diff --git a/.github/workflows/test-sfw-regression.yml b/.github/workflows/test-sfw-regression.yml new file mode 100644 index 0000000..af942a7 --- /dev/null +++ b/.github/workflows/test-sfw-regression.yml @@ -0,0 +1,77 @@ +name: 'test: sfw regression' +run-name: 'test: sfw regression' + +# Regression test for the one way THIS action has taken a customer install +# down: the sfw binary download failing at its only origin. It forces the +# failure against the checked-out action and asserts the fallback holds. It is +# deterministic and runs once, so it runs on every pull request. Tests of the +# sfw binary's own behaviour live in SocketDev/firewall. + +on: + push: + branches: [main] + pull_request: + branches: [main] + workflow_dispatch: + +permissions: + contents: read + +jobs: + fault-download-origin: + name: 'Block a download origin (${{ matrix.os }}, ${{ matrix.blocked }})' + runs-on: ${{ matrix.os }} + timeout-minutes: 20 + strategy: + fail-fast: false + matrix: + os: [windows-2025, ubuntu-26.04] + # Each origin must carry the install alone. The github case only + # passes with the mirror fallback in the checked-out action. + blocked: [github, mirror] + steps: + - name: 'Bootstrap checkout' + shell: bash + env: + GITHUB_TOKEN: ${{ github.token }} + SERVER_URL: ${{ github.server_url }} + REPOSITORY: ${{ github.repository }} + TRIGGER_REF: ${{ github.sha }} + run: | + set -euo pipefail + git init -q + git config --local advice.detachedHead false + git remote add origin "${SERVER_URL}/${REPOSITORY}" + AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')" + export GIT_CONFIG_COUNT=1 + export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" + export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" + git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}" + git checkout -q --detach FETCH_HEAD + - name: 'Block the origin in the hosts file' + shell: bash + env: + BLOCKED: ${{ matrix.blocked }} + RUNNER_OS: ${{ runner.os }} + run: | + set -euo pipefail + if [ "$RUNNER_OS" = Windows ]; then HOSTS="$WINDIR/System32/drivers/etc/hosts"; else HOSTS=/etc/hosts; fi + if [ "$BLOCKED" = github ]; then + hosts="github.com objects.githubusercontent.com release-assets.githubusercontent.com" + else + hosts="install.socket.dev" + fi + # 127.0.0.1 refuses the connection at once. A black-hole address would + # make every attempt wait out a TCP connect timeout, which on Linux + # outlives the job. + for h in $hosts; do printf '127.0.0.1 %s\n' "$h" | sudo tee -a "$HOSTS" > /dev/null 2>&1 || printf '127.0.0.1 %s\n' "$h" >> "$HOSTS"; done + [ "$RUNNER_OS" = Windows ] && ipconfig //flushdns > /dev/null || true + - name: 'Install socket firewall via the remaining origin' + uses: ./ + with: + mode: firewall + job-summary: errors + use-cache: 'false' + - name: 'Run the installed binary' + shell: bash + run: sfw --version