From e1f0b4975446ab83e2089578145a2de1b9e4be27 Mon Sep 17 00:00:00 2001 From: zqlit Date: Thu, 1 Oct 2026 12:37:22 +0800 Subject: [PATCH] =?UTF-8?q?fix(ci):=20=E4=BF=AE=E5=A4=8D=E6=8F=90=E4=BA=A4?= =?UTF-8?q?=E4=BF=A1=E6=81=AF=E5=90=AB=20${{=20}}=20=E5=AD=97=E6=A0=B7?= =?UTF-8?q?=E5=AF=BC=E8=87=B4=20pre-check=20=E5=B4=A9=E6=BA=83?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 根因:pre-check 的 Validate commit 步骤把 commit message 直接插值进 shell 脚本: COMMIT_MESSAGE="${{ github.event.head_commit.message }}" 多行提交信息会撑破脚本;若正文里出现 ${{ ... }} 之类字样(例如上一次提交 正文中的 ${{ gitea.* }}),bash 会把它当变量展开并报 "bad substitution", exit 1 → pre-check failure → build 被 skip。 实证(Gitea task 35 日志): /var/run/act/workflow/commit-check: line 20: perf(ci): 兼容 GitHub Actions... : bad substitution ❌ Failure - Main Validate commit (only for push events) 修复:改用 step 级 env: 传值(COMMIT_AUTHOR / COMMIT_MESSAGE), commit message 不再进入脚本文本。GitHub Actions 与 Gitea Actions 行为一致,两边都安全,同时消除命令注入面。 本次提交正文刻意保留了 ${{ gitea.* }} 字样,作为该修复的回归验证。 --- .github/workflows/deploy.yml | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 553fb48d..afaf9579 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -50,10 +50,13 @@ jobs: - name: Validate commit (only for push events) if: github.event_name == 'push' id: commit-check + # 注意:commit message 是用户可控的多行文本,必须经 env 传入。 + # 直接写 ${{ github.event.head_commit.message }} 会把内容展开进脚本, + # 多行信息或含 $ / ` 的字符会导致 "bad substitution" 甚至命令注入。 + env: + COMMIT_AUTHOR: ${{ github.event.head_commit.author.name }} + COMMIT_MESSAGE: ${{ github.event.head_commit.message }} run: | - COMMIT_AUTHOR="${{ github.event.head_commit.author.name }}" - COMMIT_MESSAGE="${{ github.event.head_commit.message }}" - echo "📝 提交作者: $COMMIT_AUTHOR" echo "📄 提交信息: $COMMIT_MESSAGE"