Compare commits

..

13 Commits

Author SHA1 Message Date
Hermes Agent
16481ece3d fix(tools): attribute read-back to acting identity and paginate fully (#865)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
Round 2 remediation for the read-back verification in issue-comment.sh and
pr-review.sh.

BLOCKER A (invocation attribution): id-above-boundary + content/state match
only proves temporal ordering — a concurrent write from a different identity
could satisfy it while this tea invocation created nothing. Both wrappers now
resolve the acting identity once via curl GET /api/v1/user and additionally
require the accepted record's author login to equal that identity. Residual
same-identity same-body/state concurrency is documented in-code (tea 0.11.1
emits no reliable created-record id to close it further).

BLOCKER B (pagination): the comments and reviews list reads now walk every
page (?limit=&page=1,2,… until a short/empty page) for both the pre-write
boundary and the post-write read-back, so a record beyond page 1 is still
found.

Adds regressions: concurrent different-identity write fails closed (comments
and reviews); a matching review beyond page 1 is still found. README updated.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 19:02:25 -05:00
Hermes Agent
10fdd49e32 fix(tools): bound Gitea read-back to this write; verify approve/reject state (#865)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
Review remediation for two correctness holes in the #865 fix:

BLOCKER 1 — issue-comment.sh read-back was body-only across all history:
if `tea comment` silently no-opped (the #865 bug) while an identically
bodied comment already existed from a prior run, the read-back matched the
OLD comment and falsely reported success. Now record the pre-write maximum
comment id as a boundary and require a comment with id > boundary AND exact
body match; monotonic Gitea ids make id > boundary mean "created by this
write". Fails closed otherwise.

BLOCKER 2 — pr-review.sh approve/reject trusted tea's exit code for the
review STATE (same never-trust-exit-zero defect class as #865). Removed the
TODO deferral and added a real bounded read-back: record the max review id
before `tea pr approve`/`reject`, then require a review with id > boundary,
the expected state (APPROVED / REQUEST_CHANGES), and commit_id equal to the
PR's current head. Fails closed if absent.

Tests: extended test-pr-review-gitea-comment.sh to model and assert the new
review-state read-back (guardrails preserved, assertions added). Added
test-issue-comment-readback.sh proving the pre-existing-identical-body
false positive now fails closed and a genuinely new comment verifies.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:21:02 -05:00
Hermes Agent
a27f1fa7df fix(tools): use top-level tea comment invocation and formalize --login passthrough (#865)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
issue-comment.sh called the non-existent `tea issue comment` subcommand
form; tea 0.11.1 silently no-ops and exits 0 instead of erroring, producing
a false-success write. Switch to the top-level `tea comment <index> <body>`
form and add fail-closed REST read-back verification so the wrapper no
longer trusts tea's exit code alone.

pr-review.sh's comment path was already fixed for this bug by #812/#835
(routes through a read-back-verified REST comment API instead of any
tea comment subcommand); this change formalizes an explicit --login
override flag there too and documents the after-detection last-wins
--login ordering, consistent with issue-comment.sh.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 17:50:43 -05:00
4e5af23214 Merge pull request 'skills: add glpi-* family (solve, followup, sweep, list, create)' (#863) from feat/glpi-skills into main
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-21 01:09:50 +00:00
Hermes Agent
880c28b191 docs(glpi-skills): genericize operator-specific content per review
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
2026-07-20 19:45:50 -05:00
Jason Woltje
7bc2dfb6c8 skills: add glpi-* family (solve, followup, sweep, list, create)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
GLPI helpdesk workflow skills written against the portable
tools/glpi/ tooling (session-init.sh, ticket-list.sh, ticket-create.sh),
cross-linked via [[glpi-*]]:

- glpi-solve    — close a ticket by setting status Solved (5); GLPI auto-closes
- glpi-followup — add a followup via the top-level /ITILFollowup endpoint
- glpi-sweep    — read-only hunt for done-but-open tickets needing Solve
- glpi-list     — query tickets by status/recency
- glpi-create   — open a new ticket

Core rule encoded: completing work means setting status Solved, not just
posting a resolution followup (a followup documents; only Solved auto-closes).

Note: illustrative examples in the bodies are USC-flavored (M2M / helpdesk
ticket numbers) and can be genericized in review if preferred.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019GjBgrb9tHgvq414Fqj37c
2026-07-20 18:04:53 -05:00
b0d78d8632 fix(mosaic): de-flake mutator-class lease gate TTL-expiry test (#861)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-20 10:32:45 +00:00
344d86a635 fix(#812 follow-up): normalize detect-platform.sh host-match port comparison by scheme (#859)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-20 10:13:29 +00:00
acd7d380f6 fix(framework): install deps on worktree bootstrap + legible deps-preflight at gate seam (#856) (#858)
Some checks failed
ci/woodpecker/push/ci Pipeline failed
ci/woodpecker/push/publish Pipeline was successful
2026-07-20 09:38:12 +00:00
3b70c66c07 fix(framework): drop unsupported --comment from tea pr approve/reject; route review body via durable comment (#835) (#857)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-20 09:19:48 +00:00
11d2818453 docs(tasks): FCM-M5-001 done — verified completion evidence (supersedes #848) (#853)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-20 07:45:08 +00:00
aa999daf1b fix(framework): durable Gitea comment posting in pr-review.sh via REST + read-back verify (#812) (#852)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
2026-07-20 06:45:48 +00:00
77c9a82614 fix(lease-broker): de-flake recovery_runtime b2 broker-socket ConnectionRefused race (#849) (#851)
Some checks failed
ci/woodpecker/push/publish Pipeline was canceled
ci/woodpecker/push/ci Pipeline was canceled
2026-07-20 06:44:37 +00:00
18 changed files with 2102 additions and 21 deletions

View File

@@ -64,7 +64,7 @@ Active workstream is **W1 — Federation v1**. Workers should:
| FCM-M3-002 | in-progress | Add isolated systemd/tmux lifecycle, drift, socket, unmanaged-session, crash, and rollback acceptance coverage | #758 | sonnet | mosaicstack/stack | `test/758-reconciler-lifecycle-gates` | FCM-M3-001 | 25K | Canonical v2 named-socket + legacy-v1 default-server boundaries; fake adapters/temp fixtures only |
| FCM-M4-001 | done | Implement field-complete v1-to-v2 inventory/preview/migrator with alias, lifecycle, env-quarantine, and remote/connector disposition evidence | #758 | codex | mosaicstack/stack | `feat/758-v1-v2-migrator` | FCM-M1-003, FCM-M3-001 | 35K | PR #788; final head `d63bb0206a1d312ab8352ec1d3ca3631146b0baa`; tree `4da210da9a71b035130d4160a4a2e691bdfde2da`; squash `9745bc3f29c26b021a478b7ad03cfb494f6c9de3`; descendant-main pipeline 1855 terminal success |
| FCM-M4-002 | not-started | Add reversible canary migration, rollback, stale-projection/orphan classification, and current-host 9-managed/3-unmanaged fixture coverage | #758 | sonnet | mosaicstack/stack | `test/758-migration-rollback-gates` | FCM-M4-001, FCM-M3-002 | 25K | HOLD: never starts a previously stopped agent or kills an unproven unmanaged session; not authorized by FCM-M5-001 |
| FCM-M5-001 | in-progress | Deliver the accepted fleet documentation IA, how-to/operations/migration references, and link/example validation | #758 | haiku | mosaicstack/stack | `docs/758-fleet-config-operator-docs` | FCM-M1-003, FCM-M2-002, FCM-M3-001, FCM-M4-001 | 24K | Sole owner: this FCM-M5-001 delivery on the recorded branch; must close every checklist item or record an approved deferral |
| FCM-M5-001 | done | Deliver the accepted fleet documentation IA, how-to/operations/migration references, and link/example validation | #758 | haiku | mosaicstack/stack | `docs/758-fleet-config-operator-docs` | FCM-M1-003, FCM-M2-002, FCM-M3-001, FCM-M4-001 | 24K | #789 content squash 627cf2bb; de-flake repair PR#851/#849 squash 77c9a826; completion proof wp1937 @aa999daf push/ci step 49632 recovery_runtime_unittest.py 3/3 OK (closes wp1932 step 49576 Errno111) |
| FCM-M5-002 | not-started | Package/update asset-drift checks, rolling local canary, independent validation certificate, and release evidence | #758 | sonnet | mosaicstack/stack | `feat/758-fleet-config-release-gate` | FCM-M3-002, FCM-M4-002, FCM-M5-001 | 30K | HOLD: final #758 gate; quality, independent code/security review, validator certificate, merge-gate approval, and green CI remain out of M5-001 |
## Thin-core prompt diet (#528) — feat/contract-thin-core

View File

@@ -0,0 +1,58 @@
# Issue #812 — durable Gitea PR review comments
- **Lane:** ms-812
- **Branch:** `fix/812-pr-review-comment`
- **Issue:** mosaicstack/stack#812
- **Budget:** 15K working estimate; single focused shell-wrapper/test/docs change.
## Objective
Make the Gitea `comment` action in `packages/mosaic/framework/tools/git/pr-review.sh` use the supported Gitea comments REST API and report success only after provider read-back verifies the created comment against the intended repository, PR, and exact body.
## Plan
1. Add and commit a failing shell regression harness before production changes.
2. Verify RED against the nonexistent `tea pr comment` fallback false-positive.
3. Implement the minimal supported write plus ID-based provider read-back.
4. Document that wrapper write output is not durable provenance until read-back succeeds.
5. Run focused regression tests, touched-package tests, and repository quality gates.
6. Remediate review findings, queue-guard, and push for coordinator-owned independent review. Do not open or merge a PR.
## Progress checkpoints
- [x] RED regression committed and reported to mosaic-100 (rebased commit `770e3f57`)
- [x] Initial minimal fix implemented (rebased commit `ea7f8c57`)
- [x] Rebased cleanly onto main `627cf2bb387f7c84a532d88819903a7679ce0d72`
- [x] Codex blocker remediated by replacing unsupported `tea api` with authenticated REST write/read-back
- [x] Focused, package, and repository gates green
- [ ] Coordinator-owned independent review pending after push
- [x] No PR opened; no self-review or self-merge
## Tests run
- RED after rebase: the regression harness failed against `origin/main` with status 1 after reproducing the old `tea pr comment` zero-exit fallback and false success echo.
- GREEN at resumed head: the same harness passed with REST POST 201 plus GET 200 read-back.
- All `packages/mosaic/framework/tools/git/test-*.sh` harnesses passed.
- `shellcheck -x` passed for the changed scripts; `bash -n` passed.
- Manifest resolver returned `framework` for `tools/git/test-pr-review-gitea-comment.sh`.
- `pnpm test` passed (43/43 Turbo tasks; Mosaic 75 files/1434 tests; Gateway 56 files/628 tests plus documented skips).
- `pnpm typecheck` passed (42/42 tasks), `pnpm lint` passed (23/23), and `pnpm format:check` passed.
- Firewall checks found no user-home paths or operator identities in changed shipped files; no token value is logged or echoed.
## Risks / blockers
- No active implementation blocker. #789 reached terminal merged state and the coordination hold was lifted.
- Review round 1 found one portability blocker: the API base reconstructed `https://$host` and discarded configured schemes/path prefixes.
- Review round 2 found a second subpath portability blocker: clone-derived `get_repo_slug` retained the deployment prefix, duplicating it under `/api/v1/repos/`.
- Round 3 resolves owner/repo relative to the configured Gitea base path for HTTP(S) clones while preserving root-mounted and SSH clone forms. Host matching now compares non-default ports consistently.
- REST transport failures, non-201 writes, malformed/missing created IDs, non-200 read-backs, and read-back mismatches all fail closed.
- Existing approve/request-changes behavior remains covered.
- Independent exact-head re-review remains coordinator-owned.
## Final verification evidence
- URL-portability regression was RED before remediation at the new `http://git.mosaicstack.dev` case and GREEN afterward.
- Round-3 genuine subpath regression was RED against round-2 head `1b190201` and GREEN after the fix: `https://git.example/gitea/owner/repo.git` maps to API repository `owner/repo` under configured base `/gitea`.
- Regression coverage verifies POST and read-back GET for root-mounted HTTP(S), path-prefixed HTTP(S), non-default HTTP port, scp-style SSH, and `ssh://` clone forms.
- Focused shell checks, all git-wrapper harnesses, and full repository test/typecheck/lint/format gates passed after remediation.
- Branch will be force-pushed with lease for coordinator re-verification; no PR opened.

View File

@@ -0,0 +1,26 @@
# Git provider wrappers
These scripts provide host-aware GitHub and Gitea issue, pull-request, milestone, and CI operations.
## Durable review provenance
A successful provider write command—or a wrapper message based only on that command's exit code—is **not** durable review provenance. Review comments, approvals, and change requests count as durable provenance only after the wrapper reads the created provider record back and verifies that it was created by _this_ write.
`pr-review.sh` therefore fails closed when a Gitea comment cannot be written, its created comment ID cannot be identified, or provider read-back does not match. It reports comment success only after that read-back verification passes. The `approve` and `request-changes` actions apply the same discipline to the review **state** itself: they record the maximum existing review id _before_ invoking `tea pr approve`/`reject`, then require a review whose id is strictly greater than that boundary, whose **author login equals the acting identity** (resolved via `GET /api/v1/user` for the token in use), whose state matches the requested action (`APPROVED` / `REQUEST_CHANGES`), and whose reviewed commit equals the PR's current head. tea's exit code alone is never treated as evidence the review landed.
`issue-comment.sh` applies the same fail-closed, boundary-bounded read-back to issue comments: it records the maximum existing comment id _before_ posting via `tea comment`, then re-fetches the issue's comments via the Gitea REST API and requires a comment whose id is strictly greater than that boundary, **whose author login equals the acting identity**, **and** whose body exactly matches what was submitted. Bounding the read-back by the pre-write id is essential — a body-only match across all history would falsely report success if `tea comment` silently no-ops (the #865 bug) while an identically-bodied comment already existed from a prior run. Gitea comment and review ids are monotonic, so `id > boundary` reliably means "created after this write began".
**Invocation attribution, not just temporal ordering.** `id > boundary` alone only proves a record was created after the write began; it would still be satisfied by a _concurrent_ write from a _different_ identity while this `tea` invocation created nothing. Both wrappers therefore additionally require the accepted record's author login to equal the identity the API token authenticates as, narrowing the match to this invocation's writer. The one residual window — a concurrent write by the _same_ identity with an identical body/state inside the boundary window — cannot be eliminated without a tea-emitted created-record id, which tea 0.11.1 does not reliably provide; it is strictly narrower than temporal-only matching and is documented in-code.
**Full pagination.** Gitea paginates list endpoints, so a single-page read of the comments or reviews list would false-negative once the freshly created record lands beyond the first page. Both the pre-write boundary computation and the post-write read-back walk every page (`?limit=&page=1,2,…` until a short/empty page) so the match is exhaustive regardless of how many comments or reviews already exist.
## `tea` invocation notes (Gitea)
- tea v0.11.1 has **no `comment` subcommand under `tea pr` or `tea issue`**. The correct invocation is the **top-level** `tea comment <index> <body> [--repo ...] [--login ...]`. The `tea pr comment` / `tea issue comment` forms don't error — tea silently falls through to a no-op and still exits 0, producing a false-success write (#865). Always use the top-level form.
- `tea pr approve` and `tea pr reject` take an optional review comment/reason as a **trailing positional argument**, not a `--comment`/`-comment` flag (that flag does not exist on those subcommands). `pr-review.sh` avoids this positional form entirely for the approve/reject actions and instead posts any review comment through the same durable, read-back-verified comment API used for the `comment` action (see #835/#812) — the trailing-positional form remains available to callers who invoke `tea` directly, but is not used by these wrappers.
### `--login` passthrough
Both `pr-review.sh` and `issue-comment.sh` accept an optional `--login <name>` flag that overrides the automatically detected Gitea `tea` login for that single invocation. The override is appended to the `tea` command line **after** the detected default (`get_gitea_repo_args()` / `get_gitea_login[_for_host]()`), because tea honors only the **last** `--login` flag on its command line — an override placed before the default would be silently clobbered by it. Callers who need a different login than the host default should pass `--login <reviewer-login>` rather than relying on ordering tricks or re-invoking `tea login` globally.
As a durable successor to this mechanism, consider giving each reviewer/approver slot its own dedicated Gitea login credential, so that author≠reviewer holds at the credential level rather than relying on wrapper-level `--login` bookkeeping. This is a recommendation for future hardening, not something implemented by this flag.

View File

@@ -81,7 +81,32 @@ get_repo_slug() {
gitea_url_matches_host() {
local url="${1:-}" host="${2:-}"
[[ -n "$url" && -n "$host" ]] || return 1
[[ "${url%/}" == "https://$host" || "${url%/}" == "http://$host" || "${url%/}" == *"//$host" ]]
python3 - "$url" "$host" <<'PY'
import sys
from urllib.parse import urlparse
url, remote_host = sys.argv[1:]
configured = urlparse(url)
remote = urlparse(f"//{remote_host}")
if configured.scheme not in {"http", "https"} or configured.hostname != remote.hostname:
raise SystemExit(1)
# Normalize by scheme: an implicit (portless) HTTP(S) URL and its explicit
# default-port form (":80" for http, ":443" for https) name the same
# provider endpoint. Apply that equivalence symmetrically -- whichever side
# omits the port is treated as carrying the scheme's default port -- so
# "configured implicit vs. remote explicit" and "configured explicit vs.
# remote implicit" both match. (The remote side here is always an HTTP(S)
# authority; an SSH remote's transport port is stripped by get_remote_host
# before reaching this comparison, since it identifies an unrelated
# service on the same host, not the HTTP(S) provider port.)
default_port = 80 if configured.scheme == "http" else 443
normalized_configured = configured.port if configured.port is not None else default_port
normalized_remote = remote.port if remote.port is not None else default_port
if normalized_configured != normalized_remote:
raise SystemExit(1)
raise SystemExit(0)
PY
}
get_gitea_service_for_host() {
@@ -347,6 +372,47 @@ get_gitea_api_host_for_repo_override() {
get_host_from_url "${GITEA_URL:-}"
}
# Resolve owner/repo relative to a configured Gitea base URL. HTTP(S) clone
# URLs can include the deployment prefix (for example /gitea/owner/repo.git),
# but Gitea's /repos API expects only owner/repo. Root-mounted and SSH clone
# forms retain their existing owner/repo behavior.
get_gitea_repo_slug_for_url() {
local configured_url="$1" remote_url
remote_url=$(git remote get-url origin 2>/dev/null) || return 1
if [[ "$remote_url" =~ ^https?:// ]]; then
python3 - "$remote_url" "$configured_url" <<'PY'
import sys
from urllib.parse import urlparse
remote = urlparse(sys.argv[1])
base = urlparse(sys.argv[2])
remote_path = remote.path.strip("/")
if remote_path.endswith(".git"):
remote_path = remote_path[:-4]
base_path = base.path.strip("/")
remote_parts = [part for part in remote_path.split("/") if part]
base_parts = [part for part in base_path.split("/") if part]
if base_parts and remote_parts[:len(base_parts)] == base_parts:
repo_parts = remote_parts[len(base_parts):]
elif len(remote_parts) == 2:
# Preserve a root-shaped clone URL when provider API configuration carries
# a reverse-proxy prefix separately.
repo_parts = remote_parts
else:
raise SystemExit(1)
if len(repo_parts) != 2:
raise SystemExit(1)
print("/".join(repo_parts))
PY
return
fi
get_repo_slug
}
get_gitea_repo_args() {
local repo host login
repo=$(get_repo_slug) || return 1
@@ -370,6 +436,15 @@ get_remote_host() {
echo "${host##*@}"
return 0
fi
if [[ "$remote_url" =~ ^ssh://([^/]+)/ ]]; then
local host="${BASH_REMATCH[1]}"
host="${host##*@}"
# Strip an SSH transport port (e.g. "git.example:2222"): it names the
# SSH daemon port, not the HTTP(S) provider API port, and must not
# feed gitea_url_matches_host's port comparison (#850).
echo "${host%%:*}"
return 0
fi
if [[ "$remote_url" =~ ^git@([^:]+): ]]; then
echo "${BASH_REMATCH[1]}"
return 0
@@ -377,6 +452,51 @@ get_remote_host() {
return 1
}
# Resolve the configured Gitea base URL for a host from the same credential
# source used by get_gitea_token. The scheme and any deployment path prefix are
# provider configuration and must not be reconstructed from the git remote.
get_gitea_url_for_host() {
local host="$1" script_dir cred_loader url
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
cred_loader="$script_dir/../_lib/credentials.sh"
if [[ -f "$cred_loader" ]]; then
url=$(
# shellcheck source=/dev/null
source "$cred_loader"
unset GITEA_TOKEN GITEA_URL
case "$host" in
git.mosaicstack.dev) load_credentials gitea-mosaicstack 2>/dev/null ;;
git.uscllc.com) load_credentials gitea-usc 2>/dev/null ;;
*)
for svc in gitea-mosaicstack gitea-usc; do
unset GITEA_TOKEN GITEA_URL
load_credentials "$svc" 2>/dev/null || continue
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
break
fi
unset GITEA_TOKEN GITEA_URL
done
;;
esac
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
printf '%s' "${GITEA_URL%/}"
fi
)
if [[ -n "$url" ]]; then
printf '%s\n' "$url"
return 0
fi
fi
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
printf '%s\n' "${GITEA_URL%/}"
return 0
fi
return 1
}
# Resolve a Gitea API token for the given host.
# Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials
get_gitea_token() {
@@ -403,7 +523,7 @@ get_gitea_token() {
for svc in gitea-mosaicstack gitea-usc; do
unset GITEA_TOKEN GITEA_URL
load_credentials "$svc" 2>/dev/null || continue
if [[ "${GITEA_URL:-}" == "https://$host" || "${GITEA_URL:-}" == "http://$host" || "${GITEA_URL:-}" == *"//$host" ]]; then
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
matched=true
break
fi
@@ -423,7 +543,7 @@ get_gitea_token() {
# 2. GITEA_TOKEN env var (only when GITEA_URL, if present, matches the remote host)
if [[ -n "${GITEA_TOKEN:-}" ]]; then
if [[ -z "${GITEA_URL:-}" || "${GITEA_URL:-}" == "https://$host" || "${GITEA_URL:-}" == "http://$host" || "${GITEA_URL:-}" == *"//$host" ]]; then
if [[ -z "${GITEA_URL:-}" ]] || gitea_url_matches_host "$GITEA_URL" "$host"; then
echo "$GITEA_TOKEN"
return 0
fi

View File

@@ -1,6 +1,23 @@
#!/bin/bash
# issue-comment.sh - Add a comment to an issue on GitHub or Gitea
# Usage: issue-comment.sh -i <issue_number> -c <comment>
# Usage: issue-comment.sh -i <issue_number> -c <comment> [--login <name>]
#
# tea v0.11.1 defines no `comment` subcommand under `tea issue` (or `tea pr`);
# the correct invocation is the TOP-LEVEL `tea comment <index> <body>` form.
# Calling the non-existent `tea issue comment ...` form does not error — tea
# silently falls through to a no-op and still exits 0, so a caller trusting
# the exit code alone believes a comment was posted when it was not (#865).
# Because that failure mode is silent, this script never trusts tea's exit
# code alone: after posting, it independently re-fetches the issue's comments
# via the Gitea REST API (curl — urllib is blocked by Cloudflare on this
# host) and fails closed if the posted body cannot be found.
#
# --login override: the default `--login` is resolved from the local `tea`
# login list for this repo's host (get_gitea_login). Pass --login <name> to
# override that default for this invocation only. The override is appended
# to the tea command line AFTER the detected default, because tea honors
# only the LAST `--login` flag on the command line — a flag placed before
# the default would be silently clobbered by it.
set -e
@@ -10,6 +27,7 @@ source "$SCRIPT_DIR/detect-platform.sh"
# Parse arguments
ISSUE_NUMBER=""
COMMENT=""
LOGIN_OVERRIDE=""
while [[ $# -gt 0 ]]; do
case $1 in
@@ -21,12 +39,17 @@ while [[ $# -gt 0 ]]; do
COMMENT="$2"
shift 2
;;
-l|--login)
LOGIN_OVERRIDE="$2"
shift 2
;;
-h|--help)
echo "Usage: issue-comment.sh -i <issue_number> -c <comment>"
echo "Usage: issue-comment.sh -i <issue_number> -c <comment> [--login <name>]"
echo ""
echo "Options:"
echo " -i, --issue Issue number (required)"
echo " -c, --comment Comment text (required)"
echo " -l, --login Override the detected Gitea tea login for this call"
echo " -h, --help Show this help"
exit 0
;;
@@ -49,6 +72,212 @@ fi
detect_platform >/dev/null
# Resolve and cache the Gitea REST endpoint + token for the current remote.
# Populates GITEA_API_ROOT (…/api/v1), GITEA_API_BASE (…/api/v1/repos/<slug>),
# and GITEA_API_TOKEN. Returns non-zero (with a clear stderr message) if any
# part of the resolution fails.
gitea_resolve_api() {
local host configured_url repo
host=$(get_remote_host)
GITEA_API_TOKEN=$(get_gitea_token "$host") || {
echo "Error: Gitea token not found for comment read-back verification" >&2
return 1
}
configured_url=$(get_gitea_url_for_host "$host") || {
echo "Error: Configured Gitea URL not found for comment read-back verification" >&2
return 1
}
repo=$(get_gitea_repo_slug_for_url "$configured_url") || {
echo "Error: Could not resolve Gitea owner/repository relative to configured URL" >&2
return 1
}
GITEA_API_ROOT="${configured_url%/}/api/v1"
GITEA_API_BASE="$GITEA_API_ROOT/repos/$repo"
return 0
}
# Fetch every page of a Gitea list endpoint into $2 (merged into one JSON
# array). Gitea paginates list responses, so a single-page read would
# false-negative once a newly created record lands beyond page 1. Walks
# page=1,2,… until a short page (fewer than the requested limit) or an empty
# page is returned, so the merged array is exhaustive. $1 is the endpoint URL
# with NO query string. Returns non-zero (clear stderr) on any transport /
# HTTP / parse failure.
gitea_fetch_all() {
local base_url="$1" dest="$2" page=1 limit=50 status page_file count
printf '[]' > "$dest"
while :; do
page_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-issue-comment-page.XXXXXX")
if ! status=$(curl -sS -o "$page_file" -w '%{http_code}' \
-H "Authorization: token $GITEA_API_TOKEN" \
"${base_url}?limit=${limit}&page=${page}"); then
rm -f "$page_file"
echo "Error: Gitea list read transport failed" >&2
return 1
fi
if [[ "$status" != "200" ]]; then
rm -f "$page_file"
echo "Error: Gitea list read failed with HTTP $status" >&2
return 1
fi
count=$(DEST="$dest" python3 - "$page_file" <<'PY'
import json
import os
import sys
try:
with open(os.environ["DEST"], encoding="utf-8") as merged_file:
merged = json.load(merged_file)
with open(sys.argv[1], encoding="utf-8") as page_file:
page = json.load(page_file)
if not isinstance(page, list):
raise ValueError("page response is not a list")
merged.extend(item for item in page if isinstance(item, dict))
with open(os.environ["DEST"], "w", encoding="utf-8") as merged_file:
json.dump(merged, merged_file)
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not merge Gitea list page: {error}", file=sys.stderr)
raise SystemExit(1)
print(len(page))
PY
) || { rm -f "$page_file"; return 1; }
rm -f "$page_file"
[[ "$count" -lt "$limit" ]] && break
page=$((page + 1))
if [[ "$page" -gt 1000 ]]; then
echo "Error: Gitea list pagination exceeded 1000 pages" >&2
return 1
fi
done
return 0
}
# Resolve the login of the identity the API token authenticates as (GET
# /user). Used to attribute a read-back record to THIS invocation's writer so
# a concurrent write from a DIFFERENT identity cannot satisfy verification.
# Prints the login on success.
gitea_authenticated_login() {
local response_file status
response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-issue-comment-whoami.XXXXXX")
trap 'rm -f "$response_file"' RETURN
if ! status=$(curl -sS -o "$response_file" -w '%{http_code}' \
-H "Authorization: token $GITEA_API_TOKEN" \
"$GITEA_API_ROOT/user"); then
echo "Error: Gitea authenticated-identity read transport failed" >&2
return 1
fi
if [[ "$status" != "200" ]]; then
echo "Error: Gitea authenticated-identity read failed with HTTP $status" >&2
return 1
fi
python3 - "$response_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
user = json.load(response)
login = user.get("login") if isinstance(user, dict) else None
if not isinstance(login, str) or not login:
raise ValueError("missing authenticated login")
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not resolve authenticated Gitea identity: {error}", file=sys.stderr)
raise SystemExit(1)
print(login)
PY
}
# Print the maximum existing comment id on an issue (0 if none). This is the
# pre-write BOUNDARY: Gitea comment ids are monotonic, so any comment created
# by a subsequent write has an id strictly greater than this value.
gitea_max_comment_id() {
local issue_number="$1" merged_file
merged_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-issue-comment-boundary.XXXXXX")
trap 'rm -f "$merged_file"' RETURN
gitea_fetch_all "$GITEA_API_BASE/issues/$issue_number/comments" "$merged_file" || return 1
python3 - "$merged_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
comments = json.load(response)
ids = [c.get("id") for c in comments if isinstance(c, dict) and isinstance(c.get("id"), int)]
print(max(ids) if ids else 0)
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not compute Gitea comment boundary: {error}", file=sys.stderr)
raise SystemExit(1)
PY
}
# Independently re-fetch (all pages of) the issue's comments and require a
# comment attributable to THIS invocation: id strictly greater than the
# pre-write boundary AND author login equal to the acting identity AND exact
# body match. tea's exit code is not trustworthy evidence of a durable write
# on its own (#865); id-above-boundary alone is only temporal ordering, so the
# author-login check is what excludes a concurrent write by a DIFFERENT
# identity. Prints the matched comment ID on success.
#
# Residual (documented, not eliminable without a tea-emitted created-record
# id, which tea 0.11.1 does not reliably provide): a concurrent write by the
# SAME identity with an identical body inside the boundary window could still
# be accepted. That is a strictly narrower window than temporal-only matching.
gitea_verify_comment_posted() {
local issue_number="$1" comment_body="$2" boundary="$3" acting_login="$4"
local merged_file
merged_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-issue-comment-readback.XXXXXX")
trap 'rm -f "$merged_file"' RETURN
gitea_fetch_all "$GITEA_API_BASE/issues/$issue_number/comments" "$merged_file" || return 1
EXPECTED_COMMENT_BODY="$comment_body" BOUNDARY_COMMENT_ID="$boundary" ACTING_LOGIN="$acting_login" \
python3 - "$merged_file" <<'PY'
import json
import os
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
comments = json.load(response)
if not isinstance(comments, list):
raise ValueError("response is not a comment list")
expected_body = os.environ["EXPECTED_COMMENT_BODY"]
boundary = int(os.environ["BOUNDARY_COMMENT_ID"])
acting_login = os.environ["ACTING_LOGIN"]
# Attribution to THIS write: created-after-boundary AND authored by the
# acting identity AND exact body match. The author check excludes a
# concurrent DIFFERENT-identity writer that id+body alone would admit.
matches = [
c for c in comments
if isinstance(c, dict)
and isinstance(c.get("id"), int)
and c.get("id") > boundary
and (c.get("user") or {}).get("login") == acting_login
and c.get("body") == expected_body
]
if not matches:
raise ValueError(
"no comment attributable to this write matched "
"(id > boundary, acting identity, exact body); "
"tea may have silently no-opped (#865)"
)
comment_id = max(c["id"] for c in matches)
except (OSError, json.JSONDecodeError, KeyError, TypeError, ValueError) as error:
print(f"Error: Gitea comment persistence verification failed: {error}", file=sys.stderr)
raise SystemExit(1)
print(comment_id)
PY
}
if [[ "$PLATFORM" == "github" ]]; then
gh issue comment "$ISSUE_NUMBER" --body "$COMMENT"
echo "Added comment to GitHub issue #$ISSUE_NUMBER"
@@ -61,8 +290,28 @@ elif [[ "$PLATFORM" == "gitea" ]]; then
echo "Error: could not resolve a Gitea login for this repo; cannot comment on issue #$ISSUE_NUMBER." >&2
exit 1
}
tea issue comment "$ISSUE_NUMBER" "$COMMENT" --repo "$REPO_SLUG" --login "$GITEA_LOGIN_NAME"
echo "Added comment to Gitea issue #$ISSUE_NUMBER"
# Resolve the REST endpoint, the acting identity, and the pre-write
# boundary BEFORE the write, so the read-back can require a strictly-newer
# comment id authored by this identity.
gitea_resolve_api || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
boundary=$(gitea_max_comment_id "$ISSUE_NUMBER") || exit 1
TEA_ARGS=(comment "$ISSUE_NUMBER" "$COMMENT" --repo "$REPO_SLUG" --login "$GITEA_LOGIN_NAME")
# --login override goes LAST: tea honors only the final --login on its
# command line, so an override placed before the detected default above
# would be silently clobbered by it.
if [[ -n "$LOGIN_OVERRIDE" ]]; then
TEA_ARGS+=(--login "$LOGIN_OVERRIDE")
fi
tea "${TEA_ARGS[@]}"
comment_id=$(gitea_verify_comment_posted "$ISSUE_NUMBER" "$COMMENT" "$boundary" "$ACTING_LOGIN") || {
echo "Error: could not verify comment landed on Gitea issue #$ISSUE_NUMBER via bounded read-back; treating tea's exit code as untrustworthy (#865)." >&2
exit 1
}
echo "Added and verified comment on Gitea issue #$ISSUE_NUMBER (comment ID $comment_id)"
else
echo "Error: Unknown platform"
exit 1

View File

@@ -1,16 +1,29 @@
#!/bin/bash
# pr-review.sh - Review a pull request on GitHub or Gitea
# Usage: pr-review.sh -n <pr_number> -a <action> [-c <comment>]
# Usage: pr-review.sh -n <pr_number> -a <action> [-c <comment>] [--login <name>]
#
# --login override: approve/request-changes on Gitea invoke `tea pr
# approve`/`tea pr reject` with a `--login` resolved from the local tea
# login list for this repo's host (get_gitea_login_for_host). Pass
# --login <name> to override that default for this invocation only. The
# override is appended to the tea command line AFTER the detected default
# (get_gitea_repo_args()-equivalent resolution happens first), because tea
# honors only the LAST `--login` flag on its command line — a flag placed
# before the default would be silently clobbered by it. The `comment`
# action does not shell out to `tea` at all (see gitea_post_verified_comment
# below), so --login has no effect on it.
set -e
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# shellcheck source=packages/mosaic/framework/tools/git/detect-platform.sh
source "$SCRIPT_DIR/detect-platform.sh"
# Parse arguments
PR_NUMBER=""
ACTION=""
COMMENT=""
LOGIN_OVERRIDE=""
while [[ $# -gt 0 ]]; do
case $1 in
@@ -26,13 +39,18 @@ while [[ $# -gt 0 ]]; do
COMMENT="$2"
shift 2
;;
-l|--login)
LOGIN_OVERRIDE="$2"
shift 2
;;
-h|--help)
echo "Usage: pr-review.sh -n <pr_number> -a <action> [-c <comment>]"
echo "Usage: pr-review.sh -n <pr_number> -a <action> [-c <comment>] [--login <name>]"
echo ""
echo "Options:"
echo " -n, --number PR number (required)"
echo " -a, --action Review action: approve, request-changes, comment (required)"
echo " -c, --comment Review comment (required for request-changes)"
echo " -l, --login Override the detected Gitea tea login (approve/request-changes only)"
echo " -h, --help Show this help"
exit 0
;;
@@ -55,6 +73,377 @@ fi
detect_platform >/dev/null
# Post a review comment body to a Gitea PR via the supported comments REST API
# and verify it durably via provider read-back (see docs on durable review
# provenance in README.md). Used by the `comment` action and, since `tea`
# v0.11.1 defines no `--comment`/`-comment` flag on `pr approve`/`pr reject`,
# also by the `approve` and `request-changes` actions to carry an optional
# review body that `tea` itself cannot attach.
#
# Args: $1 = PR number, $2 = comment body
# On success: prints only the created comment ID to stdout, returns 0.
# On failure: prints an error to stderr, returns 1.
gitea_post_verified_comment() {
local pr_number="$1" comment_body="$2"
local host token configured_url repo api_base payload
local write_response_file readback_response_file comment_id
host=$(get_remote_host)
token=$(get_gitea_token "$host") || {
echo "Error: Gitea token not found for comment persistence" >&2
return 1
}
configured_url=$(get_gitea_url_for_host "$host") || {
echo "Error: Configured Gitea URL not found for comment persistence" >&2
return 1
}
repo=$(get_gitea_repo_slug_for_url "$configured_url") || {
echo "Error: Could not resolve Gitea owner/repository relative to configured URL" >&2
return 1
}
api_base="${configured_url%/}/api/v1/repos/$repo"
payload=$(COMMENT_BODY="$comment_body" python3 -c '
import json
import os
print(json.dumps({"body": os.environ["COMMENT_BODY"]}))
')
write_response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-write.XXXXXX")
readback_response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-readback.XXXXXX")
trap 'rm -f "$write_response_file" "$readback_response_file"' RETURN
if ! write_status=$(curl -sS -o "$write_response_file" -w '%{http_code}' \
-X POST \
-H "Authorization: token $token" \
-H 'Content-Type: application/json' \
-d "$payload" \
"$api_base/issues/$pr_number/comments"); then
echo "Error: Gitea comment write transport failed" >&2
return 1
fi
if [[ "$write_status" != "201" ]]; then
echo "Error: Gitea comment write failed with HTTP $write_status" >&2
return 1
fi
comment_id=$(python3 - "$write_response_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
comment = json.load(response)
comment_id = comment.get("id") if isinstance(comment, dict) else None
if not isinstance(comment_id, int) or comment_id <= 0:
raise ValueError("missing positive comment id")
except (OSError, json.JSONDecodeError, ValueError) as error:
print(f"Error: could not identify created Gitea comment: {error}", file=sys.stderr)
raise SystemExit(1)
print(comment_id)
PY
) || return 1
if ! readback_status=$(curl -sS -o "$readback_response_file" -w '%{http_code}' \
-H "Authorization: token $token" \
"$api_base/issues/comments/$comment_id"); then
echo "Error: Gitea comment read-back transport failed" >&2
return 1
fi
if [[ "$readback_status" != "200" ]]; then
echo "Error: Gitea comment read-back failed with HTTP $readback_status" >&2
return 1
fi
if EXPECTED_COMMENT_ID="$comment_id" EXPECTED_COMMENT_BODY="$comment_body" EXPECTED_REPO="$repo" EXPECTED_PR_NUMBER="$pr_number" \
python3 - "$readback_response_file" <<'PY'
import json
import os
import sys
from urllib.parse import urlparse
try:
with open(sys.argv[1], encoding="utf-8") as response:
comment = json.load(response)
if not isinstance(comment, dict):
raise ValueError("response is not a comment object")
expected_id = int(os.environ["EXPECTED_COMMENT_ID"])
expected_body = os.environ["EXPECTED_COMMENT_BODY"]
expected_repo = os.environ["EXPECTED_REPO"]
expected_pr = os.environ["EXPECTED_PR_NUMBER"]
issue_path = urlparse(comment.get("issue_url", "")).path.rstrip("/")
expected_suffix = f"/repos/{expected_repo}/issues/{expected_pr}"
if comment.get("id") != expected_id:
raise ValueError("comment id mismatch")
if comment.get("body") != expected_body:
raise ValueError("comment body mismatch")
if not issue_path.endswith(expected_suffix):
raise ValueError("repository or PR mismatch")
except (OSError, json.JSONDecodeError, KeyError, TypeError, ValueError) as error:
print(f"Error: Gitea comment persistence verification failed: {error}", file=sys.stderr)
raise SystemExit(1)
PY
then
true
else
return 1
fi
echo "$comment_id"
return 0
}
# Resolve and cache the Gitea REST endpoint + token for the current remote.
# Populates GITEA_API_ROOT (…/api/v1), GITEA_API_BASE (…/api/v1/repos/<slug>),
# and GITEA_API_TOKEN. Returns non-zero (with a clear stderr message) on any
# resolution failure.
gitea_resolve_api() {
local host configured_url repo
host=$(get_remote_host)
GITEA_API_TOKEN=$(get_gitea_token "$host") || {
echo "Error: Gitea token not found for review read-back verification" >&2
return 1
}
configured_url=$(get_gitea_url_for_host "$host") || {
echo "Error: Configured Gitea URL not found for review read-back verification" >&2
return 1
}
repo=$(get_gitea_repo_slug_for_url "$configured_url") || {
echo "Error: Could not resolve Gitea owner/repository relative to configured URL" >&2
return 1
}
GITEA_API_ROOT="${configured_url%/}/api/v1"
GITEA_API_BASE="$GITEA_API_ROOT/repos/$repo"
return 0
}
# Fetch every page of a Gitea list endpoint into $2 (merged into one JSON
# array). Gitea paginates list responses, so a single-page read would
# false-negative once a newly created review/comment lands beyond page 1.
# Walks page=1,2,… until a short or empty page is returned so the merged array
# is exhaustive. $1 is the endpoint URL with NO query string. Returns non-zero
# (clear stderr) on any transport / HTTP / parse failure.
gitea_fetch_all() {
local base_url="$1" dest="$2" page=1 limit=50 status page_file count
printf '[]' > "$dest"
while :; do
page_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-page.XXXXXX")
if ! status=$(curl -sS -o "$page_file" -w '%{http_code}' \
-H "Authorization: token $GITEA_API_TOKEN" \
"${base_url}?limit=${limit}&page=${page}"); then
rm -f "$page_file"
echo "Error: Gitea list read transport failed" >&2
return 1
fi
if [[ "$status" != "200" ]]; then
rm -f "$page_file"
echo "Error: Gitea list read failed with HTTP $status" >&2
return 1
fi
count=$(DEST="$dest" python3 - "$page_file" <<'PY'
import json
import os
import sys
try:
with open(os.environ["DEST"], encoding="utf-8") as merged_file:
merged = json.load(merged_file)
with open(sys.argv[1], encoding="utf-8") as page_file:
page = json.load(page_file)
if not isinstance(page, list):
raise ValueError("page response is not a list")
merged.extend(item for item in page if isinstance(item, dict))
with open(os.environ["DEST"], "w", encoding="utf-8") as merged_file:
json.dump(merged, merged_file)
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not merge Gitea list page: {error}", file=sys.stderr)
raise SystemExit(1)
print(len(page))
PY
) || { rm -f "$page_file"; return 1; }
rm -f "$page_file"
[[ "$count" -lt "$limit" ]] && break
page=$((page + 1))
if [[ "$page" -gt 1000 ]]; then
echo "Error: Gitea list pagination exceeded 1000 pages" >&2
return 1
fi
done
return 0
}
# Resolve the login of the identity the API token authenticates as (GET
# /user). Used to attribute a read-back review to THIS action's reviewer so a
# concurrent review from a DIFFERENT identity cannot satisfy verification.
# Prints the login on success.
gitea_authenticated_login() {
local response_file status
response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-whoami.XXXXXX")
trap 'rm -f "$response_file"' RETURN
if ! status=$(curl -sS -o "$response_file" -w '%{http_code}' \
-H "Authorization: token $GITEA_API_TOKEN" \
"$GITEA_API_ROOT/user"); then
echo "Error: Gitea authenticated-identity read transport failed" >&2
return 1
fi
if [[ "$status" != "200" ]]; then
echo "Error: Gitea authenticated-identity read failed with HTTP $status" >&2
return 1
fi
python3 - "$response_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
user = json.load(response)
login = user.get("login") if isinstance(user, dict) else None
if not isinstance(login, str) or not login:
raise ValueError("missing authenticated login")
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not resolve authenticated Gitea identity: {error}", file=sys.stderr)
raise SystemExit(1)
print(login)
PY
}
# Print the maximum existing review id on a PR (0 if none). This is the
# pre-write BOUNDARY: Gitea pull-review ids are monotonic, so any review
# submitted by a subsequent `tea pr approve`/`reject` has an id strictly
# greater than this value. Paginates fully so a boundary review beyond page 1
# is still counted.
gitea_max_review_id() {
local pr_number="$1" merged_file
merged_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-boundary.XXXXXX")
trap 'rm -f "$merged_file"' RETURN
gitea_fetch_all "$GITEA_API_BASE/pulls/$pr_number/reviews" "$merged_file" || return 1
python3 - "$merged_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
reviews = json.load(response)
ids = [r.get("id") for r in reviews if isinstance(r, dict) and isinstance(r.get("id"), int)]
print(max(ids) if ids else 0)
except (OSError, json.JSONDecodeError, TypeError, ValueError) as error:
print(f"Error: could not compute Gitea review boundary: {error}", file=sys.stderr)
raise SystemExit(1)
PY
}
# Independently verify that `tea pr approve`/`reject` produced a durable review
# record — never trust tea's exit code alone (#865, same defect class). Require
# a review attributable to THIS action: its id must be strictly greater than
# the pre-write boundary, its author login must equal the acting identity, its
# state must equal the expected state (APPROVED / REQUEST_CHANGES), and it must
# have been submitted against the PR's current head commit. The reviews list is
# paginated fully so a matching review beyond page 1 is still found. Prints the
# matched review id on success; fails closed (non-zero, clear stderr) if no
# such review is found.
#
# id-above-boundary alone is only temporal ordering; the author-login check is
# what excludes a concurrent review submitted by a DIFFERENT identity.
#
# Residual (documented, not eliminable without a tea-emitted created-record id,
# which tea 0.11.1 does not reliably provide for approve/reject): a concurrent
# review by the SAME identity with the same state against the same head inside
# the boundary window could still be accepted. That is strictly narrower than
# temporal-only matching.
#
# Args: $1 = PR number, $2 = expected state (APPROVED|REQUEST_CHANGES),
# $3 = pre-write boundary review id, $4 = acting reviewer login.
gitea_verify_review_submitted() {
local pr_number="$1" expected_state="$2" boundary="$3" acting_login="$4"
local pr_response_file reviews_merged_file status head_sha review_id
pr_response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-head.XXXXXX")
reviews_merged_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-state.XXXXXX")
trap 'rm -f "$pr_response_file" "$reviews_merged_file"' RETURN
# Resolve the PR's current head commit so the review can be pinned to it.
if ! status=$(curl -sS -o "$pr_response_file" -w '%{http_code}' \
-H "Authorization: token $GITEA_API_TOKEN" \
"$GITEA_API_BASE/pulls/$pr_number"); then
echo "Error: Gitea PR head read transport failed" >&2
return 1
fi
if [[ "$status" != "200" ]]; then
echo "Error: Gitea PR head read failed with HTTP $status" >&2
return 1
fi
head_sha=$(python3 - "$pr_response_file" <<'PY'
import json
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
pr = json.load(response)
head_sha = pr.get("head", {}).get("sha") if isinstance(pr, dict) else None
if not isinstance(head_sha, str) or not head_sha:
raise ValueError("missing PR head sha")
except (OSError, json.JSONDecodeError, AttributeError, TypeError, ValueError) as error:
print(f"Error: could not resolve PR head commit: {error}", file=sys.stderr)
raise SystemExit(1)
print(head_sha)
PY
) || return 1
gitea_fetch_all "$GITEA_API_BASE/pulls/$pr_number/reviews" "$reviews_merged_file" || return 1
review_id=$(EXPECTED_STATE="$expected_state" BOUNDARY_REVIEW_ID="$boundary" EXPECTED_HEAD_SHA="$head_sha" ACTING_LOGIN="$acting_login" \
python3 - "$reviews_merged_file" <<'PY'
import json
import os
import sys
try:
with open(sys.argv[1], encoding="utf-8") as response:
reviews = json.load(response)
if not isinstance(reviews, list):
raise ValueError("response is not a review list")
expected_state = os.environ["EXPECTED_STATE"]
boundary = int(os.environ["BOUNDARY_REVIEW_ID"])
expected_head = os.environ["EXPECTED_HEAD_SHA"]
acting_login = os.environ["ACTING_LOGIN"]
# Attribution to THIS action: created-after-boundary AND submitted by the
# acting reviewer identity AND expected state AND pinned to the PR's
# current head commit. The author check excludes a concurrent
# DIFFERENT-identity review that id+state+head alone would admit.
matches = [
r for r in reviews
if isinstance(r, dict)
and isinstance(r.get("id"), int)
and r.get("id") > boundary
and (r.get("user") or {}).get("login") == acting_login
and r.get("state") == expected_state
and r.get("commit_id") == expected_head
]
if not matches:
raise ValueError(
f"no {expected_state} review attributable to this action found "
"(id > boundary, acting identity, expected state, current head); "
"tea may have silently failed (#865 defect class)"
)
review_id = max(r["id"] for r in matches)
except (OSError, json.JSONDecodeError, KeyError, TypeError, ValueError) as error:
print(f"Error: Gitea review persistence verification failed: {error}", file=sys.stderr)
raise SystemExit(1)
print(review_id)
PY
) || return 1
echo "$review_id"
return 0
}
if [[ "$PLATFORM" == "github" ]]; then
case $ACTION in
approve)
@@ -85,24 +474,75 @@ if [[ "$PLATFORM" == "github" ]]; then
elif [[ "$PLATFORM" == "gitea" ]]; then
case $ACTION in
approve)
tea pr approve "$PR_NUMBER" $(get_gitea_repo_args) ${COMMENT:+--comment "$COMMENT"}
echo "Approved Gitea PR #$PR_NUMBER"
repo=$(get_repo_slug)
host=$(get_remote_host)
login=$(get_gitea_login_for_host "$host")
# Resolve the REST endpoint and record the pre-write review-id
# boundary BEFORE the write, so the read-back can require a
# strictly-newer review created by THIS action (never trust tea's
# exit code alone — #865 defect class applies to the review state).
gitea_resolve_api || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
review_boundary=$(gitea_max_review_id "$PR_NUMBER") || exit 1
# tea v0.11.1 defines no --comment/-comment flag on `pr approve`;
# route any review body via the durable comment API instead (#835).
TEA_ARGS=(pr approve "$PR_NUMBER" --repo "$repo" --login "$login")
# --login override goes LAST: tea honors only the final --login on
# its command line, so an override placed before the detected
# default above would be silently clobbered by it.
if [[ -n "$LOGIN_OVERRIDE" ]]; then
TEA_ARGS+=(--login "$LOGIN_OVERRIDE")
fi
tea "${TEA_ARGS[@]}"
review_id=$(gitea_verify_review_submitted "$PR_NUMBER" "APPROVED" "$review_boundary" "$ACTING_LOGIN") || {
echo "Error: could not verify an APPROVED review landed on Gitea PR #$PR_NUMBER via bounded read-back; treating tea's exit code as untrustworthy (#865)." >&2
exit 1
}
echo "Approved and verified Gitea PR #$PR_NUMBER (review ID $review_id)"
if [[ -n "$COMMENT" ]]; then
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
echo "Added and verified review comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
fi
;;
request-changes)
if [[ -z "$COMMENT" ]]; then
echo "Error: Comment required for request-changes"
exit 1
fi
tea pr reject "$PR_NUMBER" $(get_gitea_repo_args) --comment "$COMMENT"
echo "Requested changes on Gitea PR #$PR_NUMBER"
repo=$(get_repo_slug)
host=$(get_remote_host)
login=$(get_gitea_login_for_host "$host")
# Record the pre-write review-id boundary BEFORE the write (see the
# approve path above for the rationale).
gitea_resolve_api || exit 1
ACTING_LOGIN=$(gitea_authenticated_login) || exit 1
review_boundary=$(gitea_max_review_id "$PR_NUMBER") || exit 1
# tea v0.11.1 defines no --comment/-comment flag on `pr reject`;
# route the review body via the durable comment API instead (#835).
TEA_ARGS=(pr reject "$PR_NUMBER" --repo "$repo" --login "$login")
# --login override goes LAST: tea honors only the final --login on
# its command line, so an override placed before the detected
# default above would be silently clobbered by it.
if [[ -n "$LOGIN_OVERRIDE" ]]; then
TEA_ARGS+=(--login "$LOGIN_OVERRIDE")
fi
tea "${TEA_ARGS[@]}"
review_id=$(gitea_verify_review_submitted "$PR_NUMBER" "REQUEST_CHANGES" "$review_boundary" "$ACTING_LOGIN") || {
echo "Error: could not verify a REQUEST_CHANGES review landed on Gitea PR #$PR_NUMBER via bounded read-back; treating tea's exit code as untrustworthy (#865)." >&2
exit 1
}
echo "Requested changes and verified on Gitea PR #$PR_NUMBER (review ID $review_id)"
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
echo "Added and verified review comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
;;
comment)
if [[ -z "$COMMENT" ]]; then
echo "Error: Comment required"
exit 1
fi
tea pr comment "$PR_NUMBER" "$COMMENT" $(get_gitea_repo_args)
echo "Added comment to Gitea PR #$PR_NUMBER"
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
echo "Added and verified comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
;;
*)
echo "Error: Unknown action: $ACTION"

View File

@@ -0,0 +1,265 @@
#!/usr/bin/env bash
# Regression harness for issue-comment.sh top-level `tea comment` invocation and
# its BOUNDED, INVOCATION-ATTRIBUTED, PAGINATED read-back verification (#865).
#
# The #865 bug: `tea issue comment ...` (a nonexistent subcommand on tea
# v0.11.1) silently no-ops and exits 0, so a comment is never posted. A naive
# read-back that matches ANY historical comment by body would falsely report
# success whenever an identically-bodied comment already exists from a prior
# run. Merely bounding by "id > pre-write max" is also insufficient: it accepts
# ANY newer matching comment, including one a CONCURRENT DIFFERENT identity
# posted while this tea invocation created nothing. This harness proves the
# wrapper:
# 1. uses the top-level `tea comment` form (never `tea issue comment`);
# 2. records the pre-write maximum comment id as a boundary and requires a
# strictly-newer comment on read-back, so a pre-existing identical body
# does NOT satisfy verification (fails closed);
# 3. attributes the matched comment to the acting identity (GET /user login),
# so a concurrent DIFFERENT-identity write does NOT satisfy verification;
# 4. reports success only when a genuinely new comment (id > boundary) with
# the exact body AND the acting author appears.
#
# The `tea` stub NEVER creates a comment (it mimics the silent no-op); the
# "server" comment state is modeled entirely by the curl stub's responses, so
# the fresh-success vs. no-op distinction is driven purely by whether the
# post-write read-back surfaces a new, correctly-attributed id.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/issue-comment-readback}"
REPO_DIR="$WORK_DIR/repo"
BIN_DIR="$WORK_DIR/bin"
TEA_LOG="$WORK_DIR/tea.log"
CURL_LOG="$WORK_DIR/curl.log"
OUTPUT_FILE="$WORK_DIR/output.log"
CREDENTIALS_FILE="$WORK_DIR/credentials.json"
CALLS_FILE="$WORK_DIR/comment_calls"
cleanup() {
rm -rf "$WORK_DIR"
}
trap cleanup EXIT
mkdir -p "$REPO_DIR" "$BIN_DIR"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
ISSUE_NUMBER=7
API_BASE="https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack"
API_ROOT="https://git.mosaicstack.dev/api/v1"
BODY='durable "note" -- marker'
ACTING_LOGIN="primary-reviewer"
FOREIGN_LOGIN="other-writer"
CONFIGURED_GITEA_URL="https://git.mosaicstack.dev" python3 - "$CREDENTIALS_FILE" <<'PY'
import json
import os
import sys
with open(sys.argv[1], "w", encoding="utf-8") as credentials:
json.dump({
"gitea": {
"mosaicstack": {
"url": os.environ["CONFIGURED_GITEA_URL"],
"token": "test-only-placeholder",
}
}
}, credentials)
PY
# tea stub: resolves the login list, and treats `tea comment ...` as a silent
# no-op (exit 0 without creating anything) to mimic the real failure mode.
cat > "$BIN_DIR/tea" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' "$*" >> "$ISSUE_COMMENT_TEA_LOG"
if [[ "$*" == "login list --output json" ]]; then
printf '%s\n' '[{"name":"mosaicstack","url":"https://git.mosaicstack.dev"}]'
exit 0
fi
# The wrapper must use the TOP-LEVEL `tea comment` form; the broken
# `tea issue comment` subcommand must never be invoked.
if [[ "$*" == issue\ comment* ]]; then
echo "wrapper invoked nonexistent 'tea issue comment' subcommand" >&2
exit 90
fi
if [[ "$*" == comment\ * ]]; then
# Mimic tea v0.11.1: exit 0. Whether a comment actually lands is modeled
# by the curl stub's post-write read-back response, not here.
exit 0
fi
echo "Unexpected tea command: $*" >&2
exit 92
SH
chmod +x "$BIN_DIR/tea"
# curl stub: serves GET /user (acting identity) and GET .../issues/7/comments
# (paginated: ?limit=&page=). The comments endpoint's first call = pre-write
# boundary, second call = post-write read-back. The boundary always contains a
# pre-existing comment (id 50) whose body is IDENTICAL to the one under test,
# which is exactly the condition a body-only match would trip over.
cat > "$BIN_DIR/curl" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
output_file=""
method="GET"
url=""
while [[ $# -gt 0 ]]; do
case "$1" in
-o) output_file="$2"; shift 2 ;;
-w|-H) shift 2 ;;
-X) method="$2"; shift 2 ;;
-d|--data) shift 2 ;;
-s|-S|-sS) shift ;;
http://*|https://*) url="$1"; shift ;;
*) shift ;;
esac
done
# Strip any query string so pagination params don't defeat path matching, but
# still log the full URL (including ?limit=&page=) so the test can assert the
# read-back paginated.
path="${url%%\?*}"
printf '%s %s\n' "$method" "$url" >> "$ISSUE_COMMENT_CURL_LOG"
write_response() {
local status="$1" body="$2"
[[ -n "$output_file" ]] || exit 96
printf '%s' "$body" > "$output_file"
printf '%s' "$status"
}
if [[ "$method" == "GET" && "$path" == "$ISSUE_COMMENT_API_ROOT/user" ]]; then
write_response 200 "$(ISSUE_COMMENT_LOGIN="$ISSUE_COMMENT_ACTING_LOGIN" python3 - <<'PY'
import json
import os
print(json.dumps({"login": os.environ["ISSUE_COMMENT_LOGIN"]}))
PY
)"
elif [[ "$method" == "GET" && "$path" == "$ISSUE_COMMENT_API_BASE/issues/7/comments" ]]; then
calls_file="$ISSUE_COMMENT_CALLS"
if [[ -f "$calls_file" ]]; then
# post-write read-back
response=$(ISSUE_COMMENT_BODY="$ISSUE_COMMENT_EXPECTED_BODY" \
ISSUE_COMMENT_ACTING_LOGIN="$ISSUE_COMMENT_ACTING_LOGIN" \
ISSUE_COMMENT_FOREIGN_LOGIN="$ISSUE_COMMENT_FOREIGN_LOGIN" \
ISSUE_COMMENT_TEST_MODE="$ISSUE_COMMENT_TEST_MODE" python3 - <<'PY'
import json
import os
body = os.environ["ISSUE_COMMENT_BODY"]
acting = os.environ["ISSUE_COMMENT_ACTING_LOGIN"]
foreign = os.environ["ISSUE_COMMENT_FOREIGN_LOGIN"]
mode = os.environ["ISSUE_COMMENT_TEST_MODE"]
if mode == "fresh-success":
# A genuinely new comment (id 60 > boundary 50) authored by the acting
# identity.
records = [
{"id": 50, "body": body, "user": {"login": acting}},
{"id": 60, "body": body, "user": {"login": acting}},
]
elif mode == "foreign-identity":
# A concurrent new comment (id 60 > boundary 50) with the SAME body but a
# DIFFERENT author. tea created nothing; attribution must reject this.
records = [
{"id": 50, "body": body, "user": {"login": acting}},
{"id": 60, "body": body, "user": {"login": foreign}},
]
else:
# no-op: nothing new landed; the pre-existing id-50 comment remains.
records = [{"id": 50, "body": body, "user": {"login": acting}}]
print(json.dumps(records))
PY
)
else
: > "$calls_file"
response=$(ISSUE_COMMENT_BODY="$ISSUE_COMMENT_EXPECTED_BODY" \
ISSUE_COMMENT_ACTING_LOGIN="$ISSUE_COMMENT_ACTING_LOGIN" python3 - <<'PY'
import json
import os
body = os.environ["ISSUE_COMMENT_BODY"]
acting = os.environ["ISSUE_COMMENT_ACTING_LOGIN"]
print(json.dumps([{"id": 50, "body": body, "user": {"login": acting}}]))
PY
)
fi
write_response 200 "$response"
else
echo "Unexpected curl request: $method $url" >&2
exit 97
fi
SH
chmod +x "$BIN_DIR/curl"
run_comment() {
local mode="$1"
: > "$TEA_LOG"
: > "$CURL_LOG"
: > "$OUTPUT_FILE"
rm -f "$CALLS_FILE"
(
cd "$REPO_DIR"
PATH="$BIN_DIR:$PATH" \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
ISSUE_COMMENT_TEA_LOG="$TEA_LOG" \
ISSUE_COMMENT_CURL_LOG="$CURL_LOG" \
ISSUE_COMMENT_CALLS="$CALLS_FILE" \
ISSUE_COMMENT_TEST_MODE="$mode" \
ISSUE_COMMENT_EXPECTED_BODY="$BODY" \
ISSUE_COMMENT_ACTING_LOGIN="$ACTING_LOGIN" \
ISSUE_COMMENT_FOREIGN_LOGIN="$FOREIGN_LOGIN" \
ISSUE_COMMENT_API_BASE="$API_BASE" \
ISSUE_COMMENT_API_ROOT="$API_ROOT" \
"$SCRIPT_DIR/issue-comment.sh" -i "$ISSUE_NUMBER" -c "$BODY"
) > "$OUTPUT_FILE" 2>&1
}
# Case 1: silent no-op with a pre-existing identical body must FAIL CLOSED.
if run_comment noop-preexisting; then
echo "FAIL: wrapper reported success when tea no-opped but an identical body pre-existed" >&2
cat "$OUTPUT_FILE" >&2
exit 1
fi
if grep -q 'Added and verified comment' "$OUTPUT_FILE"; then
echo "FAIL: read-back matched a pre-existing comment by body only" >&2
exit 1
fi
# The wrapper must have used the top-level form and read comments back twice
# (boundary + post-write).
grep -q "^comment 7 " "$TEA_LOG"
if grep -q '^issue comment' "$TEA_LOG"; then
echo "FAIL: wrapper used the broken 'tea issue comment' subcommand" >&2
exit 1
fi
[[ "$(grep -c "^GET $API_BASE/issues/7/comments?" "$CURL_LOG")" == "2" ]]
# Read-back must be paginated (limit + page query params present).
grep -q "^GET $API_BASE/issues/7/comments?limit=[0-9]*&page=1$" "$CURL_LOG"
# Attribution must have resolved the acting identity via GET /user.
grep -q "^GET $API_ROOT/user$" "$CURL_LOG"
# Case 2: a concurrent DIFFERENT-identity write (id 60 > boundary, same body,
# foreign author) must FAIL CLOSED — temporal ordering is not attribution.
if run_comment foreign-identity; then
echo "FAIL: wrapper accepted a concurrent comment authored by a different identity" >&2
cat "$OUTPUT_FILE" >&2
exit 1
fi
if grep -q 'Added and verified comment' "$OUTPUT_FILE"; then
echo "FAIL: read-back matched a different-identity comment (attribution bypassed)" >&2
exit 1
fi
# Case 3: a genuinely new comment (id 60 > boundary 50, acting author) verifies.
run_comment fresh-success
grep -q 'Added and verified comment on Gitea issue #7 (comment ID 60)' "$OUTPUT_FILE"
grep -q "^comment 7 " "$TEA_LOG"
echo "issue-comment.sh bounded + attributed read-back regression passed"

View File

@@ -0,0 +1,447 @@
#!/usr/bin/env bash
# Regression harness for durable Gitea PR review comments (#812) and for the
# approve/reject `--comment` flag removal (#835). The `tea` stub below rejects
# any `-comment`/`--comment` flag on `pr approve`/`pr reject` exactly like real
# `tea` v0.11.1 does ("flag provided but not defined: -comment"), so this
# harness fails RED against the pre-#835 wrapper (which passed that flag) and
# only passes once the wrapper routes the review body through the durable
# comment REST API instead.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-review-gitea-comment}"
REPO_DIR="$WORK_DIR/repo"
BIN_DIR="$WORK_DIR/bin"
TEA_LOG="$WORK_DIR/tea.log"
CURL_LOG="$WORK_DIR/curl.log"
OUTPUT_FILE="$WORK_DIR/output.log"
CREDENTIALS_FILE="$WORK_DIR/credentials.json"
cleanup() {
rm -rf "$WORK_DIR"
}
trap cleanup EXIT
ACTING_LOGIN="review-bot"
FOREIGN_LOGIN="other-writer"
mkdir -p "$REPO_DIR" "$BIN_DIR"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
write_credentials() {
local configured_url="$1"
CONFIGURED_GITEA_URL="$configured_url" python3 - "$CREDENTIALS_FILE" <<'PY'
import json
import os
import sys
with open(sys.argv[1], "w", encoding="utf-8") as credentials:
json.dump({
"gitea": {
"mosaicstack": {
"url": os.environ["CONFIGURED_GITEA_URL"],
"token": "test-only-placeholder",
}
}
}, credentials)
PY
}
cat > "$BIN_DIR/tea" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' "$*" >> "$PR_REVIEW_TEA_LOG"
if [[ "$*" == "login list --output json" ]]; then
printf '%s\n' '[{"name":"mosaicstack","url":"https://git.mosaicstack.dev"}]'
exit 0
fi
# tea v0.11.1 defines no --comment/-comment flag on `pr approve` or `pr
# reject`; it fails closed with this exact message and a nonzero exit. Any
# regression that reintroduces the flag on those subcommands must hit this
# branch and fail RED (#835).
if [[ "$*" == *" -comment "* || "$*" == *" --comment "* || "$*" == *" -comment" || "$*" == *" --comment" ]]; then
echo "flag provided but not defined: -comment" >&2
exit 1
fi
case "${PR_REVIEW_TEST_MODE:-}" in
approve|paginated-approve|foreign-review)
[[ "$*" == "pr approve 123 --repo mosaicstack/stack --login mosaicstack" ]] || exit 90
;;
request-changes)
[[ "$*" == "pr reject 123 --repo mosaicstack/stack --login mosaicstack" ]] || exit 91
;;
legacy-fallback|comment-success|http-success|prefix-success|subpath-success|port-success|scp-ssh-success|url-ssh-success|ssh-transport-port-success|explicit-default-port-success|write-transport-failure|write-http-failure|readback-failure)
if [[ "$*" == pr\ comment* ]]; then
# tea v0.11.1 treats the nonexistent subcommand as `tea pr list` and exits 0.
printf '%s\n' 'INDEX TITLE STATE'
exit 0
fi
echo "Unexpected tea command: $*" >&2
exit 92
;;
*)
exit 95
;;
esac
SH
chmod +x "$BIN_DIR/tea"
cat > "$BIN_DIR/curl" <<'SH'
#!/usr/bin/env bash
set -euo pipefail
output_file=""
method="GET"
payload=""
url=""
while [[ $# -gt 0 ]]; do
case "$1" in
-o)
output_file="$2"
shift 2
;;
-w|-H)
shift 2
;;
-X)
method="$2"
shift 2
;;
-d|--data)
payload="$2"
shift 2
;;
-s|-S|-sS)
shift
;;
http://*|https://*)
url="$1"
shift
;;
*)
shift
;;
esac
done
# Strip any query string so pagination params (?limit=&page=) don't defeat
# path matching, but keep the full URL in the log so tests can assert that the
# read-back paginated.
path="${url%%\?*}"
page="${url##*page=}"
[[ "$page" == "$url" ]] && page=1
printf '%s %s\n' "$method" "$url" >> "$PR_REVIEW_CURL_LOG"
write_response() {
local status="$1" body="$2"
[[ -n "$output_file" ]] || exit 96
printf '%s' "$body" > "$output_file"
printf '%s' "$status"
}
case "${PR_REVIEW_TEST_MODE:-}" in
legacy-fallback|write-transport-failure)
echo "simulated transport failure" >&2
exit 7
;;
write-http-failure)
write_response 500 '{"message":"simulated rejection"}'
;;
approve|request-changes|paginated-approve|foreign-review|comment-success|http-success|prefix-success|subpath-success|port-success|scp-ssh-success|url-ssh-success|ssh-transport-port-success|explicit-default-port-success|readback-failure)
if [[ "$method" == "GET" && "$path" == "$PR_REVIEW_API_ROOT/user" ]]; then
# Acting reviewer identity used for invocation attribution.
write_response 200 "$(PR_REVIEW_LOGIN="$PR_REVIEW_ACTING_LOGIN" python3 - <<'PY'
import json
import os
print(json.dumps({"login": os.environ["PR_REVIEW_LOGIN"]}))
PY
)"
elif [[ "$method" == "GET" && "$path" == "$PR_REVIEW_EXPECTED_API_BASE/pulls/123/reviews" ]]; then
# First (boundary) call precedes the write; later calls are the
# post-write read-back that must surface a strictly-newer review
# created by THIS action (id 200 > boundary 100), authored by the
# acting identity, with the expected state and pinned to the PR's
# current head commit. The list is served PAGINATED so a target
# beyond page 1 is only found by a fully-paginating read-back.
calls_file="${PR_REVIEW_REVIEW_CALLS:-/dev/null}"
if [[ -f "$calls_file" ]]; then
phase="post"
else
: > "$calls_file"
phase="boundary"
fi
state="APPROVED"
[[ "$PR_REVIEW_TEST_MODE" == "request-changes" ]] && state="REQUEST_CHANGES"
response=$(PR_REVIEW_PHASE="$phase" PR_REVIEW_PAGE="$page" \
PR_REVIEW_MODE="$PR_REVIEW_TEST_MODE" PR_REVIEW_STATE="$state" \
PR_REVIEW_ACTING_LOGIN="$PR_REVIEW_ACTING_LOGIN" \
PR_REVIEW_FOREIGN_LOGIN="$PR_REVIEW_FOREIGN_LOGIN" python3 - <<'PY'
import json
import os
phase = os.environ["PR_REVIEW_PHASE"]
page = int(os.environ["PR_REVIEW_PAGE"])
mode = os.environ["PR_REVIEW_MODE"]
state = os.environ["PR_REVIEW_STATE"]
acting = os.environ["PR_REVIEW_ACTING_LOGIN"]
foreign = os.environ["PR_REVIEW_FOREIGN_LOGIN"]
def review(review_id, review_state, commit, login):
return {
"id": review_id,
"state": review_state,
"commit_id": commit,
"user": {"login": login},
}
if phase == "boundary":
records = [review(100, "COMMENT", "oldsha0000", acting)] if page == 1 else []
elif mode == "paginated-approve":
# A full first page (50 non-matching records) forces the read-back to
# request page 2, where the genuine matching review lives.
if page == 1:
records = [review(101 + i, "COMMENT", "oldsha0000", acting) for i in range(50)]
elif page == 2:
records = [review(200, state, "HEADSHA_FEEDFACE", acting)]
else:
records = []
elif mode == "foreign-review":
# A concurrent APPROVED review at the current head, but authored by a
# DIFFERENT identity. tea created nothing; attribution must reject this.
records = [review(200, state, "HEADSHA_FEEDFACE", foreign)] if page == 1 else []
else:
if page == 1:
records = [
review(100, "COMMENT", "oldsha0000", acting),
review(200, state, "HEADSHA_FEEDFACE", acting),
]
else:
records = []
print(json.dumps(records))
PY
)
write_response 200 "$response"
elif [[ "$method" == "GET" && "$path" == "$PR_REVIEW_EXPECTED_API_BASE/pulls/123" ]]; then
write_response 200 '{"head":{"sha":"HEADSHA_FEEDFACE"}}'
elif [[ "$method" == "POST" && "$url" == "$PR_REVIEW_EXPECTED_API_BASE/issues/123/comments" ]]; then
PR_REVIEW_PAYLOAD="$payload" python3 - <<'PY'
import json
import os
assert json.loads(os.environ["PR_REVIEW_PAYLOAD"]) == {"body": os.environ["PR_REVIEW_EXPECTED_BODY"]}
PY
response=$(python3 - <<'PY'
import json
import os
print(json.dumps({"id": 456, "body": os.environ["PR_REVIEW_EXPECTED_BODY"]}))
PY
)
write_response 201 "$response"
elif [[ "$method" == "GET" && "$url" == "$PR_REVIEW_EXPECTED_API_BASE/issues/comments/456" ]]; then
if [[ "$PR_REVIEW_TEST_MODE" == "readback-failure" ]]; then
body="different-body"
else
body="$PR_REVIEW_EXPECTED_BODY"
fi
response=$(PR_REVIEW_BODY="$body" python3 - <<'PY'
import json
import os
print(json.dumps({
"id": 456,
"body": os.environ["PR_REVIEW_BODY"],
"issue_url": os.environ["PR_REVIEW_EXPECTED_API_BASE"] + "/issues/123",
}))
PY
)
write_response 200 "$response"
else
echo "Unexpected curl request: $method $url" >&2
exit 97
fi
;;
*)
exit 98
;;
esac
SH
chmod +x "$BIN_DIR/curl"
run_review() {
local mode="$1" action="$2" comment="${3:-}"
local configured_url="${4:-https://git.mosaicstack.dev}"
local remote_url="${5:-https://git.mosaicstack.dev/mosaicstack/stack.git}"
local expected_repo="${6:-mosaicstack/stack}"
local expected_api_base="${configured_url%/}/api/v1/repos/$expected_repo"
local expected_api_root="${configured_url%/}/api/v1"
git -C "$REPO_DIR" remote set-url origin "$remote_url"
write_credentials "$configured_url"
: > "$TEA_LOG"
: > "$CURL_LOG"
: > "$OUTPUT_FILE"
rm -f "$WORK_DIR/review_calls"
(
cd "$REPO_DIR"
PATH="$BIN_DIR:$PATH" \
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
PR_REVIEW_TEA_LOG="$TEA_LOG" \
PR_REVIEW_CURL_LOG="$CURL_LOG" \
PR_REVIEW_REVIEW_CALLS="$WORK_DIR/review_calls" \
PR_REVIEW_TEST_MODE="$mode" \
PR_REVIEW_EXPECTED_BODY="$comment" \
PR_REVIEW_EXPECTED_API_BASE="$expected_api_base" \
PR_REVIEW_API_ROOT="$expected_api_root" \
PR_REVIEW_ACTING_LOGIN="$ACTING_LOGIN" \
PR_REVIEW_FOREIGN_LOGIN="$FOREIGN_LOGIN" \
"$SCRIPT_DIR/pr-review.sh" -n 123 -a "$action" ${comment:+-c "$comment"}
) > "$OUTPUT_FILE" 2>&1
}
run_review approve approve
grep -q '^pr approve 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
grep -q 'Approved and verified Gitea PR #123 (review ID 200)' "$OUTPUT_FILE"
# #865: the approval STATE itself is read back — a pre-write boundary GET and a
# post-write read-back GET on the (paginated) reviews endpoint, plus a PR head
# lookup and an acting-identity (GET /user) resolution for attribution.
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/pulls/123/reviews?limit=[0-9]*&page=1$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/pulls/123$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/api/v1/user$' "$CURL_LOG"
if grep -q 'comment' "$TEA_LOG"; then
echo "Plain approve (no review body) unexpectedly touched comment persistence" >&2
exit 1
fi
# #865 (invocation attribution): a concurrent APPROVED review at the current
# head, authored by a DIFFERENT identity while tea created nothing, must NOT
# satisfy verification — id-above-boundary + state + head is only temporal
# ordering, not proof THIS reviewer wrote it.
if run_review foreign-review approve; then
echo "FAIL: approve accepted a review authored by a different identity" >&2
cat "$OUTPUT_FILE" >&2
exit 1
fi
if grep -q 'Approved and verified' "$OUTPUT_FILE"; then
echo "FAIL: read-back matched a different-identity review (attribution bypassed)" >&2
exit 1
fi
# #865 (pagination): a genuine matching review that lands beyond page 1 of the
# reviews list must still be found by a fully-paginating read-back.
run_review paginated-approve approve
grep -q 'Approved and verified Gitea PR #123 (review ID 200)' "$OUTPUT_FILE"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/pulls/123/reviews?limit=[0-9]*&page=2$' "$CURL_LOG"
# #835: tea v0.11.1 defines no --comment/-comment flag on `pr approve`. A
# review body supplied alongside approve must be routed through the durable
# comment REST API instead of being passed to `tea` directly.
run_review approve approve approve-note
grep -q '^pr approve 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
grep -q 'Approved and verified Gitea PR #123 (review ID 200)' "$OUTPUT_FILE"
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
grep -q 'Added and verified review comment on Gitea PR #123 (comment ID 456)' "$OUTPUT_FILE"
# #835: same for `pr reject` (request-changes), where a comment is required.
run_review request-changes request-changes changes-required
grep -q '^pr reject 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
grep -q 'Requested changes and verified on Gitea PR #123 (review ID 200)' "$OUTPUT_FILE"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/pulls/123/reviews?limit=[0-9]*&page=1$' "$CURL_LOG"
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
grep -q 'Added and verified review comment on Gitea PR #123 (comment ID 456)' "$OUTPUT_FILE"
if run_review legacy-fallback comment durable-body; then
echo "The old nonexistent tea pr comment fallback returned success" >&2
cat "$OUTPUT_FILE" >&2
exit 1
fi
if grep -q '^pr comment ' "$TEA_LOG"; then
echo "Wrapper invoked unsupported tea pr comment" >&2
exit 1
fi
if grep -q 'Added comment to Gitea PR' "$OUTPUT_FILE"; then
echo "Wrapper reported success without durable persistence" >&2
exit 1
fi
complex_body=$'durable "body"\n-- marker'
run_review comment-success comment "$complex_body"
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
grep -q 'Added and verified comment on Gitea PR #123' "$OUTPUT_FILE"
if [[ -s "$TEA_LOG" ]]; then
echo "REST comment path unexpectedly invoked tea" >&2
cat "$TEA_LOG" >&2
exit 1
fi
run_review http-success comment durable-body http://git.mosaicstack.dev
grep -q '^POST http://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
grep -q '^GET http://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
run_review prefix-success comment durable-body https://git.mosaicstack.dev/gitea/
grep -q '^POST https://git.mosaicstack.dev/gitea/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
grep -q '^GET https://git.mosaicstack.dev/gitea/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
run_review subpath-success comment durable-body https://git.example/gitea https://git.example/gitea/owner/repo.git owner/repo
grep -q '^POST https://git.example/gitea/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
grep -q '^GET https://git.example/gitea/api/v1/repos/owner/repo/issues/comments/456$' "$CURL_LOG"
if grep -q '/repos/gitea/owner/repo/' "$CURL_LOG"; then
echo "Configured Gitea path prefix leaked into the repository slug" >&2
exit 1
fi
run_review port-success comment durable-body http://git.example:3000 http://git.example:3000/owner/repo.git owner/repo
grep -q '^POST http://git.example:3000/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
grep -q '^GET http://git.example:3000/api/v1/repos/owner/repo/issues/comments/456$' "$CURL_LOG"
run_review scp-ssh-success comment durable-body https://git.example git@git.example:owner/repo.git owner/repo
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
run_review url-ssh-success comment durable-body https://git.example ssh://git@git.example/owner/repo.git owner/repo
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
# #850 (follow-up to #812): an SSH remote's transport port (e.g. `ssh://
# git@host:2222/...`) must NOT be compared against the configured HTTP(S) API
# URL's port -- they identify unrelated properties (SSH daemon port vs. HTTP(S)
# provider port) of the same Gitea host. Before the fix, host-match required
# the configured URL to carry the identical port, so this failed closed even
# though both remote and configured URL name the same host.
run_review ssh-transport-port-success comment durable-body https://git.example ssh://git@git.example:2222/owner/repo.git owner/repo
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
# #850 (follow-up to #812): an explicit default HTTP(S) port on the remote
# (`https://host:443/...`) must be treated as equal to an implicit
# (portless) configured URL on BOTH sides -- the pre-fix comparison only
# normalized the default port when the REMOTE side was portless, so the
# inverse (explicit remote, implicit configured) form failed closed.
run_review explicit-default-port-success comment durable-body https://git.example https://git.example:443/owner/repo.git owner/repo
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
if run_review write-transport-failure comment durable-body; then
echo "Expected provider transport failure to return nonzero" >&2
exit 1
fi
if run_review write-http-failure comment durable-body; then
echo "Expected non-201 provider write to return nonzero" >&2
exit 1
fi
if run_review readback-failure comment durable-body; then
echo "Expected mismatched provider read-back to return nonzero" >&2
exit 1
fi
if grep -q 'Added and verified comment' "$OUTPUT_FILE"; then
echo "Read-back mismatch reported durable success" >&2
exit 1
fi
echo "pr-review.sh durable Gitea comment regression passed"

View File

@@ -50,6 +50,21 @@ if ! [[ "$FILE_PATH" =~ \.(ts|tsx|js|jsx|mjs|cjs)$ ]]; then
exit 0
fi
# Deps preflight (#856): this hook is the common gate-entry seam the delivery
# cycle invokes on every Edit/Write/MultiEdit — it fires before any pnpm-based
# gate (test/lint/typecheck/format:check) runs against the edited file. In a
# freshly created git worktree (pnpm workspaces do NOT share node_modules
# across worktrees), node_modules/.bin is empty until `pnpm install` has run,
# so gate binaries (tsc/eslint/prettier/vitest) fail with a raw, illegible
# `sh: 1: <tool>: not found` that is indistinguishable from a real failure.
# Fail legibly here instead, before that raw error has a chance to surface.
BIN_DIR="$PROJECT_ROOT/node_modules/.bin"
if [ ! -d "$BIN_DIR" ] || [ -z "$(ls -A "$BIN_DIR" 2>/dev/null)" ]; then
echo "deps not installed — run pnpm install" >&2
echo "[$(date '+%Y-%m-%d %H:%M:%S')] [ERROR] deps not installed — run pnpm install ($BIN_DIR is missing or empty)" >> "$LOG_FILE"
exit 1
fi
# Call the main QA handler with extracted parameters
if [ -f ~/.config/mosaic/tools/qa/qa-hook-handler.sh ]; then
echo "[$(date '+%Y-%m-%d %H:%M:%S')] Calling QA handler for $FILE_PATH" >> "$LOG_FILE"

View File

@@ -0,0 +1,116 @@
#!/usr/bin/env bash
# Regression harness for #856: worker git-worktrees under a fresh `git worktree
# add` have no node_modules until `pnpm install` runs (pnpm workspaces do NOT
# share node_modules across worktrees). Before the fix, the gate-entry seam
# (qa-hook-stdin.sh, registered as the PostToolUse hook for every Edit/Write/
# MultiEdit in runtime/claude/settings.json) silently let a raw
# `sh: 1: <tool>: not found` surface from any downstream gate invocation —
# indistinguishable from a real test/lint failure (false-red).
#
# Asserts:
# 1. RED (documented): a completely fresh worktree with no node_modules/.bin
# at all produces the raw "not found" for a gate binary — this is the
# defect the fix prevents from reaching the operator un-annotated.
# 2. With node_modules/.bin missing entirely, the seam exits nonzero with
# the legible sentinel "deps not installed — run pnpm install" instead
# of silently proceeding (exit 0) into a would-be raw not-found.
# 3. With node_modules/.bin present but empty, same legible-sentinel
# behavior (covers `git worktree add` immediately followed by an
# as-yet-incomplete/interrupted install).
# 4. Once node_modules/.bin is populated (post `pnpm install`), the seam
# proceeds normally (exit 0) — the preflight does not false-positive.
# 5. Non-JS/TS files are unaffected (existing skip behavior preserved).
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
HOOK="$SCRIPT_DIR/qa-hook-stdin.sh"
TMP_DIR=$(mktemp -d)
trap 'rm -rf "$TMP_DIR"' EXIT
fail=0
fail_msg() {
echo "FAIL: $*" >&2
fail=1
}
run_hook() {
local file_path="$1"
printf '{"tool_name":"Edit","tool_input":{"file_path":"%s"}}' "$file_path" | "$HOOK"
}
make_fixture_repo() {
local dir="$1"
mkdir -p "$dir"
git -C "$dir" init -q .
git -C "$dir" -c user.email=fixture@test -c user.name=fixture commit -q --allow-empty -m init
}
# --- Scenario 1: RED — document the pre-fix raw not-found a gate hits when
# node_modules/.bin is entirely absent (this is what the preflight now
# intercepts before any gate command runs).
RED_DIR="$TMP_DIR/red-fixture"
make_fixture_repo "$RED_DIR"
RED_OUTPUT=$(PATH="/usr/bin:/bin" sh -c 'tsc --noEmit' 2>&1) && RED_STATUS=0 || RED_STATUS=$?
case "$RED_OUTPUT" in
*"not found"*) ;;
*) fail_msg "expected the raw un-preflighted invocation to demonstrate 'not found'; got: $RED_OUTPUT" ;;
esac
[[ "$RED_STATUS" -ne 0 ]] || fail_msg "expected raw invocation without deps installed to fail"
# --- Scenario 2: node_modules/.bin missing entirely -> legible sentinel, nonzero.
MISSING_DIR="$TMP_DIR/missing-bin"
make_fixture_repo "$MISSING_DIR"
echo "console.log(1)" > "$MISSING_DIR/x.ts"
OUTPUT=$(cd "$MISSING_DIR" && run_hook "$MISSING_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
[[ "$STATUS" -ne 0 ]] || fail_msg "missing node_modules/.bin: expected nonzero exit, got 0"
case "$OUTPUT" in
*"deps not installed"*"pnpm install"*) ;;
*) fail_msg "missing node_modules/.bin: expected legible sentinel, got: $OUTPUT" ;;
esac
# --- Scenario 3: node_modules/.bin present but empty -> legible sentinel, nonzero.
EMPTY_DIR="$TMP_DIR/empty-bin"
make_fixture_repo "$EMPTY_DIR"
mkdir -p "$EMPTY_DIR/node_modules/.bin"
echo "console.log(1)" > "$EMPTY_DIR/x.ts"
OUTPUT=$(cd "$EMPTY_DIR" && run_hook "$EMPTY_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
[[ "$STATUS" -ne 0 ]] || fail_msg "empty node_modules/.bin: expected nonzero exit, got 0"
case "$OUTPUT" in
*"deps not installed"*"pnpm install"*) ;;
*) fail_msg "empty node_modules/.bin: expected legible sentinel, got: $OUTPUT" ;;
esac
# --- Scenario 4: node_modules/.bin populated (post `pnpm install`) -> proceeds normally.
OK_DIR="$TMP_DIR/installed-bin"
make_fixture_repo "$OK_DIR"
mkdir -p "$OK_DIR/node_modules/.bin"
printf '#!/bin/sh\necho ok\n' > "$OK_DIR/node_modules/.bin/tsc"
chmod +x "$OK_DIR/node_modules/.bin/tsc"
echo "console.log(1)" > "$OK_DIR/x.ts"
OUTPUT=$(cd "$OK_DIR" && run_hook "$OK_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
[[ "$STATUS" -eq 0 ]] || fail_msg "populated node_modules/.bin: expected exit 0, got $STATUS ($OUTPUT)"
case "$OUTPUT" in
*"deps not installed"*) fail_msg "populated node_modules/.bin: unexpected sentinel fired: $OUTPUT" ;;
*) ;;
esac
# --- Scenario 5: non-JS/TS files are unaffected by the preflight (still
# skipped before the deps check, regardless of node_modules state).
NONJS_DIR="$TMP_DIR/nonjs"
make_fixture_repo "$NONJS_DIR"
echo "# doc" > "$NONJS_DIR/README.md"
OUTPUT=$(cd "$NONJS_DIR" && run_hook "$NONJS_DIR/README.md" 2>&1) && STATUS=0 || STATUS=$?
[[ "$STATUS" -eq 0 ]] || fail_msg "non-JS/TS file: expected exit 0 (skip), got $STATUS ($OUTPUT)"
case "$OUTPUT" in
*"deps not installed"*) fail_msg "non-JS/TS file: preflight incorrectly fired: $OUTPUT" ;;
*) ;;
esac
if [[ "$fail" -eq 0 ]]; then
echo "deps-preflight regression passed (5/5 scenarios)"
fi
exit "$fail"

View File

@@ -25,7 +25,7 @@
"lint": "eslint src",
"typecheck": "tsc --noEmit",
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh"
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh"
},
"dependencies": {
"@mosaicstack/brain": "workspace:*",

View File

@@ -661,13 +661,27 @@ describe('whole mutator-class lease gate', () => {
test('observer revocation and monotonic TTL expiry deny the next mutator', async () => {
const { socket } = await startBroker();
const sessionId = await register(socket);
const pending = await beginVerification(socket, sessionId, 'claude', 1, 1);
await promote(socket, sessionId, pending.receipt_challenge!);
// Establish the lease with a normal (non-racing) TTL first and prove it
// authorizes. This "still valid" check is setup, not a TTL-expiry
// assertion, so it must not share a lease with a 1-second TTL: on a
// contended push-CI host, scheduling delay alone between promote() and
// this authorize() call can consume that entire 1-second margin and
// spuriously deny it (CI#1945). Using a generous TTL here removes that
// real-time race without touching lease-gate security semantics.
const pending = await beginVerification(socket, sessionId, 'claude');
await promote(socket, sessionId, pending.receipt_challenge!);
expect(await authorize(socket, sessionId, 'claude', 'Bash')).toMatchObject({
ok: true,
decision: 'allow',
});
// A dedicated, isolated short-TTL lease drives the deliberate monotonic
// expiry demonstration below. It is never used for anything but the
// wait-then-expire assertion, so there is no setup work racing its
// 1-second window.
const shortLived = await beginVerification(socket, sessionId, 'claude', 1, 1, 2);
await promote(socket, sessionId, shortLived.receipt_challenge!);
await new Promise((resolve) => setTimeout(resolve, 1_100));
expect(await authorize(socket, sessionId, 'claude', 'Bash')).toMatchObject({
ok: false,
@@ -675,7 +689,7 @@ describe('whole mutator-class lease gate', () => {
decision: 'deny',
});
const refreshed = await beginVerification(socket, sessionId, 'claude', 1, 300, 2);
const refreshed = await beginVerification(socket, sessionId, 'claude', 1, 300, 3);
await promote(socket, sessionId, refreshed.receipt_challenge!);
expect(
await request(socket, {

View File

@@ -217,12 +217,22 @@ git fetch origin
mkdir -p ~/src/${projectName}-worktrees
git worktree add ~/src/${projectName}-worktrees/<task-slug> -b <branch-name> origin/main
cd ~/src/${projectName}-worktrees/<task-slug>
pnpm install --frozen-lockfile --prefer-offline
# ... all work happens here ...
git push origin <branch-name>
cd ~/src/${projectName} && git worktree remove ~/src/${projectName}-worktrees/<task-slug>
\`\`\`
Worktrees path: \`~/src/<repo>-worktrees/<task-slug>\` — NEVER use /tmp.`);
Worktrees path: \`~/src/<repo>-worktrees/<task-slug>\` — NEVER use /tmp.
\`pnpm install --frozen-lockfile --prefer-offline\` MUST run immediately after
\`git worktree add\`/\`cd\`, BEFORE any gate (\`pnpm test\`/\`lint\`/\`typecheck\`/\`format:check\`)
is invoked. pnpm workspaces do NOT share \`node_modules\` across separate git
worktrees — a fresh worktree has an empty \`node_modules/.bin\`, so every gate
binary (\`tsc\`/\`eslint\`/\`prettier\`/\`vitest\`) fails \`sh: 1: <tool>: not found\`
until deps are installed. That failure is indistinguishable from a real
test/lint failure — a false-red gate. Never skip this step and never reorder
it after the first gate invocation.`);
// 6. Completion gates
sections.push(`# Completion Gates — ENFORCED

View File

@@ -0,0 +1,50 @@
# Skill: glpi-create — Open a New GLPI Ticket
> Create a new GLPI helpdesk ticket. Mutates GLPI — confirm the details before running.
## When to use
- Logging a new incident or request that should live in the helpdesk queue.
## Required information
- **title** — short subject line.
- **content** — description of the issue / request.
## Optional
- **priority** — `1`=VeryLow, `2`=Low, `3`=Medium (default), `4`=High, `5`=VeryHigh, `6`=Major.
- **type** — `1`=Incident (default), `2`=Request.
## Command
Wraps the existing tooling:
```bash
~/.config/mosaic/tools/glpi/ticket-create.sh \
-t "<title>" \
-c "<content>" \
[-p <priority>] \
[-y <type>] \
[-f json]
```
Example:
```bash
~/.config/mosaic/tools/glpi/ticket-create.sh \
-t "Paint-area camera install" \
-c "Ordered 2 cameras for Paint and stock; schedule mounting + NVR config." \
-p 3 -y 2
```
## After creating
- Note the returned **ticket ID** — you'll need it for **[[glpi-followup]]** and
**[[glpi-solve]]**.
- If it should also be tracked as brain work, add a matching task (see the `add-task` skill).
## Guardrails
- Confirm title/content/priority with the user before creating — a ticket is outward-facing.
- Never echo GLPI tokens.

View File

@@ -0,0 +1,56 @@
# Skill: glpi-followup — Add a Followup to a GLPI Ticket
> Post a followup (comment / progress note / resolution writeup) to a GLPI ticket.
> This documents work but does **not** change the ticket status — to close a ticket
> out, follow with **[[glpi-solve]]** to set status to Solved.
## When to use
- Recording progress, a decision, or a root-cause/resolution note on a ticket.
- The documentation step that usually precedes closing a ticket out (`glpi-solve`).
## Critical quirk
Use the **top-level `/ITILFollowup` endpoint**, NOT `/Ticket/<id>/ITILFollowup`. The
sub-resource path returns permission errors even with a Super-Admin profile.
## Procedure
### 1. Session + creds
```bash
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
```
### 2. Post the followup
```bash
TICKET_ID=<id>
CONTENT="<the followup text>"
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
-H "App-Token: $GLPI_APP_TOKEN" \
-H "Session-Token: $SESSION" \
-H "Content-Type: application/json" \
-d "$(jq -n --argjson id "$TICKET_ID" --arg c "$CONTENT" \
'{input:{itemtype:"Ticket", items_id:$id, content:$c}}')"
```
Expect HTTP 201. Building the payload with `jq` keeps quotes/newlines in the content safe.
### 3. Long or multi-paragraph content
Write the note to a file first, then read it into the payload:
```bash
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
-H "Content-Type: application/json" \
-d "$(jq -n --argjson id "$TICKET_ID" --rawfile c /path/to/note.md \
'{input:{itemtype:"Ticket", items_id:$id, content:$c}}')"
```
## Guardrails
- Never echo the GLPI app/user/session tokens.
- A followup alone leaves the ticket open. If the work is done, run **[[glpi-solve]]** next.

57
skills/glpi-list/SKILL.md Normal file
View File

@@ -0,0 +1,57 @@
# Skill: glpi-list — Query GLPI Tickets
> Quick lookups of GLPI helpdesk tickets by status or recency. Read-only.
## When to use
- "What tickets are open / pending?" · "Show recent tickets" · finding a ticket ID
before running **[[glpi-followup]]** or **[[glpi-solve]]**.
## Command
Wraps the existing tooling:
```bash
GLPI=~/.config/mosaic/tools/glpi
# Most recent tickets (default 50, newest first)
"$GLPI/ticket-list.sh"
# Filter by status: new | processing | pending | solved | closed
"$GLPI/ticket-list.sh" -s pending
# JSON output (for parsing / piping to jq) and a custom limit
"$GLPI/ticket-list.sh" -s processing -f json -l 20
```
Status IDs: 1 New · 2/3 Processing · 4 Pending · 5 Solved · 6 Closed.
## Details lookup for one ticket
When you have an ID and want the full record:
```bash
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
curl -sk "${GLPI_URL}/Ticket/<id>?expand_dropdowns=true" \
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
| jq '{id, name, status, date, date_mod}'
# Followups on a ticket
curl -sk "${GLPI_URL}/Ticket/<id>/ITILFollowup" \
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
| jq '.[] | {date, content}'
```
(Reading followups via the sub-resource is fine — only _creating_ them requires the
top-level `/ITILFollowup` endpoint. See **[[glpi-followup]]**.)
## Present to user
Group by status, one line per ticket: `#<id> · <title> · <status> · <last-modified>`.
Use neutral phrasing — no "OVERDUE"/"URGENT".
## Guardrails
- Read-only. Never echo GLPI tokens.
- To sync tickets into brain data instead, use `python tools/sync_glpi.py` (not this skill).

View File

@@ -0,0 +1,96 @@
# Skill: glpi-solve — Close Out a GLPI Ticket
> Properly close out a completed GLPI helpdesk ticket. Completing the work is not
> enough — the ticket **status must be set to "Solved"**, which is what triggers
> GLPI's config-driven auto-close. Posting a resolution followup documents the work
> but does **not** change status, so a ticket left at Solved-less status stays open.
## When to use
- Any time work on a GLPI ticket is finished and it should be closed out.
- After posting a root-cause / resolution writeup as an `/ITILFollowup`.
- During a cleanup sweep of tickets that are done in reality but still open in GLPI.
## The rule (from an operator, 2026-07-20)
**"Solved" is the correct terminal state to set — not "Closed."** GLPI is configured
to auto-close Solved tickets after its delay. If you only post a followup and never set
status, the ticket sits open (this bit us on a real incident where resolution followups
were posted but status was never advanced, leaving tickets open, which the operator had
to mark Solved by hand).
Close-out = **followup (optional but preferred) + set status to Solved.**
## GLPI status IDs
| ID | Status | |
| ----- | --------------------- | -------------------------------------------- |
| 1 | New | |
| 2 | Processing (assigned) | |
| 3 | Processing (planned) | |
| 4 | Pending / Waiting | |
| **5** | **Solved** | ← set this on close-out |
| 6 | Closed | ← happens automatically; do not set manually |
## Procedure
### 1. Get a session token
```bash
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
```
### 2. (Preferred) Post the resolution followup
Use the **top-level `/ITILFollowup` endpoint** — the `/Ticket/<id>/ITILFollowup`
sub-resource returns permission errors even as Super-Admin (known GLPI quirk).
```bash
TICKET_ID=<id>
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
-H "App-Token: $GLPI_APP_TOKEN" \
-H "Session-Token: $SESSION" \
-H "Content-Type: application/json" \
-d "{\"input\":{\"itemtype\":\"Ticket\",\"items_id\":${TICKET_ID},\"content\":\"<resolution summary>\"}}"
```
### 3. Set status to Solved (the step that actually closes it out)
```bash
curl -sk -X PUT "${GLPI_URL}/Ticket/${TICKET_ID}" \
-H "App-Token: $GLPI_APP_TOKEN" \
-H "Session-Token: $SESSION" \
-H "Content-Type: application/json" \
-d "{\"input\":{\"id\":${TICKET_ID},\"status\":5}}"
```
Expect HTTP 200/201. GLPI will auto-close it later per its config — leave status at 5.
### 4. Verify
```bash
curl -sk "${GLPI_URL}/Ticket/${TICKET_ID}?expand_dropdowns=true" \
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
| jq '{id, name, status}'
```
`status` should read `Solved` (or `5`).
## Optional: sweep for done-but-open tickets
List tickets still open (New/Processing/Pending) to spot ones whose work is actually
finished but were never marked Solved:
```bash
~/.config/mosaic/tools/glpi/ticket-list.sh -s processing -f table
~/.config/mosaic/tools/glpi/ticket-list.sh -s pending -f table
```
Review each; for any that are genuinely resolved, run steps 23.
## Guardrails
- Read-only until you intend to close — confirm the ticket is actually done first.
- Never echo the GLPI app/user/session tokens.
- Set **Solved (5)**, never Closed (6) — auto-close owns that transition.

View File

@@ -0,0 +1,62 @@
# Skill: glpi-sweep — Find Done-But-Open Tickets
> Read-only sweep for tickets that are finished in reality but still sitting open in
> GLPI (never moved to Solved). Surfaces the exact miss an operator caught on 2026-07-20
> (a real incident where an affected ticket had resolution followups posted but was left
> open). For each one that's genuinely done, close it out with **[[glpi-solve]]**.
## When to use
- Periodic hygiene pass (e.g. before a weekly update or month-end).
- After a burst of ticket work, to catch any you resolved-in-followup but never Solved.
## Why this exists
Posting an `/ITILFollowup` documents work but does **not** change status. Tickets only
auto-close once set to **Solved (status 5)**. Anything left at New/Processing/Pending
stays open indefinitely. This sweep finds those.
## Procedure
### 1. List still-open tickets by status
```bash
GLPI=~/.config/mosaic/tools/glpi
"$GLPI/ticket-list.sh" -s new -f table
"$GLPI/ticket-list.sh" -s processing -f table
"$GLPI/ticket-list.sh" -s pending -f table
```
(GLPI status IDs: 1 New · 2/3 Processing · 4 Pending · 5 Solved · 6 Closed.)
### 2. Triage
For each open ticket, judge whether the underlying work is actually finished — check
its latest followups and cross-reference brain tasks / recent work. Read-only here;
change nothing yet.
Reasonable "probably done" signals:
- A resolution/root-cause followup already posted, but status never advanced.
- The related brain task is `done`, or the fix shipped and was confirmed.
- Requester confirmed resolution but the ticket was never Solved.
### 3. Present the candidates
List them for review before touching anything — never bulk-solve blindly:
```
Open tickets that look resolved:
- #<id> "<title>" — <why it looks done> → glpi-solve?
```
### 4. Close out the confirmed ones
For each ticket the user (or clear evidence) confirms is done, run **[[glpi-solve]]**
(optionally **[[glpi-followup]]** first if a closing note is warranted).
## Guardrails
- Read-only until a ticket is confirmed done — do not auto-solve on a guess.
- Never echo GLPI tokens.
- Set **Solved (5)**, never Closed (6) — GLPI auto-close owns that transition.