docs: document PHP 8 hardening and CI behavior - #330
Open
somethingwithproof wants to merge 3 commits into
Open
Conversation
Three defects, all failing open or failing at setup:
- the plugin syntax check redirected find's own output rather than php's, so
PHP errors never reached the grep testing for them; the step could not fail
- MYSQL_AUTH_USR carried a literal tilde, because parameter expansion happens
after tilde expansion, so MySQL was handed a path it could not resolve
- the Cacti checkout took the default branch, which is 1.3 in development and
whose CLI installer currently fatals with an undefined __()
plugin_syslog additionally installed libapache2-mod-php${{ matrix.php }},
which Ubuntu does not package, so apt exited 100 before Cacti was reached.
Verified with actionlint, which is clean on the result.
Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The integration workflow changes introduce CI correctness risks (PHP matrix integrity and MySQL privilege host mismatch) that could make the integration results unreliable or intermittently failing.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR documents the develop-branch PHP 8 hardening/security posture and records related CI/test behavior changes, while also updating the GitHub Actions integration workflow to pin the Cacti baseline and adjust setup steps.
Changes:
- Added a “Develop Branch Compatibility and Hardening Notes” section to the README covering runtime/CI baselines, security-sensitive behaviors, partition maintenance, and validation.
- Updated the
developchangelog with entries summarizing security hardening, test additions, and CI matrix/baseline details. - Adjusted the integration workflow to pin the Cacti checkout to
release/1.2.31and updated lint/MySQL initialization steps.
File summaries
| File | Description |
|---|---|
| README.md | Documents PHP 8 baseline, hardening behaviors, and validation approach for develop. |
| CHANGELOG.md | Records security/test/CI changes in the develop section. |
| .github/workflows/plugin-ci-workflow.yml | Pins Cacti checkout and refines lint + integration environment setup. |
Review details
Suppressed comments (1)
.github/workflows/plugin-ci-workflow.yml:174
- The workflow grants privileges to
'cactiuser'@'localhost', but the Cacti config is rewritten to use127.0.0.1and the MySQL service connection will not authenticate aslocalhost. This can leave the actually-used account (typically'cactiuser'@'%') without themysql.time_zone_nameprivilege and cause intermittent install/runtime failures.
mysql "$MYSQL_AUTH_USR" -e "CREATE USER IF NOT EXISTS 'cactiuser'@'localhost' IDENTIFIED BY 'cactiuser';"
mysql "$MYSQL_AUTH_USR" -e "GRANT ALL PRIVILEGES ON cacti.* TO 'cactiuser'@'localhost';"
mysql "$MYSQL_AUTH_USR" -e "GRANT SELECT ON mysql.time_zone_name TO 'cactiuser'@'localhost';"
mysql "$MYSQL_AUTH_USR" -e "FLUSH PRIVILEGES;"
- Files reviewed: 3/3 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| - name: Install System Dependencies | ||
| run: sudo apt-get install -y apache2 snmp snmpd rrdtool fping libapache2-mod-php${{ matrix.php }} | ||
| run: sudo apt-get install -y apache2 snmp snmpd rrdtool fping libapache2-mod-php |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
dMaxValuefail-safe behaviorDependency
This branch includes the existing commit from #329 so the documentation PR can run against the repaired integration workflow. Once #329 lands in
develop, the remaining diff is documentation-only.Validation
actionlintand YAML parsingdevelopfailuresdevelopbaseline at 48 legacy findings and introduces no new violationsrelease/1.2.31composer.jsonvalidated and installed in an ephemeral Linux Composer containergit diff --checkNo
composer.jsonwas added, edited, or pushed.