Cleaning up the working directory fails if the application created files/directories under different UID/GID.
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 6.3k
- Forks
- 1.4k
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 24
Description
Describe the bug
In a GitHub-hosted runner the issue doesn't occur due to Azure clean-up strategy. While in the self-hosted runner is pretty common.
While the runtime creates the files owned by i.e. root under a non-root user (i.e. runner), the Post Checkout or whatever else fails to fully cleanup the working directory, resulting in further failures of the self-hosted and corruption of the pending steps / other workflows.
To Reproduce
Steps to reproduce the behavior:
- Create self-hosted runner.
- Run a workflow what's checking branch and creating a directory along with a file, both owned by root or other user.
- Create another workflow step what's checking out the same or other branch or re-run the workflow under the same repo or any other under the same runner.
- Get the error as follows:
Warning: Unable to clean or reset the repository. The repository will be recreated instead.
Deleting the contents of '/home/runner/actions-runner/_work/<working dir>/<repo>'
Error: File was unable to be removed Error: EACCES: permission denied, unlink '/home/runner/actions-runner/_work/<working dir>/<repo>/<root owned DIR>/<root owned FILE>'
Expected behavior
Once the step is finished, GitHub runner attempts to use SUDO as to cleanup remainings of the _work directory, in order to make sure the work zone is ready for the rest of the tasks.
Runner Version and Platform
Linux-x64-2.230.0
OS of the machine running the runner?
Debian 12 server
What's not working?
The final cleanup job of the runner.
Job Log Output
The log comes from https://github.com/GamePlayer-8/stoney-kernel/actions/runs/11687408761/job/32546565772
Run actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
with:
repository: GamePlayer-8/stoney-kernel
token: ***
ssh-strict: true
ssh-user: git
persist-credentials: true
clean: true
sparse-checkout-cone-mode: true
fetch-depth: 1
fetch-tags: false
show-progress: true
lfs: false
submodules: false
set-safe-directory: true
env:
DEBIAN_FRONTEND: noninteractive
TZ: Etc/UTC
Syncing repository: GamePlayer-8/stoney-kernel
Getting Git version info
Working directory is '/home/runner/actions-runner/_work/stoney-kernel/stoney-kernel'
/usr/bin/git version
git version 2.39.5
Temporarily overriding HOME='/home/runner/actions-runner/_work/_temp/099e3bdf-613f-4e79-a90d-85068bb500bc' before making global git config changes
Adding repository directory to the temporary git global config as a safe directory
/usr/bin/git config --global --add safe.directory /home/runner/actions-runner/_work/stoney-kernel/stoney-kernel
/usr/bin/git config --local --get remote.origin.url
https://github.com/GamePlayer-8/stoney-kernel
Removing previously created refs, to avoid conflicts
/usr/bin/git rev-parse --symbolic-full-name --verify --quiet HEAD
refs/heads/main
/usr/bin/git checkout --detach
HEAD is now at 1dd5b26 install gawk & diffutils to the alpine image
/usr/bin/git branch --delete --force main
Deleted branch main (was 1dd5b26).
/usr/bin/git submodule status
Cleaning the repository
Warning: Unable to clean or reset the repository. The repository will be recreated instead.
Deleting the contents of '/home/runner/actions-runner/_work/stoney-kernel/stoney-kernel'
Error: File was unable to be removed Error: EACCES: permission denied, unlink '/home/runner/actions-runner/_work/stoney-kernel/stoney-kernel/packages/kernel-alpine.tar.gz'
Runner and Worker's Diagnostic Logs
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the runner's final cleanup job and reproduce the failure on a self-hosted Debian 12 runner using files and directories owned by another UID/GID. No source files or tests are named; done means the working directory is cleaned successfully and later workflow steps are not blocked by permission errors.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp, git, github-actions, linux
- Domain
- ci-cd, devops, operating-systems
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100