fix: harden workspace registry refresh and snapshots

This commit is contained in:
2026-08-03 22:33:39 +02:00
parent 2087fbb0c9
commit 553bb41138
4 changed files with 312 additions and 42 deletions
+82 -1
View File
@@ -1,5 +1,7 @@
import { execFile } from "node:child_process";
import { existsSync, mkdtempSync, mkdirSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
import {
chmodSync, existsSync, mkdtempSync, mkdirSync, readFileSync, rmSync, symlinkSync, writeFileSync,
} from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { promisify } from "node:util";
@@ -132,3 +134,82 @@ test("rejects a symbolic-link registry root before creating a lock below it", as
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" });
expect(existsSync(join(target, "locks"))).toBe(false);
});
test("rejects a locally-ahead checkout instead of activating local-only content", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const checkout = join(root, "repo");
writeFileSync(join(checkout, "workspaces", "psd-clinical.yaml"), validYaml.replace(
"name: Policlinico San Donato", "name: Local only workspace",
));
await git(checkout, ["config", "user.name", "Workspace Registry Test"]);
await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]);
await git(checkout, ["add", "workspaces/psd-clinical.yaml"]);
await git(checkout, ["commit", "-m", "Local-only workspace"]);
await expect(registry.pull()).rejects.toMatchObject({ code: "git_non_fast_forward" });
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
workspace: { workspace: { name: "Policlinico San Donato" } },
});
});
test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
mkdirSync(join(root, "locks"), { recursive: true });
writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 }));
const registry = new WorkspaceRegistry(config(root, remote.remote));
await expect(registry.bootstrap()).resolves.toMatchObject({
head: remote.initialCommit,
degraded: false,
});
});
test.each(["manifest", "blob", "workspace", "document"])(
"rejects a corrupted %s snapshot component instead of reporting it active",
async (component) => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const snapshot = join(root, "snapshots", remote.initialCommit);
if (component === "manifest") {
const file = join(snapshot, "snapshot.json");
chmodSync(file, 0o600);
writeFileSync(file, "{");
}
if (component === "blob") {
const activePath = join(root, "state", "active.json");
const active = JSON.parse(readFileSync(activePath, "utf8"));
active.revisions[0].blob = "not-a-git-blob";
writeFileSync(activePath, JSON.stringify(active));
}
if (component === "workspace") {
const file = join(snapshot, "psd-clinical.yaml");
chmodSync(file, 0o600);
writeFileSync(file, "truncated");
}
if (component === "document") rmSync(join(snapshot, "psd-clinical.md"));
await expect(registry.list()).rejects.toMatchObject({ code: "workspace_invalid" });
await expect(registry.read("psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" });
},
);
test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md");
chmodSync(document, 0o600);
writeFileSync(document, "corrupt");
rmSync(remote.remote, { recursive: true, force: true });
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
});