feat(ql3): export redacted cluster evidence bundle

This commit is contained in:
whyour
2026-08-16 07:07:32 +08:00
parent 7955d55629
commit 4f62a86d15
17 changed files with 1308 additions and 25 deletions
@@ -57,6 +57,8 @@ test('binds the live image gate to native and container-published loopback', ()
assert.match(source, /runConsoleContract\(image\);/);
assert.match(source, /consoleLoopback: true/);
assert.match(source, /consoleAssets: true/);
assert.match(source, /consoleEvidenceBundle: true/);
assert.match(source, /createClusterConsoleEvidenceBundle/);
assert.match(source, /function runPublishedConsoleContract\(image\)/);
assert.match(
source,
@@ -42,7 +42,16 @@ test('keeps the QingLong 3.0 Copilot Console independent and read-only', () => {
],
legacyUiCoupled: false,
kubernetesResident: false,
assetCount: 3,
assetCount: 4,
evidenceBundle: {
lifecycle: 'browser-local-explicit-export',
maximumRecords: 16,
maximumRawBytes: 8 * 1024 * 1024,
maximumBundleBytes: 512 * 1024,
upstreamReadsOnExport: 0,
attestation: 'none',
actionAuthority: 'none',
},
sourceFileCount: 4,
findings: [],
compatible: true,
@@ -128,6 +137,29 @@ test('rejects browser persistence, dynamic rendering and product drift', () => {
);
});
test('rejects evidence export network, persistence and authority widening', () => {
for (const injected of [
'fetch(',
'navigator.share(',
'localStorage',
'setTimeout(',
]) {
const report = auditClusterCopilotConsole({
root,
readFile: intercept(
'packages/ql3-cluster-admin/assets/copilot-console/evidence-bundle.js',
(source) => source + '\n// ' + injected + '\n',
),
});
assert.equal(report.compatible, false);
assert.ok(
report.findings.some(
({ code }) => code === 'CLUSTER_COPILOT_CONSOLE_AUTHORITY_WIDENED',
),
);
}
});
test('rejects coupling into the legacy UI or Kubernetes workloads', () => {
const legacyTarget = 'src/pages/login/index.tsx';
const legacy = auditClusterCopilotConsole({