Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
77 changes: 77 additions & 0 deletions .github/workflows/test-sfw-regression.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
name: 'test: sfw regression'
run-name: 'test: sfw regression'

# Regression test for the one way THIS action has taken a customer install
# down: the sfw binary download failing at its only origin. It forces the
# failure against the checked-out action and asserts the fallback holds. It is
# deterministic and runs once, so it runs on every pull request. Tests of the
# sfw binary's own behaviour live in SocketDev/firewall.

on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:

permissions:
contents: read

jobs:
fault-download-origin:
name: 'Block a download origin (${{ matrix.os }}, ${{ matrix.blocked }})'
runs-on: ${{ matrix.os }}
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
os: [windows-2025, ubuntu-26.04]
# Each origin must carry the install alone. The github case only
# passes with the mirror fallback in the checked-out action.
blocked: [github, mirror]
steps:
- name: 'Bootstrap checkout'
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
SERVER_URL: ${{ github.server_url }}
REPOSITORY: ${{ github.repository }}
TRIGGER_REF: ${{ github.sha }}
run: |
set -euo pipefail
git init -q
git config --local advice.detachedHead false
git remote add origin "${SERVER_URL}/${REPOSITORY}"
AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')"
export GIT_CONFIG_COUNT=1
export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader"
export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}"
git checkout -q --detach FETCH_HEAD
- name: 'Block the origin in the hosts file'
shell: bash
env:
BLOCKED: ${{ matrix.blocked }}
RUNNER_OS: ${{ runner.os }}
run: |
set -euo pipefail
if [ "$RUNNER_OS" = Windows ]; then HOSTS="$WINDIR/System32/drivers/etc/hosts"; else HOSTS=/etc/hosts; fi
if [ "$BLOCKED" = github ]; then
hosts="github.com objects.githubusercontent.com release-assets.githubusercontent.com"
else
hosts="install.socket.dev"
fi
# 127.0.0.1 refuses the connection at once. A black-hole address would
# make every attempt wait out a TCP connect timeout, which on Linux
# outlives the job.
for h in $hosts; do printf '127.0.0.1 %s\n' "$h" | sudo tee -a "$HOSTS" > /dev/null 2>&1 || printf '127.0.0.1 %s\n' "$h" >> "$HOSTS"; done
[ "$RUNNER_OS" = Windows ] && ipconfig //flushdns > /dev/null || true
- name: 'Install socket firewall via the remaining origin'
uses: ./
with:
mode: firewall
job-summary: errors
use-cache: 'false'
- name: 'Run the installed binary'
shell: bash
run: sfw --version