Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
218 commits
Select commit Hold shift + click to select a range
46a9f1a
test(infrastructure): add deterministic component harnesses
kvinwang Jul 31, 2026
8039bbb
test(plan): define core component acceptance coverage
kvinwang Jul 31, 2026
d3514fe
test(results): promote verified component coverage
kvinwang Jul 31, 2026
ad558d5
docs(testing): account for split product commits
kvinwang Jul 31, 2026
f1d4d91
docs(testing): record product PR split audit
kvinwang Jul 31, 2026
cca2575
docs(testing): account for simulator PR split
kvinwang Jul 31, 2026
b7844cf
docs(testing): retain merged PRs in split inventory
kvinwang Jul 31, 2026
c6b48c4
test(simulator): enforce configured TPM node ownership
kvinwang Jul 31, 2026
804d68e
docs(testing): account for TPM ownership correction
kvinwang Jul 31, 2026
9fb4610
Revert "test(simulator): enforce configured TPM node ownership"
kvinwang Jul 31, 2026
70ebe2f
docs(testing): reject TPM node race tolerance
kvinwang Jul 31, 2026
708d291
docs(testing): add simulator retest watchlist
kvinwang Jul 31, 2026
7f2571e
test(gateway): use existing health and dashboard routes
kvinwang Aug 3, 2026
f4046b2
test(verifier): assert simulator trust-root isolation
kvinwang Aug 4, 2026
4791e9b
test(verifier): validate embedded cache versions
kvinwang Aug 4, 2026
1d8282f
docs(testing): align rewritten PR accounting
kvinwang Aug 4, 2026
a42c047
test(guest): validate normal swap boot lifecycle
kvinwang Aug 4, 2026
246668f
docs(testing): record closed supervisor socket PR
kvinwang Aug 4, 2026
e7c62ed
test(supervisor): validate UDS auto-start lifecycle
kvinwang Aug 4, 2026
ee45a04
test(util): validate certificate outputs independently
kvinwang Aug 4, 2026
297821f
test(supervisor): separate client lifecycle coverage
kvinwang Aug 4, 2026
81e45aa
test(gateway): drop DNS credential encryption assumptions
kvinwang Aug 4, 2026
12e161f
test(gateway): cover app-address DNS failover
kvinwang Aug 5, 2026
23cb480
test(guest): pin wg-checker timing to a uniform 10s clock
kvinwang Aug 5, 2026
1bda1d2
test(vmm): cover filesystem-only CID reload
kvinwang Aug 5, 2026
17a1234
test(gateway): register upgrade domain through admin API
kvinwang Aug 5, 2026
18728bc
test(gateway): provision upgrade domain through certbot
kvinwang Aug 5, 2026
cea8a1c
test(vmm): preserve stopped VM CID on reload
kvinwang Aug 5, 2026
9ca6c9e
test(guest): retarget tc-gos-observabil-003 at the gateway checker
kvinwang Aug 5, 2026
fd0ed30
test(gateway): cover ACME credential rotation
kvinwang Aug 5, 2026
0f72316
test(kms): cover CA persistence and renewal
kvinwang Aug 5, 2026
1bddddc
test(vmm): retarget tc-vmm-serial-006 at log rotation
kvinwang Aug 6, 2026
be33592
test(vmm): cover libvirt network filter lifecycle
kvinwang Aug 6, 2026
d9506f4
test(vmm): wait for restarted netd listener
kvinwang Aug 6, 2026
e8a3d5c
test(vmm): avoid destructive netd readiness probe
kvinwang Aug 6, 2026
11b7a1f
test(vmm): read generated NIC MACs from launch plan
kvinwang Aug 6, 2026
0ac39f8
test(vmm): isolate secondary host API port
kvinwang Aug 6, 2026
58d8aee
test(vmm): inject spoof traffic on the host interface
kvinwang Aug 6, 2026
827a296
test(vmm): preserve failure evidence and force cleanup
kvinwang Aug 6, 2026
4032689
test(vmm): verify filtered network survives QEMU restart
kvinwang Aug 6, 2026
68f4747
test: follow current guest and VMM configuration
kvinwang Aug 7, 2026
2a69862
test(runner): retain sweep failure diagnostics
kvinwang Aug 7, 2026
3f92d6c
test(tdxlab): prepare deterministic run prerequisites
kvinwang Aug 7, 2026
87b2aff
test(tdxlab): provision pinned Foundry tools
kvinwang Aug 7, 2026
18d10b9
test(kms): resolve prepared startup binary
kvinwang Aug 7, 2026
bddb328
test(tdxlab): resolve user toolchain paths
kvinwang Aug 7, 2026
979bd9d
test(kms): accept canonical empty Finish response
kvinwang Aug 7, 2026
9c71e45
test(tdxlab): document prepared execution path
kvinwang Aug 7, 2026
ef1bebf
test(runner): fail sweeps with nonpassing cases
kvinwang Aug 7, 2026
889d6ad
test(gateway): follow current debug config
kvinwang Aug 7, 2026
14d6fb7
test(attestation): prepare legacy TDX image verification
kvinwang Aug 7, 2026
c8872a3
test(attestation): refresh NitroTPM replay fixture
kvinwang Aug 7, 2026
8dd9663
test(guest): retain gateway checker failure context
kvinwang Aug 7, 2026
5964306
test(tdxlab): build candidate guest prerequisites
kvinwang Aug 7, 2026
f12df83
test(tdxlab): build images from a clean worktree
kvinwang Aug 7, 2026
668e1b6
test(tdxlab): discover flavor-specific mkosi outputs
kvinwang Aug 7, 2026
9e2a40d
test(gateway): follow current public RPC route
kvinwang Aug 7, 2026
925ebdf
test(tdxlab): prepare current GCP TPM replay
kvinwang Aug 7, 2026
c44bae7
test(guest): capture gateway checker exit codes safely
kvinwang Aug 7, 2026
67990f4
test(mkosi): prepare ephemeral OpenSSH host keys
kvinwang Aug 7, 2026
363e2e9
test(guest): use deterministic quote output fault
kvinwang Aug 7, 2026
2252fe5
test(guest): use deterministic app-key output fault
kvinwang Aug 7, 2026
0e2dbf3
test(guest): follow atomic random output replacement
kvinwang Aug 7, 2026
ae4ed64
test(guest): use deterministic attestation output fault
kvinwang Aug 7, 2026
3b36bd3
test(guest): use deterministic get-keys output fault
kvinwang Aug 7, 2026
fdf2f9a
test(simulator): prepare platform replay fixtures
kvinwang Aug 7, 2026
ac3b28d
test(gateway): follow current RPC response contracts
kvinwang Aug 7, 2026
cbbd454
test(kms): accept current Empty JSON encoding
kvinwang Aug 7, 2026
de1db3f
test(kms): follow cloned shutdown handle
kvinwang Aug 7, 2026
d898776
test(verifier): follow certificate profile validation
kvinwang Aug 7, 2026
236f5e8
test(verifier): use a valid oneshot config port
kvinwang Aug 7, 2026
eabfa7c
test(vmm): follow missing log response contract
kvinwang Aug 7, 2026
b1b6468
test(vmm): materialize mutable image fixtures
kvinwang Aug 7, 2026
ef8bb69
test(kms): follow current root-key handover
kvinwang Aug 7, 2026
c7e6263
test(gateway): isolate fixture WireGuard subnets
kvinwang Aug 7, 2026
6c9f9c0
test(gateway): follow current public info route
kvinwang Aug 7, 2026
2b6e067
test(gateway): accept current Empty exit response
kvinwang Aug 7, 2026
7ebc614
test(gateway): verify malformed Empty framing
kvinwang Aug 7, 2026
0e64ecc
test(gateway): follow current debug configuration
kvinwang Aug 7, 2026
7dea5ed
test(gateway): follow on-demand TLS key generation
kvinwang Aug 7, 2026
57eec9a
test(gateway): edit prepared TLS paths by section
kvinwang Aug 7, 2026
f82cfac
test(gateway): accept current DNS Empty responses
kvinwang Aug 7, 2026
1c8f341
test(gateway): follow current certificate store suite
kvinwang Aug 7, 2026
7d54fc4
test(vmm): follow private CID state contract
kvinwang Aug 7, 2026
5a8b911
test(vmm): stage reload fixtures across filesystems
kvinwang Aug 7, 2026
74d15d8
test(vmm): prepare management port for config checks
kvinwang Aug 7, 2026
3bf3f3c
test(vmm): follow current UI RPC diagnostics
kvinwang Aug 7, 2026
bac80a3
test(vmm): follow current internal source matrices
kvinwang Aug 7, 2026
195fb44
test(guest): prepare a shell-capable log fixture image
kvinwang Aug 7, 2026
9bd582d
test(guest): capture log fixture preparation diagnostics
kvinwang Aug 7, 2026
cbf3c4e
test(tdxlab): prepare dashboard log workload image
kvinwang Aug 7, 2026
e6b8487
test(tdxlab): bind dashboard preparation to case identity
kvinwang Aug 7, 2026
357674a
test(kms): prepare finalized Ethereum head
kvinwang Aug 7, 2026
998c949
test(integration): follow current gateway admin contract
kvinwang Aug 7, 2026
781b322
test(tdxlab): preserve guest image integrity
kvinwang Aug 7, 2026
6b11cd1
test(integration): bound gateway DNS fixture waits
kvinwang Aug 7, 2026
895faa9
test(integration): accept compatible Exit request evolution
kvinwang Aug 7, 2026
97fde28
style(test): format integration matrix
kvinwang Aug 7, 2026
48d08e8
test(integration): use mock DNS listener port
kvinwang Aug 7, 2026
11020ee
test(fixtures): bind cleanup to prepared state root
kvinwang Aug 7, 2026
e0b732e
test(integration): pin mock DNS zone
kvinwang Aug 7, 2026
7fae5c1
test(tdxlab): preflight Docker daemon
kvinwang Aug 7, 2026
c2965f9
test(integration): model Cloudflare zone discovery
kvinwang Aug 7, 2026
68a0c92
test(tdxlab): prepare user namespaces
kvinwang Aug 7, 2026
e62422c
test(integration): bridge legacy Gateway contracts
kvinwang Aug 7, 2026
cabeefb
test: fix mixed-version gateway failover harness
kvinwang Aug 8, 2026
26cf6c3
test: select live KMS for failover preparation
kvinwang Aug 8, 2026
a42b70f
test: prepare identity matrix alternate image
kvinwang Aug 8, 2026
9a75c33
test: remove unused collateral prerequisite
kvinwang Aug 8, 2026
6eed4c4
test: update KMS compatibility certificate config
kvinwang Aug 8, 2026
426c451
test: follow split VMM restart policy tests
kvinwang Aug 8, 2026
1174ae1
test: resolve Cargo for gateway refresh harness
kvinwang Aug 8, 2026
161186d
test: align VMM QEMU platform matrix
kvinwang Aug 8, 2026
82c2fea
test: follow current VMM networking contract
kvinwang Aug 8, 2026
bd4cadd
test: shorten VMM networking runtime paths
kvinwang Aug 8, 2026
558b69b
test: start bridge VM before launch inspection
kvinwang Aug 8, 2026
d832717
test: prepare VMM hugepage prerequisites
kvinwang Aug 8, 2026
c760bf3
test: exercise VMM hugepage lifecycle
kvinwang Aug 8, 2026
89becb7
test: explicitly start user network VM
kvinwang Aug 8, 2026
9f57e88
test: detach networking case supervisor
kvinwang Aug 8, 2026
5cffa84
test: preserve VMM placement command evidence
kvinwang Aug 8, 2026
a5d8188
test: inspect supervised QEMU launch spec
kvinwang Aug 8, 2026
a72ba70
test: follow attestation suite growth
kvinwang Aug 8, 2026
5c127ce
test: follow current mock attestation CLI
kvinwang Aug 8, 2026
41d3607
test: require both cloud quote matrices
kvinwang Aug 8, 2026
1b14287
test: replace removed verifier matrix selectors
kvinwang Aug 8, 2026
80260ac
test: align verifier coverage with current suites
kvinwang Aug 8, 2026
2db795a
test: prepare isolated Docker subnet pool
kvinwang Aug 8, 2026
fb06251
test: preserve CAA concurrency diagnostics
kvinwang Aug 8, 2026
5df6708
test: follow Gateway CAA operation locking
kvinwang Aug 8, 2026
170f3fd
test: restore current Certbot and auth regressions
kvinwang Aug 8, 2026
2f78ccc
test: follow current Gateway unit matrices
kvinwang Aug 8, 2026
e2b8ec8
test: follow current Gateway port-policy matrix
kvinwang Aug 8, 2026
7a67e6c
test: make Gateway DNS routing fixture deterministic
kvinwang Aug 8, 2026
18a8c61
test: follow removed KMS certificate-log surface
kvinwang Aug 8, 2026
a20b781
test: execute current KMS binary test target
kvinwang Aug 8, 2026
9f1678a
test: prepare seed-matched guest compatibility evidence
kvinwang Aug 8, 2026
52001e7
test: cover KMS signatures and injected Gateway outages
kvinwang Aug 8, 2026
02e5f17
test: select prepared TDX simulator explicitly
kvinwang Aug 8, 2026
805bdba
test: run compatibility evidence without hardware TDX
kvinwang Aug 8, 2026
250bbdf
test: follow verifier certificate profile ownership
kvinwang Aug 8, 2026
3a3a930
test: prepare lease-owned attestation VMM
kvinwang Aug 8, 2026
fd25155
test: separate physical and simulator collateral
kvinwang Aug 8, 2026
b2fa075
test: observe app identity during Gateway outage
kvinwang Aug 8, 2026
0735ca0
test: separate Gateway boot and registration probes
kvinwang Aug 8, 2026
a931c7e
test: exercise Gateway identity fallback
kvinwang Aug 8, 2026
3b91974
test: decouple identity probe from Gateway cache
kvinwang Aug 8, 2026
c3faa0e
test: allow clients without Gateway endpoints
kvinwang Aug 8, 2026
4c3d687
test: run guest compatibility on physical TDX
kvinwang Aug 8, 2026
e3cbeba
test: prepare physical compatibility collateral
kvinwang Aug 8, 2026
377dea3
test(verifier): avoid fixed cc-eventlog test count
kvinwang Aug 8, 2026
51dce1f
test: prepare simulator collateral before guest boot
kvinwang Aug 8, 2026
20c95f3
test: prepare simulated identity image variant
kvinwang Aug 8, 2026
60b2d13
test(simulator): restore SEV-SNP ABI regression coverage
kvinwang Aug 8, 2026
6fa6fdb
test(kms): prepare nested contract dependencies
kvinwang Aug 8, 2026
5307a16
test(kms): probe event audit contract fixtures
kvinwang Aug 8, 2026
93cd8fb
test(kms): probe runtime contract fixtures
kvinwang Aug 8, 2026
47acec9
test(guest): wait for bind conflict cleanup
kvinwang Aug 9, 2026
c99af03
test(gateway): synchronize concurrent renewal requests
kvinwang Aug 9, 2026
47de33b
test(guest): cancel bind conflict restart jobs
kvinwang Aug 9, 2026
de68f2d
test(gateway): prepare allocation wireguard fixture
kvinwang Aug 9, 2026
b2ef123
test(gateway): establish distributed renewal contention
kvinwang Aug 9, 2026
6915516
test(gateway): isolate allocation recycle phase
kvinwang Aug 9, 2026
123e733
test(integration): retry rolling KMS metadata probes
kvinwang Aug 9, 2026
41dc9c9
test(platform): wait for sealing provider recovery
kvinwang Aug 9, 2026
0bc59d6
test(harness): probe lifecycle readiness deterministically
kvinwang Aug 9, 2026
af366ef
test(gateway): align allocation and renewal invariants
kvinwang Aug 9, 2026
5eba870
test(integration): await bounded KMS boot failure
kvinwang Aug 10, 2026
7f3f693
test(gateway): recheck distributed renewal freshness
kvinwang Aug 10, 2026
c6793e7
test(provider): retry transient sealing startup
kvinwang Aug 10, 2026
93cf81d
test(harness): harden runtime readiness probes
kvinwang Aug 10, 2026
172e2db
test(vmm): probe the browser endpoint directly
kvinwang Aug 10, 2026
2e24f69
test(plan): cover post-baseline merged regressions
kvinwang Aug 14, 2026
72cd0bd
test(plan): refresh post-merge harness expectations
kvinwang Aug 14, 2026
88850cc
test(plan): align ACPI measurement matrix
kvinwang Aug 14, 2026
9df1d0e
test(plan): harden dependency-backed harnesses
kvinwang Aug 14, 2026
dffe36e
test(plan): run prepared Playwright offline
kvinwang Aug 14, 2026
a0bc29d
test(plan): make UI browser execution deterministic
kvinwang Aug 14, 2026
969c166
test(plan): preserve expected stargz failures
kvinwang Aug 14, 2026
5d4ea96
test(plan): unmount stale stargz snapshots
kvinwang Aug 14, 2026
2fa623e
test(plan): use persistent stargz storage
kvinwang Aug 14, 2026
c598652
test(plan): wait for stargz unmounts
kvinwang Aug 14, 2026
8e8e74b
test(plan): preserve concurrent pull failures
kvinwang Aug 14, 2026
dea0309
test(plan): deterministically corrupt stargz layer
kvinwang Aug 14, 2026
40c13ab
test(plan): accept truncated stargz diagnostics
kvinwang Aug 14, 2026
e129531
test(plan): assert corrupt stargz rejection by status
kvinwang Aug 14, 2026
2647360
test(plan): assert stargz outages by status
kvinwang Aug 14, 2026
1ed1de4
test(plan): force remote stargz corruption path
kvinwang Aug 14, 2026
78eef1a
test(plan): zero corrupt stargz layer
kvinwang Aug 14, 2026
72cfbd7
test(plan): clear stargz cache before corruption
kvinwang Aug 14, 2026
8c6421d
test(plan): restart registry after layer corruption
kvinwang Aug 14, 2026
a1736ea
test(gateway): cover multi-cluster CVM registration
kvinwang Aug 17, 2026
bcac106
test(gateway): align native multi-cluster rows
kvinwang Aug 17, 2026
7134ff1
test(gateway): verify multi-cluster proxy data paths
kvinwang Aug 17, 2026
ba5feff
test(gateway): harden multi-cluster proxy acceptance
kvinwang Aug 17, 2026
44d71b6
test(vmm): document macvtap connectivity acceptance
kvinwang Aug 17, 2026
8821eba
test(plan): gate tdxlab sweeps on preflight
kvinwang Aug 18, 2026
f40b039
refactor(test): colocate core component suite
kvinwang Aug 18, 2026
104bf14
fix(test): align image provenance with builder metadata
kvinwang Aug 18, 2026
542cd86
test: harden core component coverage
kvinwang Aug 18, 2026
c9c2b34
fix(test): preserve current source fixtures
kvinwang Aug 18, 2026
a697765
test: pin Bun for tdxlab runs
kvinwang Aug 18, 2026
a15a7d4
fix(test): preserve Bun path operations
kvinwang Aug 18, 2026
6e18a28
refactor(test): externalize hardware host configuration
kvinwang Aug 18, 2026
ba227ff
fix(test): resolve configured Docker runner lazily
kvinwang Aug 18, 2026
2c608ae
fix(test): retain guest port reservations for active leases
kvinwang Aug 18, 2026
662a2e9
fix(test): wait for guest API before Gateway startup
kvinwang Aug 18, 2026
b624d3f
fix(test): retry bounded Sysbox recovery
kvinwang Aug 18, 2026
f80e09f
fix(test): make version cleanup independent of caller env
kvinwang Aug 18, 2026
ef5abf0
fix(test): execute gated Cloudflare client tests
kvinwang Aug 18, 2026
494ba26
test(plan): cover changes since PR 841 baseline
kvinwang Aug 25, 2026
fc0bf17
fix(test): align frozen guest RPC coverage
kvinwang Aug 25, 2026
6c616fb
fix(test): record removed RPC evidence schema
kvinwang Aug 25, 2026
1e868da
fix(test): align component matrices with next
kvinwang Aug 25, 2026
67295cb
fix(test): cover declarative OVMF selection
kvinwang Aug 25, 2026
3ea55a8
fix(test): ignore legacy image version metadata
kvinwang Aug 25, 2026
1e7ead1
fix(test): accept explicit gateway fallback rejection
kvinwang Aug 26, 2026
d8cbd45
fix(test): tolerate absent gateway recovery samples
kvinwang Aug 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
26 changes: 26 additions & 0 deletions REUSE.toml
Original file line number Diff line number Diff line change
Expand Up @@ -266,3 +266,29 @@ SPDX-License-Identifier = "CC0-1.0"
path = "dstack/crates/qemu-acpi/fixtures/*.bin"
SPDX-FileCopyrightText = "NONE"
SPDX-License-Identifier = "CC0-1.0"

[[annotations]]
path = "test-suites/catalog/source-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/configuration-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/api-inventory.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/catalog/source-coverage-map.json"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"

[[annotations]]
path = "test-suites/**"
precedence = "aggregate"
SPDX-FileCopyrightText = "© 2026 Phala Network <dstack@phala.network>"
SPDX-License-Identifier = "Apache-2.0"
145 changes: 145 additions & 0 deletions docs/testing/dstack-test-methodology.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,145 @@
<!-- SPDX-FileCopyrightText: © 2026 Phala Network <dstack@phala.network> -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<a id="dstack-test-methodology"></a>
# dstack Test Methodology

This document defines the common process for dstack release testing, from change analysis and risk assessment through execution, evidence collection, and release decisions. See the [test-case authoring specification](test-case-authoring-spec.md#dstack-test-case-authoring-spec) and [report output specification](test-report-output-spec.md#dstack-test-report-output-spec) for normative formats.

<a id="method-objectives"></a>
## 1. Objectives

Testing must produce reproducible, auditable, and traceable release evidence—not merely show that a script once exited successfully. A conclusion must be traceable from a requirement or risk to a case, step, original command evidence, observation, and attachment.

Testing is complete only when:

1. every relevant change, requirement, and material risk has explicit coverage;
2. an executor unfamiliar with the implementation can reproduce each case;
3. the native AI session preserves executed commands and their raw output;
4. simulated and physical-hardware results are reported separately;
5. tools can recompute aggregate status from atomic case results; and
6. references, attachment digests, and statistics are machine-verifiable.

<a id="method-artifacts"></a>
## 2. Artifact layers

Do not mix these four layers:

| Layer | Purpose | Immutable after execution starts |
|---|---|---:|
| Change audit | Establishes changed behavior, dependencies, and risks | Yes |
| Test plan | Defines scope, topology, cases, and execution order | Yes |
| Case specification | Defines preconditions, actions, and expected results | Yes |
| `results/<run-id>/` | Records versions, native sessions, observations, and attachments | No, while running |

A plan uses exactly three semantic levels: chapter, section, and case. Its machine-readable execution order is defined by `index.json`; its top-level `README.md` is the executor's environment guide.

<a id="method-workflow"></a>
## 3. Workflow

### 3.1 Audit the release delta

Compare the previous released tag with the candidate commit. Inspect commits, pull requests, schemas, RPCs, command-line interfaces, configuration defaults, systemd units, image recipes, deployment manifests, migrations, and dependency changes. For every change record:

- the user-visible or operational behavior;
- affected components and interfaces;
- compatibility direction and version combinations;
- failure modes and security impact;
- the requirement and risk IDs used by test cases; and
- whether physical TEE hardware is required.

Generated changelogs alone are insufficient. Follow data and control flow across component boundaries.

### 3.2 Build a risk-based coverage matrix

Classify coverage as:

- **new or changed functionality**: full positive, boundary, and relevant negative coverage;
- **regression**: behavior likely to be affected by shared code, configuration, images, protocols, or lifecycle changes;
- **compatibility**: supported mixed-version combinations and upgrade order;
- **security**: trust boundaries, identity, attestation, key handling, authorization, and secret disclosure;
- **operations**: install, upgrade, restart, recovery, logging, and diagnostics.

Prioritize by impact, likelihood, detectability, and breadth. `P0` covers release-blocking trust, data-loss, availability, or primary-path risks; `P1` covers important supported behavior; `P2` covers lower-risk variants.

### 3.3 Define environments

The plan guide must describe topology, component endpoints, credentials, test data, health checks, concurrency constraints, cleanup, and prohibited operations. Record common software versions once in run-level context. A case records a version override only when it deliberately uses a different component version.

Environment levels are:

- **UNIT**: isolated code-level validation;
- **SIMULATOR**: no-TEE or mock-attestation execution;
- **INTEGRATION**: deployed multi-component system;
- **HARDWARE**: physical supported TEE hardware.

Simulation may follow `docs/development-without-tee.md`; a no-TEE development guest may independently use `key_provider=tpm` when the SGX local key provider is unavailable. This does not run local-key-provider in a TPM mode or cover its SGX behavior. Simulation never proves hardware-specific boot, measurement, attestation, sealing, or device behavior. Such unconfirmed items must be called out separately in the report.

### 3.4 Author and review cases

Each case validates one independently decidable behavior and references at least one requirement or risk. Prefer three to eight logical steps. Every step defines an action and exact observable expected results. Do not write a separate failure criterion: any result that does not fully match the expected result is `FAIL`.

Review the plan for change coverage, regression breadth, compatibility matrices, security boundaries, operational recovery, test-data isolation, and cleanup before execution.

### 3.5 Execute

The `run-plan` orchestration agent must first read the guide, index, and every
case specification. It processes cases in index order, starts an independent
case-agent session for each runnable case, and reads the completed result before
deciding about later cases. It may mark a later case `SKIPPED` without launching
it only when a recorded earlier non-PASS result demonstrably makes the later
case's prerequisite false or its result meaningless. Similarity, expected cost,
or a mere possibility of failure is not sufficient. Independent cases continue.

Each case executor must:

1. read the plan `README.md` and `index.json`;
2. execute cases in index order unless the guide explicitly permits parallelism;
3. start a fresh Codex or Claude session for each case;
4. execute real commands rather than infer outcomes;
5. preserve the native JSONL session as step evidence;
6. write only a shallow atomic `result.json`; and
7. continue to later independent cases after a case-level failure.

The executor name and model are recorded by the runner. Secrets must never be emitted into sessions or artifacts.

<a id="method-status"></a>
## 4. Status model

Case and step status is one of:

- `PASS`: every expected result was fully observed;
- `FAIL`: at least one expected result was not fully observed;
- `BLOCKED`: an external prerequisite prevented the tested behavior from starting;
- `NOT_RUN`: execution was not attempted;
- `SKIPPED`: omission was explicitly authorized and explained.

`PARTIAL` is forbidden. A completed run may contain any terminal case status. A run is `INCOMPLETE` only when required case result artifacts are missing.

Product failure and test-infrastructure failure must be distinguished. A healthy system returning the wrong response is `FAIL`; an unavailable required laboratory host before the tested action begins is `BLOCKED`.

<a id="method-evidence"></a>
## 5. Evidence and traceability

Every logical step must be supported by observed commands and raw output in the native session. Screenshots or other files are attachments, not replacements for command evidence where machine-readable evidence is available. Preserve timestamps, exit codes, stdout, stderr, and tool errors as supplied by the agent CLI.

Use explicit HTML anchors for all chapters, sections, cases, and steps. Do not rely on renderer-specific heading slugs. `index.json` is the authority for ordering and paths; IDs remain stable after publication.

<a id="method-compatibility"></a>
## 6. Compatibility testing

Derive version combinations from supported deployment behavior rather than testing arbitrary permutations. For a rolling upgrade, cover at least:

- latest control-plane services with both previous and latest guest images;
- persisted state created by the previous release and consumed by the candidate;
- protocol/schema defaults when one side omits newly introduced fields;
- upgrade order, restart behavior, and rollback where supported; and
- explicit rejection of unsupported combinations with actionable diagnostics.

For dstack v0.6.0, the expected online topology includes latest VMM, KMS, and gateway components while instances may use a mixture of old and new images.

<a id="method-release-decision"></a>
## 7. Release decision

The final report must provide coverage by requirement and risk, status counts, unresolved failures, blocked or skipped cases, simulation-only results, unconfirmed hardware items, and material deviations from the plan. Release acceptance criteria belong in the plan guide and must state which statuses or open risks block release.

Before publishing, run `dstack-test validate`, render the self-contained HTML report, and package the selected run. The package is an immutable review artifact and must not include secrets or results from unrelated run IDs.
Loading
Loading