Files
ThothII/backend/test/workspace-registry.test.ts
T

1086 lines
46 KiB
TypeScript

import { execFile } from "node:child_process";
import { createHash } from "node:crypto";
import {
chmodSync, existsSync, mkdtempSync, mkdirSync, readdirSync, readFileSync, rmSync, symlinkSync, writeFileSync,
} from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { promisify } from "node:util";
import { afterEach, expect, test } from "vitest";
import { WorkspaceRepositoryLock } from "../src/workspaces/git-repository.js";
import { WorkspaceRegistry } from "../src/workspaces/registry.js";
import {
parseWorkspaceYaml, renderWorkspaceDocs, serializeWorkspaceYaml, type CanonicalWorkspace,
} from "../src/workspaces/schema.js";
import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js";
const validYaml = `workspace:
schema_version: 3
id: psd-clinical
name: Policlinico San Donato
language: it
dwh:
engine: postgres
database: postgres
schema: datawarehouse
supported_transports: [postgres_direct]
semantic_index:
vector_store:
engine: qdrant
collection: psd-clinical
dimensions: 1024
distance: cosine
embedding:
provider: ollama_internal
model: qwen3-embedding:0.6b
dimensions: 1024
llm_policy:
allowed: [zai/glm-5.2]
`;
function withFilesystemEvidence(source: string, id = "psd-clinical"): string {
return source.concat(`evidence:
source:
type: filesystem
uri: workspace-content/${id}/evidence
`);
}
function withDwhRestTransport(source: string): string {
return source.replace(
"supported_transports: [postgres_direct]",
"supported_transports: [postgres_direct, rest_api]",
);
}
function withDwhRestDiagnostic(source: string): string {
return withDwhRestTransport(source).concat(`diagnostics:
dwh_rest:
method: GET
path: /health
auth: none
response:
database: database
schema: schema
`);
}
function withEmbeddingDiagnostic(source: string): string {
return source.concat(`diagnostics:
embedding:
method: GET
path: /models
auth: none
response:
model: model
dimensions: dimensions
`);
}
function withDwhRestAndEmbeddingDiagnostics(source: string): string {
return withDwhRestTransport(source).concat(`diagnostics:
dwh_rest:
method: GET
path: /health
auth: none
response:
database: database
schema: schema
embedding:
method: GET
path: /models
auth: none
response:
model: model
dimensions: dimensions
`);
}
function withVectorRestTransport(source: string): string {
return source.replace(
"supported_transports: [pgvector_direct]",
"supported_transports: [pgvector_direct, rest_api]",
);
}
function withVectorMetadataDiagnostic(source: string): string {
return withVectorRestTransport(source).concat(`diagnostics:
vector_rest:
metadata:
method: GET
path: /metadata
auth: none
response:
collection: collection
dimensions: dimensions
distance: distance
`);
}
function withReversibleVectorProbe(source: string): string {
return withVectorRestTransport(source).concat(`diagnostics:
vector_rest:
metadata:
method: GET
path: /metadata
auth: none
response:
collection: collection
dimensions: dimensions
distance: distance
reversible_probe:
method: POST
path: /probe
auth: bearer
response:
operation: operation
`);
}
function legacyV1Yaml(source = validYaml): string {
return source
.replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n")
.replace(" collection: psd-clinical\n", " collection: psd_clinical\n")
.replace(" dimensions: 1024", " dimensions: 768")
.replace(" provider: ollama_internal", " provider: ollama_compatible")
.replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe")
.replace(" dimensions: 1024", " dimensions: 768")
.replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n")
.replace("schema_version: 3", "schema_version: 1");
}
function legacyV2Yaml(source = validYaml): string {
return source
.replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n")
.replace(" collection: psd-clinical\n", " collection: psd_clinical\n")
.replace(" dimensions: 1024", " dimensions: 768")
.replace(" provider: ollama_internal", " provider: ollama_compatible")
.replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe")
.replace(" dimensions: 1024", " dimensions: 768")
.replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n")
.replace("schema_version: 3", "schema_version: 2");
}
const runFile = promisify(execFile);
const temporaryRoots: string[] = [];
afterEach(() => {
temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true }));
});
async function git(cwd: string, args: string[]): Promise<void> {
await runFile("git", args, { cwd });
}
async function gitOutput(cwd: string, args: string[]): Promise<string> {
const { stdout } = await runFile("git", args, { cwd });
return stdout.trim();
}
async function fixture(workspaceSource = validYaml): Promise<{
root: string; remote: string; source: string; initialCommit: string;
}> {
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"));
temporaryRoots.push(root);
const remote = join(root, "remote.git");
const source = join(root, "source");
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
mkdirSync(source);
await git(source, ["init", "--initial-branch=main"]);
await git(source, ["config", "user.name", "Workspace Registry Test"]);
await git(source, ["config", "user.email", "workspace-registry@example.invalid"]);
mkdirSync(join(source, "workspaces"));
writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), workspaceSource);
if (workspaceSource.includes("type: filesystem")) {
mkdirSync(join(source, "workspace-content", "psd-clinical", "evidence"), { recursive: true });
mkdirSync(join(source, "workspace-content", "research", "evidence"), { recursive: true });
writeFileSync(join(source, "workspace-content", "psd-clinical", "evidence", "guide.md"), "guide v1\n");
writeFileSync(join(source, "workspace-content", "research", "evidence", "guide.md"), "research guide\n");
await git(source, ["add", "workspaces", "workspace-content"]);
} else {
await git(source, ["add", "workspaces/psd-clinical.yaml"]);
}
await git(source, ["commit", "-m", "Initial workspace"]);
await git(source, ["remote", "add", "origin", remote]);
await git(source, ["push", "origin", "main"]);
const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source });
return { root, remote, source, initialCommit: stdout.trim() };
}
async function multiWorkspaceFixture(workspaces: Record<string, string>): Promise<{
root: string; remote: string; source: string; initialCommit: string;
}> {
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"));
temporaryRoots.push(root);
const remote = join(root, "remote.git");
const source = join(root, "source");
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
mkdirSync(source);
await git(source, ["init", "--initial-branch=main"]);
await git(source, ["config", "user.name", "Workspace Registry Test"]);
await git(source, ["config", "user.email", "workspace-registry@example.invalid"]);
mkdirSync(join(source, "workspaces"));
for (const [id, workspaceSource] of Object.entries(workspaces)) {
writeFileSync(join(source, "workspaces", `${id}.yaml`), workspaceSource);
}
await git(source, ["add", "workspaces"]);
await git(source, ["commit", "-m", "Initial workspaces"]);
await git(source, ["remote", "add", "origin", remote]);
await git(source, ["push", "origin", "main"]);
const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source });
return { root, remote, source, initialCommit: stdout.trim() };
}
function config(
root: string,
remoteUrl: string,
overrides: Partial<WorkspaceRegistryConfig> = {},
): WorkspaceRegistryConfig {
return {
root,
remoteUrl,
branch: "main",
gitAuthorName: "Workspace Registry Test",
gitAuthorEmail: "workspace-registry@example.invalid",
installationId: "test",
secretRoots: [],
maxImportBytes: 1024,
maxImportEntries: 1,
...overrides,
};
}
function workspaceWith(
id: string,
changes: Partial<Pick<CanonicalWorkspace["workspace"], "name" | "description">> = {},
): CanonicalWorkspace {
const workspace = parseWorkspaceYaml(validYaml) as CanonicalWorkspace;
return {
...workspace,
workspace: { ...workspace.workspace, id, name: id, ...changes },
semantic_index: {
...workspace.semantic_index,
vector_store: { ...workspace.semantic_index.vector_store, collection: id },
},
};
}
function filesystemWorkspace(id: string): CanonicalWorkspace {
return parseWorkspaceYaml(withFilesystemEvidence(
validYaml
.replace("id: psd-clinical", `id: ${id}`)
.replace("name: Policlinico San Donato", `name: ${id}`)
.replace("collection: psd-clinical", `collection: ${id}`),
id,
)) as CanonicalWorkspace;
}
async function checkoutStatus(checkout: string): Promise<{ porcelain: string; divergence: string }> {
return {
porcelain: await gitOutput(checkout, ["status", "--porcelain"]),
divergence: await gitOutput(checkout, ["rev-list", "--left-right", "--count", "HEAD...@{upstream}"]),
};
}
async function pushInvalidWorkspace(source: string): Promise<void> {
writeFileSync(join(source, "workspaces", "psd-clinical.yaml"), "workspace: invalid\n");
await git(source, ["add", "workspaces/psd-clinical.yaml"]);
await git(source, ["commit", "-m", "Invalid workspace"]);
await git(source, ["push", "origin", "main"]);
}
function legacyDigest(contents: string): string {
return createHash("sha256").update(contents).digest("hex");
}
function persistPreStateManifest(root: string, commit: string): void {
const snapshotDirectory = join(root, "snapshots", commit);
const activePath = join(root, "state", "active.json");
const snapshotPath = join(snapshotDirectory, "snapshot.json");
const active = JSON.parse(readFileSync(activePath, "utf8"));
const manifest = JSON.parse(readFileSync(snapshotPath, "utf8"));
const envName = "psd-clinical.env.example";
const docsName = "psd-clinical.md";
const envExample = "# Legacy registry artifact\n";
const markdown = "# Legacy registry artifact\n";
writeFileSync(join(snapshotDirectory, envName), envExample);
writeFileSync(join(snapshotDirectory, docsName), markdown);
active.revisions = active.revisions.map(({ state: _state, ...revision }: Record<string, unknown>) => revision);
manifest.revisions = manifest.revisions.map(({ state: _state, ...revision }: Record<string, unknown>) => revision);
manifest.files = {
"psd-clinical.yaml": manifest.files["psd-clinical.yaml"],
[envName]: legacyDigest(envExample),
[docsName]: legacyDigest(markdown),
};
writeFileSync(activePath, JSON.stringify(active));
chmodSync(snapshotPath, 0o600);
writeFileSync(snapshotPath, JSON.stringify(manifest));
}
test("bootstraps a checkout and activates a validated immutable snapshot", async () => {
const remote = await fixture();
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
const status = await registry.bootstrap();
expect(status.head).toMatch(/^[0-9a-f]{40}$/);
expect(existsSync(registry.snapshotPath(status.head!, "psd-clinical"))).toBe(true);
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit, id: "psd-clinical" },
});
});
test("concurrent first lists lazily bootstrap a clean registry once safely", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
const [first, second] = await Promise.all([registry.list(), registry.list()]);
for (const revisions of [first, second]) {
expect(revisions).toEqual([
expect.objectContaining({
id: "psd-clinical",
commit: remote.initialCommit,
state: "operational",
}),
]);
}
expect(existsSync(join(root, "state", "active.json"))).toBe(true);
});
test("publishes a filesystem descriptor only when its Evidence tree exists in the pulled base", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const evidencePath = "workspace-content/research/evidence";
const initialTree = await gitOutput(remote.root, [
"--git-dir", remote.remote, "rev-parse", `${remote.initialCommit}:${evidencePath}`,
]);
const created = await registry.publish({
action: "create",
workspace: filesystemWorkspace("research"),
baseCommit: remote.initialCommit,
});
expect(created?.commit).not.toBe(remote.initialCommit);
await expect(runFile("git", [
"--git-dir", remote.remote, "cat-file", "-e", `${created!.commit}:workspaces/research.yaml`,
], { cwd: remote.root })).resolves.toBeDefined();
await expect(runFile("git", [
"--git-dir", remote.remote, "cat-file", "-e", `${created!.commit}:${evidencePath}/guide.md`,
], { cwd: remote.root })).resolves.toBeDefined();
expect(await gitOutput(remote.root, [
"--git-dir", remote.remote, "rev-parse", `${created!.commit}:${evidencePath}`,
])).toBe(initialTree);
const remoteHeadBeforeMissing = await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"]);
await expect(registry.publish({
action: "create",
workspace: filesystemWorkspace("missing-tree"),
baseCommit: created!.commit,
})).rejects.toMatchObject({ code: "workspace_invalid" });
expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"])).toBe(
remoteHeadBeforeMissing,
);
expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" });
});
test.each(["missing", "blob"])(
"rejects a remote filesystem descriptor with a %s Evidence root and keeps the active snapshot",
async (invalidKind) => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
const evidenceRoot = join(remote.source, "workspace-content", "psd-clinical", "evidence");
rmSync(evidenceRoot, { recursive: true, force: true });
if (invalidKind === "blob") writeFileSync(evidenceRoot, "not a tree\n");
await git(remote.source, ["add", "-A", "workspace-content/psd-clinical/evidence"]);
await git(remote.source, ["commit", "-m", `Make Evidence root ${invalidKind}`]);
await git(remote.source, ["push", "origin", "main"]);
const invalidCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
expect(invalidCommit).not.toBe(remote.initialCommit);
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
});
},
);
test("activation validates filesystem Evidence against its exact safeHead rather than checkout HEAD", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
rmSync(join(remote.source, "workspace-content", "psd-clinical", "evidence"), {
recursive: true, force: true,
});
await git(remote.source, ["add", "-A", "workspace-content/psd-clinical/evidence"]);
await git(remote.source, ["commit", "-m", "Remove current Evidence root"]);
await git(remote.source, ["push", "origin", "main"]);
const invalidHead = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
const internals = registry as unknown as {
repository: { pull(): Promise<{ head?: string }> };
activate(commit: string): Promise<void>;
};
expect((await internals.repository.pull()).head).toBe(invalidHead);
await expect(internals.activate(remote.initialCommit)).resolves.toBeUndefined();
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
});
});
test("creates an immutable descriptor revision for a content-only Evidence commit", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const initial = await registry.read("psd-clinical");
const evidencePath = "workspace-content/psd-clinical/evidence";
const initialTree = await gitOutput(remote.source, ["rev-parse", `${remote.initialCommit}:${evidencePath}`]);
writeFileSync(join(remote.source, evidencePath, "guide.md"), "guide v2\n");
await git(remote.source, ["add", `${evidencePath}/guide.md`]);
await git(remote.source, ["commit", "-m", "Update Evidence only"]);
await git(remote.source, ["push", "origin", "main"]);
const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
const contentTree = await gitOutput(remote.source, ["rev-parse", `${contentCommit}:${evidencePath}`]);
await registry.pull();
const current = await registry.read("psd-clinical");
expect(contentTree).not.toBe(initialTree);
expect(current.revision).toMatchObject({ commit: contentCommit, blob: initial.revision.blob });
expect(current.revision.snapshotPath).not.toBe(initial.revision.snapshotPath);
expect(readFileSync(current.revision.snapshotPath, "utf8")).toBe(
readFileSync(initial.revision.snapshotPath, "utf8"),
);
await expect(runFile("git", [
"--git-dir", remote.remote, "cat-file", "-e", `${contentCommit}:${evidencePath}/guide.md`,
], { cwd: remote.root })).resolves.toBeDefined();
});
test("rejects a stale API update after a content-only Evidence commit", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
const initial = await registry.read("psd-clinical");
const guide = join(remote.source, "workspace-content", "psd-clinical", "evidence", "guide.md");
writeFileSync(guide, "curator content\n");
await git(remote.source, ["add", "workspace-content/psd-clinical/evidence/guide.md"]);
await git(remote.source, ["commit", "-m", "Curator Evidence update"]);
await git(remote.source, ["push", "origin", "main"]);
const curatorCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
await expect(registry.publish({
action: "update",
workspace: filesystemWorkspace("psd-clinical"),
baseCommit: initial.revision.commit,
baseBlob: initial.revision.blob,
})).rejects.toMatchObject({ code: "workspace_stale" });
expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "rev-parse", "HEAD"])).toBe(curatorCommit);
});
test("keeps content-only historical descriptor revisions distinguishable by commit", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
writeFileSync(
join(remote.source, "workspace-content", "psd-clinical", "evidence", "guide.md"),
"historical content\n",
);
await git(remote.source, ["add", "workspace-content/psd-clinical/evidence/guide.md"]);
await git(remote.source, ["commit", "-m", "Retained Evidence update"]);
await git(remote.source, ["push", "origin", "main"]);
const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
await registry.pull();
await registry.reconcileSnapshotRetention([remote.initialCommit]);
const retained = (await registry.listRetainedSnapshots()).filter(({ id }) => id === "psd-clinical");
expect(retained.map(({ commit }) => commit)).toEqual([contentCommit, remote.initialCommit]);
const oldPinned = await registry.readPinned("psd-clinical", remote.initialCommit);
const newPinned = await registry.readPinned("psd-clinical", contentCommit);
expect(oldPinned.workspaceConfigPath).not.toBe(newPinned.workspaceConfigPath);
expect(oldPinned.workspace).toEqual(newPinned.workspace);
});
test("publishes create, update, and delete with the configured Git author identity", async () => {
const remote = await fixture();
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote, {
gitAuthorName: "Configured Workspace Publisher",
gitAuthorEmail: "publisher@example.invalid",
}));
await registry.bootstrap();
const createdWorkspace = workspaceWith("research-registry", { name: "Research registry" });
const created = await registry.publish({
action: "create",
workspace: createdWorkspace,
baseCommit: remote.initialCommit,
});
expect(created).toMatchObject({ id: "research-registry", commit: expect.stringMatching(/^[0-9a-f]{40}$/) });
expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "log", "-1", "--format=%an <%ae>"])).toBe(
"Configured Workspace Publisher <publisher@example.invalid>",
);
await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspace-docs/research-registry/README.md"], {
cwd: remote.root,
})).resolves.toBeDefined();
const updated = await registry.publish({
action: "update",
workspace: workspaceWith("research-registry", { description: "Updated workspace description" }),
baseCommit: created!.commit,
baseBlob: created!.blob,
});
expect(updated).toMatchObject({ id: "research-registry" });
expect(await gitOutput(remote.root, ["--git-dir", remote.remote, "show", "HEAD:workspaces/research-registry.yaml"])).toContain(
"description: Updated workspace description",
);
await expect(registry.publish({
action: "delete",
id: "research-registry",
baseCommit: updated!.commit,
baseBlob: updated!.blob,
})).resolves.toBeUndefined();
await expect(runFile("git", ["--git-dir", remote.remote, "cat-file", "-e", "HEAD:workspaces/research-registry.yaml"], {
cwd: remote.root,
})).rejects.toBeDefined();
});
test("reports stale publish conflicts with expected and actual revisions", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const initial = await registry.read("psd-clinical");
writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace(
"schema: datawarehouse", "schema: analytics",
));
await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]);
await git(remote.source, ["commit", "-m", "Change dwh schema"]);
await git(remote.source, ["push", "origin", "main"]);
const actualCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
const actualBlob = await gitOutput(remote.source, ["rev-parse", "HEAD:workspaces/psd-clinical.yaml"]);
await expect(registry.publish({
action: "update",
workspace: workspaceWith("psd-clinical", { description: "Local stale change" }),
baseCommit: initial.revision.commit,
baseBlob: initial.revision.blob,
})).rejects.toMatchObject({
code: "workspace_conflict",
fields: ["dwh.schema"],
expected: { commit: initial.revision.commit, blob: initial.revision.blob },
actual: { commit: actualCommit, blob: actualBlob },
});
});
test.each([
["adds", validYaml, withDwhRestDiagnostic(validYaml)],
["removes", withDwhRestDiagnostic(validYaml), validYaml],
])("reports an optional diagnostics branch when the registry %s it", async (_operation, baseSource, remoteSource) => {
const remote = await fixture(baseSource);
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
const initial = await registry.read("psd-clinical");
writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), remoteSource);
await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]);
await git(remote.source, ["commit", "-m", `Registry ${_operation} diagnostic branch`]);
await git(remote.source, ["push", "origin", "main"]);
await expect(registry.publish({
action: "update",
workspace: workspaceWith("psd-clinical", { description: "Local stale change" }),
baseCommit: initial.revision.commit,
baseBlob: initial.revision.blob,
})).rejects.toMatchObject({
code: "workspace_conflict",
fields: ["dwh.supported_transports", "diagnostics"],
});
});
test("restores a clean checkout after a failed commit and retries publication", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const objects = join(root, "repo", ".git", "objects");
chmodSync(objects, 0o500);
const request = {
action: "create" as const,
workspace: workspaceWith("commit-recovery"),
baseCommit: remote.initialCommit,
};
try {
await expect(registry.publish(request)).rejects.toMatchObject({ code: "git_unavailable" });
} finally {
chmodSync(objects, 0o700);
}
expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" });
await expect(registry.pull()).resolves.toMatchObject({ head: remote.initialCommit });
await expect(registry.publish(request)).resolves.toMatchObject({ id: "commit-recovery" });
});
test("resets an ahead checkout after a rejected push and retries publication", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const hook = join(remote.remote, "hooks", "pre-receive");
writeFileSync(hook, "#!/bin/sh\nexit 1\n", { mode: 0o755 });
const request = {
action: "create" as const,
workspace: workspaceWith("push-recovery"),
baseCommit: remote.initialCommit,
};
await expect(registry.publish(request)).rejects.toMatchObject({ code: "git_push_rejected" });
expect(await checkoutStatus(join(root, "repo"))).toEqual({ porcelain: "", divergence: "0\t0" });
rmSync(hook);
await expect(registry.pull()).resolves.toMatchObject({ head: remote.initialCommit });
await expect(registry.publish(request)).resolves.toMatchObject({ id: "push-recovery" });
});
test("lists a v1 descriptor in migration-required state without rendering operational artifacts", async () => {
const legacyYaml = legacyV1Yaml();
const remote = await fixture(legacyYaml);
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
const status = await registry.bootstrap();
const [revision] = await registry.list();
expect(revision).toMatchObject({ state: "migration_required" });
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
workspace: { workspace: { schema_version: 1 } },
});
expect(existsSync(join(remote.root, "registry", "snapshots", status.head!, "psd-clinical.env.example"))).toBe(false);
expect(existsSync(join(remote.root, "registry", "snapshots", status.head!, "psd-clinical.md"))).toBe(false);
});
test("migrates a validated pre-state manifest and keeps its v1 workspace migration-gated", async () => {
const legacyYaml = legacyV1Yaml();
const remote = await fixture(legacyYaml);
const root = join(remote.root, "registry");
const firstRegistry = new WorkspaceRegistry(config(root, remote.remote));
await firstRegistry.bootstrap();
persistPreStateManifest(root, remote.initialCommit);
const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote));
await expect(restoredRegistry.bootstrap()).resolves.toMatchObject({
head: remote.initialCommit,
degraded: false,
});
await expect(restoredRegistry.list()).resolves.toMatchObject([
{ id: "psd-clinical", state: "migration_required" },
]);
const active = JSON.parse(readFileSync(join(root, "state", "active.json"), "utf8"));
const manifest = JSON.parse(readFileSync(join(root, "snapshots", remote.initialCommit, "snapshot.json"), "utf8"));
expect(active.revisions[0].state).toBe("migration_required");
expect(manifest.revisions[0].state).toBe("migration_required");
expect(Object.keys(manifest.files)).toEqual(["psd-clinical.yaml"]);
});
test("finishes a pre-state active manifest migration after its snapshot was atomically updated", async () => {
const legacyYaml = legacyV1Yaml();
const remote = await fixture(legacyYaml);
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
persistPreStateManifest(root, remote.initialCommit);
const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json");
const manifest = JSON.parse(readFileSync(snapshotPath, "utf8"));
manifest.revisions[0].state = "migration_required";
manifest.files = { "psd-clinical.yaml": manifest.files["psd-clinical.yaml"] };
writeFileSync(snapshotPath, JSON.stringify(manifest));
const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote));
await expect(restoredRegistry.list()).resolves.toMatchObject([
{ id: "psd-clinical", state: "migration_required" },
]);
});
test("rejects a corrupt pre-state manifest rather than accepting it during migration", async () => {
const legacyYaml = legacyV1Yaml();
const remote = await fixture(legacyYaml);
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
persistPreStateManifest(root, remote.initialCommit);
const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json");
const manifest = JSON.parse(readFileSync(snapshotPath, "utf8"));
manifest.files["psd-clinical.yaml"] = "0".repeat(64);
writeFileSync(snapshotPath, JSON.stringify(manifest));
const restoredRegistry = new WorkspaceRegistry(config(root, remote.remote));
await expect(restoredRegistry.bootstrap()).rejects.toMatchObject({ code: "workspace_invalid" });
await expect(restoredRegistry.list()).rejects.toMatchObject({ code: "workspace_invalid" });
});
test("keeps the last valid snapshot when a pulled commit has invalid YAML", async () => {
const remote = await fixture();
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
await pushInvalidWorkspace(remote.source);
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
});
});
test("rejects duplicate schema v3 collection ownership and keeps the previous active snapshot", async () => {
const v3Yaml = validYaml;
const remote = await multiWorkspaceFixture({
"psd-clinical": v3Yaml,
"research-clinical": v3Yaml
.replace("id: psd-clinical", "id: research-clinical")
.replace("name: Policlinico San Donato", "name: Research Clinical")
.replace("collection: psd-clinical", "collection: research-clinical"),
});
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
writeFileSync(
join(remote.source, "workspaces", "research-clinical.yaml"),
v3Yaml
.replace("id: psd-clinical", "id: research-clinical")
.replace("name: Policlinico San Donato", "name: Research Clinical")
.replace("collection: psd-clinical", "collection: shared"),
);
writeFileSync(
join(remote.source, "workspaces", "psd-clinical.yaml"),
v3Yaml.replace("collection: psd-clinical", "collection: shared"),
);
await git(remote.source, ["add", "workspaces"]);
await git(remote.source, ["commit", "-m", "Duplicate collection ownership"]);
await git(remote.source, ["push", "origin", "main"]);
await expect(registry.pull()).rejects.toMatchObject({
code: "workspace_invalid",
message: "Workspace repository content is invalid",
});
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
});
await expect(registry.read("research-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
});
});
test("retains a historical snapshot while a resumable manifest still references its revision", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace(
"name: Policlinico San Donato", "name: Updated Policlinico San Donato",
));
await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]);
await git(remote.source, ["commit", "-m", "Update workspace"]);
await git(remote.source, ["push", "origin", "main"]);
const currentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
await registry.pull();
await registry.reconcileSnapshotRetention([remote.initialCommit]);
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true);
await registry.reconcileSnapshotRetention([]);
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false);
expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true);
});
test("a session revision lease survives stale retention scans until its manifest is observed", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const lease = await registry.acquireSessionRevision("psd-clinical");
writeFileSync(join(remote.source, "workspaces", "psd-clinical.yaml"), validYaml.replace(
"name: Policlinico San Donato", "name: Concurrent revision",
));
await git(remote.source, ["add", "workspaces/psd-clinical.yaml"]);
await git(remote.source, ["commit", "-m", "Publish while session is starting"]);
await git(remote.source, ["push", "origin", "main"]);
await registry.pull();
await registry.reconcileSnapshotRetention([]);
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
await lease.markPersisted();
await registry.reconcileSnapshotRetention([]);
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
await registry.reconcileSnapshotRetention([remote.initialCommit]);
await registry.reconcileSnapshotRetention([]);
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false);
});
test("does not acquire a session revision lease for a migration_required workspace", async () => {
const remote = await fixture(legacyV1Yaml());
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
await expect(registry.acquireSessionRevision("psd-clinical")).rejects.toMatchObject({
code: "workspace_invalid",
});
});
test("lists a schema v2 descriptor as migration_required and refuses to acquire it", async () => {
const remote = await fixture(legacyV2Yaml());
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
await registry.bootstrap();
await expect(registry.list()).resolves.toMatchObject([
{ id: "psd-clinical", state: "migration_required" },
]);
await expect(registry.acquireSessionRevision("psd-clinical")).rejects.toMatchObject({
code: "workspace_invalid",
});
await expect(registry.readPinned("psd-clinical", remote.initialCommit)).rejects.toMatchObject({
code: "workspace_invalid",
});
});
test("lists operational descriptors retained after their workspace was removed from the active revision", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
writeFileSync(join(remote.source, "workspaces", "archive-only.yaml"), validYaml.replace(
"id: psd-clinical", "id: archive-only",
).replace("collection: psd-clinical", "collection: archive-only"));
await git(remote.source, ["add", "workspaces/archive-only.yaml"]);
await git(remote.source, ["commit", "-m", "Add retained workspace"]);
await git(remote.source, ["push", "origin", "main"]);
await registry.pull();
rmSync(join(remote.source, "workspaces", "psd-clinical.yaml"));
await git(remote.source, ["add", "-u"]);
await git(remote.source, ["commit", "-m", "Remove original workspace"]);
await git(remote.source, ["push", "origin", "main"]);
await registry.pull();
const retained = await registry.listRetainedSnapshots();
expect(retained).toEqual(expect.arrayContaining([
expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit, state: "operational" }),
expect.objectContaining({ id: "archive-only", state: "operational" }),
]));
});
test("does not bypass an existing live advisory repository lock", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
const lock = new WorkspaceRepositoryLock(join(root, "locks"));
let release!: () => void;
let started!: () => void;
const held = lock.run(async () => {
started();
await new Promise<void>((resolve) => { release = resolve; });
});
await new Promise<void>((resolve) => { started = resolve; });
try {
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_stale" });
} finally {
release();
await held;
}
});
test("rejects a symbolic-link registry root before creating a lock below it", async () => {
const remote = await fixture();
const target = join(remote.root, "registry-target");
const root = join(remote.root, "registry-link");
mkdirSync(target);
symlinkSync(target, root);
const registry = new WorkspaceRegistry(config(root, remote.remote));
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" });
expect(existsSync(join(target, "locks"))).toBe(false);
});
test("rejects a locally-ahead checkout instead of activating local-only content", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const checkout = join(root, "repo");
writeFileSync(join(checkout, "workspaces", "psd-clinical.yaml"), validYaml.replace(
"name: Policlinico San Donato", "name: Local only workspace",
));
await git(checkout, ["config", "user.name", "Workspace Registry Test"]);
await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]);
await git(checkout, ["add", "workspaces/psd-clinical.yaml"]);
await git(checkout, ["commit", "-m", "Local-only workspace"]);
await expect(registry.pull()).rejects.toMatchObject({ code: "git_non_fast_forward" });
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
revision: { commit: remote.initialCommit },
workspace: { workspace: { name: "Policlinico San Donato" } },
});
});
test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
mkdirSync(join(root, "locks"), { recursive: true });
writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 }));
const registry = new WorkspaceRegistry(config(root, remote.remote));
await expect(registry.bootstrap()).resolves.toMatchObject({
head: remote.initialCommit,
degraded: false,
});
});
test.each(["manifest", "blob", "workspace", "document"])(
"rejects a corrupted %s snapshot component instead of reporting it active",
async (component) => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const snapshot = join(root, "snapshots", remote.initialCommit);
if (component === "manifest") {
const file = join(snapshot, "snapshot.json");
chmodSync(file, 0o600);
writeFileSync(file, "{");
}
if (component === "blob") {
const activePath = join(root, "state", "active.json");
const active = JSON.parse(readFileSync(activePath, "utf8"));
active.revisions[0].blob = "not-a-git-blob";
writeFileSync(activePath, JSON.stringify(active));
}
if (component === "workspace") {
const file = join(snapshot, "psd-clinical.yaml");
chmodSync(file, 0o600);
writeFileSync(file, "truncated");
}
if (component === "document") rmSync(join(snapshot, "psd-clinical.md"));
await expect(registry.list()).rejects.toMatchObject({ code: "workspace_invalid" });
await expect(registry.read("psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" });
},
);
test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => {
const remote = await fixture();
const root = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(root, remote.remote));
await registry.bootstrap();
const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md");
chmodSync(document, 0o600);
writeFileSync(document, "corrupt");
rmSync(remote.remote, { recursive: true, force: true });
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
});
test("snapshots canonical Evidence artifacts at the active commit without copying Evidence bytes", async () => {
const remote = await fixture(withFilesystemEvidence(validYaml));
const registryRoot = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote));
const status = await registry.bootstrap();
const active = await registry.read("psd-clinical");
const snapshotDirectory = join(registryRoot, "snapshots", status.head!);
const descriptor = active.workspace as CanonicalWorkspace;
const docs = renderWorkspaceDocs(descriptor);
const expectedFiles: Record<string, string> = {
"psd-clinical.yaml": serializeWorkspaceYaml(descriptor),
"psd-clinical.env.example": docs.envExample,
"psd-clinical.md": docs.markdown,
};
const manifest = JSON.parse(readFileSync(join(snapshotDirectory, "snapshot.json"), "utf8"));
expect(status.head).toBe(remote.initialCommit);
const committedDescriptor = parseWorkspaceYaml(await gitOutput(remote.source, [
"show", `${remote.initialCommit}:workspaces/psd-clinical.yaml`,
])) as CanonicalWorkspace;
expect(expectedFiles["psd-clinical.yaml"]).toBe(serializeWorkspaceYaml(committedDescriptor));
expect(readdirSync(snapshotDirectory).sort()).toEqual([
"psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "snapshot.json",
]);
expect(manifest.head).toBe(remote.initialCommit);
expect(manifest.revisions[0]).toMatchObject({
id: "psd-clinical", commit: remote.initialCommit, blob: active.revision.blob,
});
expect(Object.keys(manifest.files).sort()).toEqual(Object.keys(expectedFiles).sort());
for (const [name, contents] of Object.entries(expectedFiles)) {
expect(readFileSync(join(snapshotDirectory, name), "utf8")).toBe(contents);
expect(manifest.files[name]).toBe(createHash("sha256").update(contents).digest("hex"));
}
expect(JSON.stringify(manifest)).not.toContain("workspace-content/");
expect(readdirSync(snapshotDirectory).some((name) => name === "workspace-content")).toBe(false);
expect(readFileSync(join(remote.source, "workspace-content/psd-clinical/evidence/guide.md"), "utf8"))
.toBe("guide v1\n");
});
test("never copies an installation secret canary into Git, generated artifacts, metadata, or errors", async () => {
const remote = await fixture(validYaml.concat(`evidence:
source:
type: http
uris: [https://evidence.example.test/guide.md]
authentication: signed_urls_file
`));
const canary = "CANARY-EVIDENCE-SECRET-ONLY-IN-FIXTURE";
const secretDirectory = join(remote.root, "fixture-secrets");
mkdirSync(secretDirectory);
const secretFile = join(secretDirectory, "signed-urls");
writeFileSync(secretFile, canary);
const registryRoot = join(remote.root, "registry");
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote, {
secretRoots: [secretDirectory],
}));
const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = secretFile;
try {
const status = await registry.bootstrap();
const snapshotDirectory = join(registryRoot, "snapshots", status.head!);
let gitBlobText = "";
try {
gitBlobText = (await runFile(
"git", ["grep", "-I", "-h", "-e", canary, "HEAD", "--", "."], { cwd: remote.source },
)).stdout;
} catch (error) {
if (!error || typeof error !== "object" || !("code" in error) || error.code !== 1) throw error;
gitBlobText = "stdout" in error ? String(error.stdout ?? "") : "";
}
expect(gitBlobText).toBe("");
for (const name of readdirSync(snapshotDirectory)) {
expect(readFileSync(join(snapshotDirectory, name), "utf8")).not.toContain(canary);
}
let thrown: unknown;
try {
await registry.publish({
action: "create",
workspace: filesystemWorkspace("missing-secret-canary-tree"),
baseCommit: status.head!,
});
} catch (error) {
thrown = error;
}
expect(thrown).toMatchObject({ code: "workspace_invalid" });
expect(String(thrown)).not.toContain(canary);
} finally {
if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous;
}
});