feat: make filesystem Evidence operational after materialization (P6)

This commit is contained in:
2026-08-13 12:35:25 +02:00
parent bb2eabceb6
commit 871de800f0
2 changed files with 12 additions and 7 deletions
@@ -584,9 +584,9 @@ export class WorkspacePreprocessingService {
} | undefined {
const evidence = workspace.evidence;
if (!evidence) return undefined;
if (evidence.source.type === "filesystem") {
return { status: "blocked", code: "evidence_materialization_required" };
}
// P6: filesystem Evidence is materialized from the pinned commit at activation, so the
// engine may proceed directly against the immutable revision content root.
if (evidence.source.type === "filesystem") return undefined;
if (evidence.source.type === "http") {
for (const value of evidence.source.uris) {
const host = new URL(value).hostname;
@@ -289,11 +289,16 @@ test("index schema fails closed when semantic preflight refuses the collection",
expect(runChild).not.toHaveBeenCalled();
});
test("evidence stops before child execution for filesystem sources and refuses private HTTP hosts outside the allowlist", async () => {
test("filesystem Evidence proceeds after materialization and private HTTP hosts outside the allowlist are refused", async () => {
const filesystem = fixture(filesystemWorkspace);
const blocked = await filesystem.service.preprocessEvidence({ workspaceId: "fs-workspace" });
expect(blocked).toMatchObject({ status: "blocked", code: "evidence_materialization_required" });
expect(filesystem.runChild).not.toHaveBeenCalled();
filesystem.runChild.mockResolvedValueOnce({
exitCode: 0,
stdout: JSON.stringify({ status: "succeeded", counts: { added: 1 } }),
stderr: "",
});
const materialized = await filesystem.service.preprocessEvidence({ workspaceId: "fs-workspace" });
expect(materialized).toMatchObject({ status: "succeeded", code: "ok" });
expect(filesystem.runChild).toHaveBeenCalledTimes(1);
const httpDataRoot = mkdtempSync(join(tmpdir(), "tht-preprocessing-service-"));
roots.push(httpDataRoot);