From 08c123299a372bb708b8eb9c520e758e4f6f10bc Mon Sep 17 00:00:00 2001 From: silverwind Date: Mon, 5 Oct 2026 07:04:11 +0200 Subject: [PATCH] revert: return 401 for unregistered runner (#39599) Reverts the backport https://github.com/go-gitea/gitea/pull/39585 before v28.0.1 ships. The change stays on main for v29. gitea-runner v4.1.0 recognizes a rejected registration only by the old `Unknown`-coded `rpc error: code = Unauthenticated desc = unregistered runner` error. With the new `Unauthenticated` reply, an ephemeral runner keeps its spent registration file and fails on every restart instead of registering again. The runner fix is in https://gitea.com/gitea/runner/pulls/1287, so a patch release shouldn't change runner behavior before that fix has shipped. Written by Claude Code. --- routers/api/actions/runner/interceptor.go | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/routers/api/actions/runner/interceptor.go b/routers/api/actions/runner/interceptor.go index e981deff303..8b79962c11d 100644 --- a/routers/api/actions/runner/interceptor.go +++ b/routers/api/actions/runner/interceptor.go @@ -27,9 +27,6 @@ const ( ) var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unaryFunc connect.UnaryFunc) connect.UnaryFunc { - // A plain gRPC status.Error is treated as unknown by Connect and becomes HTTP 500 - // To respond an HTTP status code, use connect.Error instead - errUnregisteredRunner := connect.NewError(connect.CodeUnauthenticated, errors.New("unregistered runner")) return func(ctx context.Context, request connect.AnyRequest) (connect.AnyResponse, error) { methodName := getMethodName(request) if methodName == "Register" { @@ -41,12 +38,12 @@ var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unar runner, err := actions_model.GetRunnerByUUID(ctx, uuid) if err != nil { if errors.Is(err, util.ErrNotExist) { - return nil, errUnregisteredRunner + return nil, status.Error(codes.Unauthenticated, "unregistered runner") } return nil, status.Error(codes.Internal, err.Error()) } if !util.CryptoConstTimeEqual(runner.TokenHash, auth_model.HashToken(token, runner.TokenSalt)) { - return nil, errUnregisteredRunner + return nil, status.Error(codes.Unauthenticated, "unregistered runner") } now := time.Now()