Fix source-check CI so make test can pass on main - #7
Merged
Merged
Conversation
ubuntu-24.04 runners set apparmor_restrict_unprivileged_userns=1, so bwrap --unshare-net dies on RTM_NEWADDR before any sandbox probe runs. Lift that restriction on the disposable runner. The Codex missing-key case now stubs resolve_executable the same way the rest of the test already did, so hosts without the CLI still exercise "not configured". Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Firebreak launches via systemd-run --user. Hosts without a user session (this agent VM, and GitHub runners until linger is enabled) fail the shell containment script on a dbus error before any namespace check. Skip when the user bus is missing, matching the Python live-sandbox gate, and start a lingering user session on the disposable CI runner so the script still runs there. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
Once missions pass, the same workflow still dies later: - drift_gate treated git SHAs on the ISO readme as a second signing key because they sit next to an OpenPGP fingerprint line - tools/tests require qemu-img and qemu-system-x86_64 on the runner - the Firebreak shell script must probe systemd-run --user, not merely the presence of a leftover user bus socket Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
Those four attacks already skip when bwrap/systemd-run/ffmpeg are absent. On a host where the binaries exist but systemd-run --user cannot start a scope (no user manager), they used to fail as harness errors. Probe the wrapper the same way the Firebreak shell test does. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
…INE path The allowlist attack treated a Firebreak launch failure (no RESULT) as a containment failure. Skip that measurement when systemd-run --user cannot start the probe. Point attack_domain at the repo missions tree instead of a hardcoded 4.0.0 home path. Install slirp4netns on CI so hosted runners can run the live egress case. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
make test can pass on main
product_files() skipped any absolute path whose parts included work, build, tests, etc. Hosted runners check out under /home/runner/work, so the fireproof pin lists compared against an empty tree after missions went green. Match skip names against the path relative to packages/ instead. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
…ripts A shallow Actions checkout has no tags. After fireproof went green, five phoenix tests ERRORed on `git show v4.0.0:packages/shadowfetch-phoenix/...`. Fetch that tag so the published-vs-fixed comparison can run. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
make test is green on hosted runners. The next step json.loads every tracked .json file, including missions fixture broken-not-json.json, which exists to prove a provider manifest that never parses is refused. Do not require test fixtures to be valid JSON. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
Shadowfetchapps
marked this pull request as ready for review
September 20, 2026 15:59
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What failed
Default-branch workflow
.github/workflows/build-iso.yml(“Source and package checks”; does not build an ISO) has been red onmainsince the 4.1.0 fast-forward, including docs-only tipb214a9c. Failed step: Test behavior (make test, exit 2). After that gate was unblocked on this PR, later workflow steps failed in turn.Latest failing
mainruns:Root cause
make testis a stacked gate, and the workflow has two more steps after it. Unblocking each layer exposed the next env-specific failure:kernel.apparmor_restrict_unprivileged_userns=1makesbwrap --unshare-netfailRTM_NEWADDR(26 missions sandbox tests)."not configured"; CLI-not-found ran first becauseresolve_executablewas not stubbed.systemd-run --user, qemu, slirp4netns.attack_domainimported a hardcoded$HOME/.../4.0.0path.drift_gatetreated git SHAs next to a fingerprint as keys.product_files()skipped any absolute path containingwork(/home/runner/work/...emptied the scan).git show v4.0.0— shallow checkout has no tags; five restore/report proofs ERRORed.json.loadsevery tracked.json, including missions fixturebroken-not-json.json.Fix (smallest reversible)
v4.0.0.resolve_executablein the missing-key test.systemd-run --usercannot launch; resolveattack_domainENGINE from the repo tree; ignore prosecommitSHAs in the drift window.SKIP_PARTSagainst the path relative topackages/.tests/to be valid JSON.Verification
Local
make test: exited 0. Missions 1057 OK (26 skipped — this agent has no systemd as PID 1). Attacks: approval 15/15, lifecycle 3 PASS / 4 SKIP, concurrency 17 PASS / 1 SKIP, verifier 21/21, domain 0/16 undetected.CI: run 35509236740 on
c9d22c5— green (11m22s). Test behavior, source syntax, and unsigned packages all passed.