mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-11 03:38:07 +00:00
fix(eval): build release dependencies offline without CUDA downloads (#3541)
Set the supported ONNX installer skip policy inside the cleared build sandbox so optional CUDA downloads do not abort offline lifecycle scripts. Keep CPU binaries, network containment, and all grading checks intact. Strengthen command construction and real Bubblewrap lifecycle coverage. Targeted tests: 114 passed, 15 skipped. Full core and real containment validation deferred to hosted CI with maintainer approval.
This commit is contained in:
parent
4756e8a820
commit
d4e6c9422c
3 changed files with 15 additions and 1 deletions
|
|
@ -169,6 +169,7 @@ def test_real_bubblewrap_candidate_lifecycle_cannot_replace_harness_or_read_toke
|
|||
harness = tmp_path / "trusted-harness.py"
|
||||
harness.write_text("trusted main evaluator\n")
|
||||
monkeypatch.setenv("GITNEXUS_BENCH_OPENAI_API_KEY", "canary-token")
|
||||
monkeypatch.setenv("ONNXRUNTIME_NODE_INSTALL", "cuda12")
|
||||
attack = (
|
||||
"const fs=require('fs');\n"
|
||||
f"const target={json.dumps(str(harness))};\n"
|
||||
|
|
@ -177,6 +178,7 @@ def test_real_bubblewrap_candidate_lifecycle_cannot_replace_harness_or_read_toke
|
|||
"try { fs.appendFileSync('.git/config','[core]\\n\\tfsmonitor = forged\\n'); } catch {}\n"
|
||||
"fs.writeFileSync('receipt.json', JSON.stringify({visible, token:"
|
||||
"process.env.GITNEXUS_BENCH_OPENAI_API_KEY ?? null,"
|
||||
"onnxInstall:process.env.ONNXRUNTIME_NODE_INSTALL ?? null,"
|
||||
"interfaces:Object.keys(require('os').networkInterfaces()).sort()}));\n"
|
||||
)
|
||||
(candidate / "attack.cjs").write_text(attack)
|
||||
|
|
@ -199,6 +201,7 @@ def test_real_bubblewrap_candidate_lifecycle_cannot_replace_harness_or_read_toke
|
|||
assert json.loads((candidate / "receipt.json").read_text()) == {
|
||||
"visible": False,
|
||||
"token": None,
|
||||
"onnxInstall": "skip",
|
||||
"interfaces": ["lo"],
|
||||
}
|
||||
assert (core / "built.txt").read_text() == "runtime"
|
||||
|
|
|
|||
|
|
@ -43,6 +43,7 @@ def test_candidate_build_rejects_symlinked_checkout_before_execution(monkeypatch
|
|||
|
||||
def test_candidate_build_clears_tokens_and_mounts_only_candidate_writable(monkeypatch, tmp_path):
|
||||
calls = []
|
||||
monkeypatch.setenv('ONNXRUNTIME_NODE_INSTALL', 'cuda12')
|
||||
monkeypatch.setattr(release_build, "preflight_bubblewrap", lambda: Path('/usr/bin/bwrap'))
|
||||
monkeypatch.setattr(release_build, "run_checked", lambda *a, **k: calls.append((a, k)))
|
||||
write_lockfiles(tmp_path)
|
||||
|
|
@ -54,7 +55,12 @@ def test_candidate_build_clears_tokens_and_mounts_only_candidate_writable(monkey
|
|||
at = command.index('--bind')
|
||||
assert command[at + 1:at + 3] == [str(tmp_path), '/workspace']
|
||||
assert command.count('--bind') == 1
|
||||
assert [command[i + 1] for i, v in enumerate(command) if v == '--setenv'] == ['PATH', 'HOME']
|
||||
environment = {command[i + 1]: command[i + 2] for i, v in enumerate(command) if v == '--setenv'}
|
||||
assert environment == {
|
||||
'PATH': release_build.SANDBOX_PATH,
|
||||
'HOME': '/home/build',
|
||||
'ONNXRUNTIME_NODE_INSTALL': 'skip',
|
||||
}
|
||||
assert '--unshare-pid' in command and '--cap-drop' in command
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -82,6 +82,11 @@ def build_candidate(repo: Path) -> None:
|
|||
"--setenv",
|
||||
"HOME",
|
||||
"/home/build",
|
||||
# CPU binaries ship in the npm package. Optional CUDA downloads
|
||||
# cannot run during the network-isolated lifecycle phase.
|
||||
"--setenv",
|
||||
"ONNXRUNTIME_NODE_INSTALL",
|
||||
"skip",
|
||||
"--chdir",
|
||||
"/workspace",
|
||||
"--",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue