runner-guard: block workflows that hand a self-hosted runner to strangers (Boss 10-01)
R1 pull_request_target; R2 fork pull_request on self-hosted without a same-repo/environment gate; R3 outsider events (issue_comment, workflow_run, ...) on self-hosted; R0 unparseable. PR mode in the 5-min sync posts windy-git/runner-guard on open PRs of public sneakyfree repos that change a workflow (each status once). Nightly sweep (Windy 0 timer) over every public repo: page + BOARD line on new hits + red windy-job heartbeat. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
28
deploy/windy0/nightly-runner-guard-sweep.sh
Executable file
28
deploy/windy0/nightly-runner-guard-sweep.sh
Executable file
@@ -0,0 +1,28 @@
|
||||
#!/usr/bin/env bash
|
||||
# Nightly (Boss 10-01): runner-guard over the default branch of EVERY public repo in Grant's
|
||||
# 5 GitHub accounts (runs on Veron: windy-git scripts/runner_guard.py report). Writes
|
||||
# ~/windy-orchestra/RUNNER_GUARD.md (repo, file:line, rule; no file content), appends ONE
|
||||
# BOARD line per NEW hit vs the last run, and prints "runner-guard sweep: N hit(s)" last, so
|
||||
# the windy-job heartbeat (--expect "runner-guard sweep: 0 hit") goes red while any hit exists.
|
||||
set -euo pipefail
|
||||
page=~/windy-orchestra/RUNNER_GUARD.md
|
||||
state=~/.local/state/runner-guard-sweep.txt
|
||||
mkdir -p "$(dirname "$state")"
|
||||
out=$(timeout 900 ssh -o BatchMode=yes -o ConnectTimeout=15 ts-veron \
|
||||
'cd /srv/windygit/src && timeout 850 python3 scripts/runner_guard.py report' || true)
|
||||
summary=$(grep '^# runner-guard sweep:' <<<"$out" || echo "# runner-guard sweep: ERROR (no summary)")
|
||||
hits=$(grep -v '^#' <<<"$out" | grep . || true)
|
||||
{
|
||||
echo "# Runner guard: stranger-code paths to self-hosted runners ($(date -u '+%Y-%m-%d %H:%MZ'))"
|
||||
echo "_Nightly; windy-git scripts/runner_guard.py. R1 pull_request_target · R2 fork PR on self-hosted without a same-repo/environment gate · R3 outsider events (issue_comment, workflow_run, ...) on self-hosted · R0 unparseable._"
|
||||
echo; echo "${summary#\# }"; echo
|
||||
echo "| repo | file:line | rule | fix |"; echo "|---|---|---|---|"
|
||||
while IFS=$'\t' read -r repo loc rule msg; do [[ -n $repo ]] && echo "| $repo | $loc | $rule | $msg |"; done <<<"$hits"
|
||||
} > "$page"
|
||||
new=$(comm -13 <(sort -u "$state" 2>/dev/null || true) <(cut -f1-3 <<<"$hits" | sort -u))
|
||||
cut -f1-3 <<<"$hits" | sort -u > "$state"
|
||||
if [[ -n "$new" ]]; then
|
||||
n=$(grep -c . <<<"$new")
|
||||
echo "$(date -u +%Y-%m-%dT%H:%MZ) Windy Git: 🚨 runner-guard: $n NEW stranger-code path(s) to a self-hosted runner in public repos; see ~/windy-orchestra/RUNNER_GUARD.md" >> ~/windy-orchestra/BOARD.md
|
||||
fi
|
||||
echo "${summary#\# }"
|
||||
Reference in New Issue
Block a user