mirror of
https://gitea.com/gitea/act_runner.git
synced 2026-08-06 00:44:22 +02:00
feat: gate set-env/add-path and render annotation locations (#1109)
`::set-env::` and `::add-path::` let a step rewrite the environment of every later step from its own output, which the runner honoured silently. They are now refused, as GitHub has done since 2020, and `ACTIONS_ALLOW_UNSECURE_COMMANDS` opts back in per step or job. Support for that variable is new here too, and is the only opt-in, matching GitHub rather than adding a runner config key on top. Annotations keep their source location: Gitea has no annotation store and its web UI strips command properties, so `::error file=main.go,line=12::msg` is rendered as `::error::main.go:12: msg`. `DEVELOPMENT.md` writes down the log line encoding rules this relies on. --------- Co-authored-by: silverwind <me@silverwind.io> Reviewed-on: https://gitea.com/gitea/runner/pulls/1109 Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com> Co-authored-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -6,6 +6,7 @@ package runner
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
@@ -45,17 +46,24 @@ func (rc *RunContext) commandHandler(ctx context.Context) common.LineHandler {
|
||||
return true
|
||||
}
|
||||
|
||||
if resumeCommand != "" && command != resumeCommand {
|
||||
if resumeCommand != "" {
|
||||
// There should not be any emojis in the log output for Gitea.
|
||||
// The code in the switch statement is the same.
|
||||
// Return true (not false) so the line still reaches the raw_output
|
||||
// log handler; otherwise everything between ::stop-commands:: and
|
||||
// its end token is silently dropped from the step log.
|
||||
logger.Infof("%s", line)
|
||||
// Resumed here rather than from the switch, because the end token is arbitrary
|
||||
// and a token naming a real command would otherwise never resume.
|
||||
if command == resumeCommand {
|
||||
resumeCommand = ""
|
||||
}
|
||||
return true
|
||||
}
|
||||
arg = UnescapeCommandData(arg)
|
||||
kvPairs = unescapeKvPairs(kvPairs)
|
||||
if (command == "set-env" || command == "add-path") && rc.refuseUnsecureCommand(ctx, command) {
|
||||
return true
|
||||
}
|
||||
switch command {
|
||||
case "set-env":
|
||||
rc.setEnv(ctx, kvPairs, arg)
|
||||
@@ -63,27 +71,20 @@ func (rc *RunContext) commandHandler(ctx context.Context) common.LineHandler {
|
||||
rc.setOutput(ctx, kvPairs, arg)
|
||||
case "add-path":
|
||||
rc.addPath(ctx, arg)
|
||||
case "debug":
|
||||
logger.Infof("%s", line)
|
||||
case "warning":
|
||||
logger.Infof("%s", line)
|
||||
case "error":
|
||||
logger.Infof("%s", line)
|
||||
case "add-mask":
|
||||
rc.AddMask(arg)
|
||||
logger.Infof("%s", "***")
|
||||
// The raw line is still forwarded, carrying the secret: that is how the reporter
|
||||
// learns the mask, and it drops the row rather than writing it out.
|
||||
case "stop-commands":
|
||||
resumeCommand = arg
|
||||
logger.Infof("%s", line)
|
||||
case resumeCommand:
|
||||
resumeCommand = ""
|
||||
logger.Infof("%s", line)
|
||||
case "save-state":
|
||||
logger.Infof("%s", line)
|
||||
rc.saveState(ctx, kvPairs, arg)
|
||||
case "add-matcher":
|
||||
logger.Infof("%s", line)
|
||||
default:
|
||||
// ::debug::, ::error::, ::warning::, ::add-matcher:: and anything unrecognised are
|
||||
// passed through for the reporter and Gitea's web UI to render.
|
||||
logger.Infof("%s", line)
|
||||
}
|
||||
|
||||
@@ -92,6 +93,52 @@ func (rc *RunContext) commandHandler(ctx context.Context) common.LineHandler {
|
||||
}
|
||||
}
|
||||
|
||||
const allowUnsecureCommandsVar = "ACTIONS_ALLOW_UNSECURE_COMMANDS"
|
||||
|
||||
// refuseUnsecureCommand reports whether a deprecated ::set-env:: or ::add-path:: command must
|
||||
// not run, recording the error that fails the step. GitHub disabled both because a step that
|
||||
// echoes untrusted content can use them to set NODE_OPTIONS or PATH for every later step.
|
||||
func (rc *RunContext) refuseUnsecureCommand(ctx context.Context, command string) bool {
|
||||
if rc.allowUnsecureCommandsOptIn() {
|
||||
return false
|
||||
}
|
||||
|
||||
// The step executor logs the failure itself, so keep this line's wording distinct.
|
||||
common.Logger(ctx).WithField(rawOutputField, true).Errorf("##[error]%s", EscapeCommandData(fmt.Sprintf(
|
||||
"The `%s` command is disabled: it can set the environment of every later step from untrusted output. "+
|
||||
"Write to $GITHUB_ENV or $GITHUB_PATH instead, or set ACTIONS_ALLOW_UNSECURE_COMMANDS to allow it",
|
||||
command)))
|
||||
|
||||
rc.unsecureCommandMu.Lock()
|
||||
defer rc.unsecureCommandMu.Unlock()
|
||||
if rc.unsecureCommandErr == nil {
|
||||
rc.unsecureCommandErr = fmt.Errorf("the `%s` workflow command is disabled", command)
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
// allowUnsecureCommandsOptIn reports whether the workflow itself asked for the deprecated
|
||||
// commands, from any env scope, as it can on GitHub.
|
||||
func (rc *RunContext) allowUnsecureCommandsOptIn() bool {
|
||||
return isTruthyEnv(rc.currentStepEnv()[allowUnsecureCommandsVar]) ||
|
||||
isTruthyEnv(rc.Env[allowUnsecureCommandsVar]) ||
|
||||
isTruthyEnv(rc.GlobalEnv[allowUnsecureCommandsVar])
|
||||
}
|
||||
|
||||
// isTruthyEnv mirrors GitHub's bool.TryParse: only "true", in any casing.
|
||||
func isTruthyEnv(v string) bool {
|
||||
return strings.EqualFold(strings.TrimSpace(v), "true")
|
||||
}
|
||||
|
||||
// takeUnsecureCommandError returns and clears the error left by a refused command.
|
||||
func (rc *RunContext) takeUnsecureCommandError() error {
|
||||
rc.unsecureCommandMu.Lock()
|
||||
defer rc.unsecureCommandMu.Unlock()
|
||||
err := rc.unsecureCommandErr
|
||||
rc.unsecureCommandErr = nil
|
||||
return err
|
||||
}
|
||||
|
||||
func (rc *RunContext) setEnv(ctx context.Context, kvPairs map[string]string, arg string) {
|
||||
name := kvPairs["name"]
|
||||
common.Logger(ctx).Infof("::set-env:: %s=%s", name, arg)
|
||||
@@ -161,9 +208,9 @@ var (
|
||||
commandPropertyUnescaper = strings.NewReplacer("%25", "%", "%0D", "\r", "%0A", "\n", "%3A", ":", "%2C", ",")
|
||||
)
|
||||
|
||||
// escapeCommandData encodes the data part of a "::cmd::" or "##[cmd]" line the runner writes itself,
|
||||
// EscapeCommandData encodes the data part of a "::cmd::" or "##[cmd]" line the runner writes itself,
|
||||
// so the log renderer decodes it back. Lines forwarded from step output are already escaped.
|
||||
func escapeCommandData(arg string) string {
|
||||
func EscapeCommandData(arg string) string {
|
||||
return commandDataEscaper.Replace(arg)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user