mirror of
https://gitea.com/gitea/act_runner.git
synced 2026-08-06 17:04:22 +02:00
Compare commits
2 Commits
3c4bcf3ebf
...
v2.0.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b7f6b6d90a | ||
|
|
cdcea87a45 |
@@ -6,7 +6,9 @@ package runner
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"crypto/sha256"
|
||||||
"embed"
|
"embed"
|
||||||
|
"encoding/hex"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
@@ -272,6 +274,36 @@ func removeGitIgnore(ctx context.Context, directory string) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// dockerActionImageTag derives the local docker image tag used when an action
|
||||||
|
// is built from a Dockerfile.
|
||||||
|
//
|
||||||
|
// For Gitea: a local action (`uses: ./` or `uses: ./path`) has an actionName
|
||||||
|
// that is the workspace-relative path of the action. That path is identical
|
||||||
|
// across repositories (e.g. "./" for a self-referencing action), so without
|
||||||
|
// namespacing, every repository's local docker action would build and reuse the
|
||||||
|
// same `act-dockeraction:latest` image on a shared docker daemon. A subsequent
|
||||||
|
// repository would then silently run the image built for an earlier one.
|
||||||
|
// Including the repository keeps the tag stable for caching within a repository
|
||||||
|
// while preventing cross-repository collisions.
|
||||||
|
// See https://gitea.com/gitea/runner/issues/1039.
|
||||||
|
func dockerActionImageTag(repository, actionName string, localAction bool) string {
|
||||||
|
name := actionName
|
||||||
|
if localAction {
|
||||||
|
name = path.Join(repository, actionName)
|
||||||
|
}
|
||||||
|
// The human-readable name is sanitized by collapsing every non-alphanumeric character to "-".
|
||||||
|
sanitized := regexp.MustCompile("[^a-zA-Z0-9]").ReplaceAllString(name, "-")
|
||||||
|
if localAction {
|
||||||
|
// For local actions a short hash of the raw repository and action path is appended so the tag stays unique per repository.
|
||||||
|
sum := sha256.Sum256([]byte(repository + "\x00" + actionName))
|
||||||
|
sanitized += "-" + hex.EncodeToString(sum[:])[:12]
|
||||||
|
}
|
||||||
|
// "-dockeraction" ensures that "./", "./test " won't get converted to "act-:latest", "act-test-:latest" which are invalid docker image names
|
||||||
|
image := fmt.Sprintf("%s-dockeraction:%s", sanitized, "latest")
|
||||||
|
image = "act-" + strings.TrimLeft(image, "-")
|
||||||
|
return strings.ToLower(image)
|
||||||
|
}
|
||||||
|
|
||||||
// TODO: break out parts of function to reduce complexicity
|
// TODO: break out parts of function to reduce complexicity
|
||||||
func execAsDocker(ctx context.Context, step actionStep, actionName, actionDir, basedir string, localAction bool) error {
|
func execAsDocker(ctx context.Context, step actionStep, actionName, actionDir, basedir string, localAction bool) error {
|
||||||
logger := common.Logger(ctx)
|
logger := common.Logger(ctx)
|
||||||
@@ -286,10 +318,7 @@ func execAsDocker(ctx context.Context, step actionStep, actionName, actionDir, b
|
|||||||
// Apply forcePull only for prebuild docker images
|
// Apply forcePull only for prebuild docker images
|
||||||
forcePull = rc.Config.ForcePull
|
forcePull = rc.Config.ForcePull
|
||||||
} else {
|
} else {
|
||||||
// "-dockeraction" enshures that "./", "./test " won't get converted to "act-:latest", "act-test-:latest" which are invalid docker image names
|
image = dockerActionImageTag(step.getGithubContext(ctx).Repository, actionName, localAction)
|
||||||
image = fmt.Sprintf("%s-dockeraction:%s", regexp.MustCompile("[^a-zA-Z0-9]").ReplaceAllString(actionName, "-"), "latest")
|
|
||||||
image = "act-" + strings.TrimLeft(image, "-")
|
|
||||||
image = strings.ToLower(image)
|
|
||||||
contextDir, fileName := filepath.Split(filepath.Join(basedir, action.Runs.Image))
|
contextDir, fileName := filepath.Split(filepath.Join(basedir, action.Runs.Image))
|
||||||
|
|
||||||
anyArchExists, err := ContainerImageExistsLocally(ctx, image, "any")
|
anyArchExists, err := ContainerImageExistsLocally(ctx, image, "any")
|
||||||
|
|||||||
@@ -455,3 +455,50 @@ func TestExecAsDockerHoldsCloneLockForRemoteUncached(t *testing.T) {
|
|||||||
t.Fatal("execAsDocker did not return after inner was released and ctx was canceled")
|
t.Fatal("execAsDocker did not return after inner was released and ctx was canceled")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestDockerActionImageTag(t *testing.T) {
|
||||||
|
// Remote actions already carry a unique, ref-scoped actionName (the uses
|
||||||
|
// hash), so the tag must be left untouched for backwards compatibility.
|
||||||
|
assert.Equal(t,
|
||||||
|
"act-abc123-dockeraction:latest",
|
||||||
|
dockerActionImageTag("owner/repo", "abc123", false),
|
||||||
|
)
|
||||||
|
|
||||||
|
// Local actions keep a human-readable, repository-namespaced prefix and gain a short hash suffix that makes the tag unique per (repository, actionName).
|
||||||
|
// See https://gitea.com/gitea/runner/issues/1039.
|
||||||
|
assert.Equal(t,
|
||||||
|
"act-owner-repo-baca2daaa2fe-dockeraction:latest",
|
||||||
|
dockerActionImageTag("owner/repo", "./", true),
|
||||||
|
)
|
||||||
|
assert.Equal(t,
|
||||||
|
"act-owner-repo-sub-e847b61255a8-dockeraction:latest",
|
||||||
|
dockerActionImageTag("owner/repo", "./sub", true),
|
||||||
|
)
|
||||||
|
|
||||||
|
// Sanitizing every non-alphanumeric character to "-" is lossy, so distinct inputs can collapse to the same readable prefix.
|
||||||
|
// The hash suffix must keep such cases apart, otherwise an image built for one repository is reused for another.
|
||||||
|
collisions := [][2]struct {
|
||||||
|
repoName string
|
||||||
|
actionName string
|
||||||
|
}{
|
||||||
|
// Two different repositories, both `uses: ./`: "a/b-c" and "a-b/c" both sanitize to "a-b-c".
|
||||||
|
{{"a/b-c", "./"}, {"a-b/c", "./"}},
|
||||||
|
// A repository's root action vs another repository's sub-path action:
|
||||||
|
// "owner/repo-a" + "./" and "owner/repo" + "./a" both sanitize to "owner-repo-a".
|
||||||
|
{{"owner/repo-a", "./"}, {"owner/repo", "./a"}},
|
||||||
|
}
|
||||||
|
for _, c := range collisions {
|
||||||
|
assert.NotEqual(t,
|
||||||
|
dockerActionImageTag(c[0].repoName, c[0].actionName, true),
|
||||||
|
dockerActionImageTag(c[1].repoName, c[1].actionName, true),
|
||||||
|
"local docker action tags must differ for %q/%q vs %q/%q",
|
||||||
|
c[0].repoName, c[0].actionName, c[1].repoName, c[1].actionName,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Distinct local actions within the same repository keep distinct tags.
|
||||||
|
assert.NotEqual(t,
|
||||||
|
dockerActionImageTag("owner/repo", "./", true),
|
||||||
|
dockerActionImageTag("owner/repo", "./sub", true),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|||||||
@@ -114,9 +114,18 @@ func (sar *stepActionRemote) prepareActionExecutor() common.Executor {
|
|||||||
|
|
||||||
actionDir := fmt.Sprintf("%s/%s", sar.RunContext.ActionCacheDir(), sar.Step.UsesHash())
|
actionDir := fmt.Sprintf("%s/%s", sar.RunContext.ActionCacheDir(), sar.Step.UsesHash())
|
||||||
defaultActionURL := sar.RunContext.Config.DefaultActionURL()
|
defaultActionURL := sar.RunContext.Config.DefaultActionURL()
|
||||||
token := getGitCloneToken(sar.getRunContext().Config, sar.remoteAction.CloneURL(defaultActionURL))
|
// For Gitea
|
||||||
|
// A composite RunContext nils Config.Secrets, so getGitCloneToken would yield an
|
||||||
|
// empty token and clone the action anonymously (401 against the authenticated
|
||||||
|
// instance). github.Token survives the composite config copy and matches the
|
||||||
|
// top-level token; keep the shouldCloneURLUseToken host gate to avoid leaking it.
|
||||||
|
cloneURL := sar.remoteAction.CloneURL(defaultActionURL)
|
||||||
|
token := ""
|
||||||
|
if shouldCloneURLUseToken(sar.RunContext.Config.GitHubInstance, cloneURL) {
|
||||||
|
token = github.Token
|
||||||
|
}
|
||||||
gitClone := stepActionRemoteNewCloneExecutor(git.NewGitCloneExecutorInput{
|
gitClone := stepActionRemoteNewCloneExecutor(git.NewGitCloneExecutorInput{
|
||||||
URL: sar.remoteAction.CloneURL(defaultActionURL),
|
URL: cloneURL,
|
||||||
Ref: sar.remoteAction.Ref,
|
Ref: sar.remoteAction.Ref,
|
||||||
Dir: actionDir,
|
Dir: actionDir,
|
||||||
Token: token,
|
Token: token,
|
||||||
|
|||||||
@@ -838,3 +838,83 @@ func Test_safeFilename(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Regression: a nested action in a composite cloned anonymously (401) because the
|
||||||
|
// composite RunContext nils Config.Secrets. The token must come from github.Token,
|
||||||
|
// which survives the config copy; the host gate must still withhold it cross-host.
|
||||||
|
func TestStepActionRemoteCloneTokenSurvivesNilSecrets(t *testing.T) {
|
||||||
|
const wantToken = "job-token"
|
||||||
|
|
||||||
|
table := []struct {
|
||||||
|
name string
|
||||||
|
gitHubInstance string
|
||||||
|
defaultActionInstance string
|
||||||
|
wantCloneToken string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "same host forwards token despite nil secrets",
|
||||||
|
gitHubInstance: "gitea.example.com",
|
||||||
|
wantCloneToken: wantToken,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "foreign host is not given the token",
|
||||||
|
gitHubInstance: "gitea.example.com",
|
||||||
|
defaultActionInstance: "github.com",
|
||||||
|
wantCloneToken: "",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range table {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
var capturedToken string
|
||||||
|
origStepAtionRemoteNewCloneExecutor := stepActionRemoteNewCloneExecutor
|
||||||
|
stepActionRemoteNewCloneExecutor = func(input git.NewGitCloneExecutorInput) common.Executor {
|
||||||
|
capturedToken = input.Token
|
||||||
|
return func(ctx context.Context) error { return nil }
|
||||||
|
}
|
||||||
|
defer (func() {
|
||||||
|
stepActionRemoteNewCloneExecutor = origStepAtionRemoteNewCloneExecutor
|
||||||
|
})()
|
||||||
|
|
||||||
|
sarm := &stepActionRemoteMocks{}
|
||||||
|
sar := &stepActionRemote{
|
||||||
|
Step: &model.Step{Uses: "org/repo@v1"},
|
||||||
|
RunContext: &RunContext{
|
||||||
|
Config: &Config{
|
||||||
|
GitHubInstance: tt.gitHubInstance,
|
||||||
|
DefaultActionInstance: tt.defaultActionInstance,
|
||||||
|
ActionCacheDir: "/tmp/test-cache",
|
||||||
|
// Mirrors the state of a composite RunContext: job secrets are
|
||||||
|
// stripped, but the job token is still reachable via Config.Token.
|
||||||
|
Secrets: nil,
|
||||||
|
Token: wantToken,
|
||||||
|
},
|
||||||
|
Run: &model.Run{
|
||||||
|
JobID: "1",
|
||||||
|
Workflow: &model.Workflow{
|
||||||
|
Jobs: map[string]*model.Job{"1": {}},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
StepResults: map[string]*model.StepResult{},
|
||||||
|
},
|
||||||
|
readAction: sarm.readAction,
|
||||||
|
}
|
||||||
|
sar.RunContext.ExprEval = sar.RunContext.NewExpressionEvaluator(ctx)
|
||||||
|
|
||||||
|
suffixMatcher := func(suffix string) any {
|
||||||
|
return mock.MatchedBy(func(actionDir string) bool {
|
||||||
|
return strings.HasSuffix(actionDir, suffix)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
sarm.On("readAction", sar.Step, suffixMatcher(sar.Step.UsesHash()), "", mock.Anything, mock.Anything).Return(&model.Action{}, nil)
|
||||||
|
|
||||||
|
err := sar.prepareActionExecutor()(ctx)
|
||||||
|
require.NoError(t, err)
|
||||||
|
assert.Equal(t, tt.wantCloneToken, capturedToken)
|
||||||
|
|
||||||
|
sarm.AssertExpectations(t)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user