mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-27 15:11:47 +02:00
v1.88.1.0 fix: harden credential boundaries and owned state (#2942)
* fix(settings): preserve symlinked settings targets
Resolve the selected target for locking, mutation, backup, and rollback; refuse target changes and preserve private modes. Addresses #2830.
* fix(redact): bind masking to original detected spans
Inspired by #2929's anchored-span diagnosis; independently implemented using normalization offsets. Addresses #2930 and the relocation portion of #2912 without changing detection sensitivity.
* fix(evals): exclude operator credentials from prefix admission
Adapts the credential-suffix screen proposed in #2636, with real launched-child regression coverage and deliberate provider-auth exceptions.
* fix(artifacts): retain custom allowlist rules on reinitialization
Preserve the exact user-owned suffix and publish only a successfully assembled replacement. Independently implements the repair reported in #2907.
* test(cso): verify exact masked reads and unmaskable payload refusal
* fix(cso): preserve exact filesystem identities through lease recovery
Preserve 64-bit device/inode identity and nanosecond race checks. Add native NTFS lifecycle coverage for #2927; retain ambiguous legacy-state refusal without claiming Windows PID-reuse recovery is resolved.
* fix(redact): bind pre-push scans to destination and preserve seam context
Uses #2935 (bd07318) as source evidence for push-target range and slice-overlap defects. Independently implemented; no cherry-pick or release metadata adoption.
* test(ci): gate native agent ownership and settings links on macOS
* fix(browse): bind agent lifetimes and cleanup to owned generations
Uses #2931 by Chris Hutton / Claude Fable 5.1 as attributed design input; independently implemented without broad sweeps or copied code. Keep uncertain children and locks rather than deleting foreign state.
* test(ci): include concurrent shutdown controls in the native macOS gate
* v1.88.1.0 fix: harden credential boundaries and owned state
* fix(redact): preserve target provenance and scan boundary semantics
* test(artifacts): read managed rules from atomic allowlist assembly
* fix: preserve native exit observations and fixture prerequisites
* fix: preserve UTF-16 offsets through redaction normalization
This commit is contained in:
@@ -573,20 +573,10 @@ describe("redactFindingSpans — machine-egress masking (#1947)", () => {
|
||||
expect(out).toBe("first <REDACTED-aws.access_key> then <REDACTED-github.pat> end");
|
||||
});
|
||||
|
||||
test("fails closed (null) when a span cannot be relocated — never raw passthrough", () => {
|
||||
// env.kv's span (the value) starts well past the regex match start (the
|
||||
// var name), so locateSpan's rewind-2 re-exec misses it. The contract is
|
||||
// null → caller drops the whole payload. The one thing that must never
|
||||
// happen is the secret surviving in the output.
|
||||
test("masks an anchored env.kv value rather than withholding the whole payload", () => {
|
||||
const secret = "8Fk2pQ9vXz4wL7mN3rT6yB1cD5eG0hJq";
|
||||
const out = redactFindingSpans(`API_KEY=${secret}`, { repoVisibility: "private" });
|
||||
if (out !== null) {
|
||||
// If locateSpan ever learns to find context-prefixed spans, masking
|
||||
// must actually mask.
|
||||
expect(out).not.toContain(secret);
|
||||
} else {
|
||||
expect(out).toBeNull();
|
||||
}
|
||||
expect(out).toBe("API_KEY=<REDACTED-env.kv>");
|
||||
});
|
||||
|
||||
test("line/col at boundaries: line start, after blank lines, first char, last unterminated line", () => {
|
||||
@@ -603,7 +593,7 @@ describe("redactFindingSpans — machine-egress masking (#1947)", () => {
|
||||
expect(redactFindingSpans(`a\nb\n${token} x`, { repoVisibility: "private" })).toBe("a\nb\n<REDACTED-github.pat> x");
|
||||
});
|
||||
|
||||
test("multiline input redacts a finding past the first line (locateSpan line/col path)", () => {
|
||||
test("multiline input redacts a finding past the first line (original span map)", () => {
|
||||
const token = "ghp_" + "1234567890abcdefghijklmnopqrstuvwxyz";
|
||||
const out = redactFindingSpans(`line one\nline two has ${token}\nline three`, {
|
||||
repoVisibility: "private",
|
||||
|
||||
Reference in New Issue
Block a user