Compare commits

...

4 Commits

Author SHA1 Message Date
bircni
4034634340 fix 2026-07-03 22:09:38 +02:00
bircni
4691a92ea8 fix: checkout pull_request_target head commit
For pull_request_target tasks, use the pull request head SHA from the event payload as the default checkout ref so actions/checkout resolves the submitted PR content instead of the base branch tip.

Fixes: https://gitea.com/gitea/runner/issues/563

Co-Authored-By: GPT-5 Codex <codex@openai.com>
2026-07-03 21:58:37 +02:00
silverwind
0ee4643d4a fix: install nftables in dind images to silence nft cleanup errors (#1064)
Fixes: https://gitea.com/gitea/runner/issues/1061
Related: https://github.com/moby/moby/pull/52886

Docker 29.6.0 changed `dockerd` to shell out to the external `nft` binary for firewall-rule cleanup instead of linking `libnftables` (release note: *"Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the `nft` command instead."*). The upstream `docker:dind` image only ships `iptables`/`ip6tables`, so `dockerd` logs `failed to find nft tool` on startup and shutdown.

Networking is unaffected (default firewall backend is still iptables), but the errors are noisy. Install `nftables` in both dind variants to provide the binary.

*PR authored by Claude (Opus 4.8).*Reviewed-on: https://gitea.com/gitea/runner/pulls/1064
Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-07-03 08:23:12 +00:00
Renovate Bot
e774003c18 chore(deps): update docker docker tag to v29.6.1 (#1063)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| docker | stage | patch | `29.6.0-dind-rootless` → `29.6.1-dind-rootless` |
| docker | stage | patch | `29.6.0-dind` → `29.6.1-dind` |

Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
2026-07-02 08:22:37 +00:00
3 changed files with 102 additions and 4 deletions

View File

@@ -17,14 +17,14 @@ RUN make clean && make build
### DIND VARIANT ### DIND VARIANT
# #
# #
FROM docker:29.6.0-dind AS dind FROM docker:29.6.1-dind AS dind
ARG VERSION=dev ARG VERSION=dev
LABEL org.opencontainers.image.source="https://gitea.com/gitea/runner" LABEL org.opencontainers.image.source="https://gitea.com/gitea/runner"
LABEL org.opencontainers.image.version="${VERSION}" LABEL org.opencontainers.image.version="${VERSION}"
RUN apk add --no-cache s6 bash git tzdata RUN apk add --no-cache s6 bash git tzdata nftables
COPY --from=builder /opt/src/runner/gitea-runner /usr/local/bin/gitea-runner COPY --from=builder /opt/src/runner/gitea-runner /usr/local/bin/gitea-runner
COPY scripts/run.sh /usr/local/bin/run.sh COPY scripts/run.sh /usr/local/bin/run.sh
@@ -37,7 +37,7 @@ ENTRYPOINT ["s6-svscan","/etc/s6"]
### DIND-ROOTLESS VARIANT ### DIND-ROOTLESS VARIANT
# #
# #
FROM docker:29.6.0-dind-rootless AS dind-rootless FROM docker:29.6.1-dind-rootless AS dind-rootless
ARG VERSION=dev ARG VERSION=dev
@@ -45,7 +45,7 @@ LABEL org.opencontainers.image.source="https://gitea.com/gitea/runner"
LABEL org.opencontainers.image.version="${VERSION}" LABEL org.opencontainers.image.version="${VERSION}"
USER root USER root
RUN apk add --no-cache s6 bash git tzdata RUN apk add --no-cache s6 bash git tzdata nftables
COPY --from=builder /opt/src/runner/gitea-runner /usr/local/bin/gitea-runner COPY --from=builder /opt/src/runner/gitea-runner /usr/local/bin/gitea-runner
COPY scripts/run.sh /usr/local/bin/run.sh COPY scripts/run.sh /usr/local/bin/run.sh

View File

@@ -366,6 +366,7 @@ func (r *Runner) run(ctx context.Context, task *runnerv1.Task, reporter *report.
} else if t := task.Secrets["GITHUB_TOKEN"]; t != "" { } else if t := task.Secrets["GITHUB_TOKEN"]; t != "" {
preset.Token = t preset.Token = t
} }
applyPullRequestTargetCheckoutContext(preset)
if actionsIDTokenRequestURL := taskContext["actions_id_token_request_url"].GetStringValue(); actionsIDTokenRequestURL != "" { if actionsIDTokenRequestURL := taskContext["actions_id_token_request_url"].GetStringValue(); actionsIDTokenRequestURL != "" {
envs["ACTIONS_ID_TOKEN_REQUEST_URL"] = actionsIDTokenRequestURL envs["ACTIONS_ID_TOKEN_REQUEST_URL"] = actionsIDTokenRequestURL
@@ -574,6 +575,41 @@ func postInternalCache(url, secret string, body map[string]string) error {
return nil return nil
} }
func applyPullRequestTargetCheckoutContext(preset *model.GithubContext) {
if preset == nil || preset.EventName != "pull_request_target" {
return
}
headSHA := nestedString(preset.Event, "pull_request", "head", "sha")
if headSHA == "" {
return
}
preset.Sha = headSHA
preset.Ref = headSHA
if headRef := nestedString(preset.Event, "pull_request", "head", "ref"); headRef != "" {
preset.HeadRef = headRef
preset.RefName = headRef
}
}
func nestedString(m map[string]any, keys ...string) string {
var current any = m
for _, key := range keys {
next, ok := current.(map[string]any)
if !ok {
return ""
}
current, ok = next[key]
if !ok {
return ""
}
}
value := current.(string)
if value == "" {
return ""
}
return value
}
func (r *Runner) RunningCount() int64 { func (r *Runner) RunningCount() int64 {
return r.runningCount.Load() return r.runningCount.Load()
} }

View File

@@ -7,6 +7,7 @@ import (
"context" "context"
"testing" "testing"
"gitea.com/gitea/runner/act/model"
clientmocks "gitea.com/gitea/runner/internal/pkg/client/mocks" clientmocks "gitea.com/gitea/runner/internal/pkg/client/mocks"
"gitea.com/gitea/runner/internal/pkg/config" "gitea.com/gitea/runner/internal/pkg/config"
"gitea.com/gitea/runner/internal/pkg/ver" "gitea.com/gitea/runner/internal/pkg/ver"
@@ -92,6 +93,67 @@ func TestNewRunnerInitializesLabelsAndEnvironment(t *testing.T) {
require.Nil(t, r.cacheHandler) require.Nil(t, r.cacheHandler)
} }
func TestApplyPullRequestTargetCheckoutContextUsesHeadSHA(t *testing.T) {
preset := &model.GithubContext{
EventName: "pull_request_target",
Sha: "base-sha",
Ref: "refs/heads/main",
RefName: "main",
HeadRef: "feature",
Event: map[string]any{
"pull_request": map[string]any{
"head": map[string]any{
"sha": "head-sha",
"ref": "contributor-branch",
},
},
},
}
applyPullRequestTargetCheckoutContext(preset)
require.Equal(t, "head-sha", preset.Sha)
require.Equal(t, "head-sha", preset.Ref)
require.Equal(t, "contributor-branch", preset.RefName)
require.Equal(t, "contributor-branch", preset.HeadRef)
}
func TestApplyPullRequestTargetCheckoutContextNoOpsWithoutHeadSHA(t *testing.T) {
preset := &model.GithubContext{
EventName: "pull_request_target",
Sha: "base-sha",
Ref: "refs/heads/main",
RefName: "main",
Event: map[string]any{},
}
applyPullRequestTargetCheckoutContext(preset)
require.Equal(t, "base-sha", preset.Sha)
require.Equal(t, "refs/heads/main", preset.Ref)
require.Equal(t, "main", preset.RefName)
}
func TestApplyPullRequestTargetCheckoutContextNoOpsForOtherEvents(t *testing.T) {
preset := &model.GithubContext{
EventName: "pull_request",
Sha: "merge-sha",
Ref: "refs/pull/1/merge",
Event: map[string]any{
"pull_request": map[string]any{
"head": map[string]any{
"sha": "head-sha",
},
},
},
}
applyPullRequestTargetCheckoutContext(preset)
require.Equal(t, "merge-sha", preset.Sha)
require.Equal(t, "refs/pull/1/merge", preset.Ref)
}
func taskWithDefaultActionsURL(url string) *runnerv1.Task { func taskWithDefaultActionsURL(url string) *runnerv1.Task {
return &runnerv1.Task{ return &runnerv1.Task{
Context: &structpb.Struct{ Context: &structpb.Struct{