import { execFileSync } from "node:child_process"; import { existsSync, readFileSync } from "node:fs"; import { expect, test } from "vitest"; import { parseWorkspaceYaml } from "../src/workspaces/schema.js"; test("declares a durable isolated registry volume and only read-only Git credential mounts", () => { const compose = readFileSync(new URL("../../compose.yaml", import.meta.url), "utf8"); const development = readFileSync(new URL("../../docker-compose.dev.yml", import.meta.url), "utf8"); const gitHttps = readFileSync(new URL("../../deploy/compose.git-https.yaml", import.meta.url), "utf8"); const gitSsh = readFileSync(new URL("../../deploy/compose.git-ssh.yaml", import.meta.url), "utf8"); const dockerfile = readFileSync(new URL("../../docker/core.Dockerfile", import.meta.url), "utf8"); const smoke = readFileSync(new URL("../../scripts/workspace-registry-smoke.sh", import.meta.url), "utf8"); for (const source of [compose, development]) { expect(source).toContain("THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry"); expect(source).toContain("THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}"); expect(source).toContain("workspace-registry:/data/workspace-registry"); } expect(compose).not.toMatch(/workspace-registry-git-(?:credentials|ca|ssh-key|known-hosts):ro/); expect(gitHttps).toMatch(/workspace-registry-git-credentials:ro/); expect(gitHttps).toMatch(/workspace-registry-git-ca:ro/); expect(gitSsh).toMatch(/workspace-registry-git-ssh-key:ro/); expect(gitSsh).toMatch(/workspace-registry-git-known-hosts:ro/); expect(dockerfile).toMatch(/mkdir -p[^\n]*\/data\/workspace-registry/); expect(dockerfile).toMatch(/chown -R thoth:thoth \/home\/thoth\/\.pi \/data/); expect(smoke).toContain('core_remote="/fixtures/offline.git"'); expect(smoke).toContain('"degraded":true'); expect(smoke).toContain('core_remote="/fixtures/remote.git"'); expect(smoke).toContain( 'cp "$root/scripts/fixtures/workspace-registry-smoke.yaml" "$seed/workspaces/local.yaml"', ); expect(smoke).not.toMatch(/npm\s+--prefix\s+[^\n]*backend[^\n]*\srun\s+build/); expect(smoke).not.toMatch(/migrate-(?:legacy|v2-qdrant)/); expect(smoke).toContain("<<'COMPOSE_YAML'"); expect(smoke).toContain('context: "${SMOKE_ROOT:?}"'); expect(smoke).toContain('image: "${SMOKE_IMAGE:?}"'); expect(smoke).toContain('THT_WORKSPACE_GIT_REMOTE: "${SMOKE_CORE_REMOTE:?}"'); expect(smoke).toContain('THT_WORKSPACE_GIT_BRANCH: "${SMOKE_BRANCH:?}"'); expect(smoke).toContain('source: "${SMOKE_REMOTE:?}"'); expect(smoke).toContain("type: bind"); expect(smoke).toContain("read_only: true"); expect(smoke).not.toContain("context: $root"); expect(smoke).not.toContain("image: $image"); expect(smoke).not.toContain("- $remote:/fixtures/remote.git:ro"); expect(smoke).toContain("compose-config-contract)"); expect(smoke).toContain("cleanup-failure-path)"); }); test("shared workspace registry smoke fixture parses as schema v3 internal semantic identity", () => { const source = readFileSync( new URL("../../scripts/fixtures/workspace-registry-smoke.yaml", import.meta.url), "utf8", ); const descriptor = parseWorkspaceYaml(source); expect(descriptor).toMatchObject({ workspace: { schema_version: 3, id: "local", name: "Local" }, dwh: { engine: "postgres", database: "postgres", schema: "public", supported_transports: ["postgres_direct", "rest_api"], }, semantic_index: { vector_store: { engine: "qdrant", collection: "local", dimensions: 1024, distance: "cosine", }, embedding: { provider: "ollama_internal", model: "qwen3-embedding:0.6b", dimensions: 1024, }, }, llm_policy: { default: "zai/glm-5.2", allowed: ["zai/glm-5.2"] }, diagnostics: { dwh_rest: { method: "GET", path: "/health", auth: "none", response: { database: "database", schema: "schema" }, }, }, }); expect(descriptor).not.toHaveProperty("evidence"); }); test("Windows clone contract copies the shared complete schema v3 descriptor", () => { const fixture = readFileSync( new URL("../../scripts/fixtures/workspace-registry-windows.yaml", import.meta.url), "utf8", ); const descriptor = parseWorkspaceYaml(fixture); const windows = readFileSync( new URL("../../scripts/test-windows-clone-contract.ps1", import.meta.url), "utf8", ); expect(windows).toContain('"scripts/fixtures/workspace-registry-windows.yaml"'); expect(windows).toContain("Copy-Item -LiteralPath $workspaceFixture -Destination $workspaceDestination"); expect(windows).not.toContain("schema_version:"); expect(descriptor).toEqual({ workspace: { schema_version: 3, id: "task13-windows", name: "Task 13 Windows", language: "en", }, dwh: { engine: "postgres", database: "warehouse", schema: "public", port: 5432, timeout_ms: 5000, supported_transports: ["postgres_direct", "rest_api"], }, semantic_index: { vector_store: { engine: "qdrant", collection: "task13-windows", dimensions: 1024, distance: "cosine", }, embedding: { provider: "ollama_internal", model: "qwen3-embedding:0.6b", dimensions: 1024, }, }, llm_policy: { default: "zai/glm-5.2", allowed: ["zai/glm-5.2"] }, diagnostics: { dwh_rest: { method: "GET", path: "/health", auth: "none", response: { database: "database", schema: "schema" }, }, }, }); expect(descriptor).not.toHaveProperty("evidence"); }); test("workspace registry smoke image cleanup is scoped to the per-run image identity", () => { const output = execFileSync("bash", ["scripts/workspace-registry-smoke.sh"], { cwd: new URL("../..", import.meta.url), env: { ...process.env, WORKSPACE_REGISTRY_SMOKE_SELF_TEST: "image-cleanup-identity" }, encoding: "utf8", }); expect(output).toContain("workspace registry smoke image cleanup identity self-test passed"); }); test("workspace registry smoke cleanup failure-path self-test preserves status and retention", () => { const output = execFileSync("bash", ["scripts/workspace-registry-smoke.sh"], { cwd: new URL("../..", import.meta.url), env: { ...process.env, WORKSPACE_REGISTRY_SMOKE_SELF_TEST: "cleanup-failure-path" }, encoding: "utf8", }); expect(output).toContain("workspace registry smoke cleanup failure-path self-test passed"); }); test("workspace migration source modules are absent from the live backend boundary", () => { expect(existsSync(new URL("../src/workspaces/migrate-legacy.ts", import.meta.url))).toBe(false); expect(existsSync(new URL("../src/workspaces/migrate-v2-qdrant.ts", import.meta.url))).toBe(false); });