fix: harden runtime config lease boundary

This commit is contained in:
2026-08-11 12:43:14 +02:00
parent cf88e2df86
commit ec92f7f994
8 changed files with 324 additions and 149 deletions
@@ -169,8 +169,8 @@ test("real schema-v3 registry revision loads through ThtRunner and the harness c
test("separate runtime leases hand off byte-identical revision Evidence configs accepted by tht", async () => {
const f = await fixture();
const runner = runnerFor(f);
const first = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const second = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const first = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const second = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const expectedRoot = join(
f.registryConfig.root,
"snapshots",
@@ -226,7 +226,7 @@ test("separate runtime leases hand off byte-identical revision Evidence configs
test("real Evidence-content-only commit changes runtime identity and root with identical descriptor YAML", async () => {
const f = await fixture();
const runner = runnerFor(f);
const first = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const first = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const descriptorBefore = readFileSync(f.revision.snapshotPath, "utf8");
writeFileSync(
join(f.source, "workspace-content", "psd-clinical", "evidence", "guide.md"),
@@ -237,7 +237,7 @@ test("real Evidence-content-only commit changes runtime identity and root with i
await git(f.source, ["push", "origin", "main"]);
await f.registry.pull();
const current = (await f.registry.list())[0];
const second = runner.acquireWorkspaceRuntime(current.snapshotPath);
const second = await runner.acquireWorkspaceRuntime(current.snapshotPath);
try {
expect(current.commit).not.toBe(f.revision.commit);
@@ -281,7 +281,7 @@ test("signed HTTP Evidence resolves its file binding and config check never capt
max_cache_bytes: 67890
`));
const runner = runnerFor(f);
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const lease = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
try {
const yaml = readFileSync(lease.path, "utf8");
expect(parse(yaml).evidence.sources).toEqual([{
@@ -325,7 +325,7 @@ test("static S3 Evidence resolves only configured secret-root file paths", async
retain_published_generations: 7
`));
const runner = runnerFor(f);
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
const lease = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
try {
const yaml = readFileSync(lease.path, "utf8");
expect(parse(yaml).evidence.sources).toEqual([{