Skip to content
1,294 linesCodeBlameRaw
1//! What starts a run: an event on the bus, a schedule, or someone running a
2//! workflow by hand. Each finds the workflows that want it, at the commit
3//! the event is about, and checks their filters.
4
5use g1t_actions::events::{RunInfo, github_events};
6use g1t_actions::workflow::{self, Trigger, Workflow};
7use g1t_contracts::access::{self, Capability};
8use g1t_contracts::actions::{DispatchArgs, RepositoryDispatchArgs, WorkflowRun};
9use g1t_contracts::events::{Event, caused_by_job};
10use g1t_contracts::identity::{AGENT_ID, AGENT_NAME, UsernamesArgs};
11use g1t_contracts::repos::{Commit, CompareArgs, Comparison, LogArgs, Repo, RepoPath};
12use g1t_contracts::work::{IssueDetail, PullDetail, ViewArgs};
13use g1t_contracts::{FailureCode, Outcome, User, new_id};
14use g1t_contracts::time::rfc3339;
15use g1t_kit::now_ms;
16use serde_json::{Map, Value, json};
17use worker::Result;
18
19use crate::plan::NewRun;
20use crate::sync::{Read, WorkflowRow};
21use crate::{API, Actions, SITE, check, fail, payload};
22
23/// What an event is about, worked out once for every workflow it starts.
24struct Subject {
25 /// Where the workflow files are read, and at which commit.
26 source: RepoPath,
27 source_ref: Option<String>,
28 git_ref: String,
29 sha: String,
30 head_ref: Option<String>,
31 base_ref: Option<String>,
32 pull: Option<u32>,
33 /// The branch or tag for `branches`/`tags` filters; for pull requests,
34 /// the branch they merge into.
35 filter_ref: String,
36 /// The files it changes, for `paths` filters; `None` until needed.
37 paths: Option<Vec<String>>,
38 /// For a push, what to compare to find the files.
39 compare: Option<(Option<String>, String)>,
40 payload: Value,
41 title: String,
42 trusted: bool,
43 /// Why its runs wait for approval first: a pull request from outside,
44 /// by the repository's approval policy (protection.rs).
45 approval: Option<String>,
46}
47
48/// Whether a deployment's `ref` is a commit's full hash rather than a
49/// branch or tag.
50fn is_commit(name: &str) -> bool {
51 name.len() == 40 && name.chars().all(|c| c.is_ascii_hexdigit())
52}
53
54/// Whether whoever a pull request is for is trusted without asking
55/// identity: g1t's agent in work nobody asked it for, or someone whose
56/// role here is known to allow pushing.
57fn trusted_outright(owner: &User, repo: &Repo) -> bool {
58 owner.id == AGENT_ID || access::can(Some(owner), repo, Capability::Push)
59}
60
61impl Actions {
62 async fn username(&self, id: Option<&str>) -> Result<Option<String>> {
63 let Some(id) = id else { return Ok(None) };
64 if id == AGENT_ID {
65 return Ok(Some(AGENT_NAME.to_owned()));
66 }
67 let names: std::collections::HashMap<String, String> =
68 g1t_kit::call(&self.identity, "usernames", &UsernamesArgs { ids: vec![id.to_owned()] }).await?;
69 Ok(names.get(id).cloned())
70 }
71
72 /// Whether whoever a pull request is for (Pull::owner: whoever asked
73 /// g1t for it, or its author) could push to the repository, so its
74 /// runs get the secrets and a token. Anyone else's, a reader's included
75 /// (who may open one on a private repository too), runs without them.
76 /// A change g1t made for someone is trusted as they are.
77 async fn insider(&self, owner: &User, repo: &Repo, ws: &User) -> Result<bool> {
78 if trusted_outright(owner, repo) {
79 return Ok(true);
80 }
81 // Stored authors carry no memberships or grants: ask identity, as
82 // the workspace (which may see anyone's permission).
83 let permission: Outcome<access::PermissionInfo> = g1t_kit::call(
84 &self.identity,
85 "collaborator_permission",
86 &access::CollaboratorPermissionArgs {
87 viewer: Some(ws.clone()),
88 path: RepoPath { namespace: repo.namespace.clone(), name: repo.name.clone() },
89 username: owner.username.clone(),
90 },
91 )
92 .await?;
93 Ok(permission
94 .into_result()
95 .ok()
96 .and_then(|info| info.role)
97 .is_some_and(|role| access::allows(role, Capability::Push)))
98 }
99
100 async fn commits(&self, repo: &Repo, actor: &User, after: &str, before: Option<&str>) -> Result<Vec<Commit>> {
101 let log: Outcome<Vec<Commit>> = g1t_kit::call(
102 &self.repos,
103 "log",
104 &LogArgs {
105 path: RepoPath {
106 namespace: repo.namespace.clone(),
107 name: repo.name.clone(),
108 },
109 viewer: Some(actor.clone()),
110 git_ref: Some(after.to_owned()),
111 limit: 20,
112 },
113 )
114 .await?;
115 let mut commits: Vec<Commit> = log.into_result().unwrap_or_default();
116 if let Some(before) = before
117 && let Some(at) = commits.iter().position(|commit| commit.hash == before)
118 {
119 commits.truncate(at);
120 }
121 // GitHub lists them oldest first, with the head commit last.
122 commits.reverse();
123 Ok(commits)
124 }
125
126 async fn changed_paths(&self, repo: &Repo, actor: &User, base: Option<String>, head: String) -> Result<Vec<String>> {
127 let compared: Outcome<Comparison> = g1t_kit::call(
128 &self.repos,
129 "compare",
130 &CompareArgs {
131 repo_id: repo.id.clone(),
132 viewer: Some(actor.clone()),
133 base,
134 head: Some(head),
135 base_branch: None,
136 },
137 )
138 .await?;
139 Ok(compared.into_result().map(|c| c.files.into_iter().map(|f| f.path).collect()).unwrap_or_default())
140 }
141
142 async fn default_head(&self, repo: &Repo) -> Result<Option<String>> {
143 g1t_kit::call(
144 &self.repos,
145 "head",
146 &g1t_contracts::repos::HeadArgs {
147 repo_id: repo.id.clone(),
148 branch: repo.default_branch.clone(),
149 },
150 )
151 .await
152 }
153
154 /// Whether `name` is one of the repository's branches.
155 async fn is_branch(&self, repo: &Repo, ws: &User, name: &str) -> Result<bool> {
156 let branches: Outcome<Vec<g1t_contracts::repos::Branch>> = g1t_kit::call(
157 &self.repos,
158 "branches",
159 &g1t_contracts::repos::BranchesArgs {
160 path: Self::repo_path(repo),
161 viewer: Some(ws.clone()),
162 },
163 )
164 .await?;
165 Ok(branches.into_result().unwrap_or_default().iter().any(|branch| branch.name == name))
166 }
167
168 fn repo_path(repo: &Repo) -> RepoPath {
169 RepoPath {
170 namespace: repo.namespace.clone(),
171 name: repo.name.clone(),
172 }
173 }
174
175 /// The subject of an event of `kind`, as GitHub's `event_name`.
176 async fn subject(&self, event: &Event, event_name: &str, action: Option<&str>, repo: &Repo, ws: &User, sender: &str) -> Result<Option<Subject>> {
177 let path = Self::repo_path(repo);
178 let data = &event.data;
179 let on_default = |sha: String, payload: Value, title: String, pull: Option<u32>| Subject {
180 source: path.clone(),
181 source_ref: None,
182 git_ref: format!("refs/heads/{}", repo.default_branch),
183 sha,
184 head_ref: None,
185 base_ref: None,
186 pull,
187 filter_ref: format!("refs/heads/{}", repo.default_branch),
188 paths: None,
189 compare: None,
190 payload,
191 title,
192 trusted: true,
193 approval: None,
194 };
195 let view = |number: u32| ViewArgs {
196 repo: path.clone(),
197 number,
198 viewer: Some(ws.clone()),
199 after_seq: 0,
200 };
201 Ok(match event_name {
202 "push" => {
203 let (Some(git_ref), Some(after)) = (data["ref"].as_str(), data["after"].as_str()) else {
204 return Ok(None);
205 };
206 // The merge queue's states run merge_group workflows, not push ones.
207 if git_ref.starts_with("refs/heads/g1t-queue/") {
208 return Ok(None);
209 }
210 let before = data["before"].as_str();
211 let commits = self.commits(repo, ws, after, before).await?;
212 let title = commits.last().map(|c| c.message.lines().next().unwrap_or_default().to_owned()).unwrap_or_default();
213 let mut payload = payload::push(repo, git_ref, before, after, &commits, sender);
214 if let Some(head) = commits.last() {
215 payload["head_commit"] = payload::commit(repo, head);
216 }
217 Some(Subject {
218 source: path.clone(),
219 source_ref: Some(after.to_owned()),
220 git_ref: git_ref.to_owned(),
221 sha: after.to_owned(),
222 head_ref: None,
223 base_ref: None,
224 pull: None,
225 filter_ref: git_ref.to_owned(),
226 paths: None,
227 compare: Some((before.map(str::to_owned), after.to_owned())),
228 payload,
229 title,
230 trusted: true,
231 approval: None,
232 })
233 }
234 // A branch or tag was made: its own commit, as on GitHub.
235 "create" => {
236 let (Some(git_ref), Some(after)) = (data["ref"].as_str(), data["after"].as_str()) else {
237 return Ok(None);
238 };
239 if git_ref.starts_with("refs/heads/g1t-queue/") || !data["before"].is_null() {
240 return Ok(None);
241 }
242 let (ref_type, name) = match (git_ref.strip_prefix("refs/heads/"), git_ref.strip_prefix("refs/tags/")) {
243 (Some(branch), _) => ("branch", branch),
244 (_, Some(tag)) => ("tag", tag),
245 _ => return Ok(None),
246 };
247 let payload = json!({
248 "ref": name,
249 "ref_type": ref_type,
250 "master_branch": repo.default_branch,
251 "description": repo.description,
252 "pusher_type": "user",
253 "repository": payload::repository(repo),
254 "sender": payload::user(sender),
255 });
256 Some(Subject {
257 source: path.clone(),
258 source_ref: Some(after.to_owned()),
259 git_ref: git_ref.to_owned(),
260 sha: after.to_owned(),
261 head_ref: None,
262 base_ref: None,
263 pull: None,
264 filter_ref: git_ref.to_owned(),
265 paths: None,
266 compare: None,
267 payload,
268 title: format!("Created {ref_type} {name}"),
269 trusted: true,
270 approval: None,
271 })
272 }
273 "pull_request" | "pull_request_target" | "pull_request_review" => {
274 let Some(number) = data["number"].as_u64().map(|n| n as u32) else { return Ok(None) };
275 let detail: Outcome<PullDetail> = g1t_kit::call(&self.work, "get_pull", &view(number)).await?;
276 let Outcome::Ok(detail) = detail else { return Ok(None) };
277 let pull = &detail.pull;
278 let base_ref = pull.base_branch(&repo.default_branch).to_owned();
279 let mut payload = json!({
280 "action": action,
281 "number": pull.number,
282 "pull_request": payload::pull(repo, pull),
283 "repository": payload::repository(repo),
284 "sender": payload::user(sender),
285 });
286 payload::changed(&mut payload, data);
287 if event_name == "pull_request_review" {
288 let review = detail.comments.iter().rev().find(|c| c.verdict.is_some() && !c.advisory);
289 payload["review"] = json!({
290 "state": review.and_then(|r| r.verdict).map(|v| format!("{v:?}").to_lowercase()),
291 "body": review.map(|r| r.body.clone()),
292 "user": review.map(|r| payload::user(&r.author.username)),
293 });
294 }
295 let trusted = self.insider(pull.owner(), repo, ws).await?;
296 // A pull request from outside may wait for approval before
297 // its head's code runs. `pull_request_target` runs the
298 // base's code, and a merged one's run the commit it landed
299 // as, so neither waits.
300 let approval = if event_name != "pull_request_target" && action != Some("closed") {
301 self.approval_needed(repo, pull.owner(), ws).await?
302 } else {
303 None
304 };
305 let head_ref = payload::head_ref(pull);
306 if event_name == "pull_request_target" {
307 // In the base's context: its workflows, its head.
308 let Some(sha) = self.default_head(repo).await? else { return Ok(None) };
309 let mut subject = on_default(sha, payload, pull.title.clone(), Some(pull.number));
310 subject.head_ref = Some(head_ref);
311 subject.base_ref = Some(base_ref.clone());
312 subject.filter_ref = format!("refs/heads/{base_ref}");
313 subject.paths = Some(pull.files.iter().map(|f| f.path.clone()).collect());
314 return Ok(Some(subject));
315 }
316 // A merged pull request's run is on the commit it landed as,
317 // in the repository; otherwise on its head, where that is.
318 let landed = match (action, data["commit"].as_str()) {
319 (Some("closed"), Some(commit)) => Some(commit.to_owned()),
320 _ => None,
321 };
322 let sha = match (&landed, data["commit"].as_str(), &pull.head_commit) {
323 (Some(commit), _, _) => commit.clone(),
324 (None, Some(commit), _) => commit.to_owned(),
325 (None, None, Some(head)) => head.clone(),
326 (None, None, None) => return Ok(None),
327 };
328 let source = match landed {
329 Some(_) => path.clone(),
330 None => pull.fork.clone().unwrap_or_else(|| path.clone()),
331 };
332 Some(Subject {
333 source,
334 source_ref: Some(sha.clone()),
335 git_ref: format!("refs/pull/{}/merge", pull.number),
336 sha,
337 head_ref: Some(head_ref),
338 base_ref: Some(base_ref.clone()),
339 pull: Some(pull.number),
340 // `branches` filters on pull requests name the base.
341 filter_ref: format!("refs/heads/{base_ref}"),
342 paths: Some(pull.files.iter().map(|f| f.path.clone()).collect()),
343 compare: None,
344 payload,
345 title: pull.title.clone(),
346 trusted,
347 approval,
348 })
349 }
350 "workflow_run" => {
351 // A run of a workflow_run workflow does not start another,
352 // so two such workflows cannot set each other off.
353 if data["event"].as_str() == Some("workflow_run") {
354 return Ok(None);
355 }
356 let Some(sha) = self.default_head(repo).await? else { return Ok(None) };
357 let head_branch = data["ref"].as_str().unwrap_or_default().trim_start_matches("refs/heads/").to_owned();
358 let name = data["workflow"].as_str().unwrap_or_default();
359 let payload = json!({
360 "action": "completed",
361 "workflow_run": {
362 "id": data["runId"],
363 "name": name,
364 "path": data["path"],
365 "event": data["event"],
366 "status": "completed",
367 "conclusion": data["conclusion"],
368 "head_sha": data["sha"],
369 "head_branch": head_branch,
370 "run_number": data["number"],
371 "html_url": format!("{SITE}/{}/{}/actions/runs/{}", repo.namespace, repo.name, data["runId"].as_str().unwrap_or_default()),
372 "pull_requests": data["pull"].as_u64().map(|n| vec![json!({ "number": n })]).unwrap_or_default(),
373 },
374 "workflow": { "name": name, "path": data["path"] },
375 "repository": payload::repository(repo),
376 "sender": payload::user(sender),
377 });
378 let mut subject = on_default(sha, payload, format!("After {name}"), None);
379 // Branch filters apply to the branch the followed run was on.
380 subject.filter_ref = format!("refs/heads/{head_branch}");
381 Some(subject)
382 }
383 "issues" | "issue_comment" => {
384 let Some(number) = data["number"].as_u64().map(|n| n as u32) else { return Ok(None) };
385 let Some(sha) = self.default_head(repo).await? else { return Ok(None) };
386 let issue: Outcome<IssueDetail> = g1t_kit::call(&self.work, "get_issue", &view(number)).await?;
387 let (issue_json, comments, title, on_pull) = match issue {
388 Outcome::Ok(detail) => (payload::issue(repo, &detail.issue), detail.comments, detail.issue.title.clone(), false),
389 Outcome::Fail(_) => {
390 let pull: Outcome<PullDetail> = g1t_kit::call(&self.work, "get_pull", &view(number)).await?;
391 let Outcome::Ok(detail) = pull else { return Ok(None) };
392 (payload::pull_as_issue(repo, &detail.pull), detail.comments, detail.pull.title.clone(), true)
393 }
394 };
395 let mut payload = json!({
396 "action": action,
397 "issue": issue_json,
398 "repository": payload::repository(repo),
399 "sender": payload::user(sender),
400 });
401 payload::changed(&mut payload, data);
402 if event_name == "issue_comment" {
403 let comment_id = data["commentId"].as_str();
404 if action == Some("deleted") {
405 // Gone by now: as the event kept it.
406 match data.get("comment").filter(|kept| kept.is_object()) {
407 Some(kept) => payload["comment"] = payload::deleted_comment(repo, number, kept, on_pull),
408 None => return Ok(None),
409 }
410 } else {
411 let comment = comments.iter().find(|c| Some(c.id.as_str()) == comment_id);
412 // A new comment is the newest; an edited one must be found.
413 let comment = if action == Some("created") { comment.or(comments.last()) } else { comment };
414 match comment {
415 Some(comment) => payload["comment"] = payload::comment(repo, number, comment, on_pull),
416 None => return Ok(None),
417 }
418 }
419 // `edited`: what the body was before.
420 if let Some(changes) = data.get("changes").filter(|changes| changes.is_object()) {
421 payload["changes"] = changes.clone();
422 }
423 }
424 Some(on_default(sha, payload, title, on_pull.then_some(number)))
425 }
426 // A release: on its tag, at the commit the tag named.
427 "release" => {
428 let release = &data["release"];
429 let Some(tag) = data["tagName"].as_str().or_else(|| release["tagName"].as_str()) else { return Ok(None) };
430 let sha = match release["target"].as_str().filter(|target| !target.is_empty()) {
431 Some(target) => target.to_owned(),
432 None => match self.default_head(repo).await? {
433 Some(head) => head,
434 None => return Ok(None),
435 },
436 };
437 let git_ref = format!("refs/tags/{tag}");
438 let mut payload = json!({
439 "action": action,
440 "release": payload::release(repo, release),
441 "repository": payload::repository(repo),
442 "sender": payload::user(sender),
443 });
444 if let Some(changes) = data.get("changes").filter(|changes| changes.is_object()) {
445 payload["changes"] = changes.clone();
446 }
447 let name = release["name"].as_str().filter(|name| !name.is_empty()).unwrap_or(tag);
448 Some(Subject {
449 source: path.clone(),
450 source_ref: Some(sha.clone()),
451 git_ref: git_ref.clone(),
452 sha,
453 head_ref: None,
454 base_ref: None,
455 pull: None,
456 filter_ref: git_ref,
457 paths: None,
458 compare: None,
459 payload,
460 title: format!("Release {name} {}", action.unwrap_or("changed")),
461 trusted: true,
462 approval: None,
463 })
464 }
465 // A deployment, or a new status of one: at the commit deployed,
466 // on the branch or tag it names (none for a bare commit).
467 "deployment" | "deployment_status" => {
468 let deployment = &data["deployment"];
469 let Some(sha) = deployment["sha"].as_str().filter(|sha| !sha.is_empty()).map(str::to_owned) else { return Ok(None) };
470 let named = deployment["ref"].as_str().unwrap_or_default();
471 let git_ref = if named.is_empty() || named == sha || is_commit(named) {
472 String::new()
473 } else if named.starts_with("refs/") {
474 named.to_owned()
475 } else if self.is_branch(repo, ws, named).await? {
476 format!("refs/heads/{named}")
477 } else {
478 format!("refs/tags/{named}")
479 };
480 let environment = deployment["environment"].as_str().unwrap_or_default();
481 let mut payload = json!({
482 "action": "created",
483 "deployment": payload::deployment(repo, deployment),
484 "repository": payload::repository(repo),
485 "sender": payload::user(sender),
486 });
487 let title = if event_name == "deployment_status" {
488 let status = &data["deploymentStatus"];
489 payload["deployment_status"] = payload::deployment_status(repo, status, deployment);
490 format!("Deployment to {environment}: {}", status["state"].as_str().unwrap_or("changed"))
491 } else {
492 format!("Deployment to {environment}")
493 };
494 Some(Subject {
495 source: path.clone(),
496 source_ref: Some(sha.clone()),
497 filter_ref: git_ref.clone(),
498 git_ref,
499 sha,
500 head_ref: None,
501 base_ref: None,
502 pull: None,
503 paths: None,
504 compare: None,
505 payload,
506 title,
507 trusted: true,
508 approval: None,
509 })
510 }
511 _ => None,
512 })
513 }
514
515 /// A push keeps the repository's schedules going (`run_schedules`).
516 /// Written at most once a day, and only on scheduled workflows.
517 async fn note_push(&self, repo_id: &str) -> Result<()> {
518 let at = now_ms();
519 self.db
520 .prepare("UPDATE workflows SET pushed_at = ? WHERE repo_id = ? AND crons != '[]' AND (pushed_at IS NULL OR pushed_at < ?)")
521 .bind(&[rfc3339(at).into(), repo_id.into(), rfc3339(at.saturating_sub(24 * 60 * 60 * 1000)).into()])?
522 .run()
523 .await?;
524 Ok(())
525 }
526
527 pub async fn on_event(&self, event: &Event) -> Result<()> {
528 let Some(repo_id) = event.repo_id.as_deref() else { return Ok(()) };
529 let mut mapped = github_events(&event.kind);
530 // A new branch or tag is also `create`.
531 if event.kind == "git.push" && event.data["before"].is_null() {
532 mapped.push(("create", None));
533 }
534 let pushed_default = event.kind == "git.push" && event.data["defaultBranch"].as_bool() == Some(true);
535 if event.kind == "git.push" {
536 self.note_push(repo_id).await?;
537 }
538 if mapped.is_empty() && !pushed_default {
539 return Ok(());
540 }
541 let Some((repo, ws)) = self.repo_by_id(repo_id).await? else { return Ok(()) };
542 if pushed_default {
543 self.sync(&repo, &ws).await?;
544 }
545 // A mirror runs only what its state says (mirrored.rs).
546 let copied_in = event.kind == "git.push" && event.data["mirrored"].as_bool() == Some(true);
547 let policy = crate::mirrored::policy(repo.mirror.as_ref(), copied_in);
548 if !policy.runs {
549 return Ok(());
550 }
551 // What a workflow job's own token did starts no workflows, as on
552 // GitHub, so a workflow cannot set itself off; only
553 // `workflow_dispatch` and `repository_dispatch` do.
554 if let Some(run) = caused_by_job(&event.data) {
555 worker::console_log!("actions: {} {} came from run {run}'s token; no workflows start for it", event.kind, event.id);
556 return Ok(());
557 }
558 let sender = self.username(event.actor.as_deref()).await?.unwrap_or_else(|| repo.namespace.clone());
559 for (event_name, action) in mapped {
560 // Issues and comments start the default branch's workflows,
561 // which the synced table lists: when none listens, nothing is
562 // read from git. Agents make many of these events.
563 // Deployments' statuses are as frequent (every g1t.page build
564 // reports several), so they look there first too.
565 if matches!(event_name, "issues" | "issue_comment" | "deployment" | "deployment_status")
566 && self.listens(repo_id, event_name).await? == Some(false)
567 {
568 continue;
569 }
570 let Some(mut subject) = self.subject(event, event_name, action, &repo, &ws, &sender).await? else {
571 continue;
572 };
573 // A change to workflows made on the remote, by someone g1t
574 // knows nothing of, waits before it may use this repository's
575 // secrets.
576 if copied_in && matches!(event_name, "push" | "create") {
577 if subject.paths.is_none() {
578 let (base, head) = subject.compare.clone().unwrap_or((None, subject.sha.clone()));
579 subject.paths = Some(self.changed_paths(&repo, &ws, base, head).await?);
580 }
581 if crate::mirrored::touches_workflows(subject.paths.as_deref().unwrap_or_default())
582 && let Some(mirror) = &repo.mirror
583 {
584 subject.approval = subject.approval.take().or_else(|| Some(crate::mirrored::copied_workflows(&mirror.remote)));
585 }
586 }
587 // A pull request from a fork reads the fork's files.
588 let read = if subject.source == Self::repo_path(&repo) {
589 self.read_for(&repo, &ws, subject.source_ref.as_deref(), policy.github).await?
590 } else {
591 self.read_workflows(&subject.source, &ws, subject.source_ref.as_deref()).await?
592 };
593 // A pull request's head runs each workflow once, however many
594 // events say it is there (marked ready, and pushed).
595 let key = match subject.pull {
596 Some(number) if event_name.starts_with("pull_request") && event_name != "pull_request_review" => {
597 // Reopened or made a draft again runs anew, at a head
598 // that may have run before.
599 let phase = match action {
600 Some("closed") => "closed".to_owned(),
601 Some(again @ ("reopened" | "converted_to_draft")) => format!("{again}:{}", event.id),
602 _ => "open".to_owned(),
603 };
604 format!("{event_name}:{number}:{}:{phase}", subject.sha)
605 }
606 _ if event_name == "create" => format!("{}:create", event.id),
607 _ => event.id.clone(),
608 };
609 self.start_matching(&repo, &ws, read, &mut subject, event_name, action, &key, event.actor.as_deref(), &sender)
610 .await?;
611 }
612 Ok(())
613 }
614
615 #[allow(clippy::too_many_arguments)]
616 async fn start_matching(
617 &self,
618 repo: &Repo,
619 ws: &User,
620 read: Read,
621 subject: &mut Subject,
622 event_name: &str,
623 action: Option<&str>,
624 event_key: &str,
625 actor_id: Option<&str>,
626 sender: &str,
627 ) -> Result<()> {
628 for file in read.files {
629 let parsed = workflow::parse(&file.source);
630 let workflow = match parsed {
631 Ok(workflow) => workflow,
632 Err(problem) => {
633 // A push shows a broken workflow as a failed run, as GitHub does.
634 if event_name == "push" && file.source.contains("on") {
635 self.record_invalid(repo, &file.path, &file.source, subject, event_key, actor_id, sender, &problem)
636 .await?;
637 }
638 continue;
639 }
640 };
641 let Some(trigger) = workflow.trigger(event_name) else { continue };
642 // workflow_run follows the workflows it names.
643 if event_name == "workflow_run" {
644 let followed = subject.payload["workflow_run"]["name"].as_str().unwrap_or_default();
645 if !trigger.workflows.iter().any(|name| name == followed) {
646 continue;
647 }
648 }
649 if !trigger.wants_type(action) || !self.passes(repo, ws, trigger, subject, event_name).await? {
650 continue;
651 }
652 if self.disabled(&repo.id, &file.path).await? {
653 continue;
654 }
655 // On a mirror the remote may deploy too: a workflow that deploys
656 // waits for approval (mirrored.rs).
657 let held = crate::mirrored::policy(repo.mirror.as_ref(), false)
658 .hold
659 .zip(crate::mirrored::deploys_to(&workflow))
660 .map(|(remote, environment)| crate::mirrored::held(&remote, &environment));
661 self.create_run(NewRun {
662 repo: repo.clone(),
663 path: file.path,
664 source: file.source,
665 info: self.run_info(repo, &workflow, event_name, subject, sender, actor_id),
666 workflow,
667 action: action.map(str::to_owned),
668 pull: subject.pull,
669 title: subject.title.clone(),
670 inputs: Map::new(),
671 event_key: event_key.to_owned(),
672 actor_id: actor_id.map(str::to_owned),
673 actor: Some(sender.to_owned()),
674 trusted: subject.trusted,
675 approval: subject.approval.clone().or(held),
676 })
677 .await?;
678 }
679 Ok(())
680 }
681
682 /// Whether the branch, tag and path filters let the event through.
683 async fn passes(&self, repo: &Repo, ws: &User, trigger: &Trigger, subject: &mut Subject, event_name: &str) -> Result<bool> {
684 let git_ref = subject.filter_ref.as_str();
685 if let Some(tag) = git_ref.strip_prefix("refs/tags/") {
686 // A tag push runs a workflow that filters tags, or filters nothing.
687 if trigger.tags.is_set() {
688 if !trigger.tags.allows(tag) {
689 return Ok(false);
690 }
691 } else if trigger.branches.is_set() {
692 return Ok(false);
693 }
694 // Paths are not checked for tags, as on GitHub.
695 return Ok(true);
696 }
697 let branch = git_ref.strip_prefix("refs/heads/").unwrap_or(git_ref);
698 if trigger.branches.is_set() {
699 if !trigger.branches.allows(branch) {
700 return Ok(false);
701 }
702 } else if event_name == "push" && trigger.tags.is_set() {
703 return Ok(false);
704 }
705 if trigger.paths.is_set() {
706 if subject.paths.is_none() {
707 let (base, head) = subject.compare.clone().unwrap_or((None, subject.sha.clone()));
708 subject.paths = Some(self.changed_paths(repo, ws, base, head).await?);
709 }
710 if !trigger.paths.allows_paths(subject.paths.as_deref().unwrap_or_default()) {
711 return Ok(false);
712 }
713 }
714 Ok(true)
715 }
716
717 async fn disabled(&self, repo_id: &str, path: &str) -> Result<bool> {
718 let row = self
719 .db
720 .prepare("SELECT * FROM workflows WHERE repo_id = ? AND path = ?")
721 .bind(&[repo_id.into(), path.into()])?
722 .first::<WorkflowRow>(None)
723 .await?;
724 Ok(row.is_some_and(|row| row.state == "disabled"))
725 }
726
727 fn run_info(&self, repo: &Repo, workflow: &Workflow, event_name: &str, subject: &Subject, sender: &str, actor_id: Option<&str>) -> RunInfo {
728 RunInfo {
729 repository: format!("{}/{}", repo.namespace, repo.name),
730 repository_id: repo.id.clone(),
731 default_branch: repo.default_branch.clone(),
732 event_name: event_name.to_owned(),
733 event: subject.payload.clone(),
734 git_ref: subject.git_ref.clone(),
735 sha: subject.sha.clone(),
736 head_ref: subject.head_ref.clone(),
737 base_ref: subject.base_ref.clone(),
738 actor: sender.to_owned(),
739 actor_id: actor_id.unwrap_or_default().to_owned(),
740 triggering_actor: sender.to_owned(),
741 run_id: String::new(),
742 run_number: 0,
743 run_attempt: 1,
744 workflow: workflow.name.clone().unwrap_or_default(),
745 workflow_path: String::new(),
746 server_url: SITE.to_owned(),
747 api_url: API.to_owned(),
748 }
749 }
750
751 #[allow(clippy::too_many_arguments)]
752 async fn record_invalid(
753 &self,
754 repo: &Repo,
755 path: &str,
756 source: &str,
757 subject: &Subject,
758 event_key: &str,
759 actor_id: Option<&str>,
760 sender: &str,
761 problem: &str,
762 ) -> Result<()> {
763 let row = self.workflow_row(repo, path, path, source).await?;
764 self.record_failed_run(&row, subject.git_ref.as_str(), &subject.sha, event_key, actor_id, sender, problem).await
765 }
766
767 /// Scheduled workflows that run this minute, on the default branch: at
768 /// most every five minutes (`cron::Schedule::runs_at`). Not in a
769 /// repository with no push for [`crate::SCHEDULE_IDLE_MS`], nor for an
770 /// hour after billing refused one of the workflow's scheduled jobs
771 /// ([`crate::SCHEDULE_REFUSED_MS`]): no run is made only to be refused.
772 pub async fn run_schedules(&self, minute: u64) -> Result<()> {
773 let rows = self
774 .db
775 .prepare(
776 "SELECT * FROM workflows WHERE state = 'active' AND crons != '[]' AND error IS NULL
777 AND COALESCE(pushed_at, updated_at) >= ? AND (schedule_refused_until IS NULL OR schedule_refused_until <= ?)",
778 )
779 .bind(&[rfc3339(minute.saturating_sub(crate::SCHEDULE_IDLE_MS)).into(), rfc3339(minute).into()])?
780 .all()
781 .await?
782 .results::<WorkflowRow>()?;
783 for row in rows {
784 let crons: Vec<String> = serde_json::from_str(&row.crons).unwrap_or_default();
785 let Some(cron) = crons.iter().find(|cron| g1t_actions::cron::Schedule::parse(cron).is_ok_and(|s| s.runs_at(minute))) else {
786 continue;
787 };
788 let Ok(workflow) = workflow::parse(&row.source) else { continue };
789 // Schedules wait while a repository is archived, or a mirror runs
790 // nothing; a deleted one is not found.
791 let Some((repo, _ws)) = self
792 .repo_by_id(&row.repo_id)
793 .await?
794 .filter(|(repo, _)| !repo.archived() && crate::mirrored::policy(repo.mirror.as_ref(), false).runs)
795 else {
796 continue;
797 };
798 let Some(sha) = self.default_head(&repo).await? else { continue };
799 let payload = json!({ "schedule": cron, "repository": payload::repository(&repo), "workflow": row.path });
800 let mut subject = Subject {
801 source: Self::repo_path(&repo),
802 source_ref: None,
803 git_ref: format!("refs/heads/{}", repo.default_branch),
804 sha,
805 head_ref: None,
806 base_ref: None,
807 pull: None,
808 filter_ref: String::new(),
809 paths: None,
810 compare: None,
811 payload,
812 title: format!("Scheduled: {cron}"),
813 trusted: true,
814 approval: None,
815 };
816 subject.filter_ref = subject.git_ref.clone();
817 let info = self.run_info(&repo, &workflow, "schedule", &subject, &repo.namespace, None);
818 self.create_run(NewRun {
819 repo: repo.clone(),
820 path: row.path.clone(),
821 source: row.source.clone(),
822 workflow,
823 info,
824 action: None,
825 pull: None,
826 title: subject.title.clone(),
827 inputs: Map::new(),
828 event_key: format!("schedule:{minute}"),
829 actor_id: None,
830 actor: None,
831 trusted: true,
832 approval: None,
833 })
834 .await?;
835 }
836 Ok(())
837 }
838
839 /// `dispatch`: someone with the Write role runs a workflow that has
840 /// `workflow_dispatch`.
841 pub async fn dispatch(&self, a: DispatchArgs) -> Result<Outcome<WorkflowRun>> {
842 let repo = check!(self.may(&a.actor, &a.repo, Capability::Run).await?);
843 if repo.archived() {
844 return Ok(fail(FailureCode::Forbidden, g1t_contracts::repos::archived_message(&repo.namespace, &repo.name)));
845 }
846 let Some(ws) = self.workspace_actor(&repo.namespace).await? else {
847 return Ok(fail(FailureCode::NotFound, "There is no such workspace."));
848 };
849 let git_ref = a.git_ref.clone().unwrap_or_else(|| repo.default_branch.clone());
850 let full_ref = if git_ref.starts_with("refs/") {
851 git_ref.clone()
852 } else {
853 // A branch if there is one by that name, otherwise a tag.
854 let branches: Outcome<Vec<g1t_contracts::repos::Branch>> = g1t_kit::call(
855 &self.repos,
856 "branches",
857 &g1t_contracts::repos::BranchesArgs {
858 path: Self::repo_path(&repo),
859 viewer: Some(ws.clone()),
860 },
861 )
862 .await?;
863 let is_branch = branches.into_result().unwrap_or_default().iter().any(|branch| branch.name == git_ref);
864 format!("refs/{}/{git_ref}", if is_branch { "heads" } else { "tags" })
865 };
866 let short = full_ref.trim_start_matches("refs/heads/").trim_start_matches("refs/tags/").to_owned();
867 let policy = crate::mirrored::policy(repo.mirror.as_ref(), false);
868 if let Some(mirror) = repo.mirror.as_ref().filter(|_| !policy.runs) {
869 return Ok(fail(FailureCode::Forbidden, crate::mirrored::refused(&repo.namespace, &repo.name, mirror)));
870 }
871 let read = self.read_for(&repo, &ws, Some(&short), policy.github).await?;
872 let Some(sha) = read.head.clone() else {
873 return Ok(fail(FailureCode::NotFound, format!("There is no branch or tag called {short}.")));
874 };
875 // A workflow is named by its file (`build.yml`), its path, or its id
876 // (`wfl_…`), which stands for the path it was read from.
877 let by_id = if a.workflow.starts_with("wfl_") {
878 self.db
879 .prepare("SELECT * FROM workflows WHERE repo_id = ? AND id = ?")
880 .bind(&[repo.id.as_str().into(), a.workflow.as_str().into()])?
881 .first::<WorkflowRow>(None)
882 .await?
883 .map(|row| row.path)
884 } else {
885 None
886 };
887 let named = by_id.as_deref().unwrap_or(&a.workflow);
888 let wanted = named.trim_start_matches(".g1t/workflows/");
889 let Some(file) = read.files.iter().find(|file| {
890 file.path.rsplit('/').next() == Some(wanted) || file.path == named
891 }) else {
892 return Ok(fail(FailureCode::NotFound, format!("There is no workflow {wanted} on {short}.")));
893 };
894 let workflow = match workflow::parse(&file.source) {
895 Ok(workflow) => workflow,
896 Err(problem) => return Ok(fail(FailureCode::Invalid, format!("The workflow does not read: {problem}"))),
897 };
898 let Some(trigger) = workflow.trigger("workflow_dispatch") else {
899 return Ok(fail(FailureCode::Invalid, "That workflow cannot be run by hand: it has no `workflow_dispatch` trigger."));
900 };
901 let inputs = check!(dispatch_inputs(trigger, &a.inputs));
902 let payload = json!({
903 "inputs": inputs,
904 "ref": full_ref,
905 "repository": payload::repository(&repo),
906 "sender": payload::user(&a.actor.username),
907 "workflow": file.path,
908 });
909 let subject = Subject {
910 source: Self::repo_path(&repo),
911 source_ref: Some(sha.clone()),
912 git_ref: full_ref.clone(),
913 sha,
914 head_ref: None,
915 base_ref: None,
916 pull: None,
917 filter_ref: full_ref,
918 paths: None,
919 compare: None,
920 payload,
921 title: format!("{} run by {}", workflow.display_name(&file.path), a.actor.username),
922 trusted: true,
923 approval: None,
924 };
925 let info = self.run_info(&repo, &workflow, "workflow_dispatch", &subject, &a.actor.username, Some(&a.actor.id));
926 let created = self
927 .create_run(NewRun {
928 repo: repo.clone(),
929 path: file.path.clone(),
930 source: file.source.clone(),
931 workflow,
932 info,
933 action: None,
934 pull: None,
935 title: subject.title.clone(),
936 inputs,
937 event_key: format!("dispatch:{}", new_id("dsp", now_ms())),
938 actor_id: Some(a.actor.id.clone()),
939 actor: Some(a.actor.username.clone()),
940 trusted: true,
941 approval: None,
942 })
943 .await?;
944 match created {
945 Some(id) => self.run_summary(&id).await,
946 None => Ok(fail(FailureCode::Conflict, "It did not start.")),
947 }
948 }
949
950 /// `repository_dispatch`: an outside event, by name, starts the default
951 /// branch's workflows that run `on: repository_dispatch` with that type
952 /// (or with no `types`). A workflow job's token may send one: this,
953 /// with `workflow_dispatch`, is how a workflow starts another.
954 pub async fn repository_dispatch(&self, a: RepositoryDispatchArgs) -> Result<Outcome<u32>> {
955 let repo = check!(self.may(&a.actor, &a.repo, Capability::Push).await?);
956 if repo.archived() {
957 return Ok(fail(FailureCode::Forbidden, g1t_contracts::repos::archived_message(&repo.namespace, &repo.name)));
958 }
959 let event_type = a.event_type.trim().to_owned();
960 if event_type.is_empty() || event_type.chars().count() > 100 {
961 return Ok(fail(FailureCode::Invalid, "event_type is 1 to 100 characters."));
962 }
963 let client_payload = match a.client_payload {
964 Value::Null => json!({}),
965 Value::Object(map) if map.len() <= 10 => Value::Object(map),
966 Value::Object(_) => return Ok(fail(FailureCode::Invalid, "client_payload has at most 10 top-level properties.")),
967 _ => return Ok(fail(FailureCode::Invalid, "client_payload is a JSON object.")),
968 };
969 if serde_json::to_string(&client_payload).map_or(0, |text| text.len()) > 64 * 1024 {
970 return Ok(fail(FailureCode::Invalid, "client_payload is at most 64 KB."));
971 }
972 let Some(ws) = self.workspace_actor(&repo.namespace).await? else {
973 return Ok(fail(FailureCode::NotFound, "There is no such workspace."));
974 };
975 let policy = crate::mirrored::policy(repo.mirror.as_ref(), false);
976 if let Some(mirror) = repo.mirror.as_ref().filter(|_| !policy.runs) {
977 return Ok(fail(FailureCode::Forbidden, crate::mirrored::refused(&repo.namespace, &repo.name, mirror)));
978 }
979 let read = self.read_for(&repo, &ws, Some(&repo.default_branch), policy.github).await?;
980 let Some(sha) = read.head.clone() else {
981 return Ok(fail(FailureCode::NotFound, "The repository has no default branch to run on yet."));
982 };
983 let git_ref = format!("refs/heads/{}", repo.default_branch);
984 let payload = json!({
985 "action": event_type,
986 "branch": repo.default_branch,
987 "client_payload": client_payload,
988 "repository": payload::repository(&repo),
989 "sender": payload::user(&a.actor.username),
990 });
991 let key = format!("repository_dispatch:{}", new_id("dsp", now_ms()));
992 let mut started = 0u32;
993 for file in read.files {
994 let Ok(workflow) = workflow::parse(&file.source) else { continue };
995 let Some(trigger) = workflow.trigger("repository_dispatch") else { continue };
996 if !trigger.wants_type(Some(&event_type)) || self.disabled(&repo.id, &file.path).await? {
997 continue;
998 }
999 let subject = Subject {
1000 source: Self::repo_path(&repo),
1001 source_ref: Some(sha.clone()),
1002 git_ref: git_ref.clone(),
1003 sha: sha.clone(),
1004 head_ref: None,
1005 base_ref: None,
1006 pull: None,
1007 filter_ref: git_ref.clone(),
1008 paths: None,
1009 compare: None,
1010 payload: payload.clone(),
1011 title: event_type.clone(),
1012 trusted: true,
1013 approval: None,
1014 };
1015 let info = self.run_info(&repo, &workflow, "repository_dispatch", &subject, &a.actor.username, Some(&a.actor.id));
1016 let created = self
1017 .create_run(NewRun {
1018 repo: repo.clone(),
1019 path: file.path.clone(),
1020 source: file.source.clone(),
1021 workflow,
1022 info,
1023 action: Some(event_type.clone()),
1024 pull: None,
1025 title: subject.title.clone(),
1026 inputs: Map::new(),
1027 event_key: key.clone(),
1028 actor_id: Some(a.actor.id.clone()),
1029 actor: Some(a.actor.username.clone()),
1030 trusted: true,
1031 approval: None,
1032 })
1033 .await?;
1034 if created.is_some() {
1035 started += 1;
1036 }
1037 }
1038 Ok(Outcome::Ok(started))
1039 }
1040}
1041
1042#[derive(serde::Deserialize)]
1043#[serde(rename_all = "camelCase")]
1044pub struct MergeGroupArgs {
1045 pub repo_id: String,
1046 pub entry: String,
1047 pub sha: String,
1048 pub head_ref: String,
1049 #[serde(default)]
1050 pub base_sha: Option<String>,
1051 pub number: u32,
1052 #[serde(default)]
1053 pub ahead: Vec<u32>,
1054}
1055
1056impl Actions {
1057 /// `merge_group`: the merge queue built a state and its checks passed.
1058 /// Starts the workflows that run `on: merge_group` on it, as GitHub's
1059 /// queue does, and says how many started; the queue waits for their
1060 /// statuses on that commit.
1061 pub async fn merge_group(&self, a: MergeGroupArgs) -> Result<Outcome<Value>> {
1062 let Some((repo, ws)) = self.repo_by_id(&a.repo_id).await? else {
1063 return Ok(Outcome::Ok(json!({ "runs": 0 })));
1064 };
1065 let read = self.read_workflows(&Self::repo_path(&repo), &ws, Some(&a.sha)).await?;
1066 let head_commit = self.commits(&repo, &ws, &a.sha, None).await?.pop();
1067 let payload = json!({
1068 "action": "checks_requested",
1069 "merge_group": {
1070 "head_sha": a.sha,
1071 "head_ref": a.head_ref,
1072 "base_sha": a.base_sha,
1073 "base_ref": format!("refs/heads/{}", repo.default_branch),
1074 "head_commit": head_commit.as_ref().map(|c| payload::commit(&repo, c)),
1075 },
1076 "repository": payload::repository(&repo),
1077 "sender": payload::user(&repo.namespace),
1078 });
1079 let mut started = 0u32;
1080 for file in read.files {
1081 let Ok(workflow) = workflow::parse(&file.source) else { continue };
1082 let Some(trigger) = workflow.trigger("merge_group") else { continue };
1083 if !trigger.wants_type(Some("checks_requested")) || self.disabled(&repo.id, &file.path).await? {
1084 continue;
1085 }
1086 // Branch filters on merge_group name the branch it merges into.
1087 if trigger.branches.is_set() && !trigger.branches.allows(&repo.default_branch) {
1088 continue;
1089 }
1090 let ahead = if a.ahead.is_empty() {
1091 String::new()
1092 } else {
1093 format!(" after {}", a.ahead.iter().map(|n| format!("#{n}")).collect::<Vec<_>>().join(", "))
1094 };
1095 let subject = Subject {
1096 source: Self::repo_path(&repo),
1097 source_ref: Some(a.sha.clone()),
1098 git_ref: a.head_ref.clone(),
1099 sha: a.sha.clone(),
1100 head_ref: None,
1101 base_ref: Some(repo.default_branch.clone()),
1102 pull: Some(a.number),
1103 filter_ref: format!("refs/heads/{}", repo.default_branch),
1104 paths: None,
1105 compare: None,
1106 payload: payload.clone(),
1107 title: format!("Merge queue: #{}{ahead}", a.number),
1108 trusted: true,
1109 approval: None,
1110 };
1111 let info = self.run_info(&repo, &workflow, "merge_group", &subject, &repo.namespace, None);
1112 let created = self
1113 .create_run(NewRun {
1114 repo: repo.clone(),
1115 path: file.path.clone(),
1116 source: file.source.clone(),
1117 workflow,
1118 info,
1119 action: Some("checks_requested".to_owned()),
1120 pull: Some(a.number),
1121 title: subject.title.clone(),
1122 inputs: Map::new(),
1123 event_key: format!("merge_group:{}:{}", a.entry, a.sha),
1124 actor_id: None,
1125 actor: None,
1126 trusted: true,
1127 approval: None,
1128 })
1129 .await?;
1130 if created.is_some() {
1131 started += 1;
1132 }
1133 }
1134 Ok(Outcome::Ok(json!({ "runs": started })))
1135 }
1136}
1137
1138/// The inputs of a manual run: what was given, checked against the
1139/// workflow's declared inputs, with their defaults filled in.
1140fn dispatch_inputs(trigger: &Trigger, given: &Map<String, Value>) -> Outcome<Map<String, Value>> {
1141 let mut inputs = Map::new();
1142 for (name, spec) in &trigger.inputs {
1143 let kind = spec.get("type").and_then(Value::as_str).unwrap_or("string");
1144 let value = given.get(name).cloned().or_else(|| spec.get("default").cloned());
1145 let required = spec.get("required").and_then(Value::as_bool).unwrap_or(false);
1146 let value = match value {
1147 Some(Value::Null) | None if required => return fail(FailureCode::Invalid, format!("The input `{name}` is required.")),
1148 Some(Value::Null) | None => match kind {
1149 "boolean" => Value::Bool(false),
1150 _ => Value::String(String::new()),
1151 },
1152 Some(value) => match kind {
1153 "boolean" => Value::Bool(match &value {
1154 Value::Bool(flag) => *flag,
1155 Value::String(text) => text == "true",
1156 _ => false,
1157 }),
1158 "number" => match &value {
1159 Value::Number(_) => value,
1160 Value::String(text) => match text.parse::<f64>().ok().and_then(serde_json::Number::from_f64) {
1161 Some(number) => Value::Number(number),
1162 None => return fail(FailureCode::Invalid, format!("The input `{name}` is a number.")),
1163 },
1164 _ => return fail(FailureCode::Invalid, format!("The input `{name}` is a number.")),
1165 },
1166 "choice" => {
1167 let text = g1t_actions::expr::to_text(&value);
1168 let options: Vec<String> =
1169 spec.get("options").and_then(Value::as_array).map(|o| o.iter().map(g1t_actions::expr::to_text).collect()).unwrap_or_default();
1170 if !options.is_empty() && !options.contains(&text) {
1171 return fail(FailureCode::Invalid, format!("The input `{name}` is one of {}.", options.join(", ")));
1172 }
1173 Value::String(text)
1174 }
1175 _ => Value::String(g1t_actions::expr::to_text(&value)),
1176 },
1177 };
1178 inputs.insert(name.clone(), value);
1179 }
1180 Outcome::Ok(inputs)
1181}
1182
1183#[cfg(test)]
1184mod tests {
1185 use super::*;
1186 use g1t_contracts::work::{Pull, g1t_author};
1187
1188 #[test]
1189 fn every_event_a_workflow_runs_on_is_sent_to_this_queue() {
1190 for kind in g1t_contracts::webhooks::EVENT_TYPES {
1191 if !github_events(kind).is_empty() {
1192 assert!(
1193 g1t_contracts::subscribers::routed("SUBSCRIBER_ACTIONS", kind),
1194 "{kind} starts workflows but is not routed to actions (g1t_contracts::subscribers)"
1195 );
1196 }
1197 }
1198 }
1199 use g1t_contracts::{Membership, PrincipalKind};
1200
1201 fn repo() -> Repo {
1202 serde_json::from_value(json!({
1203 "id": "rep_1", "namespace": "acme", "name": "web", "description": null, "isPrivate": true,
1204 "ownerId": "ws_1", "defaultBranch": "main", "forkOf": null, "createdAt": ""
1205 }))
1206 .unwrap()
1207 }
1208
1209 fn person(id: &str, username: &str) -> User {
1210 User { id: id.into(), username: username.into(), kind: PrincipalKind::User, ..User::default() }
1211 }
1212
1213 fn made_for(asker: User) -> Pull {
1214 serde_json::from_value(json!({
1215 "id": "pr_1", "repoId": "rep_1", "number": 14, "issue": 12, "title": "Fix it", "body": null,
1216 "agent": "g1t", "runtime": "hosted", "status": "open",
1217 "fork": { "namespace": "pulls", "name": "pr_1" }, "forkRepoId": "rep_f",
1218 "branch": null, "headCommit": "abc", "mergeBase": null, "mergedBy": null, "mergedAt": null,
1219 "supersededBy": null, "checkStatus": null,
1220 "author": g1t_author(), "requestedBy": asker,
1221 "createdAt": "", "updatedAt": ""
1222 }))
1223 .unwrap()
1224 }
1225
1226 #[test]
1227 fn g1t_s_change_for_someone_is_trusted_as_they_are() {
1228 // Stored people carry no memberships, so identity is asked about
1229 // them; being g1t's change gives it nothing more.
1230 let pull = made_for(person("usr_2", "ana"));
1231 assert!(!trusted_outright(pull.owner(), &repo()));
1232 // Someone known to be able to push is trusted at once.
1233 let mut member = person("usr_1", "syntaqx");
1234 member.workspaces.push(Membership::member("acme"));
1235 let pull = made_for(member);
1236 assert!(trusted_outright(pull.owner(), &repo()));
1237 }
1238
1239 #[test]
1240 fn the_payload_names_g1t_as_its_user_and_who_asked_for_it() {
1241 let pull = made_for(person("usr_1", "syntaqx"));
1242 let event = payload::pull(&repo(), &pull);
1243 assert_eq!(event["user"]["login"], "g1t");
1244 assert_eq!(event["user"]["type"], "Bot");
1245 assert_eq!(event["requested_by"]["login"], "syntaqx");
1246 assert_eq!(event["requested_by"]["type"], "User");
1247 let as_issue = payload::pull_as_issue(&repo(), &pull);
1248 assert_eq!(as_issue["user"]["login"], "g1t");
1249 assert_eq!(as_issue["requested_by"]["login"], "syntaqx");
1250 }
1251
1252 #[test]
1253 fn releases_deployments_and_deleted_comments_read_as_githubs() {
1254 let release = payload::release(
1255 &repo(),
1256 &json!({ "id": "rel_1", "tagName": "v1.2.0", "target": "abc", "name": null, "body": "Notes", "draft": false,
1257 "prerelease": true, "author": "ana", "createdAt": "2026-10-08T00:00:00Z", "publishedAt": "2026-10-08T00:00:00Z" }),
1258 );
1259 assert_eq!(release["tag_name"], "v1.2.0");
1260 assert_eq!(release["name"], "v1.2.0");
1261 assert_eq!(release["prerelease"], true);
1262 assert_eq!(release["author"]["login"], "ana");
1263 assert_eq!(release["html_url"], "https://g1t.sh/acme/web/releases/tag/v1.2.0");
1264 let deployment = json!({ "id": "dep_1", "sha": "abc", "ref": "main", "environment": "staging", "creator": "ana",
1265 "production_environment": false, "created_at": "t", "updated_at": "t" });
1266 let status = payload::deployment_status(&repo(), &json!({ "id": "dst_1", "state": "success", "environment_url": "https://s.example", "log_url": null, "creator": "g1t", "created_at": "t" }), &deployment);
1267 assert_eq!(status["state"], "success");
1268 assert_eq!(status["environment"], "staging");
1269 assert_eq!(status["environment_url"], "https://s.example");
1270 assert_eq!(payload::deployment(&repo(), &deployment)["payload"], json!({}));
1271 let gone = payload::deleted_comment(&repo(), 7, &json!({ "id": "cmt_1", "body": "hi", "author": { "id": "usr_1", "username": "bo" }, "createdAt": "t" }), true);
1272 assert_eq!(gone["user"]["login"], "bo");
1273 assert_eq!(gone["html_url"], "https://g1t.sh/acme/web/pull/7#cmt_1");
1274 assert!(is_commit("0123456789abcdef0123456789abcdef01234567"));
1275 assert!(!is_commit("main"));
1276 }
1277
1278 #[test]
1279 fn a_pull_request_names_its_own_base_labels_and_milestone() {
1280 let mut pull = made_for(person("usr_1", "syntaqx"));
1281 let event = payload::pull(&repo(), &pull);
1282 assert_eq!(event["base"]["ref"], repo().default_branch);
1283 pull.base = Some("release/1.x".into());
1284 pull.labels = vec!["bug".into()];
1285 pull.milestone = Some(g1t_contracts::work::MilestoneRef { number: 2, title: "1.1".into() });
1286 let event = payload::pull(&repo(), &pull);
1287 assert_eq!(event["base"]["ref"], "release/1.x");
1288 assert_eq!(event["labels"], serde_json::json!([{ "name": "bug" }]));
1289 assert_eq!(event["milestone"]["title"], "1.1");
1290 let mut labeled = serde_json::json!({ "action": "labeled" });
1291 payload::changed(&mut labeled, &serde_json::json!({ "label": { "name": "bug", "color": "d73a4a" } }));
1292 assert_eq!(labeled["label"]["color"], "d73a4a");
1293 }
1294}