From cdb3217694106461882d9458f02524a61fc5f09f Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:42:34 +0000 Subject: [PATCH] Stop GPG agent before verification home cleanup Co-authored-by: brunoborges <129743+brunoborges@users.noreply.github.com> --- __tests__/gpg.test.ts | 27 ++++++++++++++++++++++----- dist/cleanup/index.js | 8 ++++++-- dist/setup/220.index.js | 8 ++++++-- dist/setup/463.index.js | 8 ++++++-- dist/setup/81.index.js | 8 ++++++-- src/gpg.ts | 10 +++++++--- 6 files changed, 53 insertions(+), 16 deletions(-) diff --git a/__tests__/gpg.test.ts b/__tests__/gpg.test.ts index f9a0ca3c..93c4593a 100644 --- a/__tests__/gpg.test.ts +++ b/__tests__/gpg.test.ts @@ -236,7 +236,12 @@ describe('gpg tests', () => { process.env['RUNNER_TEMP'] = tempDir; }); - it.each(['success', 'import failure', 'verification failure'])( + it.each([ + 'success', + 'import failure', + 'verification failure', + 'gpgconf unavailable' + ])( 'uses a short macOS home or RUNNER_TEMP elsewhere and cleans up after %s', async outcome => { const longRunnerTemp = path.join( @@ -257,9 +262,16 @@ describe('gpg tests', () => { fs.writeFileSync(signaturePath, 'signature'); (tc.downloadTool as jest.Mock).mockResolvedValue(signaturePath); (exec.exec as jest.Mock).mockImplementation( - async (_command: string, args: string[]) => { + async (command: string, args: string[]) => { gpgHome = path.join(expectedParent, path.posix.basename(args[1])); expect(args[1]).toBe(gpg.toGpgPath(gpgHome)); + if (command === 'gpgconf') { + expect(fs.existsSync(gpgHome)).toBe(true); + if (outcome === 'gpgconf unavailable') { + throw new Error('gpgconf unavailable'); + } + return 0; + } if (process.platform === 'darwin') { expect( Buffer.byteLength(path.join(gpgHome, 'S.gpg-agent.browser')) @@ -287,13 +299,18 @@ describe('gpg tests', () => { 'https://example.com/jdk.tar.gz.sig', 'public key' ); - if (outcome === 'success') { + if (outcome === 'success' || outcome === 'gpgconf unavailable') { await verification; } else { await expect(verification).rejects.toThrow(outcome); } expect(exec.exec).toHaveBeenCalledTimes( - outcome === 'import failure' ? 1 : 2 + outcome === 'import failure' ? 2 : 3 + ); + expect(exec.exec).toHaveBeenLastCalledWith( + 'gpgconf', + ['--homedir', gpg.toGpgPath(gpgHome), '--kill', 'gpg-agent'], + {silent: true, ignoreReturnCode: true} ); expect(fs.existsSync(gpgHome)).toBe(false); expect(fs.existsSync(signaturePath)).toBe(false); @@ -368,7 +385,7 @@ describe('gpg tests', () => { ], expect.objectContaining({silent: true}) ); - expect(exec.exec).toHaveBeenCalledTimes(2); + expect(exec.exec).toHaveBeenCalledTimes(3); }); }); }); diff --git a/dist/cleanup/index.js b/dist/cleanup/index.js index 00ad7724..d22ce764 100644 --- a/dist/cleanup/index.js +++ b/dist/cleanup/index.js @@ -35832,13 +35832,16 @@ async function removeGpgHome(gpgHome) { if (!external_fs_.existsSync(resolvedGpgHome)) { return; } + await stopGpgAgent(resolvedGpgHome); + await lib_io/* rmRF */.Yz(resolvedGpgHome); +} +async function stopGpgAgent(gpgHome) { try { - await lib_exec/* exec */.m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); + await lib_exec/* exec */.m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); } catch { // gpgconf may be unavailable, but directory removal must still be attempted. } - await lib_io/* rmRF */.Yz(resolvedGpgHome); } async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { const signaturePath = await tc.downloadTool(signatureUrl); @@ -35884,6 +35887,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten ], options); } finally { + await stopGpgAgent(gpgHome); await io.rmRF(signaturePath); await io.rmRF(gpgHome); } diff --git a/dist/setup/220.index.js b/dist/setup/220.index.js index f5cfebc7..d1ae361f 100644 --- a/dist/setup/220.index.js +++ b/dist/setup/220.index.js @@ -263,13 +263,16 @@ async function removeGpgHome(gpgHome) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { return; } + await stopGpgAgent(resolvedGpgHome); + await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); +} +async function stopGpgAgent(gpgHome) { try { - await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); + await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); } catch { // gpgconf may be unavailable, but directory removal must still be attempted. } - await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); } async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); @@ -315,6 +318,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten ], options); } finally { + await stopGpgAgent(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); } diff --git a/dist/setup/463.index.js b/dist/setup/463.index.js index 02b5bfc9..226dd024 100644 --- a/dist/setup/463.index.js +++ b/dist/setup/463.index.js @@ -375,13 +375,16 @@ async function removeGpgHome(gpgHome) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { return; } + await stopGpgAgent(resolvedGpgHome); + await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); +} +async function stopGpgAgent(gpgHome) { try { - await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); + await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); } catch { // gpgconf may be unavailable, but directory removal must still be attempted. } - await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); } async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); @@ -427,6 +430,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten ], options); } finally { + await stopGpgAgent(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); } diff --git a/dist/setup/81.index.js b/dist/setup/81.index.js index 3ac82d8f..1aecd7fa 100644 --- a/dist/setup/81.index.js +++ b/dist/setup/81.index.js @@ -350,13 +350,16 @@ async function removeGpgHome(gpgHome) { if (!fs__WEBPACK_IMPORTED_MODULE_0__.existsSync(resolvedGpgHome)) { return; } + await stopGpgAgent(resolvedGpgHome); + await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); +} +async function stopGpgAgent(gpgHome) { try { - await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); + await _actions_exec__WEBPACK_IMPORTED_MODULE_4__/* .exec */ .m('gpgconf', ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], { silent: true, ignoreReturnCode: true }); } catch { // gpgconf may be unavailable, but directory removal must still be attempted. } - await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(resolvedGpgHome); } async function verifyPackageSignature(archivePath, signatureUrl, publicKeyContent) { const signaturePath = await _actions_tool_cache__WEBPACK_IMPORTED_MODULE_5__/* .downloadTool */ .bq(signatureUrl); @@ -402,6 +405,7 @@ async function verifyPackageSignature(archivePath, signatureUrl, publicKeyConten ], options); } finally { + await stopGpgAgent(gpgHome); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(signaturePath); await _actions_io__WEBPACK_IMPORTED_MODULE_3__/* .rmRF */ .Yz(gpgHome); } diff --git a/src/gpg.ts b/src/gpg.ts index b522d126..4ea4044d 100644 --- a/src/gpg.ts +++ b/src/gpg.ts @@ -89,17 +89,20 @@ export async function removeGpgHome(gpgHome: string): Promise { return; } + await stopGpgAgent(resolvedGpgHome); + await io.rmRF(resolvedGpgHome); +} + +async function stopGpgAgent(gpgHome: string): Promise { try { await exec.exec( 'gpgconf', - ['--homedir', toGpgPath(resolvedGpgHome), '--kill', 'gpg-agent'], + ['--homedir', toGpgPath(gpgHome), '--kill', 'gpg-agent'], {silent: true, ignoreReturnCode: true} ); } catch { // gpgconf may be unavailable, but directory removal must still be attempted. } - - await io.rmRF(resolvedGpgHome); } export async function verifyPackageSignature( @@ -160,6 +163,7 @@ export async function verifyPackageSignature( options ); } finally { + await stopGpgAgent(gpgHome); await io.rmRF(signaturePath); await io.rmRF(gpgHome); }