test: stabilize pre-deployment gates
Remove the redundant timing-dependent native Argon2 concurrency test while retaining native vector coverage and deterministic limiter coverage. Refresh stale deployment and browser contracts, make release scripts portable across Bash/macOS, and update production dependency locks for resolved security advisories.
This commit is contained in:
@@ -41,6 +41,31 @@ printf 'fixture-session-ca\n' >"$fixture/session-ca.pem"
|
||||
cp "$root/deploy/workspaces/server-sessions.yaml.example" "$fixture/server-sessions.yaml"
|
||||
chmod 0600 "$fixture"/*.json "$fixture"/*.secrets "$fixture"/*.yaml "$fixture"/*password "$fixture"/*.pem
|
||||
|
||||
model_projection="$fixture/generated-models"
|
||||
mkdir -p "$model_projection/pi"
|
||||
printf '{}\n' >"$model_projection/catalog.json"
|
||||
printf '{}\n' >"$model_projection/pi/models.json"
|
||||
printf '{}\n' >"$model_projection/pi/settings.json"
|
||||
cat >"$model_projection/compose.models.yaml" <<EOF
|
||||
services:
|
||||
core:
|
||||
volumes:
|
||||
- type: bind
|
||||
source: "$model_projection/catalog.json"
|
||||
target: /run/thothii-model-catalog/catalog.json
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: "$model_projection/pi/models.json"
|
||||
target: /home/thoth/.pi/agent/models.json
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: "$model_projection/pi/settings.json"
|
||||
target: /home/thoth/.pi/agent/settings.json
|
||||
read_only: true
|
||||
EOF
|
||||
chmod 0600 "$model_projection/catalog.json" "$model_projection/pi"/*.json \
|
||||
"$model_projection/compose.models.yaml"
|
||||
|
||||
cat >"$fixture/server.env" <<EOF
|
||||
THOTH_SERVER_BIND=127.0.0.1
|
||||
THOTH_HTTP_PORT=0
|
||||
@@ -67,13 +92,14 @@ docker compose --project-directory "$root" --env-file "$fixture/server.env" \
|
||||
-f "$root/compose.yaml" \
|
||||
-f "$root/deploy/compose.server.yaml" \
|
||||
-f "$root/deploy/compose.session-server.yaml.example" \
|
||||
-f "$model_projection/compose.models.yaml" \
|
||||
config --format json >"$fixture/rendered.json"
|
||||
|
||||
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" <<'NODE'
|
||||
node - "$fixture/rendered.json" "$pi_state" "$fixture/pi-auth.json" "$model_projection" <<'NODE'
|
||||
const fs = require("fs");
|
||||
const path = require("path");
|
||||
|
||||
const [renderedPath, piState, authSource] = process.argv.slice(2);
|
||||
const [renderedPath, piState, authSource, modelProjection] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(renderedPath, "utf8"));
|
||||
const core = config.services?.core;
|
||||
if (!core) throw new Error("server render lacks core");
|
||||
@@ -98,6 +124,15 @@ for (const name of ["auth.json", "models.json", "settings.json"]) {
|
||||
if (children.get("auth.json").source !== authSource) {
|
||||
throw new Error("server Pi auth source changed while preparing nested targets");
|
||||
}
|
||||
if (children.get("models.json").source !== path.join(modelProjection, "pi", "models.json")
|
||||
|| children.get("settings.json").source !== path.join(modelProjection, "pi", "settings.json")) {
|
||||
throw new Error("server Pi model projection sources changed");
|
||||
}
|
||||
const modelCatalog = mounts.find((mount) => mount.target === "/run/thothii-model-catalog/catalog.json");
|
||||
if (!modelCatalog || modelCatalog.type !== "bind" || !modelCatalog.read_only
|
||||
|| modelCatalog.source !== path.join(modelProjection, "catalog.json")) {
|
||||
throw new Error("server model catalog is not the expected read-only bind");
|
||||
}
|
||||
if (JSON.stringify(config).includes("fixture-model-key")) {
|
||||
throw new Error("server render leaked a secret value");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user