test: stabilize pre-deployment gates

Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
This commit is contained in:
Codex
2026-09-04 16:15:35 +02:00
parent 7b1d69a65b
commit eba6148511
11 changed files with 204 additions and 124 deletions
+3 -6
View File
@@ -27,11 +27,7 @@ while (($#)); do
done
case "$output" in
# Explicit paths must already be canonical; the default is canonical by construction.
/*)
canonical_output=$(realpath -m "$output")
[[ "$canonical_output" == "$output" ]] || { echo "build-dwh-auth: output must be canonical" >&2; exit 2; }
;;
/*) ;;
*)
echo "build-dwh-auth: output must be an absolute canonical directory" >&2
exit 2
@@ -57,7 +53,8 @@ fi
exit 2
}
leaf=$(basename "$output")
[[ "$parent/$leaf" == "$output" ]] || {
canonical_parent=$(cd "$parent" && pwd -P)
[[ "${canonical_parent%/}/$leaf" == "$output" ]] || {
echo "build-dwh-auth: output must be canonical" >&2
exit 2
}
+1 -1
View File
@@ -119,7 +119,7 @@ while IFS= read -r name; do
exit 2
fi
value="$(read_env_value "$env_file" "$name")"
if [[ -v "$name" ]]; then
if declare -p "$name" >/dev/null 2>&1; then
value="${!name}"
fi
if [[ -n "$value" ]] && ! is_safe_absolute_path "$value"; then
+11 -4
View File
@@ -80,17 +80,24 @@ fi
if command -v docker >/dev/null 2>&1; then
out=$(mktemp -d)
out=$(cd "$out" && pwd -P)
trap 'rm -rf "$out"' EXIT
scripts/build-dwh-auth.sh --output "$out"
for arch in amd64 arm64; do
artifact="$out/dwh-auth-linux-$arch"
[[ -s "$artifact" ]] || die "missing non-empty $artifact"
file "$artifact" | grep -Eq 'ELF .*executable' || die "$artifact is not an ELF executable"
readelf -h "$artifact" | grep -Eq 'OS/ABI:[[:space:]]+UNIX - (System V|GNU)' || die "$artifact is not a Linux ELF"
if [[ "$arch" == amd64 ]]; then
readelf -h "$artifact" | grep -Eq 'Machine:.*(X86-64|AMD64)' || die "$artifact has the wrong architecture"
if command -v readelf >/dev/null 2>&1; then
readelf -h "$artifact" | grep -Eq 'OS/ABI:[[:space:]]+UNIX - (System V|GNU)' || die "$artifact is not a Linux ELF"
if [[ "$arch" == amd64 ]]; then
readelf -h "$artifact" | grep -Eq 'Machine:.*(X86-64|AMD64)' || die "$artifact has the wrong architecture"
else
readelf -h "$artifact" | grep -Eq 'Machine:.*AArch64' || die "$artifact has the wrong architecture"
fi
elif [[ "$arch" == amd64 ]]; then
file "$artifact" | grep -Eqi '(x86[-_ ]64|amd64)' || die "$artifact has the wrong architecture"
else
readelf -h "$artifact" | grep -Eq 'Machine:.*AArch64' || die "$artifact has the wrong architecture"
file "$artifact" | grep -Eqi '(aarch64|arm64)' || die "$artifact has the wrong architecture"
fi
done
fi
+37 -2
View File
@@ -41,6 +41,31 @@ printf 'fixture-session-ca\n' >"$fixture/session-ca.pem"
cp "$root/deploy/workspaces/server-sessions.yaml.example" "$fixture/server-sessions.yaml"
chmod 0600 "$fixture"/*.json "$fixture"/*.secrets "$fixture"/*.yaml "$fixture"/*password "$fixture"/*.pem
model_projection="$fixture/generated-models"
mkdir -p "$model_projection/pi"
printf '{}\n' >"$model_projection/catalog.json"
printf '{}\n' >"$model_projection/pi/models.json"
printf '{}\n' >"$model_projection/pi/settings.json"
cat >"$model_projection/compose.models.yaml" <<EOF
services:
core:
volumes:
- type: bind
source: "$model_projection/catalog.json"
target: /run/thothii-model-catalog/catalog.json
read_only: true
- type: bind
source: "$model_projection/pi/models.json"
target: /home/thoth/.pi/agent/models.json
read_only: true
- type: bind
source: "$model_projection/pi/settings.json"
target: /home/thoth/.pi/agent/settings.json
read_only: true
EOF
chmod 0600 "$model_projection/catalog.json" "$model_projection/pi"/*.json \
"$model_projection/compose.models.yaml"
cat >"$fixture/server.env" <<EOF
THOTH_SERVER_BIND=127.0.0.1
THOTH_HTTP_PORT=0
@@ -67,13 +92,14 @@ docker compose --project-directory "$root" --env-file "$fixture/server.env" \
-f "$root/compose.yaml" \
-f "$root/deploy/compose.server.yaml" \
-f "$root/deploy/compose.session-server.yaml.example" \
-f "$model_projection/compose.models.yaml" \
config --format json >"$fixture/rendered.json"
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" <<'NODE'
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" "$model_projection" <<'NODE'
const fs = require("fs");
const path = require("path");
const [renderedPath, piState, authSource] = process.argv.slice(2);
const [renderedPath, piState, authSource, modelProjection] = process.argv.slice(2);
const config = JSON.parse(fs.readFileSync(renderedPath, "utf8"));
const core = config.services?.core;
if (!core) throw new Error("server render lacks core");
@@ -98,6 +124,15 @@ for (const name of ["auth.json", "models.json", "settings.json"]) {
if (children.get("auth.json").source !== authSource) {
throw new Error("server Pi auth source changed while preparing nested targets");
}
if (children.get("models.json").source !== path.join(modelProjection, "pi", "models.json")
|| children.get("settings.json").source !== path.join(modelProjection, "pi", "settings.json")) {
throw new Error("server Pi model projection sources changed");
}
const modelCatalog = mounts.find((mount) => mount.target === "/run/thothii-model-catalog/catalog.json");
if (!modelCatalog || modelCatalog.type !== "bind" || !modelCatalog.read_only
|| modelCatalog.source !== path.join(modelProjection, "catalog.json")) {
throw new Error("server model catalog is not the expected read-only bind");
}
if (JSON.stringify(config).includes("fixture-model-key")) {
throw new Error("server render leaked a secret value");
}