Files
Garry TanandOpenAI Codex 4a3c6a8a3c v1.87.0.0 feat: add verified CSO audits and replayable repair bundles (#2852)
* feat(cso): add verified audits and replayable repair bundles

* fix(cso): harden qualification and setup boundaries

* fix(cso): assemble security canaries at runtime

* fix(cso): bound release proof and maintenance work

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): require complete evaluation reports

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): replay expired snapshots from supplied source

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): synchronize DNS cancellation assertion

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore(ship): exempt repository owner from liveness proof

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): make recheck retention overlap deterministic

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: bump version and changelog (v1.85.0.0)

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass native release gates

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.86.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): resolve rechecks by finding

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.87.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass macOS and Windows release gates

Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures.

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): harden native verification gates

* fix(cso): refine Windows native diagnostics

* test(cso): isolate Windows Git startup failure

* test(cso): stabilize Windows native diagnostics

* fix(cso): support hardened Git on Windows

* fix(cso): close final verification gaps

* test(cso): bound cold Docker fixture setup

* fix(cso): restore cross-platform free-suite gates

---------

Co-authored-by: OpenAI Codex <noreply@openai.com>
2026-09-14 15:14:58 -07:00

56 lines
1.7 KiB
Bash

#!/bin/sh
set -eu
umask 077
test "$PWD" = /work
test "$#" -eq 1
policy="$1"
case "$policy" in /policy/*) ;; *) exit 64 ;; esac
test -f "$policy"
count=0
while IFS= read -r database || test -n "$database"; do
case "$database" in cso_[A-Za-z_]*) ;; *) exit 64 ;; esac
case "$database" in *[!A-Za-z0-9_]*) exit 64 ;; esac
test "${#database}" -le 52
count=$((count + 1)); test "$count" -le 64
done < "$policy"
test "$count" -gt 0
data=/work/postgresql-data
socket=/work/postgresql-socket
password=/work/postgresql-password
mkdir -m 700 "$socket"
printf '%s\n' 'cso-disposable-test' > "$password"
/opt/cso/bin/initdb -D "$data" --username=cso --pwfile="$password" --auth-local=scram-sha-256 --auth-host=scram-sha-256 >/dev/null
rm -f "$password"
cat >> "$data/postgresql.conf" <<'EOF'
listen_addresses = '127.0.0.1'
port = 5432
unix_socket_directories = '/work/postgresql-socket'
ssl = off
max_connections = 32
password_encryption = 'scram-sha-256'
fsync = off
synchronous_commit = off
full_page_writes = off
EOF
cleanup() {
if test -n "${postgres_pid:-}" && kill -0 "$postgres_pid" 2>/dev/null; then
kill -TERM "$postgres_pid" 2>/dev/null || true
wait "$postgres_pid" 2>/dev/null || true
fi
}
trap cleanup EXIT INT TERM
/opt/cso/bin/postgres -D "$data" >/dev/null 2>&1 &
postgres_pid=$!
export PGPASSWORD=cso-disposable-test
attempt=0
until /opt/cso/bin/pg_isready -h 127.0.0.1 -p 5432 -U cso -d postgres >/dev/null 2>&1; do
attempt=$((attempt + 1)); test "$attempt" -lt 100; sleep 0.05
done
while IFS= read -r database || test -n "$database"; do
/opt/cso/bin/createdb -h 127.0.0.1 -p 5432 -U cso "$database" >/dev/null
done < "$policy"
printf 'ready\n' > /work/postgresql.ready
wait "$postgres_pid"