import { execFile } from "node:child_process"; import { existsSync, mkdtempSync, mkdirSync, rmSync, symlinkSync, writeFileSync } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { promisify } from "node:util"; import { afterEach, expect, test } from "vitest"; import { WorkspaceRegistry } from "../src/workspaces/registry.js"; import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js"; const validYaml = `workspace: schema_version: 1 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct] semantic_index: vector_store: engine: pgvector collection: clinical_documents dimensions: 768 distance: cosine supported_transports: [pgvector_direct] embedding: provider: ollama_compatible model: nomic-embed-text-v2-moe dimensions: 768 llm_policy: allowed: [zai/glm-5.2] `; const runFile = promisify(execFile); const temporaryRoots: string[] = []; afterEach(() => { temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true })); }); async function git(cwd: string, args: string[]): Promise { await runFile("git", args, { cwd }); } async function fixture(): Promise<{ root: string; remote: string; source: string; initialCommit: string; }> { const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-")); temporaryRoots.push(root); const remote = join(root, "remote.git"); const source = join(root, "source"); await git(root, ["init", "--bare", "--initial-branch=main", remote]); mkdirSync(source); await git(source, ["init", "--initial-branch=main"]); await git(source, ["config", "user.name", "Workspace Registry Test"]); await git(source, ["config", "user.email", "workspace-registry@example.invalid"]); mkdirSync(join(source, "workspaces")); writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), validYaml); await git(source, ["add", "workspaces/psd-clinical.yaml"]); await git(source, ["commit", "-m", "Initial workspace"]); await git(source, ["remote", "add", "origin", remote]); await git(source, ["push", "origin", "main"]); const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source }); return { root, remote, source, initialCommit: stdout.trim() }; } function config(root: string, remoteUrl: string): WorkspaceRegistryConfig { return { root, remoteUrl, branch: "main", gitAuthorName: "Workspace Registry Test", gitAuthorEmail: "workspace-registry@example.invalid", installationId: "test", secretRoots: [], maxImportBytes: 1024, maxImportEntries: 1, }; } async function pushInvalidWorkspace(source: string): Promise { writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), "workspace: invalid\n"); await git(source, ["add", "workspaces/psd-clinical.yaml"]); await git(source, ["commit", "-m", "Invalid workspace"]); await git(source, ["push", "origin", "main"]); } test("bootstraps a checkout and activates a validated immutable snapshot", async () => { const remote = await fixture(); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); const status = await registry.bootstrap(); expect(status.head).toMatch(/^[0-9a-f]{40}$/); expect(existsSync(registry.snapshotPath(status.head!, "psd-clinical"))).toBe(true); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit, id: "psd-clinical" }, }); }); test("keeps the last valid snapshot when a pulled commit has invalid YAML", async () => { const remote = await fixture(); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); await registry.bootstrap(); await pushInvalidWorkspace(remote.source); await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }); test("does not bypass an existing advisory repository lock", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); mkdirSync(join(root, "locks"), { recursive: true }); writeFileSync(join(root, "locks", "repository.lock"), "held"); await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_stale" }); }); test("rejects a symbolic-link registry root before creating a lock below it", async () => { const remote = await fixture(); const target = join(remote.root, "registry-target"); const root = join(remote.root, "registry-link"); mkdirSync(target); symlinkSync(target, root); const registry = new WorkspaceRegistry(config(root, remote.remote)); await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" }); expect(existsSync(join(target, "locks"))).toBe(false); });