test: stabilize pre-deployment gates

Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
This commit is contained in:
Codex
2026-09-04 16:15:35 +02:00
parent 7b1d69a65b
commit eba6148511
11 changed files with 204 additions and 124 deletions
+11 -4
View File
@@ -80,17 +80,24 @@ fi
if command -v docker >/dev/null 2>&1; then
out=$(mktemp -d)
out=$(cd "$out" && pwd -P)
trap 'rm -rf "$out"' EXIT
scripts/build-dwh-auth.sh --output "$out"
for arch in amd64 arm64; do
artifact="$out/dwh-auth-linux-$arch"
[[ -s "$artifact" ]] || die "missing non-empty $artifact"
file "$artifact" | grep -Eq 'ELF .*executable' || die "$artifact is not an ELF executable"
readelf -h "$artifact" | grep -Eq 'OS/ABI:[[:space:]]+UNIX - (System V|GNU)' || die "$artifact is not a Linux ELF"
if [[ "$arch" == amd64 ]]; then
readelf -h "$artifact" | grep -Eq 'Machine:.*(X86-64|AMD64)' || die "$artifact has the wrong architecture"
if command -v readelf >/dev/null 2>&1; then
readelf -h "$artifact" | grep -Eq 'OS/ABI:[[:space:]]+UNIX - (System V|GNU)' || die "$artifact is not a Linux ELF"
if [[ "$arch" == amd64 ]]; then
readelf -h "$artifact" | grep -Eq 'Machine:.*(X86-64|AMD64)' || die "$artifact has the wrong architecture"
else
readelf -h "$artifact" | grep -Eq 'Machine:.*AArch64' || die "$artifact has the wrong architecture"
fi
elif [[ "$arch" == amd64 ]]; then
file "$artifact" | grep -Eqi '(x86[-_ ]64|amd64)' || die "$artifact has the wrong architecture"
else
readelf -h "$artifact" | grep -Eq 'Machine:.*AArch64' || die "$artifact has the wrong architecture"
file "$artifact" | grep -Eqi '(aarch64|arm64)' || die "$artifact has the wrong architecture"
fi
done
fi