Skip to content

Commit fa02c6f

Browse files
committed
ci: permit only exact emulator containers
1 parent cef0903 commit fa02c6f

2 files changed

Lines changed: 21 additions & 6 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 18 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -253,9 +253,14 @@ jobs:
253253
# claiming the sources are missing.
254254
cd keepkey-firmware/deps/python-keepkey/tests
255255
python tx_fixture_manifest.py --check
256-
sudo iptables -I OUTPUT 1 ! -o lo -m conntrack --ctstate NEW -j REJECT
256+
EMULATOR_IP=$(docker inspect -f \
257+
'{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' kkemu)
258+
test -n "$EMULATOR_IP"
259+
sudo iptables -I OUTPUT 1 -d "$EMULATOR_IP" -j ACCEPT
260+
sudo iptables -I OUTPUT 2 ! -o lo -m conntrack --ctstate NEW -j REJECT
257261
cleanup_network_gate() {
258262
sudo iptables -D OUTPUT ! -o lo -m conntrack --ctstate NEW -j REJECT
263+
sudo iptables -D OUTPUT -d "$EMULATOR_IP" -j ACCEPT
259264
}
260265
trap cleanup_network_gate EXIT
261266
pytest -v --junitxml=junit.xml 2>&1 | tee pytest-output.txt
@@ -468,9 +473,14 @@ jobs:
468473
run: |
469474
cd keepkey-firmware/deps/python-keepkey/tests
470475
python tx_fixture_manifest.py --check
471-
sudo iptables -I OUTPUT 1 ! -o lo -m conntrack --ctstate NEW -j REJECT
476+
EMULATOR_IP=$(docker inspect -f \
477+
'{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' kkemu-rc18)
478+
test -n "$EMULATOR_IP"
479+
sudo iptables -I OUTPUT 1 -d "$EMULATOR_IP" -j ACCEPT
480+
sudo iptables -I OUTPUT 2 ! -o lo -m conntrack --ctstate NEW -j REJECT
472481
cleanup_network_gate() {
473482
sudo iptables -D OUTPUT ! -o lo -m conntrack --ctstate NEW -j REJECT
483+
sudo iptables -D OUTPUT -d "$EMULATOR_IP" -j ACCEPT
474484
}
475485
trap cleanup_network_gate EXIT
476486
pytest -v --junitxml=junit-rc18.xml 2>&1 | tee pytest-rc18-output.txt
@@ -689,9 +699,14 @@ jobs:
689699
run: |
690700
cd keepkey-firmware/deps/python-keepkey/tests
691701
python tx_fixture_manifest.py --check
692-
sudo iptables -I OUTPUT 1 ! -o lo -m conntrack --ctstate NEW -j REJECT
702+
EMULATOR_IP=$(docker inspect -f \
703+
'{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' kkemu-btc)
704+
test -n "$EMULATOR_IP"
705+
sudo iptables -I OUTPUT 1 -d "$EMULATOR_IP" -j ACCEPT
706+
sudo iptables -I OUTPUT 2 ! -o lo -m conntrack --ctstate NEW -j REJECT
693707
cleanup_network_gate() {
694708
sudo iptables -D OUTPUT ! -o lo -m conntrack --ctstate NEW -j REJECT
709+
sudo iptables -D OUTPUT -d "$EMULATOR_IP" -j ACCEPT
695710
}
696711
trap cleanup_network_gate EXIT
697712
pytest -v --junitxml=junit-btc.xml test_msg_bitcoin_only_variant.py \

‎docs/handoff-python-test-hermeticity.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,9 @@ Affected surfaces:
3030
mode for every KeepKeyTest.
3131
- tests/conftest.py rejects external DNS, socket, and HTTP access per test while
3232
permitting only loopback emulator traffic and Unix-domain sockets.
33-
- .github/workflows/ci.yml checks fixture integrity, adds a kernel outbound-new-
34-
connection deny rule during authoritative pytest, and records the manifest
35-
SHA-256 in every summary.
33+
- .github/workflows/ci.yml checks fixture integrity, permits the exact local
34+
emulator container IP, rejects every other new non-loopback connection during
35+
authoritative pytest, and records the manifest SHA-256 in every summary.
3636
- tests/tx_fixture_manifest.py and tests/test_tx_fixture_integrity.py account
3737
for every fixture, reconstruct canonical transactions, recompute every txid,
3838
test cwd independence and fail-closed misses, and statically reject new

0 commit comments

Comments
 (0)