Skip to content

fix(LH-3904): propose exact Gemfury signed-download host admission - #284

Open
michal-larahealth wants to merge 1 commit into
dependabot:mainfrom
michal-larahealth:fix/LH-3904-gemfury-egress
Open

michal-larahealth wants to merge 1 commit into
dependabot:mainfrom
michal-larahealth:fix/LH-3904-gemfury-egress

Conversation

@michal-larahealth

@michal-larahealth michal-larahealth commented Oct 1, 2026 •

Copy link
Copy Markdown

What are you trying to accomplish?

Propose an exact-host exception for Gemfury's signed Python artifact downloads. Authenticated requests to its documented PyPI endpoint succeed, then redirect package downloads to gemfury.s3-accelerate.dualstack.amazonaws.com, which the egress proxy blocks. This adds one exact host under the Python anchor shared by pip and uv; it does not configure registry authentication.

Reference: Gemfury PyPI endpoint documentation and GitHub blocked-host guidance. Ownership evidence is the HTTPS redirect issued by the provider's authenticated index. No private artifact paths or signed URLs are included.

Anything you want to highlight for special attention from reviewers?

Draft policy-exception proposal; maintainer acceptance is required. The repository's allowlist skill prohibits shared multi-tenant path hosts in static defaults. This exact, existing provider bucket contains customer-uploaded objects. The handler unions defaults for every job; placement under Python does not limit access to Python jobs or to one customer's paths. Exact matching blocks other buckets and child hosts but does not close that path boundary. Please assess whether this exception is acceptable, or prefer a proxy fix for credential-free per-job admission.

A per-job anonymous python-index declaration is currently not a working alternative: the static Python handler supplies empty Basic authentication. A live signed download returned HTTP 200 without Authorization and HTTP 400 with that empty header. Index credentials were never sent to the download host. The proposal adds no secrets, no arbitrary S3 wildcard, no runner change, and no authentication handler change.

How will you know you've accomplished your goal?

Synthetic egress tests admit the exact artifact host and reject its child, a sibling bucket and the S3 apex. A temporary leading-dot mutation failed the negative test and was restored. Hosted deployment must subsequently be verified by a fresh successful package update; a merge alone is not deployment evidence. Rollback removes the exact default entry.

Validation

  • PASS: go build ./...
  • PASS: go test ./internal/handlers/ -run TestEgress -count=1
  • PASS: go vet ./...
  • PASS: gofmt -l internal/handlers/egress_allowlist_test.go (no output)
  • PASS: git diff --check
  • PASS: leading-dot mutation is rejected by TestEgressAllowlist_NewEntriesDoNotWidenBeyondExactHosts; exact entry restored.
  • PASS (hosted): complete script/test Docker race suite, lint and four-platform build matrix in CI.
  • PASS (hosted): complete Smoke matrix. All 108 PR checks passed at head 7264725; maintainer policy acceptance and hosted deployment remain pending.

Test Cases

Synthetic admission boundaries
  • Exact Gemfury artifact URL passes.
  • Child hostname remains blocked.
  • Another S3 acceleration bucket remains blocked.
  • Path-style S3 acceleration apex remains blocked.
  • Existing alias synchronization and redundant-entry checks pass with the egress suite.

Checklist

  • I have run the complete test suite to ensure all tests and linters pass (verified hosted script/test, lint and the complete smoke matrix).
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

@michal-larahealth
michal-larahealth marked this pull request as ready for review October 1, 2026 09:49
@michal-larahealth
michal-larahealth requested a review from a team as a code owner October 1, 2026 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant