test(infra): clamd detects EICAR and passes a clean stream over INSTREAM (refs #191)

Red: no clamav service exists yet, so verify-clamav finds no container.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:01:01 +02:00
co-authored by Claude Opus 5.5
parent eba1381ef2
commit 3e9bda9031
4 changed files with 73 additions and 1 deletions
+40
View File
@@ -0,0 +1,40 @@
#!/usr/bin/env python3
"""S-28 (#191): prove clamd is up, has signatures loaded, and scans a stream over INSTREAM.
The EICAR test file must come back FOUND and a clean payload OK — the same protocol the domain's
scanner adapter will speak (ADR-0036). EICAR is assembled from two halves so this file itself is
not flagged by an on-access scanner on a developer laptop. Stdlib only (python:3-slim).
"""
import os
import socket
import struct
import sys
import time
HOST = os.environ["CLAMAV"]
TIMEOUT = int(os.environ.get("CLAMAV_TIMEOUT", "60"))
EICAR = (r"X5O!P%@AP[4\PZX54(P^)7CC)7}$" + r"EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*").encode()
def instream(payload):
with socket.create_connection((HOST, 3310), timeout=30) as s:
s.sendall(b"zINSTREAM\0" + struct.pack(">I", len(payload)) + payload + struct.pack(">I", 0))
return s.recv(4096).rstrip(b"\0").decode()
deadline = time.time() + TIMEOUT
while True:
try:
clean, infected = instream(b"%PDF-1.4 clean"), instream(EICAR)
break
except OSError as e:
if time.time() > deadline:
sys.exit(f"FAIL: clamd at {HOST}:3310 unreachable: {e}")
time.sleep(3)
print(f"clean → {clean!r}; eicar → {infected!r}")
if clean != "stream: OK":
sys.exit("FAIL: clean payload was not reported OK")
if not infected.endswith("FOUND"):
sys.exit("FAIL: EICAR was not detected")
print("OK: clamd detects EICAR and passes a clean stream")
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/env bash
#
# S-28 (#191): assert clamd scans over INSTREAM (EICAR → FOUND, clean → OK), against an
# ALREADY-RUNNING stack. Runs the check in a python:3-slim container on the stack network (the
# runner can't reach published ports — gitea-actions-gotchas.md §5/§6).
set -euo pipefail
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
av="$(docker ps -q --filter 'name=[-_]clamav[-_][0-9]+$' | head -1)"
[ -n "$av" ] || { echo "ERROR: no running clamav container — bring the stack up first" >&2; exit 1; }
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$av" | head -1)"
ip="$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$av")"
echo ">> network=$net clamav=$ip"
cid="$(docker create --network "$net" -e "CLAMAV=$ip" -e "CLAMAV_TIMEOUT=${CLAMAV_TIMEOUT:-60}" \
python:3-slim python /clamav-check.py)"
docker cp "$here/clamav-check.py" "$cid:/clamav-check.py" >/dev/null
rc=0; docker start -a "$cid" || rc=$?
docker rm -f "$cid" >/dev/null
exit $rc