-
Notifications
You must be signed in to change notification settings - Fork 5
77 lines (66 loc) · 3.14 KB
/
Copy pathverify.yml
File metadata and controls
77 lines (66 loc) · 3.14 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
name: Verify
on:
push:
branches:
- '**'
jobs:
roundtrip:
name: Encryption roundtrip
runs-on: windows-latest
timeout-minutes: 5
steps:
- name: Checkout repository
uses: actions/checkout@v7.0.1
- name: Verify encryption roundtrip
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
trap {
Write-Host "::error::❌ Verification failed: $($_.Exception.Message)"
exit 1
}
$sandbox = Join-Path $env:RUNNER_TEMP 'ramonware-ci'
$probe = Join-Path $sandbox 'probe.txt'
$aes = "$probe.aes"
$log = 'C:\Original.txt'
$plain = [Text.Encoding]::UTF8.GetBytes('ramonware-integrity')
$pass = [guid]::NewGuid().ToString('N')
if (Test-Path $sandbox) { Remove-Item $sandbox -Recurse -Force }
New-Item -ItemType Directory -Path $sandbox -Force | Out-Null
[IO.File]::WriteAllBytes($probe, $plain)
if (Test-Path $log) { Remove-Item $log -Force }
Write-Host '✅ Test file and random password created'
function Replace-Exact($text, $old, $new, $expected = 1) {
$actual = [regex]::Matches($text, [regex]::Escape($old)).Count
if ($actual -ne $expected) {
throw "Expected $expected occurrence(s) of '$old', found $actual"
}
$text.Replace($old, $new)
}
$sourcePath = Join-Path $env:GITHUB_WORKSPACE 'code\Ramonware.bat'
$batPath = Join-Path $sandbox 'RamonWare-ci.bat'
$utf8 = New-Object Text.UTF8Encoding $false
$bat = [IO.File]::ReadAllText($sourcePath)
$bat = Replace-Exact $bat 'set ROOT_PATH=%homedrive%\' "set pass=$pass`r`nset ROOT_PATH=$sandbox"
$bat = Replace-Exact $bat '*.labasset' '*.txt'
$bat = Replace-Exact $bat 'REM powershell -NoProfile' 'powershell -NoProfile' 2
$bat = Replace-Exact $bat 'REM del "%%X"' 'del "%%X"'
$bat = Replace-Exact $bat 'cls' 'exit /b'
[IO.File]::WriteAllText($batPath, $bat, $utf8)
Write-Host '✅ Temporary batch prepared in the sandbox'
$process = Start-Process -FilePath $env:ComSpec -ArgumentList '/d', '/c', "`"$batPath`"" -Wait -PassThru
if ($process.ExitCode -ne 0) { throw "RamonWare-ci.bat exited with $($process.ExitCode)" }
Write-Host '✅ Batch encryption and decryption completed'
if (-not (Test-Path $log) -or -not (Select-String -Path $log -Pattern 'probe.txt' -SimpleMatch -Quiet)) {
if (Test-Path $log) { Get-Content $log }
throw "Original.txt does not contain probe.txt"
}
Write-Host '✅ Test file found in Original.txt'
if (-not (Test-Path $aes)) { throw "missing $aes" }
Write-Host '✅ Encrypted file created'
$restored = [IO.File]::ReadAllBytes($probe)
if ([Convert]::ToBase64String($plain) -ne [Convert]::ToBase64String($restored)) {
throw 'encrypt roundtrip failed'
}
Write-Host '✅ Decrypted file matches the original'
Write-Host '🎉 RamonWare encryption roundtrip passed'