mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 08:45:33 +02:00
fix(actions): reject jobs without runs-on (#39480)
Align job and `runs-on` validation with github.com, as implemented by the parser in https://github.com/actions/runner. A job without `runs-on` could be claimed by any runner, so a job meant for a container could run on the host. - Jobs without `runs-on` fail with `Required property is missing: runs-on`, called workflows included - Unknown job keys and callers (`uses:`) mixed with steps-only keys like `runs-on` are rejected - Empty, null and nested `runs-on` values are rejected - A `runs-on` evaluating to such a value fails only that job - Called workflows are validated at run creation, an invalid one fails the run as an invalid workflow file - Zero labels (`runs-on: []` or `{}`) never match a runner, including jobs queued before upgrading <img width="960" alt="image" src="https://github.com/user-attachments/assets/e746ce5a-b711-4e8b-aab8-81336ff53d86" /> **Behavior Change:** workflows that omit `runs-on`, use unknown job keys or mix `uses` with `runs-on` stop running until fixed. --------- Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
23 files changed
+410
-98
No files matched your search
@@ -200,7 +200,7 @@ func (r *ActionRunner) GenerateAndFillToken() {
|
||||
// CanMatchLabels checks whether the runner's labels can match a job's "runs-on"
|
||||
// See https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idruns-on
|
||||
func (r *ActionRunner) CanMatchLabels(jobRunsOn []string) bool {
|
||||
return !slices.ContainsFunc(jobRunsOn, func(label string) bool { return !util.SliceContainsString(r.AgentLabels, label, true) })
|
||||
return len(jobRunsOn) > 0 && !slices.ContainsFunc(jobRunsOn, func(label string) bool { return !util.SliceContainsString(r.AgentLabels, label, true) })
|
||||
}
|
||||
|
||||
func init() {
|
||||
|
||||
@@ -86,4 +86,5 @@ func TestCanMatchLabelsCaseInsensitive(t *testing.T) {
|
||||
runner := &ActionRunner{AgentLabels: []string{"self-hosted", "Linux", "X64"}}
|
||||
assert.True(t, runner.CanMatchLabels([]string{"SELF-HOSTED", "linux"}))
|
||||
assert.False(t, runner.CanMatchLabels([]string{"linux", "arm64"}))
|
||||
assert.False(t, runner.CanMatchLabels(nil))
|
||||
}
|
||||
Reference in new issue
Block a user