Skip to content

Fix source-check CI so make test can pass on main - #7

Merged
Shadowfetchapps merged 8 commits into
mainfrom
cursor/fix-ci-make-test-2f2c
Sep 20, 2026
Merged

Shadowfetchapps merged 8 commits into
mainfrom
cursor/fix-ci-make-test-2f2c

Conversation

@Shadowfetchapps

@Shadowfetchapps Shadowfetchapps commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

What failed

Default-branch workflow .github/workflows/build-iso.yml (“Source and package checks”; does not build an ISO) has been red on main since the 4.1.0 fast-forward, including docs-only tip b214a9c. Failed step: Test behavior (make test, exit 2). After that gate was unblocked on this PR, later workflow steps failed in turn.

Latest failing main runs:

Root cause

make test is a stacked gate, and the workflow has two more steps after it. Unblocking each layer exposed the next env-specific failure:

  1. bubblewrap + AppArmor — kernel.apparmor_restrict_unprivileged_userns=1 makes bwrap --unshare-net fail RTM_NEWADDR (26 missions sandbox tests).
  2. Codex missing-key test — expected "not configured"; CLI-not-found ran first because resolve_executable was not stubbed.
  3. Firebreak / later attacks — live probes need systemd-run --user, qemu, slirp4netns. attack_domain imported a hardcoded $HOME/.../4.0.0 path. drift_gate treated git SHAs next to a fingerprint as keys.
  4. Fireproof pin lists vs GHA path — product_files() skipped any absolute path containing work (/home/runner/work/... emptied the scan).
  5. Phoenix git show v4.0.0 — shallow checkout has no tags; five restore/report proofs ERRORed.
  6. Source-syntax JSON scan — json.loads every tracked .json, including missions fixture broken-not-json.json.

Fix (smallest reversible)

  • Lift AppArmor userns restriction; start a lingering systemd user session; install qemu + slirp4netns; fetch tag v4.0.0.
  • Stub Codex resolve_executable in the missing-key test.
  • Skip Firebreak/lifecycle/allowlist measurements when systemd-run --user cannot launch; resolve attack_domain ENGINE from the repo tree; ignore prose commit SHAs in the drift window.
  • Match fireproof SKIP_PARTS against the path relative to packages/.
  • Do not require files under tests/ to be valid JSON.

Verification

Local make test: exited 0. Missions 1057 OK (26 skipped — this agent has no systemd as PID 1). Attacks: approval 15/15, lifecycle 3 PASS / 4 SKIP, concurrency 17 PASS / 1 SKIP, verifier 21/21, domain 0/16 undetected.

CI: run 35509236740 on c9d22c5 — green (11m22s). Test behavior, source syntax, and unsigned packages all passed.

Open in Web Open in Cursor 

ubuntu-24.04 runners set apparmor_restrict_unprivileged_userns=1, so
bwrap --unshare-net dies on RTM_NEWADDR before any sandbox probe runs.
Lift that restriction on the disposable runner. The Codex missing-key
case now stubs resolve_executable the same way the rest of the test
already did, so hosts without the CLI still exercise "not configured".

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e87cfb70-dc8b-4b9c-a510-a01292f6e96e


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

cursoragent and others added 4 commits September 20, 2026 10:54
Firebreak launches via systemd-run --user. Hosts without a user session
(this agent VM, and GitHub runners until linger is enabled) fail the
shell containment script on a dbus error before any namespace check.
Skip when the user bus is missing, matching the Python live-sandbox
gate, and start a lingering user session on the disposable CI runner
so the script still runs there.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
Once missions pass, the same workflow still dies later:

- drift_gate treated git SHAs on the ISO readme as a second signing key
  because they sit next to an OpenPGP fingerprint line
- tools/tests require qemu-img and qemu-system-x86_64 on the runner
- the Firebreak shell script must probe systemd-run --user, not merely
  the presence of a leftover user bus socket

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
Those four attacks already skip when bwrap/systemd-run/ffmpeg are
absent. On a host where the binaries exist but systemd-run --user
cannot start a scope (no user manager), they used to fail as harness
errors. Probe the wrapper the same way the Firebreak shell test does.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
…INE path

The allowlist attack treated a Firebreak launch failure (no RESULT) as a
containment failure. Skip that measurement when systemd-run --user cannot
start the probe. Point attack_domain at the repo missions tree instead of a
hardcoded 4.0.0 home path. Install slirp4netns on CI so hosted runners can
run the live egress case.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
@cursor cursor Bot changed the title Fix source-check CI: bubblewrap loopback and Codex test isolation Fix source-check CI so make test can pass on main Sep 20, 2026
cursoragent and others added 3 commits September 20, 2026 11:39
product_files() skipped any absolute path whose parts included work,
build, tests, etc. Hosted runners check out under /home/runner/work,
so the fireproof pin lists compared against an empty tree after
missions went green. Match skip names against the path relative to
packages/ instead.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
…ripts

A shallow Actions checkout has no tags. After fireproof went green, five
phoenix tests ERRORed on `git show v4.0.0:packages/shadowfetch-phoenix/...`.
Fetch that tag so the published-vs-fixed comparison can run.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
make test is green on hosted runners. The next step json.loads every
tracked .json file, including missions fixture broken-not-json.json,
which exists to prove a provider manifest that never parses is refused.
Do not require test fixtures to be valid JSON.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
@Shadowfetchapps
Shadowfetchapps marked this pull request as ready for review September 20, 2026 15:59
@Shadowfetchapps
Shadowfetchapps merged commit 2ce2465 into main Sep 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants