Skip to content

Extend release and crosscompile security coverage - #156

Merged
matveynator merged 4 commits into
mainfrom
security-tests/database-domain-isolation
Sep 27, 2026
Merged

matveynator merged 4 commits into
mainfrom
security-tests/database-domain-isolation

Conversation

@matveynator

Copy link
Copy Markdown
Owner

Summary

  • verify stable release artifact allowlists and fail-closed workflow behavior
  • prove mail delivery failures never log secret-bearing error details
  • exercise crosscompile macOS packaging, Docker/rsync orchestration, artifact validation, and full server target publication with command doubles

Validation

  • targeted security tests pass for mailout, accountauth, channelacme, and crosscompile
  • mailout remains above 90% coverage
  • accountauth remains above 90% coverage
  • channelacme and crosscompile are improved with meaningful platform/error-path coverage, but remain below 90%; the remaining gap is documented rather than filled with synthetic tests
  • race testing was unavailable in this environment because gcc is not installed

@matveynator
matveynator force-pushed the security-tests/database-domain-isolation branch from 6a59f07 to 24e79c8 Compare September 27, 2026 05:50

Copy link
Copy Markdown
Owner Author

Added and validated the next reverse-order security slice.

Local results:

  • go test ./pkg/mailout ./pkg/accountauth ./pkg/channelacme ./scripts/crosscompile passes.
  • mailout: 90.6% coverage.
  • accountauth: 90.3% coverage.
  • channelacme: 85.7% coverage.
  • crosscompile: 85.4% coverage after adding meaningful macOS/Docker/rsync/artifact orchestration tests.
  • -race could not run in this environment because gcc is unavailable.

Merge is currently blocked by the repository-required CodeQL check waiting for results on this commit; no bypass was used.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@matveynator
matveynator merged commit d6a7925 into main Sep 27, 2026
7 checks passed
@matveynator
matveynator deleted the security-tests/database-domain-isolation branch September 27, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants