From f09ab2b8c6160ca2a0f4ab4987d605e5f6301c72 Mon Sep 17 00:00:00 2001 From: mptyl Date: Thu, 13 Aug 2026 12:38:53 +0200 Subject: [PATCH] test: expect filesystem Evidence materialization in the canonical snapshot --- backend/test/workspace-registry.test.ts | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/backend/test/workspace-registry.test.ts b/backend/test/workspace-registry.test.ts index 5d702c4a..550b9285 100644 --- a/backend/test/workspace-registry.test.ts +++ b/backend/test/workspace-registry.test.ts @@ -1158,7 +1158,7 @@ test("rejects a corrupt fallback snapshot instead of returning degraded active s }); -test("snapshots canonical Evidence artifacts at the active commit without copying Evidence bytes", async () => { +test("snapshots canonical Evidence artifacts at the active commit and materializes filesystem Evidence bytes", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registryRoot = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(registryRoot, remote.remote)); @@ -1185,23 +1185,36 @@ test("snapshots canonical Evidence artifacts at the active commit without copyin expect(active.revision.blob).toBe(committedBlob); expect(expectedFiles["psd-clinical.yaml"]).toBe(serializeWorkspaceYaml(committedDescriptor)); expect(readdirSync(snapshotDirectory).sort()).toEqual([ - "psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "snapshot.json", + "psd-clinical", "psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "snapshot.json", ]); expect(manifest.head).toBe(remote.initialCommit); expect(manifest.revisions[0]).toMatchObject({ id: "psd-clinical", commit: remote.initialCommit, blob: committedBlob, }); - expect(Object.keys(manifest.files).sort()).toEqual(Object.keys(expectedFiles).sort()); + expect(Object.keys(manifest.files).sort()).toEqual([ + "psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "psd-clinical/evidence.manifest.json", + ]); for (const [name, contents] of Object.entries(expectedFiles)) { expect(readFileSync(join(snapshotDirectory, name), "utf8")).toBe(contents); expect(manifest.files[name]).toBe(createHash("sha256").update(contents).digest("hex")); } + // P6: the materialized Evidence tree and its digest-chained manifest. + const evidenceManifest = JSON.parse(readFileSync( + join(snapshotDirectory, "psd-clinical", "evidence.manifest.json"), "utf8", + )); + expect(evidenceManifest).toMatchObject({ workspace: "psd-clinical", commit: remote.initialCommit, entryCount: 1 }); + expect(manifest.files["psd-clinical/evidence.manifest.json"]).toBe( + createHash("sha256").update(`${JSON.stringify(evidenceManifest)}\n`).digest("hex"), + ); + expect(readFileSync(join(snapshotDirectory, "psd-clinical", "evidence", "guide.md"), "utf8")) + .toBe("guide v1\n"); expect(JSON.stringify(manifest)).not.toContain("workspace-content/"); expect(readdirSync(snapshotDirectory).some((name) => name === "workspace-content")).toBe(false); expect(readFileSync(join(remote.source, "psd-clinical/evidence/guide.md"), "utf8")) .toBe("guide v1\n"); }); + test("never copies an installation secret canary into Git, generated artifacts, metadata, or errors", async () => { const remote = await fixture(validYaml.concat(`evidence: source: