Skip to content

ci: add a mirror test for the sfw download fallback - #22

Merged
Julian Gruber (juliangruber) merged 1 commit into
julian/sfw-mirror-originfrom
ci/sfw-regression-test
Sep 30, 2026
Merged

Julian Gruber (juliangruber) merged 1 commit into
julian/sfw-mirror-originfrom
ci/sfw-regression-test

Conversation

@juliangruber

@juliangruber Julian Gruber (juliangruber) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Why

The one way this action has taken a customer install down is the sfw binary download failing at its only origin, GitHub release assets, during a GitHub incident. #18 adds a second origin with fallback. This test makes sure the fallback keeps working, in both directions, on every pull request.

Stacked on #18 because without the mirror the GitHub-blocked leg has nothing to fall back to. Split out of #21, which keeps the dispatchable simulation.

What

.github/workflows/test-sfw-mirror.yml, on every pull request against main and on pushes to main. Matrix: windows-2025, ubuntu-26.04 × blocked origin.

Job Forces Passes when
Block a download origin GitHub (github.com, objects.githubusercontent.com, release-assets.githubusercontent.com) or install.socket.dev pointed at 127.0.0.1 in the hosts file, so the blocked origin refuses at once the action, run as ./, installs sfw from the other origin and sfw --version works

Fleet form: inline bootstrap checkout, no third-party actions, pinned runner images, named steps. pnpm run lint --all passes.

Verification

Negative control (run 36710376223): the same test on main without the mirror. The GitHub-blocked leg fails at the install step (connect ETIMEDOUT, with the earlier black-hole address); the mirror-blocked legs pass, as they should on any version. The Ubuntu GitHub-blocked leg only hit the job timeout, which is why the blocked origin now points at 127.0.0.1 instead of a black hole.

Positive control: runs on this PR once #18's base is main, since the workflow triggers on PRs against main.

🤖 Generated with Claude Code


Note

Low Risk
CI-only change; it exercises install paths on runners and does not alter runtime action or customer-facing behavior.

Overview
Adds a regression CI workflow (test-sfw-mirror.yml) that runs on every PR and push to main (plus workflow_dispatch).

For each Windows 2025 and Ubuntu 26.04 runner, it blocks either GitHub release hosts or install.socket.dev via the hosts file (127.0.0.1 for immediate refusal), then installs the action from the checked-out repo (./, firewall mode, cache off) and asserts sfw --version succeeds—proving each download origin can carry the install alone and that GitHub ↔ mirror fallback still works.

Checkout is an inline git bootstrap (no third-party actions); matrix legs use fail-fast: false and a 20-minute timeout.

Reviewed by Cursor Bugbot for commit 2390e2c. Configure here.

test-sfw-regression.yml runs on every pull request. It forces the one
way this action has taken a customer install down, the binary download
failing at its only origin, by pointing GitHub or the mirror at
127.0.0.1 in the hosts file, and asserts the install still succeeds from
the other origin. It is deterministic and runs once per runner
(windows-2025, ubuntu-26.04). Tests of the sfw binary's own behaviour
live in SocketDev/firewall, next to the code they test.

Fleet form: inline bootstrap checkout, no third-party actions, pinned
runner images, named steps.
@juliangruber
Julian Gruber (juliangruber) marked this pull request as ready for review September 30, 2026 13:16
@juliangruber
Julian Gruber (juliangruber) merged commit 3af8a1e into julian/sfw-mirror-origin Sep 30, 2026
6 checks passed
@juliangruber Julian Gruber (juliangruber) changed the title ci: add a regression test for the sfw download fallback ci: add a mirror test for the sfw download fallback Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant