diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dbb21084..cb980964 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -216,13 +216,6 @@ jobs: rust-stable-test-linux-with-docker: name: rust-stable-test / linux-with-docker runs-on: ubuntu-latest - services: - docker: - image: docker:dind - options: --privileged - env: - DOCKER_TLS_CERTDIR: "" - DOCKER_HOST: tcp://docker:2375 steps: - uses: actions/checkout@v6 @@ -253,13 +246,6 @@ jobs: escape-positive-control: name: escape-positive-control runs-on: ubuntu-latest - services: - docker: - image: docker:dind - options: --privileged - env: - DOCKER_TLS_CERTDIR: "" - DOCKER_HOST: tcp://docker:2375 steps: - uses: actions/checkout@v6 @@ -364,16 +350,18 @@ jobs: cache: true cache-key: benchmark-gate-release + - uses: taiki-e/install-action@nextest + - name: Build benchmark + perf test binaries - run: cargo test --release --all-features --test benchmark_test --test perf_tests --no-run + run: cargo nextest run --release --all-features --test benchmark_test --test perf_tests --no-run - name: Accuracy regression gate (P/R/F1) - run: cargo test --release --all-features --test benchmark_test -- --ignored --nocapture benchmark_evaluation + run: cargo nextest run --release --all-features --test benchmark_test --run-ignored only --no-capture benchmark_evaluation - name: Performance regression gate env: NYX_CI_BENCH: "1" - run: cargo test --release --all-features --test perf_tests -- --nocapture + run: cargo nextest run --release --all-features --test perf_tests --no-capture - name: Upload benchmark results if: always() @@ -404,6 +392,8 @@ jobs: toolchain: stable cache: true + - uses: taiki-e/install-action@nextest + - name: Corpus unit tests (no_marker_collisions, all_payloads_have_fixture_paths) run: cargo nextest run --lib -p nyx-scanner dynamic::corpus env: diff --git a/.github/workflows/corpus_promote.yml b/.github/workflows/corpus_promote.yml index c9e60652..744c7109 100644 --- a/.github/workflows/corpus_promote.yml +++ b/.github/workflows/corpus_promote.yml @@ -111,18 +111,18 @@ jobs: body_file=$(mktemp) cat > "$body_file" <<'PREAMBLE' -## Corpus Promotion Proposal + ## Corpus Promotion Proposal -This PR was generated automatically by the weekly corpus-promote workflow. -It does **not** auto-merge — a human reviewer must approve each candidate -before it can land in `src/dynamic/corpus.rs` (§16.4). + This PR was generated automatically by the weekly corpus-promote workflow. + It does **not** auto-merge — a human reviewer must approve each candidate + before it can land in `src/dynamic/corpus.rs` (§16.4). -### Candidates + ### Candidates -The following payloads were discovered by the internal mutation fuzzer and -confirmed via `sink_hit && oracle_fired` against instrumented fixtures: + The following payloads were discovered by the internal mutation fuzzer and + confirmed via `sink_hit && oracle_fired` against instrumented fixtures: -PREAMBLE + PREAMBLE for f in $CANDIDATE_FILES; do sidecar="${f}.json" @@ -136,16 +136,16 @@ PREAMBLE cat >> "$body_file" <<'CHECKLIST' -### Review checklist + ### Review checklist -- [ ] Bytes are a genuine attack vector, not a fixture artifact -- [ ] Oracle marker is unique (no collision with other caps) -- [ ] `fixture_paths` updated in `src/dynamic/corpus.rs` -- [ ] `since_corpus_version` set to next version -- [ ] `CORPUS_VERSION` bumped and bump history updated + - [ ] Bytes are a genuine attack vector, not a fixture artifact + - [ ] Oracle marker is unique (no collision with other caps) + - [ ] `fixture_paths` updated in `src/dynamic/corpus.rs` + - [ ] `since_corpus_version` set to next version + - [ ] `CORPUS_VERSION` bumped and bump history updated -_Generated by corpus_promote.yml — do not auto-merge._ -CHECKLIST + _Generated by corpus_promote.yml — do not auto-merge._ + CHECKLIST git add fuzz-discovered/ || true git diff --cached --quiet || git commit -m "chore: add ${CANDIDATE_COUNT} fuzzer-discovered corpus candidates" diff --git a/.github/workflows/dynamic.yml b/.github/workflows/dynamic.yml index 1e060e0d..03e44655 100644 --- a/.github/workflows/dynamic.yml +++ b/.github/workflows/dynamic.yml @@ -13,7 +13,7 @@ # chroot-leg of the escape suite skips silently # (Phase 20 follow-up #4 in deferred.md). # -# linux-with-docker — Ubuntu host with docker-in-docker. Exercises +# linux-with-docker — Ubuntu host with the runner Docker daemon. Exercises # the docker backend (Phase 19) and the # differential-confirmation parity tests. # @@ -79,13 +79,6 @@ jobs: linux-with-docker: name: dynamic / linux-with-docker runs-on: ubuntu-latest - services: - docker: - image: docker:dind - options: --privileged - env: - DOCKER_TLS_CERTDIR: "" - DOCKER_HOST: tcp://docker:2375 steps: - uses: actions/checkout@v6 diff --git a/THIRDPARTY-LICENSES.html b/THIRDPARTY-LICENSES.html index a545c7c5..73b982c9 100644 --- a/THIRDPARTY-LICENSES.html +++ b/THIRDPARTY-LICENSES.html @@ -44,8 +44,8 @@
GNU GENERAL PUBLIC LICENSE @@ -4894,6 +4898,39 @@ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ++ +
Copyright (c) 2017 h2 authors + +Permission is hereby granted, free of charge, to any +person obtaining a copy of this software and associated +documentation files (the "Software"), to deal in the +Software without restriction, including without +limitation the rights to use, copy, modify, merge, +publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software +is furnished to do so, subject to the following +conditions: + +The above copyright notice and this permission notice +shall be included in all copies or substantial portions +of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF +ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED +TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A +PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT +SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR +IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER +DEALINGS IN THE SOFTWARE.
{a.payload_label}
{a.triggered
diff --git a/frontend/src/pages/FindingsPage.tsx b/frontend/src/pages/FindingsPage.tsx
index 40dd9c61..4f71b69a 100644
--- a/frontend/src/pages/FindingsPage.tsx
+++ b/frontend/src/pages/FindingsPage.tsx
@@ -781,7 +781,9 @@ export function FindingsPage() {
{nodeLocation(other)}
+
+ {nodeLocation(other)}
+
);
})}
@@ -250,7 +254,11 @@ export function SurfacePage() {
-