fix: close P1 acceptance audit gaps

This commit is contained in:
2026-08-09 22:16:37 +02:00
parent 6b2fd71018
commit c1ca814440
4 changed files with 676 additions and 150 deletions
+6 -4
View File
@@ -5,17 +5,19 @@ if [[ $# -lt 1 || "$1" != "integration" || $# -gt 2 || ( $# -eq 2 && "$2" != "--
printf 'usage: %s integration [--keep]\n' "$0" >&2
exit 2
fi
for command in node npm git; do command -v "$command" >/dev/null || { printf 'missing command: %s\n' "$command" >&2; exit 127; }; done
for command in node npm git python3; do command -v "$command" >/dev/null || { printf 'missing command: %s\n' "$command" >&2; exit 127; }; done
node_command="$(command -v node)"
node_bin="$(cd "$(dirname "$node_command")" && pwd -P)/$(basename "$node_command")"
THT_BIN="${THT_BIN:-$repo_root/harness/.venv/bin/tht}"
[[ "$THT_BIN" = /* && -x "$THT_BIN" ]] || { printf 'THT_BIN must be an absolute executable path\n' >&2; exit 127; }
npm --prefix "$repo_root/backend" run build
safe_env=(env -i "PATH=$PATH" "HOME=${HOME:-/nonexistent}" "LANG=${LANG:-C}" "THT_BIN=$THT_BIN")
for name in LC_ALL TMPDIR TZ; do
safe_env=(env -i "PATH=/usr/bin:/bin" "HOME=/nonexistent" "TMPDIR=/tmp" "LANG=${LANG:-C}" "THT_BIN=$THT_BIN")
for name in LC_ALL TZ; do
[[ -n "${!name:-}" ]] && safe_env+=("$name=${!name}")
done
[[ -n "${P1_ACCEPTANCE_FAIL_AT:-}" ]] && safe_env+=("P1_ACCEPTANCE_FAIL_AT=$P1_ACCEPTANCE_FAIL_AT")
set +e
"${safe_env[@]}" node "$repo_root/backend/scripts/p1-acceptance.mjs" "$@"
"${safe_env[@]}" "$node_bin" "$repo_root/backend/scripts/p1-acceptance.mjs" "$@"
status=$?
set -e
exit "$status"