From 5ed9ac519f6815b4eaf6b82fc689ef813ae7b94d Mon Sep 17 00:00:00 2001 From: RhenCloud Date: Fri, 2 Oct 2026 21:43:29 +0800 Subject: [PATCH 1/2] fix: download archives outside workspace --- .github/workflows/ci.yml | 1 + action.yml | 14 +++++++++----- tests/action_download_test.py | 15 +++++++++++++++ 3 files changed, 25 insertions(+), 5 deletions(-) create mode 100644 tests/action_download_test.py diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5bc8ecf..33ea41b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -20,6 +20,7 @@ jobs: steps: - uses: actions/checkout@v4 - run: cargo test + - run: python3 tests/action_download_test.py fmt: name: Format diff --git a/action.yml b/action.yml index bb043de..8e1cb46 100644 --- a/action.yml +++ b/action.yml @@ -108,7 +108,7 @@ runs: - name: Download verified-bot-commit shell: bash run: | - VERSION="v0.2.0" + VERSION="v0.2.1" BASE_URL="https://github.com/siiway/verified_bot_commit/releases/download/${VERSION}" case "$RUNNER_OS-$RUNNER_ARCH" in @@ -122,12 +122,16 @@ runs: ARCHIVE="verified_bot_commit-${TARGET}" if [ "$RUNNER_OS" = "Windows" ]; then - curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o archive.zip - unzip -o archive.zip -d "$RUNNER_TEMP" + ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip" + curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH" + unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP" + rm -f "$ARCHIVE_PATH" BINARY="$RUNNER_TEMP/verified_bot_commit.exe" else - curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o archive.tar.gz - tar -xzf archive.tar.gz -C "$RUNNER_TEMP" + ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz" + curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH" + tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP" + rm -f "$ARCHIVE_PATH" BINARY="$RUNNER_TEMP/verified_bot_commit" chmod +x "$BINARY" fi diff --git a/tests/action_download_test.py b/tests/action_download_test.py new file mode 100644 index 0000000..e922326 --- /dev/null +++ b/tests/action_download_test.py @@ -0,0 +1,15 @@ +from pathlib import Path + + +action = Path("action.yml").read_text() + +assert 'VERSION="v0.2.1"' in action +assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action +assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action +assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action +assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action +assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action +assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action +assert action.count('rm -f "$ARCHIVE_PATH"') == 2 +assert '-o archive.zip' not in action +assert '-o archive.tar.gz' not in action From a8c2df1f0d7e8f17fa2733deadbc90064b9fc5d2 Mon Sep 17 00:00:00 2001 From: RhenCloud Date: Fri, 2 Oct 2026 22:05:37 +0800 Subject: [PATCH 2/2] test: execute archive download regression --- action.yml | 4 +- tests/action_download_test.py | 82 ++++++++++++++++++++++++++++++----- 2 files changed, 73 insertions(+), 13 deletions(-) diff --git a/action.yml b/action.yml index 8e1cb46..233bfbe 100644 --- a/action.yml +++ b/action.yml @@ -123,15 +123,15 @@ runs: ARCHIVE="verified_bot_commit-${TARGET}" if [ "$RUNNER_OS" = "Windows" ]; then ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip" + trap 'rm -f "$ARCHIVE_PATH"' EXIT curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH" unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP" - rm -f "$ARCHIVE_PATH" BINARY="$RUNNER_TEMP/verified_bot_commit.exe" else ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz" + trap 'rm -f "$ARCHIVE_PATH"' EXIT curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH" tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP" - rm -f "$ARCHIVE_PATH" BINARY="$RUNNER_TEMP/verified_bot_commit" chmod +x "$BINARY" fi diff --git a/tests/action_download_test.py b/tests/action_download_test.py index e922326..c23c67f 100644 --- a/tests/action_download_test.py +++ b/tests/action_download_test.py @@ -1,15 +1,75 @@ +import os +import subprocess +import tarfile +import tempfile from pathlib import Path -action = Path("action.yml").read_text() +ROOT = Path(__file__).resolve().parents[1] +ACTION = ROOT / "action.yml" -assert 'VERSION="v0.2.1"' in action -assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action -assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action -assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action -assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action -assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action -assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action -assert action.count('rm -f "$ARCHIVE_PATH"') == 2 -assert '-o archive.zip' not in action -assert '-o archive.tar.gz' not in action + +def download_script(): + lines = ACTION.read_text().splitlines() + start = lines.index(" - name: Download verified-bot-commit") + run = lines.index(" run: |", start) + 1 + end = lines.index(" - name: Run verified-bot-commit", run) + return "\n".join(line[6:] for line in lines[run:end]) + + +def write_mock_curl(path): + path.write_text( + "#!/bin/sh\n" + "if [ \"$MOCK_CURL_FAILURE\" = \"1\" ]; then\n" + " : > \"$4\"\n" + " exit 1\n" + "fi\n" + "cp \"$MOCK_ARCHIVE\" \"$4\"\n" + ) + path.chmod(0o755) + + +def run_download(workspace, runner_temp, archive, fail=False): + bin_dir = workspace / "bin" + bin_dir.mkdir() + write_mock_curl(bin_dir / "curl") + env = os.environ | { + "GITHUB_ENV": str(runner_temp / "github_env"), + "MOCK_ARCHIVE": str(archive), + "MOCK_CURL_FAILURE": "1" if fail else "0", + "PATH": f"{bin_dir}:{os.environ['PATH']}", + "RUNNER_ARCH": "X64", + "RUNNER_OS": "Linux", + "RUNNER_TEMP": str(runner_temp), + } + return subprocess.run( + ["bash", "-e", "-c", download_script()], + cwd=workspace, + env=env, + check=False, + ) + + +with tempfile.TemporaryDirectory() as directory: + root = Path(directory) + workspace = root / "workspace" + runner_temp = root / "runner_temp" + workspace.mkdir() + runner_temp.mkdir() + binary = root / "verified_bot_commit" + binary.write_text("test binary") + archive = root / "release.tar.gz" + with tarfile.open(archive, "w:gz") as tar: + tar.add(binary, arcname="verified_bot_commit") + + assert run_download(workspace, runner_temp, archive).returncode == 0 + assert (runner_temp / "verified_bot_commit").read_text() == "test binary" + assert not (runner_temp / "verified_bot_commit-x86_64-unknown-linux-gnu.tar.gz").exists() + assert not (workspace / "archive.tar.gz").exists() + + failed_workspace = root / "failed_workspace" + failed_temp = root / "failed_temp" + failed_workspace.mkdir() + failed_temp.mkdir() + assert run_download(failed_workspace, failed_temp, archive, fail=True).returncode != 0 + assert not (failed_temp / "verified_bot_commit-x86_64-unknown-linux-gnu.tar.gz").exists()