diff --git a/.github/workflows/deployment.yml b/.github/workflows/deployment.yml index 48ebd168..803cb1b8 100644 --- a/.github/workflows/deployment.yml +++ b/.github/workflows/deployment.yml @@ -64,6 +64,11 @@ jobs: run: | bash scripts/test-server-pi-state-topology.sh bash scripts/unified-deployment-smoke.sh --self-test + - name: Install harness CLI for backend integration tests + working-directory: harness + run: | + python3 -m venv .venv + .venv/bin/python -m pip install -e . - name: Install backend dependencies working-directory: backend run: npm ci diff --git a/backend/scripts/verify-workspace-descriptor-files.mjs b/backend/scripts/verify-workspace-descriptor-files.mjs index 05e55356..7f5fbfd8 100755 --- a/backend/scripts/verify-workspace-descriptor-files.mjs +++ b/backend/scripts/verify-workspace-descriptor-files.mjs @@ -31,8 +31,8 @@ const reviewedExpandableBlocks = new Map([ { sha256: "40b8a10a3c06aaa98e324fbf688b7d1f5cead330d7ba7eef98e06256d412a85a", rationale: "Generates the reviewed restore safety manifest." }, ]], ["scripts/test-windows-clone-contract.ps1", [ - { sha256: "80f4880576a0679cb58e7b92600e7a90550c93c254553a2d4b299539f9ff0bcf", rationale: "Generates reviewed Windows clone test configuration." }, - { sha256: "6166294bdc8a8bf6436ad402bcbf7cae0f3b67dc6051cecfcca79267a62b082c", rationale: "Same reviewed block in the repository-required CRLF checkout representation." }, + { sha256: "3204f772d33cad42bcac99191507051aefb2c91d2935bec6698b956e44f9bf45", rationale: "Generates reviewed Windows clone test configuration with its authentication configuration root." }, + { sha256: "f4814d842a7502b7ef30fd6b224d5cb17b0ffd6fb2367c41c49ac16587536d93", rationale: "Same reviewed block in the repository-required CRLF checkout representation." }, { sha256: "8db9ab0ee3580399f311fe7a24d4ea97105873b8a2d41e34a1ec64302d86bee2", rationale: "Generates the reviewed Windows Compose override with a braced remote path." }, { sha256: "5afbeb3de5b89f978ef00b15f52e0066147bbfb8f6c9d1b7e081f4a1571ab204", rationale: "Same reviewed Compose override in the repository-required CRLF checkout representation." }, { sha256: "5d0d1a3fc45e99b3aacaf4ee5dd09a6bee1937784375dfe4bcfaa4ae32cfb9de", rationale: "Generates reviewed Windows clone test configuration." }, diff --git a/backend/test/workspace-registry-deployment.test.ts b/backend/test/workspace-registry-deployment.test.ts index 3c205843..2beb60c9 100644 --- a/backend/test/workspace-registry-deployment.test.ts +++ b/backend/test/workspace-registry-deployment.test.ts @@ -293,6 +293,7 @@ test("Windows clone contract copies the shared complete schema v3 descriptor int expect(windows).toContain('thoth-workspaces.yaml'); expect(windows).toContain('$workspaceDestination = Join-Path $workspaceDirectory "workspace.yaml"'); expect(windows).toContain('Join-Path $workspaceEvidence "guide.md"'); + expect(windows).toContain('THT_AUTH_CONFIG_ROOT=$authConfigRoot'); expect(windows).not.toContain('schema_version: 3'); expect(descriptor).toMatchObject({ workspace: { diff --git a/scripts/test-verify-schema-v3-only.sh b/scripts/test-verify-schema-v3-only.sh index 0b675a2d..9e74b436 100755 --- a/scripts/test-verify-schema-v3-only.sh +++ b/scripts/test-verify-schema-v3-only.sh @@ -577,6 +577,10 @@ expect_rejected "nested workspace fixture" "scripts/fixtures/nested/deeper/works # Python bytecode is disabled before pre-gate docs, and release dry-run starts with bootstrap trust. grep -Fq 'PYTHONDONTWRITEBYTECODE: "1"' "$project_root/.github/workflows/deployment.yml" \ || fail "workflow does not disable Python bytecode" +grep -Fq 'python3 -m venv .venv' "$project_root/.github/workflows/deployment.yml" \ + || fail "workflow does not install the real harness CLI before backend integration tests" +grep -Fq '.venv/bin/python -m pip install -e .' "$project_root/.github/workflows/deployment.yml" \ + || fail "workflow does not install the harness package into its canonical virtual environment" grep -Fq 'export PYTHONDONTWRITEBYTECODE=1' "$project_root/scripts/verify-schema-v3-only-release.sh" \ || fail "release wrapper does not disable Python bytecode" release_plan="$($gate_bash "$project_root/scripts/verify-schema-v3-only-release.sh" --dry-run)" diff --git a/scripts/test-windows-clone-contract.ps1 b/scripts/test-windows-clone-contract.ps1 index 37d72d53..ff5561bf 100644 --- a/scripts/test-windows-clone-contract.ps1 +++ b/scripts/test-windows-clone-contract.ps1 @@ -142,10 +142,12 @@ try { $piAuth = Join-Path $fixtureRoot "Pi Auth/pi-auth.json" $secrets = Join-Path $fixtureRoot "Secrets/thothii.secrets" + $authConfigRoot = Join-Path $fixtureRoot "Auth Config" $secretValue = "windows-contract-$runId" $script:SensitiveValues.Add($secretValue) Write-Utf8File $piAuth "{}`n" Write-Utf8File $secrets "THT_MODEL_API_KEY=$secretValue`n" + [System.IO.Directory]::CreateDirectory($authConfigRoot) | Out-Null $remote = Join-Path $fixtureRoot "Workspace Remote/remote.git" $seed = Join-Path $fixtureRoot "Workspace Seed" @@ -190,6 +192,7 @@ THOTH_HTTP_PORT=0 THOTH_CORE_HTTP_PORT=0 PI_AUTH_FILE=$piAuth THT_SECRETS_FILE=$secrets +THT_AUTH_CONFIG_ROOT=$authConfigRoot THT_WORKSPACE_GIT_REMOTE=/fixtures/remote.git THT_WORKSPACE_GIT_BRANCH=main THT_WORKSPACE_INSTALLATION_ID=task13-windows