diff --git a/tests/runner-e2e/README.md b/tests/runner-e2e/README.md index 56ceb3772d..c9bd1e3480 100644 --- a/tests/runner-e2e/README.md +++ b/tests/runner-e2e/README.md @@ -207,8 +207,8 @@ cost. The CI report job stages the same portable site at Permanent public history has a narrower boundary. A trusted job without provider or AWS credentials copies successful declared PNG screenshots into a separate publication tree. It validates the PNG container, reduces each image -to at most 160 pixels on either edge, applies a strong blur, limits the image to -24 colors, and removes metadata. It then runs OCR and rejects the whole public +to at most 96 pixels on either edge, applies a 3.5-sigma blur, limits the image +to 16 colors, and removes metadata. It then runs OCR and rejects the whole public bundle if any letter or digit remains readable. These layout previews preserve coarse UI state while making rendered task and provider text unreadable. The job then removes the full-resolution raster files, failure screenshots, video, archives, diff --git a/tests/runner-e2e/SECURITY.md b/tests/runner-e2e/SECURITY.md index ac76ff74d0..b2607f38b9 100644 --- a/tests/runner-e2e/SECURITY.md +++ b/tests/runner-e2e/SECURITY.md @@ -197,9 +197,9 @@ packaging because it is active content. Before permanent publication, the trusted report job creates a separate tree. It accepts only declared screenshots from passing results. It validates a bounded, non-interlaced PNG container before invoking ImageMagick with strict -memory, disk, thread, and time limits. It reduces each image to at most 160 -pixels on either edge, applies a strong blur, limits the palette, removes alpha -and metadata, and validates the new PNG again. Tesseract must then find no +memory, disk, thread, and time limits. It reduces each image to at most 96 +pixels on either edge, applies a 3.5-sigma blur, limits the palette to 16 +colors, removes alpha and metadata, and validates the new PNG again. Tesseract must then find no readable letter or digit. OCR output is never logged. Any readable text or OCR failure blocks the whole publication. This is a layout preview, not diagnostic evidence. The job then prunes full-resolution raster files, all failure images, diff --git a/tests/runner-e2e/history-public-bundle.ts b/tests/runner-e2e/history-public-bundle.ts index ae05da7538..a6484975b9 100644 --- a/tests/runner-e2e/history-public-bundle.ts +++ b/tests/runner-e2e/history-public-bundle.ts @@ -31,7 +31,7 @@ const PNG_SIGNATURE = Buffer.from([ const MAX_PRIVATE_PNG_BYTES = 32 * 1024 * 1024; const MAX_PRIVATE_PNG_PIXELS = 64 * 1024 * 1024; const MAX_PRIVATE_PNG_EDGE = 32 * 1024; -const MAX_PUBLIC_PREVIEW_EDGE = 160; +const MAX_PUBLIC_PREVIEW_EDGE = 96; const MAX_PUBLIC_PREVIEW_BYTES = 256 * 1024; const PRIVATE_PNG_CHUNKS = new Set([ "IHDR", @@ -320,9 +320,9 @@ export async function createPublicLayoutPreview( "-resize", `${MAX_PUBLIC_PREVIEW_EDGE}x${MAX_PUBLIC_PREVIEW_EDGE}>`, "-blur", - "0x2.5", + "0x3.5", "-colors", - "24", + "16", "-strip", "-define", "png:exclude-chunks=all",