mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-18 02:42:25 +02:00
v1.87.0.0 feat: add verified CSO audits and replayable repair bundles (#2852)
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
This commit is contained in:
co-authored by
OpenAI Codex
parent
9f81911136
commit
4a3c6a8a3c
@@ -0,0 +1,29 @@
|
||||
import { describe, expect, test } from 'bun:test';
|
||||
import { GROUP_LIMITS, ROLE_LIMITS, type Role } from '../lib/cso/admission';
|
||||
import { CONTAINER_SHM_BYTES, writableAllocation } from '../lib/cso/docker';
|
||||
|
||||
describe('CSO Docker writable-storage policy',()=>{
|
||||
test('every default role includes the explicitly bounded shm allocation',()=>{
|
||||
for(const role of Object.keys(ROLE_LIMITS) as Role[]){
|
||||
const allocation=writableAllocation(role);
|
||||
expect(allocation.shmBytes).toBe(CONTAINER_SHM_BYTES);
|
||||
expect(allocation.totalBytes).toBe(ROLE_LIMITS[role].writableMiB*1024*1024);
|
||||
expect(allocation.temporaryBytes).toBeGreaterThan(0);
|
||||
expect(allocation.workBytes).toBeGreaterThan(0);
|
||||
}
|
||||
});
|
||||
|
||||
test('the Rails PostgreSQL group stays within two GiB including every shm mount',()=>{
|
||||
const roles:Role[]=['anchor','postgres','app','verifier'];
|
||||
const bytes=roles.reduce((sum,role)=>sum+writableAllocation(role).totalBytes,0);
|
||||
expect(bytes).toBe(GROUP_LIMITS.writableMiB*1024*1024);
|
||||
});
|
||||
|
||||
test('dependency acquisition accounts for metadata, archives, and shm together',()=>{
|
||||
const mib=1024*1024,allocation=writableAllocation('app',{
|
||||
temporaryTmpfsBytes:64*mib,workTmpfsBytes:64*mib,metadataTmpfsBytes:1024*mib,archiveTmpfsBytes:384*mib,
|
||||
});
|
||||
expect(allocation.totalBytes).toBe((64+64+1024+384)*mib+CONTAINER_SHM_BYTES);
|
||||
expect(writableAllocation('anchor').totalBytes+allocation.totalBytes).toBeLessThan(GROUP_LIMITS.writableMiB*mib);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user