Repository navigation
Conversation
…n actions/requires-setup. fixes apache#2238
| <exec_per_row>N</exec_per_row> | ||
| <set_append_logfile>N</set_append_logfile> | ||
| <insertScript>Y</insertScript> | ||
| <script>echo Hello from the Shell action</script> |
There was a problem hiding this comment.
[bug] Hop does not run an inline script through a shell. On Linux and macOS ActionShell writes this text to a temp file, marks it executable, and ProcessBuilder execs that file. Without a shebang the kernel returns ENOEXEC (Exec format error), the action fails, and the note that echo works on every operating system is wrong. A #!/bin/sh first line is not enough on its own either: Windows runs the same text as a .bat file, and cmd.exe treats #!/bin/sh as a command.
The failure hop only writes a log line. Write to log succeeds, so the workflow result stays successful and read-samples-build-hop-run will not notice that the script never ran.
Suggestion: Branch with the JavaScript action (is_windows is already in scope). On Windows keep echo Hello from the Shell action. On Linux and macOS use a script whose first line is #!/bin/sh. Point the failure hop at an Abort action so a script that does not run fails the sample.
There was a problem hiding this comment.
The failure hop now goes to an Abort action, so a script that fails also fails the sample (tested with exit 3: hop-run returns rc=1).
I didn't add a shebang. When exec returns ENOEXEC, both the JDK and libc rerun the file with /bin/sh. The shebang-less temp script runs fine through ProcessBuilder and hop-run on Linux, and #!/bin/sh would break the Windows .bat run.
| <field> | ||
| <action_type>sign</action_type> | ||
| <source_filefolder>${java.io.tmpdir}/hop-samples/pgp/report.csv</source_filefolder> | ||
| <userid>${PGP_USER_ID}</userid> |
There was a problem hiding this comment.
[bug] This row is the sign step, but userid is only the encryption recipient. ActionPGPEncryptFiles signs with local_user (gpg -u) and explicitly ignores userid for action_type sign, logging UserIdIgnoredWhenSigning. The note tells you to set PGP_USER_ID as the key, yet this step leaves local_user empty, so GnuPG signs with its default secret key instead of that id. Encrypt above is fine; sign and the following verify are not using the key the sample documents.
Suggestion: On the sign field, set local_user to ${PGP_USER_ID} and drop userid (or leave it empty). Keep userid only on the encrypt row.
There was a problem hiding this comment.
Fixed: the sign row now uses local_user = ${PGP_USER_ID}, and userid is only on the encrypt row. I tested with a second key set as the GnuPG default, and the signature now comes from the PGP_USER_ID key.
…a failed Shell sample script
…n actions/requires-setup. fixes #2238
Please add a meaningful description for your change here
Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:
mvn clean install apache-rat:checkto make sure basic checks pass. A more thorough check will be performed on your pull request automatically.git rebase -i.addresses #123), if applicable.To make clear that you license your contribution under the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.