mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 09:55:29 +02:00
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
56 lines
1.7 KiB
Bash
56 lines
1.7 KiB
Bash
#!/bin/sh
|
|
set -eu
|
|
umask 077
|
|
test "$PWD" = /work
|
|
test "$#" -eq 1
|
|
policy="$1"
|
|
case "$policy" in /policy/*) ;; *) exit 64 ;; esac
|
|
test -f "$policy"
|
|
count=0
|
|
while IFS= read -r database || test -n "$database"; do
|
|
case "$database" in cso_[A-Za-z_]*) ;; *) exit 64 ;; esac
|
|
case "$database" in *[!A-Za-z0-9_]*) exit 64 ;; esac
|
|
test "${#database}" -le 52
|
|
count=$((count + 1)); test "$count" -le 64
|
|
done < "$policy"
|
|
test "$count" -gt 0
|
|
|
|
data=/work/postgresql-data
|
|
socket=/work/postgresql-socket
|
|
password=/work/postgresql-password
|
|
mkdir -m 700 "$socket"
|
|
printf '%s\n' 'cso-disposable-test' > "$password"
|
|
/opt/cso/bin/initdb -D "$data" --username=cso --pwfile="$password" --auth-local=scram-sha-256 --auth-host=scram-sha-256 >/dev/null
|
|
rm -f "$password"
|
|
cat >> "$data/postgresql.conf" <<'EOF'
|
|
listen_addresses = '127.0.0.1'
|
|
port = 5432
|
|
unix_socket_directories = '/work/postgresql-socket'
|
|
ssl = off
|
|
max_connections = 32
|
|
password_encryption = 'scram-sha-256'
|
|
fsync = off
|
|
synchronous_commit = off
|
|
full_page_writes = off
|
|
EOF
|
|
|
|
cleanup() {
|
|
if test -n "${postgres_pid:-}" && kill -0 "$postgres_pid" 2>/dev/null; then
|
|
kill -TERM "$postgres_pid" 2>/dev/null || true
|
|
wait "$postgres_pid" 2>/dev/null || true
|
|
fi
|
|
}
|
|
trap cleanup EXIT INT TERM
|
|
/opt/cso/bin/postgres -D "$data" >/dev/null 2>&1 &
|
|
postgres_pid=$!
|
|
export PGPASSWORD=cso-disposable-test
|
|
attempt=0
|
|
until /opt/cso/bin/pg_isready -h 127.0.0.1 -p 5432 -U cso -d postgres >/dev/null 2>&1; do
|
|
attempt=$((attempt + 1)); test "$attempt" -lt 100; sleep 0.05
|
|
done
|
|
while IFS= read -r database || test -n "$database"; do
|
|
/opt/cso/bin/createdb -h 127.0.0.1 -p 5432 -U cso "$database" >/dev/null
|
|
done < "$policy"
|
|
printf 'ready\n' > /work/postgresql.ready
|
|
wait "$postgres_pid"
|