mirror of
https://github.com/actions/setup-java.git
synced 2026-09-09 20:24:21 +02:00
Fix import-safe checks when scripts are run from a path with symlinks (#1265)
* Fix import-safe checks when scripts are run from a path with symlinks In v6, setup-java was made "import-safe" to facilitate testing. This prevents setup-java & cleanup-java from doing anything when their sources get imported. This works fine in the general case, but actually invoking the script (`node setup-java/index.js`) when the path to the script contains symlinks led to the script incorrectly believing it was imported, and refuse to actually run. To fix this, we pass `process.argv[1]` through `fs.realpathSync`, which resolves symlinks in the path. Fixes #1264 * Preserve import safety when resolving symlink entrypoints Share entrypoint detection between setup and cleanup, handle non-file entrypoints safely, and normalize both paths for preserved symlinks. Add real-process regression coverage and rebuild action bundles. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554 * Update js-yaml to fix merge-source denial of service Bump the transitive development dependency from 3.15.1 to 3.15.2 to address GHSA-2883-xcg3-v3hh without changing dependency ranges or CI checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554 --------- Co-authored-by: Bruno Borges <brborges@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 831c32f2-a275-45bd-a92b-c387372a1554
This commit is contained in:
co-authored by
Copilot App
Bruno Borges
parent
0781fc6af3
commit
134912a529
@@ -0,0 +1,87 @@
|
||||
import {afterAll, beforeAll, describe, expect, it} from '@jest/globals';
|
||||
import {spawnSync} from 'child_process';
|
||||
import fs from 'fs';
|
||||
import os from 'os';
|
||||
import path from 'path';
|
||||
import {fileURLToPath, pathToFileURL} from 'url';
|
||||
|
||||
const dist = fileURLToPath(new URL('../dist/', import.meta.url));
|
||||
let tempDir: string;
|
||||
let linkedDist: string;
|
||||
|
||||
beforeAll(() => {
|
||||
tempDir = fs.mkdtempSync(path.join(os.tmpdir(), 'setup-java-entrypoints-'));
|
||||
linkedDist = path.join(tempDir, 'linked # dist');
|
||||
fs.symlinkSync(dist, linkedDist, 'junction');
|
||||
});
|
||||
|
||||
afterAll(() => {
|
||||
fs.rmSync(tempDir, {recursive: true, force: true});
|
||||
});
|
||||
|
||||
function execute(args: string[], input?: string) {
|
||||
return spawnSync(process.execPath, args, {
|
||||
encoding: 'utf8',
|
||||
input,
|
||||
timeout: 10000,
|
||||
env: {
|
||||
PATH: process.env.PATH,
|
||||
SystemRoot: process.env.SystemRoot
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
describe.each([
|
||||
['setup', 1, 'java-version or java-version-file input expected'],
|
||||
['cleanup', 0, '']
|
||||
] as const)('%s entrypoint', (name, exitCode, output) => {
|
||||
it.each(['direct', 'symlink', 'preserved symlink'])(
|
||||
'executes through a %s path',
|
||||
mode => {
|
||||
const entry = path.join(
|
||||
mode === 'direct' ? dist : linkedDist,
|
||||
name,
|
||||
'index.js'
|
||||
);
|
||||
const args =
|
||||
mode === 'preserved symlink'
|
||||
? ['--preserve-symlinks-main', entry]
|
||||
: [entry];
|
||||
const result = execute(args);
|
||||
|
||||
expect(result.error).toBeUndefined();
|
||||
expect(result.status).toBe(exitCode);
|
||||
expect(result.stderr).toBe('');
|
||||
expect(result.stdout).not.toContain('skipping the execution');
|
||||
if (output) {
|
||||
expect(result.stdout).toContain(output);
|
||||
} else {
|
||||
expect(result.stdout).toBe('');
|
||||
}
|
||||
}
|
||||
);
|
||||
|
||||
it.each(['eval', 'stdin', 'file'])(
|
||||
'does not execute when imported from %s',
|
||||
mode => {
|
||||
const moduleUrl = pathToFileURL(path.join(dist, name, 'index.js')).href;
|
||||
const source = `const {run} = await import(${JSON.stringify(moduleUrl)}); console.log(typeof run);`;
|
||||
const importer = path.join(tempDir, `${name}-importer.mjs`);
|
||||
fs.writeFileSync(importer, source);
|
||||
const args =
|
||||
mode === 'file'
|
||||
? [importer]
|
||||
: mode === 'eval'
|
||||
? ['--input-type=module', '-e', source]
|
||||
: ['--input-type=module', '-'];
|
||||
const result = execute(args, mode === 'stdin' ? source : undefined);
|
||||
|
||||
expect(result.error).toBeUndefined();
|
||||
expect(result.status).toBe(0);
|
||||
expect(result.stderr).toBe('');
|
||||
expect(result.stdout).toContain('skipping the execution');
|
||||
expect(result.stdout).toContain('function');
|
||||
expect(result.stdout).not.toContain('::error::');
|
||||
}
|
||||
);
|
||||
});
|
||||
Reference in New Issue
Block a user