test: stabilize pre-deployment gates

Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
This commit is contained in:
Codex
2026-09-04 16:15:35 +02:00
parent 7b1d69a65b
commit eba6148511
11 changed files with 204 additions and 124 deletions
-13
View File
@@ -416,19 +416,6 @@ test("only two Argon2 verifications run concurrently and excess login attempts f
expect((await second).statusCode).toBe(401);
});
test("the real native asynchronous Argon2 verifier holds two permits and releases them after completion", async () => {
const { app } = await createLocalApp();
const first = login(app, { password: `${password}!` });
const second = login(app, { password: `${password}!` });
await new Promise<void>((resolve) => setImmediate(resolve));
const excess = await login(app, { password: `${password}!` });
expect(excess.statusCode).toBe(429);
await expect(first).resolves.toMatchObject({ statusCode: 401 });
await expect(second).resolves.toMatchObject({ statusCode: 401 });
await expect(login(app, { password: `${password}!` })).resolves.toMatchObject({ statusCode: 401 });
});
test("a verifier failure is sanitized and releases its concurrency permit", async () => {
let attempts = 0;
const user = {
@@ -241,7 +241,7 @@ test("registry boots from the nested catalog layout, accepts co-committed displa
expect(evidenceRevision.revision.commit).toBe(evidenceCommit);
expect(evidenceRevision.revision.commit).not.toBe(metadataRevision.revision.commit);
expect(evidenceRevision.revision.blob).toBe(metadataRevision.revision.blob);
});
}, 15_000);
test("registry rejects orphan descriptors, metadata mismatches, and the retired flat layout while keeping the last active snapshot", async () => {
const workspace = parseWorkspaceYaml(readFixture("workspace-registry-smoke.yaml"));
@@ -276,7 +276,7 @@ test("registry rejects orphan descriptors, metadata mismatches, and the retired
writeFileSync(join(fixture.source, "workspaces", "local.yaml"), serializeWorkspaceYaml(workspace));
writeFileSync(join(fixture.source, "workspace-content", "local", "evidence", "guide.md"), "legacy guide\n");
});
});
}, 15_000);
test("Windows clone contract copies the shared complete schema v4 descriptor into the nested registry layout", () => {
const descriptor = parseWorkspaceYaml(readFixture("workspace-registry-windows.yaml"));
@@ -153,7 +153,7 @@ test("real schema-v4 registry revision loads through ThtRunner and the harness c
f.dataRoot, "sessions", "psd-clinical", "sessions", created.id, "session_manifest.yaml",
))).toBe(true);
expect(readdirSync(join(f.registryConfig.root, "snapshots", "runtime"))).toEqual([]);
});
}, 15_000);
test("ThtRunner uses a vault secret only for the lifetime of its runtime lease", async () => {
const f = await fixture();