Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions rust/crates/git-locator/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -128,6 +128,24 @@ pub fn parse_git_ref(value: &str) -> Result<GitRef, String> {
})
}

/// Validate the explicit owner/repository accepted by GitHub tools.
pub fn github_repository(repository: &str) -> Result<(), String> {
let pieces: Vec<_> = repository.split('/').collect();
if pieces.len() != 2
|| pieces.iter().any(|p| {
p.is_empty()
|| p.starts_with('.')
|| p.starts_with('-')
|| !p
.bytes()
.all(|b| b.is_ascii_alphanumeric() || b"-_.".contains(&b))
})
{
return Err("repository must be GitHub owner/repository".into());
}
Ok(())
}

#[cfg(test)]
mod git_ref_tests {
use super::{parse_git_ref, GitRef};
Expand Down
10 changes: 10 additions & 0 deletions std/github/.caos-expr
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
HELP=<<END
Run GitHub CLI with an explicit repository and an invocation identity. Use a new identity for a new observation and retain it on retry. A claimed invocation without a result is uncertain and is never executed again.
@param repository GitHub owner/repository.
@param args JSON array of literal arguments to gh.
@param invocation Unique caller-supplied invocation ID (64 lowercase hexadecimal characters).
@param [stdin] Standard input, for example a PR body passed with --body-file -.
END
RUNNER=run --base:@=DEEP-DEPS/flake-builder --in:@=runner --lock:@=DEEP-DEPS/flake.lock
WORKER=run --base:@=DEEP-DEPS/rustc --src:@=. --dep0:@=DEEP-DEPS/conversation-protocol --dep1:@=DEEP-DEPS/git-locator --output-runner=$RUNNER
curry --base=$WORKER --help=$HELP
21 changes: 21 additions & 0 deletions std/github/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
[package]
name = "github"
version = "0.0.0"
edition = "2021"

[[bin]]
name = "worker"
path = "src/main.rs"

[dependencies]
worker-common = { path = "worker-common" }
conversation-protocol = { path = "conversation-protocol", features = ["git-cli"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
git-locator = { path = "git-locator" }

[profile.dev.package."*"]
opt-level = 2

[profile.dev.build-override]
opt-level = 0
5 changes: 5 additions & 0 deletions std/github/DEPS
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
../rustc rustc
../../rust/crates/conversation-protocol conversation-protocol
../../rust/crates/git-locator git-locator
../flake-builder flake-builder
../../flake.lock flake.lock
31 changes: 31 additions & 0 deletions std/github/runner/flake.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
{
description = "GitHub CLI runtime";
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
outputs = { self, nixpkgs }: {
packages = builtins.listToAttrs (map (system:
let
pkgs = import nixpkgs { inherit system; };
arch = if system == "aarch64-linux" then "arm64" else "amd64";
digest = if system == "aarch64-linux"
then "2da13f8c46f2770237c744b341ab6be9f07508585a6762634c4a88aa355460bc"
else "9ed103934fab0f90d3341fdfc4a342785396d39f5621fc7313a62602ce2b5462";
stack = pkgs.fetchurl {
url = "https://github.com/github/gh-stack/releases/download/v0.1.1/linux-${arch}";
sha256 = digest;
};
root = pkgs.runCommand "github-runner" {} ''
mkdir -p $out/opt
install -m755 ${stack} $out/opt/gh-stack
install -m755 ${./worker} $out/worker
'';
in {
name = system;
value.caosImage = pkgs.dockerTools.buildLayeredImage {
name = "github-runner";
tag = "latest";
contents = [ root pkgs.bash pkgs.coreutils pkgs.gitMinimal pkgs.gh pkgs.cacert ];
config.Env = [ "PATH=/bin" "SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt" ];
};
}) [ "x86_64-linux" "aarch64-linux" ]);
};
}
15 changes: 15 additions & 0 deletions std/github/runner/worker
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
#!/usr/bin/env bash
# Stage the compiled worker in the GitHub CLI image.
set -euo pipefail

bin=/cas/args/worker1
caos get "$bin"
if [ ! -f "$bin" ]; then
echo "github-runner: the worker1 arg is not a regular file" >&2
exit 1
fi

run_dir=$(mktemp -d /tmp/caos-github-runner.XXXXXX)
cp "$bin" "$run_dir/worker"
chmod 755 "$run_dir/worker"
exec "$run_dir/worker"
Loading
Loading