feat(discord): git verbs for the Discord Sage on the shared-signals root, seat identity through a package credential helper, vault record protocol (#1509)

Row 24. A writable root that is a git work tree may carry a git object in
the binding; the seat then has git_status, git_commit (explicit paths, seat
author, Requested-by trailer from the envelope requester, push at once per
D6), git_pull (ff-only) and git_push (one branch, never force), plus
reserve_id and per-write clone locks under protocol vault. Git children run
with no host config and one credential helper, bin/git-credential.mjs,
reading the 0600 seat token file named in the binding; the fleet helper
serves only the Gitea hosts. Suite 58/58, node 143. rev-code-02 APPROVED
round 1 (#1509 comment 26375, tree 82ab962f).

Co-Authored-By: Claude Fable 5.1 <[email protected]>
This commit is contained in:
2026-09-18 07:52:35 -05:00
co-authored by Claude Fable 5.1
parent 1685deb423
commit 1949ed8d31
23 changed files with 1284 additions and 48 deletions
+27 -1
View File
@@ -204,7 +204,7 @@ test("binding: tools is optional, validated strictly, a fixed key for reload, an
const docs = join(root, "docs");
mkdirSync(docs);
const ok = validateBinding(rawBinding({ tools: { roots: [{ name: "docs", path: docs }] } }));
assert.deepEqual(ok.tools, { roots: [{ name: "docs", path: docs, write: false }], maxFileBytes: 262144, maxCallsPerTurn: 8, web: null });
assert.deepEqual(ok.tools, { roots: [{ name: "docs", path: docs, write: false, git: null }], maxFileBytes: 262144, maxCallsPerTurn: 8, web: null });
assert.ok(FIXED_KEYS.includes("tools"));
const bad = [
[{ tools: [] }, /must be an object/],
@@ -239,3 +239,29 @@ test("binding: tools is optional, validated strictly, a fixed key for reload, an
const linked = validateBinding(rawBinding({ tools: { roots: [{ name: "l", path: join(root, "docs-link") }] } }));
assert.throws(() => resolveToolRoots(linked, { dataRoot }), /symlink/);
});
test("binding: a git key is validated at load and reaches the extension whole, and only on a writable root", () => {
const root = makeRoot();
const repo = join(root, "repo");
mkdirSync(repo);
const tokenFile = join(root, "token");
writeFileSync(tokenFile, "not_a_real_token_just_a_test_value_x\n", { mode: 0o600 });
const git = { branch: "main", identity: "sage", tokenFile, author: "Sage <[email protected]>" };
const b = validateBinding(rawBinding({ tools: { roots: [{ name: "ss", path: repo, write: true, git }] } }));
assert.deepEqual(b.tools.roots[0].git, { branch: "main", identity: "sage", tokenFile, author: { name: "Sage", email: "[email protected]" }, protocol: null });
const dataRoot = join(root, "data");
mkdirSync(join(dataRoot, "discord"), { recursive: true });
assert.deepEqual(resolveToolRoots(b, { dataRoot }).roots, [{ name: "ss", path: repo, write: true, git: { branch: "main", identity: "sage", tokenFile, author: "Sage <[email protected]>" } }]);
const v = validateBinding(rawBinding({ tools: { roots: [{ name: "ss", path: repo, write: true, git: { ...git, protocol: "vault" } }] } }));
assert.equal(resolveToolRoots(v, { dataRoot }).roots[0].git.protocol, "vault");
const bad = [
[{ git }, /git needs write: true/],
[{ write: true, git: { ...git, branch: "" } }, /branch/],
[{ write: true, git: { ...git, tokenFile: join(root, "nope") } }, /not found/],
[{ write: true, git: { ...git, protocol: "x" } }, /protocol/],
[{ write: true, git: "yes" }, /git: not an object/],
];
for (const [o, re] of bad) assert.throws(() => validateBinding(rawBinding({ tools: { roots: [{ name: "ss", path: repo, ...o }] } })), re, JSON.stringify(o));
chmodSync(tokenFile, 0o640);
assert.throws(() => validateBinding(rawBinding({ tools: { roots: [{ name: "ss", path: repo, write: true, git }] } })), (e) => e instanceof DiscordError && /mode 0600/.test(e.message));
});