Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
7d16f3e
feat(agent): add policy audit events
CBenoit Sep 8, 2026
590b52e
build(dgw,agent): embed policy event catalogs
CBenoit Sep 8, 2026
c90ca09
test(dgw,agent): enforce event catalog parity
CBenoit Sep 8, 2026
35987bc
fix(dgw,agent): harden policy audit validation
CBenoit Sep 9, 2026
03e1d31
fix(agent): audit legacy policy rejection
CBenoit Sep 15, 2026
86434e6
fix(dgw,agent): compile localized event messages
CBenoit Sep 15, 2026
06625d5
fix(dgw,agent,agent-installer): retain canonical audits
CBenoit Sep 17, 2026
a7869c7
fix(agent): sanitize audit text controls
CBenoit Sep 18, 2026
f0e6711
refactor(agent): isolate policy audit event codes
CBenoit Sep 18, 2026
0e3ff3b
test(agent): isolate audit recorders
CBenoit Sep 18, 2026
2e3becf
test(agent): scope audit fixtures locally
CBenoit Sep 18, 2026
e6349c4
refactor(agent): require policy write audits
CBenoit Sep 18, 2026
3e25250
refactor(agent): adopt shared warning contract
CBenoit Sep 19, 2026
63be294
test(dgw,agent): check event catalogs from the testsuite
CBenoit Sep 29, 2026
2241298
test(agent-installer): document the Event Log source test
CBenoit Sep 29, 2026
ff404e6
refactor(dgw,agent): make the event code tables independent
CBenoit Sep 29, 2026
abaf253
docs(agent): drop the cross-product reference from the event table
CBenoit Sep 29, 2026
fed277e
docs(agent): name the families in the 6000 event code block
CBenoit Sep 29, 2026
00ef849
docs(agent): split the 6000 event block per module
CBenoit Sep 29, 2026
18ba064
docs(agent): state the event table contract without the history note
CBenoit Sep 29, 2026
c35633d
refactor(agent): give each 6000-family module its own hundred
CBenoit Sep 29, 2026
ca50d00
test(sysevent): tie each catalog message to the code it declares
CBenoit Sep 29, 2026
4b855be
fix(agent): stop auditing post-publication failures as external changes
CBenoit Sep 29, 2026
54953f9
build(deps): relax the now-policy-api version requirement
CBenoit Sep 29, 2026
3b87f50
refactor(dgw,agent): compare the profile against `release` when gatin…
CBenoit Sep 29, 2026
13ae19b
fix(agent): drain the policy audit queue when the broker shuts down
CBenoit Sep 29, 2026
2770d92
test(sysevent): check the Gateway builders against their catalog inse…
CBenoit Sep 29, 2026
9aa4ebb
fix(agent): wait for the connections still serving a request before d…
CBenoit Sep 29, 2026
248ee67
fix(agent-installer): keep the Event Log source key on uninstall
CBenoit Sep 29, 2026
ce7e2b5
fix(agent): reserve Event Log capacity for the policy audit outcomes
CBenoit Sep 29, 2026
695fddc
build(deps): restore the master lockfile resolution for the windows c…
CBenoit Sep 29, 2026
6fe4c89
fix(agent): preserve the policy audit order and audit readiness reloads
CBenoit Sep 29, 2026
2d890ee
fix(agent): record a policy denial as an admission event
CBenoit Sep 29, 2026
1bdb44d
fix(agent): audit an external policy replacement after publication
CBenoit Sep 29, 2026
5436ba4
test(agent-installer): correct the Event Log source registration rati…
CBenoit Sep 29, 2026
fd5e6ca
fix(agent): drain the accepted pipe connections before an accept loop…
CBenoit Sep 29, 2026
690dad9
fix(agent): bound the pipe shutdown so the audit queue is always drained
CBenoit Sep 29, 2026
268554c
fix(agent): keep the audit queue open for a connection that can still…
CBenoit Sep 29, 2026
3ec0886
fix(agent): bound the audit worker shutdown
CBenoit Sep 29, 2026
affb04b
docs(agent): label the user session block by its full hundred
CBenoit Sep 30, 2026
dbc4ae2
build(deps): relax the now-policy-server-template requirement
CBenoit Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@
*.scss text eol=lf
*.html text eol=lf
*.slog text eol=lf
*.mc text eol=lf

devolutions-gateway/openapi/doc/index.adoc linguist-generated merge=binary
devolutions-gateway/openapi/dotnet-client/src/** linguist-generated merge=binary
Expand Down
79 changes: 71 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -354,8 +354,6 @@ jobs:
$VSINSTALLDIR = $(vswhere.exe -latest -requires Microsoft.VisualStudio.Component.VC.Llvm.Clang -property installationPath)
Write-Output "LIBCLANG_PATH=$VSINSTALLDIR\VC\Tools\Llvm\x64\bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append

# Install Visual Studio Developer PowerShell Module for cmdlets such as Enter-VsDevShell
Install-Module VsDevShell -Force
shell: pwsh

- name: Configure Windows (arm) runner
Expand Down Expand Up @@ -735,9 +733,6 @@ jobs:
# NASM is required by aws-lc-rs (used as rustls crypto backend)
choco install nasm

# Install Visual Studio Developer PowerShell Module for cmdlets such as Enter-VsDevShell
Install-Module VsDevShell -Force

# We need to add the NASM binary folder to the PATH manually.
Write-Output "$Env:ProgramFiles\NASM" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append
shell: pwsh
Expand All @@ -746,9 +741,31 @@ jobs:
id: find_mc
if: ${{ matrix.os == 'windows' }}
run: |
Enter-VsDevShell
$path = (Get-Command -Type Application mc).Source | Split-Path -Parent
$sdkRoots = @(
$Env:WindowsSdkDir
(Get-ItemPropertyValue -Path "HKLM:\SOFTWARE\Microsoft\Windows Kits\Installed Roots" -Name KitsRoot10 -ErrorAction SilentlyContinue)
"${Env:ProgramFiles(x86)}\Windows Kits\10"
) | Where-Object { $_ } | Select-Object -Unique
$candidates = @()
if ($Env:WindowsSdkVerBinPath) {
$candidates += Join-Path $Env:WindowsSdkVerBinPath "mc.exe"
$candidates += Join-Path $Env:WindowsSdkVerBinPath "x64\mc.exe"
}
foreach ($root in $sdkRoots) {
$bin = Join-Path $root "bin"
$candidates += Join-Path $bin "x64\mc.exe"
$candidates += Get-ChildItem -LiteralPath $bin -Directory -ErrorAction SilentlyContinue |
Where-Object Name -Match '^\d+\.\d+\.\d+\.\d+$' |
Sort-Object { [version]$_.Name } -Descending |
ForEach-Object { Join-Path $_.FullName "x64\mc.exe" }
}
$mc = $candidates | Where-Object { Test-Path -LiteralPath $_ -PathType Leaf } | Select-Object -First 1
if (-Not $mc) {
throw "mc.exe was not found in the installed Windows SDK"
}
$path = Split-Path -Parent $mc
Write-Output "windows_sdk_ver_bin_path=$path" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -Encoding utf8
Write-Output $path | Out-File -FilePath $env:GITHUB_PATH -Append -Encoding utf8
shell: pwsh

- name: Build
Expand Down Expand Up @@ -1014,6 +1031,37 @@ jobs:
if: ${{ matrix.os == 'windows' }}
uses: microsoft/setup-msbuild@v3

- name: Find mc.exe
id: find_mc
if: ${{ matrix.os == 'windows' }}
run: |
$sdkRoots = @(
$Env:WindowsSdkDir
(Get-ItemPropertyValue -Path "HKLM:\SOFTWARE\Microsoft\Windows Kits\Installed Roots" -Name KitsRoot10 -ErrorAction SilentlyContinue)
"${Env:ProgramFiles(x86)}\Windows Kits\10"
) | Where-Object { $_ } | Select-Object -Unique
$candidates = @()
if ($Env:WindowsSdkVerBinPath) {
$candidates += Join-Path $Env:WindowsSdkVerBinPath "mc.exe"
$candidates += Join-Path $Env:WindowsSdkVerBinPath "x64\mc.exe"
}
foreach ($root in $sdkRoots) {
$bin = Join-Path $root "bin"
$candidates += Join-Path $bin "x64\mc.exe"
$candidates += Get-ChildItem -LiteralPath $bin -Directory -ErrorAction SilentlyContinue |
Where-Object Name -Match '^\d+\.\d+\.\d+\.\d+$' |
Sort-Object { [version]$_.Name } -Descending |
ForEach-Object { Join-Path $_.FullName "x64\mc.exe" }
}
$mc = $candidates | Where-Object { Test-Path -LiteralPath $_ -PathType Leaf } | Select-Object -First 1
if (-Not $mc) {
throw "mc.exe was not found in the installed Windows SDK"
}
$path = Split-Path -Parent $mc
Write-Output "windows_sdk_ver_bin_path=$path" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -Encoding utf8
Write-Output $path | Out-File -FilePath $env:GITHUB_PATH -Append -Encoding utf8
shell: pwsh

- name: Build
run: |
if ($Env:RUNNER_OS -eq "Windows") {
Expand All @@ -1024,6 +1072,7 @@ jobs:
$Env:DAGENT_TUN2SOCKS_EXE = "${{ steps.tun2socks.outputs.tun2socks-executable-path }}"
$Env:DAGENT_WINTUN_DLL = "${{ steps.tun2socks.outputs.wintun-library-path }}"
$Env:DAGENT_MULTI_PWSH_EXECUTABLE = "${{ steps.multi-pwsh.outputs.executable-path }}"
$Env:WindowsSdkVerBinPath = '${{ steps.find_mc.outputs.windows_sdk_ver_bin_path }}'
}

if ($Env:RUNNER_OS -eq "Linux") {
Expand Down Expand Up @@ -1161,6 +1210,20 @@ jobs:
run: dotnet test utils/dotnet/GatewayUtils.sln
shell: pwsh

agent-installer-event-log-tests:
name: Agent installer Event Log lifecycle tests
runs-on: windows-2022
needs: [preflight]

steps:
- name: Checkout ${{ github.repository }}
uses: actions/checkout@v6
with:
ref: ${{ needs.preflight.outputs.ref }}

- name: Tests
run: dotnet test package/AgentWindowsManaged.Tests/DevolutionsAgent.Installer.Tests.csproj
shell: pwsh

winapi-sanitizer-tests:
name: Windows API sanitizer tests
Expand Down Expand Up @@ -1405,7 +1468,7 @@ jobs:
success:
name: Success
if: ${{ always() }}
needs: [tests, agent-tunnel-e2e, agent-policy-e2e, lints, check-dependencies, jetsocat-lipo, devolutions-gateway-powershell, gateway-service-account-tests, devolutions-gateway, devolutions-gateway-merge, devolutions-pedm-desktop, devolutions-agent, devolutions-agent-merge, devolutions-pedm-client, dotnet-utils-tests, winapi-sanitizer-tests, winapi-miri, pedm-simulator, secure-memory-verifier]
needs: [tests, agent-tunnel-e2e, agent-policy-e2e, lints, check-dependencies, jetsocat-lipo, devolutions-gateway-powershell, gateway-service-account-tests, devolutions-gateway, devolutions-gateway-merge, devolutions-pedm-desktop, devolutions-agent, devolutions-agent-merge, devolutions-pedm-client, dotnet-utils-tests, agent-installer-event-log-tests, winapi-sanitizer-tests, winapi-miri, pedm-simulator, secure-memory-verifier]
runs-on: ubuntu-latest

steps:
Expand Down
20 changes: 16 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 0 additions & 2 deletions crates/agent-policy-tester/src/windows.rs
Original file line number Diff line number Diff line change
Expand Up @@ -307,7 +307,6 @@ async fn assert_redirected_policy_rejected(
"ExpectedStoreToken": management["Management"]["StoreToken"],
"Operation": "Repair",
"ConflictHandling": "Reject",
"WarningsAcknowledged": false,
"Draft": full_policy(),
"ValidationReceipt": "invalid"
});
Expand Down Expand Up @@ -393,7 +392,6 @@ async fn replace_policy(
"ExpectedStoreToken": expected_store_token,
"Operation": operation,
"ConflictHandling": "Reject",
"WarningsAcknowledged": true,
"Draft": validation["CanonicalDraft"],
"ValidationReceipt": validation["ValidationReceipt"]
});
Expand Down
13 changes: 13 additions & 0 deletions crates/agent-sysevent-codes/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
[package]
name = "agent-sysevent-codes"
version = "0.0.0"
edition = "2024"
authors = ["Devolutions Inc. <infos@devolutions.net>"]
license = "MIT OR Apache-2.0"
publish = false

[lints]
workspace = true

[dependencies]
sysevent.path = "../sysevent"
Loading
Loading