fix: render registry workspaces for harness
This commit is contained in:
@@ -1,10 +1,37 @@
|
||||
import { test, expect } from "vitest";
|
||||
import Fastify from "fastify";
|
||||
import { authPreHandler, getPrincipal } from "../src/auth/auth.js";
|
||||
import { chmodSync, mkdtempSync, rmSync, statSync } from "node:fs";
|
||||
import { chmodSync, mkdtempSync, readFileSync, rmSync, statSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { expandLocalHome, localPrincipal } from "../src/auth/principal.js";
|
||||
import { expandLocalHome, localPrincipal, upstreamPrincipal } from "../src/auth/principal.js";
|
||||
|
||||
test("server smoke trusted claims transform through nginx to a non-admin principal", () => {
|
||||
const smoke = readFileSync("../scripts/unified-deployment-smoke.sh", "utf8");
|
||||
const nginx = readFileSync("../docker/nginx.conf.template", "utf8");
|
||||
const helper = smoke.match(/task13_server_auth_headers\(\) \{([\s\S]*?)\n\}/)?.[1] ?? "";
|
||||
const trusted = Object.fromEntries(
|
||||
[...helper.matchAll(/-H '([^:']+): ([^']+)'/g)].map((match) => [match[1].toLowerCase(), match[2]]),
|
||||
);
|
||||
const normalized: Record<string, string> = {};
|
||||
for (const [header, suffix] of [
|
||||
["x-thoth-principal-issuer", "principal_issuer"],
|
||||
["x-thoth-principal-subject", "principal_subject"],
|
||||
["x-thoth-principal-display-name", "principal_display_name"],
|
||||
["x-thoth-is-admin", "is_admin"],
|
||||
]) {
|
||||
expect(nginx).toContain(`$http_x_thoth_trusted_${suffix}`);
|
||||
const value = trusted[`x-thoth-trusted-${header.slice("x-thoth-".length)}`];
|
||||
if (value !== undefined) normalized[header] = value;
|
||||
}
|
||||
|
||||
expect(upstreamPrincipal(normalized)).toEqual({
|
||||
issuer: "task13-proxy",
|
||||
subject: "task13-user",
|
||||
displayName: "Task 13 User",
|
||||
isAdmin: false,
|
||||
});
|
||||
});
|
||||
|
||||
test("local mode resolves a stable local principal", async () => {
|
||||
const app = Fastify();
|
||||
|
||||
@@ -168,6 +168,27 @@ function recordingChild() {
|
||||
return ch;
|
||||
}
|
||||
|
||||
test("Pi receives the leased workspace runtime config and releases it on direct teardown", () => {
|
||||
const child = recordingChild();
|
||||
let spawnEnv: NodeJS.ProcessEnv | undefined;
|
||||
const release = vi.fn();
|
||||
const mgr = new PiProcessManager(loadConfig({}), {
|
||||
spawnFn: (_command, _args, options) => {
|
||||
spawnEnv = options.env;
|
||||
return child as any;
|
||||
},
|
||||
});
|
||||
|
||||
mgr.createFor("canonical-runtime", {
|
||||
runtimeConfig: { path: "/trusted/runtime-uuid.yaml", release },
|
||||
} as any);
|
||||
expect(spawnEnv?.THT_CONFIG).toBe("/trusted/runtime-uuid.yaml");
|
||||
|
||||
// The child deliberately emits neither exit nor close. Ownership cleanup must not depend on it.
|
||||
mgr.teardown("canonical-runtime");
|
||||
expect(release).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
test.each([
|
||||
["new", "auth.json", '{"deepseek":{"key":"!runtime-auth-command runtime-secret /private/runtime-auth"}}\n'],
|
||||
["new", "models.json", '{"providers":{"local-qwen":{"headers":["!runtime-model-command runtime-secret /private/runtime-model"]}}}\n'],
|
||||
|
||||
@@ -601,6 +601,8 @@ test("session lifecycle locates a B session when installation default is A", asy
|
||||
provider: "zai", model: "glm-5.2", thinking: "low",
|
||||
};
|
||||
const calls: string[] = [];
|
||||
const runtimeSources: string[] = [];
|
||||
const runtimeOptions: string[] = [];
|
||||
let active: any;
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
thtRunner: {
|
||||
@@ -622,11 +624,21 @@ test("session lifecycle locates a B session when installation default is A", asy
|
||||
calls.push(`reopen:${workspace}`);
|
||||
expect(id).toBe("session-b");
|
||||
},
|
||||
acquireWorkspaceRuntime: (workspace: string) => {
|
||||
runtimeSources.push(workspace);
|
||||
return {
|
||||
path: `/runtime/${runtimeSources.length}.yaml`,
|
||||
workspaceId: "b-workspace",
|
||||
workspaceRevision: "c".repeat(40),
|
||||
release: vi.fn(),
|
||||
};
|
||||
},
|
||||
} as any,
|
||||
readiness: { ensure: async () => ({ ok: true }) } as any,
|
||||
mgr: {
|
||||
get: () => active,
|
||||
createFor: () => {
|
||||
createFor: (_id: string, options: any) => {
|
||||
runtimeOptions.push(options.runtimeConfig?.path ?? "missing");
|
||||
active = { bridge: { onClientEvent: () => {}, respond: () => true, turnState: () => "idle" } };
|
||||
return active;
|
||||
},
|
||||
@@ -673,6 +685,8 @@ test("session lifecycle locates a B session when installation default is A", asy
|
||||
expect(calls).toContain(`list:${bPath}`);
|
||||
expect(calls).toContain(`show:${bPath}`);
|
||||
expect(calls).toContain(`reopen:${bPinnedPath}`);
|
||||
expect(runtimeSources).toEqual([bPath, bPinnedPath]);
|
||||
expect(runtimeOptions).toEqual(["/runtime/1.yaml", "/runtime/2.yaml"]);
|
||||
});
|
||||
|
||||
test("POST /sessions usa i settings (workspace/provider/model/thinking) e crea+avvia", async () => {
|
||||
|
||||
@@ -85,6 +85,43 @@ test("POST /sessions/:id/sql/preview returns 500 when thtRunner throws", async (
|
||||
expect(res.json()).toMatchObject({ error: /boom/ });
|
||||
});
|
||||
|
||||
test("registry-backed SQL preview resolves and uses the session's pinned runtime revision", async () => {
|
||||
const activePath = `/registry/snapshots/${"a".repeat(40)}/psd-clinical.yaml`;
|
||||
const pinnedPath = `/registry/snapshots/${"b".repeat(40)}/psd-clinical.yaml`;
|
||||
const calls: string[] = [];
|
||||
const runner = {
|
||||
sessionShow: async (_id: string, workspace: string) => {
|
||||
calls.push(`show:${workspace}`);
|
||||
if (workspace === activePath) return {
|
||||
id: "s1", workspace_id: "psd-clinical", workspace_revision: "b".repeat(40),
|
||||
};
|
||||
throw new Error("session not found");
|
||||
},
|
||||
sqlPreview: async (_id: string, _page: unknown, workspace: string) => {
|
||||
calls.push(`preview:${workspace}`);
|
||||
return { columns: [], rows: [], execution_ms: 0, truncated: false };
|
||||
},
|
||||
};
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
thtRunner: { ...runner, withPrincipal: () => runner } as any,
|
||||
getSettings: () => ({ workspace: "legacy-default" }) as any,
|
||||
workspaceRegistry: {
|
||||
list: async () => [{
|
||||
id: "psd-clinical", commit: "a".repeat(40), blob: "c".repeat(40),
|
||||
snapshotPath: activePath, state: "operational",
|
||||
}],
|
||||
readPinned: async () => ({ workspace: {}, workspaceConfigPath: pinnedPath }),
|
||||
} as any,
|
||||
});
|
||||
|
||||
const response = await app.inject({
|
||||
method: "POST", url: "/sessions/s1/sql/preview", payload: { limit: 10 },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(calls).toEqual([`show:${activePath}`, `preview:${pinnedPath}`]);
|
||||
});
|
||||
|
||||
// Workspace registry route coverage lives in routes-workspaces.test.ts. `/workspaces` no longer
|
||||
// reads legacy harness files: the Git registry is the single shared source of truth.
|
||||
|
||||
|
||||
@@ -0,0 +1,167 @@
|
||||
import { execFile } from "node:child_process";
|
||||
import { chmodSync, existsSync, mkdtempSync, mkdirSync, readdirSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join, resolve } from "node:path";
|
||||
import { promisify } from "node:util";
|
||||
import { afterEach, expect, test, vi } from "vitest";
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
import { ThtRunner } from "../src/tht/tht-runner.js";
|
||||
import { WorkspaceRegistry } from "../src/workspaces/registry.js";
|
||||
import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js";
|
||||
|
||||
const runFile = promisify(execFile);
|
||||
const harnessDir = resolve("../harness");
|
||||
const thtBin = join(harnessDir, ".venv", "bin", "tht");
|
||||
const roots: string[] = [];
|
||||
|
||||
const canonicalWorkspace = `workspace:
|
||||
schema_version: 2
|
||||
id: psd-clinical
|
||||
name: Runtime handoff
|
||||
language: en
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: analytics
|
||||
schema: mart
|
||||
supported_transports: [postgres_direct]
|
||||
semantic_index:
|
||||
vector_store:
|
||||
engine: pgvector
|
||||
database: analytics
|
||||
schema: vectors
|
||||
collection: documents
|
||||
dimensions: 768
|
||||
distance: cosine
|
||||
supported_transports: [pgvector_direct]
|
||||
embedding:
|
||||
provider: ollama_compatible
|
||||
model: embed
|
||||
dimensions: 768
|
||||
llm_policy:
|
||||
allowed: [zai/glm-5.2]
|
||||
`;
|
||||
|
||||
afterEach(() => {
|
||||
vi.unstubAllEnvs();
|
||||
roots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true }));
|
||||
});
|
||||
|
||||
async function git(cwd: string, args: string[]): Promise<string> {
|
||||
return (await runFile("git", args, { cwd })).stdout.trim();
|
||||
}
|
||||
|
||||
async function fixture() {
|
||||
const root = mkdtempSync(join(tmpdir(), "tht-runtime-handoff-"));
|
||||
roots.push(root);
|
||||
const remote = join(root, "remote.git");
|
||||
const source = join(root, "source");
|
||||
const registryRoot = join(root, "registry");
|
||||
const secretRoot = join(root, "secrets");
|
||||
const dataRoot = join(root, "data");
|
||||
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
|
||||
mkdirSync(source);
|
||||
await git(source, ["init", "--initial-branch=main"]);
|
||||
await git(source, ["config", "user.name", "Runtime Handoff Test"]);
|
||||
await git(source, ["config", "user.email", "runtime-handoff@example.invalid"]);
|
||||
mkdirSync(join(source, "workspaces"));
|
||||
writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), canonicalWorkspace);
|
||||
await git(source, ["add", "workspaces/psd-clinical.yaml"]);
|
||||
await git(source, ["commit", "-m", "Canonical workspace"]);
|
||||
await git(source, ["remote", "add", "origin", remote]);
|
||||
await git(source, ["push", "origin", "main"]);
|
||||
mkdirSync(secretRoot);
|
||||
for (const name of ["dwh-password", "vector-password"]) {
|
||||
const path = join(secretRoot, name);
|
||||
writeFileSync(path, `${name}-value`, { mode: 0o600 });
|
||||
chmodSync(path, 0o600);
|
||||
}
|
||||
mkdirSync(dataRoot);
|
||||
const registryConfig: WorkspaceRegistryConfig = {
|
||||
root: registryRoot,
|
||||
remoteUrl: remote,
|
||||
branch: "main",
|
||||
gitAuthorName: "Runtime Handoff Test",
|
||||
gitAuthorEmail: "runtime-handoff@example.invalid",
|
||||
installationId: "test",
|
||||
secretRoots: [secretRoot],
|
||||
maxImportBytes: 1024 * 1024,
|
||||
maxImportEntries: 16,
|
||||
};
|
||||
const registry = new WorkspaceRegistry(registryConfig);
|
||||
await registry.bootstrap();
|
||||
const revision = (await registry.list())[0];
|
||||
const environment = {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.invalid",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: join(secretRoot, "dwh-password"),
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "pgvector_direct",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_HOST: "vector.invalid",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_USER: "vector-reader",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE: join(secretRoot, "vector-password"),
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "http://embedding.invalid",
|
||||
};
|
||||
for (const [name, value] of Object.entries(environment)) vi.stubEnv(name, value);
|
||||
vi.stubEnv("THT_HOME", join(root, "home"));
|
||||
return { root, dataRoot, registry, registryConfig, revision };
|
||||
}
|
||||
|
||||
function runnerFor(f: Awaited<ReturnType<typeof fixture>>): ThtRunner {
|
||||
return new ThtRunner({
|
||||
thtBin,
|
||||
harnessDir,
|
||||
configPath: "config/tht.yaml",
|
||||
dataRoot: f.dataRoot,
|
||||
runtimeSnapshotRoot: join(f.registryConfig.root, "snapshots", "runtime"),
|
||||
secretRoots: f.registryConfig.secretRoots,
|
||||
} as any);
|
||||
}
|
||||
|
||||
test("real schema-v2 registry revision loads through ThtRunner and the harness contract", async () => {
|
||||
const f = await fixture();
|
||||
const runner = runnerFor(f);
|
||||
|
||||
expect(await runner.sessionList(f.revision.snapshotPath)).toEqual([]);
|
||||
const created = await runner.sessionNew({
|
||||
question: "runtime handoff",
|
||||
workspaceConfigPath: f.revision.snapshotPath,
|
||||
workspaceId: f.revision.id,
|
||||
workspaceRevision: f.revision.commit,
|
||||
});
|
||||
expect(await runner.sessionShow(created.id, f.revision.snapshotPath)).toMatchObject({
|
||||
id: created.id,
|
||||
workspace_id: "psd-clinical",
|
||||
workspace_revision: f.revision.commit,
|
||||
});
|
||||
expect(existsSync(join(
|
||||
f.dataRoot, "sessions", "psd-clinical", "sessions", created.id, "session_manifest.yaml",
|
||||
))).toBe(true);
|
||||
expect(readdirSync(join(f.registryConfig.root, "snapshots", "runtime"))).toEqual([]);
|
||||
});
|
||||
|
||||
test("local GET sessions mine uses the real canonical handoff and returns an empty inventory", async () => {
|
||||
const f = await fixture();
|
||||
const app = buildApp(loadConfig({
|
||||
AUTH_MODE: "none",
|
||||
THT_HARNESS_DIR: harnessDir,
|
||||
THT_BIN: thtBin,
|
||||
THT_DATA_ROOT: f.dataRoot,
|
||||
THT_WORKSPACE_REGISTRY_ROOT: f.registryConfig.root,
|
||||
THT_WORKSPACE_GIT_REMOTE: f.registryConfig.remoteUrl,
|
||||
THT_WORKSPACE_SECRET_ROOTS: f.registryConfig.secretRoots.join(","),
|
||||
}), {
|
||||
thtRunner: runnerFor(f),
|
||||
workspaceRegistry: f.registry,
|
||||
mgr: { get: () => undefined } as any,
|
||||
});
|
||||
try {
|
||||
const response = await app.inject({ method: "GET", url: "/sessions?scope=mine" });
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(response.json()).toEqual([]);
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
});
|
||||
@@ -61,6 +61,13 @@ test("rejects unknown keys and invalid immutable IDs", () => {
|
||||
.toThrow(/id/i);
|
||||
});
|
||||
|
||||
test("rejects executable or otherwise custom YAML tags in canonical descriptors", () => {
|
||||
expect(() => parseWorkspaceYaml(validYaml.replace(
|
||||
"name: Policlinico San Donato",
|
||||
"name: !command echo-never-execute",
|
||||
))).toThrow(/tag|yaml/i);
|
||||
});
|
||||
|
||||
test("accepts optional connection ports and timeouts but rejects unsafe values", () => {
|
||||
expect(parseWorkspaceYaml(validYaml).dwh.port).toBe(5432);
|
||||
expect(() => parseWorkspaceYaml(validYaml.replace("port: 5432", "port: 0")))
|
||||
|
||||
Reference in New Issue
Block a user