mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 17:41:28 +00:00
Merge pull request #4035 from github/mbg/improve-global-proxy-tests
Improve global proxy tests
This commit is contained in:
30
.github/workflows/__global-proxy.yml
generated
vendored
30
.github/workflows/__global-proxy.yml
generated
vendored
@@ -55,17 +55,45 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'false'
|
||||
- name: Block direct internet access to force proxy usage
|
||||
run: |
|
||||
apt-get update -qq && apt-get install -y -qq iptables >/dev/null 2>&1
|
||||
PROXY_IP=$(getent hosts squid-proxy | awk '{ print $1 }')
|
||||
echo "Squid proxy IP: $PROXY_IP"
|
||||
# Allow all traffic to the proxy container
|
||||
iptables -A OUTPUT -d "$PROXY_IP" -j ACCEPT
|
||||
# Allow DNS resolution
|
||||
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
|
||||
iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
|
||||
# Allow loopback
|
||||
iptables -A OUTPUT -o lo -j ACCEPT
|
||||
# Allow already-established connections (from checkout/prepare-test)
|
||||
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
# Block all other outbound HTTP and HTTPS, ensuring direct access fails
|
||||
iptables -A OUTPUT -p tcp --dport 80 -j REJECT --reject-with tcp-reset
|
||||
iptables -A OUTPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
|
||||
echo "Direct HTTP/HTTPS access is now blocked - all traffic must go through the proxy"
|
||||
|
||||
- name: Set proxy environment variables
|
||||
shell: bash
|
||||
run: |
|
||||
echo "http_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTP_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "https_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTPS_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
|
||||
- uses: ./../action/analyze
|
||||
env:
|
||||
https_proxy: http://squid-proxy:3128
|
||||
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
container:
|
||||
image: ubuntu:22.04
|
||||
options: --cap-add=NET_ADMIN
|
||||
services:
|
||||
squid-proxy:
|
||||
image: ubuntu/squid:latest
|
||||
|
||||
6
lib/entry-points.js
generated
6
lib/entry-points.js
generated
@@ -145861,7 +145861,11 @@ function getRegistryProxy(action) {
|
||||
return void 0;
|
||||
}
|
||||
function makeProxyRequestOptions(dispatcher) {
|
||||
if (dispatcher === void 0) {
|
||||
return githubUtils.defaults.request;
|
||||
}
|
||||
return {
|
||||
...githubUtils.defaults.request,
|
||||
fetch: (req, init2) => {
|
||||
return (0, import_undici.fetch)(req, { ...init2, dispatcher });
|
||||
}
|
||||
@@ -145870,7 +145874,7 @@ function makeProxyRequestOptions(dispatcher) {
|
||||
function createApiClientWithDetails(apiDetails, { allowExternal = false, proxy = void 0 } = {}) {
|
||||
const auth2 = allowExternal && apiDetails.externalRepoAuth || apiDetails.auth;
|
||||
const retryingOctokit = githubUtils.GitHub.plugin(retry);
|
||||
const requestOptions = proxy === void 0 ? githubUtils.defaults.request : makeProxyRequestOptions(proxy);
|
||||
const requestOptions = makeProxyRequestOptions(proxy);
|
||||
return new retryingOctokit(
|
||||
githubUtils.getOctokitOptions(auth2, {
|
||||
baseUrl: apiDetails.apiURL,
|
||||
|
||||
@@ -5,17 +5,45 @@ versions:
|
||||
- nightly-latest
|
||||
container:
|
||||
image: ubuntu:22.04
|
||||
options: --cap-add=NET_ADMIN
|
||||
services:
|
||||
squid-proxy:
|
||||
image: ubuntu/squid:latest
|
||||
ports:
|
||||
- 3128:3128
|
||||
env:
|
||||
https_proxy: http://squid-proxy:3128
|
||||
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||
steps:
|
||||
- name: Block direct internet access to force proxy usage
|
||||
run: |
|
||||
apt-get update -qq && apt-get install -y -qq iptables >/dev/null 2>&1
|
||||
PROXY_IP=$(getent hosts squid-proxy | awk '{ print $1 }')
|
||||
echo "Squid proxy IP: $PROXY_IP"
|
||||
# Allow all traffic to the proxy container
|
||||
iptables -A OUTPUT -d "$PROXY_IP" -j ACCEPT
|
||||
# Allow DNS resolution
|
||||
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
|
||||
iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
|
||||
# Allow loopback
|
||||
iptables -A OUTPUT -o lo -j ACCEPT
|
||||
# Allow already-established connections (from checkout/prepare-test)
|
||||
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
# Block all other outbound HTTP and HTTPS, ensuring direct access fails
|
||||
iptables -A OUTPUT -p tcp --dport 80 -j REJECT --reject-with tcp-reset
|
||||
iptables -A OUTPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
|
||||
echo "Direct HTTP/HTTPS access is now blocked - all traffic must go through the proxy"
|
||||
|
||||
- name: Set proxy environment variables
|
||||
shell: bash
|
||||
run: |
|
||||
echo "http_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTP_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "https_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTPS_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
|
||||
- uses: ./../action/analyze
|
||||
|
||||
@@ -2,6 +2,7 @@ import * as github from "@actions/github";
|
||||
import * as githubUtils from "@actions/github/lib/utils";
|
||||
import test from "ava";
|
||||
import * as sinon from "sinon";
|
||||
import { ProxyAgent } from "undici";
|
||||
|
||||
import * as actionsUtil from "./actions-util";
|
||||
import * as api from "./api-client";
|
||||
@@ -251,3 +252,23 @@ test("getRegistryProxyConfig - gets the configuration from the env vars", async
|
||||
)
|
||||
.passes(t.like, { host, port, ca });
|
||||
});
|
||||
|
||||
test("makeProxyRequestOptions - returns defaults without custom proxy", async (t) => {
|
||||
t.deepEqual(
|
||||
api.makeProxyRequestOptions(undefined),
|
||||
githubUtils.defaults.request,
|
||||
);
|
||||
});
|
||||
|
||||
test("makeProxyRequestOptions - returns fetch with custom proxy", async (t) => {
|
||||
const opts = api.makeProxyRequestOptions(
|
||||
new ProxyAgent("http://localhost:1080"),
|
||||
);
|
||||
// Fetch should be different from the defaults.
|
||||
t.notDeepEqual(opts?.fetch, githubUtils.defaults.request?.fetch);
|
||||
// The options should be the same aside from that.
|
||||
t.deepEqual(
|
||||
{ ...opts, fetch: githubUtils.defaults.request?.fetch },
|
||||
githubUtils.defaults.request,
|
||||
);
|
||||
});
|
||||
|
||||
@@ -108,12 +108,19 @@ export function getRegistryProxy(
|
||||
* Constructs a `RequestRequestOptions` with a custom `fetch` implementation
|
||||
* that uses `dispatcher` as a proxy for requests.
|
||||
*
|
||||
* @param dispatcher The proxy to use.
|
||||
* @param dispatcher The proxy to use, if any.
|
||||
*/
|
||||
export function makeProxyRequestOptions(
|
||||
dispatcher: ProxyAgent,
|
||||
): RequestRequestOptions {
|
||||
dispatcher: ProxyAgent | undefined,
|
||||
): RequestRequestOptions | undefined {
|
||||
// If we don't have a custom `ProxyAgent`, return the defaults.
|
||||
if (dispatcher === undefined) {
|
||||
return githubUtils.defaults.request;
|
||||
}
|
||||
|
||||
// Otherwise, construct the custom `fetch` and add it onto the defaults.
|
||||
return {
|
||||
...githubUtils.defaults.request,
|
||||
fetch: (req: RequestInfo, init?: RequestInit) => {
|
||||
return undiciFetch(req, { ...init, dispatcher });
|
||||
},
|
||||
@@ -136,10 +143,7 @@ function createApiClientWithDetails(
|
||||
const auth =
|
||||
(allowExternal && apiDetails.externalRepoAuth) || apiDetails.auth;
|
||||
const retryingOctokit = githubUtils.GitHub.plugin(retry.retry);
|
||||
const requestOptions =
|
||||
proxy === undefined
|
||||
? githubUtils.defaults.request
|
||||
: makeProxyRequestOptions(proxy);
|
||||
const requestOptions = makeProxyRequestOptions(proxy);
|
||||
return new retryingOctokit(
|
||||
githubUtils.getOctokitOptions(auth, {
|
||||
baseUrl: apiDetails.apiURL,
|
||||
|
||||
Reference in New Issue
Block a user