test: stabilize pre-deployment gates

Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
This commit is contained in:
Codex
2026-09-04 16:15:35 +02:00
parent 7b1d69a65b
commit eba6148511
11 changed files with 204 additions and 124 deletions
+37 -2
View File
@@ -41,6 +41,31 @@ printf 'fixture-session-ca\n' >"$fixture/session-ca.pem"
cp "$root/deploy/workspaces/server-sessions.yaml.example" "$fixture/server-sessions.yaml"
chmod 0600 "$fixture"/*.json "$fixture"/*.secrets "$fixture"/*.yaml "$fixture"/*password "$fixture"/*.pem
model_projection="$fixture/generated-models"
mkdir -p "$model_projection/pi"
printf '{}\n' >"$model_projection/catalog.json"
printf '{}\n' >"$model_projection/pi/models.json"
printf '{}\n' >"$model_projection/pi/settings.json"
cat >"$model_projection/compose.models.yaml" <<EOF
services:
core:
volumes:
- type: bind
source: "$model_projection/catalog.json"
target: /run/thothii-model-catalog/catalog.json
read_only: true
- type: bind
source: "$model_projection/pi/models.json"
target: /home/thoth/.pi/agent/models.json
read_only: true
- type: bind
source: "$model_projection/pi/settings.json"
target: /home/thoth/.pi/agent/settings.json
read_only: true
EOF
chmod 0600 "$model_projection/catalog.json" "$model_projection/pi"/*.json \
"$model_projection/compose.models.yaml"
cat >"$fixture/server.env" <<EOF
THOTH_SERVER_BIND=127.0.0.1
THOTH_HTTP_PORT=0
@@ -67,13 +92,14 @@ docker compose --project-directory "$root" --env-file "$fixture/server.env" \
-f "$root/compose.yaml" \
-f "$root/deploy/compose.server.yaml" \
-f "$root/deploy/compose.session-server.yaml.example" \
-f "$model_projection/compose.models.yaml" \
config --format json >"$fixture/rendered.json"
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" <<'NODE'
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" "$model_projection" <<'NODE'
const fs = require("fs");
const path = require("path");
const [renderedPath, piState, authSource] = process.argv.slice(2);
const [renderedPath, piState, authSource, modelProjection] = process.argv.slice(2);
const config = JSON.parse(fs.readFileSync(renderedPath, "utf8"));
const core = config.services?.core;
if (!core) throw new Error("server render lacks core");
@@ -98,6 +124,15 @@ for (const name of ["auth.json", "models.json", "settings.json"]) {
if (children.get("auth.json").source !== authSource) {
throw new Error("server Pi auth source changed while preparing nested targets");
}
if (children.get("models.json").source !== path.join(modelProjection, "pi", "models.json")
|| children.get("settings.json").source !== path.join(modelProjection, "pi", "settings.json")) {
throw new Error("server Pi model projection sources changed");
}
const modelCatalog = mounts.find((mount) => mount.target === "/run/thothii-model-catalog/catalog.json");
if (!modelCatalog || modelCatalog.type !== "bind" || !modelCatalog.read_only
|| modelCatalog.source !== path.join(modelProjection, "catalog.json")) {
throw new Error("server model catalog is not the expected read-only bind");
}
if (JSON.stringify(config).includes("fixture-model-key")) {
throw new Error("server render leaked a secret value");
}