mirror of
https://gitea.com/gitea/runner.git
synced 2026-08-27 22:37:46 +00:00
12dc9d26a2
Fixes 51 bugs discovered via comparison with `actions/runner`. Every fix has test coverage.
### Secrets
- A short secret registered no shifted-base64 form, so `base64("user:$TOKEN")` printed in the clear
- Encoded forms came only from the whole trimmed value, missing padded and per-line spellings
- Masks split only on `\n`, so `::add-mask::a%0Db` registered neither half
- Adds XML, expression-string and quote-trimming encoders
### Workflow commands
- Split at the last `::` or `]` rather than the first, so `::add-mask::a::b` registered no mask
- A command on the last line without a newline was ignored, and `::ADD-MASK::` did nothing
- `##[...]` did not decode `%3B`/`%5D`, properties lost anything after a second `=`
- `$GITHUB_ENV` and `::set-env::` now refuse `NODE_OPTIONS`
### Status
- `continue-on-error` reported failed, a cancelled job reported success, an `if:` error reported cancelled
- File commands ran after `continue-on-error`, failing the job while the step stayed green
- A bad job output aborted the whole run instead of that job
### Steps and actions
- `${{ matrix.* }}` and `${{ strategy.* }}` were empty inside composite actions
- Composite inputs leaked into nested actions as `INPUT_*`, `with:` matched case-sensitively, `pre` failures were dropped
- Docker actions dropped `runs.env` when the caller passed `with: args:`, and caller `args`/`entrypoint` beat the manifest
- An implicit shell ran with `pipefail`, a `shell:` without `{0}` passed without running
- `container.env` overrode job env and every `$GITHUB_ENV` write, heredocs lost leading blank lines, `$GITHUB_PATH` was not BOM-decoded
Written by Claude Opus 5.
Reviewed-on: https://gitea.com/gitea/runner/pulls/1194
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: silverwind <me@silverwind.io>
303 lines
8.7 KiB
Go
303 lines
8.7 KiB
Go
// Copyright 2022 The Gitea Authors. All rights reserved.
|
|
// Copyright 2020 The nektos/act Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package runner
|
|
|
|
import (
|
|
"bytes"
|
|
"context"
|
|
"io"
|
|
"os"
|
|
"testing"
|
|
|
|
"gitea.com/gitea/runner/act/common"
|
|
|
|
"gitea.dev/actionslib/pkg/model"
|
|
"github.com/sirupsen/logrus/hooks/test"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// unsecureRC opts into ::set-env:: and ::add-path::, which are refused without it.
|
|
func unsecureRC() *RunContext {
|
|
return &RunContext{Env: map[string]string{allowUnsecureCommandsVar: "true"}}
|
|
}
|
|
|
|
func TestSetEnv(t *testing.T) {
|
|
a := assert.New(t)
|
|
logger, hook := test.NewNullLogger()
|
|
ctx := common.WithLogger(context.Background(), logger)
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
handler("::set-env name=x::valz\n")
|
|
a.Equal("valz", rc.Env["x"])
|
|
handler("::SET-ENV name=NODE_OPTIONS::--require command.js\n")
|
|
rc.setEnvFile(ctx, map[string]string{"name": "node_options"}, "--require env.js")
|
|
a.NotContains(rc.Env, "NODE_OPTIONS")
|
|
a.NotContains(rc.Env, "node_options")
|
|
entries := hook.AllEntries()
|
|
require.Len(t, entries, 3)
|
|
a.Equal("##[error]Can't update NODE_OPTIONS environment variable using ::set-env:: command.", entries[1].Message)
|
|
a.Equal("##[error]Can't store NODE_OPTIONS output parameter using '$GITHUB_ENV' command.", entries[2].Message)
|
|
}
|
|
|
|
func TestStopCommandsKeepsSuppressedLinesInLog(t *testing.T) {
|
|
a := assert.New(t)
|
|
ctx := context.Background()
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
// Stop command processing until the matching end token is seen.
|
|
a.True(handler("::stop-commands::my-end-token\n"))
|
|
|
|
// A command-shaped line while stopped must not be executed (env unchanged),
|
|
// but must still return true so it reaches the raw_output log handler and is
|
|
// not dropped from the step log.
|
|
a.True(handler("::set-env name=x::valz\n"))
|
|
a.NotContains(rc.Env, "x")
|
|
|
|
// The matching end token resumes command processing.
|
|
a.True(handler("::my-end-token::\n"))
|
|
|
|
// Commands are processed again after resuming.
|
|
a.True(handler("::set-env name=y::valy\n"))
|
|
a.Equal("valy", rc.Env["y"])
|
|
}
|
|
|
|
func TestSetOutput(t *testing.T) {
|
|
a := assert.New(t)
|
|
ctx := context.Background()
|
|
rc := new(RunContext)
|
|
rc.StepResults = make(map[string]*model.StepResult)
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
rc.CurrentStep = "my-step"
|
|
rc.StepResults[rc.CurrentStep] = &model.StepResult{
|
|
Outputs: make(map[string]string),
|
|
}
|
|
handler("::set-output name=x::valz\n")
|
|
a.Equal("valz", rc.StepResults["my-step"].Outputs["x"])
|
|
|
|
handler("::set-output name=x::percent2%25\n")
|
|
a.Equal("percent2%", rc.StepResults["my-step"].Outputs["x"])
|
|
|
|
handler("::set-output name=x::percent2%25%0Atest\n")
|
|
a.Equal("percent2%\ntest", rc.StepResults["my-step"].Outputs["x"])
|
|
|
|
handler("::set-output name=x::percent2%25%0Atest another3%25test\n")
|
|
a.Equal("percent2%\ntest another3%test", rc.StepResults["my-step"].Outputs["x"])
|
|
|
|
handler("::set-output name=x%3A::percent2%25%0Atest\n")
|
|
a.Equal("percent2%\ntest", rc.StepResults["my-step"].Outputs["x:"])
|
|
|
|
handler("::set-output name=x%3A%2C%0A%25%0D%3A::percent2%25%0Atest\n")
|
|
a.Equal("percent2%\ntest", rc.StepResults["my-step"].Outputs["x:,\n%\r:"])
|
|
handler("::set-output name=symbol::std::vector")
|
|
a.Equal("std::vector", rc.StepResults["my-step"].Outputs["symbol"])
|
|
handler("::set-output name=a=b::value\n")
|
|
a.Equal("value", rc.StepResults["my-step"].Outputs["a=b"])
|
|
handler("##[set-output name=legacy%3B%5D]value%3B%5D")
|
|
a.Equal("value;]", rc.StepResults["my-step"].Outputs["legacy;]"])
|
|
handler("##[set-output name=bracket]value]tail")
|
|
a.Equal("value]tail", rc.StepResults["my-step"].Outputs["bracket"])
|
|
handler("::set-output name=modern%3B%5D::value%3B%5D\n")
|
|
a.Equal("value%3B%5D", rc.StepResults["my-step"].Outputs["modern%3B%5D"])
|
|
}
|
|
|
|
func TestAddpath(t *testing.T) {
|
|
a := assert.New(t)
|
|
ctx := context.Background()
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
handler("::add-path::/zoo\n")
|
|
a.Equal("/zoo", rc.ExtraPath[0])
|
|
|
|
handler("::add-path::/boo\n")
|
|
a.Equal("/boo", rc.ExtraPath[0])
|
|
}
|
|
|
|
func TestStopCommands(t *testing.T) {
|
|
logger, hook := test.NewNullLogger()
|
|
|
|
a := assert.New(t)
|
|
ctx := common.WithLogger(context.Background(), logger)
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
handler("::set-env name=x::valz\n")
|
|
a.Equal("valz", rc.Env["x"])
|
|
handler("::stop-commands::MY-END-TOKEN\n")
|
|
handler("::set-env name=x::abcd\n")
|
|
a.Equal("valz", rc.Env["x"])
|
|
handler("::my-end-token::\n")
|
|
handler("::set-env name=x::abcd\n")
|
|
a.Equal("abcd", rc.Env["x"])
|
|
|
|
messages := make([]string, 0)
|
|
for _, entry := range hook.AllEntries() {
|
|
messages = append(messages, entry.Message)
|
|
}
|
|
|
|
a.Contains(messages, "::set-env name=x::abcd\n")
|
|
}
|
|
|
|
// The end token is arbitrary, so one that happens to name a real command must still resume
|
|
// rather than being swallowed by that command's case.
|
|
func TestStopCommandsResumesOnCommandNamedToken(t *testing.T) {
|
|
a := assert.New(t)
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(context.Background())
|
|
|
|
handler("::stop-commands::add-mask\n")
|
|
handler("::set-env name=x::suppressed\n")
|
|
a.NotContains(rc.Env, "x")
|
|
|
|
handler("::add-mask::\n")
|
|
handler("::set-env name=x::resumed\n")
|
|
a.Equal("resumed", rc.Env["x"])
|
|
}
|
|
|
|
func TestAddpathADO(t *testing.T) {
|
|
a := assert.New(t)
|
|
ctx := context.Background()
|
|
rc := unsecureRC()
|
|
handler := rc.commandHandler(ctx)
|
|
|
|
handler("##[add-path]/zoo\n")
|
|
a.Equal("/zoo", rc.ExtraPath[0])
|
|
|
|
handler("##[add-path]/boo\n")
|
|
a.Equal("/boo", rc.ExtraPath[0])
|
|
}
|
|
|
|
func TestAddmask(t *testing.T) {
|
|
logger, hook := test.NewNullLogger()
|
|
|
|
a := assert.New(t)
|
|
ctx := context.Background()
|
|
loggerCtx := common.WithLogger(ctx, logger)
|
|
|
|
rc := new(RunContext)
|
|
handler := rc.commandHandler(loggerCtx)
|
|
handler("::ADD-MASK::my::secret")
|
|
|
|
a.Equal("***", hook.LastEntry().Message)
|
|
a.Equal([]string{"my::secret"}, rc.Masks)
|
|
}
|
|
|
|
// based on https://stackoverflow.com/a/10476304
|
|
func captureOutput(t *testing.T, f func()) string {
|
|
old := os.Stdout
|
|
r, w, _ := os.Pipe()
|
|
os.Stdout = w
|
|
|
|
f()
|
|
|
|
outC := make(chan string)
|
|
|
|
go func() {
|
|
var buf bytes.Buffer
|
|
_, err := io.Copy(&buf, r)
|
|
if err != nil {
|
|
a := assert.New(t)
|
|
a.Fail("io.Copy failed")
|
|
}
|
|
outC <- buf.String()
|
|
}()
|
|
|
|
w.Close()
|
|
os.Stdout = old
|
|
out := <-outC
|
|
|
|
return out
|
|
}
|
|
|
|
func TestAddmaskUsemask(t *testing.T) {
|
|
rc := new(RunContext)
|
|
rc.StepResults = make(map[string]*model.StepResult)
|
|
rc.CurrentStep = "my-step"
|
|
rc.StepResults[rc.CurrentStep] = &model.StepResult{
|
|
Outputs: make(map[string]string),
|
|
}
|
|
|
|
a := assert.New(t)
|
|
|
|
config := &Config{
|
|
Secrets: map[string]string{},
|
|
InsecureSecrets: false,
|
|
}
|
|
|
|
re := captureOutput(t, func() {
|
|
ctx := context.Background()
|
|
ctx = WithJobLogger(ctx, "0", "testjob", config, &rc.Masks, map[string]any{})
|
|
|
|
handler := rc.commandHandler(ctx)
|
|
handler("::add-mask::secret\n")
|
|
handler("::set-output:: token=secret\n")
|
|
})
|
|
|
|
a.Equal("[testjob] ***\n[testjob] ::set-output:: = token=***\n", re)
|
|
}
|
|
|
|
func TestSaveState(t *testing.T) {
|
|
rc := &RunContext{
|
|
CurrentStep: "step",
|
|
StepResults: map[string]*model.StepResult{},
|
|
}
|
|
|
|
ctx := context.Background()
|
|
|
|
handler := rc.commandHandler(ctx)
|
|
handler("::save-state name=state-name::state-value\n")
|
|
|
|
assert.Equal(t, "state-value", rc.IntraActionState["step"]["state-name"])
|
|
}
|
|
|
|
func TestEscapeCommandData(t *testing.T) {
|
|
a := assert.New(t)
|
|
|
|
a.Equal("a%25b%0Dc%0Ad%250A", EscapeCommandData("a%b\rc\nd%0A"))
|
|
a.Equal("a%b\rc\nd%0A", UnescapeCommandData("a%25b%0Dc%0Ad%250A"))
|
|
}
|
|
|
|
func TestUnsecureCommands(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
jobEnv map[string]string
|
|
stepEnv map[string]string
|
|
optedIn bool
|
|
}{
|
|
{name: "refused with no opt-in"},
|
|
// GitHub reads the opt-in with bool.TryParse, so "1" is not one.
|
|
{name: "refused for a value bool.TryParse rejects", jobEnv: map[string]string{allowUnsecureCommandsVar: "1"}},
|
|
{name: "opted in through the step environment", stepEnv: map[string]string{allowUnsecureCommandsVar: "true"}, optedIn: true},
|
|
{name: "opted in through the job environment", jobEnv: map[string]string{allowUnsecureCommandsVar: "TRUE"}, optedIn: true},
|
|
}
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
a := assert.New(t)
|
|
rc := &RunContext{Env: tt.jobEnv}
|
|
rc.setCurrentStepEnv(tt.stepEnv)
|
|
handler := rc.commandHandler(context.Background())
|
|
|
|
handler("::set-env name=x::valz\n")
|
|
handler("::add-path::/opt/bin\n")
|
|
|
|
if !tt.optedIn {
|
|
a.Empty(rc.Env["x"])
|
|
a.Empty(rc.ExtraPath)
|
|
// The refusal fails the step that produced it, once.
|
|
require.ErrorContains(t, rc.takeUnsecureCommandError(), "set-env")
|
|
a.NoError(rc.takeUnsecureCommandError())
|
|
return
|
|
}
|
|
a.Equal("valz", rc.Env["x"])
|
|
a.Equal([]string{"/opt/bin"}, rc.ExtraPath)
|
|
a.NoError(rc.takeUnsecureCommandError())
|
|
})
|
|
}
|
|
}
|