mirror of
https://gitea.com/gitea/runner.git
synced 2026-08-25 13:27:46 +00:00
745a1e70e6
The runner's own `container.options` and the workflow's were joined into one string before parsing, so the host-escape filter added in https://gitea.com/gitea/runner/pulls/1058 dropped the administrator's options along with the workflow's. Setups that need `--device` or `--security-opt` from the config file had no way left to get them short of enabling privileged mode. `NewContainerInput` now carries the two sources apart, as `RunnerOptions` and `WorkflowOptions`, down to the point where the filter runs. With privileged mode off, the host-escape fields are reset to what the runner's own options parse to on their own, so only the workflow's contribution is dropped. Three further ways a workflow's options reached past its container, all resolved on the runner before anything reaches the daemon: 1. `--env-file` and `--label-file` name files that are read on the runner, so any file it could read became container environment or labels. Both are refused from a workflow now, and still serve the runner's own options. 2. A bare `--env NAME` was resolved from the runner's own environment by docker's validator. That lookup is gone, for every source. Use `runner.envs` or `runner.env_file` to pass a variable on. 3. A volume driver decides for itself what it mounts, and the local driver's `device=` option turns a name `valid_volumes` allows into a bind of any host path. A workflow's mounts may no longer carry one. `--isolation`, `--volume-driver` and the two paths `--security-opt systempaths=unconfined` lands in were also missing from the fields a workflow may not set. Last, the `--network and --net in the options will be ignored.` warning fired for every container, because the runner's own network mode is fed into the parsed options before the check runs. Fixes https://gitea.com/gitea/runner/issues/1142 Reviewed-on: https://gitea.com/gitea/runner/pulls/1151 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: silverwind <me@silverwind.io>
63 lines
1.8 KiB
Go
63 lines
1.8 KiB
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package container
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestCreateFlagsFromOptions(t *testing.T) {
|
|
for _, tc := range []struct {
|
|
options string
|
|
platform string
|
|
pull string
|
|
}{
|
|
{"", "", pullPolicyMissing},
|
|
{"-v /a:/b --platform=linux/arm64 --pull always", "linux/arm64", pullPolicyAlways},
|
|
{"--platform linux/arm/v7 --pull never", "linux/arm/v7", pullPolicyNever},
|
|
{`--platform "linux/amd64`, "", pullPolicyMissing}, // malformed, defaults kept
|
|
} {
|
|
t.Run(tc.options, func(t *testing.T) {
|
|
cf := createFlagsFromOptions(tc.options)
|
|
assert.Equal(t, tc.platform, cf.platform)
|
|
assert.Equal(t, tc.pull, cf.pull)
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestCreateFlagsValidate(t *testing.T) {
|
|
for _, tc := range []struct {
|
|
options string
|
|
wantErr string
|
|
}{
|
|
{"--quiet --disable-content-trust --name mine", ""},
|
|
{"--pull sometimes", `invalid --pull option "sometimes"`},
|
|
{"--use-api-socket", "--use-api-socket is not supported"},
|
|
} {
|
|
t.Run(tc.options, func(t *testing.T) {
|
|
err := createFlagsFromOptions(tc.options).validate()
|
|
if tc.wantErr == "" {
|
|
require.NoError(t, err)
|
|
return
|
|
}
|
|
require.ErrorContains(t, err, tc.wantErr)
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestNewContainerAppliesCreateFlags(t *testing.T) {
|
|
input := &NewContainerInput{Platform: "linux/amd64", RunnerOptions: "--pull never", WorkflowOptions: "--platform linux/arm64"}
|
|
cr, ok := NewContainer(input).(*containerReference)
|
|
require.True(t, ok)
|
|
assert.Equal(t, "linux/arm64", input.Platform)
|
|
assert.Equal(t, pullPolicyNever, cr.pullPolicy)
|
|
|
|
kept := &NewContainerInput{Platform: "linux/amd64", RunnerOptions: "--privileged"}
|
|
NewContainer(kept)
|
|
assert.Equal(t, "linux/amd64", kept.Platform)
|
|
}
|