Skip to content

docs: document PHP 8 hardening and CI behavior - #330

Open
somethingwithproof wants to merge 3 commits into
Cacti:developfrom
somethingwithproof:agent/docs-security-php8-workflow
Open

docs: document PHP 8 hardening and CI behavior#330
somethingwithproof wants to merge 3 commits into
Cacti:developfrom
somethingwithproof:agent/docs-security-php8-workflow

Conversation

@somethingwithproof

Copy link
Copy Markdown
Member

Summary

  • document the PHP 8 runtime and Linux integration-test baseline
  • describe CSRF, output escaping, callback, CSV, and XML import hardening
  • explain UTC partition maintenance and the dMaxValue fail-safe behavior
  • record the security, test, and CI changes in the develop changelog

Dependency

This branch includes the existing commit from #329 so the documentation PR can run against the repaired integration workflow. Once #329 lands in develop, the remaining diff is documentation-only.

Validation

  • Dockerized actionlint and YAML parsing
  • repository-wide PHP 8.0 syntax lint in Linux Docker
  • Dockerized regression run: 5 passed, with the same 3 inherited develop failures
  • Markdown lint matches the develop baseline at 48 legacy findings and introduces no new violations
  • untouched Cacti release/1.2.31 composer.json validated and installed in an ephemeral Linux Composer container
  • Dockerized git diff --check

No composer.json was added, edited, or pushed.

Three defects, all failing open or failing at setup:

- the plugin syntax check redirected find's own output rather than php's, so
  PHP errors never reached the grep testing for them; the step could not fail
- MYSQL_AUTH_USR carried a literal tilde, because parameter expansion happens
  after tilde expansion, so MySQL was handed a path it could not resolve
- the Cacti checkout took the default branch, which is 1.3 in development and
  whose CLI installer currently fatals with an undefined __()

plugin_syslog additionally installed libapache2-mod-php${{ matrix.php }},
which Ubuntu does not package, so apt exited 100 before Cacti was reached.

Verified with actionlint, which is clean on the result.

Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The integration workflow changes introduce CI correctness risks (PHP matrix integrity and MySQL privilege host mismatch) that could make the integration results unreliable or intermittently failing.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR documents the develop-branch PHP 8 hardening/security posture and records related CI/test behavior changes, while also updating the GitHub Actions integration workflow to pin the Cacti baseline and adjust setup steps.

Changes:

  • Added a “Develop Branch Compatibility and Hardening Notes” section to the README covering runtime/CI baselines, security-sensitive behaviors, partition maintenance, and validation.
  • Updated the develop changelog with entries summarizing security hardening, test additions, and CI matrix/baseline details.
  • Adjusted the integration workflow to pin the Cacti checkout to release/1.2.31 and updated lint/MySQL initialization steps.
File summaries
File Description
README.md Documents PHP 8 baseline, hardening behaviors, and validation approach for develop.
CHANGELOG.md Records security/test/CI changes in the develop section.
.github/workflows/plugin-ci-workflow.yml Pins Cacti checkout and refines lint + integration environment setup.
Review details

Suppressed comments (1)

.github/workflows/plugin-ci-workflow.yml:174

  • The workflow grants privileges to 'cactiuser'@'localhost', but the Cacti config is rewritten to use 127.0.0.1 and the MySQL service connection will not authenticate as localhost. This can leave the actually-used account (typically 'cactiuser'@'%') without the mysql.time_zone_name privilege and cause intermittent install/runtime failures.
        mysql "$MYSQL_AUTH_USR" -e "CREATE USER IF NOT EXISTS 'cactiuser'@'localhost' IDENTIFIED BY 'cactiuser';"
        mysql "$MYSQL_AUTH_USR" -e "GRANT ALL PRIVILEGES ON cacti.* TO 'cactiuser'@'localhost';"
        mysql "$MYSQL_AUTH_USR" -e "GRANT SELECT ON mysql.time_zone_name TO 'cactiuser'@'localhost';"
        mysql "$MYSQL_AUTH_USR" -e "FLUSH PRIVILEGES;"
  • Files reviewed: 3/3 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


- name: Install System Dependencies
run: sudo apt-get install -y apache2 snmp snmpd rrdtool fping libapache2-mod-php${{ matrix.php }}
run: sudo apt-get install -y apache2 snmp snmpd rrdtool fping libapache2-mod-php
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants