#!/usr/bin/env bash # Regression coverage for coupling-scan categories, exact exclusions, and scanner failures. set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" fixture="$(mktemp -d "${TMPDIR%/}/thoth-coupling-scope.XXXXXX")" trap 'rm -rf "$fixture"' EXIT HUP INT TERM new_fixture() { rm -rf "$fixture/repository" mkdir -p \ "$fixture/repository/backend/src/workspaces" \ "$fixture/repository/deploy/env" \ "$fixture/repository/deploy/workspaces" \ "$fixture/repository/docker/smoke" \ "$fixture/repository/docs/install" \ "$fixture/repository/docs/superpowers/specs" \ "$fixture/repository/docs/superpowers/plans" \ "$fixture/repository/frontend" \ "$fixture/repository/scripts" printf '%s\n' 'services: {}' >"$fixture/repository/compose.yaml" printf '%s\n' '# generic runtime image' >"$fixture/repository/docker/core.Dockerfile" printf '%s\n' '# generic smoke' >"$fixture/repository/docker/smoke/core-smoke.sh" printf '%s\n' '# generic install' >"$fixture/repository/docs/install/local.md" printf '%s\n' 'THT_LLM_URL=https://llm.example.invalid' >"$fixture/repository/deploy/env/local.env.example" printf '%s\n' '# generic launcher' >"$fixture/repository/scripts/run-stack.sh" printf '%s\n' '// generic frontend configuration' >"$fixture/repository/frontend/vite.config.ts" printf '%s\n' '// explicit descriptor migration module may mention pgvector during conversion' \ >"$fixture/repository/backend/src/workspaces/migrate-legacy.ts" printf '%s\n' 'language: en' 'vectors: { type: qdrant, base_url: http://qdrant:6333, collection: demo }' \ >"$fixture/repository/deploy/workspaces/example.yaml" printf '%s\n' '# qdrant backup helper' >"$fixture/repository/scripts/vector-backup.sh" printf '%s\n' '# qdrant restore helper' >"$fixture/repository/scripts/vector-restore.sh" # These are the three intentionally allowed categories from the Task 10 boundary. printf '%s\n' 'historical omics_portal and Chirone record' \ >"$fixture/repository/docs/superpowers/plans/legacy.md" printf '%s\n' 'historical pgvector rollout note' \ >"$fixture/repository/docs/superpowers/specs/history.md" printf '%s\n' 'id: generic' >"$fixture/repository/deploy/workspaces/psd.yaml.example" printf '%s\n' '# migrate PSD sessions from /home/chirone' \ >"$fixture/repository/docker/session-migrate.sh" } assert_clean() { "$root/scripts/test-no-deployment-coupling.sh" --root "$fixture/repository" >/dev/null } assert_detected() { local relative_path="$1" content="$2" output status new_fixture mkdir -p "$(dirname "$fixture/repository/$relative_path")" printf '%s\n' "$content" >"$fixture/repository/$relative_path" set +e output="$("$root/scripts/test-no-deployment-coupling.sh" --root "$fixture/repository" 2>&1)" status=$? set -e if [[ $status -ne 1 ]] || ! grep -Fq "$relative_path" <<<"$output"; then echo "coupling scan missed $relative_path" >&2 printf '%s\n' "$output" >&2 exit 1 fi } new_fixture assert_clean assert_detected compose.yaml 'services: # Chirone runtime coupling' assert_detected docker/smoke/core-smoke.sh 'test -d /home/chirone' assert_detected docs/install/local.md 'Install the PSD deployment profile.' assert_detected deploy/env/local.env.example 'NETWORK=omics_portal' assert_detected scripts/run-stack.sh 'exec datamart-builder' assert_detected frontend/vite.config.ts 'const base = "/omics_portal";' assert_detected scripts/test-qwen-network-config.sh 'require localllm_default' assert_detected scripts/test-provider-network.sh 'if (!config.networks?.localllm_default?.external) exit 1' assert_detected deploy/compose.psd-local.yaml 'services: {}' assert_detected deploy/compose.local-vector.yaml 'services: {}' assert_detected deploy/compose.preprocess-local-vector.yaml 'services: {}' assert_detected scripts/run-stack.sh 'export THT_VECTOR_READER_PASSWORD_FILE=/run/secrets/vector-reader' assert_detected deploy/env/local.env.example 'THT_OLLAMA_URL=http://ollama.example.invalid:11434' assert_detected scripts/generate-override.sh 'THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_SOURCE=/tmp/vector-key' assert_detected scripts/test-contract.sh 'docker compose -f deploy/compose.local-vector.yaml --profile local-vector config' assert_detected deploy/workspaces/local-vector.yaml 'vectors: { type: pgvector_direct }' assert_detected deploy/workspaces/example.yaml 'embeddings: { base_url: ${THT_OLLAMA_URL} }' assert_detected scripts/vector-backup.sh 'pg_dump --format=custom' assert_detected scripts/vector-restore.sh 'pg_restore --single-transaction' new_fixture mkdir -p "$fixture/bin" printf '%s\n' '#!/bin/sh' 'exit 2' >"$fixture/bin/rg" chmod +x "$fixture/bin/rg" set +e PATH="$fixture/bin:$PATH" "$root/scripts/test-no-deployment-coupling.sh" \ --root "$fixture/repository" >"$fixture/rg.out" 2>"$fixture/rg.err" status=$? set -e if [[ $status -ne 2 ]]; then echo "coupling scan masked an rg failure (status $status)" >&2 cat "$fixture/rg.out" "$fixture/rg.err" >&2 exit 1 fi echo "no-coupling scope regression tests passed."