Commit

GitHub Actions on g1t, part one: reading workflows

A new crate, g1t-actions, reads .github/workflows files the way GitHub does: triggers and their branch, tag and path filters; jobs, needs and steps; matrices with include and exclude; the ${{ }} expression language with its contexts, functions and status checks; and the github context and GITHUB_* variables a run sees. It notes anything that runs differently on g1t, for the migration report. Push events now carry the commit a ref pointed to before, and tag pushes are reported as well as branch pushes.

syntaqxcommitted Parentde9d23eBrowse files
11 files+3166−260/11 viewed
+9−0
871871 version = "0.1.0"
872872
873873 [[package]]
874+name = "g1t-actions"
875+version = "0.1.0"
876+dependencies = [
877+ "serde",
878+ "serde_json",
879+ "serde_yaml",
880+]
881+
882+[[package]]
874883 name = "g1t-api"
875884 version = "0.1.0"
876885 dependencies = [
+11−0
1+[package]
2+name = "g1t-actions"
3+version = "0.1.0"
4+edition.workspace = true
5+license.workspace = true
6+description = "GitHub Actions workflows on g1t: reading them, their expressions, their filters and their jobs. Shared by the actions service and the sandbox."
7+
8+[dependencies]
9+serde = { workspace = true }
10+serde_json = { workspace = true, features = ["preserve_order"] }
11+serde_yaml = "0.9"
+221−0
1+//! g1t's events as GitHub's: which event and activity type each one is,
2+//! and the `github` context and `GITHUB_*` variables a run sees.
3+
4+use serde::{Deserialize, Serialize};
5+use serde_json::{Map, Value, json};
6+
7+/// The GitHub event and activity type for a g1t event, if it has one.
8+/// A g1t event can be more than one GitHub event: a pull request opening
9+/// is `pull_request` and `pull_request_target`.
10+pub fn github_events(kind: &str) -> Vec<(&'static str, Option<&'static str>)> {
11+ let pull = |action| vec![("pull_request", Some(action)), ("pull_request_target", Some(action))];
12+ match kind {
13+ "git.push" => vec![("push", None)],
14+ "pull.opened" => pull("opened"),
15+ "pull.updated" => pull("synchronize"),
16+ "pull.ready" => pull("ready_for_review"),
17+ "pull.closed" | "pull.merged" => pull("closed"),
18+ "issue.opened" => vec![("issues", Some("opened"))],
19+ "issue.updated" => vec![("issues", Some("edited"))],
20+ "issue.closed" => vec![("issues", Some("closed"))],
21+ "issue.reopened" => vec![("issues", Some("reopened"))],
22+ "issue.assigned" => vec![("issues", Some("assigned"))],
23+ "comment.created" => vec![("issue_comment", Some("created"))],
24+ "review.completed" => vec![("pull_request_review", Some("submitted"))],
25+ _ => Vec::new(),
26+ }
27+}
28+
29+/// What a run is about: enough to fill the `github` context.
30+#[derive(Clone, Debug, Default, Serialize, Deserialize)]
31+#[serde(rename_all = "camelCase")]
32+pub struct RunInfo {
33+ /// `acme/web`.
34+ pub repository: String,
35+ pub repository_id: String,
36+ pub default_branch: String,
37+ pub event_name: String,
38+ /// The webhook-shaped payload, `github.event`.
39+ pub event: Value,
40+ /// `refs/heads/main`, `refs/tags/v1`, `refs/pull/3/merge`.
41+ pub git_ref: String,
42+ pub sha: String,
43+ /// For pull requests: the head and base branches.
44+ pub head_ref: Option<String>,
45+ pub base_ref: Option<String>,
46+ pub actor: String,
47+ pub actor_id: String,
48+ pub triggering_actor: String,
49+ pub run_id: String,
50+ pub run_number: u64,
51+ pub run_attempt: u64,
52+ /// The workflow's name.
53+ pub workflow: String,
54+ /// `.github/workflows/ci.yml`.
55+ pub workflow_path: String,
56+ pub server_url: String,
57+ pub api_url: String,
58+}
59+
60+impl RunInfo {
61+ pub fn ref_name(&self) -> String {
62+ self.git_ref
63+ .strip_prefix("refs/heads/")
64+ .or_else(|| self.git_ref.strip_prefix("refs/tags/"))
65+ .or_else(|| self.git_ref.strip_prefix("refs/"))
66+ .unwrap_or(&self.git_ref)
67+ .to_owned()
68+ }
69+
70+ pub fn ref_type(&self) -> &'static str {
71+ if self.git_ref.starts_with("refs/tags/") { "tag" } else { "branch" }
72+ }
73+
74+ fn owner(&self) -> &str {
75+ self.repository.split('/').next().unwrap_or_default()
76+ }
77+
78+ /// The `github` context for a job. `token` is `github.token` (and
79+ /// `secrets.GITHUB_TOKEN`); `job` is the job's id.
80+ pub fn context(&self, job: &str, token: &str, action: Option<&str>) -> Value {
81+ json!({
82+ "action": action.unwrap_or_default(),
83+ "action_path": "",
84+ "action_ref": "",
85+ "action_repository": "",
86+ "actor": self.actor,
87+ "actor_id": self.actor_id,
88+ "api_url": self.api_url,
89+ "base_ref": self.base_ref.clone().unwrap_or_default(),
90+ "env": "",
91+ "event": self.event,
92+ "event_name": self.event_name,
93+ "event_path": "/home/runner/_temp/event.json",
94+ "graphql_url": "",
95+ "head_ref": self.head_ref.clone().unwrap_or_default(),
96+ "job": job,
97+ "path": "",
98+ "ref": self.git_ref,
99+ "ref_name": self.ref_name(),
100+ "ref_protected": self.ref_name() == self.default_branch,
101+ "ref_type": self.ref_type(),
102+ "repository": self.repository,
103+ "repository_id": self.repository_id,
104+ "repository_owner": self.owner(),
105+ "repository_owner_id": "",
106+ "repositoryUrl": format!("{}/{}.git", self.server_url, self.repository),
107+ "retention_days": 14,
108+ "run_attempt": self.run_attempt.to_string(),
109+ "run_id": self.run_id,
110+ "run_number": self.run_number.to_string(),
111+ "secret_source": "Actions",
112+ "server_url": self.server_url,
113+ "sha": self.sha,
114+ "token": token,
115+ "triggering_actor": self.triggering_actor,
116+ "workflow": self.workflow,
117+ "workflow_ref": format!("{}/{}@{}", self.repository, self.workflow_path, self.git_ref),
118+ "workflow_sha": self.sha,
119+ "workspace": WORKSPACE,
120+ })
121+ }
122+
123+ /// The `GITHUB_*` and `RUNNER_*` variables every step gets.
124+ pub fn variables(&self, job: &str) -> Map<String, Value> {
125+ let mut vars = Map::new();
126+ let mut set = |key: &str, value: String| {
127+ vars.insert(key.to_owned(), Value::String(value));
128+ };
129+ set("CI", "true".into());
130+ set("GITHUB_ACTIONS", "true".into());
131+ set("G1T", "true".into());
132+ set("GITHUB_ACTOR", self.actor.clone());
133+ set("GITHUB_ACTOR_ID", self.actor_id.clone());
134+ set("GITHUB_API_URL", self.api_url.clone());
135+ set("GITHUB_BASE_REF", self.base_ref.clone().unwrap_or_default());
136+ set("GITHUB_EVENT_NAME", self.event_name.clone());
137+ set("GITHUB_EVENT_PATH", "/home/runner/_temp/event.json".into());
138+ set("GITHUB_GRAPHQL_URL", String::new());
139+ set("GITHUB_HEAD_REF", self.head_ref.clone().unwrap_or_default());
140+ set("GITHUB_JOB", job.to_owned());
141+ set("GITHUB_REF", self.git_ref.clone());
142+ set("GITHUB_REF_NAME", self.ref_name());
143+ set("GITHUB_REF_PROTECTED", (self.ref_name() == self.default_branch).to_string());
144+ set("GITHUB_REF_TYPE", self.ref_type().into());
145+ set("GITHUB_REPOSITORY", self.repository.clone());
146+ set("GITHUB_REPOSITORY_ID", self.repository_id.clone());
147+ set("GITHUB_REPOSITORY_OWNER", self.owner().to_owned());
148+ set("GITHUB_RETENTION_DAYS", "14".into());
149+ set("GITHUB_RUN_ATTEMPT", self.run_attempt.to_string());
150+ set("GITHUB_RUN_ID", self.run_id.clone());
151+ set("GITHUB_RUN_NUMBER", self.run_number.to_string());
152+ set("GITHUB_SERVER_URL", self.server_url.clone());
153+ set("GITHUB_SHA", self.sha.clone());
154+ set("GITHUB_TRIGGERING_ACTOR", self.triggering_actor.clone());
155+ set("GITHUB_WORKFLOW", self.workflow.clone());
156+ set("GITHUB_WORKFLOW_REF", format!("{}/{}@{}", self.repository, self.workflow_path, self.git_ref));
157+ set("GITHUB_WORKFLOW_SHA", self.sha.clone());
158+ set("GITHUB_WORKSPACE", WORKSPACE.into());
159+ set("RUNNER_ARCH", "X64".into());
160+ set("RUNNER_NAME", "g1t".into());
161+ set("RUNNER_OS", "Linux".into());
162+ set("RUNNER_TEMP", "/home/runner/_temp".into());
163+ set("RUNNER_TOOL_CACHE", "/home/runner/_tool".into());
164+ set("RUNNER_ENVIRONMENT", "github-hosted".into());
165+ vars
166+ }
167+}
168+
169+/// Where a job's repository is checked out, as on GitHub's runners.
170+pub const WORKSPACE: &str = "/home/runner/work/repo";
171+
172+/// The `runner` context.
173+pub fn runner_context() -> Value {
174+ json!({
175+ "name": "g1t",
176+ "os": "Linux",
177+ "arch": "X64",
178+ "temp": "/home/runner/_temp",
179+ "tool_cache": "/home/runner/_tool",
180+ "environment": "github-hosted",
181+ "debug": "",
182+ })
183+}
184+
185+#[cfg(test)]
186+mod tests {
187+ use super::*;
188+
189+ #[test]
190+ fn g1t_events_are_github_events() {
191+ assert_eq!(github_events("git.push"), [("push", None)]);
192+ assert_eq!(github_events("pull.updated")[0], ("pull_request", Some("synchronize")));
193+ assert_eq!(github_events("pull.merged")[1], ("pull_request_target", Some("closed")));
194+ assert_eq!(github_events("comment.created"), [("issue_comment", Some("created"))]);
195+ assert!(github_events("session.appended").is_empty());
196+ }
197+
198+ #[test]
199+ fn contexts_and_variables_agree() {
200+ let info = RunInfo {
201+ repository: "acme/web".into(),
202+ default_branch: "main".into(),
203+ event_name: "push".into(),
204+ git_ref: "refs/tags/v1.2.0".into(),
205+ sha: "abc".into(),
206+ run_number: 7,
207+ run_attempt: 1,
208+ server_url: "https://g1t.sh".into(),
209+ ..RunInfo::default()
210+ };
211+ let github = info.context("build", "tok", None);
212+ assert_eq!(github["ref_name"], "v1.2.0");
213+ assert_eq!(github["ref_type"], "tag");
214+ assert_eq!(github["repository_owner"], "acme");
215+ assert_eq!(github["run_number"], "7");
216+ let vars = info.variables("build");
217+ assert_eq!(vars["GITHUB_REF_NAME"], "v1.2.0");
218+ assert_eq!(vars["GITHUB_JOB"], "build");
219+ assert_eq!(vars["RUNNER_OS"], "Linux");
220+ }
221+}
+1756−0
1+//! The GitHub Actions expression language: the `${{ }}` language.
2+//!
3+//! This follows GitHub's "Evaluate expressions in workflows and actions"
4+//! precisely, so a real `.github/workflows/*.yml` evaluates here the way it
5+//! does on GitHub: the same literals, the same operator precedence, the same
6+//! loose equality (with its coercions to number), the same case-insensitive
7+//! string handling, the same object filters (`labels.*.name`) and the same
8+//! functions. Parse errors are found before anything is evaluated, so an
9+//! unknown context or function is an error even in a branch that would never
10+//! run, as on GitHub.
11+
12+use serde_json::{Map, Value};
13+use std::borrow::Cow;
14+use std::cmp::Ordering;
15+
16+/// How the job is going, for success(), failure(), cancelled(), always().
17+#[derive(Clone, Copy, Debug, PartialEq, Eq)]
18+pub enum Status {
19+ Success,
20+ Failure,
21+ Cancelled,
22+}
23+
24+pub struct Scope<'a> {
25+ /// Top-level contexts by lower-case name: github, env, vars, secrets, inputs, matrix, strategy, needs, steps, job, jobs, runner.
26+ pub contexts: &'a Map<String, Value>,
27+ pub status: Status,
28+ /// hashFiles(...) when the caller can compute it (the sandbox); None means hashFiles evaluates to "".
29+ #[allow(clippy::type_complexity)]
30+ pub hash_files: Option<&'a dyn Fn(&[String]) -> String>,
31+}
32+
33+/// The contexts a workflow may name, whether or not the caller supplied them.
34+const NAMED_VALUES: &[&str] = &[
35+ "github", "env", "vars", "secrets", "inputs", "matrix", "strategy", "needs", "steps", "job",
36+ "jobs", "runner",
37+];
38+
39+/// Evaluates one expression (the text between `${{` and `}}`, or a bare `if:`).
40+pub fn evaluate(expression: &str, scope: &Scope) -> Result<Value, String> {
41+ let ast = parse(expression, scope.contexts)?;
42+ Ok(eval(&ast, scope)?.into_value())
43+}
44+
45+/// An `if:` value: with or without `${{ }}` around it; when the expression calls none of success/failure/cancelled/always, it is implicitly `success() && (expr)`. An empty condition is `success()`.
46+pub fn condition(text: &str, scope: &Scope) -> Result<bool, String> {
47+ let success = scope.status == Status::Success;
48+ let trimmed = text.trim();
49+ let source = match single_expression(trimmed) {
50+ Some(inner) => inner,
51+ // Text around or between expressions makes the whole thing a string,
52+ // as on GitHub: it is true whenever it interpolates to anything.
53+ None if has_expression(trimmed) => {
54+ let text = interpolate(trimmed, scope)?;
55+ return Ok(success && !text.is_empty());
56+ }
57+ None => trimmed,
58+ };
59+ if source.trim().is_empty() {
60+ return Ok(success);
61+ }
62+ let ast = parse(source, scope.contexts)?;
63+ if uses_status(&ast) {
64+ Ok(eval(&ast, scope)?.truthy())
65+ } else {
66+ Ok(success && eval(&ast, scope)?.truthy())
67+ }
68+}
69+
70+/// Replaces each `${{ expr }}` in text with the value converted to a string. Text without `${{` is returned unchanged.
71+pub fn interpolate(text: &str, scope: &Scope) -> Result<String, String> {
72+ if !has_expression(text) {
73+ return Ok(text.to_string());
74+ }
75+ let mut out = String::with_capacity(text.len());
76+ let mut from = 0;
77+ while let Some(rel) = text[from..].find("${{") {
78+ let open = from + rel;
79+ out.push_str(&text[from..open]);
80+ let body = open + 3;
81+ let close = find_close(text, body).ok_or_else(|| {
82+ format!(
83+ "The expression is not closed. An unescaped ${{{{ sequence was found, but the closing }}}} sequence was not found: {text}"
84+ )
85+ })?;
86+ let value = evaluate(&text[body..close], scope)?;
87+ out.push_str(&to_text(&value));
88+ from = close + 2;
89+ }
90+ out.push_str(&text[from..]);
91+ Ok(out)
92+}
93+
94+/// Interpolates every string inside a JSON value (keys too). If a string is exactly one `${{ expr }}` and nothing else, the result keeps the expression's type (as GitHub does for e.g. `strategy.matrix: ${{ fromJSON(...) }}`, `continue-on-error: ${{ ... }}`).
95+pub fn interpolate_value(value: &Value, scope: &Scope) -> Result<Value, String> {
96+ Ok(match value {
97+ Value::String(text) => match single_expression(text) {
98+ Some(inner) => evaluate(inner, scope)?,
99+ None => Value::String(interpolate(text, scope)?),
100+ },
101+ Value::Array(items) => Value::Array(
102+ items
103+ .iter()
104+ .map(|item| interpolate_value(item, scope))
105+ .collect::<Result<_, _>>()?,
106+ ),
107+ Value::Object(map) => {
108+ let mut out = Map::new();
109+ for (key, item) in map {
110+ out.insert(interpolate(key, scope)?, interpolate_value(item, scope)?);
111+ }
112+ Value::Object(out)
113+ }
114+ other => other.clone(),
115+ })
116+}
117+
118+/// false, 0, -0, NaN, "" and null are falsy; everything else is truthy.
119+pub fn truthy(value: &Value) -> bool {
120+ match value {
121+ Value::Null => false,
122+ Value::Bool(b) => *b,
123+ Value::Number(n) => n.as_f64().is_some_and(|f| f != 0.0 && !f.is_nan()),
124+ Value::String(s) => !s.is_empty(),
125+ Value::Array(_) | Value::Object(_) => true,
126+ }
127+}
128+
129+/// A value as GitHub writes it into a string: null → "", bools "true"/"false", numbers as GitHub formats them (integers without ".0"), strings as-is, and `Array` or `Object` for collections, as GitHub's runner does (`toJSON` gives their contents).
130+pub fn to_text(value: &Value) -> String {
131+ match value {
132+ Value::Null => String::new(),
133+ Value::Bool(b) => b.to_string(),
134+ Value::Number(n) => format_number(n.as_f64().unwrap_or(f64::NAN)),
135+ Value::String(s) => s.clone(),
136+ Value::Array(_) => "Array".to_owned(),
137+ Value::Object(_) => "Object".to_owned(),
138+ }
139+}
140+
141+/// Whether text contains `${{`.
142+pub fn has_expression(text: &str) -> bool {
143+ text.contains("${{")
144+}
145+
146+// ---------------------------------------------------------------------------
147+// Template scanning
148+
149+/// Finds the `}}` closing an expression whose body starts at byte `from`,
150+/// skipping over string literals (which may themselves contain `}}`).
151+fn find_close(text: &str, from: usize) -> Option<usize> {
152+ let bytes = text.as_bytes();
153+ let mut in_string = false;
154+ let mut i = from;
155+ while i < bytes.len() {
156+ match bytes[i] {
157+ b'\'' => in_string = !in_string,
158+ b'}' if !in_string && bytes.get(i + 1) == Some(&b'}') => return Some(i),
159+ _ => {}
160+ }
161+ i += 1;
162+ }
163+ None
164+}
165+
166+/// The body of text when text is exactly one `${{ expr }}` and nothing else.
167+fn single_expression(text: &str) -> Option<&str> {
168+ let text = text.trim();
169+ if !text.starts_with("${{") {
170+ return None;
171+ }
172+ let close = find_close(text, 3)?;
173+ (close + 2 == text.len()).then(|| &text[3..close])
174+}
175+
176+// ---------------------------------------------------------------------------
177+// Lexing
178+
179+#[derive(Clone, Debug, PartialEq)]
180+enum Tok {
181+ Null,
182+ True,
183+ False,
184+ Number(f64),
185+ Str(String),
186+ Ident(String),
187+ Dot,
188+ Star,
189+ LBracket,
190+ RBracket,
191+ LParen,
192+ RParen,
193+ Comma,
194+ Not,
195+ Lt,
196+ Le,
197+ Gt,
198+ Ge,
199+ Eq,
200+ Ne,
201+ And,
202+ Or,
203+}
204+
205+#[derive(Clone, Debug)]
206+struct Token {
207+ tok: Tok,
208+ /// 1-based character position within the expression.
209+ pos: usize,
210+ /// The token as written, for error messages.
211+ text: String,
212+}
213+
214+fn located(message: &str, pos: usize, src: &str) -> String {
215+ format!("{message}. Located at position {pos} within expression: {src}")
216+}
217+
218+fn lex(src: &str) -> Result<Vec<Token>, String> {
219+ let chars: Vec<char> = src.chars().collect();
220+ let mut out: Vec<Token> = Vec::new();
221+ let mut i = 0;
222+ while i < chars.len() {
223+ let c = chars[i];
224+ if c.is_whitespace() {
225+ i += 1;
226+ continue;
227+ }
228+ let start = i;
229+ let next = chars.get(i + 1).copied();
230+ // Whether a value (rather than an operator) may come next, which
231+ // decides whether `.5` is a number or a dereference.
232+ let value_may_start = out.last().is_none_or(|t| {
233+ !matches!(
234+ t.tok,
235+ Tok::Ident(_)
236+ | Tok::Number(_)
237+ | Tok::Str(_)
238+ | Tok::Null
239+ | Tok::True
240+ | Tok::False
241+ | Tok::RParen
242+ | Tok::RBracket
243+ | Tok::Star
244+ )
245+ });
246+ let starts_number = c.is_ascii_digit()
247+ || ((c == '-' || c == '+') && next.is_some_and(|n| n.is_ascii_digit() || n == '.'))
248+ || (c == '.' && value_may_start && next.is_some_and(|n| n.is_ascii_digit()));
249+ let tok = if starts_number {
250+ i += 1;
251+ while i < chars.len() {
252+ let d = chars[i];
253+ let so_far: String = chars[start..i].iter().collect();
254+ let hex = so_far
255+ .trim_start_matches(['-', '+'])
256+ .to_ascii_lowercase()
257+ .starts_with("0x");
258+ let exponent_sign =
259+ (d == '+' || d == '-') && matches!(chars[i - 1], 'e' | 'E') && !hex;
260+ if d.is_ascii_alphanumeric() || d == '.' || d == '_' || exponent_sign {
261+ i += 1;
262+ } else {
263+ break;
264+ }
265+ }
266+ let text: String = chars[start..i].iter().collect();
267+ match parse_number(&text, false) {
268+ Some(n) => Tok::Number(n),
269+ None => {
270+ return Err(located(
271+ &format!("Unexpected symbol: '{text}'"),
272+ start + 1,
273+ src,
274+ ));
275+ }
276+ }
277+ } else if c.is_alphabetic() || c == '_' {
278+ i += 1;
279+ while i < chars.len()
280+ && (chars[i].is_alphanumeric() || chars[i] == '_' || chars[i] == '-')
281+ {
282+ i += 1;
283+ }
284+ let word: String = chars[start..i].iter().collect();
285+ match word.as_str() {
286+ "null" => Tok::Null,
287+ "true" => Tok::True,
288+ "false" => Tok::False,
289+ _ => Tok::Ident(word),
290+ }
291+ } else if c == '\'' {
292+ i += 1;
293+ let mut s = String::new();
294+ loop {
295+ match chars.get(i) {
296+ None => {
297+ let text: String = chars[start..].iter().collect();
298+ return Err(located(
299+ &format!("Unexpected symbol: '{text}'"),
300+ start + 1,
301+ src,
302+ ));
303+ }
304+ Some('\'') if chars.get(i + 1) == Some(&'\'') => {
305+ s.push('\'');
306+ i += 2;
307+ }
308+ Some('\'') => {
309+ i += 1;
310+ break;
311+ }
312+ Some(&ch) => {
313+ s.push(ch);
314+ i += 1;
315+ }
316+ }
317+ }
318+ Tok::Str(s)
319+ } else {
320+ let two = |a: char, b: char| c == a && next == Some(b);
321+ let (tok, len) = if two('=', '=') {
322+ (Tok::Eq, 2)
323+ } else if two('!', '=') {
324+ (Tok::Ne, 2)
325+ } else if two('<', '=') {
326+ (Tok::Le, 2)
327+ } else if two('>', '=') {
328+ (Tok::Ge, 2)
329+ } else if two('&', '&') {
330+ (Tok::And, 2)
331+ } else if two('|', '|') {
332+ (Tok::Or, 2)
333+ } else {
334+ let tok = match c {
335+ '.' => Tok::Dot,
336+ '*' => Tok::Star,
337+ '[' => Tok::LBracket,
338+ ']' => Tok::RBracket,
339+ '(' => Tok::LParen,
340+ ')' => Tok::RParen,
341+ ',' => Tok::Comma,
342+ '!' => Tok::Not,
343+ '<' => Tok::Lt,
344+ '>' => Tok::Gt,
345+ _ => {
346+ return Err(located(
347+ &format!("Unexpected symbol: '{c}'"),
348+ start + 1,
349+ src,
350+ ));
351+ }
352+ };
353+ (tok, 1)
354+ };
355+ i += len;
356+ tok
357+ };
358+ out.push(Token {
359+ tok,
360+ pos: start + 1,
361+ text: chars[start..i].iter().collect(),
362+ });
363+ }
364+ Ok(out)
365+}
366+
367+/// Parses a number. Literals (`lenient == false`) must be exactly a number;
368+/// strings being coerced (`lenient == true`) may be padded with whitespace,
369+/// and the empty string is 0.
370+fn parse_number(text: &str, lenient: bool) -> Option<f64> {
371+ let s = if lenient { text.trim() } else { text };
372+ if s.is_empty() {
373+ return lenient.then_some(0.0);
374+ }
375+ let (negative, body) = match s.as_bytes()[0] {
376+ b'-' => (true, &s[1..]),
377+ b'+' => (false, &s[1..]),
378+ _ => (false, s),
379+ };
380+ let sign = if negative { -1.0 } else { 1.0 };
381+ let lower = body.to_ascii_lowercase();
382+ if let Some(hex) = lower.strip_prefix("0x") {
383+ return u64::from_str_radix(hex, 16).ok().map(|n| sign * n as f64);
384+ }
385+ if let Some(oct) = lower.strip_prefix("0o") {
386+ return u64::from_str_radix(oct, 8).ok().map(|n| sign * n as f64);
387+ }
388+ if lenient && body == "Infinity" {
389+ return Some(sign * f64::INFINITY);
390+ }
391+ // digits [. digits] [e [+-] digits], with at least one mantissa digit.
392+ let bytes = body.as_bytes();
393+ let mut i = 0;
394+ let mut mantissa_digits = 0;
395+ while i < bytes.len() && bytes[i].is_ascii_digit() {
396+ i += 1;
397+ mantissa_digits += 1;
398+ }
399+ if i < bytes.len() && bytes[i] == b'.' {
400+ i += 1;
401+ while i < bytes.len() && bytes[i].is_ascii_digit() {
402+ i += 1;
403+ mantissa_digits += 1;
404+ }
405+ }
406+ if mantissa_digits == 0 {
407+ return None;
408+ }
409+ if i < bytes.len() && (bytes[i] == b'e' || bytes[i] == b'E') {
410+ i += 1;
411+ if i < bytes.len() && (bytes[i] == b'+' || bytes[i] == b'-') {
412+ i += 1;
413+ }
414+ let digits_start = i;
415+ while i < bytes.len() && bytes[i].is_ascii_digit() {
416+ i += 1;
417+ }
418+ if i == digits_start {
419+ return None;
420+ }
421+ }
422+ if i != bytes.len() {
423+ return None;
424+ }
425+ let normalized = if body.starts_with('.') {
426+ format!("0{body}")
427+ } else {
428+ body.to_string()
429+ };
430+ normalized.parse::<f64>().ok().map(|n| sign * n)
431+}
432+
433+// ---------------------------------------------------------------------------
434+// Parsing
435+
436+#[derive(Clone, Copy, Debug, PartialEq, Eq)]
437+enum Func {
438+ Contains,
439+ StartsWith,
440+ EndsWith,
441+ Format,
442+ Join,
443+ ToJson,
444+ FromJson,
445+ HashFiles,
446+ Success,
447+ Always,
448+ Cancelled,
449+ Failure,
450+}
451+
452+/// Name, function, fewest and most arguments.
453+const FUNCTIONS: &[(&str, Func, usize, usize)] = &[
454+ ("contains", Func::Contains, 2, 2),
455+ ("startsWith", Func::StartsWith, 2, 2),
456+ ("endsWith", Func::EndsWith, 2, 2),
457+ ("format", Func::Format, 1, usize::MAX),
458+ ("join", Func::Join, 1, 2),
459+ ("toJSON", Func::ToJson, 1, 1),
460+ ("fromJSON", Func::FromJson, 1, 1),
461+ ("hashFiles", Func::HashFiles, 1, usize::MAX),
462+ ("success", Func::Success, 0, 0),
463+ ("always", Func::Always, 0, 0),
464+ ("cancelled", Func::Cancelled, 0, 0),
465+ ("failure", Func::Failure, 0, 0),
466+];
467+
468+#[derive(Clone, Copy, Debug)]
469+enum CmpOp {
470+ Lt,
471+ Le,
472+ Gt,
473+ Ge,
474+ Eq,
475+ Ne,
476+}
477+
478+#[derive(Debug)]
479+enum Expr {
480+ Literal(Value),
481+ Named(String),
482+ Property(Box<Expr>, String),
483+ Index(Box<Expr>, Box<Expr>),
484+ Wildcard(Box<Expr>),
485+ Not(Box<Expr>),
486+ Compare(CmpOp, Box<Expr>, Box<Expr>),
487+ And(Box<Expr>, Box<Expr>),
488+ Or(Box<Expr>, Box<Expr>),
489+ Call(Func, Vec<Expr>),
490+}
491+
492+fn parse(src: &str, contexts: &Map<String, Value>) -> Result<Expr, String> {
493+ let toks = lex(src)?;
494+ if toks.is_empty() {
495+ return Err(format!("An expression was expected: '{src}'"));
496+ }
497+ let mut parser = Parser {
498+ toks,
499+ i: 0,
500+ src,
501+ contexts,
502+ };
503+ let expr = parser.or()?;
504+ if parser.i < parser.toks.len() {
505+ return Err(parser.unexpected());
506+ }
507+ Ok(expr)
508+}
509+
510+struct Parser<'s> {
511+ toks: Vec<Token>,
512+ i: usize,
513+ src: &'s str,
514+ contexts: &'s Map<String, Value>,
515+}
516+
517+impl Parser<'_> {
518+ fn peek(&self) -> Option<&Tok> {
519+ self.toks.get(self.i).map(|t| &t.tok)
520+ }
521+
522+ fn eat(&mut self, tok: &Tok) -> bool {
523+ if self.peek() == Some(tok) {
524+ self.i += 1;
525+ true
526+ } else {
527+ false
528+ }
529+ }
530+
531+ fn unexpected(&self) -> String {
532+ match self.toks.get(self.i) {
533+ Some(t) => located(&format!("Unexpected symbol: '{}'", t.text), t.pos, self.src),
534+ None => match self.toks.last() {
535+ Some(t) => located(
536+ &format!("Unexpected end of expression: '{}'", t.text),
537+ t.pos,
538+ self.src,
539+ ),
540+ None => format!("An expression was expected: '{}'", self.src),
541+ },
542+ }
543+ }
544+
545+ fn or(&mut self) -> Result<Expr, String> {
546+ let mut left = self.and()?;
547+ while self.eat(&Tok::Or) {
548+ let right = self.and()?;
549+ left = Expr::Or(Box::new(left), Box::new(right));
550+ }
551+ Ok(left)
552+ }
553+
554+ fn and(&mut self) -> Result<Expr, String> {
555+ let mut left = self.equality()?;
556+ while self.eat(&Tok::And) {
557+ let right = self.equality()?;
558+ left = Expr::And(Box::new(left), Box::new(right));
559+ }
560+ Ok(left)
561+ }
562+
563+ fn equality(&mut self) -> Result<Expr, String> {
564+ let mut left = self.comparison()?;
565+ loop {
566+ let op = match self.peek() {
567+ Some(Tok::Eq) => CmpOp::Eq,
568+ Some(Tok::Ne) => CmpOp::Ne,
569+ _ => return Ok(left),
570+ };
571+ self.i += 1;
572+ let right = self.comparison()?;
573+ left = Expr::Compare(op, Box::new(left), Box::new(right));
574+ }
575+ }
576+
577+ fn comparison(&mut self) -> Result<Expr, String> {
578+ let mut left = self.unary()?;
579+ loop {
580+ let op = match self.peek() {
581+ Some(Tok::Lt) => CmpOp::Lt,
582+ Some(Tok::Le) => CmpOp::Le,
583+ Some(Tok::Gt) => CmpOp::Gt,
584+ Some(Tok::Ge) => CmpOp::Ge,
585+ _ => return Ok(left),
586+ };
587+ self.i += 1;
588+ let right = self.unary()?;
589+ left = Expr::Compare(op, Box::new(left), Box::new(right));
590+ }
591+ }
592+
593+ fn unary(&mut self) -> Result<Expr, String> {
594+ if self.eat(&Tok::Not) {
595+ return Ok(Expr::Not(Box::new(self.unary()?)));
596+ }
597+ self.postfix()
598+ }
599+
600+ fn postfix(&mut self) -> Result<Expr, String> {
601+ let mut expr = self.primary()?;
602+ loop {
603+ if self.eat(&Tok::Dot) {
604+ let token = self.toks.get(self.i).cloned();
605+ expr = match token.map(|t| (t.tok, t.text)) {
606+ Some((Tok::Star, _)) => Expr::Wildcard(Box::new(expr)),
607+ Some((Tok::Ident(name), _)) => Expr::Property(Box::new(expr), name),
608+ Some((Tok::True | Tok::False | Tok::Null, text)) => {
609+ Expr::Property(Box::new(expr), text)
610+ }
611+ _ => return Err(self.unexpected()),
612+ };
613+ self.i += 1;
614+ } else if self.eat(&Tok::LBracket) {
615+ if self.peek() == Some(&Tok::Star)
616+ && self.toks.get(self.i + 1).map(|t| &t.tok) == Some(&Tok::RBracket)
617+ {
618+ self.i += 2;
619+ expr = Expr::Wildcard(Box::new(expr));
620+ } else {
621+ let index = self.or()?;
622+ if !self.eat(&Tok::RBracket) {
623+ return Err(self.unexpected());
624+ }
625+ expr = Expr::Index(Box::new(expr), Box::new(index));
626+ }
627+ } else {
628+ return Ok(expr);
629+ }
630+ }
631+ }
632+
633+ fn primary(&mut self) -> Result<Expr, String> {
634+ let Some(token) = self.toks.get(self.i).cloned() else {
635+ return Err(self.unexpected());
636+ };
637+ self.i += 1;
638+ match token.tok {
639+ Tok::Null => Ok(Expr::Literal(Value::Null)),
640+ Tok::True => Ok(Expr::Literal(Value::Bool(true))),
641+ Tok::False => Ok(Expr::Literal(Value::Bool(false))),
642+ Tok::Number(n) => Ok(Expr::Literal(number(n))),
643+ Tok::Str(s) => Ok(Expr::Literal(Value::String(s))),
644+ Tok::LParen => {
645+ let inner = self.or()?;
646+ if !self.eat(&Tok::RParen) {
647+ return Err(self.unexpected());
648+ }
649+ Ok(inner)
650+ }
651+ Tok::Ident(name) if self.peek() == Some(&Tok::LParen) => {
652+ self.i += 1;
653+ self.call(&name, token.pos)
654+ }
655+ Tok::Ident(name) => {
656+ let known = NAMED_VALUES.iter().any(|n| n.eq_ignore_ascii_case(&name))
657+ || self.contexts.keys().any(|k| k.eq_ignore_ascii_case(&name));
658+ if !known {
659+ return Err(located(
660+ &format!("Unrecognized named-value: '{name}'"),
661+ token.pos,
662+ self.src,
663+ ));
664+ }
665+ Ok(Expr::Named(name))
666+ }
667+ _ => {
668+ self.i -= 1;
669+ Err(self.unexpected())
670+ }
671+ }
672+ }
673+
674+ fn call(&mut self, name: &str, pos: usize) -> Result<Expr, String> {
675+ let Some(&(canonical, func, min, max)) = FUNCTIONS
676+ .iter()
677+ .find(|(n, ..)| n.eq_ignore_ascii_case(name))
678+ else {
679+ return Err(located(
680+ &format!("Unrecognized function: '{name}'"),
681+ pos,
682+ self.src,
683+ ));
684+ };
685+ let mut args = Vec::new();
686+ if !self.eat(&Tok::RParen) {
687+ loop {
688+ args.push(self.or()?);
689+ if self.eat(&Tok::Comma) {
690+ continue;
691+ }
692+ if self.eat(&Tok::RParen) {
693+ break;
694+ }
695+ return Err(self.unexpected());
696+ }
697+ }
698+ if args.len() < min {
699+ return Err(located(
700+ &format!("Too few parameters supplied: '{canonical}'"),
701+ pos,
702+ self.src,
703+ ));
704+ }
705+ if args.len() > max {
706+ return Err(located(
707+ &format!("Too many parameters supplied: '{canonical}'"),
708+ pos,
709+ self.src,
710+ ));
711+ }
712+ Ok(Expr::Call(func, args))
713+ }
714+}
715+
716+/// Whether the expression calls success(), failure(), cancelled() or always().
717+fn uses_status(expr: &Expr) -> bool {
718+ match expr {
719+ Expr::Literal(_) | Expr::Named(_) => false,
720+ Expr::Property(base, _) | Expr::Wildcard(base) | Expr::Not(base) => uses_status(base),
721+ Expr::Index(a, b) | Expr::Compare(_, a, b) | Expr::And(a, b) | Expr::Or(a, b) => {
722+ uses_status(a) || uses_status(b)
723+ }
724+ Expr::Call(func, args) => {
725+ matches!(
726+ func,
727+ Func::Success | Func::Failure | Func::Cancelled | Func::Always
728+ ) || args.iter().any(uses_status)
729+ }
730+ }
731+}
732+
733+// ---------------------------------------------------------------------------
734+// Evaluation
735+
736+/// A value while evaluating: borrowed from the contexts where possible, and
737+/// a filtered array (the result of a `*`) kept apart, since property access on
738+/// it applies to every item.
739+enum Ev<'c> {
740+ One(Cow<'c, Value>),
741+ Filtered(Vec<Cow<'c, Value>>),
742+}
743+
744+impl Ev<'_> {
745+ fn into_value(self) -> Value {
746+ match self {
747+ Ev::One(v) => v.into_owned(),
748+ Ev::Filtered(items) => Value::Array(items.into_iter().map(Cow::into_owned).collect()),
749+ }
750+ }
751+
752+ fn truthy(&self) -> bool {
753+ match self {
754+ Ev::One(v) => truthy(v),
755+ Ev::Filtered(_) => true,
756+ }
757+ }
758+}
759+
760+fn owned<'c>(value: Value) -> Ev<'c> {
761+ Ev::One(Cow::Owned(value))
762+}
763+
764+/// A key on an object: the exact key if present, otherwise ignoring ASCII case.
765+fn find_key<'m>(map: &'m Map<String, Value>, key: &str) -> Option<&'m String> {
766+ if let Some((k, _)) = map.get_key_value(key) {
767+ return Some(k);
768+ }
769+ map.keys().find(|k| k.eq_ignore_ascii_case(key))
770+}
771+
772+enum Key {
773+ Name(String),
774+ Index(usize),
775+}
776+
777+fn child<'c>(value: Cow<'c, Value>, key: &Key) -> Option<Cow<'c, Value>> {
778+ match (value, key) {
779+ (Cow::Borrowed(Value::Object(map)), Key::Name(name)) => find_key(map, name)
780+ .and_then(|k| map.get(k))
781+ .map(Cow::Borrowed),
782+ (Cow::Owned(Value::Object(mut map)), Key::Name(name)) => {
783+ let k = find_key(&map, name)?.clone();
784+ map.remove(&k).map(Cow::Owned)
785+ }
786+ (Cow::Borrowed(Value::Array(items)), Key::Index(i)) => items.get(*i).map(Cow::Borrowed),
787+ (Cow::Owned(Value::Array(items)), Key::Index(i)) => {
788+ items.into_iter().nth(*i).map(Cow::Owned)
789+ }
790+ _ => None,
791+ }
792+}
793+
794+fn children(value: Cow<'_, Value>) -> Vec<Cow<'_, Value>> {
795+ match value {
796+ Cow::Borrowed(Value::Array(items)) => items.iter().map(Cow::Borrowed).collect(),
797+ Cow::Borrowed(Value::Object(map)) => map.values().map(Cow::Borrowed).collect(),
798+ Cow::Owned(Value::Array(items)) => items.into_iter().map(Cow::Owned).collect(),
799+ Cow::Owned(Value::Object(map)) => map.into_iter().map(|(_, v)| Cow::Owned(v)).collect(),
800+ _ => Vec::new(),
801+ }
802+}
803+
804+/// The key `index` selects on `target`: a position on an array, a name on an object.
805+fn key_for(target: &Value, index: &Value) -> Option<Key> {
806+ match target {
807+ Value::Array(_) => {
808+ let n = to_number(index);
809+ (n.is_finite() && n >= 0.0).then(|| Key::Index(n.trunc() as usize))
810+ }
811+ Value::Object(_) => Some(Key::Name(to_text(index))),
812+ _ => None,
813+ }
814+}
815+
816+fn eval<'c>(expr: &Expr, scope: &Scope<'c>) -> Result<Ev<'c>, String> {
817+ Ok(match expr {
818+ Expr::Literal(v) => owned(v.clone()),
819+ Expr::Named(name) => {
820+ let contexts: &'c Map<String, Value> = scope.contexts;
821+ match find_key(contexts, name).and_then(|k| contexts.get(k)) {
822+ Some(v) => Ev::One(Cow::Borrowed(v)),
823+ None => owned(Value::Null),
824+ }
825+ }
826+ Expr::Property(base, name) => {
827+ let key = Key::Name(name.clone());
828+ match eval(base, scope)? {
829+ Ev::One(v) => Ev::One(child(v, &key).unwrap_or(Cow::Owned(Value::Null))),
830+ Ev::Filtered(items) => {
831+ Ev::Filtered(items.into_iter().filter_map(|it| child(it, &key)).collect())
832+ }
833+ }
834+ }
835+ Expr::Index(base, index) => {
836+ let base = eval(base, scope)?;
837+ let index = eval(index, scope)?.into_value();
838+ match base {
839+ Ev::One(v) => {
840+ let found = key_for(&v, &index).and_then(|key| child(v, &key));
841+ Ev::One(found.unwrap_or(Cow::Owned(Value::Null)))
842+ }
843+ Ev::Filtered(items) => Ev::Filtered(
844+ items
845+ .into_iter()
846+ .filter_map(|it| key_for(&it, &index).and_then(|key| child(it, &key)))
847+ .collect(),
848+ ),
849+ }
850+ }
851+ Expr::Wildcard(base) => match eval(base, scope)? {
852+ Ev::One(v) => Ev::Filtered(children(v)),
853+ Ev::Filtered(items) => Ev::Filtered(items.into_iter().flat_map(children).collect()),
854+ },
855+ Expr::Not(inner) => owned(Value::Bool(!eval(inner, scope)?.truthy())),
856+ Expr::And(a, b) => {
857+ let left = eval(a, scope)?;
858+ if !left.truthy() {
859+ return Ok(left);
860+ }
861+ eval(b, scope)?
862+ }
863+ Expr::Or(a, b) => {
864+ let left = eval(a, scope)?;
865+ if left.truthy() {
866+ return Ok(left);
867+ }
868+ eval(b, scope)?
869+ }
870+ Expr::Compare(op, a, b) => {
871+ let left = eval(a, scope)?.into_value();
872+ let right = eval(b, scope)?.into_value();
873+ let result = match op {
874+ CmpOp::Eq => loose_eq(&left, &right),
875+ CmpOp::Ne => !loose_eq(&left, &right),
876+ CmpOp::Lt => compare(&left, &right) == Some(Ordering::Less),
877+ CmpOp::Le => matches!(
878+ compare(&left, &right),
879+ Some(Ordering::Less | Ordering::Equal)
880+ ),
881+ CmpOp::Gt => compare(&left, &right) == Some(Ordering::Greater),
882+ CmpOp::Ge => {
883+ matches!(
884+ compare(&left, &right),
885+ Some(Ordering::Greater | Ordering::Equal)
886+ )
887+ }
888+ };
889+ owned(Value::Bool(result))
890+ }
891+ Expr::Call(func, args) => owned(call(*func, args, scope)?),
892+ })
893+}
894+
895+fn call(func: Func, args: &[Expr], scope: &Scope) -> Result<Value, String> {
896+ let status = scope.status;
897+ match func {
898+ Func::Success => return Ok(Value::Bool(status == Status::Success)),
899+ Func::Failure => return Ok(Value::Bool(status == Status::Failure)),
900+ Func::Cancelled => return Ok(Value::Bool(status == Status::Cancelled)),
901+ Func::Always => return Ok(Value::Bool(true)),
902+ _ => {}
903+ }
904+ let values: Vec<Value> = args
905+ .iter()
906+ .map(|a| eval(a, scope).map(Ev::into_value))
907+ .collect::<Result<_, _>>()?;
908+ Ok(match func {
909+ Func::Contains => Value::Bool(match &values[0] {
910+ Value::Array(items) => items.iter().any(|item| loose_eq(item, &values[1])),
911+ search => upper(&to_text(search)).contains(&upper(&to_text(&values[1]))),
912+ }),
913+ Func::StartsWith => {
914+ Value::Bool(upper(&to_text(&values[0])).starts_with(&upper(&to_text(&values[1]))))
915+ }
916+ Func::EndsWith => {
917+ Value::Bool(upper(&to_text(&values[0])).ends_with(&upper(&to_text(&values[1]))))
918+ }
919+ Func::Format => Value::String(format_string(&values)?),
920+ Func::Join => {
921+ let separator = values.get(1).map_or_else(|| ",".to_string(), to_text);
922+ Value::String(match &values[0] {
923+ Value::Array(items) => items
924+ .iter()
925+ .map(to_text)
926+ .collect::<Vec<_>>()
927+ .join(&separator),
928+ other => to_text(other),
929+ })
930+ }
931+ Func::ToJson => Value::String(to_json(&values[0])),
932+ Func::FromJson => {
933+ let text = to_text(&values[0]);
934+ let parsed: Value = serde_json::from_str(&text)
935+ .map_err(|e| format!("Error from function 'fromJSON': {e}. Input: '{text}'"))?;
936+ normalize(parsed)
937+ }
938+ Func::HashFiles => {
939+ let patterns: Vec<String> = values.iter().map(to_text).collect();
940+ Value::String(scope.hash_files.map(|f| f(&patterns)).unwrap_or_default())
941+ }
942+ Func::Success | Func::Failure | Func::Cancelled | Func::Always => unreachable!(),
943+ })
944+}
945+
946+/// format('{0} {1}', ...): `{N}` is the Nth argument after the format string,
947+/// `{{` and `}}` are literal braces, anything else with a brace is an error.
948+fn format_string(values: &[Value]) -> Result<String, String> {
949+ let template = to_text(&values[0]);
950+ let args: Vec<String> = values[1..].iter().map(to_text).collect();
951+ let invalid = || format!("The following format string is invalid: '{template}'");
952+ let chars: Vec<char> = template.chars().collect();
953+ let mut out = String::new();
954+ let mut i = 0;
955+ while i < chars.len() {
956+ match chars[i] {
957+ '{' if chars.get(i + 1) == Some(&'{') => {
958+ out.push('{');
959+ i += 2;
960+ }
961+ '}' if chars.get(i + 1) == Some(&'}') => {
962+ out.push('}');
963+ i += 2;
964+ }
965+ '{' => {
966+ let start = i + 1;
967+ let mut end = start;
968+ while end < chars.len() && chars[end].is_ascii_digit() {
969+ end += 1;
970+ }
971+ if end == start || chars.get(end) != Some(&'}') {
972+ return Err(invalid());
973+ }
974+ let digits: String = chars[start..end].iter().collect();
975+ let index: usize = digits.parse().map_err(|_| invalid())?;
976+ let arg = args.get(index).ok_or_else(|| {
977+ format!(
978+ "The following format string references more arguments than were supplied: '{template}'"
979+ )
980+ })?;
981+ out.push_str(arg);
982+ i = end + 1;
983+ }
984+ '}' => return Err(invalid()),
985+ c => {
986+ out.push(c);
987+ i += 1;
988+ }
989+ }
990+ }
991+ Ok(out)
992+}
993+
994+fn upper(s: &str) -> String {
995+ s.to_uppercase()
996+}
997+
998+/// A value coerced to a number, as GitHub does when operand types differ.
999+fn to_number(value: &Value) -> f64 {
1000+ match value {
1001+ Value::Null => 0.0,
1002+ Value::Bool(b) => f64::from(u8::from(*b)),
1003+ Value::Number(n) => n.as_f64().unwrap_or(f64::NAN),
1004+ Value::String(s) => parse_number(s, true).unwrap_or(f64::NAN),
1005+ Value::Array(_) | Value::Object(_) => f64::NAN,
1006+ }
1007+}
1008+
1009+/// GitHub's `==`: same types compare directly (strings ignoring case; arrays
1010+/// and objects are never equal, since they cannot be the same instance here);
1011+/// different types are both coerced to numbers, and NaN equals nothing.
1012+fn loose_eq(a: &Value, b: &Value) -> bool {
1013+ match (a, b) {
1014+ (Value::Null, Value::Null) => true,
1015+ (Value::Bool(x), Value::Bool(y)) => x == y,
1016+ (Value::Number(_), Value::Number(_)) => to_number(a) == to_number(b),
1017+ (Value::String(x), Value::String(y)) => upper(x) == upper(y),
1018+ (Value::Array(_), Value::Array(_)) | (Value::Object(_), Value::Object(_)) => false,
1019+ _ => to_number(a) == to_number(b),
1020+ }
1021+}
1022+
1023+/// GitHub's ordering for `<`, `<=`, `>`, `>=`; None when they do not compare.
1024+fn compare(a: &Value, b: &Value) -> Option<Ordering> {
1025+ match (a, b) {
1026+ (Value::Null, Value::Null) => Some(Ordering::Equal),
1027+ (Value::String(x), Value::String(y)) => Some(upper(x).cmp(&upper(y))),
1028+ (Value::Array(_) | Value::Object(_), _) | (_, Value::Array(_) | Value::Object(_)) => None,
1029+ _ => to_number(a).partial_cmp(&to_number(b)),
1030+ }
1031+}
1032+
1033+/// A number as a JSON value, integral numbers as integers so they print and
1034+/// serialize without a trailing ".0".
1035+fn number(n: f64) -> Value {
1036+ if n.fract() == 0.0 && n.abs() < 9_007_199_254_740_992.0 {
1037+ Value::from(n as i64)
1038+ } else {
1039+ serde_json::Number::from_f64(n).map_or(Value::Null, Value::Number)
1040+ }
1041+}
1042+
1043+/// Integral floats as integers, all the way down.
1044+fn normalize(value: Value) -> Value {
1045+ match value {
1046+ Value::Number(n) if n.is_f64() => number(n.as_f64().unwrap_or(f64::NAN)),
1047+ Value::Array(items) => Value::Array(items.into_iter().map(normalize).collect()),
1048+ Value::Object(map) => {
1049+ Value::Object(map.into_iter().map(|(k, v)| (k, normalize(v))).collect())
1050+ }
1051+ other => other,
1052+ }
1053+}
1054+
1055+fn to_json(value: &Value) -> String {
1056+ serde_json::to_string_pretty(&normalize(value.clone())).unwrap_or_default()
1057+}
1058+
1059+/// A number the way GitHub (.NET's "G15") writes it: up to 15 significant
1060+/// digits, no trailing zeros, and scientific notation (`1E+15`, `1E-07`) for
1061+/// very large or very small magnitudes.
1062+fn format_number(n: f64) -> String {
1063+ if n.is_nan() {
1064+ return "NaN".to_string();
1065+ }
1066+ if n.is_infinite() {
1067+ return if n > 0.0 { "Infinity" } else { "-Infinity" }.to_string();
1068+ }
1069+ if n == 0.0 {
1070+ return "0".to_string();
1071+ }
1072+ let scientific = format!("{:.14e}", n.abs());
1073+ let (mantissa, exponent) = scientific.split_once('e').unwrap_or((&scientific, "0"));
1074+ let exponent: i32 = exponent.parse().unwrap_or(0);
1075+ let mut digits: String = mantissa.chars().filter(char::is_ascii_digit).collect();
1076+ while digits.len() > 1 && digits.ends_with('0') {
1077+ digits.pop();
1078+ }
1079+ let mut out = String::new();
1080+ if n < 0.0 {
1081+ out.push('-');
1082+ }
1083+ if !(-5..15).contains(&exponent) {
1084+ out.push_str(&digits[..1]);
1085+ if digits.len() > 1 {
1086+ out.push('.');
1087+ out.push_str(&digits[1..]);
1088+ }
1089+ out.push('E');
1090+ out.push(if exponent < 0 { '-' } else { '+' });
1091+ out.push_str(&format!("{:02}", exponent.abs()));
1092+ } else if exponent >= 0 {
1093+ let whole = exponent as usize + 1;
1094+ if digits.len() > whole {
1095+ out.push_str(&digits[..whole]);
1096+ out.push('.');
1097+ out.push_str(&digits[whole..]);
1098+ } else {
1099+ out.push_str(&digits);
1100+ out.push_str(&"0".repeat(whole - digits.len()));
1101+ }
1102+ } else {
1103+ out.push_str("0.");
1104+ out.push_str(&"0".repeat((-exponent - 1) as usize));
1105+ out.push_str(&digits);
1106+ }
1107+ out
1108+}
1109+
1110+// ---------------------------------------------------------------------------
1111+
1112+#[cfg(test)]
1113+mod tests {
1114+ use super::*;
1115+ use serde_json::json;
1116+
1117+ fn contexts() -> Map<String, Value> {
1118+ let value = json!({
1119+ "github": {
1120+ "ref": "refs/heads/main",
1121+ "ref_name": "main",
1122+ "event_name": "push",
1123+ "repository": "syntaqx/g1t",
1124+ "actor": "dependabot[bot]",
1125+ "event": {
1126+ "pull_request": {
1127+ "number": 42,
1128+ "draft": false,
1129+ "title": "Fix the thing",
1130+ "head": { "ref": "feature/x" },
1131+ "labels": [{ "name": "bug" }, { "name": "Enhancement" }]
1132+ },
1133+ "issues": [
1134+ { "labels": [{ "name": "a" }, { "name": "b" }] },
1135+ { "labels": [{ "name": "c" }] }
1136+ ],
1137+ "head_commit": { "message": "fix: x [skip ci]" }
1138+ }
1139+ },
1140+ "env": { "NODE_VERSION": "18", "EMPTY": "" },
1141+ "vars": { "DEPLOY": "yes" },
1142+ "secrets": { "TOKEN": "s3cret" },
1143+ "inputs": { "debug": "true", "flag": true, "count": 3, "environment": "staging" },
1144+ "matrix": { "os": "ubuntu-latest", "node": 18, "experimental": false },
1145+ "strategy": { "fail-fast": true, "job-index": 0 },
1146+ "steps": {
1147+ "build": { "outputs": { "version": "1.2.3" }, "outcome": "success", "conclusion": "success" },
1148+ "test": { "outputs": {}, "outcome": "failure", "conclusion": "success" },
1149+ "my-step": { "outputs": { "cache-hit": "true" } }
1150+ },
1151+ "needs": {
1152+ "setup": {
1153+ "result": "success",
1154+ "outputs": { "matrix": "{\"os\":[\"ubuntu-latest\",\"windows-latest\"],\"node\":[18,20]}" }
1155+ }
1156+ },
1157+ "runner": { "os": "Linux", "arch": "X64" },
1158+ "job": { "status": "success" }
1159+ });
1160+ match value {
1161+ Value::Object(map) => map,
1162+ _ => unreachable!(),
1163+ }
1164+ }
1165+
1166+ fn with<T>(status: Status, f: impl FnOnce(&Scope) -> T) -> T {
1167+ let contexts = contexts();
1168+ let hash = |patterns: &[String]| format!("hash({})", patterns.join("|"));
1169+ let scope = Scope {
1170+ contexts: &contexts,
1171+ status,
1172+ hash_files: Some(&hash),
1173+ };
1174+ f(&scope)
1175+ }
1176+
1177+ fn ev(expression: &str) -> Value {
1178+ with(Status::Success, |s| evaluate(expression, s))
1179+ .unwrap_or_else(|e| panic!("{expression}: {e}"))
1180+ }
1181+
1182+ fn err(expression: &str) -> String {
1183+ with(Status::Success, |s| evaluate(expression, s)).unwrap_err()
1184+ }
1185+
1186+ fn cond(status: Status, text: &str) -> bool {
1187+ with(status, |s| condition(text, s)).unwrap_or_else(|e| panic!("{text}: {e}"))
1188+ }
1189+
1190+ #[test]
1191+ fn literals() {
1192+ assert_eq!(ev("null"), Value::Null);
1193+ assert_eq!(ev("true"), json!(true));
1194+ assert_eq!(ev("false"), json!(false));
1195+ assert_eq!(ev("711"), json!(711));
1196+ assert_eq!(ev("-9.2"), json!(-9.2));
1197+ assert_eq!(ev("0xff"), json!(255));
1198+ assert_eq!(ev("-2.99e-2"), json!(-0.0299));
1199+ assert_eq!(ev("1e3"), json!(1000));
1200+ assert_eq!(ev("'Mona the Octocat'"), json!("Mona the Octocat"));
1201+ assert_eq!(ev("'It''s open source!'"), json!("It's open source!"));
1202+ }
1203+
1204+ #[test]
1205+ fn double_quotes_are_an_error() {
1206+ let e = err("github.ref == \"main\"");
1207+ assert!(
1208+ e.starts_with("Unexpected symbol: '\"'. Located at position 15 within expression:"),
1209+ "{e}"
1210+ );
1211+ }
1212+
1213+ #[test]
1214+ fn ref_is_main() {
1215+ assert_eq!(ev("github.ref == 'refs/heads/main'"), json!(true));
1216+ assert_eq!(ev("github.ref != 'refs/heads/main'"), json!(false));
1217+ }
1218+
1219+ #[test]
1220+ fn starts_with_tag() {
1221+ assert_eq!(ev("startsWith(github.ref, 'refs/tags/v')"), json!(false));
1222+ assert_eq!(ev("startsWith(github.ref, 'REFS/heads/')"), json!(true));
1223+ assert_eq!(ev("endsWith(github.repository, '/G1T')"), json!(true));
1224+ }
1225+
1226+ #[test]
1227+ fn contains_labels_filter() {
1228+ assert_eq!(
1229+ ev("contains(github.event.pull_request.labels.*.name, 'bug')"),
1230+ json!(true)
1231+ );
1232+ assert_eq!(
1233+ ev("contains(github.event.pull_request.labels.*.name, 'enhancement')"),
1234+ json!(true)
1235+ );
1236+ assert_eq!(
1237+ ev("contains(github.event.pull_request.labels.*.name, 'docs')"),
1238+ json!(false)
1239+ );
1240+ }
1241+
1242+ #[test]
1243+ fn nested_object_filters_flatten() {
1244+ assert_eq!(
1245+ ev("github.event.issues.*.labels.*.name"),
1246+ json!(["a", "b", "c"])
1247+ );
1248+ assert_eq!(
1249+ ev("github.event.pull_request.labels[*].name"),
1250+ json!(["bug", "Enhancement"])
1251+ );
1252+ assert_eq!(
1253+ ev("github.event.pull_request.*"),
1254+ ev("github.event.pull_request.*")
1255+ );
1256+ assert_eq!(ev("matrix.nothing.*"), json!([]));
1257+ }
1258+
1259+ #[test]
1260+ fn matrix_and() {
1261+ assert_eq!(
1262+ ev("matrix.os == 'ubuntu-latest' && matrix.node >= 18"),
1263+ json!(true)
1264+ );
1265+ assert_eq!(
1266+ ev("matrix.os == 'windows-latest' && matrix.node >= 18"),
1267+ json!(false)
1268+ );
1269+ }
1270+
1271+ #[test]
1272+ fn step_outputs() {
1273+ assert_eq!(ev("steps.build.outputs.version"), json!("1.2.3"));
1274+ assert_eq!(
1275+ ev("steps.my-step.outputs.cache-hit != 'true'"),
1276+ json!(false)
1277+ );
1278+ assert_eq!(ev("steps.missing.outputs.version"), Value::Null);
1279+ }
1280+
1281+ #[test]
1282+ fn format_with_hash_files() {
1283+ assert_eq!(
1284+ ev("format('{0}-{1}', runner.os, hashFiles('**/package-lock.json'))"),
1285+ json!("Linux-hash(**/package-lock.json)")
1286+ );
1287+ assert_eq!(ev("hashFiles('a', 'b')"), json!("hash(a|b)"));
1288+ }
1289+
1290+ #[test]
1291+ fn hash_files_without_sandbox_is_empty() {
1292+ let contexts = contexts();
1293+ let scope = Scope {
1294+ contexts: &contexts,
1295+ status: Status::Success,
1296+ hash_files: None,
1297+ };
1298+ assert_eq!(
1299+ evaluate("hashFiles('**/*.lock')", &scope).unwrap(),
1300+ json!("")
1301+ );
1302+ }
1303+
1304+ #[test]
1305+ fn format_escapes_and_errors() {
1306+ assert_eq!(
1307+ ev("format('{{Hello {0} {1} {2}!}}', 'Mona', 'the', 'Octocat')"),
1308+ json!("{Hello Mona the Octocat!}")
1309+ );
1310+ assert_eq!(ev("format('{0}{0}', 1)"), json!("11"));
1311+ assert!(err("format('{1}', 'a')").contains("more arguments than were supplied"));
1312+ assert!(err("format('{0', 'a')").contains("invalid"));
1313+ }
1314+
1315+ #[test]
1316+ fn from_json_matrix() {
1317+ assert_eq!(
1318+ ev("fromJSON(needs.setup.outputs.matrix)"),
1319+ json!({ "os": ["ubuntu-latest", "windows-latest"], "node": [18, 20] })
1320+ );
1321+ assert_eq!(
1322+ ev("fromJSON(needs.setup.outputs.matrix).node[1]"),
1323+ json!(20)
1324+ );
1325+ assert_eq!(ev("fromJSON('true')"), json!(true));
1326+ assert_eq!(ev("fromJSON('3.0')"), json!(3));
1327+ assert!(err("fromJSON('{nope')").contains("fromJSON"));
1328+ }
1329+
1330+ #[test]
1331+ fn event_name_or() {
1332+ assert_eq!(
1333+ ev("github.event_name == 'push' || github.event_name == 'workflow_dispatch'"),
1334+ json!(true)
1335+ );
1336+ }
1337+
1338+ #[test]
1339+ fn and_or_return_operands() {
1340+ assert_eq!(ev("matrix.os && 'yes'"), json!("yes"));
1341+ assert_eq!(ev("env.EMPTY && 'yes'"), json!(""));
1342+ assert_eq!(ev("env.EMPTY || 'fallback'"), json!("fallback"));
1343+ assert_eq!(ev("inputs.environment || 'production'"), json!("staging"));
1344+ assert_eq!(ev("github.event.pull_request.draft || null"), Value::Null);
1345+ }
1346+
1347+ #[test]
1348+ fn short_circuit_skips_errors() {
1349+ assert_eq!(ev("false && fromJSON('{bad')"), json!(false));
1350+ assert_eq!(ev("true || fromJSON('{bad')"), json!(true));
1351+ }
1352+
1353+ #[test]
1354+ fn not_cancelled() {
1355+ assert!(cond(Status::Success, "!cancelled()"));
1356+ assert!(cond(Status::Failure, "!cancelled()"));
1357+ assert!(!cond(Status::Cancelled, "!cancelled()"));
1358+ }
1359+
1360+ #[test]
1361+ fn failure_and_outcome() {
1362+ assert!(cond(
1363+ Status::Failure,
1364+ "failure() && steps.test.outcome == 'failure'"
1365+ ));
1366+ assert!(!cond(
1367+ Status::Success,
1368+ "failure() && steps.test.outcome == 'failure'"
1369+ ));
1370+ assert!(!cond(
1371+ Status::Failure,
1372+ "failure() && steps.build.outcome == 'failure'"
1373+ ));
1374+ }
1375+
1376+ #[test]
1377+ fn string_input_is_not_true() {
1378+ // The famous gotcha: 'true' coerces to NaN when compared with a bool.
1379+ assert_eq!(ev("inputs.debug == true"), json!(false));
1380+ assert_eq!(ev("inputs.debug == 'true'"), json!(true));
1381+ assert_eq!(ev("inputs.flag == true"), json!(true));
1382+ }
1383+
1384+ #[test]
1385+ fn coercions() {
1386+ assert_eq!(ev("'' == 0"), json!(true));
1387+ assert_eq!(ev("null == false"), json!(true));
1388+ assert_eq!(ev("null == 0"), json!(true));
1389+ assert_eq!(ev("1 == '1'"), json!(true));
1390+ assert_eq!(ev("'1.0' == 1"), json!(true));
1391+ assert_eq!(ev("' 2 ' == 2"), json!(true));
1392+ assert_eq!(ev("'0x10' == 16"), json!(true));
1393+ assert_eq!(ev("true == 1"), json!(true));
1394+ assert_eq!(ev("'abc' == 0"), json!(false));
1395+ assert_eq!(ev("'abc' != 0"), json!(true));
1396+ assert_eq!(ev("null == ''"), json!(true));
1397+ }
1398+
1399+ #[test]
1400+ fn hex_and_exponent() {
1401+ assert_eq!(ev("0x10 == 16"), json!(true));
1402+ assert_eq!(ev("1e3 == 1000"), json!(true));
1403+ assert_eq!(ev("-0x10 < 0"), json!(true));
1404+ }
1405+
1406+ #[test]
1407+ fn case_insensitive_strings() {
1408+ assert_eq!(ev("'ABC' == 'abc'"), json!(true));
1409+ assert_eq!(ev("contains('Hello World', 'WORLD')"), json!(true));
1410+ assert_eq!(ev("'a' < 'B'"), json!(true));
1411+ }
1412+
1413+ #[test]
1414+ fn case_insensitive_names() {
1415+ assert_eq!(ev("GitHub.Event_Name"), json!("push"));
1416+ assert_eq!(ev("ENV.node_version"), json!("18"));
1417+ assert_eq!(ev("StartsWith(github.ref, 'refs/')"), json!(true));
1418+ assert_eq!(ev("TOJSON(1)"), json!("1"));
1419+ }
1420+
1421+ #[test]
1422+ fn objects_and_arrays_are_never_equal() {
1423+ assert_eq!(ev("github.event == github.event"), json!(false));
1424+ assert_eq!(ev("fromJSON('[]') == fromJSON('[]')"), json!(false));
1425+ assert_eq!(ev("fromJSON('[]') == 0"), json!(false));
1426+ assert_eq!(ev("fromJSON('{}') < 1"), json!(false));
1427+ }
1428+
1429+ #[test]
1430+ fn nan_compares_false() {
1431+ assert_eq!(ev("'abc' < 1"), json!(false));
1432+ assert_eq!(ev("'abc' >= 1"), json!(false));
1433+ assert_eq!(ev("'abc' == 'abc'"), json!(true));
1434+ }
1435+
1436+ #[test]
1437+ fn comparisons() {
1438+ assert_eq!(ev("matrix.node > 16"), json!(true));
1439+ assert_eq!(ev("matrix.node <= '18'"), json!(true));
1440+ assert_eq!(ev("inputs.count < 3"), json!(false));
1441+ assert_eq!(ev("null <= null"), json!(true));
1442+ assert_eq!(ev("false < true"), json!(true));
1443+ }
1444+
1445+ #[test]
1446+ fn precedence() {
1447+ // ! binds tighter than ==, == tighter than &&, && tighter than ||.
1448+ assert_eq!(ev("!matrix.experimental == true"), json!(true));
1449+ assert_eq!(ev("true || false && false"), json!(true));
1450+ assert_eq!(ev("(true || false) && false"), json!(false));
1451+ assert_eq!(ev("1 < 2 == true"), json!(true));
1452+ assert_eq!(ev("!!'x'"), json!(true));
1453+ }
1454+
1455+ #[test]
1456+ fn indexing() {
1457+ assert_eq!(ev("github['event']['pull_request']['number']"), json!(42));
1458+ assert_eq!(ev("github.event.pull_request.labels[0].name"), json!("bug"));
1459+ assert_eq!(ev("github.event.pull_request.labels[5]"), Value::Null);
1460+ assert_eq!(ev("matrix['os']"), json!("ubuntu-latest"));
1461+ assert_eq!(ev("strategy.fail-fast"), json!(true));
1462+ assert_eq!(ev("strategy['job-index']"), json!(0));
1463+ }
1464+
1465+ #[test]
1466+ fn missing_properties_are_null() {
1467+ assert_eq!(ev("github.event.release.tag_name"), Value::Null);
1468+ assert_eq!(ev("github.ref.nope"), Value::Null);
1469+ assert_eq!(ev("jobs.anything"), Value::Null);
1470+ }
1471+
1472+ #[test]
1473+ fn unrecognized_named_value() {
1474+ let e = err("foo.bar == 1");
1475+ assert_eq!(
1476+ e,
1477+ "Unrecognized named-value: 'foo'. Located at position 1 within expression: foo.bar == 1"
1478+ );
1479+ // Found at parse time, even in a branch that never runs.
1480+ assert!(err("false && bogus").contains("Unrecognized named-value: 'bogus'"));
1481+ }
1482+
1483+ #[test]
1484+ fn function_errors() {
1485+ assert!(err("nope(1)").starts_with("Unrecognized function: 'nope'"));
1486+ assert!(err("contains('a')").starts_with("Too few parameters supplied: 'contains'"));
1487+ assert!(err("success(1)").starts_with("Too many parameters supplied: 'success'"));
1488+ assert!(err("toJSON()").starts_with("Too few parameters supplied: 'toJSON'"));
1489+ }
1490+
1491+ #[test]
1492+ fn syntax_errors() {
1493+ assert!(err("github.ref ==").starts_with("Unexpected end of expression: '=='"));
1494+ assert!(err("(true").starts_with("Unexpected end of expression"));
1495+ assert!(err("true false").starts_with("Unexpected symbol: 'false'. Located at position 6"));
1496+ assert!(err("'open").starts_with("Unexpected symbol: ''open'"));
1497+ assert!(err("a = b").contains("Unexpected symbol"));
1498+ assert!(err("github.").starts_with("Unexpected end of expression"));
1499+ assert!(err("").contains("expression was expected"));
1500+ }
1501+
1502+ #[test]
1503+ fn contains_array_uses_loose_equality() {
1504+ assert_eq!(ev("contains(fromJSON('[1, 2, 3]'), '2')"), json!(true));
1505+ assert_eq!(
1506+ ev("contains(fromJSON('[\"push\", \"pull_request\"]'), github.event_name)"),
1507+ json!(true)
1508+ );
1509+ assert_eq!(
1510+ ev("contains(github.event.head_commit.message, '[skip ci]')"),
1511+ json!(true)
1512+ );
1513+ assert_eq!(ev("contains(github.actor, '[bot]')"), json!(true));
1514+ }
1515+
1516+ #[test]
1517+ fn join() {
1518+ assert_eq!(
1519+ ev("join(github.event.pull_request.labels.*.name)"),
1520+ json!("bug,Enhancement")
1521+ );
1522+ assert_eq!(
1523+ ev("join(github.event.pull_request.labels.*.name, ', ')"),
1524+ json!("bug, Enhancement")
1525+ );
1526+ assert_eq!(ev("join('abc', '-')"), json!("abc"));
1527+ assert_eq!(
1528+ ev("join(fromJSON('[1, true, null]'), ' ')"),
1529+ json!("1 true ")
1530+ );
1531+ }
1532+
1533+ #[test]
1534+ fn to_json_pretty() {
1535+ assert_eq!(
1536+ ev("toJSON(steps.build.outputs)"),
1537+ json!("{\n \"version\": \"1.2.3\"\n}")
1538+ );
1539+ assert_eq!(ev("toJSON('a')"), json!("\"a\""));
1540+ assert_eq!(ev("toJSON(null)"), json!("null"));
1541+ assert_eq!(ev("toJSON(0x10)"), json!("16"));
1542+ }
1543+
1544+ #[test]
1545+ fn truthiness() {
1546+ assert!(!truthy(&json!(false)));
1547+ assert!(!truthy(&json!(0)));
1548+ assert!(!truthy(&json!(-0.0)));
1549+ assert!(!truthy(&json!("")));
1550+ assert!(!truthy(&Value::Null));
1551+ assert!(truthy(&json!("0")));
1552+ assert!(truthy(&json!("false")));
1553+ assert!(truthy(&json!([])));
1554+ assert!(truthy(&json!({})));
1555+ assert!(truthy(&json!(0.5)));
1556+ }
1557+
1558+ #[test]
1559+ fn text_conversion() {
1560+ assert_eq!(to_text(&Value::Null), "");
1561+ assert_eq!(to_text(&json!(true)), "true");
1562+ assert_eq!(to_text(&json!(3.0)), "3");
1563+ assert_eq!(to_text(&json!(1.5)), "1.5");
1564+ assert_eq!(to_text(&json!(-0.0299)), "-0.0299");
1565+ assert_eq!(to_text(&json!(1e20)), "1E+20");
1566+ assert_eq!(to_text(&json!(0.0000001)), "1E-07");
1567+ assert_eq!(to_text(&json!(123456789012345_i64)), "123456789012345");
1568+ assert_eq!(to_text(&json!(["a", 1])), "Array");
1569+ assert_eq!(to_text(&json!({ "a": 1 })), "Object");
1570+ assert_eq!(to_text(&json!("as-is")), "as-is");
1571+ }
1572+
1573+ #[test]
1574+ fn condition_implicit_success() {
1575+ assert!(cond(Status::Success, "github.event_name == 'push'"));
1576+ assert!(!cond(Status::Failure, "github.event_name == 'push'"));
1577+ assert!(!cond(Status::Cancelled, "github.event_name == 'push'"));
1578+ assert!(!cond(
1579+ Status::Success,
1580+ "github.event_name == 'pull_request'"
1581+ ));
1582+ }
1583+
1584+ #[test]
1585+ fn condition_status_functions() {
1586+ assert!(cond(Status::Failure, "always()"));
1587+ assert!(cond(Status::Cancelled, "always()"));
1588+ assert!(cond(Status::Failure, "failure()"));
1589+ assert!(!cond(Status::Success, "failure()"));
1590+ assert!(cond(Status::Cancelled, "cancelled()"));
1591+ assert!(cond(Status::Success, "success()"));
1592+ assert!(cond(
1593+ Status::Failure,
1594+ "${{ always() && github.ref == 'refs/heads/main' }}"
1595+ ));
1596+ // Nested inside another call still counts.
1597+ assert!(cond(Status::Failure, "contains(toJSON(always()), 'true')"));
1598+ }
1599+
1600+ #[test]
1601+ fn condition_status_not_by_substring() {
1602+ // 'failure()' inside a string is not a call; implicit success() applies.
1603+ assert!(!cond(Status::Failure, "steps.test.outcome != 'failure()'"));
1604+ assert!(cond(Status::Success, "steps.test.outcome != 'failure()'"));
1605+ }
1606+
1607+ #[test]
1608+ fn condition_wrapped_and_empty() {
1609+ assert!(cond(
1610+ Status::Success,
1611+ "${{ github.ref == 'refs/heads/main' }}"
1612+ ));
1613+ assert!(!cond(
1614+ Status::Success,
1615+ " ${{ github.ref == 'refs/heads/dev' }} "
1616+ ));
1617+ assert!(cond(Status::Success, ""));
1618+ assert!(!cond(Status::Failure, ""));
1619+ assert!(cond(Status::Success, "${{ }}"));
1620+ assert!(cond(Status::Success, "${{ matrix.os }}"));
1621+ assert!(!cond(Status::Success, "${{ env.EMPTY }}"));
1622+ assert!(cond(
1623+ Status::Success,
1624+ "vars.DEPLOY == 'yes' && !github.event.pull_request.draft"
1625+ ));
1626+ }
1627+
1628+ #[test]
1629+ fn condition_with_text_around_is_a_string() {
1630+ // On GitHub this is always true: it's the string "false && x", not an expression.
1631+ assert!(cond(Status::Success, "${{ false }} && x"));
1632+ }
1633+
1634+ #[test]
1635+ fn interpolate_mixed_text() {
1636+ let out = with(Status::Success, |s| {
1637+ interpolate(
1638+ "node-${{ matrix.node }}-${{ runner.os }}-${{ hashFiles('**/yarn.lock') }}",
1639+ s,
1640+ )
1641+ })
1642+ .unwrap();
1643+ assert_eq!(out, "node-18-Linux-hash(**/yarn.lock)");
1644+ let out = with(Status::Success, |s| {
1645+ interpolate("echo \"PR #${{ github.event.pull_request.number }}: ${{ github.event.pull_request.title }}\"", s)
1646+ })
1647+ .unwrap();
1648+ assert_eq!(out, "echo \"PR #42: Fix the thing\"");
1649+ }
1650+
1651+ #[test]
1652+ fn interpolate_edge_cases() {
1653+ assert_eq!(
1654+ with(Status::Success, |s| interpolate("plain $text {{ x }}", s)).unwrap(),
1655+ "plain $text {{ x }}"
1656+ );
1657+ assert_eq!(
1658+ with(Status::Success, |s| interpolate("${{ '}}' }}!", s)).unwrap(),
1659+ "}}!"
1660+ );
1661+ assert_eq!(
1662+ with(Status::Success, |s| interpolate("[${{ env.MISSING }}]", s)).unwrap(),
1663+ "[]"
1664+ );
1665+ assert_eq!(
1666+ with(Status::Success, |s| interpolate("${{ 1.50 }}", s)).unwrap(),
1667+ "1.5"
1668+ );
1669+ assert!(
1670+ with(Status::Success, |s| interpolate("oops ${{ github.ref", s))
1671+ .unwrap_err()
1672+ .contains("not closed")
1673+ );
1674+ assert!(with(Status::Success, |s| interpolate("${{ \"x\" }}", s)).is_err());
1675+ }
1676+
1677+ #[test]
1678+ fn interpolate_value_keeps_types() {
1679+ let input = json!({
1680+ "matrix": "${{ fromJSON(needs.setup.outputs.matrix) }}",
1681+ "continue-on-error": "${{ matrix.experimental }}",
1682+ "timeout-minutes": "${{ inputs.count }}",
1683+ "name": "Build ${{ matrix.os }}",
1684+ "env": { "VERSION_${{ matrix.node }}": "${{ steps.build.outputs.version }}" },
1685+ "list": ["${{ github.event.pull_request.labels.*.name }}", 7, null],
1686+ "plain": true
1687+ });
1688+ let out = with(Status::Success, |s| interpolate_value(&input, s)).unwrap();
1689+ assert_eq!(
1690+ out,
1691+ json!({
1692+ "matrix": { "os": ["ubuntu-latest", "windows-latest"], "node": [18, 20] },
1693+ "continue-on-error": false,
1694+ "timeout-minutes": 3,
1695+ "name": "Build ubuntu-latest",
1696+ "env": { "VERSION_18": "1.2.3" },
1697+ "list": [["bug", "Enhancement"], 7, null],
1698+ "plain": true
1699+ })
1700+ );
1701+ }
1702+
1703+ #[test]
1704+ fn has_expression_detects() {
1705+ assert!(has_expression("a ${{ b }}"));
1706+ assert!(!has_expression("a ${ b }"));
1707+ assert!(!has_expression("{{ b }}"));
1708+ }
1709+
1710+ #[test]
1711+ fn dependabot_and_draft_guards() {
1712+ assert!(!cond(Status::Success, "github.actor != 'dependabot[bot]'"));
1713+ assert!(cond(
1714+ Status::Success,
1715+ "github.event.pull_request.draft == false"
1716+ ));
1717+ assert!(cond(
1718+ Status::Success,
1719+ "!contains(github.event.head_commit.message, '[skip deploy]')"
1720+ ));
1721+ }
1722+
1723+ #[test]
1724+ fn tag_release_condition() {
1725+ let contexts = {
1726+ let mut c = contexts();
1727+ c["github"]["ref"] = json!("refs/tags/v1.4.0");
1728+ c["github"]["event_name"] = json!("push");
1729+ c
1730+ };
1731+ let scope = Scope {
1732+ contexts: &contexts,
1733+ status: Status::Success,
1734+ hash_files: None,
1735+ };
1736+ assert!(
1737+ condition(
1738+ "github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')",
1739+ &scope
1740+ )
1741+ .unwrap()
1742+ );
1743+ assert_eq!(
1744+ interpolate("${{ format('release-{0}', github.ref_name) }}", &scope).unwrap(),
1745+ "release-main"
1746+ );
1747+ }
1748+
1749+ #[test]
1750+ fn needs_result_and_number_format() {
1751+ assert!(cond(Status::Success, "needs.setup.result == 'success'"));
1752+ assert_eq!(ev("format('{0}', 0.1)"), json!("0.1"));
1753+ assert_eq!(ev("format('{0}', 100)"), json!("100"));
1754+ assert_eq!(ev("format('{0}|{1}', null, true)"), json!("|true"));
1755+ }
1756+}
+310−0
1+//! Branch, tag and path filters, with GitHub's pattern syntax:
2+//!
3+//! - `*` matches any characters except `/`; `**` matches any characters.
4+//! - `?` makes the character before it optional; `+` repeats it.
5+//! - `[a-z0-9]` matches one character of a set.
6+//! - `!` at the start of a pattern excludes what it matches. Patterns are
7+//! read in order and the last one that matches decides.
8+//! - `\` escapes the next character.
9+
10+#[derive(Clone, Debug, PartialEq, Eq)]
11+enum Atom {
12+ Char(char),
13+ Class(Vec<(char, char)>),
14+ /// `*`: anything but `/`.
15+ Star,
16+ /// `**`: anything.
17+ Globstar,
18+}
19+
20+#[derive(Clone, Debug, PartialEq, Eq)]
21+enum Repeat {
22+ One,
23+ /// `?`
24+ Optional,
25+ /// `+`
26+ OneOrMore,
27+}
28+
29+#[derive(Clone, Debug, PartialEq, Eq)]
30+struct Piece {
31+ atom: Atom,
32+ repeat: Repeat,
33+}
34+
35+/// One compiled pattern.
36+#[derive(Clone, Debug, PartialEq, Eq)]
37+pub struct Pattern {
38+ pieces: Vec<Piece>,
39+ pub negated: bool,
40+ pub source: String,
41+}
42+
43+impl Pattern {
44+ pub fn parse(source: &str) -> Pattern {
45+ let (negated, body) = match source.strip_prefix('!') {
46+ Some(rest) => (true, rest),
47+ None => (false, source),
48+ };
49+ let chars: Vec<char> = body.chars().collect();
50+ let mut pieces: Vec<Piece> = Vec::new();
51+ let mut i = 0;
52+ while i < chars.len() {
53+ let c = chars[i];
54+ match c {
55+ '*' if chars.get(i + 1) == Some(&'*') => {
56+ pieces.push(Piece { atom: Atom::Globstar, repeat: Repeat::One });
57+ i += 2;
58+ }
59+ '*' => {
60+ pieces.push(Piece { atom: Atom::Star, repeat: Repeat::One });
61+ i += 1;
62+ }
63+ '?' | '+' if pieces.last().is_some_and(|p| p.repeat == Repeat::One && !matches!(p.atom, Atom::Star | Atom::Globstar)) => {
64+ pieces.last_mut().expect("checked").repeat = if c == '?' { Repeat::Optional } else { Repeat::OneOrMore };
65+ i += 1;
66+ }
67+ '[' => {
68+ // A set, up to the next `]`; without one, a literal `[`.
69+ match chars[i + 1..].iter().position(|&x| x == ']') {
70+ Some(len) if len > 0 => {
71+ let inner = &chars[i + 1..i + 1 + len];
72+ let mut ranges = Vec::new();
73+ let mut j = 0;
74+ while j < inner.len() {
75+ if j + 2 < inner.len() && inner[j + 1] == '-' {
76+ ranges.push((inner[j], inner[j + 2]));
77+ j += 3;
78+ } else {
79+ ranges.push((inner[j], inner[j]));
80+ j += 1;
81+ }
82+ }
83+ pieces.push(Piece { atom: Atom::Class(ranges), repeat: Repeat::One });
84+ i += len + 2;
85+ }
86+ _ => {
87+ pieces.push(Piece { atom: Atom::Char('['), repeat: Repeat::One });
88+ i += 1;
89+ }
90+ }
91+ }
92+ '\\' if i + 1 < chars.len() => {
93+ pieces.push(Piece { atom: Atom::Char(chars[i + 1]), repeat: Repeat::One });
94+ i += 2;
95+ }
96+ other => {
97+ pieces.push(Piece { atom: Atom::Char(other), repeat: Repeat::One });
98+ i += 1;
99+ }
100+ }
101+ }
102+ Pattern { pieces, negated, source: source.to_owned() }
103+ }
104+
105+ /// Whether the text matches, ignoring `!`.
106+ pub fn matches(&self, text: &str) -> bool {
107+ let text: Vec<char> = text.chars().collect();
108+ matches_at(&self.pieces, &text)
109+ }
110+}
111+
112+fn atom_matches(atom: &Atom, c: char) -> bool {
113+ match atom {
114+ Atom::Char(expected) => *expected == c,
115+ Atom::Class(ranges) => ranges.iter().any(|(low, high)| (*low..=*high).contains(&c)),
116+ Atom::Star => c != '/',
117+ Atom::Globstar => true,
118+ }
119+}
120+
121+fn matches_at(pieces: &[Piece], text: &[char]) -> bool {
122+ let Some((piece, rest)) = pieces.split_first() else {
123+ return text.is_empty();
124+ };
125+ match (&piece.atom, &piece.repeat) {
126+ (Atom::Star | Atom::Globstar, _) => {
127+ // `**/` also matches nothing, so `**/README.md` finds the root's.
128+ if piece.atom == Atom::Globstar
129+ && rest.first().is_some_and(|next| next.atom == Atom::Char('/') && next.repeat == Repeat::One)
130+ && matches_at(&rest[1..], text)
131+ {
132+ return true;
133+ }
134+ // Zero or more, as long as each character is allowed.
135+ for taken in 0..=text.len() {
136+ if matches_at(rest, &text[taken..]) {
137+ return true;
138+ }
139+ if taken < text.len() && !atom_matches(&piece.atom, text[taken]) {
140+ return false;
141+ }
142+ }
143+ false
144+ }
145+ (atom, Repeat::One) => text.first().is_some_and(|&c| atom_matches(atom, c)) && matches_at(rest, &text[1..]),
146+ (atom, Repeat::Optional) => {
147+ matches_at(rest, text) || (text.first().is_some_and(|&c| atom_matches(atom, c)) && matches_at(rest, &text[1..]))
148+ }
149+ (atom, Repeat::OneOrMore) => {
150+ let mut taken = 0;
151+ while taken < text.len() && atom_matches(atom, text[taken]) {
152+ taken += 1;
153+ if matches_at(rest, &text[taken..]) {
154+ return true;
155+ }
156+ }
157+ false
158+ }
159+ }
160+}
161+
162+/// A list of patterns, read in order: a later `!pattern` excludes what an
163+/// earlier one included, and a later pattern can include it again.
164+#[derive(Clone, Debug, Default, PartialEq, Eq)]
165+pub struct Patterns(pub Vec<Pattern>);
166+
167+impl Patterns {
168+ pub fn new<S: AsRef<str>>(sources: &[S]) -> Patterns {
169+ Patterns(sources.iter().map(|source| Pattern::parse(source.as_ref())).collect())
170+ }
171+
172+ /// Whether the text is included.
173+ pub fn includes(&self, text: &str) -> bool {
174+ let mut included = false;
175+ for pattern in &self.0 {
176+ if pattern.matches(text) {
177+ included = !pattern.negated;
178+ }
179+ }
180+ included
181+ }
182+
183+ /// Whether any pattern matches the text (for `-ignore` lists, where
184+ /// `!` patterns put a text back).
185+ pub fn ignores(&self, text: &str) -> bool {
186+ self.includes(text)
187+ }
188+}
189+
190+/// A filter as a workflow gives it: `branches` or `branches-ignore`,
191+/// `tags` or `tags-ignore`, `paths` or `paths-ignore`.
192+#[derive(Clone, Debug, Default, PartialEq, Eq)]
193+pub struct Filter {
194+ pub only: Option<Patterns>,
195+ pub ignore: Option<Patterns>,
196+}
197+
198+impl Filter {
199+ pub fn is_set(&self) -> bool {
200+ self.only.is_some() || self.ignore.is_some()
201+ }
202+
203+ /// Whether one name (a branch or a tag) passes.
204+ pub fn allows(&self, name: &str) -> bool {
205+ if let Some(only) = &self.only
206+ && !only.includes(name)
207+ {
208+ return false;
209+ }
210+ if let Some(ignore) = &self.ignore
211+ && ignore.ignores(name)
212+ {
213+ return false;
214+ }
215+ true
216+ }
217+
218+ /// Whether a set of changed paths passes: `paths` needs at least one
219+ /// included path; `paths-ignore` needs at least one path not ignored.
220+ /// With no paths known, it passes.
221+ pub fn allows_paths(&self, paths: &[String]) -> bool {
222+ if paths.is_empty() {
223+ return true;
224+ }
225+ if let Some(only) = &self.only
226+ && !paths.iter().any(|path| only.includes(path))
227+ {
228+ return false;
229+ }
230+ if let Some(ignore) = &self.ignore
231+ && paths.iter().all(|path| ignore.ignores(path))
232+ {
233+ return false;
234+ }
235+ true
236+ }
237+}
238+
239+#[cfg(test)]
240+mod tests {
241+ use super::*;
242+
243+ fn m(pattern: &str, text: &str) -> bool {
244+ Pattern::parse(pattern).matches(text)
245+ }
246+
247+ #[test]
248+ fn stars_and_globstars() {
249+ assert!(m("main", "main"));
250+ assert!(!m("main", "mainline"));
251+ assert!(m("releases/*", "releases/v1"));
252+ assert!(!m("releases/*", "releases/v1/hotfix"));
253+ assert!(m("releases/**", "releases/v1/hotfix"));
254+ assert!(m("feature/**", "feature/a/b/c"));
255+ assert!(m("*", "main"));
256+ assert!(!m("*", "feature/x"));
257+ assert!(m("**", "feature/x"));
258+ assert!(m("**.js", "src/app/index.js"));
259+ assert!(m("*.js", "index.js"));
260+ assert!(!m("*.js", "src/index.js"));
261+ assert!(m("docs/**", "docs/guide/intro.md"));
262+ assert!(m("**/README.md", "a/b/README.md"));
263+ assert!(m("**/*.md", "README.md"));
264+ assert!(m("**/README.md", "README.md"));
265+ assert!(m("**/README.md", "server/README.md"));
266+ }
267+
268+ #[test]
269+ fn repeats_classes_and_escapes() {
270+ assert!(m("v[12].[0-9]+.[0-9]+", "v1.10.3"));
271+ assert!(!m("v[12].[0-9]+.[0-9]+", "v3.1.0"));
272+ assert!(m("v2*", "v2.0.0"));
273+ assert!(m("colou?r", "color"));
274+ assert!(m("colou?r", "colour"));
275+ assert!(m("v[0-9]+", "v123"));
276+ assert!(!m("v[0-9]+", "v"));
277+ assert!(m("a\\*b", "a*b"));
278+ assert!(!m("a\\*b", "axb"));
279+ }
280+
281+ #[test]
282+ fn order_decides_with_negations() {
283+ let list = Patterns::new(&["releases/**", "!releases/**-alpha"]);
284+ assert!(list.includes("releases/v1"));
285+ assert!(!list.includes("releases/v1-alpha"));
286+ let again = Patterns::new(&["**", "!docs/**", "docs/api/**"]);
287+ assert!(again.includes("src/a.rs"));
288+ assert!(!again.includes("docs/intro.md"));
289+ assert!(again.includes("docs/api/x.md"));
290+ }
291+
292+ #[test]
293+ fn filters_for_names_and_paths() {
294+ let branches = Filter { only: Some(Patterns::new(&["main", "release/**"])), ignore: None };
295+ assert!(branches.allows("main"));
296+ assert!(branches.allows("release/2.0"));
297+ assert!(!branches.allows("feature/x"));
298+ let ignored = Filter { only: None, ignore: Some(Patterns::new(&["dependabot/**"])) };
299+ assert!(!ignored.allows("dependabot/npm/x"));
300+ assert!(ignored.allows("main"));
301+
302+ let paths = Filter { only: Some(Patterns::new(&["src/**", "!src/**/*.md"])), ignore: None };
303+ assert!(paths.allows_paths(&["src/main.rs".into()]));
304+ assert!(!paths.allows_paths(&["src/notes.md".into(), "README.md".into()]));
305+ let docs = Filter { only: None, ignore: Some(Patterns::new(&["docs/**", "*.md"])) };
306+ assert!(!docs.allows_paths(&["docs/a.md".into(), "README.md".into()]));
307+ assert!(docs.allows_paths(&["docs/a.md".into(), "src/lib.rs".into()]));
308+ assert!(docs.allows_paths(&[]));
309+ }
310+}
+15−0
1+//! GitHub Actions on g1t. A repository's `.github/workflows/*.yml` run on
2+//! g1t as they are: this crate reads them ([`workflow`]), evaluates their
3+//! `${{ }}` expressions ([`expr`]), matches their branch and path filters
4+//! ([`filter`]), expands their matrices ([`matrix`]), and says which g1t
5+//! events are which GitHub events ([`events`]).
6+//!
7+//! It has no I/O, so the actions service (in a Worker) and the sandbox
8+//! (in a container) share it: the service decides what runs, the sandbox
9+//! runs the steps, and both read workflows and expressions the same way.
10+
11+pub mod events;
12+pub mod expr;
13+pub mod filter;
14+pub mod matrix;
15+pub mod workflow;
+177−0
1+//! `strategy.matrix`: every combination of its values, less `exclude`,
2+//! plus `include`, the way GitHub expands it.
3+
4+use serde_json::{Map, Value};
5+
6+/// The most jobs one matrix may make, as on GitHub.
7+pub const MAX_JOBS: usize = 256;
8+
9+/// One combination: the matrix's keys, in the file's order, and values.
10+pub type Combination = Map<String, Value>;
11+
12+/// Expands a matrix. `Ok(vec![])` means it made no jobs, which GitHub
13+/// treats as an error the caller reports.
14+pub fn expand(matrix: &Value) -> Result<Vec<Combination>, String> {
15+ let Value::Object(matrix) = matrix else {
16+ return Err("`strategy.matrix` is a mapping of names to lists of values.".to_owned());
17+ };
18+ let mut combinations: Vec<Combination> = vec![Map::new()];
19+ let mut dimensions = 0;
20+ for (key, values) in matrix {
21+ if key == "include" || key == "exclude" {
22+ continue;
23+ }
24+ let Value::Array(values) = values else {
25+ return Err(format!("`matrix.{key}` is a list of values."));
26+ };
27+ dimensions += 1;
28+ let mut next = Vec::with_capacity(combinations.len() * values.len());
29+ for combination in &combinations {
30+ for value in values {
31+ let mut extended = combination.clone();
32+ extended.insert(key.clone(), value.clone());
33+ next.push(extended);
34+ }
35+ }
36+ combinations = next;
37+ if combinations.len() > MAX_JOBS {
38+ return Err(format!("The matrix makes more than {MAX_JOBS} jobs."));
39+ }
40+ }
41+ if dimensions == 0 {
42+ combinations.clear();
43+ }
44+
45+ if let Some(exclude) = matrix.get("exclude") {
46+ let Value::Array(excludes) = exclude else {
47+ return Err("`matrix.exclude` is a list of combinations.".to_owned());
48+ };
49+ for exclude in excludes {
50+ let Value::Object(exclude) = exclude else {
51+ return Err("Each `matrix.exclude` entry is a mapping.".to_owned());
52+ };
53+ combinations.retain(|combination| !partial_match(combination, exclude));
54+ }
55+ }
56+
57+ if let Some(include) = matrix.get("include") {
58+ let Value::Array(includes) = include else {
59+ return Err("`matrix.include` is a list of combinations.".to_owned());
60+ };
61+ // The keys of the original matrix, whose values an include may not change.
62+ let originals: Vec<&String> = matrix.keys().filter(|key| *key != "include" && *key != "exclude").collect();
63+ let base_count = combinations.len();
64+ for include in includes {
65+ let Value::Object(include) = include else {
66+ return Err("Each `matrix.include` entry is a mapping.".to_owned());
67+ };
68+ let mut added = false;
69+ for combination in combinations.iter_mut().take(base_count) {
70+ let overwrites_original = include
71+ .iter()
72+ .any(|(key, value)| originals.contains(&key) && combination.get(key).is_some_and(|existing| existing != value));
73+ if !overwrites_original {
74+ for (key, value) in include {
75+ combination.insert(key.clone(), value.clone());
76+ }
77+ added = true;
78+ }
79+ }
80+ if !added {
81+ combinations.push(include.clone());
82+ }
83+ }
84+ }
85+ if combinations.len() > MAX_JOBS {
86+ return Err(format!("The matrix makes more than {MAX_JOBS} jobs."));
87+ }
88+ Ok(combinations)
89+}
90+
91+fn partial_match(combination: &Combination, pattern: &Map<String, Value>) -> bool {
92+ pattern.iter().all(|(key, value)| match (combination.get(key), value) {
93+ (Some(Value::Object(inner)), Value::Object(pattern)) => partial_match(inner, pattern),
94+ (Some(actual), expected) => actual == expected,
95+ (None, _) => false,
96+ })
97+}
98+
99+/// A job's name with its combination, as GitHub shows it:
100+/// `test (ubuntu-latest, 18)`. Objects in the combination are left out.
101+pub fn job_name(name: &str, combination: &Combination) -> String {
102+ let values: Vec<String> = combination
103+ .values()
104+ .filter_map(|value| match value {
105+ Value::String(text) => Some(text.clone()),
106+ Value::Number(number) => Some(number.to_string()),
107+ Value::Bool(flag) => Some(flag.to_string()),
108+ _ => None,
109+ })
110+ .collect();
111+ if values.is_empty() { name.to_owned() } else { format!("{name} ({})", values.join(", ")) }
112+}
113+
114+#[cfg(test)]
115+mod tests {
116+ use super::*;
117+ use serde_json::json;
118+
119+ fn names(combinations: &[Combination]) -> Vec<String> {
120+ combinations.iter().map(|c| job_name("test", c)).collect()
121+ }
122+
123+ #[test]
124+ fn products_in_file_order() {
125+ let jobs = expand(&json!({ "os": ["ubuntu-latest", "windows-latest"], "node": [18, 20] })).unwrap();
126+ assert_eq!(
127+ names(&jobs),
128+ ["test (ubuntu-latest, 18)", "test (ubuntu-latest, 20)", "test (windows-latest, 18)", "test (windows-latest, 20)"]
129+ );
130+ }
131+
132+ #[test]
133+ fn excludes_partial_matches() {
134+ let jobs = expand(&json!({
135+ "os": ["macos", "windows"], "version": [12, 14, 16], "environment": ["staging", "production"],
136+ "exclude": [{ "os": "macos", "version": 12, "environment": "production" }, { "os": "windows", "version": 16 }]
137+ }))
138+ .unwrap();
139+ assert_eq!(jobs.len(), 12 - 1 - 2);
140+ }
141+
142+ #[test]
143+ fn includes_extend_or_add_as_github_documents() {
144+ // GitHub's own example.
145+ let jobs = expand(&json!({
146+ "fruit": ["apple", "pear"], "animal": ["cat", "dog"],
147+ "include": [
148+ { "color": "green" },
149+ { "color": "pink", "animal": "cat" },
150+ { "fruit": "apple", "shape": "circle" },
151+ { "fruit": "banana" },
152+ { "fruit": "banana", "animal": "cat" }
153+ ]
154+ }))
155+ .unwrap();
156+ let expected = vec![
157+ json!({ "fruit": "apple", "animal": "cat", "color": "pink", "shape": "circle" }),
158+ json!({ "fruit": "apple", "animal": "dog", "color": "green", "shape": "circle" }),
159+ json!({ "fruit": "pear", "animal": "cat", "color": "pink" }),
160+ json!({ "fruit": "pear", "animal": "dog", "color": "green" }),
161+ json!({ "fruit": "banana" }),
162+ json!({ "fruit": "banana", "animal": "cat" }),
163+ ];
164+ let got: Vec<Value> = jobs.into_iter().map(Value::Object).collect();
165+ assert_eq!(got, expected);
166+ }
167+
168+ #[test]
169+ fn include_only_and_limits() {
170+ let jobs = expand(&json!({ "include": [{ "site": "a" }, { "site": "b" }] })).unwrap();
171+ assert_eq!(names(&jobs), ["test (a)", "test (b)"]);
172+ let big: Vec<u32> = (0..20).collect();
173+ assert!(expand(&json!({ "a": big, "b": big })).unwrap_err().contains("256"));
174+ assert!(expand(&json!({ "os": "linux" })).is_err());
175+ assert!(expand(&json!({})).unwrap().is_empty());
176+ }
177+}
+576−0
1+//! Reading a workflow file: its triggers, jobs and steps, and notes on
2+//! anything in it that runs differently on g1t, so moving a repository
3+//! from GitHub says plainly what to expect.
4+
5+use serde::{Deserialize, Serialize};
6+use serde_json::{Map, Value};
7+
8+use crate::filter::{Filter, Patterns};
9+
10+/// Where workflows live.
11+pub const FOLDER: &str = ".github/workflows";
12+
13+/// The events a workflow can name that g1t starts runs for.
14+pub const SUPPORTED_EVENTS: &[&str] = &[
15+ "push",
16+ "pull_request",
17+ "pull_request_target",
18+ "pull_request_review",
19+ "issues",
20+ "issue_comment",
21+ "schedule",
22+ "workflow_dispatch",
23+ "repository_dispatch",
24+ "workflow_call",
25+ "merge_group",
26+ "create",
27+ "delete",
28+];
29+
30+/// The `types` each event has when a workflow gives none, as on GitHub.
31+pub fn default_types(event: &str) -> &'static [&'static str] {
32+ match event {
33+ "pull_request" | "pull_request_target" => &["opened", "synchronize", "reopened"],
34+ "merge_group" => &["checks_requested"],
35+ _ => &[],
36+ }
37+}
38+
39+/// How much a note matters.
40+#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
41+#[serde(rename_all = "snake_case")]
42+pub enum Severity {
43+ /// Runs, slightly differently.
44+ Info,
45+ /// Runs, but something in it does nothing or may not work.
46+ Warning,
47+ /// Does not run on g1t.
48+ Unsupported,
49+}
50+
51+#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
52+pub struct Note {
53+ pub severity: Severity,
54+ /// The job, if the note is about one.
55+ #[serde(skip_serializing_if = "Option::is_none")]
56+ pub job: Option<String>,
57+ pub message: String,
58+}
59+
60+/// One event a workflow is started by, with its filters.
61+#[derive(Clone, Debug, Default, PartialEq, Eq)]
62+pub struct Trigger {
63+ pub event: String,
64+ /// Activity types; empty means the event's defaults (or all).
65+ pub types: Vec<String>,
66+ pub branches: Filter,
67+ pub tags: Filter,
68+ pub paths: Filter,
69+ /// For `schedule`.
70+ pub crons: Vec<String>,
71+ /// For `workflow_dispatch` and `workflow_call`: the inputs, as written.
72+ pub inputs: Map<String, Value>,
73+}
74+
75+impl Trigger {
76+ /// Whether an activity type starts it.
77+ pub fn wants_type(&self, action: Option<&str>) -> bool {
78+ let Some(action) = action else { return true };
79+ if self.types.is_empty() {
80+ let defaults = default_types(&self.event);
81+ return defaults.is_empty() || defaults.contains(&action);
82+ }
83+ self.types.iter().any(|t| t == action)
84+ }
85+}
86+
87+#[derive(Clone, Debug, PartialEq)]
88+pub struct Step {
89+ pub id: Option<String>,
90+ pub name: Option<String>,
91+ pub condition: Option<String>,
92+ pub uses: Option<String>,
93+ pub run: Option<String>,
94+ /// The whole step as written, for the sandbox.
95+ pub raw: Value,
96+}
97+
98+impl Step {
99+ /// How the step is shown when it has no name.
100+ pub fn title(&self) -> String {
101+ if let Some(name) = &self.name {
102+ return name.clone();
103+ }
104+ if let Some(uses) = &self.uses {
105+ return format!("Run {uses}");
106+ }
107+ let first = self.run.as_deref().unwrap_or_default().lines().find(|line| !line.trim().is_empty()).unwrap_or_default();
108+ format!("Run {}", first.trim())
109+ }
110+}
111+
112+#[derive(Clone, Debug, PartialEq)]
113+pub struct Job {
114+ /// Its key under `jobs:`.
115+ pub id: String,
116+ pub name: Option<String>,
117+ pub needs: Vec<String>,
118+ pub condition: Option<String>,
119+ pub runs_on: Value,
120+ /// `strategy.matrix`, as written (it may be an expression).
121+ pub matrix: Option<Value>,
122+ pub fail_fast: bool,
123+ pub max_parallel: Option<u32>,
124+ /// A reusable workflow it calls (`uses:` on a job).
125+ pub uses: Option<String>,
126+ pub steps: Vec<Step>,
127+ /// The whole job as written, for the sandbox.
128+ pub raw: Value,
129+}
130+
131+#[derive(Clone, Debug, PartialEq)]
132+pub struct Workflow {
133+ pub name: Option<String>,
134+ pub run_name: Option<String>,
135+ pub triggers: Vec<Trigger>,
136+ pub env: Map<String, Value>,
137+ pub concurrency: Option<Concurrency>,
138+ pub jobs: Vec<Job>,
139+ pub notes: Vec<Note>,
140+ /// The whole workflow as written.
141+ pub raw: Value,
142+}
143+
144+#[derive(Clone, Debug, PartialEq, Eq)]
145+pub struct Concurrency {
146+ /// May hold an expression.
147+ pub group: String,
148+ pub cancel_in_progress: Value,
149+}
150+
151+impl Workflow {
152+ pub fn trigger(&self, event: &str) -> Option<&Trigger> {
153+ self.triggers.iter().find(|trigger| trigger.event == event)
154+ }
155+
156+ /// The name shown for it: its `name`, or its file's path.
157+ pub fn display_name(&self, path: &str) -> String {
158+ self.name.clone().unwrap_or_else(|| path.to_owned())
159+ }
160+
161+ /// The job ids in an order where each comes after the jobs it needs.
162+ pub fn job_order(&self) -> Vec<&str> {
163+ let mut ordered: Vec<&str> = Vec::new();
164+ while ordered.len() < self.jobs.len() {
165+ let before = ordered.len();
166+ for job in &self.jobs {
167+ if !ordered.contains(&job.id.as_str()) && job.needs.iter().all(|need| ordered.contains(&need.as_str())) {
168+ ordered.push(&job.id);
169+ }
170+ }
171+ if ordered.len() == before {
172+ break;
173+ }
174+ }
175+ ordered
176+ }
177+}
178+
179+/// YAML to JSON, keeping the order of keys. Keys that are not strings
180+/// (`on: true` in YAML 1.1, numbers) become their text.
181+pub fn yaml_to_json(value: &serde_yaml::Value) -> Value {
182+ match value {
183+ serde_yaml::Value::Null => Value::Null,
184+ serde_yaml::Value::Bool(flag) => Value::Bool(*flag),
185+ serde_yaml::Value::Number(number) => {
186+ if let Some(n) = number.as_i64() {
187+ Value::from(n)
188+ } else if let Some(n) = number.as_u64() {
189+ Value::from(n)
190+ } else {
191+ number.as_f64().and_then(serde_json::Number::from_f64).map_or(Value::Null, Value::Number)
192+ }
193+ }
194+ serde_yaml::Value::String(text) => Value::String(text.clone()),
195+ serde_yaml::Value::Sequence(items) => Value::Array(items.iter().map(yaml_to_json).collect()),
196+ serde_yaml::Value::Mapping(map) => {
197+ let mut out = Map::new();
198+ for (key, value) in map {
199+ let key = match key {
200+ serde_yaml::Value::String(text) => text.clone(),
201+ serde_yaml::Value::Bool(flag) => flag.to_string(),
202+ serde_yaml::Value::Number(number) => number.to_string(),
203+ _ => continue,
204+ };
205+ out.insert(key, yaml_to_json(value));
206+ }
207+ Value::Object(out)
208+ }
209+ serde_yaml::Value::Tagged(tagged) => yaml_to_json(&tagged.value),
210+ }
211+}
212+
213+fn texts(value: Option<&Value>) -> Vec<String> {
214+ match value {
215+ Some(Value::String(text)) => vec![text.clone()],
216+ Some(Value::Array(items)) => items
217+ .iter()
218+ .filter_map(|item| match item {
219+ Value::String(text) => Some(text.clone()),
220+ Value::Number(n) => Some(n.to_string()),
221+ _ => None,
222+ })
223+ .collect(),
224+ _ => Vec::new(),
225+ }
226+}
227+
228+fn text(value: Option<&Value>) -> Option<String> {
229+ match value? {
230+ Value::String(text) => Some(text.clone()),
231+ Value::Number(n) => Some(n.to_string()),
232+ Value::Bool(flag) => Some(flag.to_string()),
233+ _ => None,
234+ }
235+}
236+
237+fn filter(spec: &Map<String, Value>, only: &str, ignore: &str) -> Filter {
238+ let list = |key: &str| spec.get(key).map(|value| Patterns::new(&texts(Some(value))));
239+ Filter { only: list(only), ignore: list(ignore) }
240+}
241+
242+fn trigger(event: &str, spec: &Value) -> Trigger {
243+ let mut trigger = Trigger { event: event.to_owned(), ..Trigger::default() };
244+ match spec {
245+ Value::Object(spec) => {
246+ trigger.types = texts(spec.get("types"));
247+ trigger.branches = filter(spec, "branches", "branches-ignore");
248+ trigger.tags = filter(spec, "tags", "tags-ignore");
249+ trigger.paths = filter(spec, "paths", "paths-ignore");
250+ if let Some(Value::Object(inputs)) = spec.get("inputs") {
251+ trigger.inputs = inputs.clone();
252+ }
253+ }
254+ Value::Array(entries) if event == "schedule" => {
255+ trigger.crons = entries.iter().filter_map(|entry| text(entry.get("cron"))).collect();
256+ }
257+ _ => {}
258+ }
259+ trigger
260+}
261+
262+/// Reads a workflow. `Err` is what is wrong with the file, for the person
263+/// who wrote it; what reads but runs differently is in `notes`.
264+pub fn parse(source: &str) -> Result<Workflow, String> {
265+ let yaml: serde_yaml::Value = serde_yaml::from_str(source).map_err(|error| format!("It is not valid YAML: {error}"))?;
266+ let raw = yaml_to_json(&yaml);
267+ let Value::Object(root) = &raw else {
268+ return Err("A workflow is a mapping with `on` and `jobs`.".to_owned());
269+ };
270+ let mut notes = Vec::new();
271+ let mut note = |severity, job: Option<&str>, message: String| notes.push(Note { severity, job: job.map(str::to_owned), message });
272+
273+ // `on`, in any of its three shapes. YAML 1.1 readers turn `on` into
274+ // `true`; this reader keeps it, and accepts both.
275+ let on = root.get("on").or_else(|| root.get("true")).ok_or("`on` is missing: say which events start the workflow.")?;
276+ let mut triggers = Vec::new();
277+ match on {
278+ Value::String(event) => triggers.push(trigger(event, &Value::Null)),
279+ Value::Array(events) => {
280+ for event in events {
281+ let Value::String(event) = event else { return Err("`on` lists event names.".to_owned()) };
282+ triggers.push(trigger(event, &Value::Null));
283+ }
284+ }
285+ Value::Object(events) => {
286+ for (event, spec) in events {
287+ triggers.push(trigger(event, spec));
288+ }
289+ }
290+ _ => return Err("`on` is an event, a list of events, or a mapping of events to their filters.".to_owned()),
291+ }
292+ for trigger in &triggers {
293+ if !SUPPORTED_EVENTS.contains(&trigger.event.as_str()) {
294+ note(
295+ Severity::Unsupported,
296+ None,
297+ format!("g1t has no `{}` event, so that trigger never starts it.", trigger.event),
298+ );
299+ }
300+ if trigger.event == "pull_request_target" {
301+ note(
302+ Severity::Info,
303+ None,
304+ "`pull_request_target` runs like `pull_request`, on the pull request's head, with the repository's secrets.".to_owned(),
305+ );
306+ }
307+ if trigger.event == "workflow_call" && triggers.len() == 1 {
308+ note(Severity::Info, None, "It is a reusable workflow: it runs when another workflow calls it.".to_owned());
309+ }
310+ }
311+
312+ let env = match root.get("env") {
313+ Some(Value::Object(env)) => env.clone(),
314+ _ => Map::new(),
315+ };
316+ let concurrency = match root.get("concurrency") {
317+ Some(Value::String(group)) => Some(Concurrency { group: group.clone(), cancel_in_progress: Value::Bool(false) }),
318+ Some(Value::Object(spec)) => text(spec.get("group")).map(|group| Concurrency {
319+ group,
320+ cancel_in_progress: spec.get("cancel-in-progress").cloned().unwrap_or(Value::Bool(false)),
321+ }),
322+ _ => None,
323+ };
324+
325+ let Some(Value::Object(job_specs)) = root.get("jobs") else {
326+ return Err("`jobs` is missing: a workflow needs at least one job.".to_owned());
327+ };
328+ if job_specs.is_empty() {
329+ return Err("`jobs` is empty: a workflow needs at least one job.".to_owned());
330+ }
331+ let mut jobs = Vec::new();
332+ for (id, spec) in job_specs {
333+ let Value::Object(spec) = spec else {
334+ return Err(format!("Job `{id}` is a mapping."));
335+ };
336+ let uses = text(spec.get("uses"));
337+ let steps_raw = match spec.get("steps") {
338+ Some(Value::Array(steps)) => steps.clone(),
339+ None if uses.is_some() => Vec::new(),
340+ None => return Err(format!("Job `{id}` has no `steps`.")),
341+ Some(_) => return Err(format!("Job `{id}`: `steps` is a list.")),
342+ };
343+ let mut steps = Vec::new();
344+ for (index, step) in steps_raw.iter().enumerate() {
345+ let Value::Object(fields) = step else {
346+ return Err(format!("Job `{id}`, step {}: a step is a mapping.", index + 1));
347+ };
348+ let step = Step {
349+ id: text(fields.get("id")),
350+ name: text(fields.get("name")),
351+ condition: text(fields.get("if")),
352+ uses: text(fields.get("uses")),
353+ run: text(fields.get("run")),
354+ raw: step.clone(),
355+ };
356+ match (&step.uses, &step.run) {
357+ (Some(_), Some(_)) => return Err(format!("Job `{id}`, step {}: a step has `uses` or `run`, not both.", index + 1)),
358+ (None, None) => return Err(format!("Job `{id}`, step {}: a step needs `uses` or `run`.", index + 1)),
359+ _ => {}
360+ }
361+ if let Some(uses) = &step.uses
362+ && let Some((severity, message)) = action_note(uses)
363+ {
364+ note(severity, Some(id), message);
365+ }
366+ if let Some(shell) = text(fields.get("shell"))
367+ && matches!(shell.as_str(), "pwsh" | "powershell" | "cmd")
368+ {
369+ note(Severity::Unsupported, Some(id), format!("Steps with `shell: {shell}` need Windows or PowerShell, which g1t's Linux runners do not have."));
370+ }
371+ steps.push(step);
372+ }
373+ let runs_on = spec.get("runs-on").cloned().unwrap_or(Value::Null);
374+ for label in texts(Some(&runs_on)).iter().chain(runs_on.get("labels").map(|l| texts(Some(l))).unwrap_or_default().iter()) {
375+ let lower = label.to_ascii_lowercase();
376+ if lower.contains("windows") || lower.contains("macos") {
377+ note(
378+ Severity::Unsupported,
379+ Some(id),
380+ format!("`runs-on: {label}`: g1t runs jobs on Linux only, so this job fails."),
381+ );
382+ } else if lower == "self-hosted" {
383+ note(Severity::Info, Some(id), "`self-hosted`: g1t runs it on its own Linux runner.".to_owned());
384+ }
385+ }
386+ if spec.contains_key("services") {
387+ note(Severity::Unsupported, Some(id), "`services` containers (such as a database) are not started on g1t yet.".to_owned());
388+ }
389+ if spec.contains_key("container") {
390+ note(Severity::Warning, Some(id), "`container`: steps run on g1t's runner image instead of that container.".to_owned());
391+ }
392+ if spec.contains_key("environment") {
393+ note(Severity::Info, Some(id), "`environment`: protection rules are not enforced on g1t yet; the job runs with the repository's secrets.".to_owned());
394+ }
395+ let (matrix, fail_fast, max_parallel) = match spec.get("strategy") {
396+ Some(Value::Object(strategy)) => (
397+ strategy.get("matrix").cloned(),
398+ strategy.get("fail-fast").and_then(Value::as_bool).unwrap_or(true),
399+ strategy.get("max-parallel").and_then(Value::as_u64).map(|n| n as u32),
400+ ),
401+ _ => (None, true, None),
402+ };
403+ if uses.as_deref().is_some_and(|uses| !uses.starts_with("./")) {
404+ note(Severity::Unsupported, Some(id), "Reusable workflows from other repositories are not called on g1t yet; ones in this repository (`./.github/workflows/…`) are.".to_owned());
405+ }
406+ jobs.push(Job {
407+ id: id.clone(),
408+ name: text(spec.get("name")),
409+ needs: texts(spec.get("needs")),
410+ condition: text(spec.get("if")),
411+ runs_on,
412+ matrix,
413+ fail_fast,
414+ max_parallel,
415+ uses,
416+ steps,
417+ raw: Value::Object(spec.clone()),
418+ });
419+ }
420+ for job in &jobs {
421+ for need in &job.needs {
422+ if !jobs.iter().any(|other| &other.id == need) {
423+ return Err(format!("Job `{}` needs `{need}`, and there is no job called that.", job.id));
424+ }
425+ }
426+ }
427+ let workflow = Workflow {
428+ name: text(root.get("name")),
429+ run_name: text(root.get("run-name")),
430+ triggers,
431+ env,
432+ concurrency,
433+ jobs,
434+ notes,
435+ raw,
436+ };
437+ if workflow.job_order().len() < workflow.jobs.len() {
438+ return Err("The jobs' `needs` go round in a circle.".to_owned());
439+ }
440+ Ok(workflow)
441+}
442+
443+/// What to say about an action g1t runs differently, if anything.
444+fn action_note(uses: &str) -> Option<(Severity, String)> {
445+ if uses.starts_with("docker://") {
446+ return Some((Severity::Unsupported, format!("`{uses}`: Docker actions do not run on g1t yet.")));
447+ }
448+ let name = uses.split('@').next().unwrap_or(uses).to_ascii_lowercase();
449+ match name.as_str() {
450+ "actions/checkout" => Some((Severity::Info, "`actions/checkout` checks out from g1t.".to_owned())),
451+ "actions/cache" | "actions/cache/restore" | "actions/cache/save" => Some((
452+ Severity::Warning,
453+ format!("`{name}`: g1t has no cache yet, so it always misses and the job does the work again."),
454+ )),
455+ "actions/upload-artifact" | "actions/download-artifact" => Some((
456+ Severity::Warning,
457+ format!("`{name}`: artifacts are kept for the run on g1t, and passed between its jobs."),
458+ )),
459+ _ => None,
460+ }
461+}
462+
463+#[cfg(test)]
464+mod tests {
465+ use super::*;
466+
467+ const CI: &str = r#"
468+name: CI
469+on:
470+ push:
471+ branches: [main]
472+ paths-ignore: ["docs/**"]
473+ pull_request:
474+ workflow_dispatch:
475+ inputs:
476+ debug:
477+ type: boolean
478+ default: false
479+ schedule:
480+ - cron: "0 3 * * *"
481+concurrency:
482+ group: ci-${{ github.ref }}
483+ cancel-in-progress: true
484+env:
485+ CARGO_TERM_COLOR: always
486+jobs:
487+ test:
488+ runs-on: ${{ matrix.os }}
489+ strategy:
490+ matrix:
491+ os: [ubuntu-latest, windows-latest]
492+ node: [18, 20]
493+ steps:
494+ - uses: actions/checkout@v4
495+ - uses: actions/setup-node@v4
496+ with:
497+ node-version: ${{ matrix.node }}
498+ - run: npm ci
499+ - name: Test
500+ run: npm test
501+ deploy:
502+ needs: test
503+ if: github.ref == 'refs/heads/main'
504+ runs-on: ubuntu-latest
505+ steps:
506+ - run: echo deploy
507+"#;
508+
509+ #[test]
510+ fn a_whole_workflow_reads() {
511+ let workflow = parse(CI).unwrap();
512+ assert_eq!(workflow.name.as_deref(), Some("CI"));
513+ assert_eq!(workflow.triggers.iter().map(|t| t.event.as_str()).collect::<Vec<_>>(), ["push", "pull_request", "workflow_dispatch", "schedule"]);
514+ let push = workflow.trigger("push").unwrap();
515+ assert!(push.branches.allows("main"));
516+ assert!(!push.branches.allows("dev"));
517+ assert!(!push.paths.allows_paths(&["docs/a.md".into()]));
518+ assert_eq!(workflow.trigger("schedule").unwrap().crons, ["0 3 * * *"]);
519+ assert!(workflow.trigger("workflow_dispatch").unwrap().inputs.contains_key("debug"));
520+ assert_eq!(workflow.concurrency.as_ref().unwrap().group, "ci-${{ github.ref }}");
521+ assert_eq!(workflow.jobs.len(), 2);
522+ assert_eq!(workflow.jobs[1].needs, ["test"]);
523+ assert_eq!(workflow.jobs[0].steps[0].title(), "Run actions/checkout@v4");
524+ assert_eq!(workflow.jobs[0].steps[2].title(), "Run npm ci");
525+ assert_eq!(workflow.jobs[0].steps[3].title(), "Test");
526+ assert_eq!(workflow.job_order(), ["test", "deploy"]);
527+ assert_eq!(workflow.env["CARGO_TERM_COLOR"], "always");
528+ }
529+
530+ #[test]
531+ fn short_forms_of_on() {
532+ let one = parse("on: push\njobs:\n a:\n runs-on: ubuntu-latest\n steps: [{ run: 'true' }]").unwrap();
533+ assert_eq!(one.triggers[0].event, "push");
534+ let list = parse("on: [push, pull_request]\njobs:\n a:\n runs-on: ubuntu-latest\n steps: [{ run: 'true' }]").unwrap();
535+ assert_eq!(list.triggers.len(), 2);
536+ let pr = list.trigger("pull_request").unwrap();
537+ assert!(pr.wants_type(Some("opened")));
538+ assert!(pr.wants_type(Some("synchronize")));
539+ assert!(!pr.wants_type(Some("closed")));
540+ let typed = parse("on:\n pull_request:\n types: [closed]\njobs:\n a:\n runs-on: ubuntu-latest\n steps: [{ run: 'true' }]").unwrap();
541+ assert!(typed.trigger("pull_request").unwrap().wants_type(Some("closed")));
542+ assert!(!typed.trigger("pull_request").unwrap().wants_type(Some("opened")));
543+ }
544+
545+ #[test]
546+ fn notes_say_what_runs_differently() {
547+ let workflow = parse(
548+ "on: [push, release]\njobs:\n win:\n runs-on: windows-latest\n services:\n db: { image: postgres }\n steps:\n - uses: actions/cache@v4\n - uses: docker://alpine\n - run: dir\n shell: pwsh",
549+ )
550+ .unwrap();
551+ let unsupported: Vec<&str> =
552+ workflow.notes.iter().filter(|n| n.severity == Severity::Unsupported).map(|n| n.message.as_str()).collect();
553+ assert!(unsupported.iter().any(|m| m.contains("`release`")));
554+ assert!(unsupported.iter().any(|m| m.contains("windows-latest")));
555+ assert!(unsupported.iter().any(|m| m.contains("services")));
556+ assert!(unsupported.iter().any(|m| m.contains("docker://alpine")));
557+ assert!(unsupported.iter().any(|m| m.contains("pwsh")));
558+ assert!(workflow.notes.iter().any(|n| n.severity == Severity::Warning && n.message.contains("actions/cache")));
559+ }
560+
561+ #[test]
562+ fn mistakes_are_explained() {
563+ let problem = |yaml: &str| parse(yaml).unwrap_err();
564+ assert!(problem("jobs: {}").contains("`on` is missing"));
565+ assert!(problem("on: push").contains("`jobs` is missing"));
566+ assert!(problem("on: push\njobs:\n a:\n runs-on: x").contains("no `steps`"));
567+ assert!(problem("on: push\njobs:\n a:\n runs-on: x\n steps: [{ name: nothing }]").contains("`uses` or `run`"));
568+ assert!(problem("on: push\njobs:\n a:\n needs: b\n runs-on: x\n steps: [{ run: x }]").contains("no job called that"));
569+ assert!(
570+ problem("on: push\njobs:\n a:\n needs: b\n runs-on: x\n steps: [{ run: x }]\n b:\n needs: a\n runs-on: x\n steps: [{ run: x }]")
571+ .contains("circle")
572+ );
573+ assert!(problem("on: push\njobs: [1]").contains("`jobs`"));
574+ assert!(problem(": : :").contains("not valid YAML"));
575+ }
576+}
+4−1
3535 pub pull_id: String,
3636 }
3737
38−/// One branch moved by a push. `after` is the commit it points to now.
38+/// One branch or tag moved by a push. `after` is the commit it points to now.
3939 #[derive(Debug, Serialize)]
4040 #[serde(rename_all = "camelCase")]
4141 pub struct GitPush {
4343 /// The full ref, such as `refs/heads/main`.
4444 #[serde(rename = "ref")]
4545 pub git_ref: String,
46+ /// Where it pointed before; absent for a new branch or tag.
47+ #[serde(skip_serializing_if = "Option::is_none")]
48+ pub before: Option<String>,
4649 pub after: String,
4750 /// Whether the ref is the repository's default branch.
4851 pub default_branch: bool,
+44−13
127127
128128 const ZERO_ID: &str = "0000000000000000000000000000000000000000";
129129 const HEADS: &str = "refs/heads/";
130+const TAGS: &str = "refs/tags/";
130131
131132 /// One ref a push asks to change.
132133 struct Command {
219220 })
220221 }
221222
222−/// The branches a push asks to move, as `(branch, new commit)`, read from
223−/// the commands at the start of a receive-pack request. Deletions and refs
224−/// that are not branches are left out.
225−fn pushed_branches(body: &[u8]) -> Vec<(String, String)> {
223+/// A branch or tag a push asks to move.
224+#[derive(Debug, PartialEq, Eq)]
225+pub struct Pushed {
226+ /// The full ref: `refs/heads/main`, `refs/tags/v1`.
227+ pub git_ref: String,
228+ /// Where it pointed before; `None` for a new ref.
229+ pub before: Option<String>,
230+ pub after: String,
231+}
232+
233+impl Pushed {
234+ pub fn branch(&self) -> Option<&str> {
235+ self.git_ref.strip_prefix(HEADS)
236+ }
237+}
238+
239+/// The branches and tags a push asks to move, read from the commands at the
240+/// start of a receive-pack request. Deletions and other refs are left out.
241+fn pushed_branches(body: &[u8]) -> Vec<Pushed> {
226242 commands(body)
227243 .0
228244 .into_iter()
229245 .filter(|command| command.new != ZERO_ID)
230− .filter_map(|Command { new, name, .. }| {
231− name.strip_prefix(HEADS)
232− .map(|branch| (branch.to_owned(), new))
246+ .filter(|command| command.name.starts_with(HEADS) || command.name.starts_with(TAGS))
247+ .map(|Command { old, new, name }| Pushed {
248+ git_ref: name,
249+ before: (old != ZERO_ID).then_some(old),
250+ after: new,
233251 })
234252 .collect()
235253 }
237255 /// The git store's answer, and what the request asked it to change.
238256 pub struct Forwarded {
239257 pub response: Response,
240− /// For a push: the branches it asks to move and the commits to move
241− /// them to. Whether each moved is for the caller to confirm.
242− pub pushed: Vec<(String, String)>,
258+ /// For a push: the branches and tags it asks to move, and the commits
259+ /// to move them to. Whether each moved is for the caller to confirm.
260+ pub pushed: Vec<Pushed>,
243261 }
244262
245263 /// What became of a git request.
298316
299317 #[cfg(test)]
300318 mod tests {
301− use super::{ZERO_ID, pushed_branches, refusal};
319+ use super::{Pushed, ZERO_ID, pushed_branches, refusal};
302320
303321 fn pkt(payload: &str) -> Vec<u8> {
304322 format!("{:04x}{payload}", payload.len() + 4).into_bytes()
322340 assert_eq!(
323341 pushed_branches(&body),
324342 [
325− ("main".to_owned(), new.to_owned()),
326− ("feature/x".to_owned(), new.to_owned()),
343+ Pushed {
344+ git_ref: "refs/heads/main".to_owned(),
345+ before: Some(old.to_owned()),
346+ after: new.to_owned()
347+ },
348+ Pushed {
349+ git_ref: "refs/heads/feature/x".to_owned(),
350+ before: None,
351+ after: new.to_owned()
352+ },
353+ Pushed {
354+ git_ref: "refs/tags/v1".to_owned(),
355+ before: None,
356+ after: new.to_owned()
357+ },
327358 ]
328359 );
329360 }
+43−12
339339 })
340340 .await?;
341341 if let Some(head) = pushed {
342− self.publish_push(&repo, &repo.default_branch, &head, None)
342+ self.publish_push(
343+ &repo,
344+ &format!("refs/heads/{}", repo.default_branch),
345+ None,
346+ &head,
347+ None,
348+ )
343349 .await?;
344350 }
345351 Ok(Outcome::Ok(repo))
719725 format!("{branch} could not be updated: {reason}"),
720726 ));
721727 }
722− self.publish_push(&target, branch, &new, Some(a.actor.id))
728+ self.publish_push(
729+ &target,
730+ &format!("refs/heads/{branch}"),
731+ old.as_deref(),
732+ &new,
733+ Some(a.actor.id),
734+ )
723735 .await?;
724736 Ok(Outcome::Ok(Landed {
725737 commit: new,
791803 }))
792804 }
793805
794− /// Reports that `branch` of `repo` now points to `after`.
806+ /// Reports that `git_ref` of `repo` (a full ref) now points to `after`.
795807 async fn publish_push(
796808 &self,
797809 repo: &Repo,
798− branch: &str,
810+ git_ref: &str,
811+ before: Option<&str>,
799812 after: &str,
800813 actor: Option<String>,
801814 ) -> Result<()> {
806819 actor,
807820 data: GitPush {
808821 repo_id: repo.id.clone(),
809− git_ref: format!("refs/heads/{branch}"),
822+ git_ref: git_ref.to_owned(),
823+ before: before.map(str::to_owned),
810824 after: after.to_owned(),
811− default_branch: branch == repo.default_branch,
825+ default_branch: git_ref.strip_prefix("refs/heads/")
826+ == Some(repo.default_branch.as_str()),
812827 },
813828 })
814829 .await
850865 if accepted && let Some(repo) = self.registry.by_path(&git.path).await? {
851866 let stored = self.store.open(&store_key(&repo)).await?;
852867 let actor = viewer.map(|user: User| user.id);
853− for (branch, pushed) in &forwarded.pushed {
868+ for pushed in &forwarded.pushed {
854869 // The store can refuse one ref and accept another, so each
855− // is checked against where the branch actually is.
856− let head = stored.log(branch, 1).await?;
857− if head.first().is_some_and(|commit| commit.hash == *pushed) {
858− self.publish_push(&repo, branch, pushed, actor.clone())
859− .await?;
870+ // branch is checked against where it actually is. A tag the
871+ // store cannot read back is taken as pushed.
872+ let moved = match pushed.branch() {
873+ Some(branch) => stored
874+ .log(branch, 1)
875+ .await?
876+ .first()
877+ .is_some_and(|commit| commit.hash == pushed.after),
878+ None => stored.log(&pushed.git_ref, 1).await.map_or(true, |head| {
879+ head.first().is_none_or(|commit| commit.hash == pushed.after)
880+ }),
881+ };
882+ if moved {
883+ self.publish_push(
884+ &repo,
885+ &pushed.git_ref,
886+ pushed.before.as_deref(),
887+ &pushed.after,
888+ actor.clone(),
889+ )
890+ .await?;
860891 }
861892 }
862893 }