v8.1.0 AV surface, session S1. The three poisoned fixture trees (signature-scan/poisoned, memory-scan/poisoned-project, trigger-scan/poisoned) are deleted from disk and materialized into a temp dir by the new tests/helpers/payload-trees.mjs. SIG-matching strings are assembled from fragments, the zero-width carrier comes from String.fromCodePoint, and every file carries the sha256 of the retired on-disk bytes; tests/helpers/payload-trees.test.mjs asserts the materialized trees are byte-identical (mutation-checked: one changed byte fails it). Inline payload literals in signature-scanner, signature-scanner-custom-rules and e2e/scan-pipeline are fragmented the same way; the literal U+200B in attack-simulator, auto-cleaner-rce and auto-cleaner-traversal is replaced by String.fromCodePoint(0x200B). av-surface: a 3->0, a2 3->0, c 5->1, d 5->2, b 9->8 (webshell-b64 blob gone). What remains (c=1, d=2, b) is under examples/** or is (b), both S2. Suite 2261 / 2252 pass / 3 fail (av-surface b, c, d only) / 6 skip. Golden output identical before/after (109/7/4, 61/61). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
33 lines
1.3 KiB
JavaScript
33 lines
1.3 KiB
JavaScript
// payload-trees.test.mjs — the materialized trees are byte-identical to the
|
|
// fixtures that used to sit on disk (sha256 measured before deletion, S1).
|
|
|
|
import { describe, it } from 'node:test';
|
|
import assert from 'node:assert/strict';
|
|
import { readFileSync, readdirSync } from 'node:fs';
|
|
import { join, relative } from 'node:path';
|
|
import { createHash } from 'node:crypto';
|
|
import { PAYLOAD_TREES, materializeTree } from './payload-trees.mjs';
|
|
|
|
function walk(dir) {
|
|
return readdirSync(dir, { withFileTypes: true, recursive: true })
|
|
.filter(e => e.isFile())
|
|
.map(e => join(e.parentPath, e.name));
|
|
}
|
|
|
|
describe('payload-trees: materialized bytes match the retired on-disk fixtures', () => {
|
|
for (const name of Object.keys(PAYLOAD_TREES)) {
|
|
it(name, () => {
|
|
const { dir, cleanup } = materializeTree(name);
|
|
try {
|
|
const written = walk(dir).map(f => relative(dir, f)).sort();
|
|
assert.deepEqual(written, Object.keys(PAYLOAD_TREES[name]).sort(), 'file set changed');
|
|
for (const [rel, { sha256 }] of Object.entries(PAYLOAD_TREES[name])) {
|
|
const got = createHash('sha256').update(readFileSync(join(dir, rel))).digest('hex');
|
|
assert.equal(got, sha256, `${name}/${rel} differs from the retired fixture`);
|
|
}
|
|
} finally {
|
|
cleanup();
|
|
}
|
|
});
|
|
}
|
|
});
|