ci: add a mirror test for the sfw download fallback - #22
Merged
Julian Gruber (juliangruber) merged 1 commit intoSep 30, 2026
Merged
Julian Gruber (juliangruber) merged 1 commit into
Julian Gruber (juliangruber) merged 1 commit into
Conversation
test-sfw-regression.yml runs on every pull request. It forces the one way this action has taken a customer install down, the binary download failing at its only origin, by pointing GitHub or the mirror at 127.0.0.1 in the hosts file, and asserts the install still succeeds from the other origin. It is deterministic and runs once per runner (windows-2025, ubuntu-26.04). Tests of the sfw binary's own behaviour live in SocketDev/firewall, next to the code they test. Fleet form: inline bootstrap checkout, no third-party actions, pinned runner images, named steps.
Julian Gruber (juliangruber)
marked this pull request as ready for review
September 30, 2026 13:16
Julian Gruber (juliangruber)
merged commit Sep 30, 2026
3af8a1e
into
julian/sfw-mirror-origin
6 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The one way this action has taken a customer install down is the sfw binary download failing at its only origin, GitHub release assets, during a GitHub incident. #18 adds a second origin with fallback. This test makes sure the fallback keeps working, in both directions, on every pull request.
Stacked on #18 because without the mirror the GitHub-blocked leg has nothing to fall back to. Split out of #21, which keeps the dispatchable simulation.
What
.github/workflows/test-sfw-mirror.yml, on every pull request againstmainand on pushes tomain. Matrix:windows-2025,ubuntu-26.04× blocked origin.github.com,objects.githubusercontent.com,release-assets.githubusercontent.com) orinstall.socket.devpointed at127.0.0.1in the hosts file, so the blocked origin refuses at once./, installs sfw from the other origin andsfw --versionworksFleet form: inline bootstrap checkout, no third-party actions, pinned runner images, named steps.
pnpm run lint --allpasses.Verification
Negative control (run 36710376223): the same test on
mainwithout the mirror. The GitHub-blocked leg fails at the install step (connect ETIMEDOUT, with the earlier black-hole address); the mirror-blocked legs pass, as they should on any version. The Ubuntu GitHub-blocked leg only hit the job timeout, which is why the blocked origin now points at127.0.0.1instead of a black hole.Positive control: runs on this PR once #18's base is
main, since the workflow triggers on PRs againstmain.🤖 Generated with Claude Code
Note
Low Risk
CI-only change; it exercises install paths on runners and does not alter runtime action or customer-facing behavior.
Overview
Adds a regression CI workflow (
test-sfw-mirror.yml) that runs on every PR and push tomain(plusworkflow_dispatch).For each Windows 2025 and Ubuntu 26.04 runner, it blocks either GitHub release hosts or
install.socket.devvia the hosts file (127.0.0.1for immediate refusal), then installs the action from the checked-out repo (./, firewall mode, cache off) and assertssfw --versionsucceeds—proving each download origin can carry the install alone and that GitHub ↔ mirror fallback still works.Checkout is an inline git bootstrap (no third-party actions); matrix legs use
fail-fast: falseand a 20-minute timeout.Reviewed by Cursor Bugbot for commit 2390e2c. Configure here.