v1.88.1.0 fix: harden credential boundaries and owned state (#2942)

* fix(settings): preserve symlinked settings targets

Resolve the selected target for locking, mutation, backup, and rollback; refuse target changes and preserve private modes. Addresses #2830.

* fix(redact): bind masking to original detected spans

Inspired by #2929's anchored-span diagnosis; independently implemented using normalization offsets. Addresses #2930 and the relocation portion of #2912 without changing detection sensitivity.

* fix(evals): exclude operator credentials from prefix admission

Adapts the credential-suffix screen proposed in #2636, with real launched-child regression coverage and deliberate provider-auth exceptions.

* fix(artifacts): retain custom allowlist rules on reinitialization

Preserve the exact user-owned suffix and publish only a successfully assembled replacement. Independently implements the repair reported in #2907.

* test(cso): verify exact masked reads and unmaskable payload refusal

* fix(cso): preserve exact filesystem identities through lease recovery

Preserve 64-bit device/inode identity and nanosecond race checks. Add native NTFS lifecycle coverage for #2927; retain ambiguous legacy-state refusal without claiming Windows PID-reuse recovery is resolved.

* fix(redact): bind pre-push scans to destination and preserve seam context

Uses #2935 (bd07318) as source evidence for push-target range and slice-overlap defects. Independently implemented; no cherry-pick or release metadata adoption.

* test(ci): gate native agent ownership and settings links on macOS

* fix(browse): bind agent lifetimes and cleanup to owned generations

Uses #2931 by Chris Hutton / Claude Fable 5.1 as attributed design input; independently implemented without broad sweeps or copied code. Keep uncertain children and locks rather than deleting foreign state.

* test(ci): include concurrent shutdown controls in the native macOS gate

* v1.88.1.0 fix: harden credential boundaries and owned state

* fix(redact): preserve target provenance and scan boundary semantics

* test(artifacts): read managed rules from atomic allowlist assembly

* fix: preserve native exit observations and fixture prerequisites

* fix: preserve UTF-16 offsets through redaction normalization
This commit is contained in:
Garry Tan
2026-09-23 08:54:53 -04:00
committed by GitHub
parent 636175d349
commit b9706f3635
42 changed files with 2719 additions and 339 deletions
+21
View File
@@ -336,6 +336,27 @@ describe('CSO runtime staging gates', () => {
expect(gate['continue-on-error']).not.toBe(true);
});
test('native macOS ownership and settings regressions are required by the free gate', () => {
const workflow = Bun.YAML.parse(readFileSync(join(ROOT, '.github/workflows/free-tests.yml'), 'utf8')) as any;
const job = workflow.jobs['cso-macos-launcher'];
const gate = job.steps.find((step: any) => step.name === 'Exercise native agent ownership and linked settings');
expect(job['runs-on']).toBe('macos-latest');
expect(gate.env.TMPDIR).toBe('/tmp');
expect(gate.run).toContain('test -f "$file"');
expect(gate.run).toContain('bun test "${files[@]}"');
for (const file of [
'browse/test/terminal-agent-lifecycle.test.ts',
'browse/test/terminal-agent-native-observation.test.ts',
'browse/test/terminal-agent-watchdog.test.ts',
'browse/test/server-embedder-terminal-port.test.ts',
'browse/test/server-factory.test.ts',
'test/gstack-settings-hook-symlink.test.ts',
'test/gstack-settings-hook-schema-aware.test.ts',
]) expect(gate.run).toContain(file);
expect(gate['continue-on-error']).not.toBe(true);
expect(workflow.jobs['free-tests'].needs).toContain('cso-macos-launcher');
});
test('publication requires manual protected-main review, signed evidence, and native containment checks', () => {
const raw = readFileSync(join(ROOT, '.github/workflows/cso-runtime-images.yml'), 'utf8');
const workflow = Bun.YAML.parse(raw) as any;