Skip to content

samples for all actions, stubs for actions that need infrastructure i… - #8790

Open
bamaer wants to merge 2 commits into
apache:mainfrom
bamaer:2238
Open

bamaer wants to merge 2 commits into
apache:mainfrom
bamaer:2238

Conversation

@bamaer

@bamaer bamaer commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

…n actions/requires-setup. fixes #2238

Please add a meaningful description for your change here


Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Run mvn clean install apache-rat:check to make sure basic checks pass. A more thorough check will be performed on your pull request automatically.
  • If you have a group of commits related to the same change, please squash your commits into one and force push your branch using git rebase -i.
  • Mention the appropriate issue in your description (for example: addresses #123), if applicable.

To make clear that you license your contribution under the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.

<exec_per_row>N</exec_per_row>
<set_append_logfile>N</set_append_logfile>
<insertScript>Y</insertScript>
<script>echo Hello from the Shell action</script>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[bug] Hop does not run an inline script through a shell. On Linux and macOS ActionShell writes this text to a temp file, marks it executable, and ProcessBuilder execs that file. Without a shebang the kernel returns ENOEXEC (Exec format error), the action fails, and the note that echo works on every operating system is wrong. A #!/bin/sh first line is not enough on its own either: Windows runs the same text as a .bat file, and cmd.exe treats #!/bin/sh as a command.

The failure hop only writes a log line. Write to log succeeds, so the workflow result stays successful and read-samples-build-hop-run will not notice that the script never ran.

Suggestion: Branch with the JavaScript action (is_windows is already in scope). On Windows keep echo Hello from the Shell action. On Linux and macOS use a script whose first line is #!/bin/sh. Point the failure hop at an Abort action so a script that does not run fails the sample.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The failure hop now goes to an Abort action, so a script that fails also fails the sample (tested with exit 3: hop-run returns rc=1).

I didn't add a shebang. When exec returns ENOEXEC, both the JDK and libc rerun the file with /bin/sh. The shebang-less temp script runs fine through ProcessBuilder and hop-run on Linux, and #!/bin/sh would break the Windows .bat run.

<field>
<action_type>sign</action_type>
<source_filefolder>${java.io.tmpdir}/hop-samples/pgp/report.csv</source_filefolder>
<userid>${PGP_USER_ID}</userid>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[bug] This row is the sign step, but userid is only the encryption recipient. ActionPGPEncryptFiles signs with local_user (gpg -u) and explicitly ignores userid for action_type sign, logging UserIdIgnoredWhenSigning. The note tells you to set PGP_USER_ID as the key, yet this step leaves local_user empty, so GnuPG signs with its default secret key instead of that id. Encrypt above is fine; sign and the following verify are not using the key the sample documents.

Suggestion: On the sign field, set local_user to ${PGP_USER_ID} and drop userid (or leave it empty). Keep userid only on the encrypt row.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed: the sign row now uses local_user = ${PGP_USER_ID}, and userid is only on the encrypt row. I tested with a second key set as the GnuPG default, and the signature now comes from the PGP_USER_ID key.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Task]: add samples for all actions to the samples project

2 participants