[ci] Enable Default Deny network isolation - #1555
Conversation
Apply DefaultDeny with CFSClean to the shared 1ES pipeline entry point and replace the remaining public partial-ZIP test downloads with a loopback range fixture. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused pipeline and test changes preserve existing coverage without unresolved correctness issues.
Review effort: Balanced
Findings: None
What changed in this PR
Enables default-deny network isolation while preserving partial-ZIP test coverage without public network access.
Changes:
- Enforces
DefaultDeny,CFSCleanin the shared 1ES pipeline. - Replaces external partial-ZIP downloads with a loopback HTTP range fixture.
- Verifies decompressed content for single and multiple ranges.
| File | Description |
|---|---|
azure-pipelines.yml |
Enables default-deny network isolation. |
util/Xamarin.Build.Download/source/Xamarin.Build.Download.Tests/Test.cs |
Adds deterministic local range responses and updates partial-ZIP tests. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
@dalexsoto review |
dalexsoto
left a comment
There was a problem hiding this comment.
The shared DefaultDeny,CFSClean setting is correctly propagated through the 1ES template boundary. The loopback range fixture preserves the real single- and multiple-entry download/decompression paths without public downloads, and verifies exact extracted contents. No high-confidence blocker remains in the current change.
Summary
DefaultDeny,CFSCleanat the shared AndroidX 1ES pipeline entry pointdl-ssl.google.compartial-ZIP test downloads with a deterministic loopback HTTP range fixturePipeline scope
Azure DevOps definition 12322 (
AndroidX) sources this repository'sazure-pipelines.yml. Definition 11678 (xamarin_LibZipSharp) sourcesdotnet/android-libzipsharp, so it is intentionally not changed here.Validation
azure-pipelines.ymlparsed successfully withnetworkIsolationPolicy: DefaultDeny,CFSCleangit diff --checkpassedThe latest successful AndroidX audit run showed exactly three Default Deny violations, all from the two replaced
Xamarin.Build.Download.Testscases. Its standard package-test, signing, and publish jobs were already Default Deny compliant, and all jobs were CFSClean/CFSClean2/CFSClean3 compliant.The trusted validation build runs this branch's
azure-pipelines.yml. Verify each 1ES job invokesEnforce -Policies DefaultDeny,CFSCleanand reports all four effective policies compliant.