Deploy to Talos / deploy (push) Successful in 2m40s
CI / k8s (push) Successful in 1m23s
CI / build (push) Successful in 4m55s
CI / lint (push) Successful in 6m25s
CI / unit (push) Successful in 1m6s
CI / docs (push) Successful in 1m22s
CI / frontend (push) Successful in 2m44s
CI / mutation (push) Successful in 4m22s
CI / verify-stack (push) Successful in 21m56s
Runs a ClamAV daemon (clamav/clamav:1.4.6) in both compose stacks and the Helm chart, health-gated, with a verify-clamav check (EICAR found, clean OK) in verify-stack. ADR-0036 records the scan-in-domain, fail-closed decision (#190). closes #191 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
41 lines
1.4 KiB
Python
41 lines
1.4 KiB
Python
#!/usr/bin/env python3
|
|
"""S-28 (#191): prove clamd is up, has signatures loaded, and scans a stream over INSTREAM.
|
|
|
|
The EICAR test file must come back FOUND and a clean payload OK — the same protocol the domain's
|
|
scanner adapter will speak (ADR-0036). EICAR is assembled from two halves so this file itself is
|
|
not flagged by an on-access scanner on a developer laptop. Stdlib only (python:3-slim).
|
|
"""
|
|
import os
|
|
import socket
|
|
import struct
|
|
import sys
|
|
import time
|
|
|
|
HOST = os.environ["CLAMAV"]
|
|
TIMEOUT = int(os.environ.get("CLAMAV_TIMEOUT", "60"))
|
|
EICAR = (r"X5O!P%@AP[4\PZX54(P^)7CC)7}$" + r"EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*").encode()
|
|
|
|
|
|
def instream(payload):
|
|
with socket.create_connection((HOST, 3310), timeout=30) as s:
|
|
s.sendall(b"zINSTREAM\0" + struct.pack(">I", len(payload)) + payload + struct.pack(">I", 0))
|
|
return s.recv(4096).rstrip(b"\0").decode()
|
|
|
|
|
|
deadline = time.time() + TIMEOUT
|
|
while True:
|
|
try:
|
|
clean, infected = instream(b"%PDF-1.4 clean"), instream(EICAR)
|
|
break
|
|
except OSError as e:
|
|
if time.time() > deadline:
|
|
sys.exit(f"FAIL: clamd at {HOST}:3310 unreachable: {e}")
|
|
time.sleep(3)
|
|
|
|
print(f"clean → {clean!r}; eicar → {infected!r}")
|
|
if clean != "stream: OK":
|
|
sys.exit("FAIL: clean payload was not reported OK")
|
|
if not infected.endswith("FOUND"):
|
|
sys.exit("FAIL: EICAR was not detected")
|
|
print("OK: clamd detects EICAR and passes a clean stream")
|