return self.cache(with, false, title),
350 "actions/cache/save" => return self.cache_save_now(with),
351 _ => {}
352 }
353 let source = if let Some(local) = name.strip_prefix("./") {
354 // A repository moved from GitHub renamed `.github` to `.g1t`, but
355 // its workflows still say `./.github/actions/…`.
356 let mut dir = self.workspace.join(local);
357 if let Some(rest) = local.strip_prefix(".github/")
358 && !dir.exists()
359 {
360 dir = self.workspace.join(".g1t").join(rest);
361 }
362 Source::Local(dir)
363 } else {
364 let mut parts = name.splitn(3, '/');
365 let (Some(owner), Some(repo)) = (parts.next(), parts.next()) else {
366 self.log.line(&format!("##[error]`{uses}` is not an action: use owner/repo@ref, owner/repo/path@ref, or ./path."));
367 return (false, BTreeMap::new());
368 };
369 if git_ref.is_empty() {
370 self.log.line(&format!("##[error]`{uses}` needs a version, such as @v4."));
371 return (false, BTreeMap::new());
372 }
373 Source::GitHub {
374 owner: owner.to_owned(),
375 repo: repo.to_owned(),
376 path: parts.next().unwrap_or_default().to_owned(),
377 git_ref: git_ref.to_owned(),
378 }
379 };
380 let (dir, repository) = match &source {
381 Source::Local(dir) => (dir.clone(), String::new()),
382 Source::GitHub { owner, repo, path, git_ref } => match self.fetch_remote_action(owner, repo, git_ref) {
383 Some(root) => (if path.is_empty() { root } else { root.join(path) }, format!("{owner}/{repo}")),
384 None => return (false, BTreeMap::new()),
385 },
386 };
387 let manifest = ["action.yml", "action.yaml"].iter().map(|f| dir.join(f)).find(|p| p.exists());
388 let Some(manifest) = manifest else {
389 self.log.line(&format!("##[error]`{uses}` has no action.yml."));
390 return (false, BTreeMap::new());
391 };
392 let action = match std::fs::read_to_string(&manifest).ok().and_then(|text| serde_yaml::from_str::<serde_yaml::Value>(&text).ok()) {
393 Some(yaml) => yaml_to_json(&yaml),
394 None => {
395 self.log.line(&format!("##[error]`{uses}`: its action.yml does not read."));
396 return (false, BTreeMap::new());
397 }
398 };
399
400 // Inputs: what the step gives, else the action's defaults.
401 let env_context = env.clone();
402 let contexts = self.contexts_for(frame, &env_context);
403 let mut inputs: BTreeMap<String, String> = BTreeMap::new();
404 if let Some(Value::Object(declared)) = action.get("inputs") {
405 for (input, spec) in declared {
406 let given = with.iter().find(|(k, _)| k.eq_ignore_ascii_case(input)).map(|(_, v)| v.clone());
407 let value = match given {
408 Some(value) => value,
409 None => match spec.get("default") {
410 Some(default) => {
411 let default = self.with_scope(&contexts, |scope| expr::interpolate_value(default, scope)).unwrap_or(Value::Null);
412 expr::to_text(&default)
413 }
414 None => String::new(),
415 },
416 };
417 inputs.insert(input.clone(), value);
418 }
419 }
420 for (key, value) in with {
421 if !inputs.keys().any(|k| k.eq_ignore_ascii_case(key)) {
422 inputs.insert(key.clone(), value.clone());
423 }
424 }
425
426 let runs = action.get("runs").cloned().unwrap_or(Value::Null);
427 let using = runs.get("using").map(expr::to_text).unwrap_or_default().to_ascii_lowercase();
428 let mut step_env = env.clone();
429 step_env.insert("GITHUB_ACTION".into(), id.map_or_else(|| format!("__{}", repository.replace('/', "_")), str::to_owned));
430 step_env.insert("GITHUB_ACTION_REPOSITORY".into(), repository.clone());
431 step_env.insert("GITHUB_ACTION_REF".into(), git_ref.to_owned());
432 step_env.insert("GITHUB_ACTION_PATH".into(), dir.display().to_string());
433
434 if using.starts_with("node") {
435 for (input, value) in &inputs {
436 step_env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
437 }
438 let condition_of = |key: &str| runs.get(key).map(expr::to_text).unwrap_or_else(|| "always()".into());
439 if let Some(pre) = runs.get("pre").map(expr::to_text) {
440 let run_pre = self.with_scope(&contexts, |scope| expr::condition(&condition_of("pre-if"), scope)).unwrap_or(true);
441 if run_pre && !self.run_node(&dir, &pre, &step_env) {
442 return (false, BTreeMap::new());
443 }
444 }
445 let Some(main) = runs.get("main").map(expr::to_text) else {
446 self.log.line(&format!("##[error]`{uses}` has no `runs.main`."));
447 return (false, BTreeMap::new());
448 };
449 let ok = self.run_node(&dir, &main, &step_env);
450 let outputs = std::mem::take(&mut self.last_node_outputs);
451 let state = std::mem::take(&mut self.last_node_state);
452 if let Some(post) = runs.get("post").map(expr::to_text) {
453 let mut post_env = step_env.clone();
454 for (name, value) in state {
455 post_env.insert(format!("STATE_{name}"), value);
456 }
457 self.posts.push(Post {
458 name: format!("Post {title}"),
459 condition: condition_of("post-if"),
460 env: post_env,
461 run: PostRun::Node { action_dir: dir.clone(), script: post },
462 });
463 }
464 return (ok, outputs);
465 }
466 if using == "composite" {
467 let mut inner = Frame {
468 steps: Map::new(),
469 inputs: Some(Value::Object(inputs.iter().map(|(k, v)| (k.clone(), json!(v))).collect())),
470 action_path: Some(dir.display().to_string()),
471 env: env.clone(),
472 };
473 let steps: Vec<Map<String, Value>> = runs.get("steps").and_then(Value::as_array).map(|s| s.iter().filter_map(|s| s.as_object().cloned()).collect()).unwrap_or_default();
474 let was_failed = self.failed;
475 // A composite's steps see their own success, not the job's.
476 self.failed = false;
477 let mut ok = true;
478 for step in &steps {
479 if !self.step(&mut inner, step, 0, false, &Map::new()) {
480 ok = false;
481 }
482 }
483 let contexts = self.contexts_for(&inner, &inner.env.clone());
484 let mut outputs = BTreeMap::new();
485 if let Some(Value::Object(declared)) = action.get("outputs") {
486 for (name, spec) in declared {
487 if let Some(value) = spec.get("value") {
488 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
489 outputs.insert(name.clone(), expr::to_text(&value));
490 }
491 }
492 }
493 self.failed = was_failed;
494 return (ok, outputs);
495 }
496 if using == "docker" {
497 return self.docker_action(uses, &dir, &runs, &inputs, &step_env, frame, title);
498 }
499 self.log.line(&format!("##[error]`{uses}` runs with `{using}`, which g1t does not know."));
500 (false, BTreeMap::new())
501 }
502
503 /// A Docker action: its image built from its Dockerfile (or pulled,
504 /// for `docker://`), then run with its `args`, `entrypoint` and `env`,
505 /// its inputs as `INPUT_` variables, and `pre-entrypoint` and
506 /// `post-entrypoint` around it.
507 #[allow(clippy::too_many_arguments)]
508 fn docker_action(
509 &mut self,
510 uses: &str,
511 dir: &Path,
512 runs: &Value,
513 inputs: &BTreeMap<String, String>,
514 step_env: &BTreeMap<String, String>,
515 frame: &Frame,
516 title: &str,
517 ) -> (bool, BTreeMap<String, String>) {
518 let image = runs.get("image").map(expr::to_text).unwrap_or_default();
519 let image = if let Some(pulled) = image.strip_prefix("docker://") {
520 pulled.to_owned()
521 } else if image.is_empty() {
522 self.log.line(&format!("##[error]`{uses}` has no `runs.image`."));
523 return (false, BTreeMap::new());
524 } else {
525 match self.build_action_image(dir, &image, uses) {
526 Some(tag) => tag,
527 None => return (false, BTreeMap::new()),
528 }
529 };
530 // `args` and `env` read with the action's own inputs.
531 let mut env = step_env.clone();
532 for (input, value) in inputs {
533 env.insert(format!("INPUT_{}", input.replace(' ', "_").to_ascii_uppercase()), value.clone());
534 }
535 let mut scope_frame = frame.clone();
536 scope_frame.inputs = Some(Value::Object(inputs.iter().map(|(k, v)| (k.clone(), json!(v))).collect()));
537 let contexts = self.contexts_for(&scope_frame, &env);
538 if let Some(Value::Object(own)) = runs.get("env") {
539 for (name, value) in own {
540 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(value, scope)).unwrap_or(Value::Null);
541 env.insert(name.clone(), expr::to_text(&value));
542 }
543 }
544 let args: Vec<String> = match runs.get("args") {
545 Some(Value::Array(items)) => items
546 .iter()
547 .map(|item| {
548 let value = self.with_scope(&contexts, |scope| expr::interpolate_value(item, scope)).unwrap_or(Value::Null);
549 expr::to_text(&value)
550 })
551 .collect(),
552 _ => Vec::new(),
553 };
554 let entry = |key: &str| runs.get(key).map(expr::to_text).filter(|e| !e.is_empty());
555 if let Some(pre) = entry("pre-entrypoint") {
556 let run = DockerRun { image: image.clone(), entrypoint: Some(pre), args: Vec::new(), env: env.clone() };
557 if !self.run_docker(&run).0 {
558 return (false, BTreeMap::new());
559 }
560 }
561 let run = DockerRun { image: image.clone(), entrypoint: entry("entrypoint"), args, env: env.clone() };
562 let (ok, outputs, state) = self.run_docker(&run);
563 if let Some(post) = entry("post-entrypoint") {
564 let mut post_env = env;
565 for (name, value) in state {
566 post_env.insert(format!("STATE_{name}"), value);
567 }
568 self.posts.push(Post {
569 name: format!("Post {title}"),
570 condition: runs.get("post-if").map(expr::to_text).unwrap_or_else(|| "always()".into()),
571 env: BTreeMap::new(),
572 run: PostRun::Docker(DockerRun { image, entrypoint: Some(post), args: Vec::new(), env: post_env }),
573 });
574 }
575 (ok, outputs)
576 }
577}