Skip to content

Commit a823bd3

Browse files
committed
fix(ci): repair public workflow dependencies
1 parent 5965e99 commit a823bd3

8 files changed

Lines changed: 125 additions & 23 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@ updates:
88
groups:
99
github-actions:
1010
patterns: ["*"]
11+
ignore:
12+
# This action follows a moving branch without GitHub releases, which
13+
# Dependabot currently reports as an unknown update error.
14+
- dependency-name: dtolnay/rust-toolchain
1115

1216
- package-ecosystem: cargo
1317
directory: /dory-core
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
#!/bin/bash
2+
# RustSec gate with one feature-aware exception. Cargo.lock records optional dependencies even when
3+
# their features are disabled, so cargo-audit sees russh's vulnerable RSA implementation although
4+
# Dory deliberately ships Ed25519-only SSH. Prove RSA is absent from every target graph before
5+
# ignoring that lockfile-only advisory; any future feature activation fails closed here.
6+
set -euo pipefail
7+
8+
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
9+
cd "$ROOT"
10+
11+
command -v cargo-audit >/dev/null 2>&1 \
12+
|| { echo "rust security gate: cargo-audit 0.22.2 is required" >&2; exit 1; }
13+
14+
tree_output="$(mktemp "${TMPDIR:-/tmp}/dory-rust-security.XXXXXX")"
15+
trap 'rm -f "$tree_output"' EXIT
16+
cargo tree --manifest-path dory-core/Cargo.toml --target all -i rsa -e features \
17+
>"$tree_output" 2>&1 || true
18+
if grep -Eq '^rsa v[0-9]' "$tree_output"; then
19+
cat "$tree_output" >&2
20+
echo "rust security gate: RSA entered a compiled target; RUSTSEC-2023-0071 is no longer ignorable" >&2
21+
exit 1
22+
fi
23+
24+
cargo audit --file dory-core/Cargo.lock --deny warnings \
25+
--ignore RUSTSEC-2023-0071
26+
echo "rust security gate: PASS (RSA feature absent; no actionable advisories)"
Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
#!/bin/bash
2+
set -euo pipefail
3+
4+
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
5+
cd "$ROOT"
6+
7+
fail() { echo "security contract failed: $*" >&2; exit 1; }
8+
9+
for forbidden_entitlement in \
10+
com.apple.security.cs.allow-jit \
11+
com.apple.security.cs.allow-unsigned-executable-memory \
12+
com.apple.security.cs.disable-library-validation \
13+
com.apple.security.virtualization \
14+
com.apple.security.hypervisor; do
15+
if grep -F "$forbidden_entitlement" Dory/Dory.entitlements >/dev/null; then
16+
fail "main app retains $forbidden_entitlement"
17+
fi
18+
done
19+
20+
for required_entitlement in \
21+
com.apple.security.network.client \
22+
com.apple.security.network.server; do
23+
grep -F "$required_entitlement" Dory/Dory.entitlements >/dev/null \
24+
|| fail "main app lost $required_entitlement"
25+
done
26+
27+
if grep -R -E --include='*.swift' --include='init' \
28+
'tcp://0\.0\.0\.0:2375|guestPort: 2375|remote[^\n]*:2375' \
29+
Packages/ContainerizationEngine/Sources dory-core-swift/Sources guest/initfs/init >/dev/null; then
30+
fail "a production guest path exposes unauthenticated Docker TCP 2375"
31+
fi
32+
33+
grep -F 'DorydXPCSecurity.configureIncomingConnection(connection)' \
34+
dory-core-swift/Sources/DorydKit/DorydService.swift >/dev/null \
35+
|| fail "doryd listener does not authenticate incoming peers"
36+
grep -F 'connection.setCodeSigningRequirement(productionClientRequirement)' \
37+
dory-core-swift/Sources/DorydKit/DorydXPCSecurity.swift >/dev/null \
38+
|| fail "production doryd does not pin client signatures"
39+
grep -F 'DorydDaemonSigningPolicy.daemonRequirement' \
40+
Dory/Runtime/Doryd/DorydClient.swift >/dev/null \
41+
|| fail "production app does not pin doryd's signature"
42+
grep -F 'DorydXPCSecurity.productionDaemonRequirement' \
43+
dory-core-swift/Sources/dorydctl/main.swift >/dev/null \
44+
|| fail "production dorydctl does not pin doryd's signature"
45+
46+
grep -F 'static let attachSupported = false' Dory/Net/UsbAttachmentStore.swift >/dev/null \
47+
|| fail "USB passthrough can be advertised before the guest RPC exists"
48+
49+
for kernel_contract in \
50+
'CONFIG_NETFILTER_XT_MATCH_OWNER=y' \
51+
'CONFIG_IP6_NF_FILTER=y' \
52+
'CONFIG_BLK_DEV_LOOP=y'; do
53+
grep -Fx "$kernel_contract" guest/kernel/dory.config >/dev/null \
54+
|| fail "sandbox guest kernel lost $kernel_contract"
55+
done
56+
for agent_contract in DORY_AGENT_RUN_UID DORY_AGENT_MAX_PROCESSES DORY_AGENT_MAX_FILE_BYTES; do
57+
grep -F "$agent_contract" dory-core/agent/src/exec.rs >/dev/null \
58+
|| fail "guest agent lost restricted exec key $agent_contract"
59+
done
60+
grep -F 'mode = "ro"' scripts/dory >/dev/null \
61+
|| fail "sandbox mounts no longer default read-only"
62+
grep -F 'DORY_SANDBOX_EXPIRES_AT' \
63+
scripts/dory dory-core-swift/Sources/DorydKit/SandboxTTLReconciler.swift >/dev/null \
64+
|| fail "sandbox expiry is not persisted and daemon reconciled"
65+
grep -F 'sandboxSSHAgentDenied' dory-core-swift/Sources/DoryVMMKit/DoryVMM.swift >/dev/null \
66+
|| fail "sandbox VMM does not fail closed for ambient SSH-agent forwarding"
67+
grep -F -- '--env-json-stdin' dory-core-swift/Sources/dorydctl/main.swift scripts/dory >/dev/null \
68+
|| fail "ephemeral sandbox secrets can no longer avoid process argv"
69+
[ -s SANDBOX_THREAT_MODEL.md ] || fail "sandbox threat model is missing"
70+
71+
echo "security contracts: PASS"

‎.github/workflows/intel-engine.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
ENGINES: ${{ github.event.inputs.readiness_engines || 'dory' }}
4242
READINESS_EXTRA_ARGS: ${{ github.event.inputs.readiness_extra_args || '' }}
4343
steps:
44-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
44+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
4545
with:
4646
persist-credentials: false
4747

‎.github/workflows/pages.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
name: github-pages
2929
url: ${{ steps.deployment.outputs.page_url }}
3030
steps:
31-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
31+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
3232
- name: Preserve the currently deployed Sparkle feed
3333
run: |
3434
live="$RUNNER_TEMP/live-appcast.xml"

‎.github/workflows/release.yml‎

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,7 @@ jobs:
233233
runs-on: ubuntu-latest
234234
timeout-minutes: 30
235235
steps:
236-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
236+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
237237
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
238238
with:
239239
components: rustfmt, clippy
@@ -253,7 +253,7 @@ jobs:
253253
runs-on: ubuntu-24.04-arm
254254
timeout-minutes: 180
255255
steps:
256-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
256+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
257257
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
258258
- name: Install guest build prerequisites
259259
run: sudo apt-get update && sudo apt-get install -y binutils e2fsprogs file patchelf zstd
@@ -297,7 +297,7 @@ jobs:
297297
runs-on: macos-latest
298298
timeout-minutes: 120
299299
steps:
300-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
300+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
301301
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
302302
- name: Select newest installed Xcode
303303
run: |
@@ -365,7 +365,7 @@ jobs:
365365
appcast: ${{ steps.build.outputs.appcast }}
366366
app_update: ${{ steps.build.outputs.app_update }}
367367
steps:
368-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
368+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
369369
with:
370370
fetch-depth: 0
371371
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
@@ -694,7 +694,7 @@ jobs:
694694
permissions:
695695
contents: read
696696
steps:
697-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
697+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
698698
with:
699699
persist-credentials: false
700700
- name: Download the immutable candidate
@@ -732,7 +732,7 @@ jobs:
732732
contents: read
733733
id-token: write
734734
steps:
735-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
735+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
736736
with:
737737
persist-credentials: false
738738
- name: Download immutable public candidate before the job token expires
@@ -777,7 +777,7 @@ jobs:
777777
permissions:
778778
contents: read
779779
steps:
780-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
780+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
781781
with:
782782
persist-credentials: false
783783
- name: Download immutable public candidate
@@ -825,7 +825,7 @@ jobs:
825825
permissions:
826826
contents: read
827827
steps:
828-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
828+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
829829
with:
830830
persist-credentials: false
831831
- name: Download immutable public candidate
@@ -913,7 +913,7 @@ jobs:
913913
permissions:
914914
contents: read
915915
steps:
916-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
916+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
917917
with:
918918
persist-credentials: false
919919
- name: Download immutable public candidate
@@ -992,7 +992,7 @@ jobs:
992992
permissions:
993993
contents: read
994994
steps:
995-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
995+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
996996
with:
997997
persist-credentials: false
998998
- name: Download immutable candidate for checksum binding
@@ -1053,7 +1053,7 @@ jobs:
10531053
version: ${{ needs.release_candidate.outputs.version }}
10541054
sha256: ${{ needs.release_candidate.outputs.sha256 }}
10551055
steps:
1056-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
1056+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
10571057
- name: Download the exact candidate with fresh job credentials
10581058
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
10591059
with:
@@ -1623,7 +1623,7 @@ jobs:
16231623
name: github-pages
16241624
url: ${{ steps.deployment.outputs.page_url }}
16251625
steps:
1626-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
1626+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
16271627
- name: Download the appcast generated from the signed update ZIP
16281628
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
16291629
with:
@@ -1696,7 +1696,7 @@ jobs:
16961696
permissions:
16971697
contents: write
16981698
steps:
1699-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
1699+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
17001700
with:
17011701
ref: main
17021702
- name: Bump cask to the released version

‎.github/workflows/security.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
- name: Audit Rust lockfile
2323
run: |
2424
cargo install cargo-audit --locked --version 0.22.2
25-
bash scripts/test-rust-security.sh
25+
bash .github/scripts/test-rust-security.sh
2626
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
2727
with:
2828
node-version: '24'
@@ -33,7 +33,7 @@ jobs:
3333
npm ci --prefix website
3434
npm audit --prefix website --audit-level=high
3535
- name: Security boundary contracts
36-
run: bash scripts/test-security-contracts.sh
36+
run: bash .github/scripts/test-security-contracts.sh
3737

3838
dependency-review:
3939
if: github.event_name == 'pull_request'
@@ -74,6 +74,9 @@ jobs:
7474
run: |
7575
newest="$(ls -d /Applications/Xcode*.app | sort -V | tail -1)"
7676
echo "DEVELOPER_DIR=$newest/Contents/Developer" >> "$GITHUB_ENV"
77+
- name: Install Protocol Buffers compiler
78+
if: matrix.language == 'swift'
79+
run: brew install protobuf
7780
- name: Build Swift surfaces
7881
if: matrix.language == 'swift'
7982
run: |

‎.github/workflows/tests.yml‎

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ jobs:
1212
runs-on: ubuntu-latest
1313
timeout-minutes: 20
1414
steps:
15-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
15+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
1616
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
1717
with:
1818
components: rustfmt, clippy
@@ -24,7 +24,7 @@ jobs:
2424
runs-on: macos-latest
2525
timeout-minutes: 120
2626
steps:
27-
- uses: actions/checkout@c915c33a16f01166c17c4e35fe1d4085a2d71adb # v4
27+
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
2828
- name: Select Xcode
2929
run: |
3030
newest="$(ls -d /Applications/Xcode_26*.app | sort -V | tail -1)"
@@ -41,9 +41,7 @@ jobs:
4141
run: scripts/test.sh gvproxy
4242
- name: Swift packages
4343
run: scripts/test.sh swift
44-
- name: P0 smoke harness contracts
45-
run: bash scripts/test-p0-smoke.sh
46-
- name: Offline release contracts and app tests
47-
run: bash scripts/ci-test.sh
44+
- name: App tests
45+
run: scripts/test.sh app
4846
- name: UI tests
4947
run: scripts/test.sh ui

0 commit comments

Comments
 (0)