chore: re-vendor canonical files from prompts at dd4027b (closes #472)
check / check (push) Successful in 7m32s
e2e / e2e-chrome (push) Successful in 5m30s
e2e / e2e-firefox (push) Successful in 3m56s

Copies .dockerignore, .gitignore, .prettierignore, check.yml and
REPO_POLICIES.md from sneak/prompts at dd4027b. The repo's own entries
(dist/, release/, yarn files) are kept after the canonical content.

The Dockerfile gets separate lint and test phases. Its last stage
depends on both, checks the git describe version and runs make build.
script/lint, test, check, cibuild and docker are the canonical models.
check-censored moves into the lint phase and test-verify-build into the
test phase. fmt and fmt-check fall back to the nvm-installed node. The
e2e image builds are uncached. Comments that cited the old 20-second
test cap now say 60.

Model: opus-5-5
This commit is contained in:
2026-10-06 03:44:35 +00:00
parent 88c79e7e05
commit c28e27d509
26 changed files with 708 additions and 279 deletions
+1 -1
View File
@@ -5,7 +5,7 @@
//
// The browser half of the same claim — that a real Chrome renders that
// string as text and puts no iframe in the popup DOM — is in
// tests/e2e/run.js. This half runs inside the 20-second make test cap.
// tests/e2e/run.js. This half runs inside the 60-second make test cap.
"use strict";
+1 -1
View File
@@ -105,7 +105,7 @@ describe("the flash line the message is shown in", () => {
// "a rejected dust threshold shifts no layout (#233)" and "an over-long
// flash message keeps to one line (#252)" in tests/e2e/run.js, run by
// make test-e2e. They are not in make check because REPO_POLICIES.md
// caps make test at 20 seconds and a browser suite does not fit.
// caps make test at 60 seconds and a browser suite does not fit.
test("reserves its height in the markup", () => {
const flashLine = POPUP_HTML.match(
/<div\s+id="flash-msg"\s+class="([^"]*)"/,
+1 -1
View File
@@ -8,7 +8,7 @@
// node tests/e2e/firefox/run.js [dist/firefox]
//
// Deliberately not part of script/check, and deliberately not named
// *.test.js: REPO_POLICIES.md caps make test at 20 seconds and a browser
// *.test.js: REPO_POLICIES.md caps make test at 60 seconds and a browser
// suite does not fit.
//
// This shares no driver layer with the Chrome suite in tests/e2e/, and the
+1 -1
View File
@@ -4,7 +4,7 @@
//
// This runs inside the pinned Playwright container; see script/test-e2e.
// It is deliberately NOT part of make check — REPO_POLICIES.md caps
// make test at 20 seconds and a browser suite does not fit.
// make test at 60 seconds and a browser suite does not fit.
"use strict";
+1 -1
View File
@@ -4,7 +4,7 @@
//
// A plain runner rather than jest on purpose: jest's default testMatch
// would pull these files into script/test, and browser tests do not fit
// inside the 20-second cap REPO_POLICIES.md puts on make test. Nothing
// inside the 60-second cap REPO_POLICIES.md puts on make test. Nothing
// here is named *.test.js for the same reason.
"use strict";
+2 -2
View File
@@ -12,8 +12,8 @@
// interactive parameters, which the module hardcodes. The parameters are not
// weakened or overridden anywhere in this file — they are pinned by the "key
// derivation cost" tests, since they are the vault's only defence against an
// offline attack on a stolen blob. The suite is kept inside script/test's
// 30-second budget by sharing one encrypted fixture across the tamper cases
// offline attack on a stolen blob. The suite is kept inside the 60-second
// make test cap by sharing one encrypted fixture across the tamper cases
// instead of re-encrypting per test.
const sodium = require("libsodium-wrappers-sumo");