fix: harden workspace registry refresh and snapshots
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
import { execFile } from "node:child_process";
|
||||
import { existsSync, mkdtempSync, mkdirSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
|
||||
import {
|
||||
chmodSync, existsSync, mkdtempSync, mkdirSync, readFileSync, rmSync, symlinkSync, writeFileSync,
|
||||
} from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { promisify } from "node:util";
|
||||
@@ -132,3 +134,82 @@ test("rejects a symbolic-link registry root before creating a lock below it", as
|
||||
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" });
|
||||
expect(existsSync(join(target, "locks"))).toBe(false);
|
||||
});
|
||||
|
||||
test("rejects a locally-ahead checkout instead of activating local-only content", async () => {
|
||||
const remote = await fixture();
|
||||
const root = join(remote.root, "registry");
|
||||
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
||||
await registry.bootstrap();
|
||||
const checkout = join(root, "repo");
|
||||
writeFileSync(join(checkout, "workspaces", "psd-clinical.yaml"), validYaml.replace(
|
||||
"name: Policlinico San Donato", "name: Local only workspace",
|
||||
));
|
||||
await git(checkout, ["config", "user.name", "Workspace Registry Test"]);
|
||||
await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]);
|
||||
await git(checkout, ["add", "workspaces/psd-clinical.yaml"]);
|
||||
await git(checkout, ["commit", "-m", "Local-only workspace"]);
|
||||
|
||||
await expect(registry.pull()).rejects.toMatchObject({ code: "git_non_fast_forward" });
|
||||
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
||||
revision: { commit: remote.initialCommit },
|
||||
workspace: { workspace: { name: "Policlinico San Donato" } },
|
||||
});
|
||||
});
|
||||
|
||||
test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => {
|
||||
const remote = await fixture();
|
||||
const root = join(remote.root, "registry");
|
||||
mkdirSync(join(root, "locks"), { recursive: true });
|
||||
writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 }));
|
||||
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
||||
|
||||
await expect(registry.bootstrap()).resolves.toMatchObject({
|
||||
head: remote.initialCommit,
|
||||
degraded: false,
|
||||
});
|
||||
});
|
||||
|
||||
test.each(["manifest", "blob", "workspace", "document"])(
|
||||
"rejects a corrupted %s snapshot component instead of reporting it active",
|
||||
async (component) => {
|
||||
const remote = await fixture();
|
||||
const root = join(remote.root, "registry");
|
||||
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
||||
await registry.bootstrap();
|
||||
const snapshot = join(root, "snapshots", remote.initialCommit);
|
||||
|
||||
if (component === "manifest") {
|
||||
const file = join(snapshot, "snapshot.json");
|
||||
chmodSync(file, 0o600);
|
||||
writeFileSync(file, "{");
|
||||
}
|
||||
if (component === "blob") {
|
||||
const activePath = join(root, "state", "active.json");
|
||||
const active = JSON.parse(readFileSync(activePath, "utf8"));
|
||||
active.revisions[0].blob = "not-a-git-blob";
|
||||
writeFileSync(activePath, JSON.stringify(active));
|
||||
}
|
||||
if (component === "workspace") {
|
||||
const file = join(snapshot, "psd-clinical.yaml");
|
||||
chmodSync(file, 0o600);
|
||||
writeFileSync(file, "truncated");
|
||||
}
|
||||
if (component === "document") rmSync(join(snapshot, "psd-clinical.md"));
|
||||
|
||||
await expect(registry.list()).rejects.toMatchObject({ code: "workspace_invalid" });
|
||||
await expect(registry.read("psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" });
|
||||
},
|
||||
);
|
||||
|
||||
test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => {
|
||||
const remote = await fixture();
|
||||
const root = join(remote.root, "registry");
|
||||
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
||||
await registry.bootstrap();
|
||||
const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md");
|
||||
chmodSync(document, 0o600);
|
||||
writeFileSync(document, "corrupt");
|
||||
rmSync(remote.remote, { recursive: true, force: true });
|
||||
|
||||
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
|
||||
});
|
||||
|
||||
@@ -4,7 +4,7 @@ import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { promisify } from "node:util";
|
||||
import { afterEach, expect, test } from "vitest";
|
||||
import { GitWorkspaceRepository } from "../src/workspaces/git-repository.js";
|
||||
import { GitWorkspaceRepository, WorkspaceRepositoryLock } from "../src/workspaces/git-repository.js";
|
||||
import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js";
|
||||
|
||||
const validYaml = `workspace:
|
||||
@@ -105,3 +105,35 @@ test("redacts failed Git checkout details behind a stable error code", async ()
|
||||
});
|
||||
expect((error as Error).message).not.toContain(remote);
|
||||
});
|
||||
|
||||
test("maps registry-layout failures to a stable redacted error", async () => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-git-layout-"));
|
||||
temporaryRoots.push(root);
|
||||
const file = join(root, "not-a-directory");
|
||||
writeFileSync(file, "occupied");
|
||||
const repository = new GitWorkspaceRepository(config(file, join(root, "remote.git")));
|
||||
|
||||
const error = await repository.bootstrap().catch((error: unknown) => error);
|
||||
|
||||
expect(error).toMatchObject({
|
||||
code: "git_unavailable",
|
||||
message: "Workspace registry storage is unavailable",
|
||||
});
|
||||
expect((error as Error).message).not.toContain(file);
|
||||
});
|
||||
|
||||
test("maps lock filesystem failures to a stable redacted error", async () => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-git-lock-"));
|
||||
temporaryRoots.push(root);
|
||||
const file = join(root, "not-a-directory");
|
||||
writeFileSync(file, "occupied");
|
||||
const lock = new WorkspaceRepositoryLock(file);
|
||||
|
||||
const error = await lock.run(async () => undefined).catch((error: unknown) => error);
|
||||
|
||||
expect(error).toMatchObject({
|
||||
code: "git_unavailable",
|
||||
message: "Workspace registry lock is unavailable",
|
||||
});
|
||||
expect((error as Error).message).not.toContain(file);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user