fix(ci): align lint-safe security paths

This commit is contained in:
elky
2026-09-05 03:19:53 +08:00
parent f5e1420ee6
commit 33d5cd5993
45 changed files with 180 additions and 132 deletions
@@ -39,7 +39,6 @@ use aether_scheduler_core::SchedulerRequestCandidateStatusUpdate;
use aether_usage_runtime::{
build_lifecycle_usage_seed, build_stream_terminal_usage_payload_seed,
build_terminal_usage_context_seed, stream_report_represents_failure,
DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES,
};
use base64::Engine as _;
use serde_json::Value;
@@ -433,8 +432,7 @@ impl AttemptBodyCapture {
if bytes.is_empty() || self.truncated {
return;
}
let max_bytes = DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES
.min(crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES);
let max_bytes = crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES;
if self.buffer.len() >= max_bytes {
self.truncated = true;
return;
@@ -448,10 +446,7 @@ impl AttemptBodyCapture {
}
pub(crate) fn encode(&self) -> (Option<String>, Option<UsageBodyCaptureState>) {
self.encode_with_limit(
DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES
.min(crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES),
)
self.encode_with_limit(crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES)
}
fn encode_with_limit(
@@ -1435,8 +1430,7 @@ mod stage_tests {
#[test]
fn body_capture_encodes_inline_and_empty_states() {
assert_eq!(
super::DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES
.min(crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES),
crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES,
crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES
);
@@ -585,7 +585,7 @@ fn harden_execution_runtime_socket(
// runners. The validated canonical parent and inode identity still
// close the replacement window without relying on that differing
// device number.
|| (cfg!(target_os = "linux") && metadata.ino() != stat.st_ino as u64)
|| (cfg!(target_os = "linux") && metadata.ino() != stat.st_ino)
{
return Err(io::Error::new(
io::ErrorKind::PermissionDenied,
@@ -25,7 +25,6 @@ use aether_usage_runtime::{
build_lifecycle_usage_seed, build_stream_terminal_usage_payload_seed,
build_sync_terminal_usage_payload_seed, build_terminal_usage_context_seed, LifecycleUsageSeed,
SyncTerminalUsagePayloadSeed, TerminalUsageContextSeed, UsageRequestRecordLevel,
DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES,
};
use async_stream::stream;
use axum::body::{Body, Bytes};
@@ -399,8 +398,7 @@ fn direct_passthrough_mode() -> DirectPassthroughMode {
fn stream_body_buffer_limit_for_record_level(record_level: UsageRequestRecordLevel) -> usize {
match record_level {
UsageRequestRecordLevel::Basic => BASIC_STREAM_BODY_ANALYSIS_LIMIT_BYTES,
UsageRequestRecordLevel::Full => DEFAULT_USAGE_RESPONSE_BODY_CAPTURE_LIMIT_BYTES
.min(crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES),
UsageRequestRecordLevel::Full => crate::execution_runtime::MAX_STREAM_BODY_CAPTURE_BYTES,
}
}