mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
Pin the nextest and nightly toolchain actions by commit SHA
The three cargo-nextest install steps in ci.yml and the nightly toolchain step in package-openwrt.yml were the last action references left on mutable refs. Their owners can move a tag or branch to different code at any time, and the install-action v2 tag has already moved off the commit this repository pins for cargo-ndk. The nextest steps now use that same install-action commit, so there is one install-action pin to bump rather than two. That lineage declares the `tool` input required, so each step passes `tool: nextest`; its manifest installs cargo-nextest 0.9.143, which stays fixed until the pin is bumped by hand. The toolchain step is pinned to the head of rust-toolchain's nightly branch and names `toolchain: nightly` explicitly, so a later bump to a commit whose input has no default still resolves the same channel. Pinning that action does not pin the toolchain: rustup still resolves nightly when the step runs. With every reference pinned, the action pin guard no longer needs its list of individually allowed mutable refs or the function that matched against it. Removing both, rather than leaving an empty list, also avoids expanding an empty array under `set -u`, which bash releases before 4.4 treat as an unbound variable. The comment that justified the exceptions is replaced by how to pin an action that selects its tool or toolchain from the ref name: pin the SHA and pass the selection as an explicit `with:` input. The success message drops "or justified".
This commit is contained in:
@@ -334,7 +334,9 @@ jobs:
|
||||
${{ runner.os }}-cargo-
|
||||
|
||||
- name: Install cargo-nextest
|
||||
uses: taiki-e/install-action@nextest
|
||||
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
|
||||
with:
|
||||
tool: nextest
|
||||
|
||||
# The cache restores target/, including the previous run's report. Remove
|
||||
# it so the flaky-test check below reads only this run's, and reports a
|
||||
@@ -418,7 +420,9 @@ jobs:
|
||||
${{ runner.os }}-cargo-
|
||||
|
||||
- name: Install cargo-nextest
|
||||
uses: taiki-e/install-action@nextest
|
||||
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
|
||||
with:
|
||||
tool: nextest
|
||||
|
||||
# The cache restores target/, including the previous run's report. Remove
|
||||
# it so the flaky-test check below reads only this run's, and reports a
|
||||
@@ -467,7 +471,9 @@ jobs:
|
||||
${{ runner.os }}-cargo-
|
||||
|
||||
- name: Install cargo-nextest
|
||||
uses: taiki-e/install-action@nextest
|
||||
uses: taiki-e/install-action@fcf5432d9f50d67e37ee6e29bdb7a224ff67b4a7 # v2
|
||||
with:
|
||||
tool: nextest
|
||||
|
||||
# The cache restores target/, including the previous run's report. Remove
|
||||
# it so the flaky-test check below reads only this run's, and reports a
|
||||
|
||||
@@ -120,8 +120,9 @@ jobs:
|
||||
|
||||
- name: Install Rust toolchain (nightly, Tier 3)
|
||||
if: matrix.rust_channel == 'nightly'
|
||||
uses: dtolnay/rust-toolchain@nightly
|
||||
uses: dtolnay/rust-toolchain@be39649afda95dbf70f87cce95f68b8d5797b296 # nightly
|
||||
with:
|
||||
toolchain: nightly
|
||||
components: rust-src
|
||||
|
||||
- name: Cache Cargo registry + build
|
||||
|
||||
@@ -14,8 +14,7 @@
|
||||
#
|
||||
# What counts as a violation: any `uses:` reference that is not
|
||||
# * `owner/repo@<40 hex> # <tag>` — the required form, comment mandatory; or
|
||||
# * a local action, `./path` or `docker://...`; or
|
||||
# * one of the individually justified references listed below.
|
||||
# * a local action, `./path` or `docker://...`.
|
||||
#
|
||||
# WHAT THIS GUARD DOES NOT COVER, so a green run is not read as "the workflows
|
||||
# fetch nothing unverified":
|
||||
@@ -43,19 +42,13 @@ REPO_ROOT="$SCRIPT_DIR/.."
|
||||
# it cannot describe, and a pin nobody can read is a pin nobody updates.
|
||||
PINNED_RE='^[^@]+@[0-9a-f]{40} +#.*$'
|
||||
|
||||
# Individually justified unpinned references. Each entry is the exact ref text.
|
||||
#
|
||||
# Both of these actions read the tool they install from the ref name itself
|
||||
# (`github.action_ref`), so replacing the ref with a SHA hands them a 40-hex
|
||||
# string where a toolchain or tool name belongs and the step fails outright.
|
||||
# They are not pinnable without also moving the selection into `with:`, which
|
||||
# changes which toolchain resolves, and that is a separate decision from
|
||||
# pinning. Note what stays exposed: both remain repointable by their upstream
|
||||
# owners.
|
||||
ALLOWED_REFS=(
|
||||
'dtolnay/rust-toolchain@nightly'
|
||||
'taiki-e/install-action@nextest'
|
||||
)
|
||||
# There are no exceptions. Some actions select what they install from the ref
|
||||
# they are called at: a per-tool `taiki-e/install-action` tag, or a
|
||||
# `dtolnay/rust-toolchain` channel branch, sets the selection input's default
|
||||
# in that ref's action.yml. Pin such an action by SHA and pass the selection as
|
||||
# an explicit `with:` input (`tool:`, `toolchain:`). That form works at a SHA
|
||||
# from any of the action's refs; a bare SHA does not, because their `v2` and
|
||||
# `master` trees declare the input required with no default.
|
||||
|
||||
if ! command -v git >/dev/null 2>&1; then
|
||||
echo "check-action-pins: git not available, cannot sweep" >&2
|
||||
@@ -83,15 +76,6 @@ if [[ ${#files[@]} -eq 0 ]]; then
|
||||
exit 2
|
||||
fi
|
||||
|
||||
# True when this ref is one of the justified references above.
|
||||
allowed_ref() {
|
||||
local ref="$1" entry
|
||||
for entry in "${ALLOWED_REFS[@]}"; do
|
||||
[[ "$ref" == "$entry" ]] && return 0
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
violations=0
|
||||
checked=0
|
||||
|
||||
@@ -117,7 +101,6 @@ for f in "${files[@]}"; do
|
||||
[[ "$ref" == ./* ]] && continue
|
||||
[[ "$ref" == docker://* ]] && continue
|
||||
[[ "$ref" =~ $PINNED_RE ]] && continue
|
||||
allowed_ref "$ref" && continue
|
||||
|
||||
echo "$f:$n: $ref"
|
||||
violations=$((violations + 1))
|
||||
@@ -141,5 +124,5 @@ if [[ $violations -gt 0 ]]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "check-action-pins: all $checked action reference(s) pinned or justified"
|
||||
echo "check-action-pins: all $checked action reference(s) pinned"
|
||||
exit 0
|
||||
|
||||
Reference in New Issue
Block a user