Skip to content

fix: only chmod the nitro binary right after extracting it - #1

Merged
tobias-tengler merged 1 commit into
mainfrom
gai/skip-chmod-on-cached-nitro
Sep 2, 2026
Merged

tobias-tengler merged 1 commit into
mainfrom
gai/skip-chmod-on-cached-nitro

Conversation

@glen-84

@glen-84 glen-84 commented Sep 2, 2026

Copy link
Copy Markdown
Member

Summary

  • installNitro marks the Nitro binary executable only in the download branch, right after tc.cacheDir. A binary that tc.find returns from the tool cache is left untouched.
  • On self-hosted runners the tool cache is shared between jobs, and a job that runs in a container does so as root. When such a job is the first to cache a new Nitro release, the binary is root-owned, and the unconditional chmod +x that followed every cache hit failed with "Operation not permitted". That failed every host-user job using any Nitro action on that runner until the cache entry was deleted by hand. The cached binary is always already executable, because the job that installed it ran this same chmod.

Test plan

  • yarn install --immutable and tsc --noEmit pass.
  • The repo has no test runner, and the change moves one call inside an existing branch. End-to-end verification is a consumer action rebuilt against the published package and run twice on the same self-hosted runner: the first job downloads and runs chmod, the second hits the cache and skips it.

Copilot AI lite review requested due to automatic review settings September 2, 2026 18:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is small, locally contained, and directly addresses the reported failure mode without altering the cache-hit behavior beyond removing the failing chmod step.

Pull request overview

This PR adjusts installNitro to avoid attempting to chmod +x a Nitro binary when it was retrieved from the shared GitHub Actions tool cache, preventing failures on self-hosted runners where the cached binary may be owned by a different user (e.g., root from a container job).

Changes:

  • Move chmod +x so it only runs immediately after extracting and caching a newly downloaded Nitro release.
  • Leave tool-cache hits untouched to avoid EPERM/“Operation not permitted” failures on shared self-hosted runner caches.
File summaries
File Description
src/index.ts Restricts chmod +x to the fresh-download path to avoid failing on cache hits with mismatched file ownership.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@tobias-tengler
tobias-tengler merged commit 5b82aef into main Sep 2, 2026
1 check passed
@glen-84
glen-84 deleted the gai/skip-chmod-on-cached-nitro branch September 2, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants