1112 lines
48 KiB
TypeScript
1112 lines
48 KiB
TypeScript
import { execFile } from "node:child_process";
|
|
import { createHash } from "node:crypto";
|
|
import {
|
|
chmodSync, existsSync, lstatSync, mkdtempSync, mkdirSync, readdirSync, readFileSync, rmSync, symlinkSync, utimesSync, writeFileSync,
|
|
} from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import { promisify } from "node:util";
|
|
import { afterEach, expect, test } from "vitest";
|
|
import { WorkspaceRepositoryLock } from "../src/workspaces/git-repository.js";
|
|
import { WorkspaceRegistry } from "../src/workspaces/registry.js";
|
|
import {
|
|
parseWorkspaceYaml, renderWorkspaceDocs, serializeWorkspaceYaml, type CanonicalWorkspace,
|
|
} from "../src/workspaces/schema.js";
|
|
import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js";
|
|
|
|
const validYaml = `workspace:
|
|
schema_version: 4
|
|
id: psd-clinical
|
|
name: Policlinico San Donato
|
|
language: it
|
|
dwh:
|
|
engine: postgres
|
|
database: postgres
|
|
schema: datawarehouse
|
|
supported_transports: [postgres_direct]
|
|
`;
|
|
|
|
function withFilesystemEvidence(source: string, id = "psd-clinical"): string {
|
|
return source.concat(`evidence:
|
|
source:
|
|
type: filesystem
|
|
uri: ${id}/evidence
|
|
`);
|
|
}
|
|
|
|
function withDwhRestTransport(source: string): string {
|
|
return source.replace(
|
|
"supported_transports: [postgres_direct]",
|
|
"supported_transports: [postgres_direct, rest_api]",
|
|
);
|
|
}
|
|
|
|
function withDwhRestDiagnostic(source: string): string {
|
|
return withDwhRestTransport(source).concat(`diagnostics:
|
|
dwh_rest:
|
|
method: GET
|
|
path: /health
|
|
auth: none
|
|
response:
|
|
database: database
|
|
schema: schema
|
|
`);
|
|
}
|
|
|
|
function withEmbeddingDiagnostic(source: string): string {
|
|
return source.concat(`diagnostics:
|
|
embedding:
|
|
method: GET
|
|
path: /models
|
|
auth: none
|
|
response:
|
|
model: model
|
|
dimensions: dimensions
|
|
`);
|
|
}
|
|
|
|
function withDwhRestAndEmbeddingDiagnostics(source: string): string {
|
|
return withDwhRestTransport(source).concat(`diagnostics:
|
|
dwh_rest:
|
|
method: GET
|
|
path: /health
|
|
auth: none
|
|
response:
|
|
database: database
|
|
schema: schema
|
|
embedding:
|
|
method: GET
|
|
path: /models
|
|
auth: none
|
|
response:
|
|
model: model
|
|
dimensions: dimensions
|
|
`);
|
|
}
|
|
|
|
function withVectorRestTransport(source: string): string {
|
|
return source.replace(
|
|
"supported_transports: [pgvector_direct]",
|
|
"supported_transports: [pgvector_direct, rest_api]",
|
|
);
|
|
}
|
|
|
|
function withVectorMetadataDiagnostic(source: string): string {
|
|
return withVectorRestTransport(source).concat(`diagnostics:
|
|
vector_rest:
|
|
metadata:
|
|
method: GET
|
|
path: /metadata
|
|
auth: none
|
|
response:
|
|
collection: collection
|
|
dimensions: dimensions
|
|
distance: distance
|
|
`);
|
|
}
|
|
|
|
function withReversibleVectorProbe(source: string): string {
|
|
return withVectorRestTransport(source).concat(`diagnostics:
|
|
vector_rest:
|
|
metadata:
|
|
method: GET
|
|
path: /metadata
|
|
auth: none
|
|
response:
|
|
collection: collection
|
|
dimensions: dimensions
|
|
distance: distance
|
|
reversible_probe:
|
|
method: POST
|
|
path: /probe
|
|
auth: bearer
|
|
response:
|
|
operation: operation
|
|
`);
|
|
}
|
|
|
|
function legacyV1Yaml(source = validYaml): string {
|
|
return source
|
|
.replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n")
|
|
.replace(" collection: psd-clinical\n", " collection: psd_clinical\n")
|
|
.replace(" dimensions: 1024", " dimensions: 768")
|
|
.replace(" provider: ollama_internal", " provider: ollama_compatible")
|
|
.replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe")
|
|
.replace(" dimensions: 1024", " dimensions: 768")
|
|
.replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n")
|
|
.replace("schema_version: 4", "schema_version: 1");
|
|
}
|
|
|
|
function legacyV2Yaml(source = validYaml): string {
|
|
return source
|
|
.replace(" engine: qdrant\n", " engine: pgvector\n database: postgres\n schema: vectors\n")
|
|
.replace(" collection: psd-clinical\n", " collection: psd_clinical\n")
|
|
.replace(" dimensions: 1024", " dimensions: 768")
|
|
.replace(" provider: ollama_internal", " provider: ollama_compatible")
|
|
.replace(" model: qwen3-embedding:0.6b", " model: nomic-embed-text-v2-moe")
|
|
.replace(" dimensions: 1024", " dimensions: 768")
|
|
.replace("distance: cosine\n", "distance: cosine\n supported_transports: [pgvector_direct]\n")
|
|
.replace("schema_version: 4", "schema_version: 2");
|
|
}
|
|
|
|
const runFile = promisify(execFile);
|
|
const temporaryRoots: string[] = [];
|
|
|
|
afterEach(() => {
|
|
temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true }));
|
|
});
|
|
|
|
async function git(cwd: string, args: string[]): Promise<void> {
|
|
await runFile("git", args, { cwd });
|
|
}
|
|
|
|
async function gitOutput(cwd: string, args: string[]): Promise<string> {
|
|
const { stdout } = await runFile("git", args, { cwd });
|
|
return stdout.trim();
|
|
}
|
|
|
|
function catalogYaml(entries: Array<{ id: string; name: string; description?: string }>): string {
|
|
return `schema_version: 1
|
|
workspaces:
|
|
${entries.map((entry) => ` - id: ${entry.id}
|
|
name: ${entry.name}${entry.description ? `\n description: ${entry.description}` : ""}`).join("\n")}
|
|
`;
|
|
}
|
|
|
|
async function fixture(workspaceSource = validYaml): Promise<{
|
|
root: string; remote: string; source: string; initialCommit: string;
|
|
}> {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"));
|
|
temporaryRoots.push(root);
|
|
const remote = join(root, "remote.git");
|
|
const source = join(root, "source");
|
|
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
|
|
mkdirSync(source);
|
|
await git(source, ["init", "--initial-branch=main"]);
|
|
await git(source, ["config", "user.name", "Workspace Registry Test"]);
|
|
await git(source, ["config", "user.email", "workspace-registry@example.invalid"]);
|
|
const workspace = workspaceSource.includes("schema_version: 4")
|
|
? parseWorkspaceYaml(workspaceSource) : undefined;
|
|
mkdirSync(join(source, "psd-clinical"), { recursive: true });
|
|
writeFileSync(join(source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "psd-clinical", name: workspace?.workspace.name ?? "Policlinico San Donato", ...(workspace?.workspace.description ? { description: workspace.workspace.description } : {}) },
|
|
]));
|
|
writeFileSync(join(source, "psd-clinical", "workspace.yaml"), workspaceSource);
|
|
if (workspaceSource.includes("type: filesystem")) {
|
|
mkdirSync(join(source, "psd-clinical", "evidence"), { recursive: true });
|
|
writeFileSync(join(source, "psd-clinical", "evidence", "guide.md"), "guide v1\n");
|
|
await git(source, ["add", "-A"]);
|
|
} else {
|
|
await git(source, ["add", "thoth-workspaces.yaml", "psd-clinical/workspace.yaml"]);
|
|
}
|
|
await git(source, ["commit", "-m", "Initial workspace"]);
|
|
await git(source, ["remote", "add", "origin", remote]);
|
|
await git(source, ["push", "origin", "main"]);
|
|
const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source });
|
|
return { root, remote, source, initialCommit: stdout.trim() };
|
|
}
|
|
|
|
async function contentOnlyFixture(): Promise<{
|
|
root: string; remote: string; source: string; initialCommit: string;
|
|
}> {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-empty-"));
|
|
temporaryRoots.push(root);
|
|
const remote = join(root, "remote.git");
|
|
const source = join(root, "source");
|
|
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
|
|
mkdirSync(source);
|
|
await git(source, ["init", "--initial-branch=main"]);
|
|
await git(source, ["config", "user.name", "Workspace Registry Test"]);
|
|
await git(source, ["config", "user.email", "workspace-registry@example.invalid"]);
|
|
const evidence = join(source, "p1-filesystem", "evidence");
|
|
mkdirSync(evidence, { recursive: true });
|
|
writeFileSync(join(evidence, "guide.md"), "curated content\n");
|
|
writeFileSync(join(source, "thoth-workspaces.yaml"), catalogYaml([{ id: "p1-filesystem", name: "p1-filesystem" }]));
|
|
await git(source, ["add", "-A"]);
|
|
await git(source, ["commit", "-m", "Bootstrap curated content"]);
|
|
await git(source, ["remote", "add", "origin", remote]);
|
|
await git(source, ["push", "origin", "main"]);
|
|
const initialCommit = await gitOutput(source, ["rev-parse", "HEAD"]);
|
|
return { root, remote, source, initialCommit };
|
|
}
|
|
|
|
async function multiWorkspaceFixture(workspaces: Record<string, string>): Promise<{
|
|
root: string; remote: string; source: string; initialCommit: string;
|
|
}> {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-"));
|
|
temporaryRoots.push(root);
|
|
const remote = join(root, "remote.git");
|
|
const source = join(root, "source");
|
|
await git(root, ["init", "--bare", "--initial-branch=main", remote]);
|
|
mkdirSync(source);
|
|
await git(source, ["init", "--initial-branch=main"]);
|
|
await git(source, ["config", "user.name", "Workspace Registry Test"]);
|
|
await git(source, ["config", "user.email", "workspace-registry@example.invalid"]);
|
|
const entries = [];
|
|
for (const [id, workspaceSource] of Object.entries(workspaces)) {
|
|
const workspace = workspaceSource.includes("schema_version: 4") ? parseWorkspaceYaml(workspaceSource) : undefined;
|
|
entries.push({ id, name: workspace.workspace.name, ...(workspace.workspace.description ? { description: workspace.workspace.description } : {}) });
|
|
mkdirSync(join(source, id), { recursive: true });
|
|
writeFileSync(join(source, id, "workspace.yaml"), workspaceSource);
|
|
if (workspaceSource.includes("type: filesystem")) mkdirSync(join(source, id, "evidence"), { recursive: true });
|
|
}
|
|
writeFileSync(join(source, "thoth-workspaces.yaml"), catalogYaml(entries));
|
|
await git(source, ["add", "-A"]);
|
|
await git(source, ["commit", "-m", "Initial workspaces"]);
|
|
await git(source, ["remote", "add", "origin", remote]);
|
|
await git(source, ["push", "origin", "main"]);
|
|
const { stdout } = await runFile("git", ["rev-parse", "HEAD"], { cwd: source });
|
|
return { root, remote, source, initialCommit: stdout.trim() };
|
|
}
|
|
|
|
function config(
|
|
root: string,
|
|
remoteUrl: string,
|
|
overrides: Partial<WorkspaceRegistryConfig> = {},
|
|
): WorkspaceRegistryConfig {
|
|
return {
|
|
root,
|
|
remoteUrl,
|
|
branch: "main",
|
|
gitAuthorName: "Workspace Registry Test",
|
|
gitAuthorEmail: "workspace-registry@example.invalid",
|
|
installationId: "test",
|
|
secretRoots: [],
|
|
maxImportBytes: 1024,
|
|
maxImportEntries: 1,
|
|
...overrides,
|
|
};
|
|
}
|
|
|
|
async function pushInvalidWorkspace(source: string): Promise<void> {
|
|
writeFileSync(join(source, "psd-clinical", "workspace.yaml"), "workspace: invalid\n");
|
|
await git(source, ["add", "psd-clinical/workspace.yaml"]);
|
|
await git(source, ["commit", "-m", "Invalid workspace"]);
|
|
await git(source, ["push", "origin", "main"]);
|
|
}
|
|
|
|
type HistoricalRevisionState = "absent" | "operational" | "migration_required" | "unknown";
|
|
|
|
function revisionWithHistoricalState(
|
|
revision: Record<string, unknown>,
|
|
encoding: HistoricalRevisionState,
|
|
): Record<string, unknown> {
|
|
const { state: _state, ...stateFree } = revision;
|
|
return encoding === "absent" ? stateFree : {
|
|
...stateFree,
|
|
state: encoding === "unknown" ? "retired" : encoding,
|
|
};
|
|
}
|
|
|
|
function rewritePersistedRevisionStates(
|
|
root: string,
|
|
commit: string,
|
|
activeEncoding: HistoricalRevisionState,
|
|
manifestEncoding: HistoricalRevisionState,
|
|
): void {
|
|
const activePath = join(root, "state", "active.json");
|
|
const snapshotPath = join(root, "snapshots", commit, "snapshot.json");
|
|
const active = JSON.parse(readFileSync(activePath, "utf8"));
|
|
const manifest = JSON.parse(readFileSync(snapshotPath, "utf8"));
|
|
active.revisions = active.revisions.map((revision: Record<string, unknown>) => (
|
|
revisionWithHistoricalState(revision, activeEncoding)
|
|
));
|
|
manifest.revisions = manifest.revisions.map((revision: Record<string, unknown>) => (
|
|
revisionWithHistoricalState(revision, manifestEncoding)
|
|
));
|
|
writeFileSync(activePath, JSON.stringify(active));
|
|
chmodSync(snapshotPath, 0o600);
|
|
writeFileSync(snapshotPath, JSON.stringify(manifest));
|
|
}
|
|
|
|
function persistedState(root: string, commit: string): { active: any; manifest: any } {
|
|
return {
|
|
active: JSON.parse(readFileSync(join(root, "state", "active.json"), "utf8")),
|
|
manifest: JSON.parse(readFileSync(join(root, "snapshots", commit, "snapshot.json"), "utf8")),
|
|
};
|
|
}
|
|
|
|
function filesystemFingerprint(root: string): string {
|
|
if (!existsSync(root)) return "absent";
|
|
const records: string[] = [];
|
|
const visit = (path: string, relative: string): void => {
|
|
const entry = lstatSync(path);
|
|
const metadata = [
|
|
entry.dev, entry.ino, entry.mode, entry.uid, entry.gid,
|
|
entry.size, entry.mtimeMs, entry.ctimeMs,
|
|
].join(":");
|
|
if (entry.isSymbolicLink()) {
|
|
records.push(`link:${relative}:${metadata}`);
|
|
return;
|
|
}
|
|
if (entry.isDirectory()) {
|
|
records.push(`directory:${relative}:${metadata}`);
|
|
for (const name of readdirSync(path).sort()) visit(join(path, name), relative === "." ? name : `${relative}/${name}`);
|
|
return;
|
|
}
|
|
if (entry.isFile()) {
|
|
const contents = readFileSync(path);
|
|
records.push(`file:${relative}:${metadata}:${contents.length}:${createHash("sha256").update(contents).digest("hex")}`);
|
|
return;
|
|
}
|
|
records.push(`other:${relative}:${metadata}`);
|
|
};
|
|
visit(root, ".");
|
|
return createHash("sha256").update(records.join("\n")).digest("hex");
|
|
}
|
|
|
|
test("verifies a never-initialized registry without contacting its remote", async () => {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-uninitialized-"));
|
|
temporaryRoots.push(root);
|
|
const registryRoot = join(root, "registry");
|
|
mkdirSync(registryRoot, { mode: 0o700 });
|
|
const registry = new WorkspaceRegistry(config(
|
|
registryRoot,
|
|
join(root, "missing-remote.git"),
|
|
));
|
|
|
|
const before = filesystemFingerprint(registryRoot);
|
|
|
|
await expect(registry.verifyStoredState()).resolves.toEqual({
|
|
state: "uninitialized",
|
|
workspaces: 0,
|
|
fingerprint: `sha256:${before}`,
|
|
});
|
|
expect(filesystemFingerprint(registryRoot)).toBe(before);
|
|
expect(existsSync(join(registryRoot, "repo"))).toBe(false);
|
|
expect(readdirSync(registryRoot)).toEqual([]);
|
|
});
|
|
|
|
test("never-initialized inspection refuses an absent or partial root without creating it", async () => {
|
|
const root = mkdtempSync(join(tmpdir(), "thoth-workspace-registry-absent-"));
|
|
temporaryRoots.push(root);
|
|
const registryRoot = join(root, "registry");
|
|
const registry = new WorkspaceRegistry(config(registryRoot, join(root, "missing-remote.git")));
|
|
|
|
await expect(registry.verifyStoredState()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(filesystemFingerprint(registryRoot)).toBe("absent");
|
|
|
|
mkdirSync(join(registryRoot, "state"), { recursive: true });
|
|
const partial = filesystemFingerprint(registryRoot);
|
|
await expect(registry.verifyStoredState()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(filesystemFingerprint(registryRoot)).toBe(partial);
|
|
});
|
|
|
|
test("verifies initialized snapshots and rejects partial or malformed persisted state", async () => {
|
|
const remote = await fixture();
|
|
const registryRoot = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote));
|
|
await registry.bootstrap();
|
|
|
|
const before = filesystemFingerprint(registryRoot);
|
|
const savedPath = process.env.PATH;
|
|
process.env.PATH = join(remote.root, "no-executables");
|
|
try {
|
|
await expect(registry.verifyStoredState()).resolves.toEqual({
|
|
state: "active",
|
|
workspaces: 1,
|
|
fingerprint: `sha256:${before}`,
|
|
});
|
|
} finally {
|
|
if (savedPath === undefined) delete process.env.PATH;
|
|
else process.env.PATH = savedPath;
|
|
}
|
|
expect(filesystemFingerprint(registryRoot)).toBe(before);
|
|
|
|
const firstIntegrity = await registry.verifyStoredState();
|
|
utimesSync(join(registryRoot, "repo"), new Date(1_000), new Date(1_000));
|
|
const metadataIntegrity = await registry.verifyStoredState();
|
|
expect(metadataIntegrity.fingerprint).not.toBe(firstIntegrity.fingerprint);
|
|
|
|
rmSync(join(registryRoot, "state", "active.json"));
|
|
await expect(registry.verifyStoredState()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
|
|
writeFileSync(join(registryRoot, "state", "active.json"), "{malformed");
|
|
await expect(registry.verifyStoredState()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
});
|
|
|
|
test("read-only inspection rejects extra components, links, and ephemeral runtime contents", async () => {
|
|
const remote = await fixture();
|
|
const registryRoot = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote));
|
|
const status = await registry.bootstrap();
|
|
const assertHostile = async (setup: () => void, cleanup: () => void): Promise<void> => {
|
|
setup();
|
|
const before = filesystemFingerprint(registryRoot);
|
|
await expect(registry.verifyStoredState()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(filesystemFingerprint(registryRoot)).toBe(before);
|
|
cleanup();
|
|
};
|
|
|
|
await assertHostile(
|
|
() => mkdirSync(join(registryRoot, "unexpected")),
|
|
() => rmSync(join(registryRoot, "unexpected"), { recursive: true }),
|
|
);
|
|
await assertHostile(
|
|
() => rmSync(join(registryRoot, "locks", "empty-hooks"), { recursive: true }),
|
|
() => mkdirSync(join(registryRoot, "locks", "empty-hooks")),
|
|
);
|
|
await assertHostile(
|
|
() => writeFileSync(join(registryRoot, "state", "unexpected.json"), "{}"),
|
|
() => rmSync(join(registryRoot, "state", "unexpected.json")),
|
|
);
|
|
await assertHostile(
|
|
() => writeFileSync(join(registryRoot, "snapshots", status.head!, "unexpected"), "extra"),
|
|
() => rmSync(join(registryRoot, "snapshots", status.head!, "unexpected")),
|
|
);
|
|
await assertHostile(
|
|
() => {
|
|
mkdirSync(join(registryRoot, "snapshots", "runtime"), { recursive: true });
|
|
writeFileSync(join(registryRoot, "snapshots", "runtime", "restored-secret.yaml"), "secret: forbidden");
|
|
},
|
|
() => rmSync(join(registryRoot, "snapshots", "runtime"), { recursive: true }),
|
|
);
|
|
await assertHostile(
|
|
() => symlinkSync(join(registryRoot, "state", "active.json"), join(registryRoot, "linked-active.json")),
|
|
() => rmSync(join(registryRoot, "linked-active.json")),
|
|
);
|
|
await assertHostile(
|
|
() => symlinkSync(join(registryRoot, "state", "active.json"), join(registryRoot, "repo", "linked-active.json")),
|
|
() => rmSync(join(registryRoot, "repo", "linked-active.json")),
|
|
);
|
|
});
|
|
|
|
test("rejects a catalog entry without a descriptor instead of creating a bootstrap slot", async () => {
|
|
const remote = await contentOnlyFixture();
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
|
|
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(existsSync(join(remote.root, "registry", "state", "active.json"))).toBe(false);
|
|
});
|
|
test("bootstraps a checkout and activates a validated immutable snapshot", async () => {
|
|
const remote = await fixture();
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
|
|
const status = await registry.bootstrap();
|
|
|
|
expect(status.head).toMatch(/^[0-9a-f]{40}$/);
|
|
expect(existsSync(registry.snapshotPath(status.head!, "psd-clinical"))).toBe(true);
|
|
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
|
revision: { commit: remote.initialCommit, id: "psd-clinical" },
|
|
});
|
|
});
|
|
|
|
test("concurrent first lists lazily bootstrap a clean registry once safely", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
|
|
const [first, second] = await Promise.all([registry.list(), registry.list()]);
|
|
for (const revisions of [first, second]) {
|
|
expect(revisions).toEqual([
|
|
expect.objectContaining({
|
|
id: "psd-clinical",
|
|
commit: remote.initialCommit,
|
|
}),
|
|
]);
|
|
}
|
|
expect(existsSync(join(root, "state", "active.json"))).toBe(true);
|
|
});
|
|
|
|
test.each(["missing", "blob"])(
|
|
"rejects a remote filesystem descriptor with a %s Evidence root and keeps the active snapshot",
|
|
async (invalidKind) => {
|
|
const remote = await fixture(withFilesystemEvidence(validYaml));
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
await registry.bootstrap();
|
|
const evidenceRoot = join(remote.source, "psd-clinical", "evidence");
|
|
rmSync(evidenceRoot, { recursive: true, force: true });
|
|
if (invalidKind === "blob") writeFileSync(evidenceRoot, "not a tree\n");
|
|
await git(remote.source, ["add", "-A", "psd-clinical/evidence"]);
|
|
await git(remote.source, ["commit", "-m", `Make Evidence root ${invalidKind}`]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
const invalidCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
|
|
|
|
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(invalidCommit).not.toBe(remote.initialCommit);
|
|
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
|
revision: { commit: remote.initialCommit },
|
|
});
|
|
},
|
|
);
|
|
|
|
test("activation validates filesystem Evidence against its exact safeHead rather than checkout HEAD", async () => {
|
|
const remote = await fixture(withFilesystemEvidence(validYaml));
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
await registry.bootstrap();
|
|
rmSync(join(remote.source, "psd-clinical", "evidence"), {
|
|
recursive: true, force: true,
|
|
});
|
|
await git(remote.source, ["add", "-A", "psd-clinical/evidence"]);
|
|
await git(remote.source, ["commit", "-m", "Remove current Evidence root"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
const invalidHead = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
|
|
const internals = registry as unknown as {
|
|
repository: { pull(): Promise<{ head?: string }> };
|
|
activate(commit: string): Promise<void>;
|
|
};
|
|
|
|
expect((await internals.repository.pull()).head).toBe(invalidHead);
|
|
await expect(internals.activate(remote.initialCommit)).resolves.toBeUndefined();
|
|
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
|
revision: { commit: remote.initialCommit },
|
|
});
|
|
});
|
|
|
|
test("creates an immutable descriptor revision for a content-only Evidence commit", async () => {
|
|
const remote = await fixture(withFilesystemEvidence(validYaml));
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
const initial = await registry.read("psd-clinical");
|
|
const evidencePath = "psd-clinical/evidence";
|
|
const initialTree = await gitOutput(remote.source, ["rev-parse", `${remote.initialCommit}:${evidencePath}`]);
|
|
writeFileSync(join(remote.source, evidencePath, "guide.md"), "guide v2\n");
|
|
await git(remote.source, ["add", `${evidencePath}/guide.md`]);
|
|
await git(remote.source, ["commit", "-m", "Update Evidence only"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
|
|
const contentTree = await gitOutput(remote.source, ["rev-parse", `${contentCommit}:${evidencePath}`]);
|
|
|
|
await registry.pull();
|
|
const current = await registry.read("psd-clinical");
|
|
|
|
expect(contentTree).not.toBe(initialTree);
|
|
expect(current.revision).toMatchObject({ commit: contentCommit, blob: initial.revision.blob });
|
|
expect(current.revision.snapshotPath).not.toBe(initial.revision.snapshotPath);
|
|
expect(readFileSync(current.revision.snapshotPath, "utf8")).toBe(
|
|
readFileSync(initial.revision.snapshotPath, "utf8"),
|
|
);
|
|
await expect(runFile("git", [
|
|
"--git-dir", remote.remote, "cat-file", "-e", `${contentCommit}:${evidencePath}/guide.md`,
|
|
], { cwd: remote.root })).resolves.toBeDefined();
|
|
});
|
|
|
|
test("keeps content-only historical descriptor revisions distinguishable by commit", async () => {
|
|
const remote = await fixture(withFilesystemEvidence(validYaml));
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
await registry.bootstrap();
|
|
writeFileSync(
|
|
join(remote.source, "psd-clinical", "evidence", "guide.md"),
|
|
"historical content\n",
|
|
);
|
|
await git(remote.source, ["add", "psd-clinical/evidence/guide.md"]);
|
|
await git(remote.source, ["commit", "-m", "Retained Evidence update"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
const contentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
|
|
await registry.pull();
|
|
await registry.reconcileSnapshotRetention([remote.initialCommit]);
|
|
|
|
const retained = (await registry.listRetainedSnapshots()).filter(({ id }) => id === "psd-clinical");
|
|
expect(retained.map(({ commit }) => commit)).toEqual([contentCommit, remote.initialCommit]);
|
|
const oldPinned = await registry.readPinned("psd-clinical", remote.initialCommit);
|
|
const newPinned = await registry.readPinned("psd-clinical", contentCommit);
|
|
expect(oldPinned.workspaceConfigPath).not.toBe(newPinned.workspaceConfigPath);
|
|
expect(oldPinned.workspace).toEqual(newPinned.workspace);
|
|
});
|
|
|
|
test.each([
|
|
["adds", validYaml, withDwhRestDiagnostic(validYaml)],
|
|
["removes", withDwhRestDiagnostic(validYaml), validYaml],
|
|
])("pulls a curator change that %s a diagnostics branch without API rewrite", async (_operation, baseSource, remoteSource) => {
|
|
const remote = await fixture(baseSource);
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
await registry.bootstrap();
|
|
const initial = await registry.read("psd-clinical");
|
|
writeFileSync(join(remote.source, "psd-clinical", "workspace.yaml"), remoteSource);
|
|
await git(remote.source, ["add", "psd-clinical/workspace.yaml"]);
|
|
await git(remote.source, ["commit", "-m", `Registry ${_operation} diagnostic branch`]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
|
|
await registry.pull();
|
|
const updated = await registry.read("psd-clinical");
|
|
expect(updated.revision.commit).not.toBe(initial.revision.commit);
|
|
});
|
|
test.each([
|
|
["v1", legacyV1Yaml()],
|
|
["v2", legacyV2Yaml()],
|
|
])("rejects a schema %s descriptor instead of activating it", async (_version, legacyYaml) => {
|
|
const remote = await fixture(legacyYaml);
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
|
|
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
expect(existsSync(join(remote.root, "registry", "state", "active.json"))).toBe(false);
|
|
});
|
|
|
|
test("writes only state-free revisions and never exposes revision state", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
|
|
const initial = persistedState(root, remote.initialCommit);
|
|
expect(Object.keys(initial.active).sort()).toEqual(["catalog", "head", "revisions"]);
|
|
expect(Object.keys(initial.manifest).sort()).toEqual(["catalog", "files", "head", "revisions"]);
|
|
expect(Object.keys(initial.active.revisions[0]).sort()).toEqual(["blob", "commit", "id", "snapshotPath"]);
|
|
expect(Object.keys(initial.manifest.revisions[0]).sort()).toEqual(["blob", "commit", "id", "snapshotPath"]);
|
|
|
|
const listed = await registry.list();
|
|
const read = await registry.read("psd-clinical");
|
|
expect(listed[0]).not.toHaveProperty("state");
|
|
expect(read.revision).not.toHaveProperty("state");
|
|
});
|
|
|
|
test("accepts historical operational state without leaking it or rewriting the immutable snapshot", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
rewritePersistedRevisionStates(root, remote.initialCommit, "operational", "operational");
|
|
const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json");
|
|
const historicalManifest = readFileSync(snapshotPath, "utf8");
|
|
|
|
const restored = new WorkspaceRegistry(config(root, remote.remote));
|
|
const listed = await restored.list();
|
|
const read = await restored.read("psd-clinical");
|
|
|
|
expect(listed[0]).not.toHaveProperty("state");
|
|
expect(read.revision).not.toHaveProperty("state");
|
|
expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest);
|
|
|
|
await restored.bootstrap();
|
|
const rewrittenActive = persistedState(root, remote.initialCommit).active;
|
|
expect(rewrittenActive.revisions[0]).not.toHaveProperty("state");
|
|
expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest);
|
|
});
|
|
|
|
test.each([
|
|
["historical active and state-free snapshot", "operational", "absent"],
|
|
["state-free active and historical snapshot", "absent", "operational"],
|
|
] as const)("normalizes mixed persisted revision encodings: %s", async (_name, activeState, manifestState) => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
rewritePersistedRevisionStates(root, remote.initialCommit, activeState, manifestState);
|
|
const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json");
|
|
const historicalManifest = readFileSync(snapshotPath, "utf8");
|
|
|
|
const revisions = await new WorkspaceRegistry(config(root, remote.remote)).list();
|
|
|
|
expect(revisions[0]).not.toHaveProperty("state");
|
|
expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest);
|
|
});
|
|
|
|
test.each([
|
|
["migration_required in active state", "migration_required", "absent"],
|
|
["migration_required in snapshot manifest", "absent", "migration_required"],
|
|
["unknown state in active state", "unknown", "operational"],
|
|
["unknown state in snapshot manifest", "operational", "unknown"],
|
|
] as const)("rejects %s", async (_name, activeState, manifestState) => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
rewritePersistedRevisionStates(root, remote.initialCommit, activeState, manifestState);
|
|
|
|
await expect(new WorkspaceRegistry(config(root, remote.remote)).list()).rejects.toMatchObject({
|
|
code: "workspace_invalid",
|
|
});
|
|
});
|
|
|
|
test.each([
|
|
["active top level", "active", "top"],
|
|
["active revision", "active", "revision"],
|
|
["snapshot top level", "manifest", "top"],
|
|
["snapshot revision", "manifest", "revision"],
|
|
] as const)("rejects unknown fields in %s", async (_name, component, location) => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
const path = component === "active"
|
|
? join(root, "state", "active.json")
|
|
: join(root, "snapshots", remote.initialCommit, "snapshot.json");
|
|
const persisted = JSON.parse(readFileSync(path, "utf8"));
|
|
if (location === "top") persisted.unexpected = true;
|
|
else persisted.revisions[0].unexpected = true;
|
|
if (component === "manifest") chmodSync(path, 0o600);
|
|
writeFileSync(path, JSON.stringify(persisted));
|
|
|
|
await expect(new WorkspaceRegistry(config(root, remote.remote)).list()).rejects.toMatchObject({
|
|
code: "workspace_invalid",
|
|
});
|
|
});
|
|
|
|
test("normalizes operational state in retained historical snapshots without rewriting them", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
writeFileSync(join(remote.source, "psd-clinical", "workspace.yaml"), validYaml.replace(
|
|
"name: Policlinico San Donato", "name: Current workspace",
|
|
));
|
|
writeFileSync(join(remote.source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "psd-clinical", name: "Current workspace" },
|
|
]));
|
|
await git(remote.source, ["add", "-A"]);
|
|
await git(remote.source, ["commit", "-m", "Update active workspace"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
await registry.pull();
|
|
rewritePersistedRevisionStates(root, remote.initialCommit, "absent", "operational");
|
|
const snapshotPath = join(root, "snapshots", remote.initialCommit, "snapshot.json");
|
|
const historicalManifest = readFileSync(snapshotPath, "utf8");
|
|
|
|
const retained = await new WorkspaceRegistry(config(root, remote.remote)).listRetainedSnapshots();
|
|
|
|
expect(retained).toEqual(expect.arrayContaining([
|
|
expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit }),
|
|
]));
|
|
expect(retained.every((revision) => !("state" in revision))).toBe(true);
|
|
expect(readFileSync(snapshotPath, "utf8")).toBe(historicalManifest);
|
|
});
|
|
|
|
test("normalizes historical operational state during offline fallback after restart", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
rewritePersistedRevisionStates(root, remote.initialCommit, "operational", "operational");
|
|
rmSync(remote.remote, { recursive: true, force: true });
|
|
|
|
const restored = new WorkspaceRegistry(config(root, remote.remote));
|
|
await expect(restored.pull()).resolves.toMatchObject({
|
|
degraded: true,
|
|
head: remote.initialCommit,
|
|
repository: { host: "local", repository: "configured-repository", transport: "local" },
|
|
});
|
|
const listed = await restored.list();
|
|
const read = await restored.read("psd-clinical");
|
|
expect(listed[0]).not.toHaveProperty("state");
|
|
expect(read.revision).not.toHaveProperty("state");
|
|
});
|
|
|
|
test("fails closed when a retained snapshot descriptor is not schema v4", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
await new WorkspaceRegistry(config(root, remote.remote)).bootstrap();
|
|
const snapshotDirectory = join(root, "snapshots", remote.initialCommit);
|
|
const yamlPath = join(snapshotDirectory, "psd-clinical.yaml");
|
|
chmodSync(yamlPath, 0o600);
|
|
const legacy = legacyV2Yaml();
|
|
writeFileSync(yamlPath, legacy);
|
|
const manifestPath = join(snapshotDirectory, "snapshot.json");
|
|
const manifest = JSON.parse(readFileSync(manifestPath, "utf8"));
|
|
manifest.files["psd-clinical.yaml"] = createHash("sha256").update(legacy).digest("hex");
|
|
chmodSync(manifestPath, 0o600);
|
|
writeFileSync(manifestPath, JSON.stringify(manifest));
|
|
|
|
await expect(new WorkspaceRegistry(config(root, remote.remote)).list()).rejects.toMatchObject({
|
|
code: "workspace_invalid",
|
|
});
|
|
});
|
|
|
|
test("keeps the last valid snapshot when a pulled commit has invalid YAML", async () => {
|
|
const remote = await fixture();
|
|
const registry = new WorkspaceRegistry(config(join(remote.root, "registry"), remote.remote));
|
|
await registry.bootstrap();
|
|
await pushInvalidWorkspace(remote.source);
|
|
|
|
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
|
revision: { commit: remote.initialCommit },
|
|
});
|
|
});
|
|
|
|
test("retains a historical snapshot while a resumable manifest still references its revision", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
|
|
writeFileSync(join(remote.source, "psd-clinical", "workspace.yaml"), validYaml.replace(
|
|
"name: Policlinico San Donato", "name: Updated Policlinico San Donato",
|
|
));
|
|
writeFileSync(join(remote.source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "psd-clinical", name: "Updated Policlinico San Donato" },
|
|
]));
|
|
await git(remote.source, ["add", "-A"]);
|
|
await git(remote.source, ["commit", "-m", "Update workspace"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
const currentCommit = await gitOutput(remote.source, ["rev-parse", "HEAD"]);
|
|
await registry.pull();
|
|
|
|
await registry.reconcileSnapshotRetention([remote.initialCommit]);
|
|
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
|
|
expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true);
|
|
|
|
await registry.reconcileSnapshotRetention([]);
|
|
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false);
|
|
expect(existsSync(registry.snapshotPath(currentCommit, "psd-clinical"))).toBe(true);
|
|
});
|
|
|
|
test("a session revision lease survives stale retention scans until its manifest is observed", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
const lease = await registry.acquireSessionRevision("psd-clinical");
|
|
|
|
writeFileSync(join(remote.source, "psd-clinical", "workspace.yaml"), validYaml.replace(
|
|
"name: Policlinico San Donato", "name: Concurrent revision",
|
|
));
|
|
writeFileSync(join(remote.source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "psd-clinical", name: "Concurrent revision" },
|
|
]));
|
|
await git(remote.source, ["add", "-A"]);
|
|
await git(remote.source, ["commit", "-m", "Publish while session is starting"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
await registry.pull();
|
|
|
|
await registry.reconcileSnapshotRetention([]);
|
|
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
|
|
|
|
await lease.markPersisted();
|
|
await registry.reconcileSnapshotRetention([]);
|
|
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(true);
|
|
|
|
await registry.reconcileSnapshotRetention([remote.initialCommit]);
|
|
await registry.reconcileSnapshotRetention([]);
|
|
expect(existsSync(registry.snapshotPath(remote.initialCommit, "psd-clinical"))).toBe(false);
|
|
});
|
|
|
|
test("lists operational descriptors retained after their workspace was removed from the active revision", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
|
|
mkdirSync(join(remote.source, "archive-only"), { recursive: true });
|
|
writeFileSync(join(remote.source, "archive-only", "workspace.yaml"), validYaml.replace(
|
|
"id: psd-clinical", "id: archive-only",
|
|
).replace("collection: psd-clinical", "collection: archive-only"));
|
|
writeFileSync(join(remote.source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "psd-clinical", name: "Policlinico San Donato" },
|
|
{ id: "archive-only", name: "Policlinico San Donato" },
|
|
]));
|
|
await git(remote.source, ["add", "-A"]);
|
|
await git(remote.source, ["commit", "-m", "Add retained workspace"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
await registry.pull();
|
|
|
|
rmSync(join(remote.source, "psd-clinical", "workspace.yaml"));
|
|
writeFileSync(join(remote.source, "thoth-workspaces.yaml"), catalogYaml([
|
|
{ id: "archive-only", name: "Policlinico San Donato" },
|
|
]));
|
|
await git(remote.source, ["add", "-u"]);
|
|
await git(remote.source, ["commit", "-m", "Remove original workspace"]);
|
|
await git(remote.source, ["push", "origin", "main"]);
|
|
await registry.pull();
|
|
|
|
const retained = await registry.listRetainedSnapshots();
|
|
expect(retained).toEqual(expect.arrayContaining([
|
|
expect.objectContaining({ id: "psd-clinical", commit: remote.initialCommit }),
|
|
expect.objectContaining({ id: "archive-only" }),
|
|
]));
|
|
});
|
|
|
|
test("does not bypass an existing live advisory repository lock", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
const lock = new WorkspaceRepositoryLock(join(root, "locks"));
|
|
let release!: () => void;
|
|
let started!: () => void;
|
|
const held = lock.run(async () => {
|
|
started();
|
|
await new Promise<void>((resolve) => { release = resolve; });
|
|
});
|
|
await new Promise<void>((resolve) => { started = resolve; });
|
|
|
|
try {
|
|
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "workspace_stale" });
|
|
} finally {
|
|
release();
|
|
await held;
|
|
}
|
|
});
|
|
|
|
test("rejects a symbolic-link registry root before creating a lock below it", async () => {
|
|
const remote = await fixture();
|
|
const target = join(remote.root, "registry-target");
|
|
const root = join(remote.root, "registry-link");
|
|
mkdirSync(target);
|
|
symlinkSync(target, root);
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
|
|
await expect(registry.bootstrap()).rejects.toMatchObject({ code: "git_unavailable" });
|
|
expect(existsSync(join(target, "locks"))).toBe(false);
|
|
});
|
|
|
|
test("rejects a locally-ahead checkout instead of activating local-only content", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
const checkout = join(root, "repo");
|
|
writeFileSync(join(checkout, "psd-clinical", "workspace.yaml"), validYaml.replace(
|
|
"name: Policlinico San Donato", "name: Local only workspace",
|
|
));
|
|
await git(checkout, ["config", "user.name", "Workspace Registry Test"]);
|
|
await git(checkout, ["config", "user.email", "workspace-registry@example.invalid"]);
|
|
await git(checkout, ["add", "psd-clinical/workspace.yaml"]);
|
|
await git(checkout, ["commit", "-m", "Local-only workspace"]);
|
|
|
|
await expect(registry.pull()).rejects.toMatchObject({ code: "git_non_fast_forward" });
|
|
await expect(registry.read("psd-clinical")).resolves.toMatchObject({
|
|
revision: { commit: remote.initialCommit },
|
|
workspace: { workspace: { name: "Policlinico San Donato" } },
|
|
});
|
|
});
|
|
|
|
test("recovers a dead-process advisory lock while preserving active snapshot safety", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
mkdirSync(join(root, "locks"), { recursive: true });
|
|
writeFileSync(join(root, "locks", "repository.lock"), JSON.stringify({ pid: 999_999_999 }));
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
|
|
await expect(registry.bootstrap()).resolves.toMatchObject({
|
|
head: remote.initialCommit,
|
|
degraded: false,
|
|
});
|
|
});
|
|
|
|
test.each(["manifest", "blob", "workspace", "document"])(
|
|
"rejects a corrupted %s snapshot component instead of reporting it active",
|
|
async (component) => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
const snapshot = join(root, "snapshots", remote.initialCommit);
|
|
|
|
if (component === "manifest") {
|
|
const file = join(snapshot, "snapshot.json");
|
|
chmodSync(file, 0o600);
|
|
writeFileSync(file, "{");
|
|
}
|
|
if (component === "blob") {
|
|
const activePath = join(root, "state", "active.json");
|
|
const active = JSON.parse(readFileSync(activePath, "utf8"));
|
|
active.revisions[0].blob = "not-a-git-blob";
|
|
writeFileSync(activePath, JSON.stringify(active));
|
|
}
|
|
if (component === "workspace") {
|
|
const file = join(snapshot, "psd-clinical.yaml");
|
|
chmodSync(file, 0o600);
|
|
writeFileSync(file, "truncated");
|
|
}
|
|
if (component === "document") rmSync(join(snapshot, "psd-clinical.md"));
|
|
|
|
await expect(registry.list()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
await expect(registry.read("psd-clinical")).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
},
|
|
);
|
|
|
|
test("rejects a corrupt fallback snapshot instead of returning degraded active state", async () => {
|
|
const remote = await fixture();
|
|
const root = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(root, remote.remote));
|
|
await registry.bootstrap();
|
|
const document = join(root, "snapshots", remote.initialCommit, "psd-clinical.md");
|
|
chmodSync(document, 0o600);
|
|
writeFileSync(document, "corrupt");
|
|
rmSync(remote.remote, { recursive: true, force: true });
|
|
|
|
await expect(registry.pull()).rejects.toMatchObject({ code: "workspace_invalid" });
|
|
});
|
|
|
|
|
|
test("snapshots canonical Evidence artifacts at the active commit and materializes filesystem Evidence bytes", async () => {
|
|
const remote = await fixture(withFilesystemEvidence(validYaml));
|
|
const registryRoot = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote));
|
|
|
|
const status = await registry.bootstrap();
|
|
const active = await registry.read("psd-clinical");
|
|
const snapshotDirectory = join(registryRoot, "snapshots", status.head!);
|
|
const descriptor = active.workspace as CanonicalWorkspace;
|
|
const docs = renderWorkspaceDocs(descriptor);
|
|
const expectedFiles: Record<string, string> = {
|
|
"psd-clinical.yaml": serializeWorkspaceYaml(descriptor),
|
|
"psd-clinical.env.example": docs.envExample,
|
|
"psd-clinical.md": docs.markdown,
|
|
};
|
|
const manifest = JSON.parse(readFileSync(join(snapshotDirectory, "snapshot.json"), "utf8"));
|
|
|
|
expect(status.head).toBe(remote.initialCommit);
|
|
const committedDescriptor = parseWorkspaceYaml(await gitOutput(remote.source, [
|
|
"show", `${remote.initialCommit}:psd-clinical/workspace.yaml`,
|
|
])) as CanonicalWorkspace;
|
|
const committedBlob = await gitOutput(remote.source, [
|
|
"rev-parse", `${remote.initialCommit}:psd-clinical/workspace.yaml`,
|
|
]);
|
|
expect(active.revision.blob).toBe(committedBlob);
|
|
expect(expectedFiles["psd-clinical.yaml"]).toBe(serializeWorkspaceYaml(committedDescriptor));
|
|
expect(readdirSync(snapshotDirectory).sort()).toEqual([
|
|
"psd-clinical", "psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "snapshot.json",
|
|
]);
|
|
expect(manifest.head).toBe(remote.initialCommit);
|
|
expect(manifest.revisions[0]).toMatchObject({
|
|
id: "psd-clinical", commit: remote.initialCommit, blob: committedBlob,
|
|
});
|
|
expect(Object.keys(manifest.files).sort()).toEqual([
|
|
"psd-clinical.env.example", "psd-clinical.md", "psd-clinical.yaml", "psd-clinical/evidence.manifest.json",
|
|
]);
|
|
for (const [name, contents] of Object.entries(expectedFiles)) {
|
|
expect(readFileSync(join(snapshotDirectory, name), "utf8")).toBe(contents);
|
|
expect(manifest.files[name]).toBe(createHash("sha256").update(contents).digest("hex"));
|
|
}
|
|
// P6: the materialized Evidence tree and its digest-chained manifest.
|
|
const evidenceManifest = JSON.parse(readFileSync(
|
|
join(snapshotDirectory, "psd-clinical", "evidence.manifest.json"), "utf8",
|
|
));
|
|
expect(evidenceManifest).toMatchObject({ workspace: "psd-clinical", commit: remote.initialCommit, entryCount: 1 });
|
|
expect(manifest.files["psd-clinical/evidence.manifest.json"]).toBe(
|
|
createHash("sha256").update(`${JSON.stringify(evidenceManifest)}\n`).digest("hex"),
|
|
);
|
|
expect(readFileSync(join(snapshotDirectory, "psd-clinical", "evidence", "guide.md"), "utf8"))
|
|
.toBe("guide v1\n");
|
|
expect(JSON.stringify(manifest)).not.toContain("workspace-content/");
|
|
expect(readdirSync(snapshotDirectory).some((name) => name === "workspace-content")).toBe(false);
|
|
expect(readFileSync(join(remote.source, "psd-clinical/evidence/guide.md"), "utf8"))
|
|
.toBe("guide v1\n");
|
|
});
|
|
|
|
|
|
test("never copies an installation secret canary into Git, generated artifacts, metadata, or errors", async () => {
|
|
const remote = await fixture(validYaml.concat(`evidence:
|
|
source:
|
|
type: http
|
|
uris: [https://evidence.example.test/guide.md]
|
|
authentication: signed_urls_file
|
|
`));
|
|
const canary = "CANARY-EVIDENCE-SECRET-ONLY-IN-FIXTURE";
|
|
const secretDirectory = join(remote.root, "fixture-secrets");
|
|
mkdirSync(secretDirectory);
|
|
const secretFile = join(secretDirectory, "signed-urls");
|
|
writeFileSync(secretFile, canary);
|
|
const registryRoot = join(remote.root, "registry");
|
|
const registry = new WorkspaceRegistry(config(registryRoot, remote.remote, {
|
|
secretRoots: [secretDirectory],
|
|
}));
|
|
const previous = process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
|
process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = secretFile;
|
|
try {
|
|
const status = await registry.bootstrap();
|
|
const snapshotDirectory = join(registryRoot, "snapshots", status.head!);
|
|
let gitBlobText = "";
|
|
try {
|
|
gitBlobText = (await runFile(
|
|
"git", ["grep", "-I", "-h", "-e", canary, "HEAD", "--", "."], { cwd: remote.source },
|
|
)).stdout;
|
|
} catch (error) {
|
|
if (!error || typeof error !== "object" || !("code" in error) || error.code !== 1) throw error;
|
|
gitBlobText = "stdout" in error ? String(error.stdout ?? "") : "";
|
|
}
|
|
expect(gitBlobText).toBe("");
|
|
for (const name of readdirSync(snapshotDirectory)) {
|
|
expect(readFileSync(join(snapshotDirectory, name), "utf8")).not.toContain(canary);
|
|
}
|
|
} finally {
|
|
if (previous === undefined) delete process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE;
|
|
else process.env.THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE = previous;
|
|
}
|
|
});
|