mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 08:28:19 +08:00
* feat(isolation): add RFC 0012 backend contract Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com> * refactor(isolation): name the interface crate explicitly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): expose trusted host gateway Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(agents): inventory the MXC driver Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add mediated DNS transport Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): tighten interface error and digest contracts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(isolation): remove unrelated driver inventory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): define capability-free launch contract Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): seal confirmed boundary state Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate confirmation for external backend implementations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): clarify mediated DNS identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): generalize loopback connector Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): unify typed network mediation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): bind launches to sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(mxc): initialize extended sandbox status Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add boundary protocol and Linux primitives Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden signals and separate process status from transport Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate remote confirmation through public contract Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate wire state and propagate snapshot failures Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(isolation): import owned agent specification explicitly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(isolation): describe mediated DNS channel Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): bound mediation attach without nested retries Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): generalize loopback protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add transport-neutral session authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): separate sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden runtime boundary controls Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add terminal boundary operation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): split supervisor and sandbox runtimes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): harden boundary isolation and lifecycle ownership Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): reject private root redirects and adopt typed errors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): preserve accept thread ownership on musl Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(sandbox): isolate credential probes from filtered threads Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): return retained exec exit status to independent waiters Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bound network mediation and preserve socket authorization Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bound control admission and retire stale mediation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * ci(e2e): select migrated drivers per stack layer Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): implement loopback connector Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): authenticate the Sandbox Protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(supervisor): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): consume dedicated backend crate Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(sandbox): align topology session fixture Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): align projected bootstrap bundle Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): validate refreshed credentials before rotation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): fail closed across supervisor disconnects Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): repair rebased sandbox CI Signed-off-by: Drew Newberry <anewberry@nvidia.com> * build(runtime): publish separate sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(config): configure the sandbox runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): validate sandbox binary linkage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): use backend and runtime terminology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): use a scratch runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): refresh schema and dependency policy Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bind reconnects to supervisor process Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs: align runtime split operational guidance Signed-off-by: Drew Newberry <anewberry@nvidia.com> * chore(security): document Kubernetes runtime RBAC Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): enforce runtime lifecycle invariants Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(compute): identify sandbox start generations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(server): restore sandbox launch sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): support authenticated runtime replacement Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): bind sandbox session successors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): retry pending sandbox successors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(vm): run the supervisor outside the guest workload Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): repair rebase integration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): use unified build toolchain Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): use sandbox runtime terminology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): own guest network bootstrap Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): expose guest init version Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): select native supervisor artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): guard guest init Linux symbols Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): scope Linux test imports Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): avoid guest interface casts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): reconcile admitted sandbox identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): share resolved sandbox identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): surface host supervisor failures Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): include guest logs on supervisor exit Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): rotate and clean runtime generations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): keep shared paths in the base layer Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): isolate workloads behind the host supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): use host networking for supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): preserve host gateway alias resolution Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): use separate sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): restore startup validation after rebase Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): name the sandbox runtime directly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): narrow supervisor CA runtime storage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): close companion isolation gaps Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(docker): align mediated network expectations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(docker): exercise mediated network paths Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): attach supervisor to managed network Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): defer supervisor recovery until gateway is ready Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): preserve workloads during session rotation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): remove unrelated configuration RFC changes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(kubernetes): add proxy-pod isolation topology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): use stable sandbox service authority Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(kubernetes): split sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): adapt proxy pods to current runtime APIs Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): describe the single runtime placement Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): simplify sandbox orchestration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): validate deployment prerequisites Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): update Trivy Helm profile inventory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(kubernetes): update Trivy scan inventory count Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): reuse preloaded runtime images in e2e Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): type and clean runtime resources Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): make sandbox restarts recoverable Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): preserve supervisor egress Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): adopt isolated sandbox and supervisor containers Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): stage bootstrap archives at named volume destinations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): use host networking for supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): split sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): repair rebase integration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): name the sandbox runtime directly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): provision supervisor CA runtime storage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): address isolation review findings Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): inspect Debian supervisor provenance Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): use libpod-compatible tmpfs options Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): bind verified sandbox runtime binary Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): provide external driver data directory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): start sandbox before joining user namespace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): separate supervisor user namespace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * perf(isolation): add TCP and DNS benchmark harnesses Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): align benchmark timing and supported protocols Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): report TCP benchmark metrics accurately Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): cancel failed worker startup Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): build matching local supervisor image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): make local sandbox smoke test runnable Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): wire local sandbox runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): narrow sandbox service RBAC Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): validate split runtime artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden runtime session handling Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(supervisor): add standalone network proxy role Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(rfc): remove implementation companion notes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): standardize runtime release name Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): pin renamed runtime artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): persist sandbox runtime identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(runtime): restore branch validation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): reconcile main after rebase Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(network): close unframed HTTP 1.0 responses Signed-off-by: Drew Newberry <anewberry@nvidia.com> * chore(isolation): preserve upstream OCSF updates Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(security): close credential and TLS replay paths Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): make sandbox refresh retries idempotent Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com> Signed-off-by: Drew Newberry <anewberry@nvidia.com>
248 lines
9.8 KiB
Bash
Executable File
248 lines
9.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
set -euo pipefail
|
|
|
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
|
SCANNER="${REPO_ROOT}/tasks/scripts/trivy-scan.sh"
|
|
TMP_DIR="$(mktemp -d)"
|
|
trap 'rm -rf "${TMP_DIR}"' EXIT
|
|
# Synthetic findings must not write to the real Actions summary or outputs.
|
|
export GITHUB_OUTPUT="${TMP_DIR}/github-output"
|
|
export GITHUB_STEP_SUMMARY="${TMP_DIR}/github-summary"
|
|
|
|
make_case() {
|
|
BASE="${TMP_DIR}/$1/base"
|
|
HEAD="${TMP_DIR}/$1/head"
|
|
mkdir -p "${BASE}" "${HEAD}"
|
|
}
|
|
|
|
write_report() {
|
|
local path=$1 count=$2 profile
|
|
profile="$(basename "${path}" .json)"
|
|
jq -n --argjson count "${count}" --arg profile "${profile}" '
|
|
{
|
|
SchemaVersion: 2,
|
|
ArtifactName: "deploy",
|
|
ArtifactType: "filesystem",
|
|
TrivyProfile: $profile,
|
|
Results: (if $count == 0 then [] else [{
|
|
Target: "deploy/helm/openshell/templates/clusterrole.yaml",
|
|
Class: "config",
|
|
Type: "kubernetes",
|
|
MisconfSummary: {Successes: 0, Failures: $count, Exceptions: 0},
|
|
Misconfigurations: [
|
|
range(0; $count) | {
|
|
ID: "KSV-0041",
|
|
Title: "Manage secrets",
|
|
Message: "Role permits management of secrets",
|
|
Namespace: "builtin.kubernetes.KSV041",
|
|
Type: "Kubernetes Security Check",
|
|
Status: "FAIL",
|
|
Severity: "HIGH",
|
|
CauseMetadata: {Provider: "Kubernetes", Service: "RBAC", Resource: "ClusterRole.openshell"}
|
|
}
|
|
]
|
|
}] end)
|
|
}
|
|
' >"${path}"
|
|
}
|
|
|
|
expect_status() {
|
|
local expected=$1 description=$2
|
|
shift 2
|
|
|
|
set +e
|
|
"$@" >"${TMP_DIR}/last-command.log" 2>&1
|
|
local actual=$?
|
|
set -e
|
|
if [ "${actual}" -ne "${expected}" ]; then
|
|
echo "FAIL: ${description}: expected exit ${expected}, got ${actual}" >&2
|
|
cat "${TMP_DIR}/last-command.log" >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
make_case profile-expansion
|
|
write_report "${BASE}/config-defaults.json" 0
|
|
write_report "${BASE}/config-fixture-workspace.json" 2
|
|
write_report "${HEAD}/config-defaults.json" 1
|
|
write_report "${HEAD}/config-fixture-workspace.json" 2
|
|
expect_status 10 "finding newly exposed in an existing profile" \
|
|
"${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
|
|
make_case new-profile
|
|
write_report "${BASE}/config-defaults.json" 0
|
|
write_report "${BASE}/config-fixture-workspace.json" 2
|
|
write_report "${HEAD}/config-defaults.json" 0
|
|
write_report "${HEAD}/config-fixture-workspace.json" 2
|
|
write_report "${HEAD}/config-fixture-new.json" 2
|
|
expect_status 0 "new profile repeating known findings" \
|
|
"${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
|
|
make_case occurrence-increase
|
|
write_report "${BASE}/config-defaults.json" 1
|
|
write_report "${HEAD}/config-defaults.json" 2
|
|
expect_status 10 "additional occurrence of an existing finding" \
|
|
"${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
expect_status 0 "findings below the requested threshold" \
|
|
env TRIVY_SEVERITY=CRITICAL "${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
|
|
make_case malformed
|
|
write_report "${BASE}/config-defaults.json" 1
|
|
printf '{}\n' >"${HEAD}/config-defaults.json"
|
|
expect_status 5 "structurally invalid candidate report" \
|
|
"${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
|
|
make_case no-reports
|
|
expect_status 2 "missing reports cannot pass the differential gate" \
|
|
"${SCANNER}" gate-config-diff "${BASE}" "${HEAD}"
|
|
|
|
cat >"${TMP_DIR}/valid-ignore.yaml" <<'EOF'
|
|
misconfigurations:
|
|
- id: KSV-0041
|
|
paths:
|
|
- "**/clusterrole.yaml"
|
|
EOF
|
|
expect_status 0 "concretely scoped ignore path" \
|
|
env TRIVY_IGNORE_FILE="${TMP_DIR}/valid-ignore.yaml" \
|
|
"${SCANNER}" validate-ignore
|
|
|
|
cat >"${TMP_DIR}/broad-ignore.yaml" <<'EOF'
|
|
misconfigurations:
|
|
- id: KSV-0041
|
|
paths:
|
|
- "**/*"
|
|
EOF
|
|
expect_status 2 "broad ignore path" \
|
|
env TRIVY_IGNORE_FILE="${TMP_DIR}/broad-ignore.yaml" \
|
|
"${SCANNER}" validate-ignore
|
|
|
|
# Consolidate more than 20 Helm profiles without losing resource identity or
|
|
# the per-profile input counts needed by the gate. Exercise real Trivy SARIF
|
|
# conversion with synthetic JSON; this requires no network or image downloads.
|
|
make_case sarif
|
|
write_report "${HEAD}/config-static.json" 0
|
|
write_report "${HEAD}/config-defaults.json" 1
|
|
for profile in {1..21}; do
|
|
write_report "${HEAD}/config-fixture-${profile}.json" 1
|
|
done
|
|
write_report "${TMP_DIR}/resource-source.json" 2
|
|
jq '
|
|
.TrivyProfile = "config-fixture-resources"
|
|
| .Results[0].Misconfigurations[0].CauseMetadata.StartLine = 40
|
|
| .Results[0].Misconfigurations[1].CauseMetadata.Resource = "ClusterRole.other"
|
|
' "${TMP_DIR}/resource-source.json" >"${HEAD}/config-fixture-resources.json"
|
|
|
|
# Image reports must remain separate, even if they contain identical findings.
|
|
for report in {1..25}; do
|
|
write_report "${HEAD}/image-${report}.json" 0
|
|
done
|
|
expect_status 0 "prepare one config analysis and bounded image upload batches" \
|
|
env TRIVY_SEVERITY=CRITICAL TRIVY_REPORT_DIR="${HEAD}" GITHUB_OUTPUT="${TMP_DIR}/outputs" \
|
|
"${SCANNER}" prepare-sarif
|
|
jq -e '
|
|
[.Results[].Misconfigurations[]] as $findings
|
|
| ($findings | length) == 2
|
|
and all($findings[]; .Message | contains("Profiles: "))
|
|
and any($findings[];
|
|
.CauseMetadata.Resource == "ClusterRole.openshell"
|
|
and (.Message | contains("config-defaults"))
|
|
and (.Message | contains("config-fixture-resources")))
|
|
' "${HEAD}/consolidated/config.json" >/dev/null
|
|
jq -e '.Results[0].Misconfigurations | length == 2' \
|
|
"${HEAD}/config-fixture-resources.json" >/dev/null
|
|
jq -e '
|
|
(.runs | length) == 1
|
|
and .runs[0].automationDetails.id == "trivy/config/"
|
|
and (.runs[0].results | length) == 2
|
|
and (.runs[0].originalUriBaseIds == null)
|
|
and (.runs[0] as $run | all($run.results[];
|
|
.ruleId == $run.tool.driver.rules[.ruleIndex].id
|
|
and all(.locations[].physicalLocation.artifactLocation;
|
|
.uri == "deploy/helm/openshell/templates/clusterrole.yaml" and .uriBaseId == null)))
|
|
' "${HEAD}/code-scanning/uploads/0/config.sarif" >/dev/null
|
|
jq -se '[.[].runs[]] | length == 20' "${HEAD}/code-scanning/uploads/0/"*.sarif >/dev/null
|
|
jq -se '[.[].runs[]] | length == 6' "${HEAD}/code-scanning/uploads/1/"*.sarif >/dev/null
|
|
[[ "$(<"${TMP_DIR}/outputs")" == 'batches=["0","1"]' ]]
|
|
|
|
# Report findings and the workflow summary use the same consolidated view.
|
|
expect_status 10 "consolidated findings remain blocking" \
|
|
env TRIVY_REPORT_DIR="${HEAD}" GITHUB_STEP_SUMMARY="${TMP_DIR}/summary" \
|
|
"${SCANNER}" gate
|
|
test -s "${TMP_DIR}/summary"
|
|
|
|
# Empty configuration is a valid clearing analysis, not a skipped upload.
|
|
make_case empty-sarif
|
|
write_report "${HEAD}/config-static.json" 0
|
|
write_report "${HEAD}/config-defaults.json" 0
|
|
expect_status 0 "empty configuration SARIF" \
|
|
env TRIVY_REPORT_DIR="${HEAD}" "${SCANNER}" prepare-sarif
|
|
jq -e '.runs[0].results | length == 0' \
|
|
"${HEAD}/code-scanning/uploads/0/config.sarif" >/dev/null
|
|
|
|
make_case malformed-sarif
|
|
write_report "${HEAD}/config-static.json" 0
|
|
printf '{}\n' >"${HEAD}/config-defaults.json"
|
|
expect_status 5 "reject malformed input during consolidation" \
|
|
env TRIVY_REPORT_DIR="${HEAD}" "${SCANNER}" prepare-sarif
|
|
|
|
# Record scan arguments without downloading Trivy's checks database or charts.
|
|
# shellcheck disable=SC2329 # Invoked by the scanner subprocess via export -f.
|
|
trivy() {
|
|
[ "${TRIVY_TEST_FAIL:-false}" = false ] || return 9
|
|
local output="" previous="" arg
|
|
printf '%s\n' "$@" | jq -Rs 'split("\n")[:-1]' >>"${TRIVY_TEST_CALLS}"
|
|
for arg in "$@"; do
|
|
[ "${previous}" = --output ] && output="${arg}"
|
|
previous="${arg}"
|
|
done
|
|
jq -n --arg target "${!#}" \
|
|
'{SchemaVersion: 2, ArtifactName: $target, ArtifactType: "filesystem", Results: []}' >"${output}"
|
|
}
|
|
# shellcheck disable=SC2329 # Invoked by the scanner subprocess via export -f.
|
|
helm() { touch "${!#}/chart.tgz"; }
|
|
export -f trivy helm
|
|
export TRIVY_TEST_CALLS="${TMP_DIR}/scan-calls"
|
|
expect_status 0 "scan selected profiles and retain distinct packaged chart versions/registries" \
|
|
env TRIVY_REPORT_DIR="${TMP_DIR}/scan-reports" "${SCANNER}" config \
|
|
--chart-ref oci://registry-a.example/charts/helm-chart:1.0.0 \
|
|
--chart-ref oci://registry-a.example/charts/helm-chart:1.1.0 \
|
|
--chart-ref oci://registry-b.example/charts/helm-chart:1.0.0
|
|
jq -se '
|
|
length == 19
|
|
and ([.[] | select(.[-1] == "deploy")] | length) == 1
|
|
and ([.[] | select(.[-1] == "deploy/helm")] | length) == 1
|
|
and ([.[] | select(.[-1] == "deploy/helm/openshell")] | length) == 14
|
|
and all(.[]; (join(" ") | contains("values-spire-stack.yaml")) | not)
|
|
and all(.[]; index("UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL") != null)
|
|
' "${TRIVY_TEST_CALLS}" >/dev/null
|
|
jq -se 'length == 3' "${TMP_DIR}/scan-reports/"config-packaged-*.json >/dev/null
|
|
test -z "$(find "${TMP_DIR}/scan-reports" -name '*.sarif' -print -quit)"
|
|
|
|
expect_status 0 "retain image registry, path and platform identity" \
|
|
env TRIVY_REPORT_DIR="${TMP_DIR}/images" "${SCANNER}" images \
|
|
registry-a.example/ns/image:dev registry-b.example/ns/image:dev \
|
|
registry-a.example/ns-image:dev
|
|
jq -se 'length == 6 and (map(.ArtifactName) | unique | length) == 3' \
|
|
"${TMP_DIR}/images/"*.json >/dev/null
|
|
|
|
expect_status 9 "scanner failures propagate" \
|
|
env TRIVY_TEST_FAIL=true TRIVY_REPORT_DIR="${TMP_DIR}/scan-error" "${SCANNER}" config
|
|
|
|
# Check missing fixture handling without changing the working checkout.
|
|
mkdir -p "${TMP_DIR}/candidate/tasks/scripts" "${TMP_DIR}/baseline"
|
|
cp "${SCANNER}" "${TMP_DIR}/candidate/tasks/scripts/trivy-scan.sh"
|
|
cp "${REPO_ROOT}/.trivyignore.yaml" "${TMP_DIR}/candidate/"
|
|
expect_status 2 "a selected candidate fixture cannot silently disappear" \
|
|
env TRIVY_REPORT_DIR="${TMP_DIR}/missing-candidate" \
|
|
"${TMP_DIR}/candidate/tasks/scripts/trivy-scan.sh" config
|
|
expect_status 0 "new candidate profiles may be absent from the baseline" \
|
|
env TRIVY_SOURCE_ROOT="${TMP_DIR}/baseline" TRIVY_REPORT_DIR="${TMP_DIR}/missing-baseline" \
|
|
"${TMP_DIR}/candidate/tasks/scripts/trivy-scan.sh" config
|
|
unset -f trivy helm
|
|
|
|
echo "Trivy scan tests passed."
|