Files
gstack/test/cso-verifier.test.ts
T
Garry TanandOpenAI Codex 4a3c6a8a3c v1.87.0.0 feat: add verified CSO audits and replayable repair bundles (#2852)
* feat(cso): add verified audits and replayable repair bundles

* fix(cso): harden qualification and setup boundaries

* fix(cso): assemble security canaries at runtime

* fix(cso): bound release proof and maintenance work

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): require complete evaluation reports

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): replay expired snapshots from supplied source

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): synchronize DNS cancellation assertion

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore(ship): exempt repository owner from liveness proof

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): make recheck retention overlap deterministic

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: bump version and changelog (v1.85.0.0)

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass native release gates

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.86.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): resolve rechecks by finding

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.87.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass macOS and Windows release gates

Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures.

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): harden native verification gates

* fix(cso): refine Windows native diagnostics

* test(cso): isolate Windows Git startup failure

* test(cso): stabilize Windows native diagnostics

* fix(cso): support hardened Git on Windows

* fix(cso): close final verification gaps

* test(cso): bound cold Docker fixture setup

* fix(cso): restore cross-platform free-suite gates

---------

Co-authored-by: OpenAI Codex <noreply@openai.com>
2026-09-14 15:14:58 -07:00

29 lines
1.2 KiB
TypeScript

import { describe, expect, test } from 'bun:test';
import { boundedResponseBody } from '../lib/cso/verifier';
describe('CSO bounded loopback verifier response reader',()=>{
test('accepts a response exactly at the configured byte limit',async()=>{
const body='x'.repeat(65_536);
expect(await boundedResponseBody(new Response(body))).toBe(body);
});
test('cancels an endless chunked response immediately after the byte limit',async()=>{
let pulls=0,cancelled=false;
const stream=new ReadableStream<Uint8Array>({
pull(controller){pulls++;controller.enqueue(new Uint8Array(8192));},
cancel(){cancelled=true;},
});
await expect(boundedResponseBody(new Response(stream))).rejects.toThrow('response too large');
expect(cancelled).toBe(true);
expect(pulls).toBeLessThanOrEqual(10);
});
test('rejects an oversized declared body before consuming it',async()=>{
let cancelled=false;
const stream=new ReadableStream<Uint8Array>({pull(controller){controller.enqueue(new Uint8Array(1));},cancel(){cancelled=true;}});
const response=new Response(stream,{headers:{'content-length':'65537'}});
await expect(boundedResponseBody(response)).rejects.toThrow('response too large');
expect(cancelled).toBe(true);
});
});