test: consent-gate E2E suite + functional fs-capability probes

Five hermetic gate-tier E2E cases (tpa-present / absent-linux / broken /
absent-darwin / apple-ban) drive the real contract section through
claude -p with PATH shims for aside and uname; the absent cases filter
any REAL aside binary out of the child PATH and assert absence with
Bun.which before spawning, so dev machines cannot leak into detection.
Registered per-case in E2E_TOUCHFILES/E2E_TIERS with template-level
deps (ship/SKILL.md.tmpl, gen-skill-docs.ts) and added to the evals.yml
matrix with tier: gate. eval:bg:periodic's detach timeout rises to
36000s for the grown periodic shard census (floor-enforced by
test/eval-detach-timeout-floor.test.ts); CLAUDE.md doc updated to match.

test/helpers/fs-caps.ts adds canRevokeWrites/canRevokeReads functional
probes; 13 chmod-based tests swap their uid-0-only guards for the
probes so suites skip honestly on CAP_DAC_OVERRIDE containers (this
sandbox: uid 1000 with full caps) instead of asserting revocations the
kernel ignores. path-validation's symlink test targets /etc/passwd
(exists everywhere; /etc/crontab is absent on Amazon Linux).
This commit is contained in:
Garry Tan
2026-08-28 04:47:50 +00:00
parent ade441afd0
commit 0873fce89a
21 changed files with 375 additions and 19 deletions
+4 -3
View File
@@ -12,6 +12,7 @@
*/
import { describe, test, expect, beforeEach, afterEach, afterAll } from 'bun:test';
import { canRevokeWrites } from './helpers/fs-caps';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
@@ -90,7 +91,7 @@ describe('_receipted_curl', () => {
});
test('fail-closed refusal never hits the network; stderr is problem + cause + fix', async () => {
if (process.platform === 'win32' || process.getuid?.() === 0) return;
if (!canRevokeWrites()) return; // chmod is advisory here (win32, root, DAC-override containers)
fs.mkdirSync(path.join(home, 'security'), { recursive: true, mode: 0o500 });
const result = await runBash(`
set -uo pipefail
@@ -118,7 +119,7 @@ describe('_receipted_curl', () => {
});
test('fail-open warns and proceeds when the receipt cannot be written', async () => {
if (process.platform === 'win32' || process.getuid?.() === 0) return;
if (!canRevokeWrites()) return; // chmod is advisory here (win32, root, DAC-override containers)
fs.mkdirSync(path.join(home, 'security'), { recursive: true, mode: 0o500 });
const result = await runBash(`
set -uo pipefail
@@ -168,7 +169,7 @@ describe('_receipted_git', () => {
});
test('fail-closed git refusal returns 3 without running the command', async () => {
if (process.platform === 'win32' || process.getuid?.() === 0) return;
if (!canRevokeWrites()) return; // chmod is advisory here (win32, root, DAC-override containers)
fs.mkdirSync(path.join(home, 'security'), { recursive: true, mode: 0o500 });
const marker = path.join(os.tmpdir(), `gstack-egress-git-${process.pid}`);
fs.rmSync(marker, { force: true });