test: opt-in gate for live-playwright ML tests; ios-qa build hygiene

security-live-playwright's L4 tests dlopen onnxruntime inside a bun
--parallel worker whenever the dev box has a warm model cache — the
source of the intermittent 'panic: Segmentation fault' + crashed-worker
retries (and likely the residual run wedges). Same SECURITY_BENCH=1
opt-in as security-bench.test.ts; the L1-L3 tests in the file still run
everywhere.

Also: gitignore the ios-qa gen-accessors-tool Swift .build/ output (a
side-effect of running its tests that kept polluting git status) and
commit its Package.resolved so tool builds resolve reproducibly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan 2026-08-15 10:40:21 -07:00
parent 10a0f130c7
commit 965b0d5a7c
No known key found for this signature in database
GPG Key ID: C1F69E85C74EFE1D
3 changed files with 24 additions and 1 deletions

3
.gitignore vendored
View File

@ -44,3 +44,6 @@ docs/throughput-*.json
# gbrain local source-staging dir (capability checks, source clones) — runtime artifact
.sources/
# Swift build output from the ios-qa gen-accessors tool (built on demand by its tests)
ios-qa/scripts/gen-accessors-tool/.build/

View File

@ -42,7 +42,13 @@ const MODEL_CACHE = path.join(
'onnx',
'model.onnx',
);
const ML_AVAILABLE = fs.existsSync(MODEL_CACHE);
// Opt-in only (SECURITY_BENCH=1), same rationale as security-bench.test.ts:
// gating on model-cache existence alone auto-ran ONNX inference on any dev box
// that ever warmed the classifier — and dlopen'ing onnxruntime inside a
// `bun test --parallel` worker segfaults Bun intermittently (observed twice:
// "panic: Segmentation fault ... a bug in Bun" followed by a crashed-worker
// retry, sometimes wedging the run).
const ML_AVAILABLE = process.env.SECURITY_BENCH === '1' && fs.existsSync(MODEL_CACHE);
describe('defense-in-depth — live Playwright fixture', () => {
let testServer: ReturnType<typeof startTestServer>;

View File

@ -0,0 +1,14 @@
{
"pins" : [
{
"identity" : "swift-syntax",
"kind" : "remoteSourceControl",
"location" : "https://github.com/swiftlang/swift-syntax.git",
"state" : {
"revision" : "2bc86522d115234d1f588efe2bcb4ce4be8f8b82",
"version" : "510.0.3"
}
}
],
"version" : 2
}