mirror of
https://gitea.com/gitea/runner.git
synced 2026-08-26 13:57:46 +00:00
fix: mask secrets on every path they leave a job (#1188)
A secret in a matrix value reached the log in the clear:
```yaml
strategy:
matrix:
include: "${{ github.token }}"
```
Chasing that one route is pointless, so this masks every sink a secret leaves a job by: the uploaded log rows and the on-disk `job.log`, both through one choke point in `appendLogRow`; the runner's own log, which is where planning errors like that one land with no job logger in reach; the job logger's stdout under debug logging; job summaries; job outputs; and the job name that becomes a container name.
Values the runner knows but the job never declared, the proxy password and the task token, are hidden the same way. Masks apply longest first, since `strings.Replacer` matches in argument order and one secret prefixing another would otherwise mask the prefix and print the rest.
### What changes for users
An output whose value carries a secret is skipped with a warning instead of sent, matching GitHub. Output that showed a secret now shows `***`. `ACTIONS_STEP_DEBUG` and `ACTIONS_RUNNER_DEBUG` are never masked, also matching GitHub, so an output of `true` still reaches the jobs that need it.
Each fix has a test that fails without it.
Reviewed-on: https://gitea.com/gitea/runner/pulls/1188
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
@@ -356,3 +356,25 @@ on:
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestJobNameMasksSecrets(t *testing.T) {
|
||||
workflow, err := model.ReadWorkflow(strings.NewReader(`
|
||||
jobs:
|
||||
a:
|
||||
name: deploy ${{ secrets.A }}
|
||||
b:
|
||||
name: deploy ${{ secrets.B }}
|
||||
`))
|
||||
require.NoError(t, err)
|
||||
|
||||
runner := &runnerImpl{config: &Config{Secrets: map[string]string{"A": "s3cr3t-a", "B": "s3cr3t-b"}}}
|
||||
containerName := func(jobID string) string {
|
||||
rc := runner.newRunContext(t.Context(), &model.Run{JobID: jobID, Workflow: workflow}, nil)
|
||||
assert.NotContains(t, rc.Name, "s3cr3t")
|
||||
return rc.jobContainerName()
|
||||
}
|
||||
|
||||
a, b := containerName("a"), containerName("b")
|
||||
assert.NotContains(t, a, "s3cr3t") // it reaches the container name, which no log masker covers
|
||||
assert.NotEqual(t, a, b) // masking the name must not collapse two jobs onto one container
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user