mirror of
https://github.com/DeusData/codebase-memory-mcp.git
synced 2026-10-03 21:38:57 +08:00
Step 0o (MCPB bundle contract) and Step 0q (release candidate derivation) hand the composition gate a stub compiled straight from a .c file with the compiler's defaults. That stub exists to exercise packaging, format detection and the needle scans; it is not linked with -z now and never ships. A1d measured eager binding on it anyway, so on a toolchain that binds lazily by default (test-diag: clang-22) Step 0o died deterministically with A1d-bind-now stage/codebase-memory-mcp: GOT section(s) .got.plt fall outside PT_GNU_RELRO [15824,16384) — they stay WRITABLE after relocation The property A1d protects is a property of the release link (-z now in Makefile.cbm), so the assertion is scoped to it: a caller that feeds the gate a packaging fixture declares so with CBM_COMPOSITION_FIXTURE=1 and A1d is reported n/a — printed on every run as a named exemption, never a silent skip. Every other assertion still runs on the fixture unchanged, and release derivation never sets the variable. Verified in the Linux arm64 container (Ubuntu 24.04, gcc 13.3): a stub linked -z lazy reproduces the CI failure text on the gate without the variable and reports n/a with it; both contracts pass under a CC wrapper that links lazily (the shape that was red), and unchanged on macOS. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>
scripts/ci/ — venue plumbing (single implementations)
Support scripts that keep the venues in the SAME shape. Each exists because
the logic used to live inline in workflow YAML or was hand-duplicated between
CI and the local infrastructure — both of which the venue-parity contract
(tests/test_venue_parity_contract.sh) now forbids. Everything here answers
--help (PowerShell: comment-based help, Get-Help <script>).
| script | job | called by |
|---|---|---|
new-protected-temp-root.ps1 |
Create the owner-stamped, inheritance-protected per-user TEMP root the daemon/install suites require (shared /tmp and default runner TEMP grant Authenticated-Users mutation rights, which the trust policy correctly refuses — running there produces security refusals, not signal). -ProtectDir stamps build dirs the same way. |
_test.yml, _soak.yml, vm-run-tests.sh |
clean-test-residue.ps1 |
Sweep cbm-* residue from the Windows VM and assert runner-like free disk (default 14 GB — the GitHub runner's SSD). Long-path \\?\ fallback for the guard suites' adversarial trees; every removal VERIFIED (an earlier version counted attempts and reported 86 swept while 11 GB remained). BLOCKS below the floor: a disk that fills mid-run reads as a product bug. |
win.sh before every build/run |
preflight-docker.sh |
Same idea for Colima/docker: prune runner-unlike residue, assert free space on the filesystem backing the docker data root (not the VM's /). Build cache + named volumes KEPT (the local analogue of actions/cache); --deep drops them. |
test-infrastructure/run.sh |
check-glibc-compat.sh |
Run a linux binary in debian:bullseye (glibc 2.31) — the portable binary must start on old glibc. | _smoke.yml portable legs |
generate-sbom.py |
The release SPDX SBOM (vendored versions reviewable here, diffable by vendoring PRs — was inline YAML). | release.yml |
require-all-green.sh |
The aggregate gate: fail unless every needed job succeeded or legitimately skipped (was inline YAML). | pr.yml ci-ok |
verify-shard-union.sh |
Prove sharded test legs lost nothing: shard count agreement, indices 1..n, identical suite lists, union of slices == full list (was inline YAML). | _test.yml shard-completeness |
prepare-release-candidates.sh |
Copy one linker output into stripped/unstripped candidates, finalize signatures, composition-check them without execution, and record their hashes. | _build.yml, local artifact smoke |
stage-release-candidates.py |
Admit exactly eight candidate artifacts / sixteen byte-distinct binaries into the content-addressed VirusTotal scan set. | _build.yml |
select-release-candidates.py |
Apply the reviewed tuple-local VT truth table, or the explicit dry-run stripped default, and atomically copy one content-bound binary per target. | _build.yml |
verify-release-selection.py |
Recompute the selection policy and prove every executable member in all 14 public containers equals its selected SHA-256. | _build.yml, release.yml final draft verification |
check-virustotal.sh |
Poll and validate the exact candidate scan set, enforce engine coverage and the narrow documented Microsoft !ml policy, and emit content-bound results evidence. |
_build.yml |