mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2026-05-12 22:10:25 +00:00
As described in [this comment](https://gitea.com/gitea/act_runner/issues/19#issuecomment-739221) one-job runners are not secure when running in host mode. We implemented a routine preventing runner tokens from receiving a second job in order to render a potentially compromised token useless. Also we implemented a routine that removes finished runners as soon as possible. Big thanks to [ChristopherHX](https://github.com/ChristopherHX) who did all the work for gitea! Rel: #9407 ## Checklist The [contributor guide](https://forgejo.org/docs/next/contributor/) contains information that will be helpful to first time contributors. There also are a few [conditions for merging Pull Requests in Forgejo repositories](https://codeberg.org/forgejo/governance/src/branch/main/PullRequestsAgreement.md). You are also welcome to join the [Forgejo development chatroom](https://matrix.to/#/#forgejo-development:matrix.org). ### Tests - I added test coverage for Go changes... - [ ] in their respective `*_test.go` for unit tests. - [x] in the `tests/integration` directory if it involves interactions with a live Forgejo server. - I added test coverage for JavaScript changes... - [ ] in `web_src/js/*.test.js` if it can be unit tested. - [ ] in `tests/e2e/*.test.e2e.js` if it requires interactions with a live Forgejo server (see also the [developer guide for JavaScript testing](https://codeberg.org/forgejo/forgejo/src/branch/forgejo/tests/e2e/README.md#end-to-end-tests)). ### Documentation - [ ] I created a pull request [to the documentation](https://codeberg.org/forgejo/docs) to explain to Forgejo users how to use this change. - [ ] I did not document these changes and I do not expect someone else to do it. ### Release notes - [ ] I do not want this change to show in the release notes. - [ ] I want the title to show in the release notes with a link to this pull request. - [ ] I want the content of the `release-notes/<pull request number>.md` to be be used for the release notes instead of the title. Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/9962 Reviewed-by: Andreas Ahlenstorf <aahlenst@noreply.codeberg.org> Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org> Co-authored-by: Manuel Ganter <manuel.ganter@think-ahead.tech> Co-committed-by: Manuel Ganter <manuel.ganter@think-ahead.tech>
41 lines
1 KiB
YAML
41 lines
1 KiB
YAML
-
|
|
id: 10054
|
|
job_id: 10398
|
|
attempt: 1
|
|
runner_id: 10000008
|
|
status: 6 # running
|
|
started: 1683636528
|
|
stopped: 1683636626
|
|
repo_id: 64
|
|
owner_id: 3
|
|
commit_sha: c2d72f548424103f01ee1dc02889c1e2bff816b0
|
|
is_fork_pull_request: 0
|
|
token_hash: f8d3962425466b6709b9ac51446f93260c54afe8e7b6d3686e34f991fb8a8953822b0deed86fe41a103f34bc48dbc4784222
|
|
token_salt: ffffffffff
|
|
token_last_eight: ffffffff
|
|
log_filename: artifact-test2/2f/47.log
|
|
log_in_storage: 1
|
|
log_length: 707
|
|
log_size: 90179
|
|
log_expired: 0
|
|
-
|
|
id: 10055
|
|
job_id: 10399
|
|
attempt: 1
|
|
runner_id: 10000011
|
|
status: 6 # running
|
|
started: 946684810
|
|
stopped: 0
|
|
repo_id: 64
|
|
owner_id: 3
|
|
commit_sha: c2d72f548424103f01ee1dc02889c1e2bff816b0
|
|
is_fork_pull_request: 0
|
|
token_hash: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0
|
|
token_salt: zombietask
|
|
token_last_eight: zombietk
|
|
log_filename: zombie-task/55.log
|
|
log_in_storage: 0
|
|
log_length: 100
|
|
log_size: 1000
|
|
log_expired: 0
|
|
updated: 946684810
|