From 2390e2ce9a0615b766627fc2ffbe21546170c7d4 Mon Sep 17 00:00:00 2001 From: Julian Gruber Date: Wed, 30 Sep 2026 14:56:57 +0200 Subject: [PATCH] ci: add a regression test for the sfw download fallback test-sfw-regression.yml runs on every pull request. It forces the one way this action has taken a customer install down, the binary download failing at its only origin, by pointing GitHub or the mirror at 127.0.0.1 in the hosts file, and asserts the install still succeeds from the other origin. It is deterministic and runs once per runner (windows-2025, ubuntu-26.04). Tests of the sfw binary's own behaviour live in SocketDev/firewall, next to the code they test. Fleet form: inline bootstrap checkout, no third-party actions, pinned runner images, named steps. --- .github/workflows/test-sfw-regression.yml | 77 +++++++++++++++++++++++ 1 file changed, 77 insertions(+) create mode 100644 .github/workflows/test-sfw-regression.yml diff --git a/.github/workflows/test-sfw-regression.yml b/.github/workflows/test-sfw-regression.yml new file mode 100644 index 0000000..af942a7 --- /dev/null +++ b/.github/workflows/test-sfw-regression.yml @@ -0,0 +1,77 @@ +name: 'test: sfw regression' +run-name: 'test: sfw regression' + +# Regression test for the one way THIS action has taken a customer install +# down: the sfw binary download failing at its only origin. It forces the +# failure against the checked-out action and asserts the fallback holds. It is +# deterministic and runs once, so it runs on every pull request. Tests of the +# sfw binary's own behaviour live in SocketDev/firewall. + +on: + push: + branches: [main] + pull_request: + branches: [main] + workflow_dispatch: + +permissions: + contents: read + +jobs: + fault-download-origin: + name: 'Block a download origin (${{ matrix.os }}, ${{ matrix.blocked }})' + runs-on: ${{ matrix.os }} + timeout-minutes: 20 + strategy: + fail-fast: false + matrix: + os: [windows-2025, ubuntu-26.04] + # Each origin must carry the install alone. The github case only + # passes with the mirror fallback in the checked-out action. + blocked: [github, mirror] + steps: + - name: 'Bootstrap checkout' + shell: bash + env: + GITHUB_TOKEN: ${{ github.token }} + SERVER_URL: ${{ github.server_url }} + REPOSITORY: ${{ github.repository }} + TRIGGER_REF: ${{ github.sha }} + run: | + set -euo pipefail + git init -q + git config --local advice.detachedHead false + git remote add origin "${SERVER_URL}/${REPOSITORY}" + AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')" + export GIT_CONFIG_COUNT=1 + export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" + export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" + git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}" + git checkout -q --detach FETCH_HEAD + - name: 'Block the origin in the hosts file' + shell: bash + env: + BLOCKED: ${{ matrix.blocked }} + RUNNER_OS: ${{ runner.os }} + run: | + set -euo pipefail + if [ "$RUNNER_OS" = Windows ]; then HOSTS="$WINDIR/System32/drivers/etc/hosts"; else HOSTS=/etc/hosts; fi + if [ "$BLOCKED" = github ]; then + hosts="github.com objects.githubusercontent.com release-assets.githubusercontent.com" + else + hosts="install.socket.dev" + fi + # 127.0.0.1 refuses the connection at once. A black-hole address would + # make every attempt wait out a TCP connect timeout, which on Linux + # outlives the job. + for h in $hosts; do printf '127.0.0.1 %s\n' "$h" | sudo tee -a "$HOSTS" > /dev/null 2>&1 || printf '127.0.0.1 %s\n' "$h" >> "$HOSTS"; done + [ "$RUNNER_OS" = Windows ] && ipconfig //flushdns > /dev/null || true + - name: 'Install socket firewall via the remaining origin' + uses: ./ + with: + mode: firewall + job-summary: errors + use-cache: 'false' + - name: 'Run the installed binary' + shell: bash + run: sfw --version