Stop GPG agent before removing signature-verification home (#1273)

* Initial plan

* Stop GPG agent before verification home cleanup

Co-authored-by: brunoborges <129743+brunoborges@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: brunoborges <129743+brunoborges@users.noreply.github.com>
This commit is contained in:
Copilot
2026-09-28 21:26:40 -04:00
committed by GitHub
parent 97c5a5e13a
commit a78ec39f12
6 changed files with 53 additions and 16 deletions
+22 -5
View File
@@ -236,7 +236,12 @@ describe('gpg tests', () => {
process.env['RUNNER_TEMP'] = tempDir; process.env['RUNNER_TEMP'] = tempDir;
}); });
it.each(['success', 'import failure', 'verification failure'])( it.each([
'success',
'import failure',
'verification failure',
'gpgconf unavailable'
])(
'uses a short macOS home or RUNNER_TEMP elsewhere and cleans up after %s', 'uses a short macOS home or RUNNER_TEMP elsewhere and cleans up after %s',
async outcome => { async outcome => {
const longRunnerTemp = path.join( const longRunnerTemp = path.join(
@@ -257,9 +262,16 @@ describe('gpg tests', () => {
fs.writeFileSync(signaturePath, 'signature'); fs.writeFileSync(signaturePath, 'signature');
(tc.downloadTool as jest.Mock<any>).mockResolvedValue(signaturePath); (tc.downloadTool as jest.Mock<any>).mockResolvedValue(signaturePath);
(exec.exec as jest.Mock<any>).mockImplementation( (exec.exec as jest.Mock<any>).mockImplementation(
async (_command: string, args: string[]) => { async (command: string, args: string[]) => {
gpgHome = path.join(expectedParent, path.posix.basename(args[1])); gpgHome = path.join(expectedParent, path.posix.basename(args[1]));
expect(args[1]).toBe(gpg.toGpgPath(gpgHome)); expect(args[1]).toBe(gpg.toGpgPath(gpgHome));
if (command === 'gpgconf') {
expect(fs.existsSync(gpgHome)).toBe(true);
if (outcome === 'gpgconf unavailable') {
throw new Error('gpgconf unavailable');
}
return 0;
}
if (process.platform === 'darwin') { if (process.platform === 'darwin') {
expect( expect(
Buffer.byteLength(path.join(gpgHome, 'S.gpg-agent.browser')) Buffer.byteLength(path.join(gpgHome, 'S.gpg-agent.browser'))
@@ -287,13 +299,18 @@ describe('gpg tests', () => {
'https://example.com/jdk.tar.gz.sig', 'https://example.com/jdk.tar.gz.sig',
'public key' 'public key'
); );
if (outcome === 'success') { if (outcome === 'success' || outcome === 'gpgconf unavailable') {
await verification; await verification;
} else { } else {
await expect(verification).rejects.toThrow(outcome); await expect(verification).rejects.toThrow(outcome);
} }
expect(exec.exec).toHaveBeenCalledTimes( expect(exec.exec).toHaveBeenCalledTimes(
outcome === 'import failure' ? 1 : 2 outcome === 'import failure' ? 2 : 3
);
expect(exec.exec).toHaveBeenLastCalledWith(
'gpgconf',
['--homedir', gpg.toGpgPath(gpgHome), '--kill', 'gpg-agent'],
{silent: true, ignoreReturnCode: true}
); );
expect(fs.existsSync(gpgHome)).toBe(false); expect(fs.existsSync(gpgHome)).toBe(false);
expect(fs.existsSync(signaturePath)).toBe(false); expect(fs.existsSync(signaturePath)).toBe(false);
@@ -368,7 +385,7 @@ describe('gpg tests', () => {
], ],
expect.objectContaining({silent: true}) expect.objectContaining({silent: true})
); );
expect(exec.exec).toHaveBeenCalledTimes(2); expect(exec.exec).toHaveBeenCalledTimes(3);
}); });
}); });
}); });
+6 -2
View File
@@ -35832,13 +35832,16 @@ async function removeGpgHome(gpgHome) {
if (!external_fs_.existsSync(resolvedGpgHome)) { if (!external_fs_.existsSync(resolvedGpgHome)) {
return; return;
} }
await stopGpgAgent(resolvedGpgHome);
await lib_io/* rmRF */.Yz(resolvedGpgHome);
}
async function stopGpgAgent(gpgHome) {
try { try {
await lib_exec/* exec */.m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); await lib_exec/* exec */.m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true });
} }
catch { catch {
// gpgconf may be unavailable, but directory removal must still be attempted. // gpgconf may be unavailable, but directory removal must still be attempted.
} }
await lib_io/* rmRF */.Yz(resolvedGpgHome);
} }
async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) {
const signaturePath = await tc.downloadTool(signatureUrl); const signaturePath = await tc.downloadTool(signatureUrl);
@@ -35884,6 +35887,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
], options); ], options);
} }
finally { finally {
await stopGpgAgent(gpgHome);
await io.rmRF(signaturePath); await io.rmRF(signaturePath);
await io.rmRF(gpgHome); await io.rmRF(gpgHome);
} }
+6 -2
View File
@@ -263,13 +263,16 @@ async function removeGpgHome(gpgHome) {
if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) {
return; return;
} }
await stopGpgAgent(resolvedGpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
}
async function stopGpgAgent(gpgHome) {
try { try {
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true });
} }
catch { catch {
// gpgconf may be unavailable, but directory removal must still be attempted. // gpgconf may be unavailable, but directory removal must still be attempted.
} }
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
} }
async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) {
const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl);
@@ -315,6 +318,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
], options); ], options);
} }
finally { finally {
await stopGpgAgent(gpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome);
} }
+6 -2
View File
@@ -375,13 +375,16 @@ async function removeGpgHome(gpgHome) {
if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) {
return; return;
} }
await stopGpgAgent(resolvedGpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
}
async function stopGpgAgent(gpgHome) {
try { try {
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true });
} }
catch { catch {
// gpgconf may be unavailable, but directory removal must still be attempted. // gpgconf may be unavailable, but directory removal must still be attempted.
} }
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
} }
async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) {
const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl);
@@ -427,6 +430,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
], options); ], options);
} }
finally { finally {
await stopGpgAgent(gpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome);
} }
+6 -2
View File
@@ -350,13 +350,16 @@ async function removeGpgHome(gpgHome) {
if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) {
return; return;
} }
await stopGpgAgent(resolvedGpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
}
async function stopGpgAgent(gpgHome) {
try { try {
await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true });
} }
catch { catch {
// gpgconf may be unavailable, but directory removal must still be attempted. // gpgconf may be unavailable, but directory removal must still be attempted.
} }
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome);
} }
async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) {
const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl);
@@ -402,6 +405,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten
], options); ], options);
} }
finally { finally {
await stopGpgAgent(gpgHome);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath);
await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome);
} }
+7 -3
View File
@@ -89,17 +89,20 @@ export async function removeGpgHome(gpgHome: string): Promise<void> {
return; return;
} }
await stopGpgAgent(resolvedGpgHome);
await io.rmRF(resolvedGpgHome);
}
async function stopGpgAgent(gpgHome: string): Promise<void> {
try { try {
await exec.exec( await exec.exec(
'gpgconf', 'gpgconf',
['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'],
{silent: true, ignoreReturnCode: true} {silent: true, ignoreReturnCode: true}
); );
} catch { } catch {
// gpgconf may be unavailable, but directory removal must still be attempted. // gpgconf may be unavailable, but directory removal must still be attempted.
} }
await io.rmRF(resolvedGpgHome);
} }
export async function verifyPackageSignature( export async function verifyPackageSignature(
@@ -160,6 +163,7 @@ export async function verifyPackageSignature(
options options
); );
} finally { } finally {
await stopGpgAgent(gpgHome);
await io.rmRF(signaturePath); await io.rmRF(signaturePath);
await io.rmRF(gpgHome); await io.rmRF(gpgHome);
} }