Compare commits

..
Author SHA1 Message Date
fargo 8eb8e7cfce Merge remote-tracking branch 'origin/next' into fix/1280-identity-first-resolution
ci/woodpecker/pr/ci Pipeline was successful
# Conflicts:
#	packages/mosaic/package.json
2026-08-17 16:24:43 -05:00
fargo d789a43cae test(git): hermetic fixtures for issue-create harnesses (#1282-#1287)
ci/woodpecker/pr/ci Pipeline was canceled
test-issue-create-body-safety.sh and test-issue-create-interactive-auth.sh
inherited the seat's real HOME and global git config. With the #1280 fix
activating identity mode BEFORE the tea path, a workstation-global
mosaic.gitIdentity resolved inside the fixture repo, and the wrapper's
API fallback posted to the LIVE forge with a real per-slot token — six
real issues (#1282-#1287, authored mos-dt-0, closed with provenance by
fred within the hour).

Neutralize the source the resolver actually reads, and prove it by making
the resolution fail. A control that does not make the thing fail has not
been shown to control it. The earlier attempted neutralization pinned
MOSAIC_CREDENTIALS_FILE to a fake — a real guard aimed at an adjacent
input: the identity arm reads the per-slot token file directly and never
consults credentials.json. Hence env -i with a fake HOME and
GIT_CONFIG_GLOBAL=/dev/null (severing the global identity) rather than
one more targeted variable, plus a curl tripwire stub in the body-safety
harness so ANY provider request is a loud test failure instead of a live
write.
2026-08-17 15:19:04 -05:00
fargo 19ad93999f fix(git): identity-first principal resolution across write wrappers (#1280)
MOSAIC_GIT_IDENTITY=fargo produced objects attributed to mos-dt-0: every
write wrapper resolved its acting principal from tea's login list, which
enumerates whatever logins the host happens to hold and knows nothing
about which seat is calling. The identity-aware code was present and
correct but unreachable on the happy path — it sat on arms that only ran
when tea failed.

One shared resolver, not twenty patches: resolve_gitea_principal() in
detect-platform.sh implements the precedence (explicit --login beats
MOSAIC_GIT_IDENTITY / worktree git config mosaic.gitIdentity; the tea
login list is the LAST resort), fails loud (nonzero, naming the identity
or login and the expected slot path) when the requested principal has no
credential, and never prints a token value. gitea_identity_token_slot()
is the single source of truth for the slot layout, shared with
get_gitea_token, so resolver and token resolution cannot disagree.

Call-site conversions (the proving five): pr-review.sh (principal
resolved once for every action; the comment action now honors --login),
issue-comment.sh, pr-create.sh (identity mode reaches the REST API on the
HAPPY path — tea is never consulted, so the login list cannot shadow the
identity; --login wins even on the tea-failure fallback arm),
issue-create.sh (same), pr-merge.sh (gains --login; --dry-run reports the
principal the merge WOULD act as, resolved exactly as the merge resolves
it; no cross-principal fallback — an identity-bound 401 is a hard stop).

Remaining wrappers are call-site conversions onto the same resolver,
measured: write-path issue-assign, issue-close, issue-edit, issue-reopen,
milestone-close, milestone-create, pr-close; read-path issue-list,
milestone-list, pr-list, pr-view (issue-view mixed). pr-diff, pr-metadata,
pr-ci-wait and ci-queue-wait already inherit identity-first resolution
via get_gitea_token.

Known interaction: on a host with a workstation-GLOBAL mosaic.gitIdentity,
this fix activates identity mode for every seat that has not set a local
one — correct behavior driven by a wrong configuration (measured:
#1282-#1287, six accidental live issues, closed with provenance by fred).
Set mosaic.gitIdentity per-worktree, never --global.

Tests: test-gitea-principal-resolution.sh (resolver matrix — identity
present/absent, --login precedence, env vs git-config, unrecognized-host
containment, slot-path-by-path-never-by-value); test-pr-create-identity-
first.sh (the load-bearing ordering test: identity arm REACHED on the
happy path with tea never invoked, fail-loud BEFORE any write on a
missing slot, --login wins, default preserved); test-pr-merge-principal-
resolution.sh (dry-run truthfulness, merge credential binding, unknown
--login never reaches the provider). All wired into test:framework-shell.

Sabotage control: precedence inverted to tea-list-first inside the
resolver -> exactly the three new suites redden with the #1280
signatures (identity resolves to the tea-list account; missing slot
returns rc=0 with silent fallthrough) while all 11 pre-existing git
suites stay green; restored byte-identical (sha256 verified); all 14
green again.
2026-08-17 15:18:54 -05:00
14 changed files with 1208 additions and 317 deletions
-186
View File
@@ -1,186 +0,0 @@
# Quality-Rails Probe Inventory — RI-3-001
- **Task:** RI-3-001 (SDLC-D-037 first half; PRD § Release Integrity Workstream, RI-N4)
- **Date:** 2026-08-18
- **Base:** `origin/next` @ `8199261c` (branch `docs/ri-050-qr-probe-inventory`)
- **Follow-up:** RI-3-002 consumes the dispositions here when building the single TS evaluator.
## 0. Scope and method
Every mechanism in this repository that verifies a quality, integrity, safety, or release
property — TypeScript checks, shell probes, pipeline steps, git hooks, and installer-side
assertions — gets one row. Each row's "what it actually verifies" was written from the
probe's **code**, not its name or docs. Framework tool unit/regression suites (git wrappers,
wake, tmux, orchestrator, …) are treated as one enforcement surface (`test:framework-shell`)
because they test tool behavior rather than repo quality; their wiring integrity is itself
guarded by `check-test-enumeration.sh`, and the quality-relevant members are rowed
individually.
**Kinds:** `ts` (TypeScript/Node check), `shell` (bash/python probe), `pipeline-step`
(exists only inside a Woodpecker pipeline).
**Enforcement points:** `local` (operator-invoked), `pre-commit`, `pre-push`,
`CI ci.yml#<step>`, `publish.yml#<step>` (CI on push to main/next), `turbo <task>`,
`agent-runtime` (framework hooks on an agent host), `installer` (host install path),
`unwired`.
**Dispositions** (recommendations for RI-3-002): `preserve` (keep as-is; already the
canonical or a correct guard-of-the-guard), `strengthen` (keep, but a concrete gap must
close — usually absorption into the TS evaluator), `strengthen (review)` (viable retirement
candidate once the evaluator absorbs it; do not retire yet). Note: RI-N4 requires that
effective shell probes be **absorbed before** their independent paths retire — no row here
is marked `retire` because no absorption exists yet.
## 1. Inventory
### 1.1 Repo-level gate tasks (pnpm / turbo)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ------------------------------------- | ------------------------------------------------------------------------------------ | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm preflight` (checkout preflight) | `scripts/preflight.mjs` | ts | Six gate binaries (eslint, husky, prettier, tsc, turbo, vitest) exist and are executable in `node_modules/.bin` (exit 42 if not); no stale `.mosaic-test-work/web-build.lock` (exit 43); `apps/web/.next` is a real directory (not a symlink), every entry owned by the current uid, and its `.mosaic-source-hash` fingerprint + `.mosaic-symlink-manifest` hash match the certified build written by `scripts/build-web.mjs` | `pre-push`; inside `pnpm typecheck` (→ `CI ci.yml#typecheck`, verify-release `typecheck` stage) | QC-1 Checkout integrity | preserve | Blocks a poisoned/stale generated `.next` from faking a green typecheck (the five-month-stale-`.next` class); trust chain is self-contained per-checkout. |
| `pnpm typecheck` | root `package.json``turbo run typecheck` | ts | Per-package `tsc --noEmit` (all 20 packages); turbo `typecheck` depends on `^build`, so package builds must succeed first; prefixed by checkout preflight | `CI ci.yml#typecheck`; `pre-push`; verify-release `typecheck` stage; `turbo typecheck` | QC-2 Workspace typecheck | preserve | The single workspace-wide type gate; CI and hooks invoke the same task, no divergent checklist. |
| `pnpm lint` | root `package.json``turbo run lint` | ts | Per-package `eslint src` under root `eslint.config.mjs` (ignores `dist`, `.next`, `framework/**`, etc.) | `CI ci.yml#lint`; `pre-push`; verify-release `lint` stage; `turbo lint` | QC-3 Workspace lint | preserve | Same-task invocation from every surface; no second lint definition. |
| `pnpm format:check` | root `package.json``prettier --check` | ts | Prettier parse/format equality over `**/*.{ts,tsx,js,jsx,json,md}` minus `.prettierignore` (generated trees, `docs/scratchpads/`, venvs, …) | `CI ci.yml#format`; `pre-push`; verify-release `format` stage | QC-4 Format check | preserve | Single formatter, single ignore list, enforced identically everywhere. |
| `pnpm test` | root `package.json` `test` = `test:checkout` && `turbo run test` && `test:installer` | ts | (a) `node --test scripts/*.test.mjs` — checkout-tool units; (b) per-package `vitest run` (mosaic appends the 47-command `test:framework-shell` chain); (c) `tools/install-next-lane.test.sh`; turbo `test` declares DB env vars and depends on `^build` | `CI ci.yml#test` (with `DATABASE_URL` + `db:migrate` first); verify-release `test` stage; `turbo test` | QC-5 Test suite execution | preserve | One composed test command; the chain property (any link red ⇒ step red) is the gate. |
| `pnpm build` | root `package.json``turbo run build` | ts | Per-package build (`tsc`/Next) with `^build` dependency and `dist/**` outputs | `publish.yml#build`; verify-release `build` stage; `turbo build` | QC-6 Workspace build | preserve | Publish artifacts derive from the same build task CI verifies. |
### 1.2 Framework quality shell probes (`packages/mosaic/framework/tools/quality/`)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ------------------------------------------- | ----------------------------------------------------------------------- | ----- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| Sanitization gate | `scripts/verify-sanitized.sh` | shell | Built-in self-test first (planted identity/structural/YAML+service fixtures; exit 2 if the regexes or extension coverage break), then: (1) identity denylist grep (`jarvis\|jason\|woltje\|brain.woltje.com\|/home/jwoltje\|\bPDA\b`) over all shipped text files **including** `examples/`; (2) structural grep for private `$HOME/src` defaults in shipped scripts **excluding** `examples/`. Any hit ⇒ exit 1 | `CI ci.yml#sanitization`; verify-release `sanitization` stage | QC-7 Framework sanitization | preserve | Labeled one-time regression guard with a self-test that prevents silent no-op; correctly scoped (identity vs structural) and documented as not a general PII detector. |
| Resident-context budget | `scripts/check-resident-budget.sh` (+ `--self-test`) | shell | Self-test of the comparator, then `wc -l` vs per-file ceilings (CONSTITUTION 120, AGENTS 120, each RUNTIME.md 90); missing file ⇒ fail; over ceiling ⇒ exit 1 | `CI ci.yml#sanitization` (both modes); verify-release `sanitization` stage | QC-8 Resident-context budget | preserve | Caps the container (lines), never the wording — the deliberate anti-drift design (DESIGN §7); CI-enforceable half only, by design. |
| Test-membership enumeration guard (#1017) | `scripts/check-test-enumeration.sh` + `test-enumeration-exclusions.txt` | shell | Parses surface S1 (`packages/mosaic` `test:framework-shell` via JSON+shlex) and S2 (every `framework/tools/\*.sh | .py`token in`ci.yml`, comment lines stripped); population = `_test_.sh`under`framework/tools`; FAILS on: suite-shaped file on disk neither enumerated nor signed-excluded; surface naming a path missing on disk (both directions); exclusion without reason / stale / outside population / contradicting enumeration. Proves **naming, not reachability** (stated in-file) | `CI ci.yml#sanitization` (direct line); link [0] of `test:framework-shell` (thus `CI ci.yml#test`); verify-release `sanitization` stage | QC-9 Test-membership enumeration | preserve | Makes silent under-run impossible; invoked from both surfaces it audits so severing the chain cannot silence it. |
| Enumeration-guard needles | `scripts/test-check-test-enumeration.sh` | shell | Needle/control fixtures driven through `--root`: every promised failure mode must trip the guard **on its own words**, plus controls that must pass (null-case defense); covers commented-out ci.yml lines (F1) and line-range parsing (n2b) | `test:framework-shell``CI ci.yml#test`; verify-release `test` stage | QC-9 Test-membership enumeration | preserve | Guard-of-the-guard with both polarities; same canonical check by design. |
| Upgrade manifest guard (#791 HARD GATE) | `scripts/test-upgrade-manifest-guard.sh` | shell | Keep-mode `install.sh` upgrade against seeded throwaway `MOSAIC_HOME`: every operator sentinel — including an **unanticipated** one — survives byte-identical with unchanged mtime; framework files still update; retired framework files pruned; matrix run with rsync present AND absent (keep path must be rsync-independent); fail-closed matrix (empty/operator-only/malformed/missing manifest aborts loudly, operator files untouched); operator secret never appears in installer output | `CI ci.yml#upgrade-guard`; verify-release `upgrade-guard` stage | QC-10 Upgrade/install safety | preserve | The operator-data hard gate for the `mosaic update` path; negative controls are load-bearing and documented. |
| Upgrade rollback gate (#791 B1) | `scripts/test-upgrade-rollback.sh` | shell | Mid-sync failure (PATH-shadowing `cp` shim) must trigger snapshot restore: restore message fires, corrupted file restored, target byte-identical to pre-upgrade; control installer with `set -E` stripped must NOT roll back (proves errtrace is load-bearing); plus signal/exit-guard controls | `CI ci.yml#upgrade-guard`; verify-release `upgrade-guard` stage | QC-10 Upgrade/install safety | preserve | Proves the rollback trap actually fires; the `-E`-stripped control keeps Part A honest. |
| Durable-snapshot gate (#791 PR2) | `scripts/test-upgrade-durable-snapshot.sh` | shell | Pre-update snapshot taken before any mutation (0700/0600 perms, secret never logged, retention-pruned); post-sync verify net restores operator files a manifest bug lets the sync touch; CWE-59 symlink-leaf guard proven with a portable cp shim in both polarities (write-through-link must not happen); v1→v2 migration semantics (intended `bin/` removal not healed) | `CI ci.yml#upgrade-guard`; verify-release `upgrade-guard` stage | QC-10 Upgrade/install safety | preserve | Covers tampering and leak vectors the manifest guard cannot see; the shim rationale (busybox vs GNU cp) is documented in-file. |
| Install migration matrix (v2→v3) | `scripts/test-install-migration.sh` | shell | Fixture matrix running the real installer with `MOSAIC_SYNC_ONLY=1`: fresh install seeds + stamps version 3; legacy user-edited AGENTS overwritten with `.pre-constitution.bak` preserved (and idempotent); tuned STANDARDS overwritten; operator files (SOUL, credentials) preserved. Mirrors the TS suite `packages/mosaic/src/config/file-adapter.test.ts` — both installers must behave identically | `CI ci.yml#upgrade-guard`; verify-release `upgrade-guard` stage | QC-10 Upgrade/install safety | preserve | Pins the shell/TS installer parity contract; removal would orphan that parity requirement. |
| Enforcement verification probe (bash) | `scripts/verify.sh` | shell | Attempts **real commits** in the target repo: planted type error must produce a commit blocked with `error`; planted `any` must trip `no-explicit-any`; planted lint error must trip `prettier`; gitleaks binary must exist (3a) and detect a planted AWS key via `gitleaks git --pre-commit --staged --redact` (3b). Verdicts are output-grep matches on hook stderr | `local` via installed `mosaic-quality-verify` on scaffolded target projects; **not run in this repo's CI** | QC-20 Downstream enforcement verification | strengthen (review) | Mechanism is genuinely behavioral (stronger than file presence) but verdict logic is grep-on-output and it is unwired here; absorb as the evaluator's enforcement-probe check (the RI-N4 evaluator invokes it or reimplements it) before retiring the shell path. |
| Enforcement verification probe (PowerShell) | `scripts/verify.ps1` | shell | Windows port of `verify.sh`: same planted-commit tests with `$output -match` matching; no gitleaks self-test parity beyond the same checks | `local` (Windows operator); no Windows CI runner exists | QC-20 Downstream enforcement verification | strengthen (review) | A hand-maintained twin of `verify.sh` with no CI coverage — exactly the drift shape the single evaluator removes; retire after the TS evaluator owns the probe. |
| Quality template installer (bash) | `scripts/install.sh` | shell | Copies template files (`.husky/pre-commit` incl. mandatory gitleaks, `.lintstagedrc.js`, `.eslintrc.js`, `tsconfig.json`, `.woodpecker.yml`, `.gitleaks.toml`) into a target project; **warns** (does not verify) about `package.json` snippet merge; no post-condition check | `local` / via `mosaic-quality-apply` | QC-21 Downstream rails scaffolding | strengthen (review) | Duplicates the TS `quality-rails init` scaffolder for a different template set; converging on one scaffolder (with post-scaffold verification) is prerequisite to retiring this path. |
| Quality template installer (PowerShell) | `scripts/install.ps1` | shell | Windows twin of the template copy above | `local` (Windows operator) | QC-21 Downstream rails scaffolding | strengthen (review) | Same twin-drift risk as `verify.ps1`; no runner exercises it. |
| `mosaic-quality-verify` adapter | `framework/tools/_scripts/mosaic-quality-verify` | shell | Thin adapter: validates target dir exists, asserts `verify.sh` present+executable, `cd` target, exec it. No verdict logic of its own | `local` (installed framework bin) | QC-20 Downstream enforcement verification | preserve | Already the thin-adapter shape RI-N4 prescribes for shell surfaces. |
| `mosaic-quality-apply` adapter | `framework/tools/_scripts/mosaic-quality-apply` | shell | Thin adapter: arg validation then exec of quality `install.sh --template … --target …` | `local` (installed framework bin) | QC-21 Downstream rails scaffolding | preserve | Thin adapter, no separate verdict; disposition follows its target script's convergence. |
| Roster schema regression | `scripts/test-roster-schema.py` | shell | jsonschema `Draft202012Validator` over `fleet/roster.schema.json` with valid/invalid connector-kind fixtures (tmux/discord/matrix conditional fields) | **unwired** — not on S1 or S2, not signed-excluded; also outside the enumeration guard's `*.sh` population, so the guard cannot see it | QC-5 Test suite execution | strengthen (review) | A real regression suite that currently runs nowhere; wire it into a CI surface or sign an exclusion — leaving it invisible re-arms the exact gap #1017 closed. |
| Framework shell chain (S1) | `packages/mosaic/package.json` `test:framework-shell` | shell | 47-command `&&` chain: enumeration guard + needles, 14 lease-broker/mutator-gate python unitests, `check-runtime-launches.py`, and ~30 framework-tool shell suites (git wrappers, wake, woodpecker, tmux, glpi, orchestrator, `_scripts`). Quality-relevant members rowed separately below | `turbo test``CI ci.yml#test`; verify-release `test` stage | QC-5 Test suite execution | preserve | The chain is the execution surface the enumeration guard audits; known residuals: a failing link stops later suites (measured in #1270 — suites after position 44 had not run), and the guard proves naming, not reachability. |
### 1.3 Framework runtime hooks and their harnesses (agent-host enforcement)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ------------------------------------- | ----------------------------------------------------------------------------------------- | ----- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------- | --------------------------------------- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| QA edit hook seam | `framework/tools/qa/qa-hook-stdin.sh` (+ `qa-hook-handler.sh`) | shell | PostToolUse stdin hook: extracts edited file from the tool JSON (jq or grep fallback), skips non-JS/TS, then the deps-preflight gate — exits 1 with the legible sentinel `deps not installed — run pnpm install` when `node_modules/.bin` is missing/empty (the #856 false-red class); the downstream handler only files QA remediation **report templates** (no verification logic) | `agent-runtime` (framework `runtime/claude/settings.json` PostToolUse); never CI | QC-16 Agent-runtime edit-time checks | strengthen (review) | The sentinel gate is real enforcement; the handler's report-filing adds no verdict and its name promises more than the code does — evaluator absorption should keep the sentinel, drop the report theater. |
| Typecheck-on-edit hook | `framework/tools/qa/typecheck-hook.sh` | shell | PostToolUse: for edited `.ts/.tsx`, finds nearest `tsconfig.json` and runs `tsc --noEmit`, surfacing errors nonzero to the agent immediately | `agent-runtime` (framework `runtime/claude/settings.json` PostToolUse) | QC-16 Agent-runtime edit-time checks | strengthen (review) | Edit-time duplicate of QC-2 with independent invocation logic; keep behavior, converge invocation through the evaluator adapter. |
| Deps-preflight harness | `framework/tools/qa/test-deps-preflight.sh` | shell | Five assertions against the seam incl. a documented RED control (raw `not found`), sentinel behavior for missing and empty `.bin`, and no-false-positive once populated | `test:framework-shell``CI ci.yml#test` | QC-16 Agent-runtime edit-time checks | preserve | Guard-of-the-check with a red control; keeps the sentinel from regressing. |
| Prompt-helper RCE regression | `framework/tools/_scripts/test-mosaic-init-rce.sh` | shell | Sources the prompt helpers and proves a literal `$(touch /tmp/pwned)` answer round-trips verbatim and never executes (no `/tmp/pwned` created) | `test:framework-shell``CI ci.yml#test` | QC-5 Test suite execution | preserve | Cheap, load-bearing security regression on the installer's input path. |
| Install-ordering harness (#869 C2) | `framework/tools/_scripts/test-install-ordering-guard.sh` | shell | Drives `mosaic-link-runtime-assets` with a fake `mosaic` on PATH: probe ok ⇒ settings copied + exit 0; probe fail ⇒ exit 1 with degraded outcome but all other runtime files still copied; `--allow-inactive-enforcement` forwarded; no-mosaic-on-PATH ⇒ python3 fallback strips enforcement hooks and exits 1; fallback + flag ⇒ wires as-is, exit 0 | `test:framework-shell``CI ci.yml#test` | QC-17 Lease-enforcement wiring safety | preserve | Exercises the shell wiring seam independently of the TS guard's own spec suite (complementary coverage, by design). |
| Fleet-transport harness (#1240) | `framework/tools/_scripts/test-fleet-transport-check.sh` | shell | Extracts the shipped `check_fleet_transport`/`fleet_declared_transport` functions **from the shipped scripts** (fails loud if extraction yields nothing) and drives both implementations (mosaic-doctor + `tools/install.sh`) from one case table | `test:framework-shell``CI ci.yml#test` | QC-18 Operator-host drift audit | preserve | The anti-drift harness for the one rule shipped twice; extraction-from-source keeps it from testing a stale copy. |
| Terminal-green contract (RM-61/#1000) | `framework/tools/woodpecker/test-terminal-green-contract.sh` + `verify-terminal-green.py` | shell | Red-first fixtures: pipeline JSON variants (service failure, step failure, cancelled, etc.) must produce the correct terminal-green verdict; controls must pass | `test:framework-shell``CI ci.yml#test` | QC-5 Test suite execution | preserve | Keeps the CI-wait wrapper's green-detection honest; a false green here would poison every merge gate that trusts `pr-ci-wait.sh`. |
| Lease-gate launch invariant | `framework/tools/lease-broker/check-runtime-launches.py` | shell | Scans production roots (`packages/`, `apps/`, `plugins/`, `tools/`) across sh/py/ts/yaml suffixes for Claude/Pi process launches **outside** the lease gate; allowlist-based; fails CI on violation | `test:framework-shell``CI ci.yml#test` | QC-15 Lease-gate architecture invariant | preserve | The only architectural "no ungated launches" rail; grep+allowlist is the right cost/benefit for this invariant. |
### 1.4 TypeScript quality logic (`@mosaicstack/quality-rails` + mosaic CLI)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ---------------------------------------- | ---------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `quality-rails check` | `packages/quality-rails/src/cli.ts` (`mosaic quality-rails check --project`) | ts | **Expected-file presence only**: loops `expectedFilesForKind` (node: `.eslintrc`, `biome.json`, `.githooks/pre-commit`, `PR-CHECKLIST.md`; python: `pyproject.toml`+hooks+checklist; rust: `rustfmt.toml`+…) and exits 1 listing missing paths. Does not execute any linter, formatter, hook, or scanner | `local` (operator CLI); **no CI wiring in this repo** | QC-19 Downstream rails presence check | strengthen | This is the RI-N4 evaluator seed. Today presence ≠ parity (explicitly called out by RI-N4): it must grow typed verdicts (`passed/failed/blocked/error/not-applicable`), check versioning/subject/reason, digested definitions, and absorb the effective shell probes (QC-20 first). |
| `quality-rails doctor` | `packages/quality-rails/src/cli.ts` | ts | Same presence data as `check`, printed with ok/missing lines; **cannot fail** (no nonzero exit on missing files) | `local` (operator CLI) | QC-19 Downstream rails presence check | strengthen | A doctor that cannot fail is advisory; fold into `check` (or return typed states) when the evaluator lands. |
| `quality-rails init` | `packages/quality-rails/src/cli.ts` + `scaffolder.ts`/`templates.ts` | ts | Scaffolds rails files per detected kind/profile (linters/formatters lists are advisory strings; hooks flag always true); writes files, prints follow-ups — no post-condition verification | `local` (operator CLI) | QC-21 Downstream rails scaffolding | strengthen (review) | Second scaffolding path alongside quality `install.sh` (§1.2); converge on one with post-scaffold verification before retiring either. |
| Lease activation probe (#869 C1, hidden) | `packages/mosaic/src/commands/lease-activation-probe.ts` | ts | Real capability probe, not file presence: resolves the installed mosaic CLI and requires it to advertise the exact `{name, version}` activation contract; all deps injectable; registered as hidden CLI command and consumed by C2/C5 | `local` (hidden CLI + consumed by C2/C5); spec-tested via `lease-activation-probe.spec.ts` in `turbo test` | QC-17 Lease-enforcement wiring safety | preserve | The versioned-contract probe is precisely the fail-closed capability check RI-N2 generalizes; already typed and injectable. |
| Install-ordering guard (#869 C2, hidden) | `packages/mosaic/src/commands/install-ordering-guard.ts` | ts | Decides whether enforcement hook entries are written into the `~/.claude/settings.json` the framework reseed ships: not activatable ⇒ strip hooks + nonzero loud outcome (default); explicit per-invocation `--allow-inactive-enforcement` opt-out wires-with-warning. Never touches the runtime gate's own fail-closed behavior | `installer` (framework reseed via `mosaic-link-runtime-assets`); spec + shell harness coverage in `turbo test` | QC-17 Lease-enforcement wiring safety | preserve | Correct default-deny with an explicit, non-env opt-out; test-locked from both the TS and shell sides. |
| Lease doctor check (#869 C5) | `packages/mosaic/src/commands/lease-doctor-check.ts` | ts | Combines hook-wiring detection in `~/.claude/settings.json` with C1 activatable and C3 broker-supervisor health: wired ∧ (¬activatable ¬healthy) ⇒ loud `[ERROR]` that forces `mosaic doctor` exit 1 regardless of the bash audit's own exit | `local` (inside `mosaic doctor`); spec coverage in `turbo test` | QC-17 Lease-enforcement wiring safety | preserve | Closes the "bricked host looks green" hole; cannot be masked by the bash script — that composition is the point. |
| `mosaic doctor` (framework drift audit) | `packages/mosaic/src/commands/launch.ts` (`doctor`) + `framework/tools/_scripts/mosaic-doctor` | shell+ts | Bash audit of the installed framework home: ~40 expected files/dirs present; runtime files are copies (not symlinks) matching source (`cmp`) or composed runtime-contract markers; hard-gates block present in AGENTS.md; sequential-thinking MCP configured; fleet transport binary present per roster (warn); legacy symlink trees gone; skills synced — **warn-based, exit 1 only with `--fail-on-warn`**, plus C5's forced error | `local` (operator audit) | QC-18 Operator-host drift audit | preserve | Host-state audit CI cannot see (user files by design, DESIGN §7); advisory exit is the documented contract — do not silently change it. |
| `mosaic gateway doctor` | `packages/mosaic/src/commands/gateway-doctor.ts` | ts | Probes per-service health (PostgreSQL, Valkey, pgvector) via `@mosaicstack/storage`, reports tier and JSON; exit 1 only when at least one **required** service fails (yellow stays 0) | `local` (operator) | QC-18 Operator-host drift audit | preserve | Service health with correct red/yellow exit semantics; JSON mode exists for scripting. |
| `mosaic gateway verify` | `packages/mosaic/src/commands/gateway/verify.ts` | ts | Post-install liveness: daemon meta via HTTP with retries, admin token on file, bootstrap endpoint reachable; aggregated pass/fail | `local`; consumed by `tools/e2e-install-test.sh` | QC-18 Operator-host drift audit | preserve | The first-run proof the installer E2E relies on; retry-aware so startup races don't false-red. |
| `mosaic fleet doctor` | `packages/mosaic/src/commands/fleet-reconciler-command.ts` | ts | Classifies local roster-owned drift (no mutation) from the parsed v2 roster | `local` (operator) | QC-18 Operator-host drift audit | preserve | Dry-run classification is the correct non-mutating audit shape. |
### 1.5 Git hooks (developer machine)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ------------------------- | --------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- | --------------------------- | ----------- | ----------------------------------------------------------------------------------------------------------------- |
| Pre-commit staged hygiene | `.husky/pre-commit``npx lint-staged` (`.lintstagedrc`) | shell | On staged files only: `prettier --write` + `eslint --fix` for ts/tsx/js/jsx; `prettier --write` for json/md/yaml/yml. **Mutating** (fixes and re-stages); commit blocks only if a fixer itself fails | `pre-commit` (every local commit; hooks activated by `install-hooks.mjs` via `core.hooksPath .husky/_`) | QC-13 Staged-change hygiene | preserve | Correct scoped fast gate; note it auto-fixes rather than rejects (deliberate). Gap: no secret scan here — see §3. |
| Pre-push gate | `.husky/pre-push` | shell | `pnpm preflight && pnpm typecheck && pnpm lint && pnpm format:check` (no test run — documented in AGENTS.md) | `pre-push` | QC-14 Pre-push gate | preserve | Composes QC-1..4 exactly as specified in AGENTS.md; tests intentionally left to CI. |
| Hook installer | `scripts/install-hooks.mjs` (`pnpm prepare`) | ts | Stages husky hooks into a scratch repo first, asserts husky produced its `h` shim, quarantines incomplete previous sets, verifies idempotence via full directory snapshot comparison, then sets `core.hooksPath`; skips cleanly with `HUSKY=0` or no git | `installer` (runs on `pnpm install`) | QC-13 Staged-change hygiene | preserve | Self-verifying wiring for the hook gates — a corrupted half-install cannot silently disable them. |
### 1.6 CI pipeline steps (`.woodpecker/`)
Step-to-probe mapping for container steps: `ci.yml#sanitization` = QC-7+QC-8+QC-9 (rows §1.2, plus `apk add bash` env prep); `ci.yml#upgrade-guard` = QC-10 (rows §1.2, plus `apk add rsync`); `ci.yml#typecheck`/`#lint`/`#format`/`#test` = QC-2/3/4/5 (rows §1.1). Rows below are mechanisms that exist only in a pipeline.
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| -------------------------------------- | -------------------------------------------------------------------------------------- | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------- | ----------------------------------- | --------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------- |
| Frozen install | `ci.yml#install` | pipeline-step | `pnpm install --frozen-lockfile --prefer-offline` against the baked ci-base store — lockfile supply integrity; a drifted lockfile fails the build before any gate runs | `CI ci.yml#install` | QC-1 Checkout integrity | preserve | Lockfile-pinned dep resolution is the supply-chain floor under every later gate. |
| Test-step readiness prelude | `ci.yml#test` prologue | pipeline-step | Installs pinned `@earendil-works/[email protected]` (Invariant R suite requires the real binary) + openssl; waits up to 60×1s on `pg_isready` for the `ci-postgres` service and fails fast if it never comes up; runs `db:migrate` before tests | `CI ci.yml#test` | QC-5 Test suite execution | preserve | Fail-fast environment preconditions — a missing service produces a legible failure, not a wall of red tests. |
| Publish verify step (pending RI-1-001) | `publish.yml#verify` (branch `feat/ri-050-publish-gate` @ `46784c8d`, not yet on next) | pipeline-step | (a) Commit identity: fails closed if `CI_COMMIT_SHA` empty, `git rev-parse HEAD` empty, or the two differ; (b) runs the canonical `pnpm verify:release`. **Every publish effect depends on this step; it carries no path filter** | `publish.yml#verify` | QC-11 Terminal release verification | preserve | The RI-N1 exact-commit binding; until it merges, publish steps on next depend on `build` only (see §3 gap 1). |
| Publish error classification | `publish.yml#publish-npm` | pipeline-step | Publishes `@mosaicstack/*` (minus web) and classifies outcome: success, or the **only tolerated failure** = already-published (EPUBLISHCONFLICT / "cannot publish over" / "previously published"); explicit fatal on npm `E404/E401/ENEEDAUTH/ECONNREFUSED/ETIMEDOUT/ENOTFOUND` and on any unrecognized failure (replacing the old ` | | echo` that hid a registry 404) | `publish.yml#publish-npm` (main/tags, path-filtered on `packages/**`) | QC-12 Publish-effect integrity | preserve | Converts silent publish fall-on-floor into loud failure; allowlist-of-one error tolerance is the right shape. |
| Next-lane publish assertions | `publish.yml#publish-next-npm` | pipeline-step | Guards: branch must be `next`, `CI_PIPELINE_NUMBER` required; registry dist-tags JSON must be usable; walks all manifests, strictly parses stable semver, rewrites `X.Y.(Z+1)-next.<N>`; publishes with `--tag next` (never latest); post-publish asserts `npm view @mosaicstack/mosaic@next` resolves to the exact expected version | `publish.yml#publish-next-npm` (push/manual on next) | QC-12 Publish-effect integrity | preserve | Durable prerelease lane with end-to-end resolution proof — the published artifact is verified, not assumed. |
| Image destination policy | `publish.yml#build-gateway` / `#build-appservice` / `#build-web` | pipeline-step | Kaniko builds with destination policy: `next` ⇒ sha-tag only (fatal if a tag event sneaks in); `main` ⇒ sha + `latest`; tag events ⇒ sha + `<tag>`; anything else fatal. Path filters only skip **effects**, never the verify step | `publish.yml#build-*` | QC-12 Publish-effect integrity | preserve | Fail-closed tagging matrix; the exclude-list default-safe design keeps stale images impossible. |
Adjacent pipeline surface (not a probe): `.woodpecker/ci-image.yml` rebuilds the ci-base image on `pnpm-lock.yaml`/`Dockerfile.ci` change with an immutable `lock-<hash>` tag; pipelines consume `:latest`. Recorded for completeness — no code-quality property is checked.
### 1.7 Root installer tooling (`tools/`)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| --------------------------- | --------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------- | ------------------------------- | ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Next-lane installer test | `tools/install-next-lane.test.sh` (`pnpm test:installer`) | shell | Drives `tools/install.sh --next` with faked `node`/`npm` binaries (no network): Node 20 must be rejected; installs must pin **exact** versions (mutable `@next` forbidden); fast path must not unexpectedly fall back to source; gateway-install failure takes the documented fallback | `turbo`-external tail of `pnpm test``CI ci.yml#test` | QC-5 Test suite execution | preserve | Hermetic (shimmed) regression net for the installer lane; runs as part of the standard test command. |
| Clean-container install E2E | `tools/e2e-install-test.sh` | shell | Full first-run flow in a node:22-alpine container: `install.sh --yes``mosaic wizard` (non-interactive) → `mosaic gateway install``mosaic gateway verify` exit check (with EXPECTED-SKIP if the installed CLI predates `gateway verify`); skips gracefully without Docker | `local` (manual; requires Docker); **not wired in CI** | QC-5 Test suite execution | strengthen (review) | The only end-to-end proof of the install→verify path; currently operator-initiated only — wire into a periodic/manual CI lane or sign its exclusion explicitly. |
| Host installer advisories | `tools/install.sh` (`--check`; `check_fleet_transport`) | shell | `--check` = version comparison only, no install; `check_fleet_transport` warns (non-blocking, by design — tmux is the fleet's dependency, not mosaic's) when the roster-declared transport binary is absent, naming exactly what it blocks; PATH-persistence warnings | `installer` (operator-run) | QC-18 Operator-host drift audit | preserve | Advisory-by-design warnings; the parallel doctor check is drift-tested by §1.3's harness. |
### 1.8 Pending workstream additions (branch `feat/ri-050-publish-gate` @ `46784c8d`)
| check | location | kind | what it actually verifies | enforcement point | canonical check | disposition | rationale |
| ------------------------------- | ---------------------------------------------------- | ---- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | ----------------------------------- | ----------- | ---------------------------------------------------------------------------------------------- |
| Canonical terminal verification | `scripts/verify-release.mjs` (`pnpm verify:release`) | ts | One command replaying the full mandatory set as stages — sanitization, upgrade-guard, typecheck (incl. preflight), lint, format, test, build — mirroring `ci.yml` step-for-step; fail-fast on first failing command; requires `bash`+`rsync` on PATH; `--stage <name>` for wiring smoke-tests only | `publish.yml#verify` (pending); `local` (`pnpm verify:release`) | QC-11 Terminal release verification | preserve | The RI-N1 canonical command — CI and publication share one semantic checklist by construction. |
| Verify-parity contract test | `scripts/verify-release.test.mjs` | ts | Parses the real `ci.yml`/`publish.yml`: stage table must match ci.yml step-for-step; every publish-effect step (name `publish*` or image-pushing) must transitively depend on `verify`; commit-identity assertion must be present; `verify` must carry no path filter | `test:checkout``CI ci.yml#test` (once merged) | QC-11 Terminal release verification | preserve | Guard-of-the-guard at checkout time — the two surfaces cannot drift apart silently. |
## 2. Canonical check set
The deduplicated checks every row above maps onto. IDs are stable for RI-3-002 to consume.
- **QC-1 Checkout integrity.** Owns: the checkout can run its gates — frozen-lockfile dependency resolution, required gate binaries present, no stale build lock, and the `apps/web/.next` generated-state trust chain (real directory, uid ownership, certified source fingerprint, certified symlink manifest). Implemented by `scripts/preflight.mjs` + frozen install steps.
- **QC-2 Workspace typecheck.** Owns workspace-wide TypeScript soundness: per-package `tsc --noEmit` over built dependencies (`turbo typecheck`). The single definition invoked by CI, pre-push, and terminal verification.
- **QC-3 Workspace lint.** Owns static-analysis policy: per-package ESLint under the root config. One config, one task, every surface.
- **QC-4 Format check.** Owns formatting uniformity: Prettier check with the repo ignore list. (The pre-commit variant additionally fixes; the verdict form is this check.)
- **QC-5 Test suite execution.** Owns execution of all test surfaces: checkout script units (`node --test`), per-package Vitest suites (including the framework shell chain and its python unitests), the installer-lane shim test, and — once wired — `test-roster-schema.py` and container E2E. Also owns guards-of-the-gate that live inside the chain (terminal-green contract, RCE regression).
- **QC-6 Workspace build.** Owns artifact buildability: `turbo build` producing the artifacts publication consumes.
- **QC-7 Framework sanitization.** Owns the open-source guarantee for the shipped framework package: no operator-identity tokens anywhere (examples included), no private `$HOME` defaults in shipped scripts, with a self-test that keeps the regexes honest.
- **QC-8 Resident-context budget.** Owns the line-count ceilings on framework files injected into every agent's context (Constitution, dispatcher, RUNTIME.md slices) — the CI-enforceable half of the resident-prompt budget.
- **QC-9 Test-membership enumeration.** Owns the property that no test suite can silently fall out of CI: disk population vs parsed enumeration surfaces, both-directions staleness, and signed exclusions with reasons. Includes its needle/control harness.
- **QC-10 Upgrade/install safety.** Owns the #791 family: operator-path byte-identity across keep-mode upgrades (manifest guard), mid-failure rollback (errtrace-proven), durable pre-update snapshot + verify net + CWE-59 leaf guard, and the v2→v3 migration matrix with shell/TS parity.
- **QC-11 Terminal release verification.** Owns the RI-N1 exact-commit binding: commit-identity assertion plus one canonical command (`pnpm verify:release`) replaying the complete mandatory set, with every publish effect depending on it; plus the checkout-time parity/DAG contract test that keeps pipeline and command in sync.
- **QC-12 Publish-effect integrity.** Owns publication correctness: npm publish error classification (only already-published tolerated), next-lane versioning and post-publish resolution proof, and image destination/tag policy.
- **QC-13 Staged-change hygiene.** Owns commit-time hygiene on staged files (prettier/eslint fix-and-restage) and the self-verifying hook wiring that guarantees the gates are actually installed.
- **QC-14 Pre-push gate.** Owns the local push composition: preflight + typecheck + lint + format:check (tests deliberately deferred to CI).
- **QC-15 Lease-gate architecture invariant.** Owns "no ungated runtime launches in production code": the scan + allowlist over `packages/`, `apps/`, `plugins/`, `tools/`.
- **QC-16 Agent-runtime edit-time checks.** Owns edit-time feedback on agent hosts: the deps-preflight legibility sentinel and typecheck-on-edit, plus their regression harnesses.
- **QC-17 Lease-enforcement wiring safety.** Owns the #869 C1/C2/C5 trio: activation capability probe (versioned contract), enforcement-hook wiring gate (default-deny with explicit opt-out), and the doctor check that surfaces a bricked host — with their shell/TS harnesses.
- **QC-18 Operator-host drift audit.** Owns host-state health CI cannot see: `mosaic doctor` drift audit (+ fleet transport, both implementations), `fleet doctor` roster classification, `gateway doctor`/`gateway verify` service health, and installer advisories. Advisory exits are part of the contract.
- **QC-19 Downstream rails presence check.** Owns "does a scaffolded project still carry its rails files" — today the TS `quality-rails check/doctor` presence loop; per RI-N4 this is the seed that must become the typed evaluator (presence alone is explicitly not parity).
- **QC-20 Downstream enforcement verification.** Owns "do the rails actually block" on scaffolded projects: the behavioral planted-commit probe (type error, `any`, lint, gitleaks secret) currently in `verify.sh`/`verify.ps1` behind the `mosaic-quality-verify` adapter.
- **QC-21 Downstream rails scaffolding.** Owns putting rails files into a target project: the shell template installer (+ PowerShell twin) and the TS `quality-rails init` scaffolder — currently two paths that must converge.
## 3. Coverage gaps
Enforced nowhere but implied, or named in docs/tooling but not wired:
1. **Publication not yet bound to verification on `next`.** At this base (`8199261c`), `publish.yml` publish steps depend on `build` only; the `verify` step and `scripts/verify-release.mjs` exist on `feat/ri-050-publish-gate` (`46784c8d`) but are not merged. Until RI-1-001 lands, AC-RI-1's negative control cannot hold on the real pipeline.
2. **Playwright E2E unwired.** `apps/web` ships `test:e2e` (`playwright test`) with real suites (`admin/auth/chat/navigation.spec.ts`); neither `pnpm test` nor any CI step invokes it. The web UI's user flows are verified only when an operator runs them manually.
3. **No secret scanning on this repo.** The framework's own template pre-commit makes gitleaks **required**, and `verify.sh` proves detection with a planted key — but this repository's `.husky/pre-commit` (lint-staged only) and CI run no secret scan. The repo ships the control it does not use.
4. **No dependency audit.** The quality `.woodpecker.yml` templates and `docs/CI-SETUP.md` specify `npm audit --audit-level=high` as a pipeline stage; nothing equivalent runs for this repo.
5. **No coverage thresholds.** Templates enforce 80% Jest coverage thresholds; this repo's Vitest configs collect coverage with no thresholds — coverage is measured nowhere and enforced nowhere.
6. **`test-roster-schema.py` invisible.** A real jsonschema regression suite wired to no surface and invisible to the enumeration guard (its population is `*.sh`; the suite is `.py`). Either enumerate it or sign an exclusion — silence here is the #1017 defect shape.
7. **Presence-checker expectations ≠ this repo.** `quality-rails check` expects `.eslintrc`, `biome.json`, `.githooks/pre-commit`, `PR-CHECKLIST.md` for node projects — none describe this monorepo (husky, flat eslint config, no biome, no PR-CHECKLIST.md). The evaluator's check set must be per-subject (versioned, digested), not one global file list.
8. **Chain-ordering residual (documented).** `test:framework-shell` is one `&&` chain: a failing link skips every later suite while the step still fails (measured in #1270 — four suites after position 44 had not run since a prior merge). The enumeration guard proves naming, not reachability; both residuals are in-file documented but structurally unfixed.
9. **Signed-exclusion burndown open.** 16 signed exclusions remain in `test-enumeration-exclusions.txt`; several are "unmeasured in CI image" or blocked on missing CI tooling (tmux, setsid) — tracked under #1017/#1271. Each is an enforcement promise deferred, not delivered.
10. **Windows twins unexercised.** `verify.ps1`, `install.ps1`, `mosaic-doctor.ps1` have no runner anywhere (no Windows CI); behavioral drift from their bash twins is undetectable by construction.
11. **QA hook name vs behavior.** `qa-hook-handler.sh` files remediation report templates but performs no verification; the seam's actual gate value is only the deps-preflight sentinel. Anything relying on "QA automation hook" as a check is relying on report-filing.
12. **Two test paths, one gated.** CI runs tests against ci-postgres (`DATABASE_URL` set); the local PGlite path is the documented default (AGENTS.md) until KBN-101-02/101-05. Only the CI path is enforced by pipeline.
## 4. Disposition summary
| disposition | rows | checks |
| ------------------- | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| preserve | 43 | Every canonical owner (QC-1..QC-18) plus correct guards-of-the-guard and thin adapters: all of §1.1, the CI-invoked framework probes and adapters in §1.2, all of §1.3, the C1/C2/C5 trio and doctors in §1.4, all of §1.5, all pipeline-only steps in §1.6, §1.7 rows 1 and 3, and §1.8. |
| strengthen | 2 | `quality-rails check` and `quality-rails doctor` (QC-19) — the RI-N4 evaluator seed: typed verdicts, versioned/digested check definitions, per-subject check sets. |
| strengthen (review) | 9 | `verify.sh` + `verify.ps1` (QC-20), quality `install.sh`/`install.ps1` + `quality-rails init` (QC-21 — scaffold-path convergence), `test-roster-schema.py` (QC-5 — wire or sign), `qa-hook-stdin.sh` seam + `typecheck-hook.sh` (QC-16), `tools/e2e-install-test.sh` (QC-5 — CI lane). |
| retire | 0 | None meet the bar: RI-N4 requires effective shell probes be **absorbed before** their paths retire, and no absorption exists yet. The `strengthen (review)` rows are the retirement candidates for RI-3-002 once the evaluator owns their behavior. |
Row total: 54. Canonical checks: 21 (QC-1..QC-21).
+31 -1
View File
@@ -30,7 +30,7 @@ The Gitea API token is **never passed on a curl command line.** An `Authorizatio
### `--login` override ### `--login` override
Both `pr-review.sh` and `issue-comment.sh` accept an optional `--login <name>` flag that overrides the automatically detected Gitea login for that single invocation. The override selects **which credential the REST write, the `/user` identity lookup, and the read-back all use** — its token is resolved from the tea config for that login name (`get_gitea_token_for_login`), falling back to the repo host's credential when no login is named. The resolved login is **host- and port-bound**: the login's configured URL host **and effective port** (the scheme's default port — 80 for `http`, 443 for `https` — applies when a port is omitted, symmetrically on both sides) must match the repo remote's, so a login name shared across hosts (or an override configured for a different Gitea, including one on a different port of the same host) can never send one host's credential to another — a host or port mismatch fails closed rather than leaking a cross-host token. Resolving the acting identity and the read-back from the _same_ login that performs the write is essential: a write performed under an overridden login must be verified against that login's identity, not the host default's. Callers who need a different login than the host default should pass `--login <reviewer-login>`. Both `pr-review.sh` and `issue-comment.sh` accept an optional `--login <name>` flag that overrides the automatically detected Gitea login for that single invocation (as of #1280, `pr-create.sh`, `pr-merge.sh` and `issue-create.sh` accept it too, and it wins over `MOSAIC_GIT_IDENTITY` everywhere). The override selects **which credential the REST write, the `/user` identity lookup, and the read-back all use** — its token is resolved from the tea config for that login name (`get_gitea_token_for_login`), falling back to the repo host's credential when no login is named. The resolved login is **host- and port-bound**: the login's configured URL host **and effective port** (the scheme's default port — 80 for `http`, 443 for `https` — applies when a port is omitted, symmetrically on both sides) must match the repo remote's, so a login name shared across hosts (or an override configured for a different Gitea, including one on a different port of the same host) can never send one host's credential to another — a host or port mismatch fails closed rather than leaking a cross-host token. Resolving the acting identity and the read-back from the _same_ login that performs the write is essential: a write performed under an overridden login must be verified against that login's identity, not the host default's. Callers who need a different login than the host default should pass `--login <reviewer-login>`.
As a durable successor to this mechanism, consider giving each reviewer/approver slot its own dedicated Gitea login credential, so that author≠reviewer holds at the credential level rather than relying on wrapper-level `--login` bookkeeping. This is a recommendation for future hardening, not something implemented by this flag. As a durable successor to this mechanism, consider giving each reviewer/approver slot its own dedicated Gitea login credential, so that author≠reviewer holds at the credential level rather than relying on wrapper-level `--login` bookkeeping. This is a recommendation for future hardening, not something implemented by this flag.
@@ -58,6 +58,36 @@ token file present, both tools fall through to the existing shared-account path
unchanged, so this feature is a no-op on any host that hasn't provisioned per-slot unchanged, so this feature is a no-op on any host that hasn't provisioned per-slot
tokens. tokens.
### Identity-first principal resolution in the wrappers (#1280)
`resolve_gitea_principal()` (detect-platform.sh) gives the write wrappers —
`pr-create.sh`, `pr-merge.sh`, `pr-review.sh`, `issue-create.sh`, `issue-comment.sh`
ONE precedence for choosing the acting principal:
1. an explicit `--login <name>` (now accepted by all five; operator intent beats
environment), then
2. the per-agent identity above (`MOSAIC_GIT_IDENTITY` env / worktree
`mosaic.gitIdentity`) when a per-slot token exists — the wrapper then writes via the
REST API with that identity's token and never consults `tea`, so the tea login list
cannot shadow the requested principal, then
3. the tea login list — the LAST resort, never the first, because it enumerates
whatever logins the host happens to hold and knows nothing about which seat is
calling.
A requested identity whose per-slot token is absent, or a `--login` whose token cannot
resolve host-bound, **fails loud** (nonzero, naming the identity/login and the expected
slot) instead of silently writing under whatever account `tea` has configured — that
silent fallthrough is defect #1280 (reviews, comments, merges, PRs and issues filed
under the wrong account). `pr-merge.sh --dry-run` reports the principal the merge would
act as, resolved exactly as the real merge resolves it. ⚠ A **workstation-global**
`mosaic.gitIdentity` shadows every seat on that host (a fresh clone with no local value
resolves the global one) — set it per-worktree, not with `--global`.
The resolver is covered by `test-gitea-principal-resolution.sh`; the happy-path
ordering (identity arm REACHED, not sitting behind a tea failure) by
`test-pr-create-identity-first.sh`; merge credential binding by
`test-pr-merge-principal-resolution.sh`.
### Enabling it for a clone ### Enabling it for a clone
The framework installer syncs `git-credential-mosaic` to The framework installer syncs `git-credential-mosaic` to
@@ -497,6 +497,32 @@ get_gitea_url_for_host() {
return 1 return 1
} }
# Map a Gitea host to the per-agent identity-token slot PREFIX ("gitea-usc" /
# "gitea-mosaicstack") used by identity-first principal resolution
# (MOSAIC_GIT_IDENTITY / git config mosaic.gitIdentity; #1280). Returns 1 for
# hosts with no per-slot scheme — callers treat that as "identity does not
# bind here" and fall through to existing behavior, never as an error. This is
# the single source of truth for the slot layout: get_gitea_token and
# resolve_gitea_principal both derive their slot paths from here, so the two
# resolutions can never disagree about where an identity's credential lives.
gitea_identity_slot_prefix() {
case "$1" in
git.uscllc.com) echo "gitea-usc" ;;
git.mosaicstack.dev) echo "gitea-mosaicstack" ;;
*) return 1 ;;
esac
}
# Resolve the per-slot token FILE PATH for an identity on a host. Prints the
# absolute path on success; returns 1 (no output) when the host has no per-slot
# scheme. Prints a PATH only — never a token value.
gitea_identity_token_slot() {
local identity="$1" host="$2" prefix
[[ -n "$identity" ]] || return 1
prefix=$(gitea_identity_slot_prefix "$host") || return 1
printf '%s\n' "$HOME/.config/mosaic/secrets/gitea-tokens/${prefix}-${identity}.token"
}
# Resolve a Gitea API token for the given host. # Resolve a Gitea API token for the given host.
# Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials # Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials
get_gitea_token() { get_gitea_token() {
@@ -517,13 +543,8 @@ get_gitea_token() {
_ident_src="git config mosaic.gitIdentity" _ident_src="git config mosaic.gitIdentity"
fi fi
if [[ -n "$_ident" ]]; then if [[ -n "$_ident" ]]; then
local _idpfx="" local _idtok=""
case "$host" in if _idtok="$(gitea_identity_token_slot "$_ident" "$host" 2>/dev/null)"; then
git.uscllc.com) _idpfx=gitea-usc ;;
git.mosaicstack.dev) _idpfx=gitea-mosaicstack ;;
esac
if [[ -n "$_idpfx" ]]; then
local _idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${_idpfx}-${_ident}.token"
if [[ -r "$_idtok" ]]; then if [[ -r "$_idtok" ]]; then
cat "$_idtok" cat "$_idtok"
return 0 return 0
@@ -1465,6 +1486,81 @@ raise SystemExit(1)
PY PY
} }
# resolve_gitea_principal — identity-first acting-principal resolution shared by
# the git wrappers (#1280). The defect this fixes: wrappers resolved their
# acting principal from tea's login list FIRST, and that list enumerates
# whatever logins happen to be configured on the host — it knows nothing about
# which seat is calling — so a wrapper invoked with MOSAIC_GIT_IDENTITY=fargo
# still wrote under whichever account tea held (mos-dt-0), and the correct
# identity-aware code sat behind arms that only ran when the tea path failed.
# Precedence here is the contract:
# 1. an explicit login override ($1, the wrapper's --login) — operator intent
# beats environment;
# 2. MOSAIC_GIT_IDENTITY env, else per-worktree `git config mosaic.gitIdentity`
# (mirroring get_gitea_token exactly, so resolver and token resolution can
# never disagree) — binds only on hosts with a per-slot token scheme;
# 3. the tea login list — LAST resort, never the first.
#
# Prints exactly one line, three tab-separated fields (machine-readable for
# wrapper dispatch and tests):
# mode "login" | "identity" | "default"
# principal login name (login) | identity name (identity) | tea login or "" (default)
# source "tea-login:<name>" | "identity-slot:<path>" | "tea-default" | "host-credential"
#
# Fails LOUD (nonzero, empty stdout, stderr diagnostic) when an explicit
# override cannot be honored — a refusal is a good day; silently falling
# through to whoever tea has configured is the exact defect this resolves:
# - login mode: no host-bound token for that tea login. The existence check
# runs the same tea-config lookup tea itself uses; the token VALUE is
# discarded (never printed, never used).
# - identity mode: no per-slot token file for that identity on a recognized
# host — the diagnostic names the identity, its source, and the expected
# slot path. An identity requested on a host with NO per-slot scheme does
# not bind (matching get_gitea_token's containment) and falls to default.
#
# NEVER prints a token value — principal names and slot paths only.
# $1 = explicit login override ("" when absent), $2 = host (default: the
# origin remote's host).
resolve_gitea_principal() {
local login_override="${1:-}" host="${2:-}" ident ident_src slot login
[[ -n "$host" ]] || { host=$(get_remote_host) || return 1; }
if [[ -n "$login_override" ]]; then
get_gitea_token_for_login "$login_override" "$host" >/dev/null || {
echo "Error: --login '$login_override' has no host-matched token on host '$host' (tea config lookup); refusing to fall back to any other principal (#1280 identity-first resolution)." >&2
return 1
}
printf 'login\t%s\ttea-login:%s\n' "$login_override" "$login_override"
return 0
fi
ident="${MOSAIC_GIT_IDENTITY:-}"
ident_src="MOSAIC_GIT_IDENTITY"
if [[ -z "$ident" ]]; then
ident="$(git config --get mosaic.gitIdentity 2>/dev/null || true)"
ident_src="git config mosaic.gitIdentity"
fi
if [[ -n "$ident" ]] && slot="$(gitea_identity_token_slot "$ident" "$host" 2>/dev/null)"; then
if [[ -r "$slot" ]]; then
printf 'identity\t%s\tidentity-slot:%s\n' "$ident" "$slot"
return 0
fi
echo "Error: git identity '$ident' requested (via $ident_src) for host '$host', but no per-slot token at $slot (#1280 identity-first resolution)." >&2
echo " Refusing to fall back to the tea login list or shared credentials. Provision the per-slot token, or unset the identity." >&2
return 1
fi
# No override requested: tea's login list is the LAST resort. Absence is
# not an error here — callers fall back to the host credential, exactly as
# they did before this resolver existed (preserved behavior).
if login=$(get_gitea_login_for_host "$host" 2>/dev/null); then
printf 'default\t%s\ttea-default\n' "$login"
else
printf 'default\t\thost-credential\n'
fi
return 0
}
# Resolve HTTPS basic auth credentials for a Gitea host from ~/.git-credentials. # Resolve HTTPS basic auth credentials for a Gitea host from ~/.git-credentials.
# Prints "username:password" for direct curl -u consumption. Callers must not log it. # Prints "username:password" for direct curl -u consumption. Callers must not log it.
get_gitea_basic_auth() { get_gitea_basic_auth() {
@@ -76,27 +76,36 @@ fi
detect_platform >/dev/null detect_platform >/dev/null
# Resolve and cache the Gitea REST endpoint + token for the current remote, # Resolve and cache the Gitea REST endpoint + token for the current remote,
# bound to a SPECIFIC login identity ($1). Populates GITEA_API_ROOT (…/api/v1), # bound to a SPECIFIC acting principal ($1) selected identity-first (#1280):
# GITEA_API_BASE (…/api/v1/repos/<slug>), and GITEA_API_TOKEN. # an explicit --login wins, else MOSAIC_GIT_IDENTITY / git config
# mosaic.gitIdentity binds the per-slot credential, else the tea login list
# (last resort). Populates GITEA_API_ROOT (…/api/v1), GITEA_API_BASE
# (…/api/v1/repos/<slug>), and GITEA_API_TOKEN.
# #
# The token is resolved for the EFFECTIVE login (the --login override when # The token is resolved for the EFFECTIVE principal so that the single
# given, otherwise the detected default) so that the single credential used for # credential used for the write ALSO drives the /user identity read and the
# the write ALSO drives the /user identity read and the read-back — write token # read-back — write token and read-back token are the same identity by
# and read-back token are the same identity by construction (this is the # construction (this is the credential-ordering fix: a --login override is no
# credential-ordering fix: a --login override is no longer written under one # longer written under one credential and verified under a different default
# credential and verified under a different default one). Falls back to the # one). When $2 is "identity" the principal ($1) is a requested git identity:
# host-scoped credential ONLY when NO --login override was supplied (the # the token MUST resolve from that identity's per-slot token (get_gitea_token's
# best-effort default path). When $2 is "explicit" the login came from a # identity arm), failing closed rather than borrowing the tea default login —
# caller-supplied --login: that exact login's token MUST resolve, and we FAIL # the tea login list must never shadow a requested identity (#1280). When $2
# CLOSED rather than silently downgrading the write to the host default # is "explicit" the principal came from a caller-supplied --login: that exact
# identity — otherwise a caller relying on a dedicated per-role credential would # login's token MUST resolve, and we FAIL CLOSED rather than silently
# be told the write succeeded as requested while it was attributed to the shared # downgrading the write to the host default identity. Otherwise the best-effort
# default. Returns non-zero (clear stderr) on any resolution failure. # default path applies (per-login token, else the host-scoped credential).
# Returns non-zero (clear stderr) on any resolution failure.
gitea_resolve_api_for_login() { gitea_resolve_api_for_login() {
local effective_login="$1" override_explicit="${2:-}" host configured_url repo local effective_login="$1" override_explicit="${2:-}" host configured_url repo
host=$(get_remote_host) host=$(get_remote_host)
if [[ -n "$override_explicit" ]]; then if [[ "$override_explicit" == "identity" ]]; then
GITEA_API_TOKEN=$(get_gitea_token "$host") || {
echo "Error: could not resolve the per-slot token for requested git identity '$effective_login' on host '$host'; refusing to fall back to the tea login list or shared credentials (comment write/read-back, #1280)." >&2
return 1
}
elif [[ -n "$override_explicit" ]]; then
GITEA_API_TOKEN=$(get_gitea_token_for_login "$effective_login" "$host") || { GITEA_API_TOKEN=$(get_gitea_token_for_login "$effective_login" "$host") || {
echo "Error: could not resolve a host-matched Gitea token for --login '$effective_login' on host '$host'; refusing to fall back to the host default identity or a cross-host credential (comment write/read-back)" >&2 echo "Error: could not resolve a host-matched Gitea token for --login '$effective_login' on host '$host'; refusing to fall back to the host default identity or a cross-host credential (comment write/read-back)" >&2
return 1 return 1
@@ -318,23 +327,31 @@ if [[ "$PLATFORM" == "github" ]]; then
gh issue comment "$ISSUE_NUMBER" --body "$COMMENT" gh issue comment "$ISSUE_NUMBER" --body "$COMMENT"
echo "Added comment to GitHub issue #$ISSUE_NUMBER" echo "Added comment to GitHub issue #$ISSUE_NUMBER"
elif [[ "$PLATFORM" == "gitea" ]]; then elif [[ "$PLATFORM" == "gitea" ]]; then
# Resolve the login this comment should be attributed to: the --login # Resolve the acting principal identity-first (#1280): an explicit --login
# override when given, otherwise the detected default for this repo's host. # wins; otherwise MOSAIC_GIT_IDENTITY / git config mosaic.gitIdentity
# A --login override always wins. Otherwise name this repo host's login only # selects the principal when a per-slot token exists (fail-loud when it
# as a best effort: the login name merely selects a per-login token, and # does not); the tea login list is the LAST resort — it knows nothing about
# gitea_resolve_api_for_login falls back to the host credential # which seat is calling, so resolving from it first wrote under whichever
# (get_gitea_token) when no tea login is named, so the default credential # account tea had configured (the #1280 family).
# still resolves even when the host tea has no matching login entry. principal_host=$(get_remote_host)
EFFECTIVE_LOGIN="$LOGIN_OVERRIDE" if ! principal_resolved="$(resolve_gitea_principal "$LOGIN_OVERRIDE" "$principal_host")"; then
[[ -n "$EFFECTIVE_LOGIN" ]] || EFFECTIVE_LOGIN=$(get_gitea_login 2>/dev/null || true) # resolve_gitea_principal already printed the fail-loud diagnostic.
exit 1
fi
PRINCIPAL_MODE="$(printf '%s' "$principal_resolved" | cut -f1)"
PRINCIPAL_NAME="$(printf '%s' "$principal_resolved" | cut -f2)"
# Bind the REST endpoint + token to the effective login, then derive the # Bind the REST endpoint + token to the resolved principal, then derive the
# acting identity from that SAME credential (GET /user). The write below and # acting identity from that SAME credential (GET /user). The write below and
# its read-back both use this credential, so the write is verified against # its read-back both use this credential, so the write is verified against
# the identity that actually performed it. Passing "explicit" when --login # the identity that actually performed it.
# was supplied forbids the host-default fallback: an unresolvable explicit if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# override fails closed instead of writing under the default identity. gitea_resolve_api_for_login "$PRINCIPAL_NAME" identity || exit 1
gitea_resolve_api_for_login "$EFFECTIVE_LOGIN" "${LOGIN_OVERRIDE:+explicit}" || exit 1 elif [[ "$PRINCIPAL_MODE" == "login" ]]; then
gitea_resolve_api_for_login "$PRINCIPAL_NAME" explicit || exit 1
else
gitea_resolve_api_for_login "$PRINCIPAL_NAME" "" || exit 1
fi
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1 ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
comment_id=$(gitea_create_comment_verified "$ISSUE_NUMBER" "$COMMENT" "$ACTING_LOGIN") || { comment_id=$(gitea_create_comment_verified "$ISSUE_NUMBER" "$COMMENT" "$ACTING_LOGIN") || {
@@ -1,6 +1,15 @@
#!/bin/bash #!/bin/bash
# issue-create.sh - Create issues on Gitea or GitHub # issue-create.sh - Create issues on Gitea or GitHub
# Usage: issue-create.sh -t "Title" [-b "Body"] [-l "label1,label2"] [-m "milestone"] # Usage: issue-create.sh -t "Title" [-b "Body"] [-l "label1,label2"] [-m "milestone"] [--login <name>]
#
# Acting principal is resolved identity-first (#1280): an explicit --login
# wins; otherwise MOSAIC_GIT_IDENTITY / per-worktree git config
# mosaic.gitIdentity selects the principal when a per-slot token exists (and
# the wrapper then creates the issue through the REST API with that identity's
# token — tea is never invoked, so the tea login list cannot shadow the
# requested principal); the tea login list is the LAST resort. A requested
# identity with no per-slot token fails LOUD rather than writing under
# whichever account tea happens to hold.
set -e set -e
@@ -16,6 +25,14 @@ INTERACTIVE=false
# get_remote_host and get_gitea_token are provided by detect-platform.sh # get_remote_host and get_gitea_token are provided by detect-platform.sh
# Acting-principal mode set in the Gitea branch below (from
# resolve_gitea_principal): "login" when --login was given, "identity" when a
# git identity bound, "default" otherwise. PRINCIPAL_MODE=login makes the API
# arm resolve the --login principal's token too, so an explicit --login keeps
# winning even on the tea-FAILURE fallback arm.
PRINCIPAL_MODE=""
PRINCIPAL_NAME=""
gitea_issue_create_api() { gitea_issue_create_api() {
local host repo token url payload local host repo token url payload
host=$(get_remote_host) || { host=$(get_remote_host) || {
@@ -26,10 +43,19 @@ gitea_issue_create_api() {
echo "Error: could not determine repo owner/name for API fallback" >&2 echo "Error: could not determine repo owner/name for API fallback" >&2
return 1 return 1
} }
if [[ "$PRINCIPAL_MODE" == "login" ]]; then
token=$(get_gitea_token_for_login "$PRINCIPAL_NAME" "$host") || {
echo "Error: could not resolve a host-matched Gitea token for --login '$PRINCIPAL_NAME' on host '$host' (API path)" >&2
return 1
}
else
# Identity-first when MOSAIC_GIT_IDENTITY / git config mosaic.gitIdentity
# is set (per-slot token, fail-loud on absence); shared default otherwise.
token=$(get_gitea_token "$host") || { token=$(get_gitea_token "$host") || {
echo "Error: Gitea token not found for API fallback (set GITEA_TOKEN or configure ~/.git-credentials)" >&2 echo "Error: Gitea token not found for API fallback (set GITEA_TOKEN or configure ~/.git-credentials)" >&2
return 1 return 1
} }
fi
if [[ -n "$LABELS" || -n "$MILESTONE" ]]; then if [[ -n "$LABELS" || -n "$MILESTONE" ]]; then
echo "Warning: API fallback currently applies title/body only; labels/milestone require authenticated tea setup." >&2 echo "Warning: API fallback currently applies title/body only; labels/milestone require authenticated tea setup." >&2
@@ -67,6 +93,7 @@ Options:
-b, --body BODY Issue body/description -b, --body BODY Issue body/description
-l, --labels LABELS Comma-separated labels (e.g., "bug,feature") -l, --labels LABELS Comma-separated labels (e.g., "bug,feature")
-m, --milestone NAME Milestone name to assign -m, --milestone NAME Milestone name to assign
--login NAME Act as this Gitea tea login (wins over MOSAIC_GIT_IDENTITY)
-i, --interactive Prompt for missing issue fields -i, --interactive Prompt for missing issue fields
-h, --help Show this help message -h, --help Show this help message
@@ -97,6 +124,10 @@ while [[ $# -gt 0 ]]; do
MILESTONE="$2" MILESTONE="$2"
shift 2 shift 2
;; ;;
--login)
LOGIN_OVERRIDE="$2"
shift 2
;;
-i|--interactive) -i|--interactive)
INTERACTIVE=true INTERACTIVE=true
shift shift
@@ -134,13 +165,37 @@ case "$PLATFORM" in
"${CMD[@]}" "${CMD[@]}"
;; ;;
gitea) gitea)
# Resolve the acting principal identity-first (#1280). The tea login
# list is the LAST resort: it knows nothing about which seat is calling,
# and a login resolved from it first is what attributed issues to the
# wrong account even when MOSAIC_GIT_IDENTITY was set.
principal_host=$(get_remote_host 2>/dev/null || true)
if ! principal_resolved="$(resolve_gitea_principal "${LOGIN_OVERRIDE:-}" "$principal_host")"; then
# resolve_gitea_principal already printed the fail-loud diagnostic.
exit 1
fi
PRINCIPAL_MODE="$(printf '%s' "$principal_resolved" | cut -f1)"
PRINCIPAL_NAME="$(printf '%s' "$principal_resolved" | cut -f2)"
if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# HAPPY PATH for a requested identity: create through the REST API
# with the per-slot token and never invoke tea — the identity arm
# must be REACHED, not sit behind a tea failure (#1280).
gitea_issue_create_api
exit $?
fi
if command -v tea >/dev/null 2>&1; then if command -v tea >/dev/null 2>&1; then
REPO_SLUG=$(get_repo_slug) REPO_SLUG=$(get_repo_slug)
if [[ "$PRINCIPAL_MODE" == "login" ]]; then
GITEA_LOGIN_NAME="$PRINCIPAL_NAME"
else
GITEA_LOGIN_NAME=$(get_gitea_login) || { GITEA_LOGIN_NAME=$(get_gitea_login) || {
echo "Warning: could not resolve Gitea login for tea; trying Gitea API fallback..." >&2 echo "Warning: could not resolve Gitea login for tea; trying Gitea API fallback..." >&2
gitea_issue_create_api gitea_issue_create_api
exit $? exit $?
} }
fi
if ! get_gitea_authenticated_user "$GITEA_LOGIN_NAME" >/dev/null; then if ! get_gitea_authenticated_user "$GITEA_LOGIN_NAME" >/dev/null; then
echo "Warning: Tea authenticated-user validation failed (possible stale user/login); trying Gitea API fallback..." >&2 echo "Warning: Tea authenticated-user validation failed (possible stale user/login); trying Gitea API fallback..." >&2
gitea_issue_create_api gitea_issue_create_api
@@ -1,6 +1,15 @@
#!/bin/bash #!/bin/bash
# pr-create.sh - Create pull requests on Gitea or GitHub # pr-create.sh - Create pull requests on Gitea or GitHub
# Usage: pr-create.sh -t "Title" [-b "Body"] [-B base] [-H head] [-l "labels"] [-m "milestone"] # Usage: pr-create.sh -t "Title" [-b "Body"] [-B base] [-H head] [-l "labels"] [-m "milestone"] [--login <name>]
#
# Acting principal is resolved identity-first (#1280): an explicit --login
# wins; otherwise MOSAIC_GIT_IDENTITY / per-worktree git config
# mosaic.gitIdentity selects the principal when a per-slot token exists (and
# the wrapper then creates the PR through the REST API with that identity's
# token — tea is never invoked, so the tea login list cannot shadow the
# requested principal); the tea login list is the LAST resort. A requested
# identity with no per-slot token fails LOUD rather than writing under
# whichever account tea happens to hold.
set -e set -e
@@ -19,6 +28,15 @@ ISSUE=""
# get_remote_host, get_gitea_token, get_repo_info, and get_gitea_repo_args are provided by detect-platform.sh # get_remote_host, get_gitea_token, get_repo_info, and get_gitea_repo_args are provided by detect-platform.sh
# Acting-principal mode set in the Gitea branch below (from
# resolve_gitea_principal): "login" when --login was given, "identity" when a
# git identity bound, "default" otherwise. PRINCIPAL_MODE=login makes the API
# arm resolve the --login principal's token too, so an explicit --login keeps
# winning even on the tea-FAILURE fallback arm (otherwise the fallback would
# silently re-resolve to the environment identity or shared credential).
PRINCIPAL_MODE=""
PRINCIPAL_NAME=""
gitea_pr_create_api() { gitea_pr_create_api() {
local host repo token url payload local host repo token url payload
host=$(get_remote_host) || { host=$(get_remote_host) || {
@@ -29,10 +47,19 @@ gitea_pr_create_api() {
echo "Error: could not determine repo owner/name for API fallback" >&2 echo "Error: could not determine repo owner/name for API fallback" >&2
return 1 return 1
} }
if [[ "$PRINCIPAL_MODE" == "login" ]]; then
token=$(get_gitea_token_for_login "$PRINCIPAL_NAME" "$host") || {
echo "Error: could not resolve a host-matched Gitea token for --login '$PRINCIPAL_NAME' on host '$host' (API path)" >&2
return 1
}
else
# Identity-first when MOSAIC_GIT_IDENTITY / git config mosaic.gitIdentity
# is set (per-slot token, fail-loud on absence); shared default otherwise.
token=$(get_gitea_token "$host") || { token=$(get_gitea_token "$host") || {
echo "Error: Gitea token not found for API fallback (set GITEA_TOKEN or configure ~/.git-credentials)" >&2 echo "Error: Gitea token not found for API fallback (set GITEA_TOKEN or configure ~/.git-credentials)" >&2
return 1 return 1
} }
fi
if [[ -n "$LABELS" || -n "$MILESTONE" || "$DRAFT" == true ]]; then if [[ -n "$LABELS" || -n "$MILESTONE" || "$DRAFT" == true ]]; then
echo "Warning: API fallback applies title/body/head/base only; labels/milestone/draft require authenticated tea setup." >&2 echo "Warning: API fallback applies title/body/head/base only; labels/milestone/draft require authenticated tea setup." >&2
@@ -76,6 +103,7 @@ Options:
-H, --head BRANCH Head branch with changes (default: current branch) -H, --head BRANCH Head branch with changes (default: current branch)
-l, --labels LABELS Comma-separated labels -l, --labels LABELS Comma-separated labels
-m, --milestone NAME Milestone name -m, --milestone NAME Milestone name
--login NAME Act as this Gitea tea login (wins over MOSAIC_GIT_IDENTITY)
-i, --issue NUMBER Link to issue (auto-generates title if not provided) -i, --issue NUMBER Link to issue (auto-generates title if not provided)
-d, --draft Create as draft PR -d, --draft Create as draft PR
-h, --help Show this help message -h, --help Show this help message
@@ -116,6 +144,10 @@ while [[ $# -gt 0 ]]; do
MILESTONE="$2" MILESTONE="$2"
shift 2 shift 2
;; ;;
--login)
LOGIN_OVERRIDE="$2"
shift 2
;;
-i|--issue) -i|--issue)
ISSUE="$2" ISSUE="$2"
shift 2 shift 2
@@ -174,15 +206,41 @@ case "$PLATFORM" in
"${CMD[@]}" "${CMD[@]}"
;; ;;
gitea) gitea)
# Resolve the acting principal identity-first (#1280). The tea login
# list is the LAST resort: it knows nothing about which seat is calling,
# and a login resolved from it first is what attributed PRs to the wrong
# account even when MOSAIC_GIT_IDENTITY was set.
principal_host=$(get_remote_host 2>/dev/null || true)
if ! principal_resolved="$(resolve_gitea_principal "${LOGIN_OVERRIDE:-}" "$principal_host")"; then
# resolve_gitea_principal already printed the fail-loud diagnostic.
exit 1
fi
PRINCIPAL_MODE="$(printf '%s' "$principal_resolved" | cut -f1)"
PRINCIPAL_NAME="$(printf '%s' "$principal_resolved" | cut -f2)"
if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# HAPPY PATH for a requested identity: the per-slot token IS the
# credential, so create through the REST API directly and never
# invoke tea — the identity arm must be REACHED, not sit behind a
# tea failure (#1280). Fail-loud on a missing slot already happened
# in resolve_gitea_principal.
gitea_pr_create_api
exit $?
fi
# tea pull create syntax. Always pass --repo because tea repo inference # tea pull create syntax. Always pass --repo because tea repo inference
# is unreliable in Mosaic worktrees/profile shells. Use arrays instead # is unreliable in Mosaic worktrees/profile shells. Use arrays instead
# of eval so markdown backticks/body content are not shell-executed. # of eval so markdown backticks/body content are not shell-executed.
REPO_SLUG=$(get_repo_slug) REPO_SLUG=$(get_repo_slug)
if [[ "$PRINCIPAL_MODE" == "login" ]]; then
GITEA_LOGIN_NAME="$PRINCIPAL_NAME"
else
GITEA_LOGIN_NAME=$(get_gitea_login) || { GITEA_LOGIN_NAME=$(get_gitea_login) || {
echo "Warning: could not resolve Gitea login for tea; trying Gitea API fallback..." >&2 echo "Warning: could not resolve Gitea login for tea; trying Gitea API fallback..." >&2
gitea_pr_create_api gitea_pr_create_api
exit $? exit $?
} }
fi
if ! get_gitea_authenticated_user "$GITEA_LOGIN_NAME" >/dev/null; then if ! get_gitea_authenticated_user "$GITEA_LOGIN_NAME" >/dev/null; then
echo "Warning: Tea authenticated-user validation failed (possible stale user/login); trying Gitea API fallback..." >&2 echo "Warning: Tea authenticated-user validation failed (possible stale user/login); trying Gitea API fallback..." >&2
gitea_pr_create_api gitea_pr_create_api
@@ -1,6 +1,13 @@
#!/bin/bash #!/bin/bash
# pr-merge.sh - Merge pull requests on Gitea or GitHub # pr-merge.sh - Merge pull requests on Gitea or GitHub
# Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d] [--expect-head SHA] [--co-author-trailers --escalate-to PRINCIPAL] # Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d] [--expect-head SHA] [--co-author-trailers --escalate-to PRINCIPAL] [--login <name>]
#
# Acting principal is resolved identity-first (#1280): an explicit --login
# wins; otherwise MOSAIC_GIT_IDENTITY / per-worktree git config
# mosaic.gitIdentity selects the credential (per-slot token, fail-loud when
# absent); the shared host credential is the last resort. The merge is
# performed with the resolved credential only — never a cross-principal
# fallback (an HTTP 401 from the identity-bound token is a hard stop).
set -euo pipefail set -euo pipefail
@@ -16,6 +23,7 @@ DRY_RUN=false
EXPECT_HEAD="" EXPECT_HEAD=""
CO_AUTHOR_TRAILERS=false CO_AUTHOR_TRAILERS=false
ESCALATE_TO="" ESCALATE_TO=""
LOGIN_OVERRIDE=""
usage() { usage() {
cat <<EOF cat <<EOF
@@ -31,6 +39,7 @@ Options:
--expect-head SHA Refuse unless the PR head matches this full commit SHA --expect-head SHA Refuse unless the PR head matches this full commit SHA
--co-author-trailers Build verified trailers from linked PR commit authors --co-author-trailers Build verified trailers from linked PR commit authors
--escalate-to NAME Named principal for an unresolved-author BLOCK --escalate-to NAME Named principal for an unresolved-author BLOCK
--login NAME Act as this Gitea tea login (wins over MOSAIC_GIT_IDENTITY)
-h, --help Show this help message -h, --help Show this help message
Examples: Examples:
@@ -39,6 +48,7 @@ Examples:
$(basename "$0") -n 42 -d # Squash merge and delete branch $(basename "$0") -n 42 -d # Squash merge and delete branch
$(basename "$0") -n 42 --expect-head 0123456789abcdef0123456789abcdef01234567 $(basename "$0") -n 42 --expect-head 0123456789abcdef0123456789abcdef01234567
$(basename "$0") -n 42 --co-author-trailers --escalate-to tl-mosaic $(basename "$0") -n 42 --co-author-trailers --escalate-to tl-mosaic
$(basename "$0") -n 42 --login fred-ms # Merge under the fred-ms tea login
EOF EOF
exit "${1:-1}" exit "${1:-1}"
} }
@@ -82,6 +92,14 @@ while [[ $# -gt 0 ]]; do
ESCALATE_TO="$2" ESCALATE_TO="$2"
shift 2 shift 2
;; ;;
--login|-l)
if [[ $# -lt 2 ]]; then
echo "Error: --login requires one tea login name." >&2
exit 1
fi
LOGIN_OVERRIDE="$2"
shift 2
;;
-h|--help) -h|--help)
usage 0 usage 0
;; ;;
@@ -572,10 +590,23 @@ PY
merge_gitea_with_api() { merge_gitea_with_api() {
local host="$1" token attempt_rc local host="$1" token attempt_rc
# Identity-first principal resolution (#1280): an explicit --login wins
# over MOSAIC_GIT_IDENTITY (operator intent beats environment); otherwise
# get_gitea_token resolves the identity's per-slot token when an identity
# is requested (fail-loud when absent) and the shared host credential only
# when no identity is set. No cross-principal fallback: whatever resolves
# here is the ONLY credential the merge is attempted with.
if [[ -n "$LOGIN_OVERRIDE" ]]; then
if ! token=$(get_gitea_token_for_login "$LOGIN_OVERRIDE" "$host"); then
echo "Error: --login '$LOGIN_OVERRIDE' has no host-matched token on host '$host'; refusing to merge under any other principal (#1280 identity-first resolution)." >&2
return 1
fi
else
if ! token=$(get_gitea_token "$host"); then if ! token=$(get_gitea_token "$host"); then
echo "Error: Could not resolve the required Gitea token; refusing merge without changing principals." >&2 echo "Error: Could not resolve the required Gitea token; refusing merge without changing principals." >&2
return 1 return 1
fi fi
fi
if [[ -z "$token" ]]; then if [[ -z "$token" ]]; then
echo "Error: Required Gitea token resolved empty; refusing merge without changing principals." >&2 echo "Error: Required Gitea token resolved empty; refusing merge without changing principals." >&2
return 1 return 1
@@ -602,10 +633,25 @@ if [[ "$DRY_RUN" == true ]]; then
echo "Error: Cannot determine host from origin remote URL" >&2 echo "Error: Cannot determine host from origin remote URL" >&2
exit 1 exit 1
} }
# Report the acting principal the merge WOULD use, resolved the same
# way the real merge resolves it (#1280) — a dry run that names a
# different principal than the merge would act as is a lie.
if ! principal_resolved="$(resolve_gitea_principal "$LOGIN_OVERRIDE" "$HOST")"; then
# Fail-loud diagnostic already printed (unresolvable --login or a
# requested identity with no per-slot token).
exit 1
fi
DRY_PRINCIPAL_MODE="$(printf '%s' "$principal_resolved" | cut -f1)"
DRY_PRINCIPAL_NAME="$(printf '%s' "$principal_resolved" | cut -f2)"
case "$DRY_PRINCIPAL_MODE" in
login) DRY_PRINCIPAL_DESC="tea login '$DRY_PRINCIPAL_NAME'" ;;
identity) DRY_PRINCIPAL_DESC="git identity '$DRY_PRINCIPAL_NAME' (per-slot credential)" ;;
*) DRY_PRINCIPAL_DESC="default host credential" ;;
esac
if [[ "$CO_AUTHOR_TRAILERS" == true ]]; then if [[ "$CO_AUTHOR_TRAILERS" == true ]]; then
echo "Dry run: would verify PR commit authors and merge PR #$PR_NUMBER on $HOST with authenticated Gitea API message fields (base=$BASE_BRANCH, method=squash)." echo "Dry run: would verify PR commit authors and merge PR #$PR_NUMBER on $HOST as $DRY_PRINCIPAL_DESC with authenticated Gitea API message fields (base=$BASE_BRANCH, method=squash)."
else else
echo "Dry run: would merge PR #$PR_NUMBER on $HOST with the authenticated exact-head Gitea API path (base=$BASE_BRANCH, method=squash)." echo "Dry run: would merge PR #$PR_NUMBER on $HOST as $DRY_PRINCIPAL_DESC with the authenticated exact-head Gitea API path (base=$BASE_BRANCH, method=squash)."
fi fi
else else
echo "Dry run: would merge PR #$PR_NUMBER on $PLATFORM (base=$BASE_BRANCH, method=squash)." echo "Dry run: would merge PR #$PR_NUMBER on $PLATFORM (base=$BASE_BRANCH, method=squash)."
@@ -76,7 +76,7 @@ while [[ $# -gt 0 ]]; do
echo " -n, --number PR number (required)" echo " -n, --number PR number (required)"
echo " -a, --action Review action: approve, request-changes, comment (required)" echo " -a, --action Review action: approve, request-changes, comment (required)"
echo " -c, --comment Review comment (required for request-changes)" echo " -c, --comment Review comment (required for request-changes)"
echo " -l, --login Override the detected Gitea tea login (approve/request-changes only)" echo " -l, --login Override the detected Gitea tea login (all actions; wins over MOSAIC_GIT_IDENTITY)"
echo " -r, --repo Explicit owner/repo slug (skips git-remote slug inference)" echo " -r, --repo Explicit owner/repo slug (skips git-remote slug inference)"
echo " -H, --host Explicit Gitea host (skips remote-host inference)" echo " -H, --host Explicit Gitea host (skips remote-host inference)"
echo " -h, --help Show this help" echo " -h, --help Show this help"
@@ -346,7 +346,14 @@ gitea_resolve_api_for_login() {
else else
host=$(get_remote_host) host=$(get_remote_host)
fi fi
if [[ -n "$override_explicit" ]]; then if [[ "$override_explicit" == "identity" ]]; then
# Requested git identity (#1280): the per-slot token MUST resolve via
# get_gitea_token's identity arm; never borrow the tea default login.
GITEA_API_TOKEN=$(get_gitea_token "$host") || {
echo "Error: could not resolve the per-slot token for requested git identity '$effective_login' on host '$host'; refusing to fall back to the tea login list or shared credentials (review write/read-back, #1280)." >&2
return 1
}
elif [[ -n "$override_explicit" ]]; then
GITEA_API_TOKEN=$(get_gitea_token_for_login "$effective_login" "$host") || { GITEA_API_TOKEN=$(get_gitea_token_for_login "$effective_login" "$host") || {
echo "Error: could not resolve a host-matched Gitea token for --login '$effective_login' on host '$host'; refusing to fall back to the host default identity or a cross-host credential (review write/read-back)" >&2 echo "Error: could not resolve a host-matched Gitea token for --login '$effective_login' on host '$host'; refusing to fall back to the host default identity or a cross-host credential (review write/read-back)" >&2
return 1 return 1
@@ -676,29 +683,32 @@ if [[ "$PLATFORM" == "github" ]]; then
;; ;;
esac esac
elif [[ "$PLATFORM" == "gitea" ]]; then elif [[ "$PLATFORM" == "gitea" ]]; then
# Resolve the acting principal ONCE for every action, identity-first
# (#1280): an explicit --login wins; otherwise MOSAIC_GIT_IDENTITY /
# per-worktree git config mosaic.gitIdentity selects the principal when a
# per-slot token exists (fail-loud when it does not); the tea login list is
# the LAST resort — it enumerates whatever logins this host happens to hold
# and knows nothing about which seat is calling, so resolving from it first
# wrote under whichever account tea had configured (the #1280 family).
principal_host="${HOST_OVERRIDE:-$(get_remote_host 2>/dev/null || true)}"
if ! principal_resolved="$(resolve_gitea_principal "$LOGIN_OVERRIDE" "$principal_host")"; then
# resolve_gitea_principal already printed the fail-loud diagnostic.
exit 1
fi
PRINCIPAL_MODE="$(printf '%s' "$principal_resolved" | cut -f1)"
PRINCIPAL_NAME="$(printf '%s' "$principal_resolved" | cut -f2)"
case $ACTION in case $ACTION in
approve) approve)
# Best-effort host for the tea-login GUESS only (gitea_resolve_api_for_login # Identity-first principal resolution (#1280): PRINCIPAL_MODE /
# below re-derives the real host from HOST_OVERRIDE/remote independently and # PRINCIPAL_NAME were resolved once above from --login >
# is authoritative). Prefer an explicit -H/--host; otherwise best-effort # MOSAIC_GIT_IDENTITY / git config > tea login list (last resort).
# git-remote inference, tolerating its ABSENCE (a bare `get_remote_host` here if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# under `set -e`, with no origin and no -H, previously killed the script gitea_resolve_api_for_login "$PRINCIPAL_NAME" identity || exit 1
# SILENTLY — exit 1, zero output — even though -r/-H are exactly the flags elif [[ "$PRINCIPAL_MODE" == "login" ]]; then
# that support running with no usable origin at all). gitea_resolve_api_for_login "$PRINCIPAL_NAME" explicit || exit 1
host="${HOST_OVERRIDE:-$(get_remote_host 2>/dev/null || true)}" else
# A --login override always wins. Otherwise name this host's login gitea_resolve_api_for_login "$PRINCIPAL_NAME" "" || exit 1
# only as a best effort: the login name merely selects a per-login fi
# token, and gitea_resolve_api_for_login falls back to the host
# credential (get_gitea_token) when no tea login is named — so a host
# tea's login list need not enumerate exotic (e.g. ported) hosts for
# the default credential to resolve. The single resolved token is
# then used for the write, the /user identity, and the read-back.
EFFECTIVE_LOGIN="$LOGIN_OVERRIDE"
[[ -n "$EFFECTIVE_LOGIN" ]] || EFFECTIVE_LOGIN=$(get_gitea_login_for_host "$host" 2>/dev/null || true)
# Bind the REST endpoint + token to the effective login, then derive
# the acting identity from that SAME credential so the review submit
# and its read-back verify against the identity that performed them.
gitea_resolve_api_for_login "$EFFECTIVE_LOGIN" "${LOGIN_OVERRIDE:+explicit}" || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1 ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
head_sha=$(gitea_pr_head_sha "$PR_NUMBER") || exit 1 head_sha=$(gitea_pr_head_sha "$PR_NUMBER") || exit 1
# The review body (if any) travels with the review itself in the REST # The review body (if any) travels with the review itself in the REST
@@ -715,24 +725,16 @@ elif [[ "$PLATFORM" == "gitea" ]]; then
echo "Error: Comment required for request-changes" echo "Error: Comment required for request-changes"
exit 1 exit 1
fi fi
# Best-effort host for the tea-login GUESS only (gitea_resolve_api_for_login # Identity-first principal resolution (#1280): PRINCIPAL_MODE /
# below re-derives the real host from HOST_OVERRIDE/remote independently and # PRINCIPAL_NAME were resolved once above from --login >
# is authoritative). Prefer an explicit -H/--host; otherwise best-effort # MOSAIC_GIT_IDENTITY / git config > tea login list (last resort).
# git-remote inference, tolerating its ABSENCE (a bare `get_remote_host` here if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# under `set -e`, with no origin and no -H, previously killed the script gitea_resolve_api_for_login "$PRINCIPAL_NAME" identity || exit 1
# SILENTLY — exit 1, zero output — even though -r/-H are exactly the flags elif [[ "$PRINCIPAL_MODE" == "login" ]]; then
# that support running with no usable origin at all). gitea_resolve_api_for_login "$PRINCIPAL_NAME" explicit || exit 1
host="${HOST_OVERRIDE:-$(get_remote_host 2>/dev/null || true)}" else
# A --login override always wins. Otherwise name this host's login gitea_resolve_api_for_login "$PRINCIPAL_NAME" "" || exit 1
# only as a best effort: the login name merely selects a per-login fi
# token, and gitea_resolve_api_for_login falls back to the host
# credential (get_gitea_token) when no tea login is named — so a host
# tea's login list need not enumerate exotic (e.g. ported) hosts for
# the default credential to resolve. The single resolved token is
# then used for the write, the /user identity, and the read-back.
EFFECTIVE_LOGIN="$LOGIN_OVERRIDE"
[[ -n "$EFFECTIVE_LOGIN" ]] || EFFECTIVE_LOGIN=$(get_gitea_login_for_host "$host" 2>/dev/null || true)
gitea_resolve_api_for_login "$EFFECTIVE_LOGIN" "${LOGIN_OVERRIDE:+explicit}" || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1 ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
head_sha=$(gitea_pr_head_sha "$PR_NUMBER") || exit 1 head_sha=$(gitea_pr_head_sha "$PR_NUMBER") || exit 1
review_id=$(gitea_submit_review_verified "$PR_NUMBER" "REQUEST_CHANGES" "$COMMENT" "$ACTING_LOGIN" "$head_sha") || { review_id=$(gitea_submit_review_verified "$PR_NUMBER" "REQUEST_CHANGES" "$COMMENT" "$ACTING_LOGIN" "$head_sha") || {
@@ -746,24 +748,16 @@ elif [[ "$PLATFORM" == "gitea" ]]; then
echo "Error: Comment required" echo "Error: Comment required"
exit 1 exit 1
fi fi
# Best-effort host for the tea-login GUESS only (gitea_resolve_api_for_login # Identity-first principal resolution (#1280): PRINCIPAL_MODE /
# below re-derives the real host from HOST_OVERRIDE/remote independently and # PRINCIPAL_NAME were resolved once above from --login >
# is authoritative). Prefer an explicit -H/--host; otherwise best-effort # MOSAIC_GIT_IDENTITY / git config > tea login list (last resort).
# git-remote inference, tolerating its ABSENCE (a bare `get_remote_host` here if [[ "$PRINCIPAL_MODE" == "identity" ]]; then
# under `set -e`, with no origin and no -H, previously killed the script gitea_resolve_api_for_login "$PRINCIPAL_NAME" identity || exit 1
# SILENTLY — exit 1, zero output — even though -r/-H are exactly the flags elif [[ "$PRINCIPAL_MODE" == "login" ]]; then
# that support running with no usable origin at all). gitea_resolve_api_for_login "$PRINCIPAL_NAME" explicit || exit 1
host="${HOST_OVERRIDE:-$(get_remote_host 2>/dev/null || true)}" else
# A --login override always wins. Otherwise name this host's login gitea_resolve_api_for_login "$PRINCIPAL_NAME" "" || exit 1
# only as a best effort: the login name merely selects a per-login fi
# token, and gitea_resolve_api_for_login falls back to the host
# credential (get_gitea_token) when no tea login is named — so a host
# tea's login list need not enumerate exotic (e.g. ported) hosts for
# the default credential to resolve. The single resolved token is
# then used for the write, the /user identity, and the read-back.
EFFECTIVE_LOGIN="$LOGIN_OVERRIDE"
[[ -n "$EFFECTIVE_LOGIN" ]] || EFFECTIVE_LOGIN=$(get_gitea_login_for_host "$host" 2>/dev/null || true)
gitea_resolve_api_for_login "$EFFECTIVE_LOGIN" "${LOGIN_OVERRIDE:+explicit}" || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1 ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
comment_id=$(gitea_create_comment_verified "$PR_NUMBER" "$COMMENT" "$ACTING_LOGIN") || { comment_id=$(gitea_create_comment_verified "$PR_NUMBER" "$COMMENT" "$ACTING_LOGIN") || {
echo "Error: could not create and verify a comment on Gitea PR #$PR_NUMBER via a provider-returned created id (#865)." >&2 echo "Error: could not create and verify a comment on Gitea PR #$PR_NUMBER via a provider-returned created id (#865)." >&2
@@ -0,0 +1,255 @@
#!/usr/bin/env bash
# Regression harness for detect-platform.sh's resolve_gitea_principal() — the
# identity-first acting-principal resolution shared by the git wrappers
# (mosaicstack/stack #1280).
#
# The contract under test (precedence: --login > MOSAIC_GIT_IDENTITY /
# git config mosaic.gitIdentity > tea login list, which is the LAST resort):
# 1. identity env + per-slot token present -> mode=identity, principal=
# identity name, source names the identity's slot PATH (never a token
# value).
# 2. identity env + per-slot token ABSENT -> FAIL LOUD: nonzero, empty
# stdout, stderr naming the identity and the expected slot path.
# 3. identity env + --login -> --login wins (login mode resolves even when
# the identity has no slot — operator intent beats environment).
# 4. identity unset + no --login -> default mode: the tea login list
# resolves the principal exactly as before (preserved behavior).
# 5. no identity + no host-matching tea login -> default/host-credential
# (preserved behavior; absence is not an error on the default path).
# 6. identity on an UNRECOGNIZED host (no per-slot scheme) -> does not bind;
# default mode (containment, mirroring get_gitea_token).
# 7. --login with no host-bound token for that login -> FAIL LOUD, stderr
# naming the login and the host.
# 8. git config mosaic.gitIdentity is honored when the env var is unset.
# 9. The resolver NEVER emits a token value — stdout/stderr of every
# successful resolution must not contain the slot file's contents.
#
# Uses a stubbed tea binary, stubbed tea config.yml, stubbed credentials.json
# and stubbed per-slot token files under a fake HOME. NEVER reads real secrets.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/gitea-principal-resolution}"
FAKE_HOME="$WORK_DIR/home"
REPO_DIR="$WORK_DIR/repo"
BIN_DIR="$WORK_DIR/bin"
CREDENTIALS_FILE="$FAKE_HOME/.config/mosaic/credentials.json"
rm -rf "$WORK_DIR"
mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" "$FAKE_HOME/.config/tea" "$REPO_DIR" "$BIN_DIR"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
cat > "$CREDENTIALS_FILE" <<'JSON'
{
"gitea": {
"mosaicstack": {
"url": "https://git.mosaicstack.dev",
"token": "shared-mosaicstack-token"
},
"usc": {
"url": "https://git.uscllc.com",
"token": "shared-usc-token"
}
}
}
JSON
# tea's own config store: the source get_gitea_token_for_login reads. Logins
# "alice" (mosaicstack) and "bob-usc" (usc) carry sentinel token values that
# the assertions prove are NEVER emitted by the resolver.
cat > "$FAKE_HOME/.config/tea/config.yml" <<'YAML'
logins:
- name: alice
url: https://git.mosaicstack.dev
token: SECRET-alice-tea-token
- name: bob-usc
url: https://git.uscllc.com
token: SECRET-bob-usc-tea-token
YAML
# Stubbed tea: only what login resolution needs (`login list --output json`).
cat > "$BIN_DIR/tea" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
if [[ "$*" == "login list --output json" ]]; then
cat <<'JSON'
[
{"name":"alice","url":"https://git.mosaicstack.dev","default":true},
{"name":"bob-usc","url":"https://git.uscllc.com"}
]
JSON
exit 0
fi
exit 0
SH
chmod +x "$BIN_DIR/tea"
# Per-slot identity token with a sentinel value the assertions prove is never
# emitted (proving "token came from the identity's slot BY PATH, not by value").
echo -n "SECRET-agentX-slot-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentX.token"
fail=0
assert_eq() {
local desc="$1" expected="$2" actual="$3"
if [[ "$expected" != "$actual" ]]; then
echo "FAIL: $desc — expected '$expected', got '$actual'" >&2
fail=1
fi
}
assert_contains() {
local desc="$1" haystack="$2" needle="$3"
if [[ "$haystack" != *"$needle"* ]]; then
echo "FAIL: $desc — missing '$needle' in: $haystack" >&2
fail=1
fi
}
assert_not_contains() {
local desc="$1" haystack="$2" needle="$3"
if [[ "$haystack" == *"$needle"* ]]; then
echo "FAIL: $desc — must not contain '$needle', got: $haystack" >&2
fail=1
fi
}
# Runs resolve_gitea_principal for $1=login_override $2=host inside REPO_DIR
# (per-worktree git config resolves there) under a fake HOME, stubbed tea, and
# stubbed credentials. Extra env (e.g. MOSAIC_GIT_IDENTITY) via $@.
call_resolver() {
local login="$1" host="$2"; shift 2
(
cd "$REPO_DIR"
env -i HOME="$FAKE_HOME" PATH="$BIN_DIR:$PATH" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
DETECT_PLATFORM_SH="$SCRIPT_DIR/detect-platform.sh" "$@" \
bash -c 'source "$DETECT_PLATFORM_SH"; resolve_gitea_principal "$1" "$2"' _ "$login" "$host"
)
}
field() { printf '%s' "$1" | cut -f"$2"; }
# ---------------------------------------------------------------------------
# 1. Identity env + slot present -> identity mode, slot named BY PATH, and no
# token value ever emitted.
# ---------------------------------------------------------------------------
git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
out=$(call_resolver "" "git.mosaicstack.dev" MOSAIC_GIT_IDENTITY=agentX)
assert_eq "identity mode" "identity" "$(field "$out" 1)"
assert_eq "identity principal" "agentX" "$(field "$out" 2)"
assert_eq "identity slot source" \
"identity-slot:$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentX.token" \
"$(field "$out" 3)"
assert_not_contains "identity stdout leaks token" "$out" "SECRET"
# ---------------------------------------------------------------------------
# 2. Identity env + slot ABSENT -> fail loud: nonzero, empty stdout, stderr
# naming the identity and the expected slot path.
# ---------------------------------------------------------------------------
stderr_file="$WORK_DIR/stderr.tmp"
set +e
out=$(call_resolver "" "git.mosaicstack.dev" MOSAIC_GIT_IDENTITY=agentNoSlot 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -eq 0 ]]; then
echo "FAIL: missing slot — expected nonzero return, got 0 (stdout='$out')" >&2
fail=1
fi
if [[ -n "$out" ]]; then
echo "FAIL: missing slot — expected empty stdout, got '$out'" >&2
fail=1
fi
err=$(cat "$stderr_file")
assert_contains "missing slot names identity" "$err" "agentNoSlot"
assert_contains "missing slot names slot path" "$err" \
"$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentNoSlot.token"
assert_not_contains "missing-slot stderr leaks token" "$err" "SECRET"
# ---------------------------------------------------------------------------
# 3. Identity + --login -> --login wins. Also wins when the identity has NO
# slot (no identity check may veto an explicit login).
# ---------------------------------------------------------------------------
out=$(call_resolver "alice" "git.mosaicstack.dev" MOSAIC_GIT_IDENTITY=agentX)
assert_eq "login beats identity (mode)" "login" "$(field "$out" 1)"
assert_eq "login beats identity (principal)" "alice" "$(field "$out" 2)"
assert_eq "login source" "tea-login:alice" "$(field "$out" 3)"
out=$(call_resolver "alice" "git.mosaicstack.dev" MOSAIC_GIT_IDENTITY=agentNoSlot)
assert_eq "login beats slot-less identity" "login" "$(field "$out" 1)"
# ---------------------------------------------------------------------------
# 4. No identity, no --login -> default mode via the tea login list
# (preserved behavior).
# ---------------------------------------------------------------------------
out=$(call_resolver "" "git.mosaicstack.dev")
assert_eq "default mode" "default" "$(field "$out" 1)"
assert_eq "default principal" "alice" "$(field "$out" 2)"
assert_eq "default source" "tea-default" "$(field "$out" 3)"
# ---------------------------------------------------------------------------
# 5. No identity, no --login, no host-matching tea login -> default with the
# host credential (absence is not an error on the default path).
# ---------------------------------------------------------------------------
out=$(call_resolver "" "git.unknown.test")
assert_eq "no-match default mode" "default" "$(field "$out" 1)"
assert_eq "no-match default principal" "" "$(field "$out" 2)"
assert_eq "no-match default source" "host-credential" "$(field "$out" 3)"
# ---------------------------------------------------------------------------
# 6. Identity on an UNRECOGNIZED host -> does not bind; default mode
# (containment, mirroring get_gitea_token's scope).
# ---------------------------------------------------------------------------
out=$(call_resolver "" "github.com" MOSAIC_GIT_IDENTITY=agentX)
assert_eq "unrecognized host falls to default" "default" "$(field "$out" 1)"
# ---------------------------------------------------------------------------
# 7. --login with no host-bound token for that login -> fail loud, stderr
# naming the login and the host.
# ---------------------------------------------------------------------------
: > "$stderr_file"
set +e
out=$(call_resolver "ghost-login" "git.mosaicstack.dev" 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -eq 0 ]]; then
echo "FAIL: unknown --login — expected nonzero return, got 0 (stdout='$out')" >&2
fail=1
fi
err=$(cat "$stderr_file")
assert_contains "unknown login names login" "$err" "ghost-login"
assert_contains "unknown login names host" "$err" "git.mosaicstack.dev"
# A cross-host login (exists, but for usc) must ALSO fail loud for mosaicstack.
set +e
out=$(call_resolver "bob-usc" "git.mosaicstack.dev" 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -eq 0 ]]; then
echo "FAIL: cross-host --login — expected nonzero return, got 0" >&2
fail=1
fi
# ---------------------------------------------------------------------------
# 8. git config mosaic.gitIdentity honored when env is unset.
# ---------------------------------------------------------------------------
git -C "$REPO_DIR" config mosaic.gitIdentity agentX
out=$(call_resolver "" "git.mosaicstack.dev")
assert_eq "git-config identity mode" "identity" "$(field "$out" 1)"
assert_eq "git-config identity principal" "agentX" "$(field "$out" 2)"
git -C "$REPO_DIR" config --unset mosaic.gitIdentity
# ---------------------------------------------------------------------------
# 9. Cross-host slot layout: the usc slot path is chosen for the usc host.
# ---------------------------------------------------------------------------
echo -n "SECRET-agentX-usc-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-usc-agentX.token"
out=$(call_resolver "" "git.uscllc.com" MOSAIC_GIT_IDENTITY=agentX)
assert_eq "usc identity mode" "identity" "$(field "$out" 1)"
assert_eq "usc slot source" \
"identity-slot:$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-usc-agentX.token" \
"$(field "$out" 3)"
if [[ "$fail" -eq 0 ]]; then
echo "resolve_gitea_principal identity-first resolution regression passed"
fi
exit "$fail"
@@ -77,12 +77,30 @@ exit 0
SH SH
chmod +x "$BIN_DIR/tea" chmod +x "$BIN_DIR/tea"
# TRIPWIRE provider stub: this harness tests argv construction, so ANY curl
# call is a failure of that contract (and, before this stub existed, a LIVE
# write — the #1282#1287 incident: the seat's real HOME leaked a global
# mosaic.gitIdentity, flipping the wrapper into identity mode whose real
# per-slot token created real issues on the forge). Fail loudly instead.
cat > "$BIN_DIR/curl" <<'SH'
#!/usr/bin/env bash
echo "FAIL: body-safety harness reached a provider request — this test must never curl" >&2
exit 99
SH
chmod +x "$BIN_DIR/curl"
# Hermetic invocation: fake HOME (no credentials, no tea config, no token
# slots) and GIT_CONFIG_GLOBAL severed — `git config --get mosaic.gitIdentity`
# otherwise resolves the WORKSTATION's global identity (mos-dt-0 on the seat
# that wrote this) and reroutes the wrapper into identity mode (#1280 family).
( (
cd "$REPO_DIR" cd "$REPO_DIR"
PATH="$BIN_DIR:$PATH" \ env -i HOME="$WORK_DIR/home" PATH="$BIN_DIR:$PATH" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_TEST_RECEIVED="$RECEIVED_FILE" \ MOSAIC_TEST_RECEIVED="$RECEIVED_FILE" \
"$SCRIPT_DIR/issue-create.sh" -t "Body safety test" -b "$BODY" "$SCRIPT_DIR/issue-create.sh" -t "Body safety test" -b "$BODY"
) >/dev/null ) >/dev/null
mkdir -p "$WORK_DIR/home"
# 1. No command substitution executed anywhere in the pipeline. # 1. No command substitution executed anywhere in the pipeline.
if [[ -e "$SENTINEL" ]]; then if [[ -e "$SENTINEL" ]]; then
@@ -47,14 +47,31 @@ SH
chmod +x "$BIN_DIR/tea" "$BIN_DIR/curl" chmod +x "$BIN_DIR/tea" "$BIN_DIR/curl"
run_wrapper() { run_wrapper() {
# Hermetic: fake HOME (fixture credentials only, no token slots, no tea
# config) and GIT_CONFIG_GLOBAL severed — `git config --get
# mosaic.gitIdentity` otherwise resolves the WORKSTATION's global identity
# and reroutes the wrapper into identity mode before the tea paths this
# harness exercises (#1280 family; see test-issue-create-body-safety.sh).
# An `env …` prefix (used for MOSAIC_TEA_STALE_USER) is re-wrapped, not
# doubled: arguments beginning with "env" are shifted past.
local env_pairs=()
if [[ "${1:-}" == "env" ]]; then
shift
while [[ "$#" -gt 0 && "$1" == *=* ]]; do
env_pairs+=("$1")
shift
done
fi
( (
cd "$REPO_DIR" cd "$REPO_DIR"
PATH="$BIN_DIR:$PATH" \ env -i HOME="$WORK_DIR/home" PATH="$BIN_DIR:$PATH" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \ MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
MOSAIC_TEST_LOG="$LOG_FILE" \ MOSAIC_TEST_LOG="$LOG_FILE" "${env_pairs[@]}" \
"$@" "$@"
) )
} }
mkdir -p "$WORK_DIR/home"
: > "$LOG_FILE" : > "$LOG_FILE"
printf 'Interactive title\nInteractive body\nlabel-a,label-b\nM1\n' | run_wrapper "$SCRIPT_DIR/issue-create.sh" -i >/dev/null printf 'Interactive title\nInteractive body\nlabel-a,label-b\nM1\n' | run_wrapper "$SCRIPT_DIR/issue-create.sh" -i >/dev/null
@@ -0,0 +1,244 @@
#!/usr/bin/env bash
# Load-bearing regression harness for pr-create.sh identity-first principal
# resolution (mosaicstack/stack #1280).
#
# The failure this harness is written down to catch: `MOSAIC_GIT_IDENTITY=fargo
# pr-create.sh …` produces a PR attributed to `mos-dt-0` (whichever account the
# tea login list happens to hold). Before #1280 the identity-aware code existed
# but sat on the API arm that only ran when the tea path FAILED — tea succeeded,
# so the identity arm never executed, and every test that did not check ORDERING
# passed. This harness checks ordering directly:
#
# 1. identity set + slot present -> the PR is created via the REST API with
# the identity's per-slot token (asserted by sentinel value AT the fake
# provider), and tea's `pr create` is NEVER invoked.
# 2. identity set + slot ABSENT -> nonzero, stderr naming the identity and
# the expected slot path; neither tea `pr create` nor any API request
# fires. No silent fallback to the tea login list.
# 3. identity set + --login -> --login wins: tea runs WITH the explicit
# --login, no API request.
# 4. nothing set -> preserved behavior: tea path with the tea-list login.
#
# Uses a stubbed tea, a stubbed curl provider, stubbed credentials.json and
# per-slot token under a fake HOME. NEVER reads real secrets or hits a live
# forge — all assertions are against the stubs' logs.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-create-identity-first}"
FAKE_HOME="$WORK_DIR/home"
REPO_DIR="$WORK_DIR/repo"
TOOLS_DIR="$WORK_DIR/tools"
BIN_DIR="$WORK_DIR/bin"
LOG_FILE="$WORK_DIR/calls.log"
CREDENTIALS_FILE="$FAKE_HOME/.config/mosaic/credentials.json"
rm -rf "$WORK_DIR"
mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" "$FAKE_HOME/.config/tea" \
"$REPO_DIR" "$TOOLS_DIR/git" "$TOOLS_DIR/_lib" "$BIN_DIR"
# Fixture: the real scripts under test, copied so sibling stubs (and the
# ../_lib credential loader) resolve inside the fixture tree.
cp "$SCRIPT_DIR/pr-create.sh" "$TOOLS_DIR/git/pr-create.sh"
cp "$SCRIPT_DIR/detect-platform.sh" "$TOOLS_DIR/git/detect-platform.sh"
cp "$SCRIPT_DIR/../_lib/credentials.sh" "$TOOLS_DIR/_lib/credentials.sh"
chmod +x "$TOOLS_DIR/git/pr-create.sh"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
cat > "$CREDENTIALS_FILE" <<'JSON'
{
"gitea": {
"mosaicstack": {
"url": "https://git.mosaicstack.dev",
"token": "shared-mosaicstack-token"
}
}
}
JSON
cat > "$FAKE_HOME/.config/tea/config.yml" <<'YAML'
logins:
- name: alice
url: https://git.mosaicstack.dev
token: SECRET-alice-tea-token
YAML
echo -n "SECRET-agentX-slot-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentX.token"
: > "$LOG_FILE"
# Stubbed tea: records every invocation; `login list` feeds login resolution;
# `api --login <n> /user` feeds get_gitea_authenticated_user; `pr create` marks
# the marker file (its presence fails the identity-mode assertions).
cat > "$BIN_DIR/tea" <<SH
#!/usr/bin/env bash
set -euo pipefail
printf 'TEA: %s\n' "\$*" >> "$LOG_FILE"
if [[ "\$*" == "login list --output json" ]]; then
cat <<'JSON'
[
{"name":"alice","url":"https://git.mosaicstack.dev","default":true}
]
JSON
exit 0
fi
if [[ "\${1:-}" == "api" ]]; then
printf '%s\n' '{"login":"alice"}'
exit 0
fi
if [[ "\$*" == pr\ create* ]]; then
echo "TEA-PR-CREATE-INVOKED" >> "$LOG_FILE"
exit 0
fi
exit 0
SH
chmod +x "$BIN_DIR/tea"
# Stubbed provider: records the URL and the Authorization header VALUE it
# received, answers 201 with a created-PR object. The sentinel token values are
# synthetic fixtures — asserting them at the provider proves WHICH slot's
# credential carried the write.
cat > "$BIN_DIR/curl" <<SH
#!/usr/bin/env bash
set -euo pipefail
url=""
auth=""
while [[ \$# -gt 0 ]]; do
case "\$1" in
-H)
case "\$2" in
Authorization*) auth="\$2" ;;
esac
shift 2
;;
*) [[ -n "\$1" && "\$1" != -* ]] && url="\$1"
shift
;;
esac
done
printf 'CURL-URL: %s\nCURL-AUTH: %s\n' "\$url" "\$auth" >> "$LOG_FILE"
cat <<'JSON'
{"number": 1299, "html_url": "https://git.mosaicstack.dev/mosaicstack/stack/pulls/1299"}
JSON
exit 0
SH
chmod +x "$BIN_DIR/curl"
fail=0
assert_contains() {
local desc="$1" needle="$2"
if ! grep -qF -- "$needle" "$LOG_FILE"; then
echo "FAIL: $desc — log does not contain '$needle':" >&2
cat "$LOG_FILE" >&2
fail=1
fi
}
assert_not_contains() {
local desc="$1" needle="$2"
if grep -qF -- "$needle" "$LOG_FILE"; then
echo "FAIL: $desc — log must not contain '$needle':" >&2
cat "$LOG_FILE" >&2
fail=1
fi
}
EXTRA_ARGS=""
run_pr_create() {
# "$@" carries ONLY environment assignments (VAR=value); EXTRA_ARGS (if
# set) carries wrapper arguments, so `env` never mistakes a wrapper flag
# like --login for one of its own.
(
cd "$REPO_DIR"
# shellcheck disable=SC2086 # EXTRA_ARGS is deliberately word-split wrapper args
env -i HOME="$FAKE_HOME" PATH="$BIN_DIR:$PATH" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" "$@" \
bash "$TOOLS_DIR/git/pr-create.sh" -t "Test PR" -B next -H fix/test $EXTRA_ARGS
)
}
# ---------------------------------------------------------------------------
# 1. HAPPY PATH (the load-bearing ordering test): identity set + slot present
# -> REST API with the per-slot token; tea `pr create` NEVER invoked.
# ---------------------------------------------------------------------------
set +e
out=$(run_pr_create MOSAIC_GIT_IDENTITY=agentX 2>"$WORK_DIR/stderr-1.tmp")
rc=$?
set -e
if [[ "$rc" -ne 0 ]]; then
echo "FAIL: identity happy path — expected rc=0, got $rc" >&2
cat "$WORK_DIR/stderr-1.tmp" >&2
fail=1
fi
assert_contains "identity happy path reaches the API" "CURL-URL: https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/pulls"
assert_contains "identity happy path carries the slot token" "CURL-AUTH: Authorization: token SECRET-agentX-slot-token"
assert_not_contains "identity happy path must NOT invoke tea pr create" "TEA-PR-CREATE-INVOKED"
# ---------------------------------------------------------------------------
# 2. Identity set + slot ABSENT -> fail loud BEFORE any write: nonzero, stderr
# naming identity + slot path, no tea pr create, no API request.
# ---------------------------------------------------------------------------
: > "$LOG_FILE"
set +e
out=$(run_pr_create MOSAIC_GIT_IDENTITY=agentNoSlot 2>"$WORK_DIR/stderr-2.tmp")
rc=$?
set -e
if [[ "$rc" -eq 0 ]]; then
echo "FAIL: missing slot — expected nonzero return, got 0 (stdout='$out')" >&2
fail=1
fi
err=$(cat "$WORK_DIR/stderr-2.tmp")
if [[ "$err" != *"agentNoSlot"* ]]; then
echo "FAIL: missing slot — stderr does not name the identity:" >&2
echo "$err" >&2
fail=1
fi
if [[ "$err" != *"$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentNoSlot.token"* ]]; then
echo "FAIL: missing slot — stderr does not name the expected slot path:" >&2
echo "$err" >&2
fail=1
fi
assert_not_contains "missing slot must not reach tea pr create" "TEA-PR-CREATE-INVOKED"
assert_not_contains "missing slot must not reach the API" "CURL-URL"
# ---------------------------------------------------------------------------
# 3. Identity set + --login -> --login wins: tea runs WITH the explicit login.
# ---------------------------------------------------------------------------
: > "$LOG_FILE"
EXTRA_ARGS="--login alice"
set +e
out=$(run_pr_create MOSAIC_GIT_IDENTITY=agentX 2>"$WORK_DIR/stderr-3.tmp")
rc=$?
set -e
EXTRA_ARGS=""
if [[ "$rc" -ne 0 ]]; then
echo "FAIL: login override — expected rc=0, got $rc" >&2
cat "$WORK_DIR/stderr-3.tmp" >&2
fail=1
fi
assert_contains "login override drives tea with the explicit login" "TEA: pr create --repo mosaicstack/stack --login alice"
assert_not_contains "login override must not hit the API" "CURL-URL"
# ---------------------------------------------------------------------------
# 4. Nothing set -> preserved behavior: tea path with the tea-list login.
# ---------------------------------------------------------------------------
: > "$LOG_FILE"
set +e
out=$(run_pr_create 2>"$WORK_DIR/stderr-4.tmp")
rc=$?
set -e
if [[ "$rc" -ne 0 ]]; then
echo "FAIL: default path — expected rc=0, got $rc" >&2
cat "$WORK_DIR/stderr-4.tmp" >&2
fail=1
fi
assert_contains "default path still uses the tea-list login" "TEA: pr create --repo mosaicstack/stack --login alice"
if [[ "$fail" -eq 0 ]]; then
echo "pr-create identity-first happy-path regression passed"
fi
exit "$fail"
@@ -0,0 +1,247 @@
#!/usr/bin/env bash
# Regression harness for pr-merge.sh identity-first principal resolution
# (mosaicstack/stack #1280).
#
# Covers:
# 1. --dry-run reports the acting principal the merge WOULD use, resolved the
# same way the real merge resolves it: --login > MOSAIC_GIT_IDENTITY /
# git config mosaic.gitIdentity > shared host credential. (The pre-#1280
# deployed copy reported a tea login that the merge would not act as.)
# 2. --dry-run fails closed when the requested principal has no credential:
# unknown --login, or an identity with no per-slot token (stderr names
# the login / the identity and its slot path).
# 3. The real merge POST carries the resolved principal's credential and no
# other: --login merges with that login's tea-config token; an identity
# merges with the per-slot token; an unresolvable --login never reaches
# the provider.
#
# Fixture pattern from test-pr-merge-head-pin.sh: the scripts under test are
# copied into a fixture tree with stubbed pr-metadata.sh / ci-queue-wait.sh
# siblings; the provider is a stubbed curl that records the credential it
# received. NEVER reads real secrets or hits a live forge.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-merge-principal-resolution}"
FAKE_HOME="$WORK_DIR/home"
REPO_DIR="$WORK_DIR/repo"
TOOLS_DIR="$WORK_DIR/tools"
BIN_DIR="$WORK_DIR/bin"
LOG_FILE="$WORK_DIR/calls.log"
CREDENTIALS_FILE="$FAKE_HOME/.config/mosaic/credentials.json"
SHA=0123456789abcdef0123456789abcdef01234567
rm -rf "$WORK_DIR"
mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" "$FAKE_HOME/.config/tea" \
"$REPO_DIR" "$TOOLS_DIR/git" "$TOOLS_DIR/_lib" "$BIN_DIR"
cp "$SCRIPT_DIR/pr-merge.sh" "$TOOLS_DIR/git/pr-merge.sh"
cp "$SCRIPT_DIR/detect-platform.sh" "$TOOLS_DIR/git/detect-platform.sh"
cp "$SCRIPT_DIR/../_lib/credentials.sh" "$TOOLS_DIR/_lib/credentials.sh"
chmod +x "$TOOLS_DIR/git/pr-merge.sh"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
# Stubbed siblings pr-merge.sh resolves relative to its own SCRIPT_DIR.
cat > "$TOOLS_DIR/git/pr-metadata.sh" <<SH
#!/usr/bin/env bash
printf '%s\n' '{"baseRefName":"next","headRefName":"fix/pinned","headRefOid":"$SHA","headRepository":"mosaicstack/stack","title":"Test PR","author":{"login":"contributor"}}'
SH
cat > "$TOOLS_DIR/git/ci-queue-wait.sh" <<'SH'
#!/usr/bin/env bash
exit 0
SH
chmod +x "$TOOLS_DIR/git/pr-metadata.sh" "$TOOLS_DIR/git/ci-queue-wait.sh"
cat > "$CREDENTIALS_FILE" <<'JSON'
{
"gitea": {
"mosaicstack": {
"url": "https://git.mosaicstack.dev",
"token": "shared-mosaicstack-token"
}
}
}
JSON
cat > "$FAKE_HOME/.config/tea/config.yml" <<'YAML'
logins:
- name: fred-ms
url: https://git.mosaicstack.dev
token: SECRET-fred-ms-tea-token
YAML
echo -n "SECRET-agentX-slot-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentX.token"
: > "$LOG_FILE"
# Stubbed tea for login-list resolution only.
cat > "$BIN_DIR/tea" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
if [[ "$*" == "login list --output json" ]]; then
cat <<'JSON'
[
{"name":"fred-ms","url":"https://git.mosaicstack.dev","default":true}
]
JSON
exit 0
fi
exit 0
SH
chmod +x "$BIN_DIR/tea"
# Stubbed provider. pr-merge passes curl config on STDIN with -K -; the stub
# reads stdin, records the Authorization header it received, answers 200.
cat > "$BIN_DIR/curl" <<SH
#!/usr/bin/env bash
set -euo pipefail
url=""
out_file=""
stdin_config=""
if [[ ! -t 0 ]]; then
stdin_config="\$(cat || true)"
fi
while [[ \$# -gt 0 ]]; do
case "\$1" in
-o) out_file="\$2"; shift 2 ;;
-K|-w|--max-filesize|--max-time|--connect-timeout|-sS) shift 2 ;;
*) [[ -n "\$1" && "\$1" != -* && -z "\$url" ]] && url="\$1"
shift
;;
esac
done
auth="\$(printf '%s' "\$stdin_config" | grep -o 'Authorization: token [^"]*' || true)"
printf 'CURL-URL: %s\nCURL-AUTH: %s\n' "\$url" "\$auth" >> "$LOG_FILE"
[[ -n "\$out_file" ]] && printf '{}' > "\$out_file"
printf '200\n'
exit 0
SH
chmod +x "$BIN_DIR/curl"
fail=0
assert_contains_log() {
local desc="$1" needle="$2"
if ! grep -qF -- "$needle" "$LOG_FILE"; then
echo "FAIL: $desc — log does not contain '$needle':" >&2
cat "$LOG_FILE" >&2
fail=1
fi
}
assert_not_contains_log() {
local desc="$1" needle="$2"
if grep -qF -- "$needle" "$LOG_FILE"; then
echo "FAIL: $desc — log must not contain '$needle':" >&2
cat "$LOG_FILE" >&2
fail=1
fi
}
run_pr_merge() {
local extra_args="$1"; shift
(
cd "$REPO_DIR"
# shellcheck disable=SC2086 # extra_args is deliberately word-split wrapper args
env -i HOME="$FAKE_HOME" PATH="$BIN_DIR:$PATH" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" "$@" \
bash "$TOOLS_DIR/git/pr-merge.sh" -n 42 $extra_args
)
}
# ---------------------------------------------------------------------------
# 1. --dry-run reports the resolved acting principal truthfully.
# ---------------------------------------------------------------------------
out=$(run_pr_merge "--dry-run" MOSAIC_GIT_IDENTITY=agentX)
if [[ "$out" != *"as git identity 'agentX' (per-slot credential)"* ]]; then
echo "FAIL: dry-run identity — principal not reported: $out" >&2
fail=1
fi
out=$(run_pr_merge "--dry-run --login fred-ms" MOSAIC_GIT_IDENTITY=agentX)
if [[ "$out" != *"as tea login 'fred-ms'"* ]]; then
echo "FAIL: dry-run login override — login not reported (must beat env identity): $out" >&2
fail=1
fi
out=$(run_pr_merge "--dry-run")
if [[ "$out" != *"as default host credential"* ]]; then
echo "FAIL: dry-run default — not reported: $out" >&2
fail=1
fi
# ---------------------------------------------------------------------------
# 2. --dry-run fails closed when the requested principal has no credential.
# ---------------------------------------------------------------------------
stderr_file="$WORK_DIR/stderr.tmp"
set +e
out=$(run_pr_merge "--dry-run --login ghost" 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -eq 0 ]] || [[ "$(cat "$stderr_file")" != *"ghost"* ]]; then
echo "FAIL: dry-run unknown --login — expected fail-loud naming 'ghost', rc=$rc" >&2
cat "$stderr_file" >&2
fail=1
fi
: > "$stderr_file"
set +e
out=$(run_pr_merge "--dry-run" MOSAIC_GIT_IDENTITY=agentNoSlot 2>"$stderr_file")
rc=$?
set -e
err=$(cat "$stderr_file")
if [[ "$rc" -eq 0 ]] || [[ "$err" != *"agentNoSlot"* ]] \
|| [[ "$err" != *"$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentNoSlot.token"* ]]; then
echo "FAIL: dry-run identity without slot — expected fail-loud naming identity + slot path, rc=$rc" >&2
echo "$err" >&2
fail=1
fi
# ---------------------------------------------------------------------------
# 3. The real merge POST carries the resolved principal's credential ONLY.
# ---------------------------------------------------------------------------
: > "$LOG_FILE"
set +e
out=$(run_pr_merge "--login fred-ms" MOSAIC_GIT_IDENTITY=agentX 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -ne 0 ]]; then
echo "FAIL: merge with --login — expected rc=0, got $rc" >&2
cat "$stderr_file" >&2
fail=1
fi
assert_contains_log "merge --login uses the login token" "CURL-AUTH: Authorization: token SECRET-fred-ms-tea-token"
assert_not_contains_log "merge --login must not use the identity slot token" "SECRET-agentX-slot-token"
assert_not_contains_log "merge --login must not use the shared token" "shared-mosaicstack-token"
: > "$LOG_FILE"
set +e
out=$(run_pr_merge "" MOSAIC_GIT_IDENTITY=agentX 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -ne 0 ]]; then
echo "FAIL: merge with identity — expected rc=0, got $rc" >&2
cat "$stderr_file" >&2
fail=1
fi
assert_contains_log "merge identity uses the per-slot token" "CURL-AUTH: Authorization: token SECRET-agentX-slot-token"
assert_not_contains_log "merge identity must not use the shared token" "shared-mosaicstack-token"
: > "$LOG_FILE"
set +e
out=$(run_pr_merge "--login ghost" 2>"$stderr_file")
rc=$?
set -e
if [[ "$rc" -eq 0 ]]; then
echo "FAIL: merge with unknown --login — expected nonzero, got 0" >&2
fail=1
fi
assert_not_contains_log "merge with unknown --login must not reach the provider" "CURL-URL"
if [[ "$fail" -eq 0 ]]; then
echo "pr-merge identity-first principal resolution regression passed"
fi
exit "$fail"
+1 -1
View File
@@ -25,7 +25,7 @@
"lint": "eslint src", "lint": "eslint src",
"typecheck": "tsc --noEmit", "typecheck": "tsc --noEmit",
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell", "test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/promotion_binding_unittest.py && python3 src/lease-broker/promotion_trigger_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/receipt_observer_client_unittest.py && python3 src/lease-broker/invariant_r_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-pr-merge-message-field.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/_scripts/test-mosaic-init-rce.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh && bash framework/tools/glpi/test-list-http-status.sh && bash framework/tools/orchestrator/test-board-roll.sh && bash framework/tools/woodpecker/test-ci-wait-exit-matrix.sh && bash framework/tools/_scripts/test-fleet-transport-check.sh" "test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/promotion_binding_unittest.py && python3 src/lease-broker/promotion_trigger_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/receipt_observer_client_unittest.py && python3 src/lease-broker/invariant_r_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-pr-merge-message-field.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/git/test-gitea-principal-resolution.sh && bash framework/tools/git/test-pr-create-identity-first.sh && bash framework/tools/git/test-pr-merge-principal-resolution.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/_scripts/test-mosaic-init-rce.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh && bash framework/tools/glpi/test-list-http-status.sh && bash framework/tools/orchestrator/test-board-roll.sh && bash framework/tools/woodpecker/test-ci-wait-exit-matrix.sh && bash framework/tools/_scripts/test-fleet-transport-check.sh"
}, },
"dependencies": { "dependencies": {
"@mosaicstack/brain": "workspace:*", "@mosaicstack/brain": "workspace:*",