Files
gstack/test/cso-ntfs-fixture.test.ts
T
Garry Tan a84b0b5b6d v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)
* fix(browse): prepare reliable cookie import wave for validation

* ci: sequence quality and behavior for validation branch

* fix(browse): isolate Windows qualification and preserve native diagnostics

* test(browse): cover cookie workflow quality and isolate Windows user paths

* test(browse): trace native member startup and initialize fresh folders

* fix(browse): keep Windows member stdin alive through EOF

* fix(browse): latch native timeouts and compare contained Edge startup

* test(browse): verify native version metadata and actual Windows argv

* test(browse): qualify Dia import on isolated macOS CI

* fix(browse): require picker origin for session mutations

* fix(browse): bound credential reads through stream completion

* test(browse): inspect owned Windows process arguments natively

* test(evals): preserve passing coverage during cookie repair reruns

* test(browse): isolate Dia qualification in a fresh macOS account

* test(browse): pass bounded integer timeouts to native Mac probes

* test(browse): distinguish Windows profile initialization from containment

* test(browse): await descendant pipe readiness before parent exit

* test(browse): initialize and restore isolated macOS Keychain state

* test(browse): initialize Windows fixture folders before qualification

* test(ci): pin the same Node runtime across Windows checks

* test(browse): distinguish native macOS browser preflight stages

* test(browse): isolate Windows descendant console lifetime

* test(browse): preserve native receipts and identify fixture lock holders

* test(browse): prepare dependency resolution before native Mac worker startup

* test(ci): include lock and close checks in native diagnostics

* test(browse): preserve native owner probe stages and subprocess deadlines

* fix(browse): classify Chromium profile-in-use exit precisely

* test(browse): retain Mac qualification evidence through cleanup failures

* test(browse): bound Mac fixture paths and retire its owned user domain

* test(browse): accept vanished fixture entries without weakening cleanup

* test(browse): identify probe-created macOS user domains safely

* test(browse): observe Mac user domains without targeting them first

* test(browse): use passive fresh-user ownership throughout Mac qualification

* test(browse): distinguish profile and registered-home Keychain lookups

* test(browse): qualify Dia under one registered account home

* test(browse): identify Dia startup and owned process-group failures

* test(browse): classify bounded Dia startup diagnostics without leaking output

* fix(test): preserve native Mac sandboxing and reap owned browser children

* fix(browse): preserve Chromium sandboxing for native profile imports

* test(browse): inspect signed Mach-O architecture without launching Xcode tools

* test(browse): sample pending Dia startup and reap on all cleanup paths

* test(browse): compare protected Dia launches in fresh Bun and Node accounts

* test(browse): inspect isolated Mac GUI readiness without browser access

* v1.90.0.0 fix: bind cookie picker actions to their document

* test: validate cookie guards and fit nested launch fixtures

* ci: configure the bundled Chromium sandbox helper

* fix(browse): classify Playwright authentication timeouts

* test: retain bounded Windows lifecycle diagnostics

* test(cso): reuse bounded NTFS precision candidates

* test(review): handle explicit preservation choices safely

* test(browse): remove owned fixture directories with explicit primitives

* test(review): distinguish descriptive reuse from edit commitments

* test: admit only the approved unscored cookie workflow refusal

* test: keep the Office Hours judge mock export-complete

* fix: keep dependency-free CI planners independent of the model SDK

* test: observe the exact holder after a native fixture unlink failure

* fix: start seeded PTY observations at owned readiness

* test: acquire identity-bound Windows deletion admission before profile resets

* test: preserve qualified Git index bits without authorizing mutations
2026-09-25 12:06:45 -04:00

79 lines
3.4 KiB
TypeScript

import { afterEach, expect, test } from 'bun:test';
import * as fs from 'node:fs';
import * as os from 'node:os';
import * as path from 'node:path';
import { createPrecisionLossCandidate } from './helpers/cso-ntfs-fixture';
const roots: string[] = [];
afterEach(() => {
for (const root of roots.splice(0)) fs.rmSync(root, { recursive: true, force: true });
});
function fixture() {
const root = fs.mkdtempSync(path.join(os.tmpdir(), 'ntfs-fixture-'));
roots.push(root);
return { root, target: path.join(root, 'candidate.json') };
}
test('the actual candidate builder reaches a precision-losing generation in a fresh allocator model', () => {
const { root, target } = fixture();
const generations = new Map<number, bigint>();
let reads = 0;
let selectedIdentity: bigint | undefined;
const inode = createPrecisionLossCandidate(target, 'owned candidate', file => {
reads++;
const slot = Number(path.basename(file).split('-').at(-1));
const generation = (generations.get(slot) ?? 0n) + 1n;
generations.set(slot, generation);
const result = (generation << 48n) + BigInt(101 + slot);
if (result > BigInt(Number.MAX_SAFE_INTEGER) && String(Number(result)) !== String(result)) {
selectedIdentity = fs.lstatSync(file, { bigint: true }).ino;
}
return result;
});
expect(inode).toBeGreaterThan(BigInt(Number.MAX_SAFE_INTEGER));
expect(String(Number(inode))).not.toBe(String(inode));
expect(reads).toBeLessThanOrEqual(1024);
expect(fs.lstatSync(target, { bigint: true }).ino).toBe(selectedIdentity);
expect(fs.readFileSync(target, 'utf8')).toBe('owned candidate');
expect(fs.readdirSync(root)).toEqual(['candidate.json']);
});
test('an unavailable precision-losing ID fails at the original creation bound and leaves no candidate', () => {
const { root, target } = fixture();
for (const inode of [1n, 2n ** 54n]) {
let reads = 0;
expect(() => createPrecisionLossCandidate(target, 'owned candidate', () => { reads++; return inode; }))
.toThrow('within 1024 file creations');
expect(reads).toBe(1024);
expect(fs.readdirSync(root)).toEqual([]);
}
});
test('existing targets and candidate-inspection failures never overwrite unrelated fixture state', () => {
const { root, target } = fixture();
fs.writeFileSync(target, 'preserved');
expect(() => createPrecisionLossCandidate(target, 'replacement')).toThrow('already exists');
expect(fs.readFileSync(target, 'utf8')).toBe('preserved');
const next = path.join(root, 'next.json');
expect(() => createPrecisionLossCandidate(next, 'owned candidate', () => { throw new Error('inspection failed'); }))
.toThrow('inspection failed');
expect(fs.readdirSync(root)).toEqual(['candidate.json']);
});
test('a concurrent target and a linked parent are preserved rather than written through', () => {
const { root, target } = fixture();
expect(() => createPrecisionLossCandidate(target, 'replacement', () => {
fs.writeFileSync(target, 'concurrent fixture');
return (1n << 54n) + 1n;
})).toThrow();
expect(fs.readFileSync(target, 'utf8')).toBe('concurrent fixture');
const owned = path.join(root, 'owned');
const link = path.join(root, 'linked');
fs.mkdirSync(owned);
fs.symlinkSync(owned, link, process.platform === 'win32' ? 'junction' : 'dir');
expect(() => createPrecisionLossCandidate(path.join(link, 'candidate.json'), 'replacement'))
.toThrow('must not be linked');
expect(fs.readdirSync(owned)).toEqual([]);
});