Skip to content

[ci] Enable Default Deny network isolation - #1555

Merged
jonathanpeppers merged 1 commit into
mainfrom
jonathanpeppers-enable-default-deny
Oct 3, 2026
Merged

jonathanpeppers merged 1 commit into
mainfrom
jonathanpeppers-enable-default-deny

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

  • enforce DefaultDeny,CFSClean at the shared AndroidX 1ES pipeline entry point
  • replace the remaining dl-ssl.google.com partial-ZIP test downloads with a deterministic loopback HTTP range fixture
  • preserve single- and multi-range download/decompression coverage without outbound public traffic

Pipeline scope

Azure DevOps definition 12322 (AndroidX) sources this repository's azure-pipelines.yml. Definition 11678 (xamarin_LibZipSharp) sources dotnet/android-libzipsharp, so it is intentionally not changed here.

Validation

  • targeted Release xUnit v3 run: 2 passed, 0 failed
  • azure-pipelines.yml parsed successfully with networkIsolationPolicy: DefaultDeny,CFSClean
  • git diff --check passed
  • trusted DevDiv AndroidX validation: build 20261001.2 (15536366)

The latest successful AndroidX audit run showed exactly three Default Deny violations, all from the two replaced Xamarin.Build.Download.Tests cases. Its standard package-test, signing, and publish jobs were already Default Deny compliant, and all jobs were CFSClean/CFSClean2/CFSClean3 compliant.

The trusted validation build runs this branch's azure-pipelines.yml. Verify each 1ES job invokes Enforce -Policies DefaultDeny,CFSClean and reports all four effective policies compliant.

Apply DefaultDeny with CFSClean to the shared 1ES pipeline entry point and replace the remaining public partial-ZIP test downloads with a loopback range fixture.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused pipeline and test changes preserve existing coverage without unresolved correctness issues.

Review effort: Balanced
Findings: None

What changed in this PR

Enables default-deny network isolation while preserving partial-ZIP test coverage without public network access.

Changes:

  • Enforces DefaultDeny,CFSClean in the shared 1ES pipeline.
  • Replaces external partial-ZIP downloads with a loopback HTTP range fixture.
  • Verifies decompressed content for single and multiple ranges.
File Description
azure-pipelines.yml Enables default-deny network isolation.
util/​Xamarin.Build.Download/​source/​Xamarin.Build.Download.Tests/​Test.cs Adds deterministic local range responses and updates partial-ZIP tests.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The shared DefaultDeny,CFSClean setting is correctly propagated through the 1ES template boundary. The loopback range fixture preserves the real single- and multiple-entry download/decompression paths without public downloads, and verifies exact extracted contents. No high-confidence blocker remains in the current change.

@jonathanpeppers
jonathanpeppers merged commit 06ad7c3 into main Oct 3, 2026
7 of 9 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-enable-default-deny branch October 3, 2026 23:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants