Skip to content

ci: add a dispatchable sfw CI simulation - #21

Merged
Julian Gruber (juliangruber) merged 1 commit into
mainfrom
ci/sfw-ci-simulation
Sep 30, 2026
Merged

Julian Gruber (juliangruber) merged 1 commit into
mainfrom
ci/sfw-ci-simulation

Conversation

@juliangruber

@juliangruber Julian Gruber (juliangruber) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Why

Verify stability by simulating load in GitHub Actions context. The shape is common to any user running the action plus an explicit sfw npm install in GitHub Actions.

What

One dispatchable workflow, test-sfw-ci-simulation.yml. A measurement rather than a pass/fail test. Inputs:

  • baseline_action_ref (default: latest tag v1.3.2; empty skips the baseline)
  • fixture_repo (default expressjs/express)
  • iterations (default 10)

Install — matrix of windows-2025, windows-11-arm, ubuntu-26.04 × candidate/baseline × N iterations. Each job installs sfw with uses: ./ (candidate) or a second fetch of the action at the baseline ref, then runs sfw npm install --ignore-scripts in the fixture. Failures are classified by symptom text. Report aggregates a flake table into the run summary and splits binary download failures out of action-setup-failed from the install jobs' failure annotations.

Fleet form throughout: inline bootstrap checkout (no actions/checkout), fleet upload-artifact/download-artifact composites, no third-party actions, pinned runner images, every step named. pnpm run lint --all passes; the remaining pnpm run check failures are machine-local (pricing data, telemetry env, Homebrew, roster).

Running it

gh workflow run test-sfw-ci-simulation.yml --repo SocketDev/action --ref <branch> -f iterations=20

Simulation cost: iterations=20 with baseline is ~100 install jobs, most on Windows.

🤖 Generated with Claude Code


Note

Low Risk
Adds optional CI measurement only; no changes to the action runtime, customer workflows, or release behavior.

Overview
Adds a manually dispatched workflow (test-sfw-ci-simulation.yml) to measure how reliably the Socket Firewall action plus an explicit sfw npm install behaves in GitHub Actions—before shipping action or binary changes.

Each run repeats installs across windows-2025, windows-11-arm, and ubuntu-26.04, comparing the checked-out ref (candidate) to an optional baseline action ref (default v1.3.2). Jobs install firewall mode from ./ or a fetched baseline copy, run sfw npm install in a configurable public fixture (default expressjs/express), classify outcomes (setup failure, PATH, timeouts, libuv, telemetry, etc.), and upload JSON results. A Report job always runs, merges artifacts, writes a flake table to the step summary, and breaks out binary download failures from action-setup annotations via the GitHub API.

Uses the repo’s fleet pattern: inline bootstrap checkout (no actions/checkout), local upload-artifact / download-artifact composites, and continue-on-error so the run is measurement—not a gate.

Reviewed by Cursor Bugbot for commit d087b21. Configure here.

@juliangruber
Julian Gruber (juliangruber) marked this pull request as draft September 30, 2026 10:52
@juliangruber
Julian Gruber (juliangruber) force-pushed the ci/sfw-ci-simulation branch 2 times, most recently from 7dd5455 to 79af52b Compare September 30, 2026 11:33
@juliangruber Julian Gruber (juliangruber) changed the title ci: add a dispatchable sfw CI simulation ci: add sfw fault-injection tests and a dispatchable CI simulation Sep 30, 2026
@juliangruber Julian Gruber (juliangruber) changed the title ci: add sfw fault-injection tests and a dispatchable CI simulation ci: add a download-fallback regression test and a dispatchable CI simulation Sep 30, 2026
Comment thread .github/workflows/test-sfw-regression.yml Outdated
Comment thread .github/workflows/test-sfw-fault-injection.yml Outdated
@juliangruber
Julian Gruber (juliangruber) force-pushed the ci/sfw-ci-simulation branch 2 times, most recently from 7aa241b to 6aa81e0 Compare September 30, 2026 12:10
@juliangruber Julian Gruber (juliangruber) changed the title ci: add a download-fallback regression test and a dispatchable CI simulation ci: add an sfw regression test and a dispatchable CI simulation Sep 30, 2026
Reproduces a customer CI shape, this action installing sfw followed by an
explicit `sfw npm install`, against the checked-out action, so a change
to the action or to the sfw binary it pins can be measured before it is
announced. The candidate is always `./`.

The fixture install is repeated N times per runner (windows-2025,
windows-11-arm, ubuntu-26.04) for the candidate and a baseline action
ref, each failure classified by symptom, and the report job aggregates a
flake table into the run summary, splitting binary download failures out
of the setup failures via the install jobs' annotations. A measurement,
not a pass/fail test, so it is dispatched rather than run on every PR.

Fleet form: inline bootstrap checkout, fleet artifact composites, no
third-party actions, pinned runner images, named steps.
@juliangruber
Julian Gruber (juliangruber) changed the base branch from julian/sfw-mirror-origin to main September 30, 2026 12:58
@juliangruber Julian Gruber (juliangruber) changed the title ci: add an sfw regression test and a dispatchable CI simulation ci: add a dispatchable sfw CI simulation Sep 30, 2026
@juliangruber
Julian Gruber (juliangruber) marked this pull request as ready for review September 30, 2026 13:26
@juliangruber
Julian Gruber (juliangruber) merged commit 3848fdc into main Sep 30, 2026
5 checks passed

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Fleet artifact actions never hydrated
    • The install and report jobs now run the tracked fleet checkout composite after bootstrap so upload-artifact and download-artifact exist before those steps resolve.

Create PR

Or push these changes by commenting:

@cursor push 08fd781737
Preview (08fd781737)
diff --git a/.github/workflows/test-sfw-ci-simulation.yml b/.github/workflows/test-sfw-ci-simulation.yml
--- a/.github/workflows/test-sfw-ci-simulation.yml
+++ b/.github/workflows/test-sfw-ci-simulation.yml
@@ -96,6 +96,14 @@
           export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
           git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}"
           git checkout -q --detach FETCH_HEAD
+      # Artifact composites are untracked fleet payload. Hydrate them here
+      # so upload-artifact resolves; checkout:false keeps this revision.
+      - name: 'Hydrate fleet Actions'
+        uses: ./.github/actions/fleet/checkout
+        with:
+          checkout: 'false'
+          payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }}
+          payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }}
       # The baseline is a second copy of the action at the requested ref, in
       # its own directory so `./` stays the candidate.
       - name: 'Fetch the baseline action'
@@ -211,6 +219,14 @@
           export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
           git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}"
           git checkout -q --detach FETCH_HEAD
+      # Artifact composites are untracked fleet payload. Hydrate them here
+      # so download-artifact resolves; checkout:false keeps this revision.
+      - name: 'Hydrate fleet Actions'
+        uses: ./.github/actions/fleet/checkout
+        with:
+          checkout: 'false'
+          payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }}
+          payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }}
       - name: 'Download the results'
         uses: ./.github/actions/fleet/download-artifact
         with:

You can send follow-ups to the cloud agent here.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit d087b21. Configure here.

uses: ./.github/actions/fleet/upload-artifact
with:
name: result-install-${{ matrix.os }}-${{ matrix.variant }}-${{ matrix.iteration }}
path: results/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fleet artifact actions never hydrated

High Severity

The install and report jobs call the fleet upload-artifact and download-artifact composites after an inline bootstrap only. Those action.yml files are gitignored payload and never land in a plain checkout, so every cell fails at upload and the report job cannot read results.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit d087b21. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant