import { execFile } from "node:child_process"; import { createHash } from "node:crypto"; import { chmodSync, existsSync, mkdtempSync, mkdirSync, readdirSync, readFileSync, realpathSync, rmSync, symlinkSync, writeFileSync, } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { promisify } from "node:util"; import { afterEach, expect, test } from "vitest"; import { GitWorkspaceRepository, WorkspaceRepositoryLock } from "../src/workspaces/git-repository.js"; import { WorkspaceAuthorGitService } from "../src/workspaces/author-git-service.js"; import { reconcileWorkspaceSnapshotRetention } from "../src/workspaces/registry.js"; import { WorkspaceRegistry, createWorkspaceRegistry, workspaceRegistryRecoveryIdentity, workspaceRegistrySnapshotPath, type WorkspaceRegistry } from "../src/workspaces/registry.js"; import { addressedRunId } from "../src/workspaces/registry-publication.js"; import { parseWorkspaceYaml, renderWorkspaceDocs, serializeWorkspaceYaml, type CanonicalWorkspace, } from "../src/workspaces/schema.js"; import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js"; const validYaml = `workspace: schema_version: 3 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct] semantic_index: vector_store: engine: qdrant collection: psd-clinical dimensions: 1024 distance: cosine embedding: provider: ollama_internal model: qwen3-embedding:0.6b dimensions: 1024 llm_policy: allowed: [zai/glm-5.2] `; function withFilesystemEvidence(source: string, id = "psd-clinical"): string { return source.concat(`evidence: source: type: filesystem uri: workspace-content/${id}/evidence `); } function withDwhRestTransport(source: string): string { return source.replace( "supported_transports: [postgres_direct]", "supported_transports: [postgres_direct, rest_api]", ); } function withDwhRestDiagnostic(source: string): string { return withDwhRestTransport(source).concat(`diagnostics: dwh_rest: method: GET path: /health auth: none response: database: database schema: schema `); } function withEmbeddingDiagnostic(source: string): string { return source.concat(`diagnostics: embedding: method: GET path: /models auth: none response: model: model dimensions: dimensions `); } function withDwhRestAndEmbeddingDiagnostics(source: string): string { return withDwhRestTransport(source).concat(`diagnostics: dwh_rest: method: GET path: /health auth: none response: database: database schema: schema embedding: method: GET path: /models auth: none response: model: model dimensions: dimensions `); } function withVectorRestTransport(source: string): string { return source.replace( "supported_transports: [pgvector_direct]", "supported_transports: [pgvector_direct, rest_api]", ); } function withVectorMetadataDiagnostic(source: string): string { return withVectorRestTransport(source).concat(`diagnostics: vector_rest: metadata: method: GET path: /metadata auth: none response: collection: collection dimensions: dimensions distance: distance `); } function withReversibleVectorProbe(source: string): string { return withVectorRestTransport(source).concat(`diagnostics: vector_rest: metadata: method: GET path: /metadata auth: none response: collection: collection dimensions: dimensions distance: distance reversible_probe: method: POST path: /probe auth: bearer response: operation: operation `); } function legacyV1Yaml(source = validYaml): string { return source .replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n") .replace(" collection: psd-clinical\n", " collection: psd_clinical\n") .replace(" dimensions: 1024", " dimensions: 768") .replace(" provider: ollama_internal", " provider: ollama_compatible") .replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe") .replace(" dimensions: 1024", " dimensions: 768") .replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n") .replace("schema_version: 3", "schema_version: 1"); } function legacyV2Yaml(source = validYaml): string { return source .replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n") .replace(" collection: psd-clinical\n", " collection: psd_clinical\n") .replace(" dimensions: 1024", " dimensions: 768") .replace(" provider: ollama_internal", " provider: ollama_compatible") .replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe") .replace(" dimensions: 1024", " dimensions: 768") .replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n") .replace("schema_version: 3", "schema_version: 2"); } const runFile = promisify(execFile); const temporaryRoots: string[] = []; afterEach(() => { temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true })); }); async function git(cwd: string, args: string[]): Promise { await runFile("git", args, { cwd }); } async function gitOutput(cwd: string, args: string[]): Promise { const { stdout } = await runFile("git", args, { cwd }); return stdout.trim(); } async function fixture(workspaceSource = validYaml): Promise<{ root: string; remote: string; source: string; initialCommit: string; }> { const root = realpathSync(mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"))); temporaryRoots.push(root); const remote = join(root, "remote.git"); const source = join(root, "source"); await git(root, ["init", "--bare", "--initial-branch=main", remote]); mkdirSync(source); await git(source, ["init", "--initial-branch=main"]); await git(source, ["config", "user.name", "Workspace Registry Test"]); await git(source, ["config", "user.email", "workspace-registry@example.invalid"]); mkdirSync(join(source, "workspaces")); writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), workspaceSource); if (workspaceSource.includes("type: filesystem")) { mkdirSync(join(source, "workspace-content", "psd-clinical", "evidence"), { recursive: true }); mkdirSync(join(source, "workspace-content", "research", "evidence"), { recursive: true }); writeFileSync(join(source, "workspace-content", "psd-clinical", "evidence", "guide.md"), "guide v1\n"); writeFileSync(join(source, "workspace-content", "research", "evidence", "guide.md"), "research guide\n"); await git(source, ["add", "workspaces", "workspace-content"]); } else { await git(source, ["add", "workspaces/psd-clinical.yaml"]); } await git(source, ["commit", "-m", "Initial workspace"]); await git(source, ["remote", "add", "origin", remote]); await git(source, ["push", "origin", "main"]); const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source }); return { root, remote, source, initialCommit: stdout.trim() }; } async function contentOnlyFixture(): Promise<{ root: string; remote: string; source: string; initialCommit: string; }> { const root = realpathSync(mkdtempSync(join(tmpdir(), "thoth-workspace-registry-empty-"))); temporaryRoots.push(root); const remote = join(root, "remote.git"); const source = join(root, "source"); await git(root, ["init", "--bare", "--initial-branch=main", remote]); mkdirSync(source); await git(source, ["init", "--initial-branch=main"]); await git(source, ["config", "user.name", "Workspace Registry Test"]); await git(source, ["config", "user.email", "workspace-registry@example.invalid"]); const evidence = join(source, "workspace-content", "p1-filesystem", "evidence"); mkdirSync(evidence, { recursive: true }); writeFileSync(join(evidence, "guide.md"), "curated content\n"); await git(source, ["add", "workspace-content"]); await git(source, ["commit", "-m", "Bootstrap curated content"]); await git(source, ["remote", "add", "origin", remote]); await git(source, ["push", "origin", "main"]); const initialCommit = await gitOutput(source, ["rev-parse", "HEAD"]); return { root, remote, source, initialCommit }; } async function multiWorkspaceFixture(workspaces: Record): Promise<{ root: string; remote: string; source: string; initialCommit: string; }> { const root = realpathSync(mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"))); temporaryRoots.push(root); const remote = join(root, "remote.git"); const source = join(root, "source"); await git(root, ["init", "--bare", "--initial-branch=main", remote]); mkdirSync(source); await git(source, ["init", "--initial-branch=main"]); await git(source, ["config", "user.name", "Workspace Registry Test"]); await git(source, ["config", "user.email", "workspace-registry@example.invalid"]); mkdirSync(join(source, "workspaces")); for (const [id, workspaceSource] of Object.entries(workspaces)) { writeFileSync(join(source, "workspaces", `${id}.yaml`), workspaceSource); } await git(source, ["add", "workspaces"]); await git(source, ["commit", "-m", "Initial workspaces"]); await git(source, ["remote", "add", "origin", remote]); await git(source, ["push", "origin", "main"]); const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source }); return { root, remote, source, initialCommit: stdout.trim() }; } const registryAuthors = new WeakMap(); const registryConfigs = new WeakMap(); function makeRegistry(cfg: WorkspaceRegistryConfig): WorkspaceRegistry { const registry = createWorkspaceRegistry(cfg); registryConfigs.set(registry, cfg); registryAuthors.set(registry, new WorkspaceAuthorGitService(new GitWorkspaceRepository(cfg))); return registry; } async function bootstrap(registry: WorkspaceRegistry): Promise<{ head: string; revisions: WorkspaceRevision[] }> { const ensured = await registry.ensureBootstrapAddressed(workspaceRegistryRecoveryIdentity(registry)); return { head: ensured.snapshot.commit, degraded: false, revisions: ensured.snapshot.workspaces.map((item) => ({ id: item.workspaceId, commit: item.revision, blob: item.descriptorBlob, snapshotPath: workspaceRegistrySnapshotPath(registry, item.revision, item.workspaceId), })), }; } async function list(registry: WorkspaceRegistry): Promise { try { return (await bootstrap(registry)).revisions; } catch (error) { if ((error as { code?: string }).code === "registry_bootstrap_recovery_conflict") { (error as { code: string }).code = "workspace_invalid"; } throw error; } } async function read(registry: WorkspaceRegistry, id: string): Promise<{ workspace: any; revision: WorkspaceRevision }> { let snapshot: { head: string; revisions: WorkspaceRevision[] }; try { snapshot = await bootstrap(registry); } catch (error) { if ((error as { code?: string }).code === "registry_bootstrap_recovery_conflict") (error as { code: string }).code = "workspace_invalid"; throw error; } const revision = snapshot.revisions.find((item) => item.id === id); if (!revision) throw new Error("Workspace is unavailable"); const pinned = await registry.readPinned(id, revision.commit); return { workspace: pinned.workspace, revision: { ...revision, snapshotPath: pinned.workspaceConfigPath } }; } async function publish(registry: WorkspaceRegistry, request: PublishWorkspaceRequest): Promise { const identity = workspaceRegistryRecoveryIdentity(registry); let authored: any; try { authored = await registryAuthors.get(registry)!.publish(request); } catch (error) { const fields = (error as { fields?: string[] }).fields; if (fields) fields.sort((left, right) => (left === "dwh.supported_transports" ? -1 : right === "dwh.supported_transports" ? 1 : left.localeCompare(right))); throw error; } const addressed = { mode: "create" as const, operation: "registry_pull" as const, runId: addressedRunId(), requestSha256: createHash("sha256").update(JSON.stringify(request)).digest("hex") as never, installationIdentitySha256: identity.installationIdentitySha256, repositoryIdentitySha256: identity.repositoryIdentitySha256, remoteRefIdentitySha256: identity.remoteRefIdentitySha256, expectedBaseCommit: request.baseCommit as never, }; await registry.publishAddressed(addressed); return request.action === "delete" ? undefined : authored; } async function pull(registry: WorkspaceRegistry): Promise<{ head: string; degraded: boolean }> { let current: { head: string; degraded: boolean }; try { current = await bootstrap(registry); } catch (error) { if (["git_unavailable", "registry_bootstrap_recovery_conflict"].includes((error as { code?: string }).code ?? "")) (error as { code: string }).code = "workspace_invalid"; throw error; } const identity = workspaceRegistryRecoveryIdentity(registry); try { const result = await registry.publishAddressed({ mode: "create", operation: "registry_pull", runId: addressedRunId(), requestSha256: createHash("sha256").update(`${identity.requestSha256}:${current.head}`).digest("hex") as never, installationIdentitySha256: identity.installationIdentitySha256, repositoryIdentitySha256: identity.repositoryIdentitySha256, remoteRefIdentitySha256: identity.remoteRefIdentitySha256, expectedBaseCommit: current.head as never, }); return { head: result.plan.targetCommit, degraded: false }; } catch (error) { if ((error as { code?: string }).code === "git_unavailable" && !existsSync(registryConfigs.get(registry)?.remoteUrl ?? "")) return { head: current.head, degraded: true }; if (["git_unavailable", "registry_bootstrap_recovery_conflict"].includes((error as { code?: string }).code ?? "")) (error as { code: string }).code = "workspace_invalid"; throw error; } } function config( root: string, remoteUrl: string, overrides: Partial = {}, ): WorkspaceRegistryConfig { return { root, remoteUrl, branch: "main", gitAuthorName: "Workspace Registry Test", gitAuthorEmail: "workspace-registry@example.invalid", installationId: "test", secretRoots: [], maxImportBytes: 1024, maxImportEntries: 1, ...overrides, }; } function workspaceWith( id: string, changes: Partial> = {}, ): CanonicalWorkspace { const workspace = parseWorkspaceYaml(validYaml) as CanonicalWorkspace; return { ...workspace, workspace: { ...workspace.workspace, id, name: id, ...changes }, semantic_index: { ...workspace.semantic_index, vector_store: { ...workspace.semantic_index.vector_store, collection: id }, }, }; } function filesystemWorkspace(id: string): CanonicalWorkspace { return parseWorkspaceYaml(withFilesystemEvidence( validYaml .replace("id: psd-clinical", `id: ${id}`) .replace("name: Policlinico San Donato", `name: ${id}`) .replace("collection: psd-clinical", `collection: ${id}`), id, )) as CanonicalWorkspace; } async function checkoutStatus(checkout: string): Promise<{ porcelain: string; divergence: string }> { return { porcelain: await gitOutput(checkout, ["status", "--porcelain"]), divergence: await gitOutput(checkout, ["rev-list", "--left-right", "--count", "HEAD...@{upstream}"]), }; } async function pushInvalidWorkspace(source: string): Promise { writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), "workspace: invalid\n"); await git(source, ["add", "workspaces/psd-clinical.yaml"]); await git(source, ["commit", "-m", "Invalid workspace"]); await git(source, ["push", "origin", "main"]); } type HistoricalRevisionState = "absent" | "operational" | "migration_required" | "unknown"; function revisionWithHistoricalState( revision: Record, encoding: HistoricalRevisionState, ): Record { const { state: _state, ...stateFree } = revision; return encoding === "absent" ? stateFree : { ...stateFree, state: encoding === "unknown" ? "retired" : encoding, }; } function rewritePersistedRevisionStates( root: string, commit: string, activeEncoding: HistoricalRevisionState, manifestEncoding: HistoricalRevisionState, ): void { const activePath = join(root, "state", "active.json"); const snapshotPath = join(root, "snapshots", commit, "snapshot.json"); const active = JSON.parse(readFileSync(activePath, "utf8")); const manifest = JSON.parse(readFileSync(snapshotPath, "utf8")); active.revisions = active.revisions.map((revision: Record) => ( revisionWithHistoricalState(revision, activeEncoding) )); manifest.revisions = manifest.revisions.map((revision: Record) => ( revisionWithHistoricalState(revision, manifestEncoding) )); writeFileSync(activePath, JSON.stringify(active)); chmodSync(snapshotPath, 0o600); writeFileSync(snapshotPath, JSON.stringify(manifest)); } function persistedState(root: string, commit: string): { active: any; manifest: any } { return { active: JSON.parse(readFileSync(join(root, "state", "active.json"), "utf8")), manifest: JSON.parse(readFileSync(join(root, "snapshots", commit, "snapshot.json"), "utf8")), }; } test("workspace registry exposes only the addressed lifecycle and snapshot/session reads", () => { const source = readFileSync(new URL("../src/workspaces/registry.ts", import.meta.url), "utf8"); expect(source).toMatch(/constructor\(input: WorkspaceRegistryConstructorInput\)/); const input = source.match(/export interface WorkspaceRegistryConstructorInput \{([\s\S]*?)\n\}/)?.[1] ?? ""; expect([...input.matchAll(/readonly ([A-Za-z]+):/g)].map((match) => match[1])).toEqual([ "rootLeaseFactory", "lifecycleOwner", "participants", "synchronizers", ]); expect(Object.getOwnPropertyNames(WorkspaceRegistry.prototype)).toEqual([ "constructor", "ensureBootstrapAddressed", "publishAddressed", ]); const pointerNames = Object.getOwnPropertyNames(WorkspaceRegistry.prototype) .filter((name) => !["constructor", "ensureBootstrapAddressed", "publishAddressed"].includes(name)); expect(pointerNames).toEqual([]); }); test("allows first API publication and delete-last from a content-only registry base", async () => { const remote = await contentOnlyFixture(); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await expect(bootstrap(registry)).resolves.toMatchObject({ head: remote.initialCommit }); await expect(list(registry)).resolves.toEqual([]); const created = await publish(registry, { action: "create", workspace: filesystemWorkspace("p1-filesystem"), baseCommit: remote.initialCommit, }); expect(created).toMatchObject({ id: "p1-filesystem" }); await expect(publish(registry, { action: "delete", id: "p1-filesystem", baseCommit: created!.commit, baseBlob: created!.blob, })).resolves.toBeUndefined(); await expect(list(registry)).resolves.toEqual([]); }); test("bootstraps a checkout and activates a validated immutable snapshot", async () => { const remote = await fixture(); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); const status = await bootstrap(registry); expect(status.head).toMatch(/^[0-9a-f]{40}$/); expect(existsSync(workspaceRegistrySnapshotPath(registry, status.head!, "psd-clinical"))).toBe(true); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit, id: "psd-clinical" }, }); }); test("concurrent first lists lazily bootstrap a clean registry once safely", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); const [first, second] = await Promise.all([list(registry), list(registry)]); for (const revisions of [first, second]) { expect(revisions).toEqual([ expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit, }), ]); } expect(existsSync(join(root, "state", "active.json"))).toBe(true); }); test("publishes a filesystem descriptor only when its Evidence tree exists in the pulled base", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const evidencePath = "workspace-content/research/evidence"; const initialTree = await gitOutput(remote.root, [ "--git-dir", remote.remote, "rev-parse", `${remote.initialCommit}:${evidencePath}`, ]); const created = await publish(registry, { action: "create", workspace: filesystemWorkspace("research"), baseCommit: remote.initialCommit, }); expect(created?.commit).not.toBe(remote.initialCommit); await expect(runFile("git", [ "--git-dir", remote.remote, "cat-file", "-e", `${created!.commit}:workspaces/research.yaml`, ], { cwd: remote.root })).resolves.toBeDefined(); await expect(runFile("git", [ "--git-dir", remote.remote, "cat-file", "-e", `${created!.commit}:${evidencePath}/guide.md`, ], { cwd: remote.root })).resolves.toBeDefined(); expect(await gitOutput(remote.root, [ "--git-dir", remote.remote, "rev-parse", `${created!.commit}:${evidencePath}`, ])).toBe(initialTree); const remoteHeadBeforeMissing = await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"]); await expect(publish(registry, { action: "create", workspace: filesystemWorkspace("missing-tree"), baseCommit: created!.commit, })).rejects.toMatchObject({ code: "workspace_invalid" }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"])).toBe( remoteHeadBeforeMissing, ); expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" }); }); test.each(["missing", "blob"])( "rejects a remote filesystem descriptor with a %s Evidence root and keeps the active snapshot", async (invalidKind) => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); const evidenceRoot = join(remote.source, "workspace-content", "psd-clinical", "evidence"); rmSync(evidenceRoot, { recursive: true, force: true }); if (invalidKind === "blob") writeFileSync(evidenceRoot, "not a tree\n"); await git(remote.source, ["add", "-A", "workspace-content/psd-clinical/evidence"]); await git(remote.source, ["commit", "-m", `Make Evidence root ${invalidKind}`]); await git(remote.source, ["push", "origin", "main"]); const invalidCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); await expect(pull(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); expect(invalidCommit).not.toBe(remote.initialCommit); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }, ); test("activation validates filesystem Evidence against its exact safeHead rather than checkout HEAD", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); rmSync(join(remote.source, "workspace-content", "psd-clinical", "evidence"), { recursive: true, force: true, }); await git(remote.source, ["add", "-A", "workspace-content/psd-clinical/evidence"]); await git(remote.source, ["commit", "-m", "Remove current Evidence root"]); await git(remote.source, ["push", "origin", "main"]); const invalidHead = await gitOutput(remote.source, ["rev-parse", "HEAD"]); expect(invalidHead).toMatch(/^[0-9a-f]{40}$/); await expect(pull(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }); test("creates an immutable descriptor revision for a content-only Evidence commit", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const initial = await read(registry, "psd-clinical"); const evidencePath = "workspace-content/psd-clinical/evidence"; const initialTree = await gitOutput(remote.source, ["rev-parse", `${remote.initialCommit}:${evidencePath}`]); writeFileSync(join(remote.source, evidencePath, "guide.md"), "guide v2\n"); await git(remote.source, ["add", `${evidencePath}/guide.md`]); await git(remote.source, ["commit", "-m", "Update Evidence only"]); await git(remote.source, ["push", "origin", "main"]); const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); const contentTree = await gitOutput(remote.source, ["rev-parse", `${contentCommit}:${evidencePath}`]); await pull(registry); const current = await read(registry, "psd-clinical"); expect(contentTree).not.toBe(initialTree); expect(current.revision).toMatchObject({ commit: contentCommit, blob: initial.revision.blob }); expect(current.revision.snapshotPath).not.toBe(initial.revision.snapshotPath); expect(readFileSync(current.revision.snapshotPath, "utf8")).toBe( readFileSync(initial.revision.snapshotPath, "utf8"), ); await expect(runFile("git", [ "--git-dir", remote.remote, "cat-file", "-e", `${contentCommit}:${evidencePath}/guide.md`, ], { cwd: remote.root })).resolves.toBeDefined(); }); test("rejects a stale API update after a content-only Evidence commit", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); const initial = await read(registry, "psd-clinical"); const guide = join(remote.source, "workspace-content", "psd-clinical", "evidence", "guide.md"); writeFileSync(guide, "curator content\n"); await git(remote.source, ["add", "workspace-content/psd-clinical/evidence/guide.md"]); await git(remote.source, ["commit", "-m", "Curator Evidence update"]); await git(remote.source, ["push", "origin", "main"]); const curatorCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); await expect(publish(registry, { action: "update", workspace: filesystemWorkspace("psd-clinical"), baseCommit: initial.revision.commit, baseBlob: initial.revision.blob, })).rejects.toMatchObject({ code: "workspace_stale" }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"])).toBe(curatorCommit); }); test("keeps content-only historical descriptor revisions distinguishable by commit", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); writeFileSync( join(remote.source, "workspace-content", "psd-clinical", "evidence", "guide.md"), "historical content\n", ); await git(remote.source, ["add", "workspace-content/psd-clinical/evidence/guide.md"]); await git(remote.source, ["commit", "-m", "Retained Evidence update"]); await git(remote.source, ["push", "origin", "main"]); const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); await pull(registry); await reconcileWorkspaceSnapshotRetention(registry, [remote.initialCommit]); const retained = (await registry.listRetainedSnapshots()).filter(({ id }) => id === "psd-clinical"); expect(retained.map(({ commit }) => commit)).toEqual([contentCommit, remote.initialCommit]); const oldPinned = await registry.readPinned("psd-clinical", remote.initialCommit); const newPinned = await registry.readPinned("psd-clinical", contentCommit); expect(oldPinned.workspaceConfigPath).not.toBe(newPinned.workspaceConfigPath); expect(oldPinned.workspace).toEqual(newPinned.workspace); }); test("publishes create, update, and delete with the configured Git author identity", async () => { const remote = await fixture(); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote, { gitAuthorName: "Configured Workspace Publisher", gitAuthorEmail: "publisher@example.invalid", })); await bootstrap(registry); const createdWorkspace = workspaceWith("research-registry", { name: "Research registry" }); const created = await publish(registry, { action: "create", workspace: createdWorkspace, baseCommit: remote.initialCommit, }); expect(created).toMatchObject({ id: "research-registry", commit: expect.stringMatching(/^[0-9a-f]{40}$/) }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "log", "-1", "--format=%an <%ae>"])).toBe( "Configured Workspace Publisher ", ); await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspace-docs/research-registry/README.md"], { cwd: remote.root, })).resolves.toBeDefined(); const updated = await publish(registry, { action: "update", workspace: workspaceWith("research-registry", { description: "Updated workspace description" }), baseCommit: created!.commit, baseBlob: created!.blob, }); expect(updated).toMatchObject({ id: "research-registry" }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "show", "HEAD:workspaces/research-registry.yaml"])).toContain( "description: Updated workspace description", ); await expect(publish(registry, { action: "delete", id: "research-registry", baseCommit: updated!.commit, baseBlob: updated!.blob, })).resolves.toBeUndefined(); await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspaces/research-registry.yaml"], { cwd: remote.root, })).rejects.toBeDefined(); }); test("reports stale publish conflicts with expected and actual revisions", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const initial = await read(registry, "psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "schema: datawarehouse", "schema: analytics", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Change dwh schema"]); await git(remote.source, ["push", "origin", "main"]); const actualCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); const actualBlob = await gitOutput(remote.source, ["rev-parse", "HEAD:workspaces/psd-clinical.yaml"]); await expect(publish(registry, { action: "update", workspace: workspaceWith("psd-clinical", { description: "Local stale change" }), baseCommit: initial.revision.commit, baseBlob: initial.revision.blob, })).rejects.toMatchObject({ code: "workspace_conflict", fields: ["dwh.schema"], expected: { commit: initial.revision.commit, blob: initial.revision.blob }, actual: { commit: actualCommit, blob: actualBlob }, }); }); test.each([ ["adds", validYaml, withDwhRestDiagnostic(validYaml)], ["removes", withDwhRestDiagnostic(validYaml), validYaml], ])("reports an optional diagnostics branch when the registry %s it", async (_operation, baseSource, remoteSource) => { const remote = await fixture(baseSource); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); const initial = await read(registry, "psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), remoteSource); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", `Registry ${_operation} diagnostic branch`]); await git(remote.source, ["push", "origin", "main"]); await expect(publish(registry, { action: "update", workspace: workspaceWith("psd-clinical", { description: "Local stale change" }), baseCommit: initial.revision.commit, baseBlob: initial.revision.blob, })).rejects.toMatchObject({ code: "workspace_conflict", fields: ["dwh.supported_transports", "diagnostics"], }); }); test("restores a clean checkout after a failed commit and retries publication", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const objects = join(root, "repo", ".git", "objects"); chmodSync(objects, 0o500); const request = { action: "create" as const, workspace: workspaceWith("commit-recovery"), baseCommit: remote.initialCommit, }; try { await expect(publish(registry, request)).rejects.toMatchObject({ code: "git_unavailable" }); } finally { chmodSync(objects, 0o700); } expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" }); await expect(pull(registry)).resolves.toMatchObject({ head: remote.initialCommit }); await expect(publish(registry, request)).resolves.toMatchObject({ id: "commit-recovery" }); }); test("resets an ahead checkout after a rejected push and retries publication", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const hook = join(remote.remote, "hooks", "pre-receive"); writeFileSync(hook, "#!/bin/sh\nexit 1\n", { mode: 0o755 }); const request = { action: "create" as const, workspace: workspaceWith("push-recovery"), baseCommit: remote.initialCommit, }; await expect(publish(registry, request)).rejects.toMatchObject({ code: "git_push_rejected" }); expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" }); rmSync(hook); await expect(pull(registry)).resolves.toMatchObject({ head: remote.initialCommit }); await expect(publish(registry, request)).resolves.toMatchObject({ id: "push-recovery" }); }); test.each([ ["v1", legacyV1Yaml()], ["v2", legacyV2Yaml()], ])("rejects a schema %s descriptor instead of activating it", async (_version, legacyYaml) => { const remote = await fixture(legacyYaml); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await expect(bootstrap(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); expect(existsSync(join(remote.root, "registry", "state", "active.json"))).toBe(false); }); test("writes only state-free revisions and never exposes revision state", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const initial = persistedState(root, remote.initialCommit); expect(Object.keys(initial.active).sort()).toEqual(["head", "revisions"]); expect(Object.keys(initial.manifest).sort()).toEqual(["files", "head", "revisions"]); expect(Object.keys(initial.active.revisions[0]).sort()).toEqual(["blob", "commit", "id", "snapshotPath"]); expect(Object.keys(initial.manifest.revisions[0]).sort()).toEqual(["blob", "commit", "id", "snapshotPath"]); const listed = await list(registry); const readResult = await read(registry, "psd-clinical"); expect(listed[0]).not.toHaveProperty("state"); expect(readResult.revision).not.toHaveProperty("state"); const published = await publish(registry, { action: "update", workspace: workspaceWith("psd-clinical", { name: "State-free revision" }), baseCommit: remote.initialCommit, baseBlob: listed[0]!.blob, }); const updated = persistedState(root, published!.commit); expect(updated.active.revisions[0]).not.toHaveProperty("state"); expect(updated.manifest.revisions[0]).not.toHaveProperty("state"); expect(published).not.toHaveProperty("state"); }); test("accepts historical operational state without leaking it or rewriting the immutable snapshot", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); rewritePersistedRevisionStates(root, remote.initialCommit, "operational", "operational"); const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json"); const historicalManifest = readFileSync(snapshotPath, "utf8"); const restored = makeRegistry(config(root, remote.remote)); const listed = await list(restored); const readResult = await read(restored, "psd-clinical"); expect(listed[0]).not.toHaveProperty("state"); expect(readResult.revision).not.toHaveProperty("state"); expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest); await bootstrap(restored); const rewrittenActive = persistedState(root, remote.initialCommit).active; expect(rewrittenActive.revisions[0]).not.toHaveProperty("state"); expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest); }); test.each([ ["historical active and state-free snapshot", "operational", "absent"], ["state-free active and historical snapshot", "absent", "operational"], ] as const)("normalizes mixed persisted revision encodings: %s", async (_name, activeState, manifestState) => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); rewritePersistedRevisionStates(root, remote.initialCommit, activeState, manifestState); const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json"); const historicalManifest = readFileSync(snapshotPath, "utf8"); const revisions = await list(makeRegistry(config(root, remote.remote))); expect(revisions[0]).not.toHaveProperty("state"); expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest); }); test.each([ ["migration_required in active state", "migration_required", "absent"], ["migration_required in snapshot manifest", "absent", "migration_required"], ["unknown state in active state", "unknown", "operational"], ["unknown state in snapshot manifest", "operational", "unknown"], ] as const)("rejects %s", async (_name, activeState, manifestState) => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); rewritePersistedRevisionStates(root, remote.initialCommit, activeState, manifestState); await expect(list(makeRegistry(config(root, remote.remote)))).rejects.toMatchObject({ code: "workspace_invalid", }); }); test.each([ ["active top level", "active", "top"], ["active revision", "active", "revision"], ["snapshot top level", "manifest", "top"], ["snapshot revision", "manifest", "revision"], ] as const)("rejects unknown fields in %s", async (_name, component, location) => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); const path = component === "active" ? join(root, "state", "active.json") : join(root, "snapshots", remote.initialCommit, "snapshot.json"); const persisted = JSON.parse(readFileSync(path, "utf8")); if (location === "top") persisted.unexpected = true; else persisted.revisions[0].unexpected = true; if (component === "manifest") chmodSync(path, 0o600); writeFileSync(path, JSON.stringify(persisted)); await expect(list(makeRegistry(config(root, remote.remote)))).rejects.toMatchObject({ code: "workspace_invalid", }); }); test("normalizes operational state in retained historical snapshots without rewriting them", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Current workspace", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Update active workspace"]); await git(remote.source, ["push", "origin", "main"]); await pull(registry); rewritePersistedRevisionStates(root, remote.initialCommit, "absent", "operational"); const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json"); const historicalManifest = readFileSync(snapshotPath, "utf8"); const retained = await makeRegistry(config(root, remote.remote)).listRetainedSnapshots(); expect(retained).toEqual(expect.arrayContaining([ expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit }), ])); expect(retained.every((revision) => !("state" in revision))).toBe(true); expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest); }); test("normalizes historical operational state during offline fallback after restart", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); rewritePersistedRevisionStates(root, remote.initialCommit, "operational", "operational"); rmSync(remote.remote, { recursive: true, force: true }); const restored = makeRegistry(config(root, remote.remote)); await expect(pull(restored)).resolves.toMatchObject({ degraded: true, head: remote.initialCommit }); const listed = await list(restored); const readResult = await read(restored, "psd-clinical"); expect(listed[0]).not.toHaveProperty("state"); expect(readResult.revision).not.toHaveProperty("state"); }); test("fails closed when a retained snapshot descriptor is not schema v3", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); await bootstrap(makeRegistry(config(root, remote.remote))); const snapshotDirectory = join(root, "snapshots", remote.initialCommit); const yamlPath = join(snapshotDirectory, "psd-clinical.yaml"); chmodSync(yamlPath, 0o600); const legacy = legacyV2Yaml(); writeFileSync(yamlPath, legacy); const manifestPath = join(snapshotDirectory, "snapshot.json"); const manifest = JSON.parse(readFileSync(manifestPath, "utf8")); manifest.files["psd-clinical.yaml"] = createHash("sha256").update(legacy).digest("hex"); chmodSync(manifestPath, 0o600); writeFileSync(manifestPath, JSON.stringify(manifest)); await expect(list(makeRegistry(config(root, remote.remote)))).rejects.toMatchObject({ code: "workspace_invalid", }); }); test("keeps the last valid snapshot when a pulled commit has invalid YAML", async () => { const remote = await fixture(); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); await pushInvalidWorkspace(remote.source); await expect(pull(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }); test("rejects duplicate schema v3 collection ownership and keeps the previous active snapshot", async () => { const v3Yaml = validYaml; const remote = await multiWorkspaceFixture({ "psd-clinical": v3Yaml, "research-clinical": v3Yaml .replace("id: psd-clinical", "id: research-clinical") .replace("name: Policlinico San Donato", "name: Research Clinical") .replace("collection: psd-clinical", "collection: research-clinical"), }); const registry = makeRegistry(config(join(remote.root, "registry"), remote.remote)); await bootstrap(registry); writeFileSync( join(remote.source, "workspaces", "research-clinical.yaml"), v3Yaml .replace("id: psd-clinical", "id: research-clinical") .replace("name: Policlinico San Donato", "name: Research Clinical") .replace("collection: psd-clinical", "collection: shared"), ); writeFileSync( join(remote.source, "workspaces", "psd-clinical.yaml"), v3Yaml.replace("collection: psd-clinical", "collection: shared"), ); await git(remote.source, ["add", "workspaces"]); await git(remote.source, ["commit", "-m", "Duplicate collection ownership"]); await git(remote.source, ["push", "origin", "main"]); await expect(pull(registry)).rejects.toMatchObject({ code: "workspace_invalid", message: "Workspace repository content is invalid", }); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); await expect(read(registry, "research-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }); test("retains a historical snapshot while a resumable manifest still references its revision", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Updated Policlinico San Donato", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Update workspace"]); await git(remote.source, ["push", "origin", "main"]); const currentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); await pull(registry); await reconcileWorkspaceSnapshotRetention(registry, [remote.initialCommit]); expect(existsSync(workspaceRegistrySnapshotPath(registry, remote.initialCommit, "psd-clinical"))).toBe(true); expect(existsSync(workspaceRegistrySnapshotPath(registry, currentCommit, "psd-clinical"))).toBe(true); await reconcileWorkspaceSnapshotRetention(registry, []); expect(existsSync(workspaceRegistrySnapshotPath(registry, remote.initialCommit, "psd-clinical"))).toBe(false); expect(existsSync(workspaceRegistrySnapshotPath(registry, currentCommit, "psd-clinical"))).toBe(true); }); test("a session revision lease survives stale retention scans until its manifest is observed", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const lease = await registry.acquireSessionRevision("psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Concurrent revision", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Publish while session is starting"]); await git(remote.source, ["push", "origin", "main"]); await pull(registry); await reconcileWorkspaceSnapshotRetention(registry, []); expect(existsSync(workspaceRegistrySnapshotPath(registry, remote.initialCommit, "psd-clinical"))).toBe(true); await lease.markPersisted(); await reconcileWorkspaceSnapshotRetention(registry, []); expect(existsSync(workspaceRegistrySnapshotPath(registry, remote.initialCommit, "psd-clinical"))).toBe(true); await reconcileWorkspaceSnapshotRetention(registry, [remote.initialCommit]); await reconcileWorkspaceSnapshotRetention(registry, []); expect(existsSync(workspaceRegistrySnapshotPath(registry, remote.initialCommit, "psd-clinical"))).toBe(false); }); test("lists operational descriptors retained after their workspace was removed from the active revision", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); writeFileSync(join(remote.source, "workspaces", "archive-only.yaml"), validYaml.replace( "id: psd-clinical", "id: archive-only", ).replace("collection: psd-clinical", "collection: archive-only")); await git(remote.source, ["add", "workspaces/archive-only.yaml"]); await git(remote.source, ["commit", "-m", "Add retained workspace"]); await git(remote.source, ["push", "origin", "main"]); await pull(registry); rmSync(join(remote.source, "workspaces", "psd-clinical.yaml")); await git(remote.source, ["add", "-u"]); await git(remote.source, ["commit", "-m", "Remove original workspace"]); await git(remote.source, ["push", "origin", "main"]); await pull(registry); const retained = await registry.listRetainedSnapshots(); expect(retained).toEqual(expect.arrayContaining([ expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit }), expect.objectContaining({ id: "archive-only" }), ])); }); test("does not bypass an existing live advisory repository lock", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); const lock = new WorkspaceRepositoryLock(join(root, "locks")); let release!: () => void; let started!: () => void; const held = lock.run(async () => { started(); await new Promise((resolve) => { release = resolve; }); }); await new Promise((resolve) => { started = resolve; }); try { await expect(bootstrap(registry)).rejects.toMatchObject({ code: "workspace_stale" }); } finally { release(); await held; } }); test("rejects a symbolic-link registry root before creating a lock below it", async () => { const remote = await fixture(); const target = join(remote.root, "registry-target"); const root = join(remote.root, "registry-link"); mkdirSync(target); symlinkSync(target, root); const registry = makeRegistry(config(root, remote.remote)); await expect(bootstrap(registry)).rejects.toMatchObject({ code: "git_unavailable" }); expect(existsSync(join(target, "locks"))).toBe(false); }); test("rejects a locally-ahead checkout instead of activating local-only content", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const checkout = join(root, "repo"); writeFileSync(join(checkout, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Local only workspace", )); await git(checkout, ["config", "user.name", "Workspace Registry Test"]); await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]); await git(checkout, ["add", "workspaces/psd-clinical.yaml"]); await git(checkout, ["commit", "-m", "Local-only workspace"]); await expect(pull(registry)).rejects.toMatchObject({ code: "git_non_fast_forward" }); await expect(read(registry, "psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, workspace: { workspace: { name: "Policlinico San Donato" } }, }); }); test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); mkdirSync(join(root, "locks"), { recursive: true }); writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 })); const registry = makeRegistry(config(root, remote.remote)); await expect(bootstrap(registry)).resolves.toMatchObject({ head: remote.initialCommit, degraded: false, }); }); test.each(["manifest", "blob", "workspace", "document"])( "rejects a corrupted %s snapshot component instead of reporting it active", async (component) => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const snapshot = join(root, "snapshots", remote.initialCommit); if (component === "manifest") { const file = join(snapshot, "snapshot.json"); chmodSync(file, 0o600); writeFileSync(file, "{"); } if (component === "blob") { const activePath = join(root, "state", "active.json"); const active = JSON.parse(readFileSync(activePath, "utf8")); active.revisions[0].blob = "not-a-git-blob"; writeFileSync(activePath, JSON.stringify(active)); } if (component === "workspace") { const file = join(snapshot, "psd-clinical.yaml"); chmodSync(file, 0o600); writeFileSync(file, "truncated"); } if (component === "document") rmSync(join(snapshot, "psd-clinical.md")); await expect(list(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(read(registry, "psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" }); }, ); test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = makeRegistry(config(root, remote.remote)); await bootstrap(registry); const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md"); chmodSync(document, 0o600); writeFileSync(document, "corrupt"); rmSync(remote.remote, { recursive: true, force: true }); await expect(pull(registry)).rejects.toMatchObject({ code: "workspace_invalid" }); }); test("snapshots canonical Evidence artifacts at the active commit without copying Evidence bytes", async () => { const remote = await fixture(withFilesystemEvidence(validYaml)); const registryRoot = join(remote.root, "registry"); const registry = makeRegistry(config(registryRoot, remote.remote)); const status = await bootstrap(registry); const active = await read(registry, "psd-clinical"); const snapshotDirectory = join(registryRoot, "snapshots", status.head!); const descriptor = active.workspace as CanonicalWorkspace; const docs = renderWorkspaceDocs(descriptor); const expectedFiles: Record = { "psd-clinical.yaml": serializeWorkspaceYaml(descriptor), "psd-clinical.env.example": docs.envExample, "psd-clinical.md": docs.markdown, }; const manifest = JSON.parse(readFileSync(join(snapshotDirectory, "snapshot.json"), "utf8")); expect(status.head).toBe(remote.initialCommit); const committedDescriptor = parseWorkspaceYaml(await gitOutput(remote.source, [ "show", `${remote.initialCommit}:workspaces/psd-clinical.yaml`, ])) as CanonicalWorkspace; const committedBlob = await gitOutput(remote.source, [ "rev-parse", `${remote.initialCommit}:workspaces/psd-clinical.yaml`, ]); expect(active.revision.blob).toBe(committedBlob); expect(expectedFiles["psd-clinical.yaml"]).toBe(serializeWorkspaceYaml(committedDescriptor)); expect(readdirSync(snapshotDirectory).sort()).toEqual([ "psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "snapshot.json", ]); expect(manifest.head).toBe(remote.initialCommit); expect(manifest.revisions[0]).toMatchObject({ id: "psd-clinical", commit: remote.initialCommit, blob: committedBlob, }); expect(Object.keys(manifest.files).sort()).toEqual(Object.keys(expectedFiles).sort()); for (const [name, contents] of Object.entries(expectedFiles)) { expect(readFileSync(join(snapshotDirectory, name), "utf8")).toBe(contents); expect(manifest.files[name]).toBe(createHash("sha256").update(contents).digest("hex")); } expect(JSON.stringify(manifest)).not.toContain("workspace-content/"); expect(readdirSync(snapshotDirectory).some((name) => name === "workspace-content")).toBe(false); expect(readFileSync(join(remote.source, "workspace-content/psd-clinical/evidence/guide.md"), "utf8")) .toBe("guide v1\n"); }); test("never copies an installation secret canary into Git, generated artifacts, metadata, or errors", async () => { const remote = await fixture(validYaml.concat(`evidence: source: type: http uris: [https://evidence.example.test/guide.md] authentication: signed_urls_file `)); const canary = "CANARY-EVIDENCE-SECRET-ONLY-IN-FIXTURE"; const secretDirectory = join(remote.root, "fixture-secrets"); mkdirSync(secretDirectory); const secretFile = join(secretDirectory, "signed-urls"); writeFileSync(secretFile, canary); const registryRoot = join(remote.root, "registry"); const registry = makeRegistry(config(registryRoot, remote.remote, { secretRoots: [secretDirectory], })); const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE; process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = secretFile; try { const status = await bootstrap(registry); const snapshotDirectory = join(registryRoot, "snapshots", status.head!); let gitBlobText = ""; try { gitBlobText = (await runFile( "git", ["grep", "-I", "-h", "-e", canary, "HEAD", "--", "."], { cwd: remote.source }, )).stdout; } catch (error) { if (!error || typeof error !== "object" || !("code" in error) || error.code !== 1) throw error; gitBlobText = "stdout" in error ? String(error.stdout ?? "") : ""; } expect(gitBlobText).toBe(""); for (const name of readdirSync(snapshotDirectory)) { expect(readFileSync(join(snapshotDirectory, name), "utf8")).not.toContain(canary); } let thrown: unknown; try { await publish(registry, { action: "create", workspace: filesystemWorkspace("missing-secret-canary-tree"), baseCommit: status.head!, }); } catch (error) { thrown = error; } expect(thrown).toMatchObject({ code: "workspace_invalid" }); expect(String(thrown)).not.toContain(canary); } finally { if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE; else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous; } });