mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-01 19:12:14 +00:00
e2b2bdcc34
Three hardening changes with no effect on what any workflow produces. Declare timeout-minutes on the 25 jobs that lacked it. GitHub's default is 360 minutes, and this repository has a history of runners stalling intermittently (#5394) plus a measured 9m57s plain `git checkout` under node-level I/O contention, so one wedged job could hold a runner for six hours out of a pool of roughly 15-21. Budgets follow what the jobs actually do: 10 minutes for echo-only and guard-script jobs, 30 for anything calling the GitHub API, uploading release assets or pushing over the network. scripts/security/check_job_timeouts.sh keeps it that way, checking only jobs that declare runs-on so reusable-workflow callers are not flagged. Pass workflow inputs and workflow_run fields through env instead of `${{ }}` interpolation in run blocks. A git ref name may contain `$(...)` — any string without a space is a legal tag — and interpolation pastes it into the script where bash evaluates it. The worst instance was helm-package's final commit message: it is built from the triggering tag name inside the job that holds the cross-repository push token with rustfs/helm already checked out. Also converted in build.yml, docker.yml and performance-ab.yml; the last is currently disabled, but a disabled workflow can be re-enabled. Not touched: helm-package's `contains(head_branch, '.')` tag test, since GitHub expressions have no regex and this repository's tags carry no `v` prefix, so rewriting the condition would change which builds publish a chart. Give audit.yml a scheduled-failure alert and run it daily. A scheduled cargo-deny failure usually means the dependency tree just matched a newly published RustSec advisory — the most important signal this workflow produces, and until now it was visible only to whoever happened to open the Actions tab. coverage.yml and e2e-replication-nightly.yml already use this ci-8 mechanism. The cron moves from weekly to daily so a new advisory against an unchanged tree surfaces within a day instead of seven; the check list is untouched, since splitting it into a light daily run and a weekly full run would create runs where sources, bans and licenses go unverified. Refs: rustfs/backlog#1598, rustfs/backlog#1602
181 lines
7.1 KiB
YAML
181 lines
7.1 KiB
YAML
# Copyright 2024 RustFS Team
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
name: Security Audit
|
|
|
|
on:
|
|
push:
|
|
branches: [ main ]
|
|
paths:
|
|
- '**/Cargo.toml'
|
|
- '**/Cargo.lock'
|
|
- 'deny.toml'
|
|
- '.github/actions/**'
|
|
- '.github/workflows/**'
|
|
- 'scripts/release/create_or_update_release.sh'
|
|
- 'scripts/security/check_preview_release_workflow.sh'
|
|
- 'scripts/security/check_workflow_pins.sh'
|
|
pull_request:
|
|
types: [ opened, synchronize, reopened, closed ]
|
|
branches: [ main ]
|
|
paths:
|
|
- '**/Cargo.toml'
|
|
- '**/Cargo.lock'
|
|
- 'deny.toml'
|
|
- '.github/actions/**'
|
|
- '.github/workflows/**'
|
|
- 'scripts/release/create_or_update_release.sh'
|
|
- 'scripts/security/check_preview_release_workflow.sh'
|
|
- 'scripts/security/check_workflow_pins.sh'
|
|
schedule:
|
|
# Daily, not weekly. This schedule exists to catch RustSec advisories
|
|
# published against an unchanged dependency tree; at weekly cadence a new
|
|
# advisory could sit unnoticed for seven days. The check list is unchanged —
|
|
# splitting it into a light daily advisories-only run and a weekly full run
|
|
# would create runs where sources/bans/licenses go unverified.
|
|
- cron: '0 3 * * *' # Daily 03:00 UTC (staggered after the midnight ci/build crons)
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
# Event-scoped groups: merges to main must not cancel the weekly scheduled
|
|
# run (same rationale as ci.yml).
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: ${{ github.event_name != 'schedule' }}
|
|
|
|
env:
|
|
CARGO_TERM_COLOR: always
|
|
|
|
jobs:
|
|
cancel-closed-pr-runs:
|
|
name: Cancel Closed PR Runs
|
|
if: github.event_name == 'pull_request' && github.event.action == 'closed'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Explain cancellation run
|
|
run: echo "PR closed; this run only cancels older runs in the same concurrency group."
|
|
|
|
# RustSec advisory scanning is covered by the `advisories` check of
|
|
# cargo-deny below; a separate cargo-audit job would duplicate the same
|
|
# database lookup with a second ignore list to maintain.
|
|
cargo-deny:
|
|
name: Cargo Deny
|
|
if: github.event_name != 'pull_request' || github.event.action != 'closed'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
|
|
# cargo-deny compiles nothing, so the full setup composite (apt packages,
|
|
# protoc, flatc, nextest, rustfmt/clippy) was pure overhead here. It does
|
|
# still need a real cargo: `cargo deny check` runs `cargo metadata`, and
|
|
# Cargo.toml pins datafusion and s3s as git dependencies, which must be
|
|
# materialised into ~/.cargo/git — a cold clone is hundreds of MB, so the
|
|
# cache stays.
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
|
|
|
|
# Was relying on the composite's default, which used to be "true": every
|
|
# PR touching Cargo.toml/Cargo.lock saved a second, PR-scoped copy of this
|
|
# cache and pushed the main-scoped lanes out of the 10GB quota. The
|
|
# default is now "false", but state it explicitly — see
|
|
# scripts/security/check_cache_save_if.sh.
|
|
- name: Setup Rust cache
|
|
uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
|
|
with:
|
|
cache-all-crates: true
|
|
cache-on-failure: true
|
|
shared-key: rustfs-cargo-deny
|
|
save-if: ${{ github.ref == 'refs/heads/main' }}
|
|
|
|
- name: Install cargo-deny
|
|
uses: taiki-e/install-action@bffeee26d4db9be238a4ea78d8826604ebcb594d # v2
|
|
with:
|
|
tool: cargo-deny
|
|
|
|
- name: Run cargo-deny
|
|
run: cargo deny check --hide-inclusion-graph advisories sources bans licenses
|
|
|
|
workflow-pin-report:
|
|
name: Workflow Pin Report
|
|
if: github.event_name != 'pull_request' || github.event.action != 'closed'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
|
|
- name: Report unpinned GitHub Actions
|
|
run: ./scripts/security/check_workflow_pins.sh --enforce
|
|
|
|
- name: Check setup cache-save-if is explicit
|
|
run: ./scripts/security/check_cache_save_if.sh
|
|
|
|
- name: Check every job declares a timeout
|
|
run: ./scripts/security/check_job_timeouts.sh
|
|
|
|
- name: Check preview release workflow policy
|
|
run: ./scripts/security/check_preview_release_workflow.sh
|
|
|
|
dependency-review:
|
|
name: Dependency Review
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
if: github.event_name == 'pull_request' && github.event.action != 'closed'
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
|
|
- name: Dependency Review
|
|
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5
|
|
with:
|
|
fail-on-severity: moderate
|
|
allow-ghsas: GHSA-2f9f-gq7v-9h6m
|
|
# rustfs-uring is a first-party Apache-2.0 crate, now published on
|
|
# crates.io (backlog#1104) rather than pulled as a git dependency.
|
|
# Scope the allow to the exact pinned version so a version bump forces a
|
|
# conscious re-review of the license/provenance claim (backlog#1181).
|
|
allow-dependencies-licenses: pkg:cargo/rustfs-uring@0.1.0
|
|
comment-summary-in-pr: always
|
|
|
|
alert-on-failure:
|
|
name: Alert on scheduled failure
|
|
# dependency-review is deliberately excluded: it only runs on pull_request,
|
|
# so it can never contribute a failure to a scheduled run.
|
|
needs: [cargo-deny, workflow-pin-report]
|
|
# A scheduled cargo-deny failure usually means the dependency tree just
|
|
# matched a newly published advisory — the single most important signal this
|
|
# workflow produces, and until now it was only visible to whoever happened to
|
|
# open the Actions tab. Same ci-8 mechanism coverage.yml and
|
|
# e2e-replication-nightly.yml already use.
|
|
if: always() && github.event_name == 'schedule' && contains(needs.*.result, 'failure')
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
permissions:
|
|
contents: read
|
|
issues: write
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
- name: Open or update failure-tracking issue
|
|
uses: ./.github/actions/schedule-failure-issue
|
|
with:
|
|
github-token: ${{ secrets.GITHUB_TOKEN }}
|