import { execFile } from "node:child_process"; import { createHash } from "node:crypto"; import { chmodSync, existsSync, mkdtempSync, mkdirSync, readFileSync, rmSync, symlinkSync, writeFileSync, } from "node:fs"; import { tmpdir } from "node:os"; import { join } from "node:path"; import { promisify } from "node:util"; import { afterEach, expect, test } from "vitest"; import { WorkspaceRepositoryLock } from "../src/workspaces/git-repository.js"; import { WorkspaceRegistry } from "../src/workspaces/registry.js"; import { parseWorkspaceYaml, type CanonicalWorkspace } from "../src/workspaces/schema.js"; import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js"; const validYaml = `workspace: schema_version: 2 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct] semantic_index: vector_store: engine: pgvector database: postgres schema: vectors collection: clinical_documents dimensions: 768 distance: cosine supported_transports: [pgvector_direct] embedding: provider: ollama_compatible model: nomic-embed-text-v2-moe dimensions: 768 llm_policy: allowed: [zai/glm-5.2] `; function withDwhRestTransport(source: string): string { return source.replace( "supported_transports: [postgres_direct]", "supported_transports: [postgres_direct, rest_api]", ); } function withDwhRestDiagnostic(source: string): string { return withDwhRestTransport(source).concat(`diagnostics: dwh_rest: method: GET path: /health auth: none response: database: database schema: schema `); } function withEmbeddingDiagnostic(source: string): string { return source.concat(`diagnostics: embedding: method: GET path: /models auth: none response: model: model dimensions: dimensions `); } function withDwhRestAndEmbeddingDiagnostics(source: string): string { return withDwhRestTransport(source).concat(`diagnostics: dwh_rest: method: GET path: /health auth: none response: database: database schema: schema embedding: method: GET path: /models auth: none response: model: model dimensions: dimensions `); } function withVectorRestTransport(source: string): string { return source.replace( "supported_transports: [pgvector_direct]", "supported_transports: [pgvector_direct, rest_api]", ); } function withVectorMetadataDiagnostic(source: string): string { return withVectorRestTransport(source).concat(`diagnostics: vector_rest: metadata: method: GET path: /metadata auth: none response: collection: collection dimensions: dimensions distance: distance `); } function withReversibleVectorProbe(source: string): string { return withVectorRestTransport(source).concat(`diagnostics: vector_rest: metadata: method: GET path: /metadata auth: none response: collection: collection dimensions: dimensions distance: distance reversible_probe: method: POST path: /probe auth: bearer response: operation: operation `); } const runFile = promisify(execFile); const temporaryRoots: string[] = []; afterEach(() => { temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true })); }); async function git(cwd: string, args: string[]): Promise { await runFile("git", args, { cwd }); } async function gitOutput(cwd: string, args: string[]): Promise { const { stdout } = await runFile("git", args, { cwd }); return stdout.trim(); } async function fixture(workspaceSource = validYaml): Promise<{ root: string; remote: string; source: string; initialCommit: string; }> { const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-")); temporaryRoots.push(root); const remote = join(root, "remote.git"); const source = join(root, "source"); await git(root, ["init", "--bare", "--initial-branch=main", remote]); mkdirSync(source); await git(source, ["init", "--initial-branch=main"]); await git(source, ["config", "user.name", "Workspace Registry Test"]); await git(source, ["config", "user.email", "workspace-registry@example.invalid"]); mkdirSync(join(source, "workspaces")); writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), workspaceSource); await git(source, ["add", "workspaces/psd-clinical.yaml"]); await git(source, ["commit", "-m", "Initial workspace"]); await git(source, ["remote", "add", "origin", remote]); await git(source, ["push", "origin", "main"]); const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source }); return { root, remote, source, initialCommit: stdout.trim() }; } function config( root: string, remoteUrl: string, overrides: Partial = {}, ): WorkspaceRegistryConfig { return { root, remoteUrl, branch: "main", gitAuthorName: "Workspace Registry Test", gitAuthorEmail: "workspace-registry@example.invalid", installationId: "test", secretRoots: [], maxImportBytes: 1024, maxImportEntries: 1, ...overrides, }; } function workspaceWith( id: string, changes: Partial> = {}, ): CanonicalWorkspace { const workspace = parseWorkspaceYaml(validYaml) as CanonicalWorkspace; return { ...workspace, workspace: { ...workspace.workspace, id, name: id, ...changes }, }; } async function checkoutStatus(checkout: string): Promise<{ porcelain: string; divergence: string }> { return { porcelain: await gitOutput(checkout, ["status", "--porcelain"]), divergence: await gitOutput(checkout, ["rev-list", "--left-right", "--count", "HEAD...@{upstream}"]), }; } async function pushInvalidWorkspace(source: string): Promise { writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), "workspace: invalid\n"); await git(source, ["add", "workspaces/psd-clinical.yaml"]); await git(source, ["commit", "-m", "Invalid workspace"]); await git(source, ["push", "origin", "main"]); } function legacyDigest(contents: string): string { return createHash("sha256").update(contents).digest("hex"); } function persistPreStateManifest(root: string, commit: string): void { const snapshotDirectory = join(root, "snapshots", commit); const activePath = join(root, "state", "active.json"); const snapshotPath = join(snapshotDirectory, "snapshot.json"); const active = JSON.parse(readFileSync(activePath, "utf8")); const manifest = JSON.parse(readFileSync(snapshotPath, "utf8")); const envName = "psd-clinical.env.example"; const docsName = "psd-clinical.md"; const envExample = "# Legacy registry artifact\n"; const markdown = "# Legacy registry artifact\n"; writeFileSync(join(snapshotDirectory, envName), envExample); writeFileSync(join(snapshotDirectory, docsName), markdown); active.revisions = active.revisions.map(({ state: _state, ...revision }: Record) => revision); manifest.revisions = manifest.revisions.map(({ state: _state, ...revision }: Record) => revision); manifest.files = { "psd-clinical.yaml": manifest.files["psd-clinical.yaml"], [envName]: legacyDigest(envExample), [docsName]: legacyDigest(markdown), }; writeFileSync(activePath, JSON.stringify(active)); chmodSync(snapshotPath, 0o600); writeFileSync(snapshotPath, JSON.stringify(manifest)); } test("bootstraps a checkout and activates a validated immutable snapshot", async () => { const remote = await fixture(); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); const status = await registry.bootstrap(); expect(status.head).toMatch(/^[0-9a-f]{40}$/); expect(existsSync(registry.snapshotPath(status.head!, "psd-clinical"))).toBe(true); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit, id: "psd-clinical" }, }); }); test("publishes create, update, and delete with the configured Git author identity", async () => { const remote = await fixture(); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote, { gitAuthorName: "Configured Workspace Publisher", gitAuthorEmail: "publisher@example.invalid", })); await registry.bootstrap(); const createdWorkspace = workspaceWith("research-registry", { name: "Research registry" }); const created = await registry.publish({ action: "create", workspace: createdWorkspace, baseCommit: remote.initialCommit, }); expect(created).toMatchObject({ id: "research-registry", commit: expect.stringMatching(/^[0-9a-f]{40}$/) }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "log", "-1", "--format=%an <%ae>"])).toBe( "Configured Workspace Publisher ", ); await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspace-docs/research-registry/README.md"], { cwd: remote.root, })).resolves.toBeDefined(); const updated = await registry.publish({ action: "update", workspace: workspaceWith("research-registry", { description: "Updated workspace description" }), baseCommit: created!.commit, baseBlob: created!.blob, }); expect(updated).toMatchObject({ id: "research-registry" }); expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "show", "HEAD:workspaces/research-registry.yaml"])).toContain( "description: Updated workspace description", ); await expect(registry.publish({ action: "delete", id: "research-registry", baseCommit: updated!.commit, baseBlob: updated!.blob, })).resolves.toBeUndefined(); await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspaces/research-registry.yaml"], { cwd: remote.root, })).rejects.toBeDefined(); }); test("reports stale publish conflicts with expected and actual revisions", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const initial = await registry.read("psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "model: nomic-embed-text-v2-moe", "model: mxbai-embed-large", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Change embedding model"]); await git(remote.source, ["push", "origin", "main"]); const actualCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); const actualBlob = await gitOutput(remote.source, ["rev-parse", "HEAD:workspaces/psd-clinical.yaml"]); await expect(registry.publish({ action: "update", workspace: workspaceWith("psd-clinical", { description: "Local stale change" }), baseCommit: initial.revision.commit, baseBlob: initial.revision.blob, })).rejects.toMatchObject({ code: "workspace_conflict", fields: ["semantic_index.embedding.model"], expected: { commit: initial.revision.commit, blob: initial.revision.blob }, actual: { commit: actualCommit, blob: actualBlob }, }); }); test.each([ ["adds", withEmbeddingDiagnostic(withDwhRestTransport(validYaml)), withDwhRestAndEmbeddingDiagnostics(validYaml), "diagnostics.dwh_rest"], ["removes", withDwhRestAndEmbeddingDiagnostics(validYaml), withEmbeddingDiagnostic(withDwhRestTransport(validYaml)), "diagnostics.dwh_rest"], ["adds", withVectorMetadataDiagnostic(validYaml), withReversibleVectorProbe(validYaml), "diagnostics.vector_rest.reversible_probe"], ["removes", withReversibleVectorProbe(validYaml), withVectorMetadataDiagnostic(validYaml), "diagnostics.vector_rest.reversible_probe"], ])("reports an optional diagnostics branch when the registry %s it", async (_operation, baseSource, remoteSource, field) => { const remote = await fixture(baseSource); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); await registry.bootstrap(); const initial = await registry.read("psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), remoteSource); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", `Registry ${_operation} diagnostic branch`]); await git(remote.source, ["push", "origin", "main"]); await expect(registry.publish({ action: "update", workspace: workspaceWith("psd-clinical", { description: "Local stale change" }), baseCommit: initial.revision.commit, baseBlob: initial.revision.blob, })).rejects.toMatchObject({ code: "workspace_conflict", fields: [field], }); }); test("restores a clean checkout after a failed commit and retries publication", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const objects = join(root, "repo", ".git", "objects"); chmodSync(objects, 0o500); const request = { action: "create" as const, workspace: workspaceWith("commit-recovery"), baseCommit: remote.initialCommit, }; try { await expect(registry.publish(request)).rejects.toMatchObject({ code: "git_unavailable" }); } finally { chmodSync(objects, 0o700); } expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" }); await expect(registry.pull()).resolves.toMatchObject({ head: remote.initialCommit }); await expect(registry.publish(request)).resolves.toMatchObject({ id: "commit-recovery" }); }); test("resets an ahead checkout after a rejected push and retries publication", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const hook = join(remote.remote, "hooks", "pre-receive"); writeFileSync(hook, "#!/bin/sh\nexit 1\n", { mode: 0o755 }); const request = { action: "create" as const, workspace: workspaceWith("push-recovery"), baseCommit: remote.initialCommit, }; await expect(registry.publish(request)).rejects.toMatchObject({ code: "git_push_rejected" }); expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" }); rmSync(hook); await expect(registry.pull()).resolves.toMatchObject({ head: remote.initialCommit }); await expect(registry.publish(request)).resolves.toMatchObject({ id: "push-recovery" }); }); test("lists a v1 descriptor in migration-required state without rendering operational artifacts", async () => { const legacyYaml = validYaml.replace( " database: postgres\n schema: vectors\n", "", ).replace("schema_version: 2", "schema_version: 1"); const remote = await fixture(legacyYaml); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); const status = await registry.bootstrap(); const [revision] = await registry.list(); expect(revision).toMatchObject({ state: "migration_required" }); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ workspace: { workspace: { schema_version: 1 } }, }); expect(existsSync(join(remote.root, "registry", "snapshots", status.head!, "psd-clinical.env.example"))).toBe(false); expect(existsSync(join(remote.root, "registry", "snapshots", status.head!, "psd-clinical.md"))).toBe(false); }); test("migrates a validated pre-state manifest and keeps its v1 workspace migration-gated", async () => { const legacyYaml = validYaml.replace( " database: postgres\n schema: vectors\n", "", ).replace("schema_version: 2", "schema_version: 1"); const remote = await fixture(legacyYaml); const root = join(remote.root, "registry"); const firstRegistry = new WorkspaceRegistry(config(root, remote.remote)); await firstRegistry.bootstrap(); persistPreStateManifest(root, remote.initialCommit); const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote)); await expect(restoredRegistry.bootstrap()).resolves.toMatchObject({ head: remote.initialCommit, degraded: false, }); await expect(restoredRegistry.list()).resolves.toMatchObject([ { id: "psd-clinical", state: "migration_required" }, ]); const active = JSON.parse(readFileSync(join(root, "state", "active.json"), "utf8")); const manifest = JSON.parse(readFileSync(join(root, "snapshots", remote.initialCommit, "snapshot.json"), "utf8")); expect(active.revisions[0].state).toBe("migration_required"); expect(manifest.revisions[0].state).toBe("migration_required"); expect(Object.keys(manifest.files)).toEqual(["psd-clinical.yaml"]); }); test("finishes a pre-state active manifest migration after its snapshot was atomically updated", async () => { const legacyYaml = validYaml.replace( " database: postgres\n schema: vectors\n", "", ).replace("schema_version: 2", "schema_version: 1"); const remote = await fixture(legacyYaml); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); persistPreStateManifest(root, remote.initialCommit); const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json"); const manifest = JSON.parse(readFileSync(snapshotPath, "utf8")); manifest.revisions[0].state = "migration_required"; manifest.files = { "psd-clinical.yaml": manifest.files["psd-clinical.yaml"] }; writeFileSync(snapshotPath, JSON.stringify(manifest)); const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote)); await expect(restoredRegistry.list()).resolves.toMatchObject([ { id: "psd-clinical", state: "migration_required" }, ]); }); test("rejects a corrupt pre-state manifest rather than accepting it during migration", async () => { const legacyYaml = validYaml.replace( " database: postgres\n schema: vectors\n", "", ).replace("schema_version: 2", "schema_version: 1"); const remote = await fixture(legacyYaml); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); persistPreStateManifest(root, remote.initialCommit); const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json"); const manifest = JSON.parse(readFileSync(snapshotPath, "utf8")); manifest.files["psd-clinical.yaml"] = "0".repeat(64); writeFileSync(snapshotPath, JSON.stringify(manifest)); const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote)); await expect(restoredRegistry.bootstrap()).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(restoredRegistry.list()).rejects.toMatchObject({ code: "workspace_invalid" }); }); test("keeps the last valid snapshot when a pulled commit has invalid YAML", async () => { const remote = await fixture(); const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote)); await registry.bootstrap(); await pushInvalidWorkspace(remote.source); await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, }); }); test("retains a historical snapshot while a resumable manifest still references its revision", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Updated Policlinico San Donato", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Update workspace"]); await git(remote.source, ["push", "origin", "main"]); const currentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]); await registry.pull(); await registry.reconcileSnapshotRetention([remote.initialCommit]); expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true); expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true); await registry.reconcileSnapshotRetention([]); expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false); expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true); }); test("a session revision lease survives stale retention scans until its manifest is observed", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const lease = await registry.acquireSessionRevision("psd-clinical"); writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Concurrent revision", )); await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]); await git(remote.source, ["commit", "-m", "Publish while session is starting"]); await git(remote.source, ["push", "origin", "main"]); await registry.pull(); await registry.reconcileSnapshotRetention([]); expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true); await lease.markPersisted(); await registry.reconcileSnapshotRetention([]); expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true); await registry.reconcileSnapshotRetention([remote.initialCommit]); await registry.reconcileSnapshotRetention([]); expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false); }); test("lists operational descriptors retained after their workspace was removed from the active revision", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); writeFileSync(join(remote.source, "workspaces", "archive-only.yaml"), validYaml.replace( "id: psd-clinical", "id: archive-only", )); await git(remote.source, ["add", "workspaces/archive-only.yaml"]); await git(remote.source, ["commit", "-m", "Add retained workspace"]); await git(remote.source, ["push", "origin", "main"]); await registry.pull(); rmSync(join(remote.source, "workspaces", "psd-clinical.yaml")); await git(remote.source, ["add", "-u"]); await git(remote.source, ["commit", "-m", "Remove original workspace"]); await git(remote.source, ["push", "origin", "main"]); await registry.pull(); const retained = await registry.listRetainedSnapshots(); expect(retained).toEqual(expect.arrayContaining([ expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit, state: "operational" }), expect.objectContaining({ id: "archive-only", state: "operational" }), ])); }); test("does not bypass an existing live advisory repository lock", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); const lock = new WorkspaceRepositoryLock(join(root, "locks")); let release!: () => void; let started!: () => void; const held = lock.run(async () => { started(); await new Promise((resolve) => { release = resolve; }); }); await new Promise((resolve) => { started = resolve; }); try { await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_stale" }); } finally { release(); await held; } }); test("rejects a symbolic-link registry root before creating a lock below it", async () => { const remote = await fixture(); const target = join(remote.root, "registry-target"); const root = join(remote.root, "registry-link"); mkdirSync(target); symlinkSync(target, root); const registry = new WorkspaceRegistry(config(root, remote.remote)); await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" }); expect(existsSync(join(target, "locks"))).toBe(false); }); test("rejects a locally-ahead checkout instead of activating local-only content", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const checkout = join(root, "repo"); writeFileSync(join(checkout, "workspaces", "psd-clinical.yaml"), validYaml.replace( "name: Policlinico San Donato", "name: Local only workspace", )); await git(checkout, ["config", "user.name", "Workspace Registry Test"]); await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]); await git(checkout, ["add", "workspaces/psd-clinical.yaml"]); await git(checkout, ["commit", "-m", "Local-only workspace"]); await expect(registry.pull()).rejects.toMatchObject({ code: "git_non_fast_forward" }); await expect(registry.read("psd-clinical")).resolves.toMatchObject({ revision: { commit: remote.initialCommit }, workspace: { workspace: { name: "Policlinico San Donato" } }, }); }); test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); mkdirSync(join(root, "locks"), { recursive: true }); writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 })); const registry = new WorkspaceRegistry(config(root, remote.remote)); await expect(registry.bootstrap()).resolves.toMatchObject({ head: remote.initialCommit, degraded: false, }); }); test.each(["manifest", "blob", "workspace", "document"])( "rejects a corrupted %s snapshot component instead of reporting it active", async (component) => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const snapshot = join(root, "snapshots", remote.initialCommit); if (component === "manifest") { const file = join(snapshot, "snapshot.json"); chmodSync(file, 0o600); writeFileSync(file, "{"); } if (component === "blob") { const activePath = join(root, "state", "active.json"); const active = JSON.parse(readFileSync(activePath, "utf8")); active.revisions[0].blob = "not-a-git-blob"; writeFileSync(activePath, JSON.stringify(active)); } if (component === "workspace") { const file = join(snapshot, "psd-clinical.yaml"); chmodSync(file, 0o600); writeFileSync(file, "truncated"); } if (component === "document") rmSync(join(snapshot, "psd-clinical.md")); await expect(registry.list()).rejects.toMatchObject({ code: "workspace_invalid" }); await expect(registry.read("psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" }); }, ); test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => { const remote = await fixture(); const root = join(remote.root, "registry"); const registry = new WorkspaceRegistry(config(root, remote.remote)); await registry.bootstrap(); const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md"); chmodSync(document, 0o600); writeFileSync(document, "corrupt"); rmSync(remote.remote, { recursive: true, force: true }); await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" }); });