test: strengthen evidence runtime handoff coverage

This commit is contained in:
2026-08-09 19:46:47 +02:00
parent 36fbd58277
commit 64b778ade9
2 changed files with 98 additions and 19 deletions
+47 -1
View File
@@ -141,7 +141,7 @@ async function fixture(workspaceSource = filesystemWorkspace) {
};
for (const [name, value] of Object.entries(environment)) vi.stubEnv(name, value);
vi.stubEnv("THT_HOME", join(root, "home"));
return { root, dataRoot, secretRoot, registry, registryConfig, revision };
return { root, source, dataRoot, secretRoot, registry, registryConfig, revision };
}
function runnerFor(f: Awaited<ReturnType<typeof fixture>>): ThtRunner {
@@ -234,6 +234,52 @@ test("separate runtime leases hand off byte-identical revision Evidence configs
}
});
test("real Evidence-content-only commit changes runtime identity and root with identical descriptor YAML", async () => {
const f = await fixture();
const runner = runnerFor(f);
const first = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const descriptorBefore = readFileSync(f.revision.snapshotPath, "utf8");
writeFileSync(
join(f.source, "workspace-content", "psd-clinical", "evidence", "guide.md"),
"# Content-only revision two\n",
);
await git(f.source, ["add", "workspace-content/psd-clinical/evidence/guide.md"]);
await git(f.source, ["commit", "-m", "Update Evidence content only"]);
await git(f.source, ["push", "origin", "main"]);
await f.registry.pull();
const current = (await f.registry.list())[0];
const second = runner.acquireWorkspaceRuntime(current.snapshotPath);
try {
expect(current.commit).not.toBe(f.revision.commit);
expect(current.blob).toBe(f.revision.blob);
expect(readFileSync(current.snapshotPath, "utf8")).toBe(descriptorBefore);
const firstRendered = parse(readFileSync(first.path, "utf8"));
const secondRendered = parse(readFileSync(second.path, "utf8"));
expect(firstRendered.runtime_identity.workspace_revision).toBe(f.revision.commit);
expect(secondRendered.runtime_identity.workspace_revision).toBe(current.commit);
expect(secondRendered.evidence.sources[0].root).toBe(join(
f.registryConfig.root,
"snapshots",
current.commit,
"workspace-content",
"psd-clinical",
"evidence",
));
expect(secondRendered.evidence.sources[0].root).not.toBe(firstRendered.evidence.sources[0].root);
for (const lease of [first, second]) {
await expect(runFile(thtBin, ["config", "check", "-c", lease.path], {
cwd: harnessDir,
env: { ...process.env, THT_HOME: join(f.root, "home") },
})).resolves.toBeDefined();
}
} finally {
first.release();
second.release();
}
});
test("signed HTTP Evidence resolves its file binding and config check never captures its contents", async () => {
const f = await fixture(evidenceWorkspace(` type: http
uris: [https://evidence.example.test/guide.md]