import assert from "node:assert/strict"; import { mkdir, mkdtemp, readFile, rm, writeFile } from "node:fs/promises"; import { tmpdir } from "node:os"; import { dirname, join } from "node:path"; import test from "node:test"; import { fileURLToPath } from "node:url"; import { CHECK_IDS, canonicalIntegrationBase, cleanupOwnedRun, createOwnedRun, readAndValidateOwnership, validateReport, validateRunRoot, } from "./p11-acceptance.mjs"; const roots = []; async function fakeRepository() { const root = await mkdtemp(join(tmpdir(), "p11-acceptance-repo-")); roots.push(root); await mkdir(join(root, ".artifacts", "p11-integration"), { recursive: true }); await mkdir(join(root, ".artifacts", "p1-integration"), { recursive: true }); await mkdir(join(root, ".artifacts", "manual-acceptance", "p11"), { recursive: true }); return root; } test.afterEach(async () => { await Promise.all(roots.splice(0).map((root) => rm(root, { recursive: true, force: true }))); }); test("run roots are only canonical direct p11 integration children", async () => { const repositoryRoot = await fakeRepository(); const base = canonicalIntegrationBase(repositoryRoot); const id = `p11-${"a".repeat(32)}`; assert.equal(validateRunRoot(repositoryRoot, join(base, id), id), join(base, id)); for (const candidate of [ base, join(repositoryRoot, ".artifacts", "manual-acceptance", "p11"), join(repositoryRoot, ".artifacts", "p1-integration", id), join(base, id, "nested"), join(base, "foreign"), ]) { assert.throws(() => validateRunRoot(repositoryRoot, candidate, id)); } assert.throws(() => validateRunRoot(repositoryRoot, join(base, `p11-${"A".repeat(32)}`), `p11-${"A".repeat(32)}`)); }); test("cleanup refuses p1, manual, sibling, and wrong-nonce roots", async () => { const repositoryRoot = await fakeRepository(); const run = await createOwnedRun({ repositoryRoot }); await readAndValidateOwnership({ repositoryRoot, runRoot: run.root, expectedNonce: run.nonce }); for (const bad of [ join(repositoryRoot, ".artifacts", "p1-integration", `p1-${"b".repeat(32)}`), join(repositoryRoot, ".artifacts", "manual-acceptance", "p11"), join(canonicalIntegrationBase(repositoryRoot), `p11-${"c".repeat(32)}`), ]) { await assert.rejects(cleanupOwnedRun({ repositoryRoot, runRoot: bad, expectedNonce: run.nonce })); } await assert.rejects(cleanupOwnedRun({ repositoryRoot, runRoot: run.root, expectedNonce: "0".repeat(64) })); }); test("cleanup removes exactly one owned p11 root", async () => { const repositoryRoot = await fakeRepository(); const run = await createOwnedRun({ repositoryRoot }); const sibling = join(canonicalIntegrationBase(repositoryRoot), `p11-${"d".repeat(32)}`); await mkdir(sibling); await writeFile(join(sibling, "sentinel"), "foreign"); await cleanupOwnedRun({ repositoryRoot, runRoot: run.root, expectedNonce: run.nonce }); await assert.rejects(readFile(join(run.root, "ownership.json"))); assert.equal(await readFile(join(sibling, "sentinel"), "utf8"), "foreign"); }); function resultFor(id) { return { id, status: "PASS", startedAt: "2026-08-11T00:00:00.000Z", finishedAt: "2026-08-11T00:00:01.000Z", commands: ["git"], artifacts: [{ path: `logs/${id}.json`, sha256: "a".repeat(64) }], }; } test("report validation requires exact p11 identity, check order, and unique artifacts", () => { const report = { schemaVersion: 1, runId: `p11-${"e".repeat(32)}`, startedAt: "2026-08-11T00:00:00.000Z", finishedAt: "2026-08-11T00:00:10.000Z", command: "p11-acceptance integration --keep", overall: "PASS", checks: CHECK_IDS.map(resultFor), }; assert.doesNotThrow(() => validateReport(report)); const invalid = structuredClone(report); invalid.runId = `p1-${"e".repeat(32)}`; assert.throws(() => validateReport(invalid)); const duplicate = structuredClone(report); duplicate.checks[1].artifacts[0].path = duplicate.checks[0].artifacts[0].path; assert.throws(() => validateReport(duplicate), /duplicated/); const reordered = structuredClone(report); reordered.checks.reverse(); reordered.overall = "FAIL"; assert.throws(() => validateReport(reordered)); }); test("public wrapper uses a strict empty environment", async () => { const wrapper = await readFile(join(dirname(fileURLToPath(import.meta.url)), "..", "..", "scripts", "p11-acceptance.sh"), "utf8"); assert.match(wrapper, /safe_env=\(\/usr\/bin\/env -i/); assert.doesNotMatch(wrapper, /LANG|LC_ALL|TZ/); assert.doesNotMatch(wrapper, /P11_ACCEPTANCE_FAIL_AT/); });