Harden validation, cleanup, and release asset checks - #834
Merged
LunaStev merged 1 commit intoOct 1, 2026
Merged
Conversation
Signed-off-by: LunaStev <luna@lunastev.org>
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Protect FreeBSD validation inputs from report writes, restrict
x.py cleanto repository-owned outputs, require complete release checksum coverage, and apply selected runtime cases' stdin and expected-exit metadata..tmp/.SHA256SUMS.proc_exitstatus in the Node runner.Motivation
The existing tools could overwrite validation inputs, clean files relative to the caller's directory, accept incomplete checksum coverage, or misreport runtime results by ignoring case metadata.
Closes #821
Closes #822
Closes #820
Closes #819
Part of #832. The
tools/ci/migration and rolling Nightly work remain separate follow-ups.Target and compatibility impact
Changes affect FreeBSD validation tooling, repository cleanup, release publication gates, QEMU case execution, and WebAssembly host execution. WASI explicit process exits now reach the host exit status. Invalid report destinations and release checksum records receive explicit errors.
No language or C ABI changes. Case selection, #459 runtime classification, and the separate WASM host-function dependency failures remain unchanged; this PR adds no host shims or exclusions.
Validation
python3 -m unittest tools.test_freebsd_runtime_reporting tools.test_x tools.test_release_publish tools.test_runtime_cases— 36 passed.python3 -m unittest tools.test_runtime_cases— 15 passed after the final sysroot path adjustment.PATH=/usr/lib64/llvm21/bin:$PATH LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo +1.89 test --jobs 2 --test codegen_regressions wasi_runner_preserves_explicit_process_exit_status— passed; verifies WASI explicit exits 0 and 7.3\nand exited 7. The QEMU probe used a temporary AArch64 target configuration and local sysroot without changing the manifest.PATH=/usr/lib64/llvm21/bin:$PATH LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo +1.89 clippy --jobs 2 --bin wavec --test codegen_regressions -- -D warnings— passed.cargo +1.89 fmt --all -- --checkandgit diff --check— passed.FreeBSD report failure/alias behavior was covered locally without booting a VM. Native Windows, macOS, and FreeBSD execution remains for CI. Cleanup and checksum regression tests are included in the existing Python CI steps.
Checklist
Signed-off-byline.std/.