From 166ee8c90fd7d4b8ad736af5687322639cab2ec2 Mon Sep 17 00:00:00 2001 From: Mos Date: Fri, 31 Jul 2026 13:48:33 +0000 Subject: [PATCH 1/2] fix(wake): close fd 9 in the detector's sleep child so a dead detector's lock dies with it (#993) --- packages/mosaic/framework/tools/wake/detector.sh | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/packages/mosaic/framework/tools/wake/detector.sh b/packages/mosaic/framework/tools/wake/detector.sh index 2c064eaa..7f1ddf45 100755 --- a/packages/mosaic/framework/tools/wake/detector.sh +++ b/packages/mosaic/framework/tools/wake/detector.sh @@ -529,7 +529,19 @@ cmd_run() { echo "detector.sh: WARN — off-host liveness beacon emit failed (see beacon.sh); the off-host absence check remains the authoritative dead-man." >&2 fi [ "$once" -eq 1 ] && break - sleep "$interval" + # Close the detector lock fd in the sleep child; otherwise an orphaned sleep + # keeps the single-instance flock (fd 9, taken at exec 9> above) alive after + # the detector parent dies. The lock is non-blocking (`flock -n`, above), so + # for as long as that sleep survives a replacement instance is REFUSED and + # exits rather than queueing. This particular hold is BOUNDED by one poll + # interval (WAKE_DETECTOR_INTERVAL, default 30s): when the orphaned sleep + # exits its copy of fd 9 closes, ending this bounded sleep-child hold. It + # does NOT follow that the next start succeeds — other inheritors of fd 9 + # (the M1 adapter, M2 sink grandchildren) are outside this patch's scope and + # can keep holding the flock. The cost this removes is a restart window in + # which every supervisor retry fails on the sleep child's account. + # `9>&-` closes ONLY the child's copy — the parent's lock is unaffected. + sleep "$interval" 9>&- done } From 06e0d4035286b901346ba0dc518ceb86d93a07dd Mon Sep 17 00:00:00 2001 From: mos-dt-0 Date: Fri, 31 Jul 2026 14:08:41 +0000 Subject: [PATCH 2/2] =?UTF-8?q?feat(quality):=20CI=20test-membership=20gua?= =?UTF-8?q?rd=20=E2=80=94=20enumeration=20can=20no=20longer=20silently=20u?= =?UTF-8?q?nder-run=20the=20disk=20(#1017)=20(#1018)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: mos-dt-0 --- .woodpecker/ci.yml | 5 + .../quality/scripts/check-test-enumeration.sh | 165 +++++++++++++++++ .../scripts/test-check-test-enumeration.sh | 166 ++++++++++++++++++ .../quality/test-enumeration-exclusions.txt | 45 +++++ packages/mosaic/package.json | 2 +- 5 files changed, 382 insertions(+), 1 deletion(-) create mode 100755 packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh create mode 100755 packages/mosaic/framework/tools/quality/scripts/test-check-test-enumeration.sh create mode 100644 packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt diff --git a/.woodpecker/ci.yml b/.woodpecker/ci.yml index 482e4a65..c02f3f1c 100644 --- a/.woodpecker/ci.yml +++ b/.woodpecker/ci.yml @@ -41,6 +41,11 @@ steps: # (Constitution + dispatcher + each RUNTIME.md slice). See DESIGN §7 / R9. - bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh --self-test - bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh + # Test-membership guard (#1017): also first link of test:framework-shell. + # Invoked from BOTH surfaces it audits (F2, PR #1018) — the guard is link + # [0] of the pnpm chain, so severing that chain would silence it together + # with everything it guards; this direct line keeps one instrument running. + - bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh # Blocking gate (#791): a framework upgrade must never write or delete an # operator-owned path. The HARD GATE proves an unanticipated operator sentinel diff --git a/packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh b/packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh new file mode 100755 index 00000000..0bab4467 --- /dev/null +++ b/packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh @@ -0,0 +1,165 @@ +#!/usr/bin/env bash +# check-test-enumeration.sh — CI test-membership guard (#1017). +# +# CI reaches shell suites through two hand-enumerated surfaces: +# S1 packages/mosaic/package.json scripts."test:framework-shell" +# S2 .woodpecker/ci.yml direct `bash packages/mosaic/framework/tools/...` commands +# +# A hand-enumerated allowlist re-arms its own gap: a new suite never auto-joins, +# so the list silently under-runs the disk (17 of 39 suites were invisible when +# #1017 was filed). This guard makes that under-run impossible to do silently: +# +# FAIL when a suite-shaped file exists on disk and is neither enumerated on +# the UNION of both surfaces nor listed in the exclusions file. +# ("Enumerated", deliberately — F1/F2 on PR #1018 proved this guard sees +# NAMING, not reachability, and its words must not claim otherwise.) +# FAIL when either surface names a path that does not exist on disk +# (a rename manufactures a stale entry silently — checked BOTH directions). +# FAIL when an exclusion entry has no reason, names a path that is gone, +# names a path that is also enumerated (contradiction), or names a path +# outside the population (dead weight that looks like coverage). +# +# POPULATION PATTERN — a deliberate decision, stated per #1017's record: +# basename matches *test*.sh (contains "test", ends ".sh"). Deliberately BROAD: +# the strict `test-*.sh` prefix cannot even name three real boundary files +# (tmux/agent-send.test.sh — CI-run; orchestrator/smoke-test.sh; +# wake/validate-973/microtest-wake-assert.sh), and three independent censuses +# handled that last file three different ways with no trace of the judgement. +# The broad pattern makes such files MEMBERS, so their disposition must be a +# signed exclusion, not an accident of the glob. The SAME pattern is applied to +# both sides of the comparison (disk and enumeration) — a comparison globbed two +# ways runs on two different populations. Scripts outside the pattern on both +# sides symmetrically (e.g. check-resident-budget.sh, verify-sanitized.sh) are +# check-scripts, not suites; their existence is still verified via the +# both-directions rule because every surface-named path must exist on disk. +# +# The surfaces are PARSED, never line-ranged: three seats independently +# mis-scoped hand-written line ranges against these files (#1017 thread). S1 is +# read via JSON + command-chain tokenization; S2 by extracting every +# packages/mosaic/framework/tools/ token wherever it appears in the file. +# +# Exclusions file format (framework/tools/quality/test-enumeration-exclusions.txt): +# | +# Lines starting with # and blank lines are ignored. An exclusion is a recorded +# decision someone signed, not an omission nobody made. + +set -uo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +ROOT="$(cd "$SCRIPT_DIR/../../../../../.." && pwd)" +while (( $# )); do + case "$1" in + --root) ROOT="$(cd "$2" && pwd)"; shift 2 ;; + *) echo "usage: check-test-enumeration.sh [--root ]" >&2; exit 2 ;; + esac +done + +PKG_JSON="$ROOT/packages/mosaic/package.json" +CI_YML="$ROOT/.woodpecker/ci.yml" +TOOLS_DIR="$ROOT/packages/mosaic/framework/tools" +EXCLUSIONS="$TOOLS_DIR/quality/test-enumeration-exclusions.txt" + +for f in "$PKG_JSON" "$CI_YML"; do + [[ -f "$f" ]] || { echo "FAIL: required surface file missing: $f" >&2; exit 2; } +done +[[ -d "$TOOLS_DIR" ]] || { echo "FAIL: tools dir missing: $TOOLS_DIR" >&2; exit 2; } + +fail_count=0 +fail() { printf 'FAIL %s\n' "$1"; fail_count=$(( fail_count + 1 )); } + +# in_population — the single pattern, used for BOTH sides. +in_population() { + local base; base="$(basename "$1")" + [[ "$base" == *test*.sh ]] +} + +# --- Surface 1: package.json test:framework-shell, parsed, repo-relative ----- +# Tokens are script paths iff they contain "/" and end .sh/.py; interpreter +# names and flags are skipped. Paths are relative to packages/mosaic/. +mapfile -t S1 < <(python3 - "$PKG_JSON" <<'PY' +import json, shlex, sys +cmd = json.load(open(sys.argv[1]))["scripts"].get("test:framework-shell", "") +seen = [] +for seg in cmd.split("&&"): + for tok in shlex.split(seg): + if "/" in tok and (tok.endswith(".sh") or tok.endswith(".py")): + path = "packages/mosaic/" + tok + if path not in seen: + seen.append(path) +print("\n".join(seen)) +PY +) + +# --- Surface 2: ci.yml, every framework/tools token wherever it appears ------ +# Comment lines (first non-whitespace char is #) are skipped BEFORE matching: +# commenting an invocation out is the most common way a suite actually gets +# disabled, and a raw-text regex would keep calling it enumerated (F1, 20155 on +# PR #1018 — demonstrated, not argued). Known residual limit: a path named only +# in a TRAILING comment on a live line still matches; no such line exists today +# and full fidelity would need a YAML parser the CI image does not ship. +mapfile -t S2 < <(grep -vE '^[[:space:]]*#' "$CI_YML" \ + | grep -oE 'packages/mosaic/framework/tools/[A-Za-z0-9_./-]+\.(sh|py)' | sort -u) + +# --- Union, and its population-restricted view ------------------------------- +declare -A ENUM=() ENUM_POP=() +for p in "${S1[@]:-}" "${S2[@]:-}"; do + [[ -n "$p" ]] || continue + ENUM["$p"]=1 + in_population "$p" && ENUM_POP["$p"]=1 +done + +# --- Direction B: every surface-named path must exist on disk ---------------- +for p in "${!ENUM[@]}"; do + [[ -f "$ROOT/$p" ]] || fail "STALE ENUMERATION: surfaces name '$p' but it does not exist on disk" +done + +# --- Exclusions: parsed with the same rigor the enumeration gets ------------- +declare -A EXCLUDED=() +if [[ -f "$EXCLUSIONS" ]]; then + lineno=0 + while IFS= read -r line; do + lineno=$(( lineno + 1 )) + [[ "$line" =~ ^[[:space:]]*(#|$) ]] && continue + path="${line%%|*}"; reason="${line#*|}" + path="$(echo "$path" | sed 's/^[[:space:]]*//; s/[[:space:]]*$//')" + reason="$(echo "$reason" | sed 's/^[[:space:]]*//; s/[[:space:]]*$//')" + if [[ "$line" != *"|"* || -z "$reason" ]]; then + fail "EXCLUSION MISSING REASON: line $lineno ('$path') — an exclusion is a recorded decision someone signed" + continue + fi + if [[ ! -f "$ROOT/$path" ]]; then + fail "STALE EXCLUSION: line $lineno excludes '$path' which does not exist on disk" + continue + fi + if ! in_population "$path"; then + fail "EXCLUSION OUTSIDE POPULATION: line $lineno excludes '$path' which the population pattern does not name — dead weight that reads as coverage" + continue + fi + if [[ -n "${ENUM[$path]:-}" ]]; then + fail "CONTRADICTORY EXCLUSION: line $lineno excludes '$path' which the surfaces already enumerate" + continue + fi + EXCLUDED["$path"]=1 + done < "$EXCLUSIONS" +fi + +# --- Direction A: disk population must be enumerated or signed-excluded ------ +disk_total=0 +unlisted=0 +while IFS= read -r f; do + rel="${f#"$ROOT"/}" + in_population "$rel" || continue + disk_total=$(( disk_total + 1 )) + if [[ -z "${ENUM_POP[$rel]:-}" && -z "${EXCLUDED[$rel]:-}" ]]; then + fail "UNENUMERATED: '$rel' exists on disk but is neither enumerated on any CI surface nor signed in the exclusions file" + unlisted=$(( unlisted + 1 )) + fi +done < <(find "$TOOLS_DIR" -type f -name '*.sh' | sort) + +if (( fail_count > 0 )); then + printf 'enumeration guard: %d failure(s) — population %d, enumerated (in-population) %d, excluded %d\n' \ + "$fail_count" "$disk_total" "${#ENUM_POP[@]}" "${#EXCLUDED[@]}" + exit 1 +fi +printf 'enumeration guard: OK — population %d, enumerated (in-population) %d, excluded (signed) %d, surfaces name %d path(s), all present on disk\n' \ + "$disk_total" "${#ENUM_POP[@]}" "${#EXCLUDED[@]}" "${#ENUM[@]}" diff --git a/packages/mosaic/framework/tools/quality/scripts/test-check-test-enumeration.sh b/packages/mosaic/framework/tools/quality/scripts/test-check-test-enumeration.sh new file mode 100755 index 00000000..05170632 --- /dev/null +++ b/packages/mosaic/framework/tools/quality/scripts/test-check-test-enumeration.sh @@ -0,0 +1,166 @@ +#!/usr/bin/env bash +# test-check-test-enumeration.sh — needles for the enumeration guard (#1017). +# +# Every failure mode the guard promises gets BOTH polarities: +# NEEDLE a fixture that MUST trip the guard, asserted on the guard's OWN +# words (--out) — exit 1 alone cannot distinguish "caught the rogue +# file" from "choked on the fixture". +# CONTROL a fixture that MUST pass. A guard that failed unconditionally +# would satisfy every needle here — the null-case defect the guard's +# own subject matter (#1017) exists to make impossible. +# +# The needles encode the specific errors that produced #1017's thread: +# n6 is the 20124 boundary file (a suite the strict prefix cannot name); +# n2b proves surface 2 is PARSED, not line-ranged (three seats mis-scoped +# hand-written ranges against ci.yml); +# n5/n7 keep the exclusions file honest so it cannot become the next silent cap; +# n8/c4 are F1 (20155): a commented-out ci.yml line is NOT enumeration — +# commenting-out is the most common way a suite actually gets disabled, +# and it must fail loud in one direction without false-staling the other. + +set -uo pipefail + +HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +GUARD="$HERE/check-test-enumeration.sh" +TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT +PASS=0; FAIL=0 + +# fixture — a minimal repo root the guard accepts via --root: +# one suite enumerated on S1 (plus a naming-outlier suite, so the S1 parser's +# handling of non-prefix names is always exercised), one on S2, one check-script +# named on S2 that is outside the population, and an empty exclusions file. +fixture() { + local r="$TMP/$1" + mkdir -p "$r/packages/mosaic/framework/tools/git" \ + "$r/packages/mosaic/framework/tools/tmux" \ + "$r/packages/mosaic/framework/tools/quality/scripts" \ + "$r/.woodpecker" + printf '#!/usr/bin/env bash\nexit 0\n' > "$r/packages/mosaic/framework/tools/git/test-a.sh" + printf '#!/usr/bin/env bash\nexit 0\n' > "$r/packages/mosaic/framework/tools/tmux/outlier.test.sh" + printf '#!/usr/bin/env bash\nexit 0\n' > "$r/packages/mosaic/framework/tools/quality/scripts/test-ci.sh" + printf '#!/usr/bin/env bash\nexit 0\n' > "$r/packages/mosaic/framework/tools/quality/scripts/verify-thing.sh" + cat > "$r/packages/mosaic/package.json" <<'JSON' +{"scripts": {"test:framework-shell": "bash framework/tools/git/test-a.sh && bash framework/tools/tmux/outlier.test.sh"}} +JSON + cat > "$r/.woodpecker/ci.yml" <<'YML' +steps: + sanitize: + commands: + - bash packages/mosaic/framework/tools/quality/scripts/verify-thing.sh + guard: + commands: + - bash packages/mosaic/framework/tools/quality/scripts/test-ci.sh +YML + : > "$r/packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt" + printf '%s' "$r" +} + +# expect [--out ] -- +expect() { + local kind="$1" want="$2" desc="$3"; shift 3 + local need_out="" + while (( $# )); do + case "$1" in + --out) need_out="$2"; shift 2 ;; + --) shift; break ;; + esac + done + local root="$1" got=0 out + out="$(bash "$GUARD" --root "$root" 2>&1)" || got=$? + local why="" + [[ "$got" == "$want" ]] || why="wanted exit $want, got $got" + if [[ -z "$why" && -n "$need_out" && "$out" != *"$need_out"* ]]; then + why="exit $got as expected, but output never said: $need_out" + fi + if [[ -z "$why" ]]; then + printf ' PASS [%-7s] %s (exit %s)\n' "$kind" "$desc" "$got" + PASS=$(( PASS + 1 )) + else + printf ' FAIL [%-7s] %s — %s\n' "$kind" "$desc" "$why" + printf '%s\n' "$out" | sed 's/^/ | /' + FAIL=$(( FAIL + 1 )) + fi +} + +excl() { printf '%s\n' "$2" >> "$1/packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt"; } + +echo "=== c1: a fully consistent fixture passes ===" +R="$(fixture c1)" +expect CONTROL 0 "consistent tree: both surfaces enumerated, nothing unlisted" \ + --out "enumeration guard: OK" -- "$R" + +echo "=== n1: an on-disk suite reachable from no surface must fail ===" +R="$(fixture n1)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/test-rogue.sh" +expect NEEDLE 1 "unlisted suite is named in the failure" \ + --out "UNENUMERATED: 'packages/mosaic/framework/tools/git/test-rogue.sh'" -- "$R" + +echo "=== n6: the 20124 boundary file — a suite the strict prefix cannot name ===" +R="$(fixture n6)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/rogue.test.sh" +expect NEEDLE 1 "naming-outlier suite (*.test.sh) is a population member, not invisible" \ + --out "UNENUMERATED: 'packages/mosaic/framework/tools/git/rogue.test.sh'" -- "$R" + +echo "=== c3: a non-suite script outside the pattern is outside it on BOTH sides ===" +R="$(fixture c3)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/check-unrelated.sh" +expect CONTROL 0 "check-script on disk, unlisted, outside population: not the guard's business" \ + --out "enumeration guard: OK" -- "$R" + +echo "=== n2/n2b: a surface naming a path absent from disk must fail — both surfaces ===" +R="$(fixture n2)" +rm "$R/packages/mosaic/framework/tools/git/test-a.sh" +expect NEEDLE 1 "S1 (package.json) stale entry" \ + --out "STALE ENUMERATION: surfaces name 'packages/mosaic/framework/tools/git/test-a.sh'" -- "$R" +R="$(fixture n2b)" +rm "$R/packages/mosaic/framework/tools/quality/scripts/test-ci.sh" +expect NEEDLE 1 "S2 (ci.yml) stale entry — proves ci.yml is parsed, not line-ranged" \ + --out "STALE ENUMERATION: surfaces name 'packages/mosaic/framework/tools/quality/scripts/test-ci.sh'" -- "$R" + +echo "=== c2: a rogue suite with a SIGNED exclusion passes, and is counted ===" +R="$(fixture c2)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/test-rogue.sh" +excl "$R" "packages/mosaic/framework/tools/git/test-rogue.sh | non-hermetic pending fixture work (needle-suite specimen)" +expect CONTROL 0 "signed exclusion is honoured and visible in the summary" \ + --out "excluded (signed) 1" -- "$R" + +echo "=== n3: an exclusion with no reason is not a decision ===" +R="$(fixture n3)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/test-rogue.sh" +excl "$R" "packages/mosaic/framework/tools/git/test-rogue.sh | " +expect NEEDLE 1 "empty reason rejected" --out "EXCLUSION MISSING REASON" -- "$R" +R="$(fixture n3b)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/test-rogue.sh" +excl "$R" "packages/mosaic/framework/tools/git/test-rogue.sh" +expect NEEDLE 1 "missing separator rejected (the path alone is not a signature)" \ + --out "EXCLUSION MISSING REASON" -- "$R" + +echo "=== n4: an exclusion whose path is gone is stale, not satisfied ===" +R="$(fixture n4)" +excl "$R" "packages/mosaic/framework/tools/git/test-vanished.sh | was excluded once, then deleted" +expect NEEDLE 1 "stale exclusion rejected" --out "STALE EXCLUSION" -- "$R" + +echo "=== n5: excluding an enumerated suite is a contradiction, not belt-and-braces ===" +R="$(fixture n5)" +excl "$R" "packages/mosaic/framework/tools/git/test-a.sh | already in CI but excluded anyway" +expect NEEDLE 1 "contradictory exclusion rejected" --out "CONTRADICTORY EXCLUSION" -- "$R" + +echo "=== n8/c4: a commented-out ci.yml line is not enumeration (F1, 20155) ===" +R="$(fixture n8)" +printf '#!/usr/bin/env bash\nexit 0\n' > "$R/packages/mosaic/framework/tools/git/test-disabled.sh" +printf ' # - bash packages/mosaic/framework/tools/git/test-disabled.sh\n' >> "$R/.woodpecker/ci.yml" +expect NEEDLE 1 "suite named only in a commented-out invocation is UNENUMERATED" \ + --out "UNENUMERATED: 'packages/mosaic/framework/tools/git/test-disabled.sh'" -- "$R" +R="$(fixture c4)" +printf ' # - bash packages/mosaic/framework/tools/git/test-vanished.sh\n' >> "$R/.woodpecker/ci.yml" +expect CONTROL 0 "comment naming an absent path raises no false stale-enumeration" \ + --out "enumeration guard: OK" -- "$R" + +echo "=== n7: excluding a file outside the population is dead weight, not coverage ===" +R="$(fixture n7)" +excl "$R" "packages/mosaic/framework/tools/quality/scripts/verify-thing.sh | not a suite but signing it anyway" +expect NEEDLE 1 "out-of-population exclusion rejected" --out "EXCLUSION OUTSIDE POPULATION" -- "$R" + +echo +printf 'enumeration-guard needles: %d passed, %d failed\n' "$PASS" "$FAIL" +(( FAIL == 0 )) diff --git a/packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt b/packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt new file mode 100644 index 00000000..49186d6f --- /dev/null +++ b/packages/mosaic/framework/tools/quality/test-enumeration-exclusions.txt @@ -0,0 +1,45 @@ +# test-enumeration-exclusions.txt — signed exclusions for check-test-enumeration.sh (#1017). +# +# Every entry is a recorded decision: a suite-shaped file that exists on disk, +# is NOT reachable from any CI surface, and carries the reason someone signed +# for that. The guard FAILS on an entry with no reason, a stale path, or a path +# the surfaces already enumerate. Burning an entry down = making it CI-reachable +# (package.json test:framework-shell or a ci.yml step) and deleting its line. +# +# Format: | +# All entries below were signed at #1017's filing base (main 826a8b3b, 2026-07-31) +# by pepper (sb-it-1-dt); measurements cited are one-run assertions from that seat. + +# --- tools/git: the #1007 five — non-hermetic, resolve real credentials --- +packages/mosaic/framework/tools/git/test-pr-merge-gitea-empty-uid.sh | resolves real credentials (#1007 census); joins CI after the wrapper-half hermeticity fix (git -C scoping) +packages/mosaic/framework/tools/git/test-issue-create-interactive-auth.sh | resolves real credentials (#1007 census); joins CI after the wrapper-half hermeticity fix +packages/mosaic/framework/tools/git/test-gitea-login-resolution.sh | resolves real credentials (#1007 census); joins CI after the wrapper-half hermeticity fix +packages/mosaic/framework/tools/git/test-pr-metadata-gitea.sh | resolves real credentials (#1007 census, fourth entry via family-grep); joins CI after the wrapper-half hermeticity fix +packages/mosaic/framework/tools/git/test-issue-comment-readback.sh | resolves real credentials (#1007 census, fifth entry); joins CI after the wrapper-half hermeticity fix + +# --- tools/git: push guards — measured green locally, CI-image fitness unverified --- +packages/mosaic/framework/tools/git/test-push-guard.sh | measured green at 826a8b3b (46 passed / 0 failed, one run, 2026-07-31); CI-image fitness unverified; #1017 burndown +packages/mosaic/framework/tools/git/test-mutate-push-guard.sh | measured green at 826a8b3b (8/0, 13 mutants killed 0 survived, one run, 2026-07-31); requires setsid (util-linux), absent from the alpine base image; #1017 burndown +packages/mosaic/framework/tools/git/test-issue-create-body-safety.sh | hermeticity unaudited — the unprotected suite in #1007's protected/unprotected split; audit before CI; #1017 burndown + +# --- tools/git: unmeasured --- +packages/mosaic/framework/tools/git/test-verify-clean-clone.sh | unmeasured in CI image; asserts git file-mode (100644/755) semantics that need verification on the CI filesystem first; #1017 burndown +packages/mosaic/framework/tools/git/test-help-exit-code.sh | unmeasured in CI image; stub-based (#701 regression harness), likely CI-fit; #1017 burndown +packages/mosaic/framework/tools/git/test-lane-brief-pr-linkage.sh | unmeasured in CI image; fixture-based (#546/#547 regression harness), likely CI-fit; #1017 burndown + +# --- tools/tmux: require a live tmux server --- +packages/mosaic/framework/tools/tmux/test-send-message-socket.sh | requires a real tmux server on a throwaway socket; CI image ships no tmux; #1017 burndown (needs tmux in image or a signed permanent exclusion) +packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh | requires real tmux-pane fixtures on a throwaway socket; CI image ships no tmux; #1017 burndown (same condition as its sibling) + +# --- single-suite directories: unmeasured in CI --- +packages/mosaic/framework/tools/fleet/test-start-agent-session.sh | unmeasured in CI image; stubs tmux via a fake bin dir, likely CI-fit; #1017 burndown +packages/mosaic/framework/tools/glpi/test-list-http-status.sh | unmeasured in CI image; stub-based (#807 regression harness), likely CI-fit; #1017 burndown +packages/mosaic/framework/tools/orchestrator/test-board-roll.sh | unmeasured in CI image; file-fixture based, likely CI-fit; #1017 burndown +packages/mosaic/framework/tools/woodpecker/test-ci-wait-exit-matrix.sh | unmeasured in CI image; drives ci-wait.sh against a stub pipeline-status.sh, likely CI-fit; #1017 burndown + +# --- naming-boundary files the strict test-*.sh prefix cannot even name --- +# (#1017: three independent censuses handled the microtest file three different +# ways — editorial drop, structural exclusion, accidental inclusion — with no +# recorded judgement. These lines ARE that judgement, signed.) +packages/mosaic/framework/tools/orchestrator/smoke-test.sh | behavior smoke checks for coord continue/run workflows, run manually by orchestrator seats; unmeasured in CI; #1017 burndown +packages/mosaic/framework/tools/wake/validate-973/microtest-wake-assert.sh | #973 instrument self-test, run as a precondition of the validate-973 evidence procedure rather than as a standing CI suite; #1017 burndown candidate diff --git a/packages/mosaic/package.json b/packages/mosaic/package.json index 1a04cd81..56898aa8 100644 --- a/packages/mosaic/package.json +++ b/packages/mosaic/package.json @@ -25,7 +25,7 @@ "lint": "eslint src", "typecheck": "tsc --noEmit", "test": "vitest run --passWithNoTests && pnpm run test:framework-shell", - "test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh" + "test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh" }, "dependencies": { "@mosaicstack/brain": "workspace:*",