-
Notifications
You must be signed in to change notification settings - Fork 2
98 lines (94 loc) · 4.06 KB
/
Copy pathci.yml
File metadata and controls
98 lines (94 loc) · 4.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
build-and-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: '1.26'
- name: Build
run: go build -v ./...
- name: Test
run: go test -v -count=1 ./...
- name: Race detector
run: go test -race -count=1 ./...
- name: Vet
run: go vet ./...
- name: Vet (windows target)
# The Windows platform layer (platform_windows.go, windows_scan.go,
# windows_enum.go) compiles+ vets on every push: a Linux-only eye
# must never be the only one that saw the Windows code.
run: GOOS=windows go vet ./...
- name: Gofmt
run: test -z "$(gofmt -l .)"
# The lab's --json --quiet contract (nothing but one JSON document on
# stdout; lab progress goes to stderr) is load-bearing for the README's
# `lab/rootless_lab.sh --json --quiet | jq '.summary'` promise. This smoke
# test exercises the REAL lab inside a user namespace on every push, so a
# future echo that leaks to stdout fails CI instead of silently breaking
# every jq-based consumer (round-6 security review recommendation).
lab-smoke:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: '1.26'
- name: Enable unprivileged user namespaces
# Ubuntu 24.04 runners ship AppArmor's unprivileged-userns
# restriction ON, which makes the lab's `unshare -r -m` fail with
# EPERM (actions/runner-images#10109). The lab needs a mapped-root
# user namespace; nothing else on the runner depends on this
# sysctl, and the VM is ephemeral.
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
- name: Lab smoke test — --json --quiet stdout contract
run: |
# Exit 1 is a COMPLETED read-only scan (no root obtained —
# the expected lab verdict, faithfully propagated by the
# lab script). Only >= 2 (usage/runtime error) breaks the
# stdout contract this step guards.
OUT=$(lab/rootless_lab.sh --json --quiet 2>/dev/null) || rc=$?
if [ "${rc:-0}" -ge 2 ]; then echo "lab exited $rc"; exit "$rc"; fi
echo "$OUT" | jq -e '.tool == "Auto-Privilege"' > /dev/null
echo "$OUT" | jq -e '.summary.findings > 0' > /dev/null
echo "$OUT" | jq -e '.summary.vectors > 0' > /dev/null
echo "lab stdout is a clean JSON report: OK"
# v1.9: the Windows platform layer runs FOR REAL on a Windows runner —
# build, vet and a live enumeration scan whose JSON contract is validated
# with PowerShell's own parser. The Windows binary must never be a
# cross-compile-only artifact that nobody executed.
windows:
runs-on: windows-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: '1.26'
- name: Build
run: go build -v ./...
- name: Vet
run: go vet ./...
- name: Test
# The suite is platform-agnostic by design (no syscall in tests);
# anything that only passes on Linux is a bug worth catching here.
run: go test -count=1 ./...
- name: Smoke — CLI contract on a real Windows host
run: |
go build -o autoprivilege.exe ./cmd/autoprivilege
./autoprivilege.exe --version
./autoprivilege.exe --list-vectors | Select-String "winpriv"
./autoprivilege.exe --explain winreg | Select-String "AlwaysInstallElevated"
./autoprivilege.exe --json --output win-scan.json
$j = Get-Content win-scan.json -Raw | ConvertFrom-Json
if ($j.tool -ne "Auto-Privilege") { throw "JSON contract broken: tool=$($j.tool)" }
if ($null -eq $j.summary) { throw "JSON contract broken: no summary" }
Write-Host "windows scan OK: findings=$($j.summary.findings) vectors=$($j.summary.vectors)"
shell: pwsh