mirror of
https://github.com/trailofbits/algo.git
synced 2026-09-29 04:54:58 +02:00
* ci: modernize tooling with prek, ty, and security scanning Migrate from pre-commit to prek (Rust-native, faster hooks) and add comprehensive CI improvements for code quality and security. Changes: - Replace pre-commit with prek for git hooks - Add ty type checker (Rust-based, replaces mypy) - Expand ruff rules: security (S), simplify (SIM), commented code (ERA) - Add pip-audit workflow for Python dependency CVE scanning - Add actionlint and zizmor for GitHub Actions linting/security - Add ruff format check to CI - Enable stricter ansible-lint rules (no-changed-when, risky-file-permissions) - Remove obsolete Claude workflow files - Apply ruff formatting fixes to test files Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(ci): resolve actionlint install and ty type errors - Use actionlint's official install script instead of broken URL pattern - Exclude test mock modules from ty type checking - Run workflows on push only for main/master to avoid duplicate PR runs Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(ci): use glob pattern for actionlint, exclude all tests from ty - actionlint requires *.yml glob, not directory path - Exclude all tests from ty type checking (test code has looser typing) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(ci): quote shell variables to fix shellcheck warnings Fix SC2046/SC2086 warnings in workflow scripts: - Quote $(uname -r) in apt-get install - Quote $(pwd) in docker volume mount - Quote $existing in gh issue comment Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(ci): move key-order[task] to warn_list Too many existing violations in the codebase to enable as error. Move to warn_list for gradual fixes over time. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
58 lines
1.4 KiB
Python
58 lines
1.4 KiB
Python
#!/usr/bin/env python3
|
|
"""
|
|
Wrapper for Ansible's service module that always succeeds for known services
|
|
"""
|
|
|
|
import json
|
|
import sys
|
|
|
|
# Parse module arguments
|
|
args = json.loads(sys.stdin.read())
|
|
module_args = args.get("ANSIBLE_MODULE_ARGS", {})
|
|
|
|
service_name = module_args.get("name", "")
|
|
state = module_args.get("state", "started")
|
|
|
|
# Known services that should always succeed
|
|
known_services = [
|
|
"netfilter-persistent",
|
|
"iptables",
|
|
"wg-quick@wg0",
|
|
"strongswan-starter",
|
|
"ipsec",
|
|
"apparmor",
|
|
"unattended-upgrades",
|
|
"systemd-networkd",
|
|
"systemd-resolved",
|
|
"rsyslog",
|
|
"ipfw",
|
|
"cron",
|
|
]
|
|
|
|
# Check if it's a known service
|
|
service_found = False
|
|
for svc in known_services:
|
|
if service_name == svc or service_name.startswith(svc + "."):
|
|
service_found = True
|
|
break
|
|
|
|
if service_found:
|
|
# Return success
|
|
result = {
|
|
"changed": state in ["started", "stopped", "restarted", "reloaded"],
|
|
"name": service_name,
|
|
"state": state,
|
|
"status": {
|
|
"LoadState": "loaded",
|
|
"ActiveState": "active" if state != "stopped" else "inactive",
|
|
"SubState": "running" if state != "stopped" else "dead",
|
|
},
|
|
}
|
|
print(json.dumps(result))
|
|
sys.exit(0)
|
|
else:
|
|
# Service not found
|
|
error = {"failed": True, "msg": f"Could not find the requested service {service_name}: "}
|
|
print(json.dumps(error))
|
|
sys.exit(1)
|