From 2f99677deec6d910e8a20b4e8d4b71482a2b1d3a Mon Sep 17 00:00:00 2001 From: Joshua Hoblitt Date: Mon, 22 Jun 2026 16:04:55 -0700 Subject: [PATCH] ci: fix shellcheck issues in composite actions actionlint only understands workflow files, so the .github/actionlint.yaml ignore keeps the composite action definitions out of `make lint.workflows`. Apply the same shellcheck fixes there anyway, found by running shellcheck over their run: blocks directly: - quote unquoted variable expansions (SC2086): the $GITHUB_ENV writes in collect-logs, tmate_debug and upterm_debug, and ${ARCH} in the cri-dockerd install in integration-test-setup-cluster-resources - split `export BLOCK=$(...)` into a separate assignment and export so a failing command substitution is not masked (SC2155) in encryption-pvc-kms-ibm-kp Signed-off-by: Joshua Hoblitt (cherry picked from commit 48dacb18945c823b355fe39c54930a6f2d188070) --- .github/workflows/collect-logs/action.yaml | 2 +- .github/workflows/encryption-pvc-kms-ibm-kp/action.yml | 3 ++- .../integration-test-setup-cluster-resources/action.yaml | 6 +++--- .github/workflows/tmate_debug/action.yml | 2 +- .github/workflows/upterm_debug/action.yml | 2 +- 5 files changed, 8 insertions(+), 7 deletions(-) diff --git a/.github/workflows/collect-logs/action.yaml b/.github/workflows/collect-logs/action.yaml index dfbf6feb5..6910916b5 100644 --- a/.github/workflows/collect-logs/action.yaml +++ b/.github/workflows/collect-logs/action.yaml @@ -21,7 +21,7 @@ runs: no_slash="${no_colon////-}" # echo to $GITHUB_OUTPUT doesn't work in composite steps: # https://github.com/actions/runner/issues/2009#issuecomment-1793565031 - echo "ARTIFACT_NAME=${no_slash}" >> $GITHUB_ENV + echo "ARTIFACT_NAME=${no_slash}" >> "$GITHUB_ENV" - name: collect common logs shell: bash --noprofile --norc -eo pipefail -x {0} diff --git a/.github/workflows/encryption-pvc-kms-ibm-kp/action.yml b/.github/workflows/encryption-pvc-kms-ibm-kp/action.yml index 3c2a4232a..1aa32efc4 100644 --- a/.github/workflows/encryption-pvc-kms-ibm-kp/action.yml +++ b/.github/workflows/encryption-pvc-kms-ibm-kp/action.yml @@ -46,7 +46,8 @@ runs: - name: create cluster prerequisites shell: bash --noprofile --norc -eo pipefail -x {0} run: | - export BLOCK="/dev/$(tests/scripts/github-action-helper.sh find_extra_block_dev)" + BLOCK="/dev/$(tests/scripts/github-action-helper.sh find_extra_block_dev)" + export BLOCK tests/scripts/localPathPV.sh "$BLOCK" tests/scripts/github-action-helper.sh create_cluster_prerequisites diff --git a/.github/workflows/integration-test-setup-cluster-resources/action.yaml b/.github/workflows/integration-test-setup-cluster-resources/action.yaml index b4f18f598..9f38b6da2 100644 --- a/.github/workflows/integration-test-setup-cluster-resources/action.yaml +++ b/.github/workflows/integration-test-setup-cluster-resources/action.yaml @@ -28,9 +28,9 @@ runs: ARCH=$(go env GOARCH) # --fail so an HTTP error page is not saved as the .deb (dpkg then fails on the # corrupt archive), and retry transient download errors - curl -fLO --retry 5 --retry-all-errors --retry-delay 10 https://github.com/Mirantis/cri-dockerd/releases/download/v0.3.21/cri-dockerd_0.3.21.3-0.ubuntu-focal_${ARCH}.deb - sudo dpkg -i cri-dockerd_0.3.21.3-0.ubuntu-focal_${ARCH}.deb - rm -f cri-dockerd_0.3.21.3-0.ubuntu-focal_${ARCH}.deb + curl -fLO --retry 5 --retry-all-errors --retry-delay 10 https://github.com/Mirantis/cri-dockerd/releases/download/v0.3.21/cri-dockerd_0.3.21.3-0.ubuntu-focal_"${ARCH}".deb + sudo dpkg -i cri-dockerd_0.3.21.3-0.ubuntu-focal_"${ARCH}".deb + rm -f cri-dockerd_0.3.21.3-0.ubuntu-focal_"${ARCH}".deb - name: Setup Minikube uses: medyagh/setup-minikube@latest diff --git a/.github/workflows/tmate_debug/action.yml b/.github/workflows/tmate_debug/action.yml index 7486ab0ba..9fa4f2254 100644 --- a/.github/workflows/tmate_debug/action.yml +++ b/.github/workflows/tmate_debug/action.yml @@ -16,7 +16,7 @@ runs: run: | # Enable tmate only in the Rook fork, where the USE_TMATE secret is set in the repo, or if the action is re-run if [ "$GITHUB_REPOSITORY_OWNER" = "rook" ] || [ -n "${{ inputs.use-tmate }}" ] || [ "$GITHUB_RUN_ATTEMPT" -gt 1 ]; then - echo ENABLE_TMATE=1 >> $GITHUB_ENV + echo ENABLE_TMATE=1 >> "$GITHUB_ENV" fi - name: set up tmate session diff --git a/.github/workflows/upterm_debug/action.yml b/.github/workflows/upterm_debug/action.yml index 7cc1cce78..ebabaad1f 100644 --- a/.github/workflows/upterm_debug/action.yml +++ b/.github/workflows/upterm_debug/action.yml @@ -13,7 +13,7 @@ runs: run: | # Enable upterm only in the main Rook repo, where the USE_TMATE secret is set in the repo, or if the action is re-run if [ "$GITHUB_REPOSITORY_OWNER" = "rook" ] || [ "$GITHUB_RUN_ATTEMPT" -gt 1 ]; then - echo ENABLE_UPTERM=1 >> $GITHUB_ENV + echo ENABLE_UPTERM=1 >> "$GITHUB_ENV" fi - name: set up upterm session