Skip to content

ci: run the sandbox tests and real scans on an ARM64 runner - #1259

Merged
crypt0rr merged 2 commits into
mainfrom
ci/arm64-sandbox
Oct 8, 2026
Merged

crypt0rr merged 2 commits into
mainfrom
ci/arm64-sandbox

Conversation

@crypt0rr

@crypt0rr crypt0rr commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

What changes

A new CI job, arm64-sandbox, on GitHub's ubuntu-24.04-arm runners.

The release publishes an ARM64 image, but its sandbox never ran on an ARM64 kernel:

  • the container job builds the ARM64 image only under QEMU, where neither the seccomp filter nor Landlock runs;
  • the seccomp filter's ARM64 system call table was checked only against x/sys's generated table and with a BPF interpreter.

The job does three things natively on ARM64:

  1. Tests: runs go test -race for internal/sandbox, internal/scanner, and internal/notify. This includes installing the real seccomp filter on a locked thread, the Landlock thread and sandbox-exec tests, and the notifier certificate checks.
  2. Image: builds the ARM64 image natively, with its own BuildKit cache scope, saved only from pushes to main like the other scopes.
  3. Real scans: runs ./scripts/verify-scanner-sandbox.sh against that image:
    • Nmap SYN and UDP and Naabu, sandboxed, Landlock-only, and unconfined;
    • the Landlock escape attempts;
    • the seccomp filter count and core limits of a running Nmap and of the notification process;
    • a sandboxed notification delivery.

Test fix the new job surfaced

The first ARM64 run failed one scanner test with fork/exec .../edgewatch: text file busy.

The scanner sandbox tests write fake executables while parallel tests fork. A child forked while a script is still open for writing holds that descriptor until it executes its own program, so running the script fails with ETXTBSY (golang/go#22315).

The tests now write their scripts while holding syscall.ForkLock shared. Go forks only while holding it exclusively, so no fork can happen in that window. 30 consecutive -race runs of those tests pass.

Notes

  • arm64-sandbox is not a required check yet. Branch protection still requires frontend, test, and container. Making it required is a repository setting I have not changed.
  • container-hardening.md and the AGENTS.md validation table now mention the ARM64 run.

Validation

  • node --test scripts/release-workflow.test.mjs passes; the workflow still parses, with the new job between container and release-cache.
  • GOARCH=arm64 go vet and go test -c succeed for the three packages and cmd/edgewatch.
  • npm --prefix docs run build
  • The job itself runs on this pull request.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Deploying edgewatch with  Cloudflare Pages  Cloudflare Pages

Latest commit: 3bd223b
Status: ✅  Deploy successful!
Preview URL: https://56fab8a2.edgewatch-cpd.pages.dev
Branch Preview URL: https://ci-arm64-sandbox.edgewatch-cpd.pages.dev

View logs

@crypt0rr
crypt0rr merged commit 96f71e9 into main Oct 8, 2026
16 checks passed
@crypt0rr
crypt0rr deleted the ci/arm64-sandbox branch October 8, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant