Repository navigation
test(analyzer): 宿主机低完整性令牌初始化限制的显式 opt-in 跳过 - #65
Merged
Merged
Conversation
- 提取 analyzerIsolationHostLimitationSkip 决策函数:仅当 helper 空输出且退出码恰为 0xc0000142(STATUS_DLL_INIT_FAILED)时才考虑跳过 - GitHub-hosted Windows runner 逃生门不变;新增 CYBERAGENT_ANALYZER_ISOLATION_CONFORMANCE_ACCEPT_HOST_LIMITATION=1(仅 _test.go 读取、只接受精确值 1)将同一失败转为带原因的 t.Skip - 其他退出码/有输出/未显式确认一律保持大声失败,产品权威保持关闭 - 新增决策函数单元测试覆盖 GitHub 逃生门、opt-in 精确匹配与不可放宽条件
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
internal/analyzer的两个 OS 级隔离边界一致性测试(TestAnalyzerDedicatedLowPrivilegeIdentityConformance、TestAnalyzerReadOnlyFilesystemPrivateStagingConformance)会用 CreateRestrictedToken + 禁用 Administrators SID + Low IL 构造受限低完整性主令牌,再以该令牌启动 helper 进程验证身份/文件系统边界。在某些本地 Windows 主机上,安全软件或系统策略注入的 DLL 在低完整性受限令牌下无法初始化,helper 在 main 之前就以STATUS_DLL_INIT_FAILED(0xc0000142)退出、输出为空。仓库此前已为 GitHub-hosted Windows runner 内置了精确的逃生门(
skipHostedWindowsServiceInitialization),本地宿主机则保持大声失败。本 PR 为本地宿主机补一个显式 opt-in 的同类逃生门。本次改动
analyzerIsolationHostLimitationSkip(exitCode, output, getenv)决策函数:只有「helper 空输出 + 退出码恰为0xc0000142」这一精确失败类别才进入跳过判定;其他任何失败仍然大声失败。CYBERAGENT_ANALYZER_ISOLATION_CONFORMANCE_ACCEPT_HOST_LIMITATION=1(仅_test.go读取、只接受精确值1)把同一失败转为带原因的t.Skip,原因字符串包含环境变量名并重申 "product authority remains closed"。1/空/0/true/带空格均不跳过)、非0xc0000142不可放宽、有输出不可跳过、未确认保持大声失败。测试覆盖
TestAnalyzerIsolationHostLimitationSkip:决策函数的全部分支。...=1后转为 SKIP 且打印原因;go test ./internal/analyzer/在 opt-in 下全部通过。go test -timeout 30m ./...(opt-in 下)无 FAIL;go build ./...、go vet ./...通过。验证结果
CYBERAGENT_ANALYZER_ISOLATION_CONFORMANCE_ACCEPT_HOST_LIMITATION=1)通过。安全边界与非目标
_test.go读取,产品代码零引用;跳过不代表子进程或产品证据,产品 analyzer 权威保持关闭。0xc0000142+ 空输出;不做任何放宽(无通配、无其他退出码、无模糊匹配)。