v1.87.0.0 feat: add verified CSO audits and replayable repair bundles (#2852)

* feat(cso): add verified audits and replayable repair bundles

* fix(cso): harden qualification and setup boundaries

* fix(cso): assemble security canaries at runtime

* fix(cso): bound release proof and maintenance work

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): require complete evaluation reports

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): replay expired snapshots from supplied source

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): synchronize DNS cancellation assertion

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore(ship): exempt repository owner from liveness proof

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): make recheck retention overlap deterministic

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: bump version and changelog (v1.85.0.0)

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass native release gates

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.86.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): resolve rechecks by finding

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.87.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass macOS and Windows release gates

Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures.

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): harden native verification gates

* fix(cso): refine Windows native diagnostics

* test(cso): isolate Windows Git startup failure

* test(cso): stabilize Windows native diagnostics

* fix(cso): support hardened Git on Windows

* fix(cso): close final verification gaps

* test(cso): bound cold Docker fixture setup

* fix(cso): restore cross-platform free-suite gates

---------

Co-authored-by: OpenAI Codex <noreply@openai.com>
This commit is contained in:
Garry Tan
2026-09-14 15:14:58 -07:00
committed by GitHub
co-authored by OpenAI Codex
parent 9f81911136
commit 4a3c6a8a3c
160 changed files with 24697 additions and 2288 deletions
+22
View File
@@ -6,6 +6,14 @@ cd "$ROOT"
BUN_CMD="${BUN_CMD:-bun}"
BUN_CMD_WAS_COPIED=0
BUILD_STAMP="$ROOT/browse/dist/.build-complete"
BUILD_STAMP_TMP="$BUILD_STAMP.tmp.$$"
# Setup trusts this stamp as proof that the selected multi-binary build completed.
# Ordinary/direct builds include CSO and remain strict. Setup may explicitly omit
# CSO after its host capability probe, while still publishing the general build.
# Invalidate before touching output so an interrupted build cannot hide staleness.
rm -f "$BUILD_STAMP" "$BUILD_STAMP_TMP"
case "$(uname -s)" in
MINGW*|MSYS*|CYGWIN*|Windows_NT)
@@ -29,6 +37,15 @@ esac
"$BUN_CMD" build --compile design/src/cli.ts --outfile design/dist/design
"$BUN_CMD" build --compile make-pdf/src/cli.ts --outfile make-pdf/dist/pdf
"$BUN_CMD" build --compile bin/gstack-global-discover.ts --outfile bin/gstack-global-discover
if [ "${GSTACK_SETUP_RUNNING:-0}" = "1" ] && [ "${GSTACK_SETUP_SKIP_CSO_BUILD:-0}" = "1" ]; then
# Setup removes these before invoking us too. Repeat here so the setup-private
# escape hatch can never publish a completion stamp beside stale trusted code.
rm -f bin/gstack-cso-launcher bin/gstack-cso-launcher.exe \
bin/gstack-cso-core bin/gstack-cso-core.exe bin/gstack-cso-watchdog \
bin/.gstack-cso-generation bin/.gstack-cso-generation.lock
else
BUN_CMD="$BUN_CMD" bash scripts/build-cso.sh
fi
bash browse/scripts/build-node-server.sh
bash scripts/write-version-files.sh browse/dist/.version design/dist/.version make-pdf/dist/.version
chmod +x browse/dist/browse browse/dist/find-browse design/dist/design make-pdf/dist/pdf bin/gstack-global-discover
@@ -36,3 +53,8 @@ rm -f .*.bun-build
if [ "$BUN_CMD_WAS_COPIED" -eq 1 ]; then
rm -rf "$ROOT/.tmp-bun-bin"
fi
# Publish last and on the same filesystem. A failure or interruption before the
# rename leaves the canonical stamp absent, which makes setup rebuild everything.
printf 'complete\n' > "$BUILD_STAMP_TMP"
mv -f "$BUILD_STAMP_TMP" "$BUILD_STAMP"