Merge pull request #1574 from BradGroux/fix/retained-board-evidence-620

fix: accept retained large-board evidence during release promotion
This commit is contained in:
Brad Groux 2026-09-07 21:17:39 -05:00 • committed by GitHub
commit 78da3a4756
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 23 additions and 2 deletions

View file

@ -38,7 +38,7 @@ export function validateArchiveEntries(names, listing) {
name &&
!path.posix.isAbsolute(name) &&
!name.split('/').includes('..') &&
/^(?:release\/|native-ui-evidence\/|documentation-media\/|native-distribution\.sha256$|release-candidate\.json$)/.test(
/^(?:release\/|native-ui-evidence\/|documentation-media\/|large-board-evidence\/|native-distribution\.sha256$|release-candidate\.json$)/.test(
name
),
`Unsafe candidate archive entry: ${name}`

View file

@ -79,6 +79,21 @@ test('candidate archives reject traversal, links, devices, and unexpected roots'
assert.throws(() => validateArchiveEntries('release/file', mode), /link or special/);
});
test('signed large-board evidence survives archive validation without accepting unsafe paths', () => {
assert.doesNotThrow(() =>
validateArchiveEntries(
'large-board-evidence/\nlarge-board-evidence/report.json\nlarge-board-evidence/board-5000.png\n',
'drwxr-xr-x folder\n-rw-r--r-- report\n-rw-r--r-- image\n'
)
);
for (const name of ['large-board-evidence/../outside', 'large-board-evidence-other/report.json'])
assert.throws(() => validateArchiveEntries(name, '-rw-r--r-- file'), /Unsafe/);
assert.throws(
() => validateArchiveEntries('large-board-evidence/report.json', 'lrwxrwxrwx link'),
/link or special/
);
});
test('the distribution checksum list contains each exact release artifact once', () => {
const names = [
'latest-mac.yml',

View file

@ -67,7 +67,6 @@ const report = {
unmatched: [
'Original showcase dataset is unavailable; uses the documentation fixture.',
'Native content capture excludes the baseline window frame and shadow.',
'Host OS differs from the baseline macOS 15.7.9.',
],
},
};
@ -279,6 +278,13 @@ try {
const launched = await session.launch();
({ app, page } = launched);
report.identity = launched.identity;
const baseline = JSON.parse(
await readFile(path.join(root, report.taskModeComparison.baseline), 'utf8')
);
const osMatch = baseline.host.osVersion === launched.identity.osVersion;
report.taskModeComparison[osMatch ? 'matched' : 'unmatched'].push(
`Host macOS: baseline ${baseline.host.osVersion}; candidate ${launched.identity.osVersion}.`
);
await app.evaluate(({ BrowserWindow }, sizes) => {
const win = BrowserWindow.getAllWindows().find((w) => w.isVisible());
win.webContents.setZoomFactor(1);