Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
341 commits
Select commit Hold shift + click to select a range
9921693
test(tdxlab): bind dashboard preparation to case identity
kvinwang Aug 7, 2026
d1dab6a
test(kms): prepare finalized Ethereum head
kvinwang Aug 7, 2026
4485817
test(integration): follow current gateway admin contract
kvinwang Aug 7, 2026
f505892
test(tdxlab): preserve guest image integrity
kvinwang Aug 7, 2026
a5509ac
test(integration): bound gateway DNS fixture waits
kvinwang Aug 7, 2026
ee75439
test(integration): accept compatible Exit request evolution
kvinwang Aug 7, 2026
da4b2fe
style(test): format integration matrix
kvinwang Aug 7, 2026
9d116b4
test(integration): use mock DNS listener port
kvinwang Aug 7, 2026
9205396
test(fixtures): bind cleanup to prepared state root
kvinwang Aug 7, 2026
cd03a84
test(integration): pin mock DNS zone
kvinwang Aug 7, 2026
51107be
test(tdxlab): preflight Docker daemon
kvinwang Aug 7, 2026
0e78d92
test(integration): model Cloudflare zone discovery
kvinwang Aug 7, 2026
c6aea76
test(tdxlab): prepare user namespaces
kvinwang Aug 7, 2026
875b84b
test(integration): bridge legacy Gateway contracts
kvinwang Aug 7, 2026
6481de9
test: fix mixed-version gateway failover harness
kvinwang Aug 8, 2026
b7120f8
test: select live KMS for failover preparation
kvinwang Aug 8, 2026
3192f5c
test: prepare identity matrix alternate image
kvinwang Aug 8, 2026
9ba77f4
test: remove unused collateral prerequisite
kvinwang Aug 8, 2026
dfe0fb8
test: update KMS compatibility certificate config
kvinwang Aug 8, 2026
3048ba3
test: follow split VMM restart policy tests
kvinwang Aug 8, 2026
2060d82
test: resolve Cargo for gateway refresh harness
kvinwang Aug 8, 2026
59e6d57
test: align VMM QEMU platform matrix
kvinwang Aug 8, 2026
a81a6da
test: follow current VMM networking contract
kvinwang Aug 8, 2026
c393664
test: shorten VMM networking runtime paths
kvinwang Aug 8, 2026
d835b13
test: start bridge VM before launch inspection
kvinwang Aug 8, 2026
38f08fe
test: prepare VMM hugepage prerequisites
kvinwang Aug 8, 2026
ed4f34e
test: exercise VMM hugepage lifecycle
kvinwang Aug 8, 2026
cba6661
test: explicitly start user network VM
kvinwang Aug 8, 2026
b1efaf3
test: detach networking case supervisor
kvinwang Aug 8, 2026
46f7940
test: preserve VMM placement command evidence
kvinwang Aug 8, 2026
4b49a57
test: inspect supervised QEMU launch spec
kvinwang Aug 8, 2026
b2dad1f
test: follow attestation suite growth
kvinwang Aug 8, 2026
263088f
test: follow current mock attestation CLI
kvinwang Aug 8, 2026
a048495
test: require both cloud quote matrices
kvinwang Aug 8, 2026
e33ae2e
test: replace removed verifier matrix selectors
kvinwang Aug 8, 2026
09ebd72
test: align verifier coverage with current suites
kvinwang Aug 8, 2026
6809184
test: prepare isolated Docker subnet pool
kvinwang Aug 8, 2026
5367ec3
test: preserve CAA concurrency diagnostics
kvinwang Aug 8, 2026
b603253
test: follow Gateway CAA operation locking
kvinwang Aug 8, 2026
c02a9ca
test: restore current Certbot and auth regressions
kvinwang Aug 8, 2026
f65928e
test: follow current Gateway unit matrices
kvinwang Aug 8, 2026
81eefbf
test: follow current Gateway port-policy matrix
kvinwang Aug 8, 2026
876422d
test: make Gateway DNS routing fixture deterministic
kvinwang Aug 8, 2026
d639c06
test: follow removed KMS certificate-log surface
kvinwang Aug 8, 2026
36b5638
test: execute current KMS binary test target
kvinwang Aug 8, 2026
9d08625
test: prepare seed-matched guest compatibility evidence
kvinwang Aug 8, 2026
b935b62
test: cover KMS signatures and injected Gateway outages
kvinwang Aug 8, 2026
f38f3e4
test: select prepared TDX simulator explicitly
kvinwang Aug 8, 2026
2294d49
test: run compatibility evidence without hardware TDX
kvinwang Aug 8, 2026
44036d2
test: follow verifier certificate profile ownership
kvinwang Aug 8, 2026
af81e54
test: prepare lease-owned attestation VMM
kvinwang Aug 8, 2026
ee71187
test: separate physical and simulator collateral
kvinwang Aug 8, 2026
f2e4e28
test: observe app identity during Gateway outage
kvinwang Aug 8, 2026
727fc03
test: separate Gateway boot and registration probes
kvinwang Aug 8, 2026
902be68
test: exercise Gateway identity fallback
kvinwang Aug 8, 2026
7280690
test: decouple identity probe from Gateway cache
kvinwang Aug 8, 2026
402eed1
test: allow clients without Gateway endpoints
kvinwang Aug 8, 2026
f480593
test: run guest compatibility on physical TDX
kvinwang Aug 8, 2026
d5f81fb
test: prepare physical compatibility collateral
kvinwang Aug 8, 2026
b57038e
test(verifier): avoid fixed cc-eventlog test count
kvinwang Aug 8, 2026
f32a1f4
test: prepare simulator collateral before guest boot
kvinwang Aug 8, 2026
580d4e3
test: prepare simulated identity image variant
kvinwang Aug 8, 2026
b3fc01f
test(simulator): restore SEV-SNP ABI regression coverage
kvinwang Aug 8, 2026
956c0d1
test(kms): prepare nested contract dependencies
kvinwang Aug 8, 2026
d572dd0
test(kms): probe event audit contract fixtures
kvinwang Aug 8, 2026
122eff5
test(kms): probe runtime contract fixtures
kvinwang Aug 8, 2026
f5b786b
test(guest): wait for bind conflict cleanup
kvinwang Aug 9, 2026
c25046e
test(gateway): synchronize concurrent renewal requests
kvinwang Aug 9, 2026
787b6e8
test(guest): cancel bind conflict restart jobs
kvinwang Aug 9, 2026
c831fe8
test(gateway): prepare allocation wireguard fixture
kvinwang Aug 9, 2026
2badaec
test(gateway): establish distributed renewal contention
kvinwang Aug 9, 2026
19b3704
test(gateway): isolate allocation recycle phase
kvinwang Aug 9, 2026
aaf7eb4
test(integration): retry rolling KMS metadata probes
kvinwang Aug 9, 2026
aecba2e
test(platform): wait for sealing provider recovery
kvinwang Aug 9, 2026
56cf4b7
test(harness): probe lifecycle readiness deterministically
kvinwang Aug 9, 2026
f611c47
test(gateway): align allocation and renewal invariants
kvinwang Aug 9, 2026
23bcfeb
test(integration): await bounded KMS boot failure
kvinwang Aug 10, 2026
c6f4a1a
test(gateway): recheck distributed renewal freshness
kvinwang Aug 10, 2026
2edb519
test(provider): retry transient sealing startup
kvinwang Aug 10, 2026
7be0448
test(harness): harden runtime readiness probes
kvinwang Aug 10, 2026
c13c928
test(vmm): probe the browser endpoint directly
kvinwang Aug 10, 2026
869e200
test(plan): cover post-baseline merged regressions
kvinwang Aug 14, 2026
e67a893
test(plan): refresh post-merge harness expectations
kvinwang Aug 14, 2026
55655c2
test(plan): align ACPI measurement matrix
kvinwang Aug 14, 2026
b9105cd
test(plan): harden dependency-backed harnesses
kvinwang Aug 14, 2026
7914f8d
test(plan): run prepared Playwright offline
kvinwang Aug 14, 2026
238b5ab
test(plan): make UI browser execution deterministic
kvinwang Aug 14, 2026
73df1de
test(plan): preserve expected stargz failures
kvinwang Aug 14, 2026
da36d19
test(plan): unmount stale stargz snapshots
kvinwang Aug 14, 2026
6948c40
test(plan): use persistent stargz storage
kvinwang Aug 14, 2026
dd56f6c
test(plan): wait for stargz unmounts
kvinwang Aug 14, 2026
3b05307
test(plan): preserve concurrent pull failures
kvinwang Aug 14, 2026
864a808
test(plan): deterministically corrupt stargz layer
kvinwang Aug 14, 2026
ffee265
test(plan): accept truncated stargz diagnostics
kvinwang Aug 14, 2026
f963e3d
test(plan): assert corrupt stargz rejection by status
kvinwang Aug 14, 2026
16f7d15
test(plan): assert stargz outages by status
kvinwang Aug 14, 2026
0d11659
test(plan): force remote stargz corruption path
kvinwang Aug 14, 2026
b4176bb
test(plan): zero corrupt stargz layer
kvinwang Aug 14, 2026
aadff55
test(plan): clear stargz cache before corruption
kvinwang Aug 14, 2026
80941ed
test(plan): restart registry after layer corruption
kvinwang Aug 14, 2026
5771155
test(gateway): cover multi-cluster CVM registration
kvinwang Aug 17, 2026
01f1a38
test(gateway): align native multi-cluster rows
kvinwang Aug 17, 2026
aaf72a9
test(gateway): verify multi-cluster proxy data paths
kvinwang Aug 17, 2026
4151b94
test(gateway): harden multi-cluster proxy acceptance
kvinwang Aug 17, 2026
06652b9
test(vmm): document macvtap connectivity acceptance
kvinwang Aug 17, 2026
a1fbbff
test(plan): gate tdxlab sweeps on preflight
kvinwang Aug 18, 2026
48cb2d3
refactor(test): colocate core component suite
kvinwang Aug 18, 2026
21ad01c
fix(test): align image provenance with builder metadata
kvinwang Aug 18, 2026
da33b9d
test: harden core component coverage
kvinwang Aug 18, 2026
e1a5331
test: pin Bun for tdxlab runs
kvinwang Aug 18, 2026
1c085c7
fix(test): preserve Bun path operations
kvinwang Aug 18, 2026
88d7d6e
refactor(test): externalize hardware host configuration
kvinwang Aug 18, 2026
6cb0e3b
fix(test): resolve configured Docker runner lazily
kvinwang Aug 18, 2026
4bbcb5e
fix(test): retain guest port reservations for active leases
kvinwang Aug 18, 2026
155754a
fix(test): wait for guest API before Gateway startup
kvinwang Aug 18, 2026
a774de5
fix(test): retry bounded Sysbox recovery
kvinwang Aug 18, 2026
3d4bc1b
fix(test): make version cleanup independent of caller env
kvinwang Aug 18, 2026
e4ec281
fix(test): execute gated Cloudflare client tests
kvinwang Aug 18, 2026
707e72e
test(plan): cover changes since PR 841 baseline
kvinwang Aug 25, 2026
5956864
fix(test): align frozen guest RPC coverage
kvinwang Aug 25, 2026
30110b3
fix(test): record removed RPC evidence schema
kvinwang Aug 25, 2026
5efbbc7
fix(test): align component matrices with next
kvinwang Aug 25, 2026
99f9c95
fix(test): cover declarative OVMF selection
kvinwang Aug 25, 2026
77f3146
fix(test): ignore legacy image version metadata
kvinwang Aug 25, 2026
f56f54c
fix(test): accept explicit gateway fallback rejection
kvinwang Aug 26, 2026
3b56100
fix(test): tolerate absent gateway recovery samples
kvinwang Aug 26, 2026
669870d
test(gateway): cover certbot and gateway changes on next
kvinwang Sep 17, 2026
da4ea41
test(vmm): cover netd, networking, and GPU proxy changes on next
kvinwang Sep 17, 2026
dfc2dac
test(os): cover guest kernel and image changes on next
kvinwang Sep 17, 2026
7956c0f
test(verifier): cover setup-header normalization and cmdline suffix
kvinwang Sep 17, 2026
0a43397
test(guest): cover GPU telemetry, discard, and v1 attestation
kvinwang Sep 17, 2026
a176a70
docs(testing): record next rebase coverage (2026-09-17)
kvinwang Sep 17, 2026
989c9ed
fix(test): run vitest 4 on Node 20 and wait for the shared ACME lock
kvinwang Sep 17, 2026
688f892
fix(test): mirror certbot fixture images into the upgrade registry
kvinwang Sep 17, 2026
cb68d9d
fix(test): align fixture DNS auth, vitest output, and verifier suite …
kvinwang Sep 17, 2026
394b995
test(verifier): cover the canonical setup-header layout
kvinwang Sep 18, 2026
cfc1285
test(vmm): let a run pin the QEMU the VMM launches
kvinwang Sep 18, 2026
25eda73
test(verifier): cover the shipped canonical setup header
kvinwang Sep 18, 2026
cad868c
test: add the adversarial request-contract matrix
kvinwang Sep 20, 2026
39d6fc8
test: make the echo invariant about scaling
kvinwang Sep 20, 2026
e1ff09c
test: address the onboarding listener at the mount the fixture publishes
kvinwang Sep 20, 2026
d713907
test: address the gateway listeners at the mount the fixture publishes
kvinwang Sep 20, 2026
1dfc36e
test: promote the request-contract cases on their tdxlab run
kvinwang Sep 20, 2026
79d88f0
style(test): format the request-contract matrix harness
kvinwang Sep 24, 2026
4674ceb
refactor(test): simplify the request-contract matrix harness
kvinwang Sep 24, 2026
80fbe8b
docs(test): trim the request-contract case prose
kvinwang Sep 24, 2026
c085910
test: add a guest-agent concurrency and robustness harness
kvinwang Sep 20, 2026
41383de
test: add the guest-agent concurrency and robustness cases
kvinwang Sep 20, 2026
8bfd013
test: tolerate an unreadable fd table
kvinwang Sep 20, 2026
952d4e0
test: promote the guest-agent robustness cases on their tdxlab run
kvinwang Sep 20, 2026
fdda440
test: name the restart that the concurrency-002 drops actually were
kvinwang Sep 20, 2026
3c3e47d
refactor(test): trim the guest-agent robustness harness and case prose
kvinwang Sep 24, 2026
08860c3
style(test): put the robustness case docstrings in the imperative mood
kvinwang Sep 24, 2026
eef0a76
style(test): put the request-contract harness docstrings in the imper…
kvinwang Sep 24, 2026
73b6b06
chore(test): restore files reordered by the next rebase
kvinwang Sep 25, 2026
9e81744
test(vmm): gate the installer's temporary checkout cleanup
kvinwang Sep 25, 2026
19460e7
test(guest): expect escaped backslashes in the systemd env file
kvinwang Sep 25, 2026
aa05438
test(supervisor): cover clear semantics, exit codes, socket mode, and…
kvinwang Sep 25, 2026
e669d3c
test(guest-agent): refuse certificate validity bounds past year 9999
kvinwang Sep 25, 2026
a3862d8
test(vmm): retire the OCI registry pull cases and fixture
kvinwang Sep 25, 2026
9e127d6
test(vmm): cover the hotplug, event-name, and preallocation config de…
kvinwang Sep 25, 2026
81359bd
test(vmm): cover zero-resource refusal and disk preallocation on Crea…
kvinwang Sep 25, 2026
5fd8170
test(vmm): cover port mapping policy and no partial writes on UpdateVm
kvinwang Sep 25, 2026
7134e2f
test(vmm): refuse re-enabling discard on a preallocated VM update
kvinwang Sep 25, 2026
c55c1f8
test(guest-agent): cover Info with public_tcbinfo off on both surfaces
kvinwang Sep 25, 2026
36197c3
test(dstack-util): cover include: refusal and the hardened host-share…
kvinwang Sep 25, 2026
b752ec3
test(vmm): cover vmm-cli TLS verification and owner-only local state
kvinwang Sep 25, 2026
149bff4
test(guest): assert the storage-encrypted and os-image-hash runtime e…
kvinwang Sep 25, 2026
74941af
test(verifier): measure GPU topology with hotplug off and reject it on
kvinwang Sep 25, 2026
52a0fb8
test(guest): cover owner-only boot secrets and env delivery by exec-w…
kvinwang Sep 25, 2026
d79407f
test(vmm): cover the one-shot compose preview of a multi-byte compose
kvinwang Sep 25, 2026
135b059
test(os): assert the boot-chain unit edges added on next
kvinwang Sep 25, 2026
a31c740
test(verifier): follow image download retries and the removed debug path
kvinwang Sep 25, 2026
675f4bf
test(os): check terminal presets and build-time rootfs tmpfiles on th…
kvinwang Sep 25, 2026
2f8bc15
test(gateway): install the proxy certificate through Admin.ImportCert
kvinwang Sep 25, 2026
69a5f89
test(os): require the NTS-only chrony policy in mkosi guests
kvinwang Sep 25, 2026
199d563
test(verifier): cover the collateral host allowlist key and download …
kvinwang Sep 25, 2026
e882f02
test(os): require the volatile journald budget shipped in the image
kvinwang Sep 25, 2026
336080a
test(vmm): bind the resource, GPU, update, and preallocation unit rows
kvinwang Sep 25, 2026
ba64f14
test(gateway): assert the public app-info route honors public_tcbinfo
kvinwang Sep 25, 2026
5c2f29e
test(kms): expect the eight-row authorization freshness matrix
kvinwang Sep 25, 2026
fd63692
test(kms): cover key handover on the admin listener
kvinwang Sep 25, 2026
48b222e
test(kms): cover image-verification visibility, auth API bounds, and …
kvinwang Sep 25, 2026
5badba6
test(kms): run the zero-value DstackApp policy test
kvinwang Sep 25, 2026
fd0d245
test(gateway): require registration bursts to reach the applied WireG…
kvinwang Sep 25, 2026
4eb3fac
test(verifier): follow the in-process image manifest check and cache …
kvinwang Sep 25, 2026
8ad91ae
test(gateway): run the routing-lock regression tests in tc-gw-cluster…
kvinwang Sep 25, 2026
0a387f6
test(dstack-util): require the data disk to leave the initializing label
kvinwang Sep 25, 2026
3b6cec3
test(guest): record the MR config and GPU event expectations from next
kvinwang Sep 25, 2026
ede121e
test(integration): run the renamed verifier manifest policy test
kvinwang Sep 25, 2026
644a98a
test(guest): allow the simulator collateral host in tpm-verify
kvinwang Sep 25, 2026
b024bce
test(kms): deny on an empty auth-simple device allowlist
kvinwang Sep 25, 2026
7253f6f
test(kms): refuse an unknown MOCK_POLICY in auth-mock
kvinwang Sep 25, 2026
1956cb7
test(kms): check that both auth-eth backends read one decision from o…
kvinwang Sep 25, 2026
40056ca
test(os): check early mount options, verity panic policy, and shipped…
kvinwang Sep 25, 2026
d7993d5
test(gateway): refuse own-id WaveKV envelopes and pin the peer timeou…
kvinwang Sep 25, 2026
bbe74d9
test(gateway): send normalized-domain payloads to ForceReleaseCertLoc…
kvinwang Sep 25, 2026
ab7f6f0
test(kms): check the identity SignCert stamps into the app leaf
kvinwang Sep 25, 2026
0e14919
test(vmm): cover the preallocation select and local-only images panel…
kvinwang Sep 25, 2026
3b40b9d
test(gateway): keep startup off ACME and release locks under any doma…
kvinwang Sep 25, 2026
bc74b9e
test(vmm): require pinned console dependencies in the web UI case
kvinwang Sep 25, 2026
1b89bb2
test(gateway): redact a DNS token with multi-byte characters on both …
kvinwang Sep 25, 2026
5a87599
test(kms): cover auto-bootstrap over existing and partial root keys
kvinwang Sep 25, 2026
02f4dfa
test(certbot): cover owner-only keys, atomic publication, key rotatio…
kvinwang Sep 25, 2026
a9ea500
test(kms): gate locked image builds, the pinned onboarding script, an…
kvinwang Sep 25, 2026
1d11ec2
test(vmm): require the installer to build dstackup with --locked
kvinwang Sep 25, 2026
dc2349e
test(kms): record SEV-SNP and Nitro Enclave identity changes in block…
kvinwang Sep 25, 2026
e141d79
test(verifier): cover dstack-mr diagnose, the XLF initrd ceiling, and…
kvinwang Sep 25, 2026
e11a022
test(gateway): cover SNI validation, large ClientHellos and the 53-by…
kvinwang Sep 25, 2026
66c2d76
test(gateway): require the PROXY header abort tests by name
kvinwang Sep 25, 2026
b4578dc
test(verifier): run the SEV-SNP and TPM input bound tests by name
kvinwang Sep 25, 2026
9670859
test(verifier): cover --verify-cert validity and stop pinning the ra-…
kvinwang Sep 25, 2026
9dd2186
test(gateway): hold the connection limit under a simultaneous burst
kvinwang Sep 25, 2026
5fb164e
test(kms): expect the eight-row upgrade authority matrix
kvinwang Sep 25, 2026
c89fcd0
test(verifier): follow the dstack-attest suite sizes
kvinwang Sep 25, 2026
3079b90
test(rpc): bound error text and forbid forged log lines in the contra…
kvinwang Sep 25, 2026
18b02f9
test(kms): note the admin onboarding flow that tc-kms-onboard-005 dep…
kvinwang Sep 25, 2026
1c670ce
test(gateway): wait for the restarted admin listener before restoring…
kvinwang Sep 25, 2026
a805c71
docs(test): allow the local collateral host in the simulator verifier…
kvinwang Sep 25, 2026
20709e2
Merge branch 'pr841-cov0924-vmm' into pr841-rebase-20260924
kvinwang Sep 25, 2026
dff44ff
Merge branch 'pr841-cov0924-kms' into pr841-rebase-20260924
kvinwang Sep 25, 2026
35bdd87
Merge branch 'pr841-cov0924-gw' into pr841-rebase-20260924
kvinwang Sep 25, 2026
99c6d1e
Merge branch 'pr841-cov0924-ver' into pr841-rebase-20260924
kvinwang Sep 25, 2026
9e076c1
test(kms): drop duplicate auth-010 coverage labels from the merge
kvinwang Sep 25, 2026
a7bebea
test(catalog): align inventories with next at 0fb3b24bbd
kvinwang Sep 25, 2026
81b57dc
docs(testing): record next rebase coverage (2026-09-24)
kvinwang Sep 25, 2026
e289a1a
style(test): sort imports in two harnesses as the ruff hook expects
kvinwang Sep 25, 2026
b64d9dc
docs(testing): link the rootless mkosi and WireGuard apply fixes
kvinwang Sep 25, 2026
f02b8e3
test(guest-agent): read the certificate notAfter on cryptography < 42
kvinwang Sep 25, 2026
1192729
test(fixtures): wait for the whole simulator process group on stop
kvinwang Sep 25, 2026
b5a500d
test(guest-agent): keep head-of-line observations when the step fails
kvinwang Sep 25, 2026
af7c332
test(kms): import os in the runtime-004 mock RPC and report its failures
kvinwang Sep 25, 2026
9ef34d6
test(os): wait for app-compose before repeating Tappd after an agent …
kvinwang Sep 25, 2026
8e5f792
test(guest-agent): ramp the head-of-line loaders past the slirp backlog
kvinwang Sep 25, 2026
9182c06
test(os): settle the data pool before the telemetry disk baseline
kvinwang Sep 25, 2026
5df321f
test(os): keep the mount-option set from shadowing the module options
kvinwang Sep 25, 2026
738c961
test(verifier): pin --hotplug-off in the shared dstack-mr matrix
kvinwang Sep 25, 2026
7a99895
test(gateway): wait for the debug listener before reading restored sy…
kvinwang Sep 25, 2026
d05e71e
test(os): wait for the swap lease guest to stop before starting it again
kvinwang Sep 25, 2026
23fef95
test(os): give the stargz lifecycle case the budget its own steps allow
kvinwang Sep 25, 2026
bda46dc
test(os): corrupt the stargz marker payload rather than the blob midp…
kvinwang Sep 25, 2026
d48cf4b
test(integration): reserve KMS matrix host ports across concurrent cases
kvinwang Sep 25, 2026
4359646
test(integration): prove the candidate Gateway loaded legacy WaveKV rows
kvinwang Sep 25, 2026
48cc82b
style(test): format the dstack-mr matrix harness
kvinwang Sep 25, 2026
8b4f869
style(test): keep harness docstring summaries on one line
kvinwang Sep 25, 2026
240ed49
docs(testing): record the product fixes found on hardware
kvinwang Sep 25, 2026
83bce9c
test(gateway): promote tc-gw-admin-037 and record the hardware valida…
kvinwang Sep 25, 2026
227e492
test(os): check the runtime keystore mode now that #1331 is reverted
kvinwang Sep 26, 2026
0a758b0
test(kms): promote tc-kms-onboard-005 now that #1406 is merged
kvinwang Sep 26, 2026
29f5fdb
docs(testing): record the validation of the merged product fixes
kvinwang Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
26 changes: 26 additions & 0 deletions REUSE.toml
Original file line number Diff line number Diff line change
Expand Up @@ -267,3 +267,29 @@ SPDX-License-Identifier = "CC0-1.0"
path = "dstack/crates/qemu-acpi/fixtures/*.bin"
SPDX-FileCopyrightText = "NONE"
SPDX-License-Identifier = "CC0-1.0"

[[annotations]]
path = "test-suites/catalog/source-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/configuration-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/api-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/source-coverage-map.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/**"
precedence = "aggregate"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"
145 changes: 145 additions & 0 deletions docs/testing/dstack-test-methodology.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,145 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="dstack-test-methodology"></a>
# dstack Test Methodology

This document defines the common process for dstack release testing, from change analysis and risk assessment through execution, evidence collection, and release decisions. See the [test-case authoring specification](test-case-authoring-spec.md#dstack-test-case-authoring-spec) and [report output specification](test-report-output-spec.md#dstack-test-report-output-spec) for normative formats.

<a id="method-objectives"></a>
## 1. Objectives

Testing must produce reproducible, auditable, and traceable release evidence—not merely show that a script once exited successfully. A conclusion must be traceable from a requirement or risk to a case, step, original command evidence, observation, and attachment.

Testing is complete only when:

1. every relevant change, requirement, and material risk has explicit coverage;
2. an executor unfamiliar with the implementation can reproduce each case;
3. the native AI session preserves executed commands and their raw output;
4. simulated and physical-hardware results are reported separately;
5. tools can recompute aggregate status from atomic case results; and
6. references, attachment digests, and statistics are machine-verifiable.

<a id="method-artifacts"></a>
## 2. Artifact layers

Do not mix these four layers:

| Layer | Purpose | Immutable after execution starts |
|---|---|---:|
| Change audit | Establishes changed behavior, dependencies, and risks | Yes |
| Test plan | Defines scope, topology, cases, and execution order | Yes |
| Case specification | Defines preconditions, actions, and expected results | Yes |
| `results/<run-id>/` | Records versions, native sessions, observations, and attachments | No, while running |

A plan uses exactly three semantic levels: chapter, section, and case. Its machine-readable execution order is defined by `index.json`; its top-level `README.md` is the executor's environment guide.

<a id="method-workflow"></a>
## 3. Workflow

### 3.1 Audit the release delta

Compare the previous released tag with the candidate commit. Inspect commits, pull requests, schemas, RPCs, command-line interfaces, configuration defaults, systemd units, image recipes, deployment manifests, migrations, and dependency changes. For every change record:

- the user-visible or operational behavior;
- affected components and interfaces;
- compatibility direction and version combinations;
- failure modes and security impact;
- the requirement and risk IDs used by test cases; and
- whether physical TEE hardware is required.

Generated changelogs alone are insufficient. Follow data and control flow across component boundaries.

### 3.2 Build a risk-based coverage matrix

Classify coverage as:

- **new or changed functionality**: full positive, boundary, and relevant negative coverage;
- **regression**: behavior likely to be affected by shared code, configuration, images, protocols, or lifecycle changes;
- **compatibility**: supported mixed-version combinations and upgrade order;
- **security**: trust boundaries, identity, attestation, key handling, authorization, and secret disclosure;
- **operations**: install, upgrade, restart, recovery, logging, and diagnostics.

Prioritize by impact, likelihood, detectability, and breadth. `P0` covers release-blocking trust, data-loss, availability, or primary-path risks; `P1` covers important supported behavior; `P2` covers lower-risk variants.

### 3.3 Define environments

The plan guide must describe topology, component endpoints, credentials, test data, health checks, concurrency constraints, cleanup, and prohibited operations. Record common software versions once in run-level context. A case records a version override only when it deliberately uses a different component version.

Environment levels are:

- **UNIT**: isolated code-level validation;
- **SIMULATOR**: no-TEE or mock-attestation execution;
- **INTEGRATION**: deployed multi-component system;
- **HARDWARE**: physical supported TEE hardware.

Simulation may follow `docs/development-without-tee.md`; a no-TEE development guest may independently use `key_provider=tpm` when the SGX local key provider is unavailable. This does not run local-key-provider in a TPM mode or cover its SGX behavior. Simulation never proves hardware-specific boot, measurement, attestation, sealing, or device behavior. Such unconfirmed items must be called out separately in the report.

### 3.4 Author and review cases

Each case validates one independently decidable behavior and references at least one requirement or risk. Prefer three to eight logical steps. Every step defines an action and exact observable expected results. Do not write a separate failure criterion: any result that does not fully match the expected result is `FAIL`.

Review the plan for change coverage, regression breadth, compatibility matrices, security boundaries, operational recovery, test-data isolation, and cleanup before execution.

### 3.5 Execute

The `run-plan` orchestration agent must first read the guide, index, and every
case specification. It processes cases in index order, starts an independent
case-agent session for each runnable case, and reads the completed result before
deciding about later cases. It may mark a later case `SKIPPED` without launching
it only when a recorded earlier non-PASS result demonstrably makes the later
case's prerequisite false or its result meaningless. Similarity, expected cost,
or a mere possibility of failure is not sufficient. Independent cases continue.

Each case executor must:

1. read the plan `README.md` and `index.json`;
2. execute cases in index order unless the guide explicitly permits parallelism;
3. start a fresh Codex or Claude session for each case;
4. execute real commands rather than infer outcomes;
5. preserve the native JSONL session as step evidence;
6. write only a shallow atomic `result.json`; and
7. continue to later independent cases after a case-level failure.

The executor name and model are recorded by the runner. Secrets must never be emitted into sessions or artifacts.

<a id="method-status"></a>
## 4. Status model

Case and step status is one of:

- `PASS`: every expected result was fully observed;
- `FAIL`: at least one expected result was not fully observed;
- `BLOCKED`: an external prerequisite prevented the tested behavior from starting;
- `NOT_RUN`: execution was not attempted;
- `SKIPPED`: omission was explicitly authorized and explained.

`PARTIAL` is forbidden. A completed run may contain any terminal case status. A run is `INCOMPLETE` only when required case result artifacts are missing.

Product failure and test-infrastructure failure must be distinguished. A healthy system returning the wrong response is `FAIL`; an unavailable required laboratory host before the tested action begins is `BLOCKED`.

<a id="method-evidence"></a>
## 5. Evidence and traceability

Every logical step must be supported by observed commands and raw output in the native session. Screenshots or other files are attachments, not replacements for command evidence where machine-readable evidence is available. Preserve timestamps, exit codes, stdout, stderr, and tool errors as supplied by the agent CLI.

Use explicit HTML anchors for all chapters, sections, cases, and steps. Do not rely on renderer-specific heading slugs. `index.json` is the authority for ordering and paths; IDs remain stable after publication.

<a id="method-compatibility"></a>
## 6. Compatibility testing

Derive version combinations from supported deployment behavior rather than testing arbitrary permutations. For a rolling upgrade, cover at least:

- latest control-plane services with both previous and latest guest images;
- persisted state created by the previous release and consumed by the candidate;
- protocol/schema defaults when one side omits newly introduced fields;
- upgrade order, restart behavior, and rollback where supported; and
- explicit rejection of unsupported combinations with actionable diagnostics.

For dstack v0.6.0, the expected online topology includes latest VMM, KMS, and gateway components while instances may use a mixture of old and new images.

<a id="method-release-decision"></a>
## 7. Release decision

The final report must provide coverage by requirement and risk, status counts, unresolved failures, blocked or skipped cases, simulation-only results, unconfirmed hardware items, and material deviations from the plan. Release acceptance criteria belong in the plan guide and must state which statuses or open risks block release.

Before publishing, run `dstack-test validate`, render the self-contained HTML report, and package the selected run. The package is an immutable review artifact and must not include secrets or results from unrelated run IDs.
Loading
Loading