mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-28 07:32:14 +02:00
v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)
* fix(browse): prepare reliable cookie import wave for validation * ci: sequence quality and behavior for validation branch * fix(browse): isolate Windows qualification and preserve native diagnostics * test(browse): cover cookie workflow quality and isolate Windows user paths * test(browse): trace native member startup and initialize fresh folders * fix(browse): keep Windows member stdin alive through EOF * fix(browse): latch native timeouts and compare contained Edge startup * test(browse): verify native version metadata and actual Windows argv * test(browse): qualify Dia import on isolated macOS CI * fix(browse): require picker origin for session mutations * fix(browse): bound credential reads through stream completion * test(browse): inspect owned Windows process arguments natively * test(evals): preserve passing coverage during cookie repair reruns * test(browse): isolate Dia qualification in a fresh macOS account * test(browse): pass bounded integer timeouts to native Mac probes * test(browse): distinguish Windows profile initialization from containment * test(browse): await descendant pipe readiness before parent exit * test(browse): initialize and restore isolated macOS Keychain state * test(browse): initialize Windows fixture folders before qualification * test(ci): pin the same Node runtime across Windows checks * test(browse): distinguish native macOS browser preflight stages * test(browse): isolate Windows descendant console lifetime * test(browse): preserve native receipts and identify fixture lock holders * test(browse): prepare dependency resolution before native Mac worker startup * test(ci): include lock and close checks in native diagnostics * test(browse): preserve native owner probe stages and subprocess deadlines * fix(browse): classify Chromium profile-in-use exit precisely * test(browse): retain Mac qualification evidence through cleanup failures * test(browse): bound Mac fixture paths and retire its owned user domain * test(browse): accept vanished fixture entries without weakening cleanup * test(browse): identify probe-created macOS user domains safely * test(browse): observe Mac user domains without targeting them first * test(browse): use passive fresh-user ownership throughout Mac qualification * test(browse): distinguish profile and registered-home Keychain lookups * test(browse): qualify Dia under one registered account home * test(browse): identify Dia startup and owned process-group failures * test(browse): classify bounded Dia startup diagnostics without leaking output * fix(test): preserve native Mac sandboxing and reap owned browser children * fix(browse): preserve Chromium sandboxing for native profile imports * test(browse): inspect signed Mach-O architecture without launching Xcode tools * test(browse): sample pending Dia startup and reap on all cleanup paths * test(browse): compare protected Dia launches in fresh Bun and Node accounts * test(browse): inspect isolated Mac GUI readiness without browser access * v1.90.0.0 fix: bind cookie picker actions to their document * test: validate cookie guards and fit nested launch fixtures * ci: configure the bundled Chromium sandbox helper * fix(browse): classify Playwright authentication timeouts * test: retain bounded Windows lifecycle diagnostics * test(cso): reuse bounded NTFS precision candidates * test(review): handle explicit preservation choices safely * test(browse): remove owned fixture directories with explicit primitives * test(review): distinguish descriptive reuse from edit commitments * test: admit only the approved unscored cookie workflow refusal * test: keep the Office Hours judge mock export-complete * fix: keep dependency-free CI planners independent of the model SDK * test: observe the exact holder after a native fixture unlink failure * fix: start seeded PTY observations at owned readiness * test: acquire identity-bound Windows deletion admission before profile resets * test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
@@ -0,0 +1,77 @@
|
||||
import { afterEach, expect, test } from 'bun:test';
|
||||
import { spawnSync } from 'node:child_process';
|
||||
import { existsSync, mkdirSync, mkdtempSync, readFileSync, rmSync, symlinkSync, writeFileSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import path from 'node:path';
|
||||
|
||||
const root = path.resolve(import.meta.dir, '..');
|
||||
const workflow = Bun.YAML.parse(readFileSync(path.join(root, '.github/workflows/free-tests.yml'), 'utf8')) as any;
|
||||
const steps = workflow.jobs['free-suite'].steps;
|
||||
const index = steps.findIndex((step: any) => step.name === 'Configure the bundled Chromium sandbox helper');
|
||||
const command = steps[index]?.run;
|
||||
const fixtures: string[] = [];
|
||||
|
||||
afterEach(() => {
|
||||
for (const fixture of fixtures.splice(0)) rmSync(fixture, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
function run(options: { outside?: boolean; link?: boolean; mode?: string; corrupt?: boolean } = {}) {
|
||||
const fixture = mkdtempSync(path.join(tmpdir(), 'chromium-ci-'));
|
||||
fixtures.push(fixture);
|
||||
const bin = path.join(fixture, 'bin');
|
||||
const home = path.join(fixture, 'home');
|
||||
const directory = options.outside ? path.join(fixture, 'outside') : path.join(home, '.cache/ms-playwright/chromium-1234/chrome-linux64');
|
||||
mkdirSync(bin, { recursive: true });
|
||||
mkdirSync(directory, { recursive: true });
|
||||
const executable = path.join(directory, 'chrome');
|
||||
const helper = path.join(directory, 'chrome_sandbox');
|
||||
const installed = path.join(directory, 'chrome-sandbox');
|
||||
const receipt = path.join(fixture, 'install.json');
|
||||
writeFileSync(executable, 'synthetic browser');
|
||||
if (options.link) symlinkSync(executable, helper);
|
||||
else writeFileSync(helper, 'synthetic matching helper');
|
||||
writeFileSync(path.join(bin, 'bun'), '#!/bin/sh\nprintf "%s\\n" "$FIXTURE_CHROME"\n', { mode: 0o755 });
|
||||
writeFileSync(path.join(bin, 'stat'), '#!/bin/sh\nprintf "%s\\n" "$FIXTURE_STAT"\n', { mode: 0o755 });
|
||||
writeFileSync(path.join(bin, 'sudo'), `#!/usr/bin/env node
|
||||
const fs = require('node:fs');
|
||||
const args = process.argv.slice(2);
|
||||
fs.writeFileSync(process.env.FIXTURE_RECEIPT, JSON.stringify(args));
|
||||
if (JSON.stringify(args.slice(0, 8)) !== JSON.stringify(['install', '-T', '-o', 'root', '-g', 'root', '-m', '4755']) || args.length !== 10) process.exit(2);
|
||||
fs.copyFileSync(args[8], args[9]);
|
||||
if (process.env.FIXTURE_CORRUPT === '1') fs.appendFileSync(args[9], 'changed');
|
||||
`, { mode: 0o755 });
|
||||
const result = spawnSync('/bin/bash', ['-c', command], {
|
||||
cwd: root, encoding: 'utf8', timeout: 10_000,
|
||||
env: { ...process.env, HOME: home, PATH: bin + path.delimiter + process.env.PATH,
|
||||
FIXTURE_CHROME: executable, FIXTURE_STAT: options.mode ?? '0:4755',
|
||||
FIXTURE_RECEIPT: receipt, FIXTURE_CORRUPT: options.corrupt ? '1' : '0' },
|
||||
});
|
||||
return { result, helper, installed, calls: existsSync(receipt) ? JSON.parse(readFileSync(receipt, 'utf8')) : null };
|
||||
}
|
||||
|
||||
test('the actual CI sandbox setup uses the resolved bundled helper before tests without disabling protections', () => {
|
||||
expect(typeof command).toBe('string');
|
||||
expect(index).toBeGreaterThan(steps.findIndex((step: any) => step.name === 'Install Playwright Chromium'));
|
||||
expect(index).toBeLessThan(steps.findIndex((step: any) => step.name === 'Run free suite'));
|
||||
expect(command).not.toMatch(/--no-sandbox|chromiumSandbox:\s*false|sysctl|apparmor_restrict/);
|
||||
const { result, helper, installed, calls } = run();
|
||||
expect(result.status).toBe(0);
|
||||
expect(calls).toEqual(['install', '-T', '-o', 'root', '-g', 'root', '-m', '4755', helper, installed]);
|
||||
expect(readFileSync(installed)).toEqual(readFileSync(helper));
|
||||
});
|
||||
|
||||
test('unexpected paths and linked helpers are refused before privileged installation', () => {
|
||||
for (const options of [{ outside: true }, { link: true }]) {
|
||||
const { result, calls } = run(options);
|
||||
expect(result.status).not.toBe(0);
|
||||
expect(calls).toBeNull();
|
||||
}
|
||||
});
|
||||
|
||||
test('the actual CI setup requires root ownership, setuid mode, and unchanged helper bytes', () => {
|
||||
for (const options of [{ mode: '1000:4755' }, { mode: '0:755' }, { corrupt: true }]) {
|
||||
const { result, calls } = run(options);
|
||||
expect(result.status).not.toBe(0);
|
||||
expect(calls).not.toBeNull();
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user