import { chmodSync, lstatSync, mkdirSync, mkdtempSync, readFileSync, rmSync, symlinkSync, writeFileSync } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { afterEach, expect, test } from "vitest"; import { syncAnnotations } from "../src/workspaces/annotations-sync.js"; const temporaryRoots: string[] = []; afterEach(() => { temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true })); }); function input(overrides: Partial<{ dataRoot: string; workspaceId: string; commit: string; blobId: string; contents: Buffer; }> = {}) { return { dataRoot: overrides.dataRoot ?? "", workspaceId: overrides.workspaceId ?? "research", commit: overrides.commit ?? "a".repeat(40), blobId: overrides.blobId ?? "b".repeat(40), contents: overrides.contents ?? Buffer.from("tables: {}\n"), }; } test("writes the revision-qualified annotations file and ownership manifest", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const target = input({ dataRoot }); const result = syncAnnotations(target); expect(readFileSync(result.path, "utf8")).toBe("tables: {}\n"); const manifest = JSON.parse(readFileSync(result.manifestPath, "utf8")); expect(manifest).toMatchObject({ workspace: "research", commit: "a".repeat(40), blobId: "b".repeat(40), contentDigest: result.contentDigest, destination: result.path, }); expect(result.path).toContain("/revisions/" + "a".repeat(40) + "/artifacts/mschema/annotations.yaml"); expect(lstatSync(result.path).mode & 0o777).toBe(0o400); }); test("is idempotent for the exact same blob and manifest", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const target = input({ dataRoot }); expect(syncAnnotations(target)).toEqual(syncAnnotations(target)); }); test("fails closed when the destination was tampered", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const target = input({ dataRoot }); syncAnnotations(target); const dest = join(dataRoot, "sessions", "research", "revisions", "a".repeat(40), "artifacts", "mschema", "annotations.yaml"); chmodSync(dest, 0o600); writeFileSync(dest, "tampered\n"); expect(() => syncAnnotations(target)).toThrow(); }); test("fails closed when the ownership manifest does not match", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const target = input({ dataRoot }); syncAnnotations(target); const manifestPath = join(dataRoot, "sessions", "research", "revisions", "a".repeat(40), "artifacts", "mschema", "annotations.ownership.json"); writeFileSync(manifestPath, JSON.stringify({ workspace: "other", commit: "c".repeat(40), blobId: "d".repeat(40), contentDigest: "sha256:x", destination: "/other" })); expect(() => syncAnnotations(target)).toThrow(); }); test("writes different revisions to different directories", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const first = syncAnnotations(input({ dataRoot, commit: "a".repeat(40) })); const second = syncAnnotations(input({ dataRoot, commit: "b".repeat(40) })); expect(first.path).not.toBe(second.path); expect(readFileSync(second.path, "utf8")).toBe("tables: {}\n"); }); test("rejects a symlink destination and malformed inputs before writing", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const root = join(dataRoot, "sessions", "research", "revisions", "a".repeat(40), "artifacts"); mkdirSync(root, { recursive: true }); symlinkSync(join(root, "mschema-target"), join(root, "mschema")); mkdirSync(join(root, "mschema-target")); expect(() => syncAnnotations(input({ dataRoot }))).toThrow(); expect(() => syncAnnotations(input({ dataRoot: "relative" }))).toThrow(); expect(() => syncAnnotations(input({ workspaceId: "../x" }))).toThrow(); expect(() => syncAnnotations(input({ commit: "HEAD" }))).toThrow(); expect(() => syncAnnotations(input({ blobId: "not-hex" }))).toThrow(); expect(() => syncAnnotations(input({ contents: Buffer.from("tables: [bad]\n") }))).toThrow(); }); test("does not follow a symlinked destination when verifying", () => { const dataRoot = mkdtempSync(join(tmpdir(), "thoth-annotations-sync-")); temporaryRoots.push(dataRoot); const target = input({ dataRoot }); syncAnnotations(target); const dest = join(dataRoot, "sessions", "research", "revisions", "a".repeat(40), "artifacts", "mschema", "annotations.yaml"); rmSync(dest, { force: true }); symlinkSync("/etc/hosts", dest); expect(() => syncAnnotations(target)).toThrow(); });