Compare commits
4
Commits
main
..
3934e03fa6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3934e03fa6 | ||
|
|
fd26532757 | ||
|
|
c395ecae84 | ||
|
|
c5a5f9d362 |
@@ -46,10 +46,6 @@ steps:
|
|||||||
# [0] of the pnpm chain, so severing that chain would silence it together
|
# [0] of the pnpm chain, so severing that chain would silence it together
|
||||||
# with everything it guards; this direct line keeps one instrument running.
|
# with everything it guards; this direct line keeps one instrument running.
|
||||||
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
||||||
# Hermetic regression for issue-close.sh (#1081): mocks tea/curl onto PATH
|
|
||||||
# and sandboxes a throwaway git repo, so it resolves no real credentials and
|
|
||||||
# joins CI directly rather than the exclusions file.
|
|
||||||
- bash packages/mosaic/framework/tools/git/test-issue-close-fail-closed.sh
|
|
||||||
|
|
||||||
# Blocking gate (#791): a framework upgrade must never write or delete an
|
# Blocking gate (#791): a framework upgrade must never write or delete an
|
||||||
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
||||||
|
|||||||
@@ -0,0 +1,49 @@
|
|||||||
|
# C1 detector gate. The fixture itself is intentionally RED; CI is green only
|
||||||
|
# when its exact phase verdicts/reasons match the versioned expected-RED manifest.
|
||||||
|
when:
|
||||||
|
- event: [pull_request, manual]
|
||||||
|
- event: push
|
||||||
|
branch: [next, main]
|
||||||
|
|
||||||
|
steps:
|
||||||
|
greenfield-git-present:
|
||||||
|
image: node:22-bookworm-slim
|
||||||
|
commands:
|
||||||
|
- |
|
||||||
|
set +e
|
||||||
|
MOSAIC_GREENFIELD_CONTAINER=1 \
|
||||||
|
bash tools/e2e-install-test.sh --lane next --source checkout --git present \
|
||||||
|
> /tmp/greenfield-git-present.log 2>&1
|
||||||
|
fixture_status=$?
|
||||||
|
set -e
|
||||||
|
cat /tmp/greenfield-git-present.log
|
||||||
|
bash tools/verify-greenfield-expected-red.sh \
|
||||||
|
next-git-present /tmp/greenfield-git-present.log "$fixture_status"
|
||||||
|
|
||||||
|
greenfield-main-git-present:
|
||||||
|
image: node:22-bookworm-slim
|
||||||
|
commands:
|
||||||
|
- |
|
||||||
|
set +e
|
||||||
|
MOSAIC_GREENFIELD_CONTAINER=1 \
|
||||||
|
bash tools/e2e-install-test.sh --lane main --source checkout --git present \
|
||||||
|
> /tmp/greenfield-main-git-present.log 2>&1
|
||||||
|
fixture_status=$?
|
||||||
|
set -e
|
||||||
|
cat /tmp/greenfield-main-git-present.log
|
||||||
|
bash tools/verify-greenfield-expected-red.sh \
|
||||||
|
main-git-present /tmp/greenfield-main-git-present.log "$fixture_status"
|
||||||
|
|
||||||
|
greenfield-git-absent:
|
||||||
|
image: node:22-bookworm-slim
|
||||||
|
commands:
|
||||||
|
- |
|
||||||
|
set +e
|
||||||
|
MOSAIC_GREENFIELD_CONTAINER=1 \
|
||||||
|
bash tools/e2e-install-test.sh --lane next --source checkout --git absent \
|
||||||
|
> /tmp/greenfield-git-absent.log 2>&1
|
||||||
|
fixture_status=$?
|
||||||
|
set -e
|
||||||
|
cat /tmp/greenfield-git-absent.log
|
||||||
|
bash tools/verify-greenfield-expected-red.sh \
|
||||||
|
next-git-absent /tmp/greenfield-git-absent.log "$fixture_status"
|
||||||
@@ -7,7 +7,7 @@ Mosaic gives you a unified launcher for Claude Code, Codex, OpenCode, and Pi —
|
|||||||
## Quick Install
|
## Quick Install
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSL https://mosaicstack.dev/install.sh | bash
|
bash -o pipefail -c 'curl -fsSL https://mosaicstack.dev/install.sh | bash'
|
||||||
```
|
```
|
||||||
|
|
||||||
Or use the direct URL:
|
Or use the direct URL:
|
||||||
@@ -30,6 +30,16 @@ This installs both components:
|
|||||||
| **Framework** | Bash launcher, guides, runtime configs, tools, skills | `~/.config/mosaic/` |
|
| **Framework** | Bash launcher, guides, runtime configs, tools, skills | `~/.config/mosaic/` |
|
||||||
| **@mosaicstack/mosaic** | Unified `mosaic` CLI — TUI, gateway client, wizard, auto-updater | `~/.npm-global/bin/` |
|
| **@mosaicstack/mosaic** | Unified `mosaic` CLI — TUI, gateway client, wizard, auto-updater | `~/.npm-global/bin/` |
|
||||||
|
|
||||||
|
### Install lanes
|
||||||
|
|
||||||
|
| Lane | Command | Use when | Source |
|
||||||
|
| ------------------------ | ------------------------------------- | ----------------------------------------------------- | ------------------------------------------------------------------------------------------- |
|
||||||
|
| Stable | `bash tools/install.sh` | You want the released Mosaic CLI/framework | npm registry `@mosaicstack/mosaic@latest` + framework archive at `main` |
|
||||||
|
| Prerelease integration | `bash tools/install.sh --next` | You want the current `next` integration branch | Exact `@next` CLI/gateway versions + pinned `next` framework commit; pinned-source fallback |
|
||||||
|
| Contributor/source build | `bash tools/install.sh --dev --ref X` | You are testing a branch before release; `--ref` wins | Build-from-source at the requested ref |
|
||||||
|
|
||||||
|
`--next` selects the prerelease integration lane. It installs the exact CLI/gateway versions resolved from the aligned `@next` tags, and pins the framework archive to the resolved `next` commit. If the registry path fails, it builds from that pinned source. An explicit `--ref` or `MOSAIC_REF` wins and selects source mode.
|
||||||
|
|
||||||
After install, the wizard runs automatically or you can invoke it manually:
|
After install, the wizard runs automatically or you can invoke it manually:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -38,10 +48,14 @@ mosaic wizard # Full guided setup (gateway install → verify)
|
|||||||
|
|
||||||
### Requirements
|
### Requirements
|
||||||
|
|
||||||
- Node.js ≥ 20
|
- Linux x86_64 with glibc (Debian is the greenfield CI platform; musl/Alpine, macOS, and ARM64 currently fail as unsupported)
|
||||||
- npm (for global @mosaicstack/mosaic install)
|
- Node.js ≥ 20 and npm ≥ 9
|
||||||
|
- `bash`, `curl`, `git`, `python3`, `tar`, and standard core utilities (`awk`, `df`, `find`, `flock`, `grep`, `install`, `realpath`, `sed`, `sha256sum`, `stat`, `sync`)
|
||||||
|
- At least 256 MiB free disk and 1,000 free inodes at the npm prefix
|
||||||
- One or more runtimes: [Claude Code](https://docs.anthropic.com/en/docs/claude-code), [Codex](https://github.com/openai/codex), [OpenCode](https://opencode.ai), or [Pi](https://github.com/mariozechner/pi-coding-agent)
|
- One or more runtimes: [Claude Code](https://docs.anthropic.com/en/docs/claude-code), [Codex](https://github.com/openai/codex), [OpenCode](https://opencode.ai), or [Pi](https://github.com/mariozechner/pi-coding-agent)
|
||||||
|
|
||||||
|
The installer evaluates canonical phases P0–P9 and does not print `Done.` unless every committed postcondition passes. A failed phase exits non-zero, names the phase, and points to its durable journal under `${XDG_STATE_HOME:-~/.local/state}/mosaic/install/`. See [Installer state machine and recovery](docs/guides/installer-state-machine.md).
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
### Launching Agent Sessions
|
### Launching Agent Sessions
|
||||||
@@ -60,14 +74,6 @@ The launcher verifies your config, checks for `SOUL.md`, injects your `AGENTS.md
|
|||||||
|
|
||||||
Pi launches default to a token-lean skill posture: `mosaic pi` passes `--no-skills` so Pi does not preload every global skill description into the system prompt. Use `MOSAIC_PI_SKILL_MODE=all mosaic pi` for the legacy all-skills catalog, or `MOSAIC_PI_SKILL_MODE=discover mosaic pi` to let Pi use its native settings/project skill discovery.
|
Pi launches default to a token-lean skill posture: `mosaic pi` passes `--no-skills` so Pi does not preload every global skill description into the system prompt. Use `MOSAIC_PI_SKILL_MODE=all mosaic pi` for the legacy all-skills catalog, or `MOSAIC_PI_SKILL_MODE=discover mosaic pi` to let Pi use its native settings/project skill discovery.
|
||||||
|
|
||||||
Mosaic also loads its Pi extensions from `~/.config/mosaic/runtime/pi/`. Inside Pi,
|
|
||||||
`/goal set <statement>` starts a bounded persistent loop that checks every turn and successful
|
|
||||||
compaction, requires two evidence-bearing completion reports, and can be inspected or stopped with
|
|
||||||
`/goal status`, `/goal pause`, `/goal resume`, and `/goal cancel`. Controller-owned goal-state
|
|
||||||
entries redact common credential shapes, but Pi's model/tool-call history is separate, so goals and
|
|
||||||
evidence must never contain secrets or raw sensitive output. Mosaic does not install this extension
|
|
||||||
into `~/.pi/agent/extensions/`.
|
|
||||||
|
|
||||||
### TUI & Gateway
|
### TUI & Gateway
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -345,7 +351,7 @@ Each stage has a dispatch mode (`exec` for research/review, `yolo` for coding),
|
|||||||
Run the installer again — it handles upgrades automatically:
|
Run the installer again — it handles upgrades automatically:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSL https://mosaicstack.dev/install.sh | bash
|
bash -o pipefail -c 'curl -fsSL https://mosaicstack.dev/install.sh | bash'
|
||||||
```
|
```
|
||||||
|
|
||||||
Or use the direct URL:
|
Or use the direct URL:
|
||||||
@@ -366,15 +372,17 @@ The CLI also performs a background update check on every invocation (cached for
|
|||||||
### Installer Flags
|
### Installer Flags
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
bash tools/install.sh --check # Version check only
|
bash tools/install.sh --check # Side-effect-free P0-P8 postcondition check
|
||||||
bash tools/install.sh --framework # Framework only (skip npm CLI)
|
bash tools/install.sh --framework # Framework only (skip npm CLI)
|
||||||
bash tools/install.sh --cli # npm CLI only (skip framework)
|
bash tools/install.sh --cli # npm CLI only (skip framework)
|
||||||
bash tools/install.sh --ref v1.0 # Install from a specific git ref
|
bash tools/install.sh --next # Prerelease lane: exact @next versions + pinned-source fallback
|
||||||
|
bash tools/install.sh --dev # Contributor lane: source build at --ref/main
|
||||||
|
bash tools/install.sh --ref v1.0 # Install from a specific git ref (--ref wins over --next)
|
||||||
bash tools/install.sh --yes # Non-interactive, accept all defaults
|
bash tools/install.sh --yes # Non-interactive, accept all defaults
|
||||||
bash tools/install.sh --no-auto-launch # Skip auto-launch of wizard
|
bash tools/install.sh --no-auto-launch # Skip auto-launch of wizard
|
||||||
```
|
```
|
||||||
|
|
||||||
The installer rejects unrecognized flags or positional arguments before making changes and prints the supported-option usage.
|
The installer rejects unrecognized flags or positional arguments before making changes and prints the supported-option usage. `--check` reports one PASS/FAIL row for each P0–P8 predicate and exits non-zero if any row fails; it does not create the npm prefix, lock, journal, manifest, or runtime files.
|
||||||
|
|
||||||
## Contributing
|
## Contributing
|
||||||
|
|
||||||
|
|||||||
@@ -245,21 +245,9 @@ describe('EnrollmentService.createToken', () => {
|
|||||||
const after = Date.now();
|
const after = Date.now();
|
||||||
|
|
||||||
const expiresMs = new Date(result.expiresAt).getTime();
|
const expiresMs = new Date(result.expiresAt).getTime();
|
||||||
|
// Should be at most 900s from now
|
||||||
// The property under test is CLAMPING: a 9999s request must come back as 900s.
|
expect(expiresMs - before).toBeLessThanOrEqual(900_000 + 100);
|
||||||
// The gap between clamped and unclamped is 9_099_000 ms, so the tolerance below
|
|
||||||
// only has to exceed CI scheduling jitter — it does not need to be tight to keep
|
|
||||||
// the assertion discriminating. A 5s allowance consumes 0.05% of that margin and
|
|
||||||
// an unclamped result still misses by three orders of magnitude.
|
|
||||||
//
|
|
||||||
// It was 100ms and failed on a loaded agent at 900_106 — 6ms over (#1090). A
|
|
||||||
// wall-clock budget sized to a fast machine is a flake, not a tighter test.
|
|
||||||
const CI_JITTER_MS = 5_000;
|
|
||||||
expect(expiresMs - before).toBeLessThanOrEqual(900_000 + CI_JITTER_MS);
|
|
||||||
expect(expiresMs - after).toBeGreaterThanOrEqual(0);
|
expect(expiresMs - after).toBeGreaterThanOrEqual(0);
|
||||||
// Explicitly pin the clamp itself, independent of any timing allowance:
|
|
||||||
// unclamped (9999s) would exceed this by ~9_099_000 ms.
|
|
||||||
expect(expiresMs - before).toBeLessThan(1_000_000);
|
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
+33
-184
@@ -102,128 +102,6 @@ Context compaction, session replacement, and same-PID runtime reloads can leave
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Pi Persistent Goal Loop (#1150)
|
|
||||||
|
|
||||||
### Problem and objective
|
|
||||||
|
|
||||||
A Pi agent can stop after a plausible-looking answer even when the operator's broader objective is
|
|
||||||
not complete, and ordinary compaction can weaken or omit the original objective. Mosaic needs an
|
|
||||||
optional, operator-controlled goal loop that keeps a Pi session oriented, checks progress at native
|
|
||||||
lifecycle boundaries, and resumes work until completion is verified or a bounded safety state is
|
|
||||||
reached.
|
|
||||||
|
|
||||||
The objective is a Mosaic-owned Pi extension deployed from the framework into
|
|
||||||
`~/.config/mosaic/runtime/pi/`. It must not install into or depend on `~/.pi/agent/extensions/`.
|
|
||||||
|
|
||||||
### Scope
|
|
||||||
|
|
||||||
#### In scope
|
|
||||||
|
|
||||||
1. `PGL-REQ-01`: The framework SHALL ship a dedicated Pi goal extension under
|
|
||||||
`packages/mosaic/framework/runtime/pi/`, seed it under `$MOSAIC_HOME/runtime/pi/`, and make
|
|
||||||
`mosaic pi` load it alongside the core Mosaic extension when present.
|
|
||||||
2. `PGL-REQ-02`: `/goal` SHALL support setting a goal plus status, pause, resume, cancel, and help
|
|
||||||
operations without silently replacing an active goal.
|
|
||||||
3. `PGL-REQ-03`: Active branch-specific goal state SHALL be persisted in Pi custom session entries,
|
|
||||||
restored on session start and tree navigation, and never rely on a compaction summary as its
|
|
||||||
source of truth.
|
|
||||||
4. `PGL-REQ-04`: A hidden goal contract SHALL be injected through Pi's `context` event before every
|
|
||||||
model request so it remains effective across tool turns, retries, and post-compaction requests.
|
|
||||||
5. `PGL-REQ-05`: The harness SHALL inspect every `turn_end` and successful `session_compact` event.
|
|
||||||
A structured terminating goal-report tool SHALL capture `continue`, evidence-bearing `achieved`,
|
|
||||||
or `blocked` status without requiring a redundant model turn.
|
|
||||||
6. `PGL-REQ-06`: An achievement claim SHALL remain provisional until a second consecutive
|
|
||||||
evidence-bearing verification report. Any continuation report or successful compaction during
|
|
||||||
verification SHALL reset the verification sequence.
|
|
||||||
7. `PGL-REQ-07`: Continuation SHALL be initiated at safe lifecycle boundaries, primarily
|
|
||||||
`agent_settled`; manual compaction and restored active sessions may schedule a deferred idle
|
|
||||||
continuation without re-entering compaction handlers.
|
|
||||||
8. `PGL-REQ-08`: The loop SHALL have operator cancellation plus bounded turn and repeated-no-progress
|
|
||||||
limits. Exhausted or blocked goals pause rather than continuing indefinitely.
|
|
||||||
9. `PGL-REQ-09`: Framework installation and update SHALL preserve normal manifest ownership: the
|
|
||||||
goal extension is framework-owned under `runtime/**`, while no goal extension or configuration
|
|
||||||
asset is created or modified under the operator's main Pi configuration. Pi remains the owner of
|
|
||||||
its native session files used by `appendEntry()`.
|
|
||||||
|
|
||||||
#### Out of scope
|
|
||||||
|
|
||||||
1. A mathematical guarantee that an arbitrary natural-language goal is semantically complete.
|
|
||||||
2. Automatically executing user-supplied shell predicates or accepting executable validation code in
|
|
||||||
`/goal` arguments.
|
|
||||||
3. Restarting Pi after process, host, or supervisor failure; the existing Mosaic fleet/runtime
|
|
||||||
supervisor owns process durability.
|
|
||||||
4. Gateway, database, web UI, Discord, or cross-harness goal orchestration in this slice.
|
|
||||||
|
|
||||||
### User and stakeholder requirements
|
|
||||||
|
|
||||||
- An operator can start a goal from Pi and see its current phase, evidence, limits, and latest report.
|
|
||||||
- The agent remains oriented after each turn and compaction until verified, paused, blocked,
|
|
||||||
exhausted, or cancelled.
|
|
||||||
- Local testing uses a file under `~/.config/mosaic/runtime/pi/`; the feature never writes an
|
|
||||||
extension asset to `~/.pi/agent/extensions/`.
|
|
||||||
- Framework updates deploy the same reviewed extension source through Mosaic's existing manifest
|
|
||||||
sync path.
|
|
||||||
|
|
||||||
### Non-functional requirements
|
|
||||||
|
|
||||||
1. **Safety:** bounded continuation, explicit cancellation, no arbitrary command execution, and no
|
|
||||||
completion without non-empty reported evidence.
|
|
||||||
2. **Reliability:** serialized continuation scheduling, branch-aware restoration, compaction-safe
|
|
||||||
context injection, and stale-timer cancellation on session shutdown.
|
|
||||||
3. **Performance:** no extra nested judge-model request on every turn; structured reporting uses the
|
|
||||||
active agent's final terminating tool call.
|
|
||||||
4. **Observability:** Pi status/notifications expose phase and bounded counters without recording
|
|
||||||
credentials or hidden model reasoning.
|
|
||||||
5. **Maintainability:** the state machine is deterministic and behavior-tested independently from Pi
|
|
||||||
provider/network access.
|
|
||||||
|
|
||||||
### Acceptance criteria
|
|
||||||
|
|
||||||
1. `AC-PGL-01`: A framework-sync fixture installs the extension at
|
|
||||||
`$MOSAIC_HOME/runtime/pi/goal-extension.ts`, and launcher tests prove both Mosaic Pi extensions are
|
|
||||||
emitted in deterministic order while absent optional files remain backward-compatible.
|
|
||||||
2. `AC-PGL-02`: Command tests prove set/status/pause/resume/cancel behavior, active-goal replacement
|
|
||||||
refusal, and bounded input handling.
|
|
||||||
3. `AC-PGL-03`: Lifecycle tests prove every turn is recorded, active context is injected on every
|
|
||||||
request, two evidence-bearing achievement reports are required, and `agent_settled` continues an
|
|
||||||
unmet goal without duplicate scheduling.
|
|
||||||
4. `AC-PGL-04`: Compaction and restoration tests prove goal state survives, verification is reset and
|
|
||||||
rechecked after compaction, manual compaction continuation is deferred until idle, and tree/session
|
|
||||||
branch state is reconstructed correctly.
|
|
||||||
5. `AC-PGL-05`: Limit tests prove max-turn and repeated-no-progress exhaustion stop autonomous
|
|
||||||
continuation, while pause/cancel/blocked states do not restart.
|
|
||||||
6. `AC-PGL-06`: Focused tests, package typecheck/lint/test, repository quality gates, a local Pi load
|
|
||||||
smoke test from `~/.config/mosaic/runtime/pi/`, independent review, and terminal-green CI pass before
|
|
||||||
issue #1150 closes.
|
|
||||||
|
|
||||||
### Constraints, risks, and assumptions
|
|
||||||
|
|
||||||
- Dependency: Pi's extension API must continue to provide `registerCommand`, `registerTool`,
|
|
||||||
`context`, `turn_end`, `agent_settled`, `session_compact`, session custom entries, and terminating
|
|
||||||
tool results.
|
|
||||||
- Risk: the working agent can overstate completion. Mitigation: structured evidence, a mandatory
|
|
||||||
second verification pass, explicit semantic limitations, and operator-visible reports.
|
|
||||||
- Risk: an impossible goal can consume unbounded resources. Mitigation: hard turn/no-progress bounds
|
|
||||||
and paused terminal states.
|
|
||||||
- Risk: automatic continuation can race compaction or session replacement. Mitigation: drive from
|
|
||||||
`agent_settled`, defer idle restarts, generation-check timers, and clear timers on shutdown.
|
|
||||||
- `ASSUMPTION:` Two consecutive evidence-bearing reports are the initial local verification policy;
|
|
||||||
rationale: it provides a real recheck without doubling every turn's model cost. Future policy may
|
|
||||||
add independent or deterministic validators.
|
|
||||||
- `ASSUMPTION:` Default limits are 40 turns and 6 repeated no-progress reports, configurable only by
|
|
||||||
bounded Mosaic environment settings; rationale: useful persistence with a finite autonomous budget.
|
|
||||||
- `ASSUMPTION:` Documentation remains canonical in-repo for this slice; no external docs publication
|
|
||||||
is requested.
|
|
||||||
|
|
||||||
### Testing and delivery intent
|
|
||||||
|
|
||||||
Use TDD for the deterministic controller and lifecycle invariants. Test with fake Pi lifecycle
|
|
||||||
objects first, then run a local load/smoke test from the deployed Mosaic path. Deliver source, tests,
|
|
||||||
launcher wiring, framework/runtime documentation, user/developer guides, and sitemap updates in one
|
|
||||||
reviewed squash PR to `main` with terminal-green CI.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Fleet Declarative Configuration Management Workstream (FCM, #758)
|
## Fleet Declarative Configuration Management Workstream (FCM, #758)
|
||||||
|
|
||||||
### Problem and objective
|
### Problem and objective
|
||||||
@@ -268,68 +146,6 @@ lands. M0 consists only of these normative requirements, the complete task DAG,
|
|||||||
documentation IA checklist, and the legacy example/profile disposition inventory. Subsequent cards
|
documentation IA checklist, and the legacy example/profile disposition inventory. Subsequent cards
|
||||||
are defined in [docs/TASKS.md](./TASKS.md) and must remain one card/one PR.
|
are defined in [docs/TASKS.md](./TASKS.md) and must remain one card/one PR.
|
||||||
|
|
||||||
### Fleet git identity launch propagation (#1043)
|
|
||||||
|
|
||||||
#### Problem and objective
|
|
||||||
|
|
||||||
A fleet seat can have a registered per-agent Git credential while its launched runtime process lacks
|
|
||||||
`MOSAIC_GIT_IDENTITY`. The credential resolver then cannot select the seat identity reliably, which
|
|
||||||
blocks repository operations on fail-closed estates and can fall through to an unrelated identity on
|
|
||||||
estates where that refusal is not active. The objective is to make Git identity a deterministic,
|
|
||||||
roster-derived part of the generated launch projection and prove it reaches the launched process.
|
|
||||||
|
|
||||||
#### Normative requirements
|
|
||||||
|
|
||||||
1. `FGI-REQ-01`: Every generated fleet agent projection SHALL declare
|
|
||||||
`MOSAIC_GIT_IDENTITY=<MOSAIC_AGENT_NAME>`; a differing or unsafe identity SHALL fail closed before
|
|
||||||
tmux launch.
|
|
||||||
2. `FGI-REQ-02`: The clean `/usr/bin/env -i` pane boundary SHALL pass every variable declared by the
|
|
||||||
generated projection, including `MOSAIC_GIT_IDENTITY`, to the launched runtime process.
|
|
||||||
3. `FGI-REQ-03`: A behavioral integration test SHALL set-compare the complete generated projection
|
|
||||||
against the launched process environment. Source-text/string-presence assertions are insufficient.
|
|
||||||
4. `FGI-REQ-04`: Verification SHALL include RED-first evidence and a delete-the-subject mutation that
|
|
||||||
removes Git-identity pane propagation and makes the behavioral test fail.
|
|
||||||
|
|
||||||
#### Acceptance criteria
|
|
||||||
|
|
||||||
1. `AC-FGI-01`: A launched seat process contains every key/value pair declared by its generated
|
|
||||||
environment projection, including the roster-derived Git identity.
|
|
||||||
2. `AC-FGI-02`: Missing, unsafe, or split Git identity is rejected before a tmux session is created.
|
|
||||||
3. `AC-FGI-03`: Focused launcher and generated-environment tests, repository quality gates,
|
|
||||||
independent review, and the required RED/green/R7 evidence are recorded before push.
|
|
||||||
|
|
||||||
### Framework shell assertion portability (#1098)
|
|
||||||
|
|
||||||
#### Problem and objective
|
|
||||||
|
|
||||||
The blocking framework-shell chain can report that a pane command omitted `/usr/bin/env -i` even when
|
|
||||||
`-i` matched successfully. A short-circuiting `grep -q` under `set -o pipefail` may close its pipe after
|
|
||||||
the match and cause an upstream producer to exit with SIGPIPE, turning a valid semantic result into a
|
|
||||||
nonzero aggregate pipeline. The objective is to inspect the captured NUL-delimited argv directly and
|
|
||||||
make failures carry the observed records needed for diagnosis.
|
|
||||||
|
|
||||||
#### Normative requirements
|
|
||||||
|
|
||||||
1. `FSP-REQ-01`: The pane-boundary test SHALL validate an adjacent `/usr/bin/env`, `-i` argv pair from
|
|
||||||
the authoritative NUL-delimited tmux capture without a short-circuit pipeline whose upstream status
|
|
||||||
can override a successful match.
|
|
||||||
2. `FSP-REQ-02`: Missing, reversed, or non-adjacent boundary tokens SHALL fail, while valid boundaries
|
|
||||||
SHALL remain valid regardless of trailing argv size, pipe capacity, process scheduling, or host/CI
|
|
||||||
utility implementation.
|
|
||||||
3. `FSP-REQ-03`: A failed boundary check SHALL print stable indexed, shell-escaped observed argv records
|
|
||||||
before exiting nonzero; the fixture SHALL continue to contain generated non-secret launch data only.
|
|
||||||
4. `FSP-REQ-04`: Verification SHALL include RED-first large-payload evidence, negative token-order
|
|
||||||
controls, the complete focused launcher suite, canonical Woodpecker CI, and independent review.
|
|
||||||
|
|
||||||
#### Acceptance criteria
|
|
||||||
|
|
||||||
1. `AC-FSP-01`: A large captured argv with adjacent `/usr/bin/env`, `-i` passes even when the former
|
|
||||||
`grep -q` pipeline returns nonzero from an upstream SIGPIPE.
|
|
||||||
2. `AC-FSP-02`: Missing executable, missing flag, and detached/reversed flag fixtures return nonzero and
|
|
||||||
emit the indexed observed argv.
|
|
||||||
3. `AC-FSP-03`: The focused suite passes on the development host and CI image, and the merged-main
|
|
||||||
Woodpecker pipeline is terminal green before #1098 closes.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Exact Cross-Harness Fleet Communications Contract (#766)
|
## Exact Cross-Harness Fleet Communications Contract (#766)
|
||||||
@@ -1552,3 +1368,36 @@ All work is **alpha** (< 0.1.0) until Jason approves 0.1.0 beta release.
|
|||||||
10. ASSUMPTION: **Conversations and messages get their own PG tables** (not stored in brain's entity model). They follow a chat-specific schema with proper foreign keys to users and projects. Rationale: Chat has different access patterns (streaming, pagination, search) than brain entities.
|
10. ASSUMPTION: **Conversations and messages get their own PG tables** (not stored in brain's entity model). They follow a chat-specific schema with proper foreign keys to users and projects. Rationale: Chat has different access patterns (streaming, pagination, search) than brain entities.
|
||||||
|
|
||||||
11. RESOLVED: **Pi handles all target LLM providers natively.** Anthropic, OpenAI/Codex, Z.ai, Ollama, LM Studio, and llama.cpp are all supported via Pi's built-in providers or `models.json` configuration with `openai-completions` API type. No custom provider adapters needed in @mosaicstack/agent — only configuration management.
|
11. RESOLVED: **Pi handles all target LLM providers natively.** Anthropic, OpenAI/Codex, Z.ai, Ollama, LM Studio, and llama.cpp are all supported via Pi's built-in providers or `models.json` configuration with `openai-completions` API type. No custom provider adapters needed in @mosaicstack/agent — only configuration management.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Greenfield install correctness — C1 (#1050)
|
||||||
|
|
||||||
|
### Problem and objective
|
||||||
|
|
||||||
|
A from-zero install can report success while leaving the target host unusable because the installer has no transactional state machine capable of certifying its own postconditions. C1 supplies the structural spine and red-first fixture; later cards repair the individual failed postconditions.
|
||||||
|
|
||||||
|
### Normative requirements
|
||||||
|
|
||||||
|
1. The installer SHALL implement the canonical P0–P9 numbering from the greenfield-install PRD v2: P0 Resolve context; P1 Preflight; P2 Acquire artifacts; P3 Install CLI; P4 Install framework + skills; P5 Identity; P6 Runtime linking / activation; P7 Services; P8 Shell discoverability; P9 Verify + commit. P2 is scoped to installer-distribution artifacts and SHALL NOT foreclose credentialed downstream acquisition. P5 owns validating any credential capability required by requested downstream work; P7 may provision credential-dependent resources only after that P5 postcondition commits.
|
||||||
|
2. Every phase SHALL declare preconditions, action, committed postconditions, and rollback. An unverifiable postcondition SHALL fail the install non-zero with the named phase and a remediation line; no best-effort failure may still certify success. P1's required-tool closure includes tools invoked by later phases, including `git`; a downstream prerequisite may not remain undeclared and degrade silently.
|
||||||
|
3. A durable mutation journal SHALL open before the first mutation and commit at P9. Fallible command output needed to diagnose a phase SHALL be journaled and surfaced, never discarded.
|
||||||
|
4. `--check` SHALL run exactly the P0–P8 postcondition predicates without mutation, report each phase PASS/FAIL, and exit non-zero if any predicate fails.
|
||||||
|
5. P4 SHALL consume a checkout-free, lane/versioned shipped-set declaration published by the installer. C1 SHALL NOT select among the currently disagreeing framework-payload, repository-root, sync-source, and W-jarvis populations; while no declaration exists, P4 reports `NOT-MEASURED / UNDECLARED` and remains blocking rather than fabricating a count. C5 owns the declaration's contents and containment/loadability fulfillment.
|
||||||
|
6. The from-zero fixture SHALL be lane-parametric, use Debian/glibc, run the documented install command as a non-root target user with an isolated HOME, and inherit no host credentials, npm cache, home directory, or runtime configuration.
|
||||||
|
7. The fixture SHALL select `next` with `--next` or `MOSAIC_NEXT=1` and assert the resolved lane version. Internal predicates use P3's absolute CLI path; shell discoverability is tested only at P8.
|
||||||
|
8. Fault injection after each P2–P8 phase SHALL prove either clean rollback or a durable, honestly reported resumable partial state, with no journal incorrectly left in progress.
|
||||||
|
9. Unsupported musl/Alpine and unavailable Docker SHALL fail loudly rather than skip as pass.
|
||||||
|
|
||||||
|
### C1 acceptance criteria
|
||||||
|
|
||||||
|
1. The pre-C1 from-zero matrix records both discriminating controls: with `git` absent, the legacy installer still exits zero while P1 fails and skill sync degrades; with `git` present, P1 passes and the observed sync store/runtime links are 101/101. The C1 installer must fail at P1 before mutation when `git` is absent.
|
||||||
|
2. The discriminating P3 row passes: the binary exists at the expected absolute path and reports exactly the resolved `next` lane version, while P4, P5, and P8 fail.
|
||||||
|
3. The `--check` mutation negative control proves host fingerprints are byte-identical before and after observation.
|
||||||
|
4. Woodpecker executes and validates the expected RED fixture; C1 does not repair P4/P5/P8 or activate #869.
|
||||||
|
|
||||||
|
### Explicit exclusions and dependencies
|
||||||
|
|
||||||
|
- C2 owns P8/PATH, C3 owns P5/headless identity, C4 owns P6 activation policy, and C5 owns P4/skills.
|
||||||
|
- Main-lane execution is a promotion precondition owned by #1037; C1 only makes the fixture lane-parametric.
|
||||||
|
- RM-02 and #869 activation are out of scope.
|
||||||
|
|||||||
+5
-7
@@ -9,18 +9,16 @@
|
|||||||
- [Whole mutator-class gate](architecture/mutator-class-gate.md) — default-deny policy, revoke-first/promote-last state machine, TTL, runtime adapters, and T-B/T-C assurance boundary.
|
- [Whole mutator-class gate](architecture/mutator-class-gate.md) — default-deny policy, revoke-first/promote-last state machine, TTL, runtime adapters, and T-B/T-C assurance boundary.
|
||||||
- [Compaction revocation lifecycle](architecture/compaction-revocation.md) — Claude/Pi observer matrix, same-PID generation rollover, failure fencing, and the named bounded residual stale window.
|
- [Compaction revocation lifecycle](architecture/compaction-revocation.md) — Claude/Pi observer matrix, same-PID generation rollover, failure fencing, and the named bounded residual stale window.
|
||||||
|
|
||||||
|
## Installation and upgrades
|
||||||
|
|
||||||
|
- [Installer state machine and recovery](guides/installer-state-machine.md) — canonical P0–P9 phases, side-effect-free checks, durable journal states, rollback/remediation, and the Debian greenfield CI gate.
|
||||||
|
- [Upgrade safety and recovery](guides/upgrade-safety-and-recovery.md) — framework ownership, durable operator snapshots, verify net, and projection regeneration.
|
||||||
|
|
||||||
## CLI and skill management
|
## CLI and skill management
|
||||||
|
|
||||||
- [Skill registration user guide](guides/user-guide.md#claude-code-skill-registration) — register, unregister, list statuses, automatic install/update reconciliation, and Claude reload behavior.
|
- [Skill registration user guide](guides/user-guide.md#claude-code-skill-registration) — register, unregister, list statuses, automatic install/update reconciliation, and Claude reload behavior.
|
||||||
- [Skill bridge developer guide](guides/dev-guide.md#claude-code-skill-bridge) — path-validation, ownership, clobber-protection, install/update wiring, tests, and Pi/Codex scope notes.
|
- [Skill bridge developer guide](guides/dev-guide.md#claude-code-skill-bridge) — path-validation, ownership, clobber-protection, install/update wiring, tests, and Pi/Codex scope notes.
|
||||||
|
|
||||||
## Pi persistent goals
|
|
||||||
|
|
||||||
- [Persistent goal user guide](guides/user-guide.md#pi-persistent-goals) — `/goal` commands, verification behavior, limits, compaction/resume semantics, and limitations.
|
|
||||||
- [Goal extension developer guide](guides/dev-guide.md#pi-persistent-goal-extension) — framework ownership, launcher ordering, lifecycle design, tests, and local Mosaic-path smoke workflow.
|
|
||||||
- [Goal loop operations](guides/admin-guide.md#pi-goal-loop-operations) — deployment ownership, bounded settings, pause/resume procedures, and supervisor boundary.
|
|
||||||
- [Pi runtime reference](../packages/mosaic/framework/runtime/pi/RUNTIME.md#extensions) — deployed paths, command summary, and bounded environment settings.
|
|
||||||
|
|
||||||
## Fleet configuration management
|
## Fleet configuration management
|
||||||
|
|
||||||
- [Fleet configuration entry point](fleet/README.md) — desired-versus-observed decision tree and complete operator link map.
|
- [Fleet configuration entry point](fleet/README.md) — desired-versus-observed decision tree and complete operator link map.
|
||||||
|
|||||||
+10
-13
@@ -5,14 +5,14 @@ Generated environment files are rebuildable projections, not an operator-editabl
|
|||||||
|
|
||||||
## Launch chain
|
## Launch chain
|
||||||
|
|
||||||
| Layer | Responsibility |
|
| Layer | Responsibility |
|
||||||
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
| Roster | `fleet/roster.yaml` supplies the agent name, class, supported runtime, model, reasoning, tool policy, workdir, and tmux socket; Git identity is derived from the exact agent name. |
|
| Roster | `fleet/roster.yaml` supplies the agent name, class, supported runtime, model, reasoning, tool policy, workdir, and tmux socket. |
|
||||||
| Projection writer | Renders deterministic fleet/agents/<name>.env.generated from the roster. |
|
| Projection writer | Renders deterministic fleet/agents/<name>.env.generated from the roster. |
|
||||||
| Optional local data | Reads a strict, data-only fleet/agents/<name>.env.local; it cannot shadow generated keys. |
|
| Optional local data | Reads a strict, data-only fleet/agents/<name>.env.local; it cannot shadow generated keys. |
|
||||||
| systemd | Starts the launcher with env -i and fixed bootstrap data. It does not preload either environment file. |
|
| systemd | Starts the launcher with env -i and fixed bootstrap data. It does not preload either environment file. |
|
||||||
| session launcher | Validates generated and local data before it queries, creates, or stops an exact tmux session. |
|
| session launcher | Validates generated and local data before it queries, creates, or stops an exact tmux session. |
|
||||||
| runtime launch | Derives the fixed mosaic yolo <runtime> argument array from validated roster data, then seeds the runtime contract. |
|
| runtime launch | Derives the fixed mosaic yolo <runtime> argument array from validated roster data, then seeds the runtime contract. |
|
||||||
|
|
||||||
The launcher never `source`s or `eval`s an environment file and never accepts an environment-supplied
|
The launcher never `source`s or `eval`s an environment file and never accepts an environment-supplied
|
||||||
command. `MOSAIC_AGENT_COMMAND`, command/channel overrides, unknown keys, generated-key shadowing,
|
command. `MOSAIC_AGENT_COMMAND`, command/channel overrides, unknown keys, generated-key shadowing,
|
||||||
@@ -24,7 +24,6 @@ secret-like key names, duplicate keys, comments, quoted/export syntax, and unsaf
|
|||||||
|
|
||||||
```dotenv
|
```dotenv
|
||||||
MOSAIC_AGENT_NAME=<roster name>
|
MOSAIC_AGENT_NAME=<roster name>
|
||||||
MOSAIC_GIT_IDENTITY=<roster name>
|
|
||||||
MOSAIC_AGENT_CLASS=<roster class>
|
MOSAIC_AGENT_CLASS=<roster class>
|
||||||
MOSAIC_AGENT_RUNTIME=<roster runtime>
|
MOSAIC_AGENT_RUNTIME=<roster runtime>
|
||||||
MOSAIC_AGENT_MODEL=<roster model hint>
|
MOSAIC_AGENT_MODEL=<roster model hint>
|
||||||
@@ -34,10 +33,8 @@ MOSAIC_AGENT_WORKDIR=<absolute roster work directory>
|
|||||||
MOSAIC_TMUX_SOCKET=<roster socket or empty>
|
MOSAIC_TMUX_SOCKET=<roster socket or empty>
|
||||||
```
|
```
|
||||||
|
|
||||||
`MOSAIC_GIT_IDENTITY` is not independently configurable: it must equal `MOSAIC_AGENT_NAME`, preventing
|
The generated launch contract supports `claude`, `codex`, `opencode`, and `pi`. mosaic fleet add
|
||||||
split runtime and repository identity authority. The generated launch contract supports `claude`,
|
rejects another runtime before it writes the roster or modifies generated, local, or quarantine state.
|
||||||
`codex`, `opencode`, and `pi`. mosaic fleet add rejects another runtime before it writes the roster or
|
|
||||||
modifies generated, local, or quarantine state.
|
|
||||||
The legacy dogfood stub remains an observability-only canary on its separate `mosaic-factory` socket;
|
The legacy dogfood stub remains an observability-only canary on its separate `mosaic-factory` socket;
|
||||||
it has no generated-launch adapter and cannot be added through this path.
|
it has no generated-launch adapter and cannot be added through this path.
|
||||||
|
|
||||||
|
|||||||
@@ -3,12 +3,11 @@
|
|||||||
The launcher consumes validated data, not shell configuration.
|
The launcher consumes validated data, not shell configuration.
|
||||||
|
|
||||||
1. Read and validate the canonical roster.
|
1. Read and validate the canonical roster.
|
||||||
2. Render deterministic <name>.env.generated data from that roster, including `MOSAIC_GIT_IDENTITY` derived exactly from the roster agent name.
|
2. Render deterministic <name>.env.generated data from that roster.
|
||||||
3. Parse optional <name>.env.local through a strict allowlist.
|
3. Parse optional <name>.env.local through a strict allowlist.
|
||||||
4. Reject generated-key shadowing, unknown or sensitive-looking keys, unsafe paths/values, duplicates, malformed lines, shell syntax, and command overrides.
|
4. Reject generated-key shadowing, unknown or sensitive-looking keys, unsafe paths/values, duplicates, malformed lines, shell syntax, and command overrides.
|
||||||
5. Reject a Git identity that is unsafe or differs from the generated agent name.
|
5. Derive the runtime command from validated runtime/model/reasoning data.
|
||||||
6. Derive the runtime command from validated runtime/model/reasoning data and pass every generated projection entry through the clean process environment boundary.
|
6. Target only the exact configured tmux socket and roster session after ownership checks.
|
||||||
7. Target only the exact configured tmux socket and roster session after ownership checks.
|
|
||||||
|
|
||||||
## File precedence and ownership
|
## File precedence and ownership
|
||||||
|
|
||||||
|
|||||||
@@ -35,7 +35,6 @@ values, credential material, or command text.
|
|||||||
|
|
||||||
```dotenv
|
```dotenv
|
||||||
MOSAIC_AGENT_NAME=<roster name>
|
MOSAIC_AGENT_NAME=<roster name>
|
||||||
MOSAIC_GIT_IDENTITY=<roster name>
|
|
||||||
MOSAIC_AGENT_CLASS=<roster class>
|
MOSAIC_AGENT_CLASS=<roster class>
|
||||||
MOSAIC_AGENT_RUNTIME=<roster runtime>
|
MOSAIC_AGENT_RUNTIME=<roster runtime>
|
||||||
MOSAIC_AGENT_MODEL=<roster model hint>
|
MOSAIC_AGENT_MODEL=<roster model hint>
|
||||||
@@ -45,9 +44,8 @@ MOSAIC_AGENT_WORKDIR=<absolute roster work directory>
|
|||||||
MOSAIC_TMUX_SOCKET=<roster socket or empty>
|
MOSAIC_TMUX_SOCKET=<roster socket or empty>
|
||||||
```
|
```
|
||||||
|
|
||||||
`MOSAIC_GIT_IDENTITY` is derived from and must equal `MOSAIC_AGENT_NAME`; it is not a separate
|
The generated launch contract supports only `claude`, `codex`, `opencode`, and `pi`. fleet add
|
||||||
operator-controlled identity authority. The generated launch contract supports only `claude`, `codex`,
|
uses that same runtime authority and rejects any other runtime before it writes the roster or changes
|
||||||
`opencode`, and `pi`. fleet add uses that same runtime authority and rejects any other runtime before it writes the roster or changes
|
|
||||||
projection, local, or quarantine files. The legacy dogfood stub on its separate `mosaic-factory`
|
projection, local, or quarantine files. The legacy dogfood stub on its separate `mosaic-factory`
|
||||||
socket remains an observability canary; it has no generated-launch adapter and cannot be added through
|
socket remains an observability canary; it has no generated-launch adapter and cannot be added through
|
||||||
this projection path.
|
this projection path.
|
||||||
|
|||||||
@@ -7,8 +7,7 @@
|
|||||||
3. [Provider Configuration](#provider-configuration)
|
3. [Provider Configuration](#provider-configuration)
|
||||||
4. [MCP Server Configuration](#mcp-server-configuration)
|
4. [MCP Server Configuration](#mcp-server-configuration)
|
||||||
5. [Environment Variables Reference](#environment-variables-reference)
|
5. [Environment Variables Reference](#environment-variables-reference)
|
||||||
6. [Pi Goal Loop Operations](#pi-goal-loop-operations)
|
6. [Local Fleet Canary](./fleet-local-canary.md)
|
||||||
7. [Local Fleet Canary](./fleet-local-canary.md)
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -265,16 +264,6 @@ Each OIDC provider requires its client ID, client secret, and issuer URL togethe
|
|||||||
| `AGENT_SYSTEM_PROMPT` | — | Platform-level system prompt injected into all sessions |
|
| `AGENT_SYSTEM_PROMPT` | — | Platform-level system prompt injected into all sessions |
|
||||||
| `AGENT_USER_TOOLS` | all tools | Comma-separated allowlist of tools for non-admin users |
|
| `AGENT_USER_TOOLS` | all tools | Comma-separated allowlist of tools for non-admin users |
|
||||||
|
|
||||||
### Mosaic Pi goal loop
|
|
||||||
|
|
||||||
| Variable | Default | Description |
|
|
||||||
| ----------------------------- | ------- | -------------------------------------------------------------------- |
|
|
||||||
| `MOSAIC_GOAL_MAX_TURNS` | `40` | Per-goal autonomous turn limit; accepted range `1..500` |
|
|
||||||
| `MOSAIC_GOAL_MAX_NO_PROGRESS` | `6` | Consecutive identical progress-report limit; accepted range `1..100` |
|
|
||||||
|
|
||||||
These variables are consumed by the framework-owned Pi goal extension at goal creation. Invalid or
|
|
||||||
out-of-range values fall back to the defaults; they do not disable the bounds.
|
|
||||||
|
|
||||||
### Providers
|
### Providers
|
||||||
|
|
||||||
| Variable | Default | Description |
|
| Variable | Default | Description |
|
||||||
@@ -385,29 +374,3 @@ Session cleanup is scoped to one session identifier and only removes that sessio
|
|||||||
| Variable | Default | Description |
|
| Variable | Default | Description |
|
||||||
| ----------------------- | ----------------------------- | ------------------------------------------ |
|
| ----------------------- | ----------------------------- | ------------------------------------------ |
|
||||||
| `MOSAIC_WORKSPACE_ROOT` | monorepo root (auto-detected) | Root path for mission workspace operations |
|
| `MOSAIC_WORKSPACE_ROOT` | monorepo root (auto-detected) | Root path for mission workspace operations |
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Pi Goal Loop Operations
|
|
||||||
|
|
||||||
The reviewed runtime asset is deployed at
|
|
||||||
`~/.config/mosaic/runtime/pi/goal-extension.ts` by framework install/update. Do not install another
|
|
||||||
copy under `~/.pi/agent/extensions/`; duplicate registration can create suffixed commands and two
|
|
||||||
competing lifecycle controllers.
|
|
||||||
|
|
||||||
Operational checks:
|
|
||||||
|
|
||||||
1. Run `mosaic pi` and verify `/goal help` is available.
|
|
||||||
2. Use `/goal status` to inspect phase, turn/no-progress limits, compaction checks, and evidence.
|
|
||||||
Reports persist in Pi session data; controller-owned state redacts common credential shapes, but
|
|
||||||
Pi's model/tool-call history is separate. Operators must not place secrets or raw sensitive output
|
|
||||||
in goals, pause reasons, or evidence.
|
|
||||||
3. Use `/goal pause <reason>` before planned maintenance or manual investigation. Pause and cancel
|
|
||||||
abort the current goal-driven run when Pi is busy.
|
|
||||||
4. Use `/goal resume` only after addressing a blocker; counters restart with the configured bounds.
|
|
||||||
5. Use `/goal cancel` before replacing an unfinished goal.
|
|
||||||
|
|
||||||
A blocked or exhausted goal remains stopped and visible; Mosaic does not automatically raise its
|
|
||||||
limits or restart the process. Framework sync owns file deployment, while Pi's native session file
|
|
||||||
owns branch replay. Process/host restart remains the responsibility of the existing runtime or fleet
|
|
||||||
supervisor.
|
|
||||||
|
|||||||
@@ -9,9 +9,8 @@
|
|||||||
5. [Adding New MCP Tools](#adding-new-mcp-tools)
|
5. [Adding New MCP Tools](#adding-new-mcp-tools)
|
||||||
6. [Database Schema and Migrations](#database-schema-and-migrations)
|
6. [Database Schema and Migrations](#database-schema-and-migrations)
|
||||||
7. [Claude Code Skill Bridge](#claude-code-skill-bridge)
|
7. [Claude Code Skill Bridge](#claude-code-skill-bridge)
|
||||||
8. [Pi Persistent Goal Extension](#pi-persistent-goal-extension)
|
8. [API Endpoint Reference](#api-endpoint-reference)
|
||||||
9. [API Endpoint Reference](#api-endpoint-reference)
|
9. [Local Fleet Canary](./fleet-local-canary.md)
|
||||||
10. [Local Fleet Canary](./fleet-local-canary.md)
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -386,85 +385,6 @@ M1 intentionally manages Claude Code only. Pi's Mosaic launcher can discover the
|
|||||||
canonical root directly. Codex still relies on the existing full skill-sync
|
canonical root directly. Codex still relies on the existing full skill-sync
|
||||||
linker and needs separate parity analysis before this lifecycle API is extended.
|
linker and needs separate parity analysis before this lifecycle API is extended.
|
||||||
|
|
||||||
## Pi Persistent Goal Extension
|
|
||||||
|
|
||||||
The source of the Mosaic-owned Pi goal controller is:
|
|
||||||
|
|
||||||
```text
|
|
||||||
packages/mosaic/framework/runtime/pi/goal-extension.ts
|
|
||||||
```
|
|
||||||
|
|
||||||
The framework manifest classifies `runtime/**` as framework-owned. Both the bash installer and the
|
|
||||||
TypeScript file adapter therefore deploy the same reviewed source to:
|
|
||||||
|
|
||||||
```text
|
|
||||||
$MOSAIC_HOME/runtime/pi/goal-extension.ts
|
|
||||||
# default: ~/.config/mosaic/runtime/pi/goal-extension.ts
|
|
||||||
```
|
|
||||||
|
|
||||||
Do not copy or link this extension into `~/.pi/agent/extensions/`. The launcher function
|
|
||||||
`discoverPiExtensionArgs()` emits the core `mosaic-extension.ts` first and the optional
|
|
||||||
`goal-extension.ts` second, preserving compatibility with an older installed framework that does
|
|
||||||
not have the goal file yet.
|
|
||||||
|
|
||||||
### Lifecycle design
|
|
||||||
|
|
||||||
| Pi API | Goal-controller responsibility |
|
|
||||||
| ------------------------------ | --------------------------------------------------------------------------------- |
|
|
||||||
| `registerCommand('goal')` | Set, inspect, pause, resume, or cancel one branch-specific goal |
|
|
||||||
| `registerTool(...)` | Record a terminating structured progress report with evidence |
|
|
||||||
| `context` | Inject the active goal contract before every provider request |
|
|
||||||
| `turn_end` | Record every turn, reject mixed final reports, and enforce the turn bound |
|
|
||||||
| `agent_settled` | Start one deduplicated continuation only after Pi has no retry/compact/queue work |
|
|
||||||
| `session_compact` | Record the compact check, reset provisional verification, and defer idle work |
|
|
||||||
| `session_start`/`session_tree` | Rebuild state from custom entries on the active branch |
|
|
||||||
| `session_shutdown` | Invalidate deferred callbacks and clear UI state |
|
|
||||||
|
|
||||||
State is appended as `mosaic-goal-state` custom entries, which do not enter model context. The
|
|
||||||
`context` hook creates a fresh hidden `mosaic-goal-context` message for each request instead of
|
|
||||||
trusting compaction summaries. The `mosaic_goal_report` result uses `terminate: true`; when it is the
|
|
||||||
sole final tool call, Pi avoids an unnecessary model response before the controller decides whether
|
|
||||||
to verify, continue, or stop.
|
|
||||||
|
|
||||||
Before state is appended or displayed, the controller applies bounded credential-pattern redaction
|
|
||||||
to the goal statement, report summary/evidence/next step, and stop reason. Fingerprints are computed
|
|
||||||
over redacted report content. Pi session entries are append-only, so a credential-bearing legacy
|
|
||||||
entry cannot honestly be erased by the extension: restoration fails closed, emits a warning, and
|
|
||||||
requires removal of the affected session before setting a new goal. This is defense-in-depth rather
|
|
||||||
than a secret-storage contract, and it does not rewrite Pi's separate model-message/tool-call
|
|
||||||
history. Goal prompts tell the agent not to submit credentials or raw sensitive output, and tests use
|
|
||||||
canaries to prove known forms do not reach new custom entries, status text, context, or tool details
|
|
||||||
while ordinary typed fields such as `token: string` remain intact.
|
|
||||||
|
|
||||||
Completion remains evidence-gated but semantic: two consecutive `achieved` reports are required,
|
|
||||||
and the second run is explicitly a verification pass. This avoids an extra judge-model request after
|
|
||||||
every turn. Deterministic validator commands are intentionally not accepted as `/goal` input in this
|
|
||||||
slice, so never describe this mechanism as proof of arbitrary natural-language completion.
|
|
||||||
|
|
||||||
### Tests and local smoke workflow
|
|
||||||
|
|
||||||
```bash
|
|
||||||
pnpm --filter @mosaicstack/mosaic exec vitest run \
|
|
||||||
src/runtime/pi-goal-extension.spec.ts \
|
|
||||||
src/commands/launch.spec.ts \
|
|
||||||
src/config/file-adapter.test.ts
|
|
||||||
|
|
||||||
bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
For an additive local smoke test without reseeding unrelated live framework files:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
install -D -m 0644 \
|
|
||||||
packages/mosaic/framework/runtime/pi/goal-extension.ts \
|
|
||||||
~/.config/mosaic/runtime/pi/goal-extension.ts
|
|
||||||
|
|
||||||
pi --extension ~/.config/mosaic/runtime/pi/goal-extension.ts
|
|
||||||
```
|
|
||||||
|
|
||||||
Use `/goal help`, `/goal set ...`, and `/goal status` in that test session. A released framework
|
|
||||||
sync installs the file, and a released Mosaic CLI loads it automatically through `mosaic pi`.
|
|
||||||
|
|
||||||
## API Endpoint Reference
|
## API Endpoint Reference
|
||||||
|
|
||||||
All endpoints are served by the gateway at `http://localhost:14242` by default.
|
All endpoints are served by the gateway at `http://localhost:14242` by default.
|
||||||
|
|||||||
@@ -0,0 +1,99 @@
|
|||||||
|
# Installer State Machine and Recovery
|
||||||
|
|
||||||
|
The unified installer uses a transactional P0–P9 model. It may report success only after P9 reasserts every applicable committed postcondition. Internal phases invoke the CLI by P3's absolute path; shell discovery is checked only at P8.
|
||||||
|
|
||||||
|
## Canonical phases
|
||||||
|
|
||||||
|
| Phase | Responsibility | Failure disposition |
|
||||||
|
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
|
||||||
|
| P0 Resolve context | State target user, HOME, shell, privilege mode, architecture, libc, Node, and npm | Fail before mutation |
|
||||||
|
| P1 Preflight | Validate downstream tool closure (including `git` and `python3`), writable prefix, registry lane, disk/inodes, and exclusive lock | Fail before target mutation |
|
||||||
|
| P2 Acquire artifacts | Resolve exact registry versions and an immutable framework commit; record lane and SHA-256 | Discard temporary work |
|
||||||
|
| P3 Install CLI | Install at the configured absolute prefix and require exact resolved version | Restore the prior prefix/npmrc snapshot |
|
||||||
|
| P4 Install framework + skills | Sync framework and consume a checkout-free, lane/versioned shipped-skill declaration | Restore prior framework/runtime trees |
|
||||||
|
| P5 Identity | Validate SOUL/USER content, owner, and mode; establish any credential capability requested downstream | Restore generated identity/credential binding |
|
||||||
|
| P6 Runtime linking / activation | Evaluate activation honestly; never treat dead enforcement hooks as active readiness | Restore runtime activation files |
|
||||||
|
| P7 Services | Provision only requested services/resources after any required P5 credential commits | Stop and restore requested services/resources |
|
||||||
|
| P8 Shell discoverability | Require fresh login and non-login shells of the actual target shell to resolve P3's path | Restore shell profiles |
|
||||||
|
| P9 Verify + commit | Re-run P0–P8, commit the manifest, and seal the journal | Leave an honestly reported resumable failure or restore the pre-install snapshot |
|
||||||
|
|
||||||
|
The phase numbers are a cross-workstream contract and must not be renumbered.
|
||||||
|
|
||||||
|
## Side-effect-free check
|
||||||
|
|
||||||
|
```bash
|
||||||
|
bash tools/install.sh --check # stable/latest lane
|
||||||
|
bash tools/install.sh --check --next # prerelease lane
|
||||||
|
```
|
||||||
|
|
||||||
|
`--check`:
|
||||||
|
|
||||||
|
- emits exactly one `[P0]` through `[P8]` PASS/FAIL row;
|
||||||
|
- exits non-zero if any predicate fails;
|
||||||
|
- does not create the npm prefix, lock, journal, manifest, shell profile, or runtime file;
|
||||||
|
- uses temporary npm observation storage outside the target HOME and removes it before exit.
|
||||||
|
|
||||||
|
P4 currently fails as `NOT-MEASURED / UNDECLARED` until the installer publishes `~/.config/mosaic/.install-shipped-skills.json`. C1 deliberately does not select among the conflicting candidate populations; C5 owns publishing and fulfilling that declaration. Once present, the P4 predicate requires the declaration's lane/version to match the resolved install and every named skill to remain contained under `skills/<name>/SKILL.md` with matching loadable frontmatter.
|
||||||
|
|
||||||
|
## Durable journal
|
||||||
|
|
||||||
|
Each mutating run creates a private transaction directory:
|
||||||
|
|
||||||
|
```text
|
||||||
|
${XDG_STATE_HOME:-~/.local/state}/mosaic/install/
|
||||||
|
active.json
|
||||||
|
<UTC-run-id>/
|
||||||
|
journal.ndjson
|
||||||
|
journal.ndjson.sha256 # committed runs only
|
||||||
|
commands.log
|
||||||
|
snapshot/
|
||||||
|
```
|
||||||
|
|
||||||
|
Before each mutation scope is touched, `journal.ndjson` records:
|
||||||
|
|
||||||
|
- phase and path;
|
||||||
|
- whether prior state existed and where its snapshot lives;
|
||||||
|
- the reversal action;
|
||||||
|
- the captured command-output location and command status.
|
||||||
|
|
||||||
|
Journal, action-status, manifest, or command-log write/sync failure is fatal. An unrecorded mutation is not allowed. Successful P9 runs append a seal event, write the SHA-256 sidecar, and make the journal and sidecar read-only. Required P4/P6 action failures are persisted in the manifest so a later `--check` cannot turn a failed action into a false pass.
|
||||||
|
|
||||||
|
Rollback roots must be non-overlapping, non-symlinked, target-user-owned strict descendants of canonical `HOME`; unsafe custom `MOSAIC_HOME`/`MOSAIC_PREFIX` values fail at P0. The same validation runs again immediately before recursive rollback. The OS lock is concurrency authority: if a process dies while `active.json` still says `in-progress`, a retry that acquires the free lock preserves the stale projection as `prior-active.json` and proceeds from the honestly retained partial state.
|
||||||
|
|
||||||
|
`active.json` is the current projection:
|
||||||
|
|
||||||
|
- `in-progress`: incomplete/open transaction;
|
||||||
|
- `rolled-back`: a fault restored the snapshot;
|
||||||
|
- `rollback-failed`: restoration failed or refused a replaced/unsafe target and requires manual recovery;
|
||||||
|
- `failed-resumable`: named postconditions failed and the recorded partial state remains for remediation;
|
||||||
|
- `committed`: P9 passed and the journal is sealed.
|
||||||
|
|
||||||
|
## Failure recovery
|
||||||
|
|
||||||
|
1. Read the named phase and remediation line from installer stderr.
|
||||||
|
2. Inspect `active.json`, then the referenced `journal.ndjson` and `commands.log`. Command output needed to diagnose a failure is preserved and surfaced; it is not redirected away.
|
||||||
|
3. For `rolled-back`, verify the target paths match their pre-install state before retrying.
|
||||||
|
4. For `failed-resumable`, repair the named phase owner requirement, then run `install.sh --check` before retrying the installer.
|
||||||
|
5. Do not activate the #869 enforcement hooks merely to turn P6 green. A broker-less host with those hooks is a failed P6 state.
|
||||||
|
|
||||||
|
## Greenfield CI gate
|
||||||
|
|
||||||
|
`.woodpecker/greenfield-install.yml` runs `tools/e2e-install-test.sh` from zero in Debian/glibc as a non-root uid with `env -i`. No host HOME, npm cache, credentials, or bind mount enters the target process. Checkout mode packages the complete current checkout into an archive, pins its SHA-256 through an internal fixture seam, and copies the self-contained fixture into the container; framework-installer changes in the PR are therefore exercised rather than fetched from an older remote branch.
|
||||||
|
|
||||||
|
The C1 fixture intentionally returns an attributable RED while C2–C5 remain open. CI itself remains green only when the fixture's final P0–P9 verdicts, required discriminator rows, and non-zero exit match the versioned contract in `tools/fixtures/greenfield-expected-red.tsv`. Any later remediation that changes an observed verdict makes CI red until the owning lane deliberately updates that manifest:
|
||||||
|
|
||||||
|
- `git` present: P1 and strict P3 pass; P4/P5/P6/P8 fail for their own reasons; P9 refuses success.
|
||||||
|
- `git` absent: P1 fails before target mutation and the installer emits no `Done.`.
|
||||||
|
|
||||||
|
The fixture is lane-parametric:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
bash tools/e2e-install-test.sh --lane next --git present
|
||||||
|
bash tools/e2e-install-test.sh --lane main --git present
|
||||||
|
```
|
||||||
|
|
||||||
|
CI exercises both lane parameters as expected-RED structural checks. Delivery targets `main` under the trunk-only merge rule; `next` remains a non-merging integration lane. The linked installer issue stays open after merge and closes only after Jarvis independently validates the greenfield behavior.
|
||||||
|
|
||||||
|
## Source trust boundary
|
||||||
|
|
||||||
|
Remote source mode pins the resolved commit, records the archive SHA-256, limits compressed/expanded size and entry count, and rejects traversal, links, devices, and special files before extraction. This provides immutable run provenance and archive safety, not an independent authenticity root. Signed artifact metadata/provenance is explicitly deferred by the canonical greenfield PRD; C1 does not invent a signing system. The checkout CI seam does verify an expected digest supplied independently by the fixture.
|
||||||
@@ -12,6 +12,20 @@ with no snapshot to fall back to.
|
|||||||
Protection is layered. Each layer is independent; a later layer catches what an
|
Protection is layered. Each layer is independent; a later layer catches what an
|
||||||
earlier one misses.
|
earlier one misses.
|
||||||
|
|
||||||
|
## Layer 0 — Transaction journal (install-wide recovery)
|
||||||
|
|
||||||
|
The unified installer opens a private journal under
|
||||||
|
`${XDG_STATE_HOME:-~/.local/state}/mosaic/install/` before the first target
|
||||||
|
mutation. Every mutation scope records its path, prior snapshot, and reversal
|
||||||
|
instructions before it is touched. Journal write/sync failure is fatal, and P9
|
||||||
|
seals successful journals with a SHA-256 sidecar. See
|
||||||
|
[Installer state machine and recovery](./installer-state-machine.md).
|
||||||
|
|
||||||
|
This transaction journal is distinct from the retained operator-only backup
|
||||||
|
below. The transaction journal is required for correctness and rollback;
|
||||||
|
Layer 2's durable backup remains a separately stated, fail-open recovery bonus
|
||||||
|
for a manifest bug that the normal transaction did not detect.
|
||||||
|
|
||||||
## Layer 1 — Manifest-owned sync (prevention)
|
## Layer 1 — Manifest-owned sync (prevention)
|
||||||
|
|
||||||
The single source of truth for ownership is
|
The single source of truth for ownership is
|
||||||
|
|||||||
@@ -8,10 +8,9 @@
|
|||||||
4. [Tasks](#tasks)
|
4. [Tasks](#tasks)
|
||||||
5. [Settings](#settings)
|
5. [Settings](#settings)
|
||||||
6. [CLI Usage](#cli-usage)
|
6. [CLI Usage](#cli-usage)
|
||||||
7. [Pi Persistent Goals](#pi-persistent-goals)
|
7. [Sub-package Commands](#sub-package-commands)
|
||||||
8. [Sub-package Commands](#sub-package-commands)
|
8. [Telemetry](#telemetry)
|
||||||
9. [Telemetry](#telemetry)
|
9. [Local Fleet Canary](./fleet-local-canary.md)
|
||||||
10. [Local Fleet Canary](./fleet-local-canary.md)
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -308,57 +307,6 @@ mosaic prdy
|
|||||||
mosaic quality-rails
|
mosaic quality-rails
|
||||||
```
|
```
|
||||||
|
|
||||||
## Pi Persistent Goals
|
|
||||||
|
|
||||||
`mosaic pi` loads a Mosaic-owned goal extension from
|
|
||||||
`~/.config/mosaic/runtime/pi/goal-extension.ts`. It is deliberately not installed in
|
|
||||||
`~/.pi/agent/extensions/`; framework installation and updates manage it with the rest of the Mosaic
|
|
||||||
runtime assets.
|
|
||||||
|
|
||||||
Start Pi, then set a goal:
|
|
||||||
|
|
||||||
```text
|
|
||||||
/goal set Deliver the feature, tests, documentation, and verification evidence
|
|
||||||
# Shorthand:
|
|
||||||
/goal Deliver the feature, tests, documentation, and verification evidence
|
|
||||||
```
|
|
||||||
|
|
||||||
Control and inspect the loop with:
|
|
||||||
|
|
||||||
| Command | Behavior |
|
|
||||||
| ---------------------- | ------------------------------------------------------------------ |
|
|
||||||
| `/goal status` | Show phase, limits, compaction checks, latest report, and evidence |
|
|
||||||
| `/goal pause [reason]` | Stop autonomous continuation while preserving the goal |
|
|
||||||
| `/goal resume` | Resume with fresh turn and no-progress counters |
|
|
||||||
| `/goal cancel` | Cancel the goal and remove its active status |
|
|
||||||
| `/goal help` | Show command help |
|
|
||||||
|
|
||||||
While a goal is active, Mosaic injects its contract before every Pi model request and checks every
|
|
||||||
completed model/tool turn. The agent ends each work cycle with the structured
|
|
||||||
`mosaic_goal_report` tool. `achieved` is provisional until a second consecutive report rechecks the
|
|
||||||
whole goal with evidence. A continuation report or a successful compaction resets provisional
|
|
||||||
verification.
|
|
||||||
|
|
||||||
Goal statements and reports are stored in Pi session data. Mosaic redacts common credential shapes
|
|
||||||
before appending its goal-state entries and before goal tool output or `/goal status`, but
|
|
||||||
pattern-based redaction is not a secret store. Pi's own model-message and tool-call records are
|
|
||||||
outside that redactor. Never put tokens, passwords, private keys, connection strings, or raw
|
|
||||||
sensitive output in a goal or report; cite the command, artifact, and pass/fail result instead.
|
|
||||||
|
|
||||||
The loop stops instead of running forever when it is paused, blocked, cancelled, verified, reaches
|
|
||||||
its turn limit, or repeats the same no-progress report too many times. Defaults are 40 turns and 6
|
|
||||||
repeated no-progress reports. Operators may lower or raise them within enforced bounds before
|
|
||||||
launching Pi:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
MOSAIC_GOAL_MAX_TURNS=60 MOSAIC_GOAL_MAX_NO_PROGRESS=8 mosaic pi
|
|
||||||
```
|
|
||||||
|
|
||||||
Goal state is branch-specific Pi session data. It survives compaction and session resume, but Pi's
|
|
||||||
process still must be relaunched or supervised after a process/host failure. This initial verifier
|
|
||||||
checks structured evidence twice; it cannot mathematically prove every arbitrary natural-language
|
|
||||||
goal. Use explicit acceptance criteria and inspect `/goal status` for consequential work.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
### Claude Code Skill Registration
|
### Claude Code Skill Registration
|
||||||
|
|||||||
@@ -1,72 +0,0 @@
|
|||||||
# #1099 pipefail + early-exit sweep
|
|
||||||
|
|
||||||
Baseline: `df4c591ab42aa1ae62c12935fdc0e772684864a0`
|
|
||||||
|
|
||||||
This is a site inventory, not a risk count. `FIXED` means the early-exiting consumer no longer has a piped upstream process whose SIGPIPE can become the result under `pipefail`. `NOT-LOAD-BEARING` means the pipeline status is explicitly discarded. `UNREACHABLE-AND-WHY` describes designed input, not a payload-size safety claim.
|
|
||||||
|
|
||||||
## Tranche 1 — runtime and general scripts
|
|
||||||
|
|
||||||
| Baseline site | Verdict | Construction / reason |
|
|
||||||
| --- | --- | --- |
|
|
||||||
| `tools/matrix-presence-harness/run.sh:38` | FIXED | nullglob array selects the first path; no pipeline |
|
|
||||||
| `tools/e2e-install-test.sh:139` | FIXED | capture help completely, then grep via redirection |
|
|
||||||
| `tools/install.sh:312` | FIXED | NUL `mapfile` reads all roots; count != 1 reaches the named malformed-archive diagnostic |
|
|
||||||
| `scripts/analysis/reflect-board-history.sh:76` | FIXED | capture Git history completely, then grep via redirection |
|
|
||||||
| `scripts/analysis/reflect-git-history.sh:67` | FIXED | grep reads from a here-string |
|
|
||||||
| `scripts/analysis/reflect-git-history.sh:69` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/authentik/user-create.sh:72` | FIXED | jq `first(...)` reads the response directly |
|
|
||||||
| `packages/mosaic/framework/tools/git/mutate-push-guard.sh:87` | FIXED | grep `-m1` reads the file directly; downstream `cut` consumes its complete scalar output |
|
|
||||||
| `packages/mosaic/framework/tools/orchestrator/session-resume.sh:94` | FIXED | `mapfile` plus bounded indexed loop replaces `head` pipeline |
|
|
||||||
| `packages/mosaic/framework/tools/prdy/prdy-status.sh:69` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:172` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:173` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:174` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:175` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:176` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:177` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:178` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/qa/typecheck-hook.sh:16` | FIXED | Bash regex extracts the first field without a pipeline |
|
|
||||||
| `packages/mosaic/framework/tools/qa/typecheck-hook.sh:56` | FIXED | grep and bounded sed each read from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/tmux/send-message.sh:113` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/tmux/send-message.sh:124` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/wake/detector.sh:126` | FIXED | one awk reads the manifest directly and exits after the first exact key |
|
|
||||||
| `packages/mosaic/framework/tools/wake/detector.sh:270` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/wake/detector.sh:278` | FIXED | grep reads from a here-string |
|
|
||||||
| `packages/mosaic/framework/tools/wake/digest.sh:647` | FIXED | capture complete locator output, then select first line by parameter expansion |
|
|
||||||
| `packages/mosaic/framework/tools/wake/reconcile.sh:149` | FIXED | one awk reads the manifest directly and exits after the first exact key |
|
|
||||||
|
|
||||||
## Explicit withdrawn / non-load-bearing sites
|
|
||||||
|
|
||||||
| Baseline site | Verdict | Reason |
|
|
||||||
| --- | --- | --- |
|
|
||||||
| `tools/install.sh:182` | NOT-LOAD-BEARING | `|| true` explicitly discards lookup status |
|
|
||||||
| `tools/install.sh:356` | UNREACHABLE-AND-WHY | `pnpm pack` writes one matching CLI tarball into a fresh directory immediately before lookup; citation withdrawn in #1099 |
|
|
||||||
| `tools/install.sh:357` | UNREACHABLE-AND-WHY | same fresh-directory invariant for gateway tarball; citation withdrawn in #1099 |
|
|
||||||
| `tools/install.sh:627` | NOT-LOAD-BEARING | `|| true` explicitly discards lookup status |
|
|
||||||
| `scripts/agent/session-start.sh:70` | NOT-LOAD-BEARING | optional scratchpad lookup has `|| true` |
|
|
||||||
| `packages/mosaic/framework/templates/repo/scripts/agent/session-start.sh:58` | NOT-LOAD-BEARING | optional scratchpad lookup has `|| true` |
|
|
||||||
| `packages/mosaic/framework/tools/qa/qa-hook-stdin.sh:25` | UNREACHABLE-AND-WHY | withdrawn in #1099 after designed-input reachability measurement; preserved without re-litigation |
|
|
||||||
| `packages/mosaic/framework/tools/qa/qa-hook-stdin.sh:27` | UNREACHABLE-AND-WHY | same withdrawn designed-input finding |
|
|
||||||
| `packages/mosaic/framework/tools/qa/qa-hook-stdin.sh:30` | UNREACHABLE-AND-WHY | same withdrawn designed-input finding |
|
|
||||||
| `packages/mosaic/framework/tools/qa/qa-hook-stdin.sh:32` | UNREACHABLE-AND-WHY | same withdrawn designed-input finding |
|
|
||||||
| `packages/mosaic/framework/tools/qa/qa-hook-stdin.sh:34` | UNREACHABLE-AND-WHY | same withdrawn designed-input finding |
|
|
||||||
|
|
||||||
## Tranche 2 — non-wake test harnesses
|
|
||||||
|
|
||||||
All 22 baseline sites below are `FIXED`; the checked-in tranche fixture is passed through the same scanner and asserts all 22 occurrences and 21 normalized identities (the same response-split line occurs twice).
|
|
||||||
|
|
||||||
| Baseline site(s) | Verdict | Construction |
|
|
||||||
| --- | --- | --- |
|
|
||||||
| `systemd/user/test-fleet-units.sh:148` | FIXED | capture tmux output, then grep via redirection |
|
|
||||||
| `git/test-issue-comment-readback.sh:283,302` | FIXED | parameter expansion splits status/body without `head` |
|
|
||||||
| `git/test-pr-review-gitea-comment.sh:228` | FIXED | parameter expansion splits status/body |
|
|
||||||
| `git/test-lane-brief-pr-linkage.sh:72` | FIXED | grep reads from a here-string |
|
|
||||||
| `git/test-pr-review-repo-host-override.sh:225-226` | FIXED | grep reads from a here-string |
|
|
||||||
| `orchestrator/smoke-test.sh:67,72` | FIXED | parameter expansion selects first line |
|
|
||||||
| `orchestrator/test-board-roll.sh:99-100` | FIXED | grep reads from a here-string |
|
|
||||||
| `quality/scripts/test-upgrade-durable-snapshot.sh:180` | FIXED | complete sorted output is read with `mapfile`, then indexed |
|
|
||||||
| `quality/scripts/test-upgrade-rollback.sh:339,356` | FIXED | direct `grep -m1` file reads; cleanup captures before testing |
|
|
||||||
| `tmux/test-send-message-socket.sh:37,38,44-46,68,72` | FIXED | capture commands complete before redirected grep assertions |
|
|
||||||
| `tmux/test-send-message-verdict.sh:34` | FIXED | grep reads from a here-string |
|
|
||||||
|
|
||||||
Remaining wake-validation sites are intentionally deferred to the final review-sized tranche and are not yet assigned a safety verdict here.
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
# #1019 — Zero-timeout queue-guard harness race
|
|
||||||
|
|
||||||
- **Issue:** #1019 (parent status remains `believed-fixed, pending jarvis validation`; do not close)
|
|
||||||
- **Branch:** `fix/1019-ci-queue-timeout-harness`
|
|
||||||
- **Owner:** `be-coder-08`
|
|
||||||
- **Base:** `origin/main` at `5916aeefd6ed12bcac086c6834c7f6c4ae38e1bc`
|
|
||||||
- **Charter:** `/home/hermes/agent-work/tl-mosaic/CHARTER-1019-HARNESS-FIX.md`
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Make `test-ci-queue-wait-tristate.sh` deterministic without changing any asserted outcome. Remove the indiscriminate zero-timeout race, require every status-classification case to prove the provider was observed, and prove the harness-controlled virtual clock is active.
|
|
||||||
|
|
||||||
## Scope
|
|
||||||
|
|
||||||
- In scope: `packages/mosaic/framework/tools/git/test-ci-queue-wait-tristate.sh` only, plus this evidence scratchpad.
|
|
||||||
- Out of scope: guard parsers, D2/D3 behavior, installer/reseed staleness, PR #1060, and issue closure.
|
|
||||||
|
|
||||||
## Acceptance criteria
|
|
||||||
|
|
||||||
1. RED deterministically reproduces deadline pre-emption before the provider call.
|
|
||||||
2. Every case that intends status classification positively proves provider observation.
|
|
||||||
3. Pending observes `pending` before deterministic virtual-time expiration.
|
|
||||||
4. The virtual clock has a positive interception control; a broken-clock mutant makes the suite red.
|
|
||||||
5. The exact CI-base image passes the final harness repeatedly with zero failures.
|
|
||||||
6. Baseline gates, independent code/security review, exact-head CI, and coordinator-authorized squash merge pass.
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Add deterministic RED instrumentation for the known merge/provider-unreachable pre-emption.
|
|
||||||
2. Replace global `-t 0` with a nonzero timeout interpreted under an event-driven virtual clock; stub sleep without wall waiting.
|
|
||||||
3. Add provider-observation and virtual-clock positive controls without changing outcome assertions.
|
|
||||||
4. Run focused shell checks, repeat in exact CI-base image, baseline gates, and independent reviews.
|
|
||||||
5. Commit with both identity layers, queue-guard plus direct Woodpecker terminal-state verification, push, self-post PR, verify poster/head/CI, obtain coordinator merge authorization, then squash merge without closing #1019.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
- No explicit token cap supplied. Keep scope to one harness file and one scratchpad; stop/report at the charter's 60% context gate.
|
|
||||||
|
|
||||||
## Evidence
|
|
||||||
|
|
||||||
- RED, deterministic pre-provider expiry: `evidence/1019-harness-fix/red-pre-provider-expiry.log` — rc 1; merge/provider-unreachable got rc 124 instead of 75, omitted CANNOT_ASSERT, did not observe the status provider, and wrote no additional audit record (four named failures).
|
|
||||||
- GREEN host focused harness: `evidence/1019-harness-fix/green-host.log` — rc 0, all outcome classes passed.
|
|
||||||
- Load-bearing clock negative control: a temporary same-directory mutant replaced the virtual `date` body with `/bin/date`; `evidence/1019-harness-fix/red-clock-not-intercepted.log` — rc 1 with named `virtual clock interception did not run` failures. The mutant file was removed after the run.
|
|
||||||
- Exact CI-base repeat: `git.mosaicstack.dev/mosaicstack/stack/ci-base:latest`, repository mounted read-only, harness work under container `/tmp`; `evidence/1019-harness-fix/ci-image-repeat/summary.log` — **100 pass / 0 fail / 100 total**.
|
|
||||||
- Synchronization design: provider-status observation creates the event marker; virtual time is 1000 before the event and 1002 afterward. Pending alone reaches the stubbed no-op sleep and a post-observation deadline check. `-t 1` is uniquely load-bearing because removing it restores the 900-second default deadline at virtual time 1900, which 1002 does not cross. The numeric timeout is subject semantics under virtual time, not a wall-clock synchronization duration.
|
|
||||||
|
|
||||||
## Review remediation — semantic timeout vs. liveness bound
|
|
||||||
|
|
||||||
Security review found that virtual time remained at 1000 forever before provider observation and stubbed sleep never waited. A regression looping before the status endpoint—or blocking in the first provider call—therefore could prevent `run_guard` from returning, so the post-return provider assertion could never fire.
|
|
||||||
|
|
||||||
**General rule:** A timeout usually serves two purposes: semantics and liveness. Removing wall time from semantic synchronization can silently remove the only independent hang bound. Preserve deterministic virtual time for subject semantics, but provide a separately implemented real-clock liveness watchdog and prove that watchdog fires.
|
|
||||||
|
|
||||||
Remediation:
|
|
||||||
|
|
||||||
- Every guard subject invocation is launched by absolute `/usr/bin/python3` in a new session. Python's internal monotonic `wait(timeout=...)` provides real-clock liveness independently of PATH; expiry kills the entire isolated process group, so neither PATH-front shims nor a blocked provider descendant can retain the capture pipe.
|
|
||||||
- Watchdog expiry returns distinct harness rc 90 plus `FAIL HANG watchdog`, separate from subject timeout rc 124.
|
|
||||||
- A first attempt using absolute `/usr/bin/timeout -s KILL` passed on GNU coreutils but failed in the exact Alpine CI-base image: BusyBox killed the immediate wrapper while the guard/provider descendants survived and retained the command-substitution pipe. The process-group kill is therefore required behavior, not portability polish.
|
|
||||||
- A committed positive control hangs the branch-provider stub before the status endpoint. It must terminate through the watchdog, emit the hang-specific diagnostic, return rc 90, and prove the status provider was never reached.
|
|
||||||
- RED before remediation: a temporary ordinary-success mutant hung before provider observation; only an external control could kill the suite (rc 137), and there was no internal hang-specific diagnostic (`red-watchdog-absent.log`).
|
|
||||||
- The watchdog mutant/control is load-bearing: removing the internal watchdog leaves the control unable to produce its required rc 90 and diagnostic.
|
|
||||||
|
|
||||||
Post-review evidence:
|
|
||||||
|
|
||||||
- Host focused harness with process-group watchdog: rc 0 (`green-watchdog-process-group-host.log`).
|
|
||||||
- Exact Alpine CI-base focused harness with process-group watchdog: rc 0 (`green-watchdog-ci-image.log`).
|
|
||||||
- Hanging ordinary-success mutant: suite rc 1; success returned rc 90, emitted `FAIL HANG watchdog`, and loudly reported that provider/clock observation did not occur (`red-watchdog-fires.log`).
|
|
||||||
- Removed-`-t 1` mutant: suite rc 1; pending was terminated by the watchdog instead of producing `ASSERTED_NOT_READY`, proving the explicit timeout is load-bearing (`red-timeout-argument-removed.log`).
|
|
||||||
|
|
||||||
## 60% context hold
|
|
||||||
|
|
||||||
Stopped before baseline/review/commit as required by the charter. Remaining: inspect final diff, shell/static/baseline gates, independent code/security review, remediation if any, identity-bound commit/trailer verification, mandatory queue guard plus direct terminal Woodpecker `mosaic` enumeration, push, self-posted PR/provider poster read-back, exact-head terminal-green CI, coordinator merge authorization, squash merge, main CI verification, and leave #1019 unclosed as `believed-fixed, pending jarvis validation`.
|
|
||||||
@@ -1,229 +0,0 @@
|
|||||||
# #1043 — Fleet pane git-identity propagation
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Ensure a fleet seat's launched runtime process receives its roster-derived `MOSAIC_GIT_IDENTITY`, and lock the complete generated-environment propagation boundary with an enumerated set comparison.
|
|
||||||
|
|
||||||
## Tracking
|
|
||||||
|
|
||||||
- External issue: `mosaicstack/stack#1043`
|
|
||||||
- Branch: `fix/1043-pane-git-identity`
|
|
||||||
- Coordinator: `tl-mosaic`
|
|
||||||
- `docs/TASKS.md`: read-only by project worker contract; not modified.
|
|
||||||
|
|
||||||
## Constraints
|
|
||||||
|
|
||||||
- RED-first bug reproducer is mandatory.
|
|
||||||
- R7 delete-the-subject mutation must turn the behavioral test red.
|
|
||||||
- Assert launched-process environment, not source text.
|
|
||||||
- One push only; do not poll CI after push.
|
|
||||||
- Run the CI queue guard immediately before push and report its `state=` line as state, not evidence.
|
|
||||||
- Do not modify a live host launcher or obtain/copy another credential.
|
|
||||||
- Self-post the PR, verify provider attribution, then stop.
|
|
||||||
- Final status wording: `believed-fixed, pending jarvis validation`.
|
|
||||||
|
|
||||||
## Scope inventory
|
|
||||||
|
|
||||||
Re-derived against `origin/main` at `85d2108e`:
|
|
||||||
|
|
||||||
- Launch consumer: `packages/mosaic/framework/tools/fleet/start-agent-session.sh`
|
|
||||||
- Behavioral launch test: `packages/mosaic/framework/tools/fleet/test-start-agent-session.sh`
|
|
||||||
- Generated-environment contract/parser: `packages/mosaic/src/fleet/generated-env-boundary.ts`
|
|
||||||
- Roster projection producers:
|
|
||||||
- `packages/mosaic/src/commands/fleet.ts`
|
|
||||||
- `packages/mosaic/src/fleet/fleet-reconciler.ts`
|
|
||||||
- `packages/mosaic/src/fleet/fleet-agent-crud.ts`
|
|
||||||
- `packages/mosaic/src/fleet/v1-v2-migration.ts`
|
|
||||||
- Contract and producer tests discovered by repository search.
|
|
||||||
- Generated-environment operator/developer docs and their executable documentation contract test.
|
|
||||||
|
|
||||||
Discrepancy sent to `tl-mosaic`: current main no longer contains the charter's `PANE_SHELL_SNIPPET`; #772 replaced it with an `/usr/bin/env -i` argv launch boundary, and current generated projections do not declare git identity. Code-read inventory is **NOT MEASURED** behavior.
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Add the process-environment set-comparison regression first and record RED.
|
|
||||||
2. Add roster-derived `MOSAIC_GIT_IDENTITY=<agent name>` to the complete generated projection contract.
|
|
||||||
3. Validate identity syntax and equality with `MOSAIC_AGENT_NAME`; pass it through the clean pane environment.
|
|
||||||
4. Update affected projection tests and generated-environment docs.
|
|
||||||
5. Run focused and baseline gates.
|
|
||||||
6. Perform R7 by deleting the pane propagation entry, prove RED, restore, and prove GREEN.
|
|
||||||
7. Run independent review, remediate, commit, queue guard, one push, self-post PR, verify provider attribution, and stop without CI polling.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
No explicit token cap was provided. Working cap: one narrow logical unit, no dependency installation unless existing tooling requires it, no unrelated refactor.
|
|
||||||
|
|
||||||
## Evidence log
|
|
||||||
|
|
||||||
### TDD and mutation evidence
|
|
||||||
|
|
||||||
- RED-first, repository launcher: `bash packages/mosaic/framework/tools/fleet/test-start-agent-session.sh` exited 64 on pre-fix source with `code=unknown-key key=MOSAIC_GIT_IDENTITY`. The generated seat could not launch with the required declared identity.
|
|
||||||
- GREEN: the same repository launcher test emitted `ok - start-agent-session generated environment boundary`.
|
|
||||||
- R7 delete-the-subject: removed only `"MOSAIC_GIT_IDENTITY=$MOSAIC_GIT_IDENTITY"` from the repository launch array; the same test exited 1 with `FAIL: runtime pane omitted or changed generated environment keys: MOSAIC_GIT_IDENTITY`.
|
|
||||||
- R7 restoration: restored that launch entry; the same test returned green.
|
|
||||||
- Launcher under test is explicitly `packages/mosaic/framework/tools/fleet/start-agent-session.sh` through the test's `$START`, **not** the stale installed host copy.
|
|
||||||
|
|
||||||
### Situational and focused tests
|
|
||||||
|
|
||||||
- Repository launcher boundary: green, including set comparison of all nine generated projection entries and fail-before-tmux cases for missing, unsafe, mismatched, and local-shadow Git identity.
|
|
||||||
- Fleet systemd launcher integration: `bash packages/mosaic/framework/systemd/user/test-fleet-units.sh` — green.
|
|
||||||
- Focused Mosaic Vitest set: 6 files, 311 tests — green.
|
|
||||||
- `bash -n` on changed shell files — green.
|
|
||||||
- `git diff --check` — green.
|
|
||||||
|
|
||||||
### Baseline gates
|
|
||||||
|
|
||||||
- `pnpm typecheck` — 45/45 tasks green.
|
|
||||||
- `pnpm lint` — 25/25 tasks green.
|
|
||||||
- `pnpm format:check` — green.
|
|
||||||
- `pnpm test:checkout` — green.
|
|
||||||
- Repository-wide Vitest under a hermetic current-version npm prefix: Mosaic 81/81 files and 1510/1510 tests green; other workspace test tasks shown green before the framework-shell phase.
|
|
||||||
- Canonical `pnpm test` is not fully green on this host for unrelated environment-sensitive gates:
|
|
||||||
1. the first two runs exposed the globally installed Mosaic 0.0.48 update banner in three CLI smoke tests expecting empty stderr;
|
|
||||||
2. after isolating that global-version input, the framework wake assertion aborted at the known `#973` Bash `BASH_LINENO` convention check (exit 97; observed `[3 5]`, expected `[3 4]`).
|
|
||||||
No tests were weakened or bypassed; focused changed-surface tests are green. CI remains the canonical clean-environment result and is intentionally not polled after push per charter.
|
|
||||||
|
|
||||||
### Independent review
|
|
||||||
|
|
||||||
- Codex code review first pass: request changes for missing shell rejection-path coverage.
|
|
||||||
- Remediation: added table-driven missing/unsafe/mismatch/local-shadow launcher cases, each asserting no tmux call.
|
|
||||||
- Codex code re-review: **approve**, no findings, confidence 0.88.
|
|
||||||
- Codex security review: risk `none`, no findings, confidence 0.97.
|
|
||||||
|
|
||||||
### Acceptance criteria mapping
|
|
||||||
|
|
||||||
| Acceptance criterion | Evidence |
|
|
||||||
| --- | --- |
|
|
||||||
| AC-FGI-01: launched process receives every generated key/value | Repository launcher process-environment `comm -23` set comparison; GREEN and R7 RED evidence above |
|
|
||||||
| AC-FGI-02: missing, unsafe, or split identity fails before tmux | Table-driven shell cases plus TypeScript generated-boundary tests |
|
|
||||||
| AC-FGI-03: focused/baseline/review evidence recorded | Commands and review outcomes above; host-sensitive full-suite limitations stated explicitly |
|
|
||||||
|
|
||||||
### Documentation checklist
|
|
||||||
|
|
||||||
- PRD updated with #1043 requirements and acceptance criteria.
|
|
||||||
- Fleet launch runbook, generated-env concept, and generated-env reference updated.
|
|
||||||
- No API/OpenAPI, sitemap, user publishing target, deployment, or external docs publication change applies.
|
|
||||||
- `docs/TASKS.md` remains unmodified per its single-writer project contract.
|
|
||||||
|
|
||||||
## Round 2 — PR #1073 review 97 remediation
|
|
||||||
|
|
||||||
### Review blocker
|
|
||||||
|
|
||||||
The launched-process suite was signed-excluded from CI enumeration. Manual GREEN/R7 evidence therefore did not prove a PR workflow could detect regression.
|
|
||||||
|
|
||||||
### RED-first and canonical wiring
|
|
||||||
|
|
||||||
1. Removed the suite's signed exclusion before adding a CI execution path.
|
|
||||||
2. `check-test-enumeration.sh` went RED with exact `UNENUMERATED` output for `test-start-agent-session.sh`: population 49, enumerated 30, excluded 18.
|
|
||||||
3. Added both `framework/tools/fleet/test-start-agent-session.sh` and `framework/systemd/user/test-fleet-units.sh` to `@mosaicstack/mosaic`'s canonical `test:framework-shell` chain.
|
|
||||||
4. The guard returned GREEN: population 49, enumerated 32, excluded 18, surfaces 45. The systemd suite is outside the guard's tools-only population but now has the same explicit canonical execution disposition.
|
|
||||||
|
|
||||||
### Workflow-level R7
|
|
||||||
|
|
||||||
- Deleted only the pane launch entry `"MOSAIC_GIT_IDENTITY=$MOSAIC_GIT_IDENTITY"`.
|
|
||||||
- Ran the exact `.woodpecker/ci.yml` test-step command, `pnpm test`, with only a temporary PATH-scoped npm shim reporting the checkout's current 0.0.49 version so the unrelated global 0.0.48 banner could not preempt the shell chain.
|
|
||||||
- Result: exit 1 at `@mosaicstack/mosaic#test`, with the enumeration guard GREEN followed by `FAIL: runtime pane omitted or changed generated environment keys: MOSAIC_GIT_IDENTITY`.
|
|
||||||
- Restored the launch entry. The canonical `test:framework-shell` chain then reached both newly wired suites and printed both GREEN markers before the known unrelated #973 host-only `BASH_LINENO` abort.
|
|
||||||
- An actual provider PR workflow on the intentionally broken mutant is **NOT MEASURED**: the one-push constraint forbids pushing a red mutant and then a repaired head. Local execution proves the exact PR workflow command and dependency chain go RED on the subject deletion; CI on the repaired pushed head remains canonical.
|
|
||||||
|
|
||||||
### Workflow population
|
|
||||||
|
|
||||||
- **DEFINED:** 3 workflows (`ci.yml`, `ci-image.yml`, `publish.yml`).
|
|
||||||
- **ELIGIBLE for `pull_request`:** 1/3 (`ci.yml`), based on top-level `when:` clauses.
|
|
||||||
- **REPORTED:** Round-1 exact-head provider read reported 1/1 eligible context (`ci/woodpecker/pr/ci`). Post-remediation-head reported count is **NOT MEASURED** by this seat because CI polling is prohibited; workflow definitions and eligibility did not change.
|
|
||||||
|
|
||||||
### Independent remediation review
|
|
||||||
|
|
||||||
- First Round-2 review identified a CI-image blocker: the newly wired launcher suite used Perl, which the Alpine CI base does not install.
|
|
||||||
- Replaced the suite's three Perl-only fixture mutations with POSIX/BusyBox-compatible `sed -i` substitutions; production behavior and assertions are unchanged.
|
|
||||||
- Codex re-review: **APPROVE**, confidence 0.93, no findings.
|
|
||||||
|
|
||||||
### Vitest denominator reconciliation
|
|
||||||
|
|
||||||
The PR's `311/311` is correct for its explicitly named six-file command at both the original and remediation worktrees:
|
|
||||||
|
|
||||||
- generated environment boundary: 24
|
|
||||||
- fleet documentation: 23
|
|
||||||
- Tess service profile: 6
|
|
||||||
- fleet regen command: 27
|
|
||||||
- fleet agent CRUD command: 22
|
|
||||||
- fleet command: 209
|
|
||||||
- total: **311**
|
|
||||||
|
|
||||||
Review 97 reported 312/312 without naming its six files. That is a different or miscounted population and cannot replace the command-scoped 311 denominator; the PR follow-up will name the exact files and arithmetic.
|
|
||||||
|
|
||||||
## Round 3 — Alpine stale-marker portability
|
|
||||||
|
|
||||||
### Objective and plan
|
|
||||||
|
|
||||||
- Replace the GNU-only relative-date fixture with a deterministic POSIX/BusyBox timestamp while preserving the required stale-marker assertion.
|
|
||||||
- Re-run the launcher suite in the canonical `ci-base:latest` Alpine image, then run applicable repository gates and independent review.
|
|
||||||
- Update the PR body to name the repeated GNU-host/Alpine-CI portability pattern, run the mandatory queue guard, push once, verify provider attribution, and stop without CI polling.
|
|
||||||
- Working budget: 8K tokens; scope is one fixture line plus delivery evidence. No production behavior changes.
|
|
||||||
|
|
||||||
### RED-first evidence
|
|
||||||
|
|
||||||
Before the fix, the canonical CI image command
|
|
||||||
`docker run --rm -v "$PWD:/work" -w /work git.mosaicstack.dev/mosaicstack/stack/ci-base:latest bash packages/mosaic/framework/tools/fleet/test-start-agent-session.sh`
|
|
||||||
exited 1 at the stale-marker setup with exact BusyBox output
|
|
||||||
`touch: invalid date '10 seconds ago'`. The prior fresh-marker assertions had already executed, matching pipeline 2233's failure location.
|
|
||||||
|
|
||||||
### Root cause and fix
|
|
||||||
|
|
||||||
The test used GNU `touch -d` relative-date parsing although the PR workflow runs on Alpine/BusyBox. The fixture now uses POSIX `touch -t 200001010000.00`, a fixed timestamp that is unconditionally stale; the stale assertion remains mandatory and was not made tolerant of missing timestamp metadata.
|
|
||||||
|
|
||||||
### Structural pattern
|
|
||||||
|
|
||||||
This is the third GNU-host/Alpine-CI portability defect in the lane: GNU `grep` multi-match counting, Perl-only fixture mutation, and GNU `touch -d` date parsing. The repeated cause is shell suites authored on a GNU host but executed in an Alpine CI image; durable prevention belongs in CI-image execution or portability lint, not assertion weakening.
|
|
||||||
|
|
||||||
### GREEN and quality evidence
|
|
||||||
|
|
||||||
- Focused launcher suite in `ci-base:latest`: exit 0, `ok - start-agent-session generated environment boundary`.
|
|
||||||
- Canonical test step in `ci-base:latest` with the pipeline's `pgvector/pgvector:pg17` service, readiness check, migration, and `pnpm test`: exit 0; 46/46 Turbo tasks; Mosaic 81/81 files and 1510/1510 tests; Gateway 57 passed/5 skipped files and 629 passed/11 skipped tests; enumeration 49 population / 32 enumerated / 18 signed exclusions / 45 named surfaces.
|
|
||||||
- The first image-only `pnpm test` attempt lacked the pipeline PostgreSQL service and failed only on connection refusal after the launcher suite was GREEN. The rerun supplied the canonical service precondition and passed.
|
|
||||||
- Canonical-image baseline: typecheck 45/45 tasks, lint 25/25 tasks, format check GREEN; `git diff --check` GREEN.
|
|
||||||
- Independent Codex code review: APPROVE, confidence 0.96, 2/2 Round-3 files, no findings.
|
|
||||||
- Independent Codex security review: risk none, confidence 0.99, 2/2 Round-3 files, no findings.
|
|
||||||
|
|
||||||
### Re-derived inventory and denominators
|
|
||||||
|
|
||||||
- Round-3 git delta: **2/2 files** — launcher suite and task scratchpad; 25 insertions / 1 deletion before evidence finalization.
|
|
||||||
- Full PR path inventory against `origin/main` at `85d2108e`: **19/19 changed paths**; Round 3 adds no new PR path.
|
|
||||||
- Workflow definition population: **1/3 pull-request-eligible** (`ci.yml` of `ci.yml`, `ci-image.yml`, `publish.yml`).
|
|
||||||
- Do not re-litigate the settled 311/312 populations; both are valid for their separately named Tess6 and CRUD-core7 sets.
|
|
||||||
|
|
||||||
## Round 4 — bound stale-marker observation
|
|
||||||
|
|
||||||
### Objective and plan
|
|
||||||
|
|
||||||
- Make the heartbeat assertion discriminate an initially stale native marker from a fresh marker without changing the production staleness threshold or shortening the polling window.
|
|
||||||
- Freeze only the sidecar's numeric observation clock during the stale-fixture arm so elapsed assertion time cannot turn a fresh mutant stale.
|
|
||||||
- Prove two independent mutants RED: disable production stale-marker detection while retaining the stale fixture; replace the stale fixture with a fresh marker. Restore the tree and prove GREEN in the canonical Alpine image.
|
|
||||||
- Re-derive the changed-path inventory, run applicable quality and independent review gates, commit with environment-only author/committer identity, queue-guard, push once, verify provider attribution using curl stdin config, and stop without CI polling.
|
|
||||||
- Working budget: 8K tokens. Scope is the launcher test and its scratchpad evidence; production launcher behavior remains unchanged.
|
|
||||||
|
|
||||||
### Root cause and bounded observation
|
|
||||||
|
|
||||||
The 30 × 0.1-second assertion window overlaps the production `now - marker > interval * 2 + 1` threshold at interval 1. Depending on second boundaries and load, a fresh marker can age past the threshold before the assertion ends. A focused pre-fix fresh-mutant attempt returned RED while Review 101's full-suite run returned GREEN; the differing result is itself timing dependence, not a discriminating assertion.
|
|
||||||
|
|
||||||
The test now supplies a fixed numeric epoch only to the stale-fixture sidecar. Its real marker mtime is still read from the filesystem, but assertion runtime cannot advance `now`. Date formatting still delegates to the image's real `/bin/date`. Neither the production threshold nor the 30 × 0.1-second polling window changed.
|
|
||||||
|
|
||||||
### Two-mutant RED / restored GREEN
|
|
||||||
|
|
||||||
All three runs used `git.mosaicstack.dev/mosaicstack/stack/ci-base:latest`:
|
|
||||||
|
|
||||||
1. **Stale-detection mutant RED:** replaced only the production stale-age predicate with `false` while retaining the fixed stale marker; suite exit 1 with `FAIL: heartbeat sidecar did not resume after native marker became stale or absent`.
|
|
||||||
2. **Fresh-marker mutant RED:** replaced only `touch -t 200001010000.00` with fresh `touch`; suite exit 1 with the same failed stale-resumption assertion. The fixed observation epoch kept the mutant fresh throughout all 30 polls.
|
|
||||||
3. **Restored tree GREEN:** suite exit 0 with `ok - start-agent-session generated environment boundary`.
|
|
||||||
|
|
||||||
### Re-derived inventory
|
|
||||||
|
|
||||||
- Round-4 delta: **2/2 files** — launcher test plus task scratchpad; production launcher delta is empty.
|
|
||||||
- Full PR inventory against `origin/main`: **19/19 paths**; Round 4 adds no path.
|
|
||||||
- Production stale threshold remains `now - marker > iv * 2 + 1`; assertion polling remains 30 × 0.1 seconds.
|
|
||||||
- Review 101's confirmed enumeration/workflow/CI and attribution evidence is accepted without re-polling or re-derivation.
|
|
||||||
|
|
||||||
## Residual risk
|
|
||||||
|
|
||||||
- Landing on `main` does not update the currently installed host launcher. Host framework installation/reseed and Jarvis live-seat validation are separate downstream events.
|
|
||||||
- Canonical CI result is pending and will not be polled by this seat.
|
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
# #1050 — Installer P0–P9 state machine and red-first fixture
|
||||||
|
|
||||||
|
## Objective
|
||||||
|
|
||||||
|
Implement C1 from the canonical greenfield-install PRD v2: a transactional P0–P9 installer spine, a side-effect-free P0–P8 `--check`, and a lane-parametric Debian/glibc non-root from-zero fixture. The acceptance milestone is an attributable RED on the pre-C1 installer while preserving P3 PASS.
|
||||||
|
|
||||||
|
## Authority and scope
|
||||||
|
|
||||||
|
- Canonical requirements: `jason.woltje/jarvis-brain` `docs/plans/2026-08-04-greenfield-install-blockers-PRD-v2.md`. Currency was re-derived after compaction: authenticated fetch resolved `origin/main` to `cb23e5fbc8a282fa967b93d7a134fa48d11b4bb1`; the PRD and charters are byte-identical to the previously read remote copies.
|
||||||
|
- Tracking: `mosaicstack/stack#1050` on `git.mosaicstack.dev` (author read back as `be-coder-05`).
|
||||||
|
- Historical implementation base: `origin/next` `4df478cdd150fdf8d52ea109f02ade5d85017acd`. Delivery PR #1054 targets `main` under L0's trunk-only rule; `next` remains a non-merging integration lane.
|
||||||
|
- Out of scope: PATH, skills, headless wizard/identity, activation remediation, #869 wiring, RM-02, main promotion.
|
||||||
|
- `docs/TASKS.md` is orchestrator-single-writer and is not modified by this worker.
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
1. Pre-register the canonical phase/output/side-effect-free/fault-injection checks and observe RED against the base installer.
|
||||||
|
2. Commit the immutable red-first acceptance fixture before implementation.
|
||||||
|
3. Add the state-machine/journal/postcondition spine without repairing P4/P5/P8 symptoms.
|
||||||
|
4. Wire the expected-RED from-zero fixture into Woodpecker using Debian/glibc and a non-root target user.
|
||||||
|
5. Run shell/static baselines, situational container validation, code review, security review, then deliver through a PR to `next` under the coordinator-owned merge path.
|
||||||
|
|
||||||
|
## Budget
|
||||||
|
|
||||||
|
- Working estimate: 32K reasoning/output tokens.
|
||||||
|
- Hard external cap: none stated.
|
||||||
|
- Adaptation: keep implementation in shell surfaces already in scope; no package dependency install unless repository gates require it.
|
||||||
|
|
||||||
|
## Pre-registered acceptance checks
|
||||||
|
|
||||||
|
| ID | Exact case | Expected pre-fix result |
|
||||||
|
|---|---|---|
|
||||||
|
| C1-R1 | `tools/e2e-install-test.sh --lane next` in a clean Debian 12 container as uid 1001 | non-zero; P3 PASS; P4 `NOT-MEASURED / UNDECLARED`; P5/P6/P8 FAIL with own reasons |
|
||||||
|
| C1-R2 | `tools/install-state-machine.test.sh` phase table case | RED because base installer does not enumerate canonical P0–P9 contracts |
|
||||||
|
| C1-R3 | side-effect-free `--check` case over a fingerprinted HOME | RED because base `--check` is version-only rather than P0–P8 predicates |
|
||||||
|
| C1-R4 | fault injection after each P2…P8 | RED because base installer has no injectable durable journal/rollback state |
|
||||||
|
| C1-R5 | Docker unavailable | base harness incorrectly exits 0; replacement must fail non-zero |
|
||||||
|
| C1-R6 | lane resolution | bare checkout is forbidden; fixture must pass `--next` and assert the resolved prerelease version |
|
||||||
|
| C1-R7 | same Debian fixture with `git` absent vs present | absent: P1 FAIL while legacy installer exits 0 and sync degrades; present: P1 PASS and observed store/runtime containment 101/101 |
|
||||||
|
|
||||||
|
## Progress
|
||||||
|
|
||||||
|
- [x] Charter, doctrine, delivery/CI/QA/docs guides read and re-anchored after compaction.
|
||||||
|
- [x] Canonical PRD v2/v3 addenda and charters read from fetched `origin/main`; numbering reconciles with the TL spec. No numbering conflict found. INV-B/C/D are binding and implemented without renumbering.
|
||||||
|
- [x] Target base reachability verified with `merge-base --is-ancestor`.
|
||||||
|
- [x] Issue #1050 created and provider author read back.
|
||||||
|
- [x] Initial RED captured; TL rejected P4's repo-root count as a false RED. Four populations disagree (framework payload 1, repo root 13, sync store 101 in the fixture, W-jarvis observation 7), so C1 now requires a checkout-free declared shipped-set artifact and reports P4 `NOT-MEASURED / UNDECLARED` until C5 supplies it.
|
||||||
|
- [x] P6 strengthens #869: the two dead enforcement hooks reproduce from zero on a clean broker-less container. C1 asserts the breach but neither wires nor unwires it.
|
||||||
|
- [x] P1 false pass identified from the P4 evidence row: `git` is absent from the Debian base and was undeclared even though skill sync shells out to it. C1 adds `git` to P1; the fixture matrix preserves absent/present controls. The prior claim that web1's missing runtime skills reproduce this greenfield mechanism is withdrawn by the TL and is not carried here.
|
||||||
|
- [x] Corrected RED transcript captured and reported, including the git-present/absent controls and strict P3 PASS.
|
||||||
|
- [x] State-machine implementation complete: private pre-mutation journal/snapshot, P0–P8 `--check`, P2–P8 fault seam, rollback, durable manifest/journal seal, action-status persistence, safe rollback roots, and stale-projection recovery.
|
||||||
|
- [x] Debian/glibc checkout fixture now packages the complete current checkout, verifies its digest in-container, and reaches the expected attributable RED without host inheritance. CI compares its exact final phase map/reasons to `tools/fixtures/greenfield-expected-red.tsv`; the fixture remains red while the detector job is green only on an exact match.
|
||||||
|
- [ ] Reviews complete. Automated review defects around Bash conditional errexit, explicit exits, P4/P6 persisted action status, dev/offline source resolution, stale locks, checkout coverage, and rollback path safety were remediated. Remaining automated objections are the charter-mandated expected RED/C5 boundary and signed provenance, which the canonical PRD explicitly defers; independent informed review is still required.
|
||||||
|
|
||||||
|
## Risks / blockers
|
||||||
|
|
||||||
|
- The deployed create wrappers do not expose `--dry-run`; identity preflight was performed through `pr-merge.sh --dry-run` on the same HOMELAB repo, which resolved `git.mosaicstack.dev` + `be-coder-05`. The issue create then fell back from tea to the API but provider read-back confirmed author `be-coder-05`.
|
||||||
|
- `next` is a non-merging integration lane; PR #1054 targets `main`. The old “pending promotion to main” caution dissolved when the base moved. #1050 remains open after merge and closes only after Jarvis validates the greenfield behavior.
|
||||||
|
- #869 must remain staged and inactive.
|
||||||
|
- Late sequencing input MB-BRAIN-01 is accommodated without implementation or renumbering: P2 covers installer distribution only; P5 owns requested credential capability; P7 leaves an ordered seam for credential-dependent resource provisioning after P5.
|
||||||
|
|
||||||
|
## Verification log
|
||||||
|
|
||||||
|
- `bash -n` and ShellCheck pass for all changed shell surfaces; `git diff --check` passes.
|
||||||
|
- `bash tools/install-state-machine.test.sh` passes, including exact P0–P8 rows, good/bad discrimination, persisted P4/P6 action failures, P2–P8 rollback, unsafe/overlapping/symlink roots, stale `active.json`, and fatal journal initialization.
|
||||||
|
- `bash tools/install-next-lane.test.sh` passes, including exact `@next` versions, immutable source fallback, source-build/archive-failure rollback, offline `--dev`, explicit refs, and prerelease suffix mismatch.
|
||||||
|
- `bash tools/e2e-install-test.sh --lane next --source checkout --git present` returns the required expected RED in clean Debian/glibc as uid 1001: installer P0/P1/P2/P3/P7 PASS; P4/P5/P6/P8 and P9 blocking; no `Done.` claim; checkout archive digest pinned and current framework installer exercised. `tools/verify-greenfield-expected-red.sh` converts that expected detector result into a green CI assertion and fails on any unreviewed verdict drift.
|
||||||
|
- Earlier repository gates passed: `pnpm typecheck`, `pnpm lint`, `pnpm format:check`, `pnpm test:installer`, upgrade manifest/rollback/durable-snapshot/migration suites, and focused `@mosaicstack/mosaic` tests with an isolated npm prefix. Full rerun is required after final edits.
|
||||||
@@ -1,97 +0,0 @@
|
|||||||
# #1098 — Framework shell portability / red main
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Restore terminal-green `main` by making the `test-start-agent-session.sh` clean-environment assertion semantic and portable without removing either newly enumerated framework-shell suite.
|
|
||||||
|
|
||||||
## Scope
|
|
||||||
|
|
||||||
- Tracking issue: `mosaicstack/stack#1098`
|
|
||||||
- Branch: `fix/framework-shell-portability`
|
|
||||||
- Base: `origin/main` at `4fa2768962702d53e16e8b67ee6ad52ebcb0910e`
|
|
||||||
- Primary file: `packages/mosaic/framework/tools/fleet/test-start-agent-session.sh`
|
|
||||||
- Requirements source: `docs/PRD.md` § Framework shell assertion portability (#1098)
|
|
||||||
- Out of scope: deployed files under `~/.config/mosaic`, pnpm-store cleanup, checkout deletion, and changes to the launcher’s `/usr/bin/env -i` behavior.
|
|
||||||
|
|
||||||
## Acceptance criteria
|
|
||||||
|
|
||||||
1. The test inspects the captured NUL-delimited tmux argv semantically and accepts an adjacent `/usr/bin/env`, `-i` pair regardless of trailing payload size or pipe scheduling.
|
|
||||||
2. Missing `/usr/bin/env`, missing `-i`, and non-adjacent `-i` remain failures.
|
|
||||||
3. Failure output includes the observed argv records with stable indexes and shell escaping; it exposes no credentials because this fixture supplies only generated non-secret launch data.
|
|
||||||
4. The focused suite passes on the dev host and in the repository CI image; the blocking PR/main pipeline returns terminal green.
|
|
||||||
5. Independent review passes; PR is squash-merged and #1098 is closed only after merged-main CI is terminal green.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
- ASSUMPTION: 30K-token working budget; rationale: one shell-test defect plus full PR/CI lifecycle.
|
|
||||||
- Auto-reduction: focused shell and package gates first; rely on canonical Woodpecker for the full monorepo suite rather than duplicating a dependency install under constrained `/home`.
|
|
||||||
- Disk baseline before clone/build: `/home` 7.1G free (99% used), `/tmp` 2.4G free (92% used).
|
|
||||||
|
|
||||||
## Investigation
|
|
||||||
|
|
||||||
### First-hand CI evidence
|
|
||||||
|
|
||||||
- Public log: `GET https://ci.mosaicstack.dev/api/repos/47/logs/2269/53041`
|
|
||||||
- Decoded 1,436 entries (11 null `data` entries treated as empty log rows), 190,756 bytes.
|
|
||||||
- Failure: `FAIL: pane command did not clear its environment` immediately after the expected pane-PID warning.
|
|
||||||
- BusyBox primitives, complete assertion pipeline, real CI image, stale/current image digests, Turbo cache masking, gateway failure, and heartbeat-sidecar concurrent writing were independently excluded.
|
|
||||||
|
|
||||||
### Root cause
|
|
||||||
|
|
||||||
The assertion ends in:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
printf '%s\n' "$pane_args" | tail -n +"$after_pane_env" | grep -qxF -- '-i'
|
|
||||||
```
|
|
||||||
|
|
||||||
The script has `set -o pipefail`. `grep -q` exits as soon as it finds the valid `-i` record. Upstream `tail`/`printf` can then receive SIGPIPE, making the aggregate pipeline nonzero even though grep returned 0 and the semantic property is true. This depends on payload size, pipe capacity, and scheduling, explaining a local/image pass with a CI failure.
|
|
||||||
|
|
||||||
Discriminating stress control with `/usr/bin/env` followed immediately by `-i`:
|
|
||||||
|
|
||||||
- 8,192-byte trailing payload: `printf=0 tail=0 grep=0`, aggregate 0.
|
|
||||||
- 16,384-byte trailing payload: `printf=0 tail=141 grep=0`, aggregate 141.
|
|
||||||
- 32,768+ bytes: `printf=141 tail=141 grep=0`, aggregate 141.
|
|
||||||
- A full-reading `grep -xF` control remained 0 for every payload.
|
|
||||||
|
|
||||||
This is a third branch omitted by the earlier present-vs-corrupted split: the pair can be present and intact while `pipefail` reports an upstream SIGPIPE.
|
|
||||||
|
|
||||||
## TDD plan
|
|
||||||
|
|
||||||
1. RED: preserve the one-off stress reproducer above and add an automated large-argv semantic regression that fails under the current pipeline implementation.
|
|
||||||
2. GREEN: parse the authoritative NUL-delimited capture into a Bash array and search for an adjacent `/usr/bin/env`, `-i` pair without a short-circuit pipeline.
|
|
||||||
3. Add negative controls for missing, detached, and reversed tokens.
|
|
||||||
4. On failure, print indexed `%q` argv records before returning nonzero.
|
|
||||||
5. Run focused suite, mutation controls, shell syntax/format checks, then repository baseline gates feasible without dependency installation.
|
|
||||||
6. Independent review, queue guard, push, PR, CI, coordinator merge authorization, squash merge, merged-main CI, issue close.
|
|
||||||
|
|
||||||
## Progress
|
|
||||||
|
|
||||||
- [x] Checkout created and based on `origin/main` `4fa27689`.
|
|
||||||
- [x] CI log decoded directly.
|
|
||||||
- [x] Root-cause stress control reproduced semantic match + aggregate pipeline failure.
|
|
||||||
- [x] RED evidence: intact `/usr/bin/env`, `-i` fixture produced component statuses `0/141/0` and aggregate 141 under the former `grep -q` pipeline; full-reading semantic control stayed 0.
|
|
||||||
- [x] GREEN implementation: direct NUL-argv adjacency parser, indexed diagnostics, and full-reading scalar predicates replace all load-bearing early-exit pipelines in this test.
|
|
||||||
- [x] Baseline/situational tests:
|
|
||||||
- focused launcher suite: PASS on GNU host and cached Alpine CI image;
|
|
||||||
- paired `test-fleet-units.sh`: PASS;
|
|
||||||
- enumeration guard: PASS (`population=53`, `enumerated=36`, `excluded=18`), 14/14 mutation needles;
|
|
||||||
- `bash -n`, ShellCheck, `git diff --check`: PASS;
|
|
||||||
- static denominator after change: zero load-bearing `grep -q`/`head`/`-m1` pipeline candidates in `test-start-agent-session.sh`;
|
|
||||||
- delete-the-subject mutation removing production `-i`: RED with 78 indexed argv records, byte count, and explicit boundary failure.
|
|
||||||
- [x] Independent review:
|
|
||||||
- first Codex review: request changes — negative fixtures did not each assert diagnostics;
|
|
||||||
- remediation: centralized predicate + diagnostic wrapper and exercised all four negative fixtures;
|
|
||||||
- second Codex review: APPROVE, 0 blockers/should-fix/suggestions;
|
|
||||||
- Codex security review: risk none, 0 findings.
|
|
||||||
- [ ] PR CI, formal fleet review, merge, merged-main CI, issue closure.
|
|
||||||
|
|
||||||
## Documentation disposition
|
|
||||||
|
|
||||||
- Updated canonical `docs/PRD.md` with FSP requirements and acceptance criteria.
|
|
||||||
- This is an internal test/reliability change with no API, user workflow, deployment, navigation, or publishing-surface change; no user/admin/API/sitemap update is required.
|
|
||||||
- `docs/TASKS.md` remains unchanged because the project contract makes it orchestrator-only.
|
|
||||||
|
|
||||||
## Risks
|
|
||||||
|
|
||||||
- The CI failure did not print its captured argv, so the exact CI payload is unavailable. The stress control proves the assertion is non-portable and can emit the exact false verdict; branch CI is the canonical confirmation that replacing it resolves pipeline 2269’s failure class.
|
|
||||||
- Printing fixture argv is safe only while this test’s projection remains non-secret. The diagnostic must stay scoped to the test capture and shell-escaped.
|
|
||||||
@@ -1,37 +0,0 @@
|
|||||||
# #1099 — pipefail + early-exit sweep
|
|
||||||
|
|
||||||
## Scope and decisions
|
|
||||||
|
|
||||||
- Baseline `df4c591ab42aa1ae62c12935fdc0e772684864a0`, after #1100 removed its 35 sites.
|
|
||||||
- Split into review-sized non-closing tranches: runtime/general; tmux/git/quality tests; wake validation/tests.
|
|
||||||
- Do not equate class membership with demonstrated risk. Do not use payload size or pipeline stage count as a safety proxy.
|
|
||||||
- Preserve the issue's withdrawn findings for `qa-hook-stdin.sh` and the two fresh-directory `pnpm pack` lookups. Fix `install.sh:312` because malformed multi-root input must reach its named handler.
|
|
||||||
|
|
||||||
## Tranche 1 TDD
|
|
||||||
|
|
||||||
RED-first control: `node --test scripts/pipefail-early-exit.test.mjs` reported exactly 26 non-accepted runtime/general sites, including `install.sh:312`, and exited 1. A checked-in fixture generated from immutable baseline `df4c591a` records all 26 normalized sites; the control passes every fixture entry through the same scanner, asserts exact identity/count/uniqueness, and separately requires zero findings in the current tree. It also inventories accepted sites rather than silently excluding whole files.
|
|
||||||
|
|
||||||
Construction choices:
|
|
||||||
|
|
||||||
- here-string/file redirection for scalar grep assertions;
|
|
||||||
- full capture then parameter expansion for first-line selection;
|
|
||||||
- arrays/`mapfile` for complete populations;
|
|
||||||
- direct jq/awk/grep selection where one tool can express the property;
|
|
||||||
- no `|| true` added to a load-bearing assertion.
|
|
||||||
|
|
||||||
Site-by-site verdicts: `docs/reports/quality/1099-pipefail-sweep.md`.
|
|
||||||
|
|
||||||
## Tranche 2 TDD
|
|
||||||
|
|
||||||
Expanded the unconditional scanner over 11 non-wake test harnesses. RED named exactly 22 source lines; a second immutable-baseline fixture now asserts those 22 entries through the same scanner. Rewrites preserve command status by capturing producers before redirected assertions, use parameter expansion for line selection, and use complete `mapfile` populations where ordering matters. Current-tree finding count is zero for tranches 1 and 2.
|
|
||||||
|
|
||||||
## Verification so far
|
|
||||||
|
|
||||||
- `bash -n` on every changed shell script: pass.
|
|
||||||
- structural Node control: pass.
|
|
||||||
- `test-mutate-push-guard.sh`: 8/8 pass.
|
|
||||||
- `test-send-message-verdict.sh`: 3/3 pass.
|
|
||||||
- `test-send-message-socket.sh`: pass.
|
|
||||||
- Independent review 143 found two semantic regressions: a help-probe `|| true` changed the failure truth table, and an unguarded Git capture changed non-Git data-dir behavior from rc 0 + JSON to silent rc 128. Both received RED-first regressions before correction; help status is now separate and required, and Git status remains condition-guarded.
|
|
||||||
- Wake detector/reconcile/digest/preimage suites terminate at their existing fail-closed #973 `BASH_LINENO` environment probe (exit 97, observed `[3 5]`, expected `[3 4]`) before subject tests. No bypass or skip was used; canonical CI remains required.
|
|
||||||
- ShellCheck reports only pre-existing source-following, unused-variable, and untouched `ls | head` findings; no new diagnostic was introduced.
|
|
||||||
@@ -1,156 +0,0 @@
|
|||||||
# #1150 — Pi persistent goal extension
|
|
||||||
|
|
||||||
- **Task ID:** ISSUE-1150 (no `docs/TASKS.md` row; that file is orchestrator-only)
|
|
||||||
- **Issue:** #1150 — `pi: add persistent /goal controller extension to Mosaic framework`
|
|
||||||
- **Branch:** `feat/1150-pi-goal-extension`
|
|
||||||
- **Mode:** Delivery
|
|
||||||
- **Status:** in progress
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Build and locally validate a Mosaic-owned Pi `/goal` extension. Source must ship from
|
|
||||||
`packages/mosaic/framework/runtime/pi/`, framework sync must deploy it under
|
|
||||||
`~/.config/mosaic/runtime/pi/`, and no extension/configuration asset may be written into `~/.pi`.
|
|
||||||
Pi's native session manager remains the owner of session entries.
|
|
||||||
|
|
||||||
## Scope and acceptance source
|
|
||||||
|
|
||||||
- Canonical requirements: `docs/PRD.md`, section **Pi Persistent Goal Loop (#1150)**.
|
|
||||||
- User intent: continuous goal orientation and status checking after each Pi turn and compaction,
|
|
||||||
tested locally before framework delivery.
|
|
||||||
- Documentation target: canonical in-repo user/developer/runtime docs; no external publication.
|
|
||||||
|
|
||||||
## Assumptions
|
|
||||||
|
|
||||||
- `ASSUMPTION:` Initial semantic verification uses two consecutive structured, evidence-bearing
|
|
||||||
reports from the working agent rather than a second model request after every turn. This keeps the
|
|
||||||
loop testable and avoids doubling model cost while making the limitation explicit.
|
|
||||||
- `ASSUMPTION:` Default autonomous bounds are 40 turns and 6 repeated no-progress reports, with only
|
|
||||||
bounded numeric environment overrides.
|
|
||||||
- `ASSUMPTION:` A local smoke copy to `~/.config/mosaic/runtime/pi/goal-extension.ts` is authorized by
|
|
||||||
the user's explicit request. Full framework reseed into the live home is not required for the smoke
|
|
||||||
test and would touch unrelated framework-owned files.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
- Working estimate: 30K implementation/review tokens.
|
|
||||||
- Hard user cap: none stated.
|
|
||||||
- Cost control: deterministic fake-Pi tests; no nested evaluator calls; only bounded arithmetic/load
|
|
||||||
smoke workflows against the installed runtime.
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Update PRD and create tracking/scratchpad artifacts.
|
|
||||||
2. Read launcher, installer ownership, Pi extension, and documentation surfaces.
|
|
||||||
3. TDD: add fake-Pi behavior tests for commands, state restoration, turn checks, compaction, limits,
|
|
||||||
verification, and continuation deduplication.
|
|
||||||
4. Implement `runtime/pi/goal-extension.ts` and deterministic launcher discovery.
|
|
||||||
5. Add framework-sync/deployment acceptance coverage.
|
|
||||||
6. Update user, developer, runtime, framework README, and sitemap documentation.
|
|
||||||
7. Run focused tests, local Mosaic-path smoke test, then baseline repository gates.
|
|
||||||
8. Run independent review, remediate, commit, push/PR/CI/merge/issue closure per delivery gates.
|
|
||||||
|
|
||||||
## TDD decision
|
|
||||||
|
|
||||||
Applied. The continuation state machine and lifecycle scheduling are control-path logic where a race
|
|
||||||
or false terminal state can cause unbounded work or premature completion.
|
|
||||||
|
|
||||||
## Progress checkpoints
|
|
||||||
|
|
||||||
- [x] Issue #1150 created through Mosaic wrapper.
|
|
||||||
- [x] Isolated worktree created from `origin/main`.
|
|
||||||
- [x] PRD requirements and acceptance criteria added.
|
|
||||||
- [x] Task scratchpad created.
|
|
||||||
- [x] RED controller and security-regression tests written and observed failing before implementation.
|
|
||||||
- [x] Goal controller, launcher discovery, framework deployment coverage, and bounded state machine
|
|
||||||
implemented.
|
|
||||||
- [x] User, admin, developer, runtime, adapter, README, and sitemap documentation updated.
|
|
||||||
- [x] Final source copied additively to `~/.config/mosaic/runtime/pi/goal-extension.ts`; source and
|
|
||||||
deployed SHA-256 are identical.
|
|
||||||
- [x] Live Pi RPC smoke from the exact Mosaic path reached `achieved` with two verification passes and
|
|
||||||
no extension errors.
|
|
||||||
- [x] Baseline and situational checks completed, except the explicitly documented unavailable
|
|
||||||
PostgreSQL-only root integration case.
|
|
||||||
- [x] Independent code and OWASP/security reviews completed; all findings remediated and re-reviewed.
|
|
||||||
- [ ] Commit, push, PR, terminal-green CI, squash merge, and issue closure complete.
|
|
||||||
|
|
||||||
## Tests and evidence
|
|
||||||
|
|
||||||
### Situational
|
|
||||||
|
|
||||||
- `pnpm --filter @mosaicstack/mosaic exec vitest run src/runtime/pi-goal-extension.spec.ts`
|
|
||||||
- final: 25 passed.
|
|
||||||
- Covers commands, per-turn checks, context injection, two-pass verification, mixed-report
|
|
||||||
rejection, bounded limits, compaction, branch restore, stale timers, credential redaction,
|
|
||||||
typed-field false-positive protection, and append-only legacy-state fail-closed behavior.
|
|
||||||
- Final focused launcher/controller/file-adapter run: 3 files / 67 tests passed.
|
|
||||||
- Final V8 coverage for `framework/runtime/pi/goal-extension.ts`:
|
|
||||||
- 99.17% statements/lines, 93.78% branches, 100% functions.
|
|
||||||
- Installer migration fixture: 24 passed and byte-compared the deployed framework asset.
|
|
||||||
- Standalone extension TypeScript check against installed Pi 0.84.1 types passed:
|
|
||||||
`pnpm --filter @mosaicstack/mosaic exec tsc --noEmit --pretty false --module NodeNext
|
|
||||||
--moduleResolution NodeNext --target ES2022 --skipLibCheck framework/runtime/pi/goal-extension.ts`.
|
|
||||||
- Live deployment/load evidence:
|
|
||||||
- source/deployed SHA-256:
|
|
||||||
`1f0a3806e0948ad5f49684273a7e535e9880c148f7fd16d13ee487fcd601f637`.
|
|
||||||
- `get_commands` identified `/goal` as an extension command sourced from
|
|
||||||
`~/.config/mosaic/runtime/pi/goal-extension.ts`; `/goal help` succeeded; zero extension errors.
|
|
||||||
- live arithmetic goal ended `achieved`, verification `2/2`, with 3 goal reports / 3 agent starts
|
|
||||||
and zero extension errors.
|
|
||||||
- no goal extension exists under `~/.pi` extension paths.
|
|
||||||
|
|
||||||
### Baseline
|
|
||||||
|
|
||||||
- `pnpm build`: passed before the final framework-only redaction remediation; the extension is not a
|
|
||||||
package build input and its final source passed the standalone Pi type check.
|
|
||||||
- `pnpm typecheck`: 45/45 tasks passed.
|
|
||||||
- `pnpm lint`: 25/25 tasks passed.
|
|
||||||
- `pnpm format:check`: passed.
|
|
||||||
- Final Mosaic package components:
|
|
||||||
- Vitest: 82 files / 1,539 tests passed.
|
|
||||||
- full `test:framework-shell` harness passed.
|
|
||||||
- the discovered pre-existing tmux loader-marker race was reproduced with constructor PID
|
|
||||||
evidence, fixed with a pane readiness/FIFO barrier, passed 3 consecutive focused runs, and passed
|
|
||||||
in the full shell harness.
|
|
||||||
- one combined rerun encountered the separate existing real-lease probe TOCTOU in
|
|
||||||
`install-ordering-guard.spec.ts`; an earlier final Vitest run was fully green and the changed
|
|
||||||
focused suites remained green.
|
|
||||||
- Gateway safe baseline excluding the prohibited PostgreSQL-only fixture: 55 files / 600 tests passed
|
|
||||||
(6 files / 12 tests skipped by their existing environment gates).
|
|
||||||
- Root `pnpm test` reached 43 successful workspace tasks and all changed-package Vitest tests, but
|
|
||||||
the unchanged `apps/gateway/src/__tests__/cross-user-isolation.test.ts` afterAll hook retried a
|
|
||||||
PostgreSQL connection and failed authentication (`28P01`). This checkout explicitly forbids local
|
|
||||||
PostgreSQL startup/access; the failure is unrelated to #1150 and cannot be remediated by starting
|
|
||||||
the database. The gateway suite excluding that PostgreSQL-only file and required CI are used as
|
|
||||||
the safe verification paths.
|
|
||||||
|
|
||||||
### Independent review
|
|
||||||
|
|
||||||
- Codex code review: approved, 0 findings across 15 files.
|
|
||||||
- Initial Codex security review: one medium CWE-532/A09 finding for raw report persistence.
|
|
||||||
- Remediation added central credential-pattern redaction, prompt/docs guidance, canary tests, typed
|
|
||||||
field false-positive guards, and sticky fail-closed restore for credential-bearing append-only
|
|
||||||
history.
|
|
||||||
- Codex security re-review: risk `none`, 0 findings, confidence 0.87.
|
|
||||||
- Focused remediation review findings were fixed; final focused re-review verdict: `APPROVE`.
|
|
||||||
- Focused independent review of the tmux readiness barrier: `APPROVE`, no actionable findings.
|
|
||||||
|
|
||||||
## Risks and blockers
|
|
||||||
|
|
||||||
- Live `~/.config/mosaic` is shared by active Pi/fleet processes. Local deployment remained a single
|
|
||||||
additive framework file and did not reload or restart unrelated sessions.
|
|
||||||
- Completion verification is semantic, not mathematical: the active agent supplies structured
|
|
||||||
evidence twice. Operators must still inspect consequential outcomes.
|
|
||||||
- Credential redaction is pattern-based defense-in-depth, not a secret store. It covers
|
|
||||||
controller-owned state/status/tool details, not Pi's separate model-message/tool-call history.
|
|
||||||
Goals and reports must never contain real secrets or raw sensitive output. Because Pi session
|
|
||||||
entries are append-only, a detected credential-bearing legacy branch fails closed and the affected
|
|
||||||
session must be removed.
|
|
||||||
- Current installed Pi is newer than the repository's historical gateway Pi dependency. The
|
|
||||||
extension was checked and smoke-tested against installed Pi 0.84.1 using stable documented APIs.
|
|
||||||
- Local root testing cannot safely execute the unchanged PostgreSQL-only integration fixture under
|
|
||||||
the checkout's explicit database safety constraints. Terminal-green PR CI remains mandatory before
|
|
||||||
merge.
|
|
||||||
- The unchanged real-lease default-probe test can observe different broker availability across its two
|
|
||||||
sequential probes; one combined package rerun hit that existing TOCTOU. The same final Vitest suite
|
|
||||||
passed in a separate run, and CI remains the merge authority.
|
|
||||||
@@ -1,99 +0,0 @@
|
|||||||
# PR merge squash message field
|
|
||||||
|
|
||||||
- **Charter:** `/home/hermes/agent-work/CHARTER-PRMERGE-MESSAGE-FIELD.md`
|
|
||||||
- **Owner:** `be-coder-08`
|
|
||||||
- **Branch:** `fix/pr-merge-message-field`
|
|
||||||
- **Base:** remote `main` / local `origin/main` at `85d2108e4ed15c744ad3b87a5b629e7b2d39405a`
|
|
||||||
- **Estate:** HOMELAB tooling shared by HOMELAB and USC
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Add an optional, identity-checked Gitea squash message to `pr-merge.sh` so genuine multi-author PRs retain non-poster branch authors without weakening hardcoded squash behavior.
|
|
||||||
|
|
||||||
## Binding requirements
|
|
||||||
|
|
||||||
1. `Do` remains hardcoded to `squash`; no provider/repository default may select merge style.
|
|
||||||
2. A verified trailer uses a PR commit's linked `author.login` and that same commit's author email. No `/users/{login}` primary-email lookup occurs. Recorded rationale: this asks only what the provider can answer.
|
|
||||||
3. A commit with `author.login` null blocks before merge, prints both the null provider fact and commit email fact, and names the escalation principal.
|
|
||||||
4. The BLOCK arm must be observed firing; a normal canonical single-author API payload remains explicit squash plus its reviewed `head_commit_id`.
|
|
||||||
5. Every provider mutation is read back from the provider; no real PR is merged during tests.
|
|
||||||
|
|
||||||
## Derived interface decisions
|
|
||||||
|
|
||||||
- Add `--co-author-trailers` rather than accepting arbitrary message text. The wrapper enumerates PR commits and constructs trailers, making an unchecked `Co-authored-by` line unexpressible.
|
|
||||||
- Require `--escalate-to PRINCIPAL` with `--co-author-trailers`, so the BLOCK diagnostic always names a principal rather than a generic role.
|
|
||||||
- Do not expose `MergeTitleField` separately. When trailers exist, set it from the provider PR title and set `MergeMessageField` only to construction-generated trailers. This preserves one provider source for the title and avoids an unrelated caller-controlled degree of freedom.
|
|
||||||
- Preserve first-commit order and emit one trailer per distinct non-poster `author.login`, using that first linked commit's own email.
|
|
||||||
|
|
||||||
## Canonical delivery plan
|
|
||||||
|
|
||||||
1. Port the capability into the installed source of truth, `packages/mosaic/framework/tools/git/pr-merge.sh`; do not retain `infra/fleet/tools/git` as a second copy.
|
|
||||||
2. Preserve canonical `--expect-head`, exact head branch/repository/SHA queue inspection, Gitea atomic head pinning, GitHub `--match-head-commit`, and delete-after-merge semantics.
|
|
||||||
3. Do not port the deployed-only `--skip-queue-guard` bypass. Add the focused harness to the canonical framework-shell suite and re-establish RED/GREEN on the packaged baseline.
|
|
||||||
4. Deliver through a reviewed package release followed by `mosaic update` with its default framework reseed. The installer snapshots, manifest-syncs framework-owned `tools/**`, and rolls back on failure.
|
|
||||||
5. Before either estate relies on the change, require installed/package hash equality, `MergeMessageField` presence, and a green focused harness. Release/reseed ownership is currently unassigned and blocks activation after source merge.
|
|
||||||
|
|
||||||
## Evidence
|
|
||||||
|
|
||||||
- RED against the byte-identical deployed baseline (`sha256 08a65e8584c5…`): rc 1 with eight named failures. The wrapper rejected `--co-author-trailers`; the null-login path emitted none of the required BLOCK facts/principal; and both verified/ordinary API paths failed the stdin-config credential assertion (ordinary path exposed the fixture token through curl argv). Log: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-message-field-red.log`.
|
|
||||||
- GREEN on the deployed-baseline candidate: verified linked multi-author payload, null-login BLOCK, required named principal, explicit squash, stdin-config token transport, and absence of `/users` lookup all passed. Log: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-message-field-green.log`.
|
|
||||||
- RED against canonical packaged baseline `c581ef48…`: rc 1 with 32 assertions. It rejects the new option, and the first harness version did not satisfy canonical head branch/repository/SHA metadata. Log: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-packaged-baseline-red.log`. The port adapts the fixture rather than weakening canonical head controls.
|
|
||||||
- Provider capability probe against `git.mosaicstack.dev`: authenticated `be-coder-08` POST to deliberately nonexistent PR `2147483647` with both message fields returned JSON HTTP 404; the unauthenticated same request returned JSON HTTP 401 (not the charter's predicted 403). The authenticated-vs-unauthenticated differential proves write authorization resolved while no mergeable subject existed. `tl-mosaic` ruled the literal non-load-bearing: preserve the observed 404/401 pair and do not manufacture a 403 case. No cause was inferred and no real PR was targeted.
|
|
||||||
- Provider-generated trailer behavior is not treated as exclusive or absent. The wrapper's VERIFIED/BLOCK decision binds each requested non-poster trailer to commit `author.login` plus that commit's email; it does not assume `MergeMessageField` is the squash's only trailer source. The poster is omitted from the constructed list because the resulting squash author already records the poster; any additional provider-generated trailer is outside this change's unmeasured mechanism.
|
|
||||||
- An early candidate SHA-256 `5de32876990e4f26920448cb3220cc7f1146d558b4dd2bc1ee1a2abee2f2cbe6` passed the initial harness, then author-side review found credential-fallback and argv-exposure defects. The live deployed wrapper was atomically restored to baseline SHA-256 `08a65e8584c52c6d41ea1c686f8b95585c21e4b37320a2447eba09359a0e02c1`; the remediated candidate remains only in the worktree.
|
|
||||||
|
|
||||||
## Remediation and current review state
|
|
||||||
|
|
||||||
1. Token and Basic Auth now use stdin curl configuration, not argv. PR title, contributor email, and the JSON payload also remain out of child argv.
|
|
||||||
2. Each credential attempt binds commit inspection and merge. A token failure during either inspection or mutation causes Basic fallback to repeat inspection before mutation; the payload pins the inspected `head_commit_id`.
|
|
||||||
3. Focused tests cover token-resolution fail-closed behavior, both HTTP-401 fallback seams, metadata/credential argv absence, null-login BLOCK, explicit squash, canonical reviewed-head binding, unchanged ordinary payload, and retained log-safe provider diagnostics. Token-resolution RED: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-token-resolution-red.log`.
|
|
||||||
4. Codex review rounds 3–5 requested retained provider error text, log-safe provider diagnostics, fail-closed credential fallback, stable value-option parsing, and PR-title trailer-injection prevention. These are remediated with regression assertions. A post-remediation independent review is still required.
|
|
||||||
5. **Accepted linkage limitation:** `author.login` resolution proves that the commit address maps to a registered provider account. It does not prove that the named principal authored the commit because Git author metadata is self-asserted. This gate checks attribution linkage, not authorship; commit signing is out of scope and currently unadopted. Coordinators explicitly ruled that this does not add a third state.
|
|
||||||
6. Codex's sandbox could not execute the harness because its checkout was read-only; that environmental limitation is recorded separately from host-side test results.
|
|
||||||
|
|
||||||
## Disposable provider fixture acceptance
|
|
||||||
|
|
||||||
- Use a retained scratch repository only, with two branch authors and `author != committer` on at least one commit.
|
|
||||||
- Arm A supplies a message-field trailer for one non-poster; record whether that value lands without forcing the partial-pair result into under-specified `APPENDS`/`REPLACES` labels. Demonstrate an absence control.
|
|
||||||
- Arm B includes a registered trailer for a different non-poster on a branch commit; record whether it survives or drops. Verify identity through an existing commit whose `author.login` resolves and demonstrate an absence control.
|
|
||||||
- Parse landed trailers key-agnostically with `^[A-Za-z-]+-[Bb]y:` and record generated poster pair presence/absence plus resulting poster attribution.
|
|
||||||
- Record `/users/<login>` status and raw email only as non-gating estate telemetry. Never read `active`, `visibility`, or any profile field as an identity gate.
|
|
||||||
- Use distinct principals: poster `be-coder-08`, merger `Mos`, Arm A `be-coder-07`, and Arm B `be-coder-06`. Capture every trailer-shaped line verbatim and in order. Zero trailer lines means the generator did not fire and the run is `VOID`, not evidence that either arm dropped.
|
|
||||||
- Report the same read-back evidence to `mos-claude` on socket `default` and `tl-mosaic` on socket `mosaic-fleet`. Report values rather than mechanism inferences and stop on any poster-attribution regression.
|
|
||||||
|
|
||||||
## Fixture preflight
|
|
||||||
|
|
||||||
- Retained public repository: `mosaicstack/prmerge-trailer-fixture`; PR `#1`, posted by `be-coder-08` and reserved for merge by `Mos`.
|
|
||||||
- Existing `mosaicstack/stack` commits resolve `be-coder-07` and `be-coder-06` through `author.login`; exact addresses are `[email protected]` and `[email protected]`.
|
|
||||||
- Non-gating HOMELAB telemetry for authenticated reader `be-coder-08`: `/api/v1/users/be-coder-06` returned HTTP 200 with raw `email` value `[email protected]`.
|
|
||||||
- Provider preflight showed PR commit enumeration is newest-first. A new RED test proved that deriving `head_commit_id` from the final array element selected the wrong commit. The candidate now reads `.head.sha` from the authenticated PR endpoint before enumeration, verifies it appears in the commit set, and atomically pins that SHA in the explicit squash payload. RED: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-head-order-red.log`.
|
|
||||||
- Fixture PR head `f6ba6e5105031fa21f5ff7bd8e4379d99c16e1de` has `author.login=be-coder-07`, `committer.login=be-coder-08`, and branch-message trailer `Co-authored-by: be-coder-06 <[email protected]>`.
|
|
||||||
|
|
||||||
## Fixture result
|
|
||||||
|
|
||||||
- `Mos` merged retained fixture PR `#1` through staged candidate SHA-256 `60e779a85fd13b729d859ea7c986d1e9b1641b97991611329226c1b3113ffb6e`; resulting squash commit: `3f550715d9bc716426fd355a65fe997b3a90fa7d` with one parent.
|
|
||||||
- Provider read-back: poster/commit author `be-coder-08`, committer/merger `Mos`. The run is non-void.
|
|
||||||
- Trailer-shaped lines, verbatim and in order:
|
|
||||||
1. `Co-authored-by: be-coder-07 <[email protected]>`
|
|
||||||
2. `Co-authored-by: be-coder-08 <[email protected]>`
|
|
||||||
- Arm A supplied field value (`be-coder-07`) landed. Arm B branch trailer (`be-coder-06`) dropped. Both fabricated absence controls remained absent. No `Co-committed-by:` line landed.
|
|
||||||
- The candidate payload construction explicitly excludes the poster and supplied only the Arm A `be-coder-07` line. Therefore the landed poster line was provider-generated, not candidate-composed. The raw result supports `FIELD LANDS`, `BRANCH DROPS`, and `POSTER GENERATED`; it does not support a claim that candidate code supplied the poster. Evidence: `/home/hermes/agent-work/be-coder-08/evidence/prmerge-fixture-readback.log` and the retained provider object.
|
|
||||||
- Retained fixture PR `#2` measured the N=2 shape needed by `#1030`: supplied `be-coder-07` then `be-coder-06`; both landed in that order, followed by the provider-generated poster line. No truncation or dedup occurred at N=2. Resulting squash: `39db9d13aed0…`.
|
|
||||||
|
|
||||||
## Current hold point
|
|
||||||
|
|
||||||
PR `mosaicstack/stack#1066` is open. Its first frozen head `f4b162fa…` was terminal-green in Woodpecker `mosaic` pipeline `#2225`, but that evidence becomes stale when the canonical port moves the head. The deployed wrapper remains baseline `08a65e85…`; no manual copy will occur. Canonical port tests, commit amendment, rebase, one guarded force-with-lease, exact-head CI, and new independent review remain. Even after source merge, activation remains blocked on an assigned package-release/reseed owner and installed-byte read-back.
|
|
||||||
|
|
||||||
## Security review 96 remediation
|
|
||||||
|
|
||||||
Exact reviewed predecessor head: `1ceb11058f64dd7f4a817ceb2124f980a1c4dd23`.
|
|
||||||
|
|
||||||
RED-first focused harness produced 10 named failures: all curl calls lacked size/time/connect bounds; raw ESC email reached mutation; oversized and stalled curl failures were discarded and reached mutation; nonempty Basic output with resolver rc 91 authorized mutation.
|
|
||||||
|
|
||||||
Security remediation:
|
|
||||||
|
|
||||||
- Removed the cross-principal HTTP-401 Basic fallback. Both inspection-401 and merge-401 paths now refuse without Basic resolution or mutation; `get_gitea_basic_auth` references in the merge subject are 0.
|
|
||||||
- Applied `--max-filesize`, `--max-time`, and `--connect-timeout` to all 3/3 provider curl sites and fail closed on curl transport rc at all 3/3 sites.
|
|
||||||
- Required linked email bytes to be ASCII and printable before constructing `MergeMessageField`; guarded construction sites 1/1.
|
|
||||||
|
|
||||||
GREEN: message-field, exact-head, empty-UID/API, queue branch/repository/SHA, bash syntax, ShellCheck, and diff check pass. R7 total-removal mutants went RED: email guard 3 rows; bound switches 1 row; transport-rc guards 4 rows; HTTP-401 refusal 3 rows. R7 bound: mutants prove total removal only; explicit denominators above prove site coverage.
|
|
||||||
+2
-1
@@ -10,7 +10,8 @@
|
|||||||
"clean:generated": "node scripts/clean-generated.mjs",
|
"clean:generated": "node scripts/clean-generated.mjs",
|
||||||
"typecheck": "pnpm preflight && turbo run typecheck",
|
"typecheck": "pnpm preflight && turbo run typecheck",
|
||||||
"test:checkout": "node --test scripts/*.test.mjs",
|
"test:checkout": "node --test scripts/*.test.mjs",
|
||||||
"test": "pnpm test:checkout && turbo run test",
|
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
|
||||||
|
"test:installer": "bash tools/install-state-machine.test.sh && bash tools/install-next-lane.test.sh && bash tools/verify-greenfield-expected-red.test.sh",
|
||||||
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
||||||
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
||||||
"prepare": "node scripts/install-hooks.mjs"
|
"prepare": "node scripts/install-hooks.mjs"
|
||||||
|
|||||||
@@ -13,8 +13,7 @@ Pi is the native Mosaic agent runtime. The `mosaic pi` launcher:
|
|||||||
|
|
||||||
1. Injects the full runtime contract via `--append-system-prompt`
|
1. Injects the full runtime contract via `--append-system-prompt`
|
||||||
2. Loads Mosaic skills via `--skill` flags
|
2. Loads Mosaic skills via `--skill` flags
|
||||||
3. Loads framework-owned `mosaic-extension.ts` and `goal-extension.ts` from
|
3. Loads the Mosaic extension via `--extension` for lifecycle hooks
|
||||||
`~/.config/mosaic/runtime/pi/` via ordered `--extension` flags
|
|
||||||
4. Detects active missions and injects initial prompts
|
4. Detects active missions and injects initial prompts
|
||||||
|
|
||||||
## Capabilities vs Other Runtimes
|
## Capabilities vs Other Runtimes
|
||||||
@@ -23,7 +22,6 @@ Pi is the native Mosaic agent runtime. The `mosaic pi` launcher:
|
|||||||
- Native thinking levels replace sequential-thinking MCP
|
- Native thinking levels replace sequential-thinking MCP
|
||||||
- Native skill discovery compatible with Mosaic SKILL.md format
|
- Native skill discovery compatible with Mosaic SKILL.md format
|
||||||
- Native extension system for lifecycle hooks (TypeScript, not bash shims)
|
- Native extension system for lifecycle hooks (TypeScript, not bash shims)
|
||||||
- Bounded persistent `/goal` loop with per-turn, post-compaction, and two-pass evidence checks
|
|
||||||
- Native session persistence and resume
|
- Native session persistence and resume
|
||||||
- Model-agnostic (Anthropic, OpenAI, Google, Ollama, custom providers)
|
- Model-agnostic (Anthropic, OpenAI, Google, Ollama, custom providers)
|
||||||
|
|
||||||
|
|||||||
@@ -94,14 +94,7 @@ The launcher:
|
|||||||
1. Verifies `~/.config/mosaic` exists
|
1. Verifies `~/.config/mosaic` exists
|
||||||
2. Verifies `SOUL.md` exists (auto-runs `mosaic init` if missing)
|
2. Verifies `SOUL.md` exists (auto-runs `mosaic init` if missing)
|
||||||
3. Injects `AGENTS.md` into the runtime
|
3. Injects `AGENTS.md` into the runtime
|
||||||
4. For Pi, loads the framework-owned core and persistent-goal extensions from
|
4. Forwards all arguments to the runtime CLI
|
||||||
`~/.config/mosaic/runtime/pi/`
|
|
||||||
5. Forwards all arguments to the runtime CLI
|
|
||||||
|
|
||||||
Inside `mosaic pi`, `/goal set <statement>` starts a bounded persistent goal loop. Use `/goal status`,
|
|
||||||
`/goal pause`, `/goal resume`, or `/goal cancel` to control it. The extension remains part of Mosaic
|
|
||||||
under `~/.config/mosaic/runtime/pi/goal-extension.ts`; it is not installed in Pi's main extension
|
|
||||||
directory.
|
|
||||||
|
|
||||||
You can still launch runtimes directly (`claude`, `codex`, etc.) — thin runtime adapters will tell the agent to read `~/.config/mosaic/AGENTS.md`.
|
You can still launch runtimes directly (`claude`, `codex`, etc.) — thin runtime adapters will tell the agent to read `~/.config/mosaic/AGENTS.md`.
|
||||||
|
|
||||||
@@ -121,7 +114,7 @@ You can still launch runtimes directly (`claude`, `codex`, etc.) — thin runtim
|
|||||||
│ ├── claude/ ← CLAUDE.md, RUNTIME.md, settings.json, hooks
|
│ ├── claude/ ← CLAUDE.md, RUNTIME.md, settings.json, hooks
|
||||||
│ ├── codex/ ← instructions.md, RUNTIME.md
|
│ ├── codex/ ← instructions.md, RUNTIME.md
|
||||||
│ ├── opencode/ ← AGENTS.md, RUNTIME.md
|
│ ├── opencode/ ← AGENTS.md, RUNTIME.md
|
||||||
│ ├── pi/ ← RUNTIME.md, mosaic-extension.ts, goal-extension.ts
|
│ ├── pi/ ← RUNTIME.md, mosaic-extension.ts
|
||||||
│ └── mcp/ ← MCP server configs
|
│ └── mcp/ ← MCP server configs
|
||||||
├── skills/ ← Universal skills (synced from mosaic/agent-skills)
|
├── skills/ ← Universal skills (synced from mosaic/agent-skills)
|
||||||
├── skills-local/ ← Local cross-runtime skills
|
├── skills-local/ ← Local cross-runtime skills
|
||||||
@@ -133,7 +126,7 @@ You can still launch runtimes directly (`claude`, `codex`, etc.) — thin runtim
|
|||||||
|
|
||||||
| Launch method | Injection mechanism |
|
| Launch method | Injection mechanism |
|
||||||
| ------------------- | ----------------------------------------------------------------------------------------- |
|
| ------------------- | ----------------------------------------------------------------------------------------- |
|
||||||
| `mosaic pi` | `--append-system-prompt` with composed runtime contract + skills + Mosaic extensions |
|
| `mosaic pi` | `--append-system-prompt` with composed runtime contract + skills + extension |
|
||||||
| `mosaic claude` | `--append-system-prompt` with composed runtime contract (`AGENTS.md` + runtime reference) |
|
| `mosaic claude` | `--append-system-prompt` with composed runtime contract (`AGENTS.md` + runtime reference) |
|
||||||
| `mosaic codex` | Writes composed runtime contract to `~/.codex/instructions.md` before launch |
|
| `mosaic codex` | Writes composed runtime contract to `~/.codex/instructions.md` before launch |
|
||||||
| `mosaic opencode` | Writes composed runtime contract to `~/.config/opencode/AGENTS.md` before launch |
|
| `mosaic opencode` | Writes composed runtime contract to `~/.config/opencode/AGENTS.md` before launch |
|
||||||
|
|||||||
@@ -58,6 +58,7 @@ done
|
|||||||
# packages/mosaic/src/framework/manifest.ts — both consume framework-manifest.txt.
|
# packages/mosaic/src/framework/manifest.ts — both consume framework-manifest.txt.
|
||||||
# Sourcing does not run its CLI dispatch (guarded by BASH_SOURCE==$0).
|
# Sourcing does not run its CLI dispatch (guarded by BASH_SOURCE==$0).
|
||||||
# shellcheck source=tools/_lib/manifest.sh
|
# shellcheck source=tools/_lib/manifest.sh
|
||||||
|
# shellcheck disable=SC1091 # Dynamic SOURCE_DIR; the path is validated by set -e.
|
||||||
source "$SOURCE_DIR/tools/_lib/manifest.sh"
|
source "$SOURCE_DIR/tools/_lib/manifest.sh"
|
||||||
|
|
||||||
# Which paths a keep-mode upgrade may touch is no longer a hand-maintained
|
# Which paths a keep-mode upgrade may touch is no longer a hand-maintained
|
||||||
@@ -222,12 +223,14 @@ prune_durable_snapshots() {
|
|||||||
[[ "$keep" =~ ^[0-9]+$ ]] && (( keep >= 1 )) || keep=5
|
[[ "$keep" =~ ^[0-9]+$ ]] && (( keep >= 1 )) || keep=5
|
||||||
list="$(mktemp)"
|
list="$(mktemp)"
|
||||||
if ! find "$root" -maxdepth 1 -type d -name 'pre-update-*' > "$list"; then
|
if ! find "$root" -maxdepth 1 -type d -name 'pre-update-*' > "$list"; then
|
||||||
|
warn "Backup pruning skipped; policy: retention cleanup is optional and a failed enumeration must preserve every existing recovery snapshot."
|
||||||
rm -f "$list"; return 0
|
rm -f "$list"; return 0
|
||||||
fi
|
fi
|
||||||
# Newest-first ordering needs `sort` (`-o` writes back in place — no `mv`
|
# Newest-first ordering needs `sort` (`-o` writes back in place — no `mv`
|
||||||
# dependency); if it is somehow unavailable, leave the backups untouched rather
|
# dependency); if it is somehow unavailable, leave the backups untouched rather
|
||||||
# than risk pruning in an undefined order.
|
# than risk pruning in an undefined order.
|
||||||
if ! LC_ALL=C sort -r -o "$list" "$list" 2>/dev/null; then
|
if ! LC_ALL=C sort -r -o "$list" "$list" 2>/dev/null; then
|
||||||
|
warn "Backup pruning skipped; policy: ordering failure preserves all snapshots rather than risking deletion in an undefined order."
|
||||||
rm -f "$list"; return 0
|
rm -f "$list"; return 0
|
||||||
fi
|
fi
|
||||||
while IFS= read -r d; do
|
while IFS= read -r d; do
|
||||||
@@ -266,7 +269,11 @@ make_durable_snapshot() {
|
|||||||
warn "Durable snapshot skipped: cannot create backup dir $root (upgrade continues; operator files remain manifest-protected)."
|
warn "Durable snapshot skipped: cannot create backup dir $root (upgrade continues; operator files remain manifest-protected)."
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
chmod 700 "$root" 2>/dev/null || true
|
if ! chmod 700 "$root"; then
|
||||||
|
umask "$old_umask"
|
||||||
|
warn "Durable snapshot skipped: backup root permissions could not be made private; policy: never write operator data to an insufficiently protected location."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
dir="$root/pre-update-$ts"
|
dir="$root/pre-update-$ts"
|
||||||
if [[ -e "$dir" ]]; then # same-second re-run: disambiguate
|
if [[ -e "$dir" ]]; then # same-second re-run: disambiguate
|
||||||
local n=1; while [[ -e "$dir-$n" ]]; do n=$((n + 1)); done; dir="$dir-$n"
|
local n=1; while [[ -e "$dir-$n" ]]; do n=$((n + 1)); done; dir="$dir-$n"
|
||||||
@@ -281,7 +288,10 @@ make_durable_snapshot() {
|
|||||||
if ! enumerate_operator_files "$list"; then
|
if ! enumerate_operator_files "$list"; then
|
||||||
umask "$old_umask"
|
umask "$old_umask"
|
||||||
warn "Durable snapshot skipped: could not enumerate operator files (upgrade continues)."
|
warn "Durable snapshot skipped: could not enumerate operator files (upgrade continues)."
|
||||||
rm -f "$list"; rmdir "$dir" 2>/dev/null || true
|
rm -f "$list"
|
||||||
|
if ! rmdir "$dir"; then
|
||||||
|
warn "Durable snapshot cleanup left $dir in place; policy: preserve unexpected content rather than deleting it recursively."
|
||||||
|
fi
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
while IFS= read -r -d '' rel; do
|
while IFS= read -r -d '' rel; do
|
||||||
@@ -292,12 +302,18 @@ make_durable_snapshot() {
|
|||||||
warn "Durable snapshot: could not copy operator file '$rel' (skipped)."
|
warn "Durable snapshot: could not copy operator file '$rel' (skipped)."
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
chmod 600 "$dst" 2>/dev/null || true
|
if ! chmod 600 "$dst"; then
|
||||||
|
rm -f "$dst"
|
||||||
|
warn "Durable snapshot: copied '$rel' could not be made private and was removed; policy: do not retain an insecure recovery copy."
|
||||||
|
continue
|
||||||
|
fi
|
||||||
count=$((count + 1))
|
count=$((count + 1))
|
||||||
done < "$list"
|
done < "$list"
|
||||||
rm -f "$list"
|
rm -f "$list"
|
||||||
# Tighten every dir the copy created (mkdir -p honors umask, but be explicit).
|
# Tighten every dir the copy created (mkdir -p already honored umask 077).
|
||||||
find "$dir" -type d -exec chmod 700 {} + 2>/dev/null || true
|
if ! find "$dir" -type d -exec chmod 700 {} +; then
|
||||||
|
warn "Durable snapshot directory permission recheck failed; policy: continue because every directory was created under umask 077, while retaining the diagnostic."
|
||||||
|
fi
|
||||||
umask "$old_umask" # UMASK-RESTORE-NORMAL — restore before the upgrade proper resumes (see above)
|
umask "$old_umask" # UMASK-RESTORE-NORMAL — restore before the upgrade proper resumes (see above)
|
||||||
DURABLE_SNAPSHOT_DIR="$dir"
|
DURABLE_SNAPSHOT_DIR="$dir"
|
||||||
ok "Durable pre-update snapshot: $count operator file(s) saved to $dir (recover with: mosaic restore --list)"
|
ok "Durable pre-update snapshot: $count operator file(s) saved to $dir (recover with: mosaic restore --list)"
|
||||||
@@ -344,7 +360,9 @@ verify_operator_surface() {
|
|||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
if cp "$snap" "$cur"; then
|
if cp "$snap" "$cur"; then
|
||||||
chmod 600 "$cur" 2>/dev/null || true
|
if ! chmod 600 "$cur"; then
|
||||||
|
warn "Operator file '$rel' was restored but its mode could not be tightened to 0600; policy: preserve recovered content and require manual permission repair."
|
||||||
|
fi
|
||||||
warn "Operator file was modified by the upgrade and has been restored from the pre-update snapshot: $rel"
|
warn "Operator file was modified by the upgrade and has been restored from the pre-update snapshot: $rel"
|
||||||
healed=$((healed + 1))
|
healed=$((healed + 1))
|
||||||
else
|
else
|
||||||
@@ -535,7 +553,7 @@ sync_framework_keep() {
|
|||||||
# (unreadable dir) is surfaced as a warning rather than silently swallowed;
|
# (unreadable dir) is surfaced as a warning rather than silently swallowed;
|
||||||
# the "directory not empty" races we tolerate are ignored via -delete's own
|
# the "directory not empty" races we tolerate are ignored via -delete's own
|
||||||
# rc, not by hiding stderr — so a real error is still visible to the operator.
|
# rc, not by hiding stderr — so a real error is still visible to the operator.
|
||||||
if ! find "$dst/$root" -type d -empty -delete 2>/dev/null; then
|
if ! find "$dst/$root" -type d -empty -delete; then
|
||||||
warn "prune: could not fully sweep empty framework dirs under $root (left as-is)"
|
warn "prune: could not fully sweep empty framework dirs under $root (left as-is)"
|
||||||
fi
|
fi
|
||||||
done < <(manifest_subtree_roots)
|
done < <(manifest_subtree_roots)
|
||||||
@@ -581,7 +599,7 @@ run_migrations() {
|
|||||||
MIGRATION_REMOVED_PATHS+=("bin" "rails")
|
MIGRATION_REMOVED_PATHS+=("bin" "rails")
|
||||||
if [[ -d "$TARGET_DIR/bin" ]]; then
|
if [[ -d "$TARGET_DIR/bin" ]]; then
|
||||||
ok "Removing legacy bin/ directory (executables now in npm CLI)"
|
ok "Removing legacy bin/ directory (executables now in npm CLI)"
|
||||||
rm -rf "$TARGET_DIR/bin"
|
rm -rf "${TARGET_DIR:?}/bin"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Remove old mosaic PATH entry from shell profiles
|
# Remove old mosaic PATH entry from shell profiles
|
||||||
@@ -706,13 +724,23 @@ mkdir -p "$TARGET_DIR/credentials"
|
|||||||
# by `mosaic init` from templates with user-supplied values.
|
# by `mosaic init` from templates with user-supplied values.
|
||||||
reconcile_framework_files
|
reconcile_framework_files
|
||||||
|
|
||||||
# Ensure tool scripts are executable
|
# Ensure tool scripts are executable. These are P4 postconditions, not
|
||||||
find "$TARGET_DIR/tools" -name "*.sh" -exec chmod +x {} + 2>/dev/null || true
|
# best-effort cleanup: a chmod failure leaves shipped tools unloadable.
|
||||||
find "$TARGET_DIR/tools/_scripts" -type f -exec chmod +x {} + 2>/dev/null || true
|
if ! find "$TARGET_DIR/tools" -name "*.sh" -exec chmod +x {} +; then
|
||||||
|
fail "Could not mark shipped shell tools executable."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if ! find "$TARGET_DIR/tools/_scripts" -type f -exec chmod +x {} +; then
|
||||||
|
fail "Could not mark shipped runtime scripts executable."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
# git-credential-mosaic (per-agent Gitea identity helper) ships without a .sh
|
# git-credential-mosaic (per-agent Gitea identity helper) ships without a .sh
|
||||||
# suffix — git resolves credential helpers by exact name/path, not extension —
|
# suffix — git resolves credential helpers by exact name/path, not extension.
|
||||||
# so the *.sh glob above does not cover it; chmod it explicitly.
|
if [[ -f "$TARGET_DIR/tools/git/git-credential-mosaic" ]] \
|
||||||
[[ -f "$TARGET_DIR/tools/git/git-credential-mosaic" ]] && chmod +x "$TARGET_DIR/tools/git/git-credential-mosaic" 2>/dev/null || true
|
&& ! chmod +x "$TARGET_DIR/tools/git/git-credential-mosaic"; then
|
||||||
|
fail "Could not mark git-credential-mosaic executable."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
ok "Framework synced to $TARGET_DIR"
|
ok "Framework synced to $TARGET_DIR"
|
||||||
|
|
||||||
@@ -739,49 +767,110 @@ step "Post-install tasks"
|
|||||||
|
|
||||||
SCRIPTS="$TARGET_DIR/tools/_scripts"
|
SCRIPTS="$TARGET_DIR/tools/_scripts"
|
||||||
|
|
||||||
|
# Capture every fallible post-install command. A failure's text is surfaced and
|
||||||
|
# also appended to the parent transaction's private command log. Failure to
|
||||||
|
# write that log is fatal: continuing would recreate the false-clean diagnosis
|
||||||
|
# INV-C forbids.
|
||||||
|
record_phase_outcome() {
|
||||||
|
local phase="$1" status="$2" reason="$3"
|
||||||
|
[[ -n "${MOSAIC_INSTALL_PHASE_STATUS_FILE:-}" ]] || return 0
|
||||||
|
if ! printf '%s\t%s\t%s\n' "$phase" "$status" "$reason" >> "$MOSAIC_INSTALL_PHASE_STATUS_FILE" \
|
||||||
|
|| ! sync "$MOSAIC_INSTALL_PHASE_STATUS_FILE"; then
|
||||||
|
fail "Could not durably record $phase action outcome for the parent transaction."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
run_captured() {
|
||||||
|
local label="$1" output status=0
|
||||||
|
shift
|
||||||
|
output="$(mktemp "${TMPDIR:-/tmp}/mosaic-post-install.XXXXXX.log")"
|
||||||
|
if "$@" >"$output" 2>&1; then status=0; else status=$?; fi
|
||||||
|
if [[ -n "${MOSAIC_INSTALL_COMMAND_LOG:-}" ]]; then
|
||||||
|
if ! { printf '\n=== %s (exit=%s) ===\n' "$label" "$status"; cat "$output"; } >> "$MOSAIC_INSTALL_COMMAND_LOG" \
|
||||||
|
|| ! sync "$MOSAIC_INSTALL_COMMAND_LOG"; then
|
||||||
|
cat "$output" >&2
|
||||||
|
rm -f "$output"
|
||||||
|
fail "Could not durably append '$label' diagnostics to the install command log."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
if [[ "$status" -ne 0 ]]; then cat "$output" >&2; fi
|
||||||
|
rm -f "$output"
|
||||||
|
return "$status"
|
||||||
|
}
|
||||||
|
|
||||||
if [[ -x "$SCRIPTS/mosaic-link-runtime-assets" ]]; then
|
if [[ -x "$SCRIPTS/mosaic-link-runtime-assets" ]]; then
|
||||||
link_args=()
|
link_args=()
|
||||||
[[ "$ALLOW_INACTIVE_ENFORCEMENT" == "1" ]] && link_args+=(--allow-inactive-enforcement)
|
[[ "$ALLOW_INACTIVE_ENFORCEMENT" == "1" ]] && link_args+=(--allow-inactive-enforcement)
|
||||||
# stdout is suppressed as before, but stderr is left connected: the
|
if run_captured "runtime asset linking" "$SCRIPTS/mosaic-link-runtime-assets" "${link_args[@]}"; then
|
||||||
# install-ordering guard's FAIL LOUD message (#869 Point-1 C2) must reach
|
record_phase_outcome P6 committed "runtime asset linker exited zero"
|
||||||
# the operator, not be swallowed silently.
|
|
||||||
if "$SCRIPTS/mosaic-link-runtime-assets" "${link_args[@]}" >/dev/null; then
|
|
||||||
ok "Runtime assets linked"
|
ok "Runtime assets linked"
|
||||||
else
|
else
|
||||||
warn "Runtime asset linking failed (non-fatal) — see message above for details."
|
record_phase_outcome P6 failed "runtime asset linker exited non-zero"
|
||||||
|
warn "Runtime asset linking did not commit; policy: continue only to enumerate all phase diagnostics, while P6/P9 remain blocking."
|
||||||
fi
|
fi
|
||||||
|
else
|
||||||
|
record_phase_outcome P6 failed "required runtime asset linker is missing or not executable"
|
||||||
|
warn "Runtime asset linking was not attempted; policy: a missing required linker remains a blocking P6/P9 failure."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -x "$SCRIPTS/mosaic-ensure-sequential-thinking" ]]; then
|
if [[ -x "$SCRIPTS/mosaic-ensure-sequential-thinking" ]]; then
|
||||||
if "$SCRIPTS/mosaic-ensure-sequential-thinking" >/dev/null 2>&1; then
|
if run_captured "sequential-thinking setup" "$SCRIPTS/mosaic-ensure-sequential-thinking"; then
|
||||||
ok "sequential-thinking MCP configured"
|
ok "sequential-thinking MCP configured"
|
||||||
|
elif [[ "${MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING:-0}" == "1" ]]; then
|
||||||
|
record_phase_outcome P6 failed "sequential-thinking setup failed under diagnostic-continuation compatibility mode"
|
||||||
|
warn "sequential-thinking setup did not commit; policy: the unified installer compatibility flag allows diagnostic continuation, while P6/P9 remain blocking."
|
||||||
else
|
else
|
||||||
if [[ "${MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING:-0}" == "1" ]]; then
|
fail "sequential-thinking MCP setup failed (hard requirement)."
|
||||||
warn "sequential-thinking MCP setup bypassed (MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING=1)"
|
exit 1
|
||||||
else
|
|
||||||
fail "sequential-thinking MCP setup failed (hard requirement)."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -x "$SCRIPTS/mosaic-ensure-excalidraw" ]]; then
|
if [[ -x "$SCRIPTS/mosaic-ensure-excalidraw" ]]; then
|
||||||
"$SCRIPTS/mosaic-ensure-excalidraw" >/dev/null 2>&1 && ok "excalidraw MCP configured" || warn "excalidraw MCP setup failed (non-fatal)"
|
if run_captured "excalidraw setup" "$SCRIPTS/mosaic-ensure-excalidraw"; then
|
||||||
|
ok "excalidraw MCP configured"
|
||||||
|
else
|
||||||
|
warn "excalidraw setup did not commit; policy: optional integration failure is retained in the journal and does not define core install readiness."
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "${MOSAIC_SKIP_SKILLS_SYNC:-0}" != "1" ]] && [[ -x "$SCRIPTS/mosaic-sync-skills" ]]; then
|
if [[ "${MOSAIC_SKIP_SKILLS_SYNC:-0}" == "1" ]]; then
|
||||||
"$SCRIPTS/mosaic-sync-skills" >/dev/null 2>&1 && ok "Skills synced" || warn "Skills sync failed (non-fatal)"
|
record_phase_outcome P4 failed "required skills sync explicitly skipped"
|
||||||
|
warn "Skills sync was skipped; policy: diagnostic continuation is allowed, but P4/P9 cannot certify an incomplete requested framework install."
|
||||||
|
elif [[ -x "$SCRIPTS/mosaic-sync-skills" ]]; then
|
||||||
|
if run_captured "skills sync" "$SCRIPTS/mosaic-sync-skills"; then
|
||||||
|
record_phase_outcome P4 committed "skills sync exited zero"
|
||||||
|
ok "Skills synced"
|
||||||
|
else
|
||||||
|
record_phase_outcome P4 failed "skills sync exited non-zero"
|
||||||
|
warn "Skills sync did not commit; policy: continue to collect P4 diagnostics, but P4/P9 must not certify the install."
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
record_phase_outcome P4 failed "required skills sync command is missing or not executable"
|
||||||
|
warn "Skills sync was not attempted; policy: a missing required sync command remains a blocking P4/P9 failure."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -x "$SCRIPTS/mosaic-migrate-local-skills" ]]; then
|
if [[ -x "$SCRIPTS/mosaic-migrate-local-skills" ]]; then
|
||||||
"$SCRIPTS/mosaic-migrate-local-skills" --apply >/dev/null 2>&1 && ok "Local skills migrated" || warn "Local skill migration failed (non-fatal)"
|
if run_captured "local skills migration" "$SCRIPTS/mosaic-migrate-local-skills" --apply; then
|
||||||
|
ok "Local skills migrated"
|
||||||
|
else
|
||||||
|
record_phase_outcome P4 failed "local skills migration exited non-zero"
|
||||||
|
warn "Local skill migration did not commit; policy: preserve user content and continue diagnostics, while P4/P9 remain blocking."
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -x "$SCRIPTS/mosaic-doctor" ]]; then
|
if [[ -x "$SCRIPTS/mosaic-doctor" ]]; then
|
||||||
"$SCRIPTS/mosaic-doctor" >/dev/null 2>&1 && ok "Health audit passed" || warn "Health audit reported issues — run 'mosaic doctor' for details"
|
if run_captured "health audit" "$SCRIPTS/mosaic-doctor"; then
|
||||||
|
ok "Health audit passed"
|
||||||
|
else
|
||||||
|
warn "Health audit found unresolved state; policy: preserve its diagnostics and let P9 issue the authoritative failure."
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Write version stamp AFTER everything succeeds
|
# The version stamp records the successfully committed framework file sync.
|
||||||
|
# Post-install failures are carried separately into P4/P6 and cannot be erased
|
||||||
|
# by this stamp.
|
||||||
write_framework_version
|
write_framework_version
|
||||||
|
|
||||||
# ── Summary ──────────────────────────────────────────────────
|
# ── Summary ──────────────────────────────────────────────────
|
||||||
|
|||||||
@@ -51,26 +51,12 @@ Skills are discovered from:
|
|||||||
|
|
||||||
### Extensions
|
### Extensions
|
||||||
|
|
||||||
`mosaic pi` loads framework-owned extensions directly from `~/.config/mosaic/runtime/pi/` in this
|
The Mosaic Pi extension (`~/.config/mosaic/runtime/pi/mosaic-extension.ts`) handles:
|
||||||
order:
|
|
||||||
|
|
||||||
1. `mosaic-extension.ts` — session lifecycle, mission context, memory routing, lease/mutator gates,
|
- Session start/end lifecycle hooks
|
||||||
and fleet heartbeat reporting.
|
- Active mission detection and context injection
|
||||||
2. `goal-extension.ts` — optional persistent `/goal` controller with per-turn and post-compaction
|
- Memory routing to `~/.config/mosaic/memory/`
|
||||||
checks.
|
- MACP queue status reporting
|
||||||
|
|
||||||
The goal extension is deployed by Mosaic and MUST NOT be copied into `~/.pi/agent/extensions/`.
|
|
||||||
Use `/goal set <statement>` (or `/goal <statement>`) to start, then `/goal status`, `/goal pause`,
|
|
||||||
`/goal resume`, or `/goal cancel` to control it. An active goal is injected before every model
|
|
||||||
request, restored from branch-specific session entries, and considered achieved only after two
|
|
||||||
consecutive evidence-bearing reports. Common credential shapes are redacted before controller-owned
|
|
||||||
goal-state entries are persisted or
|
|
||||||
displayed; Pi's own model/tool-call history is separate. Goals and reports must contain references
|
|
||||||
and pass/fail summaries rather than secrets or raw sensitive output.
|
|
||||||
|
|
||||||
- `MOSAIC_GOAL_MAX_TURNS` — autonomous turn limit, default `40`, accepted range `1..500`.
|
|
||||||
- `MOSAIC_GOAL_MAX_NO_PROGRESS` — identical no-progress report limit, default `6`, accepted range
|
|
||||||
`1..100`.
|
|
||||||
|
|
||||||
### Sessions
|
### Sessions
|
||||||
|
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -66,10 +66,7 @@ if command -v tmux >/dev/null 2>&1 && command -v cc >/dev/null 2>&1; then
|
|||||||
trap 'tmux -L "$TEST_SOCKET" kill-server >/dev/null 2>&1 || true; rm -rf "$TEST_ROOT"' EXIT
|
trap 'tmux -L "$TEST_SOCKET" kill-server >/dev/null 2>&1 || true; rm -rf "$TEST_ROOT"' EXIT
|
||||||
MARKER="$TEST_ROOT/loader-marker"
|
MARKER="$TEST_ROOT/loader-marker"
|
||||||
LIBRARY="$TEST_ROOT/marker.so"
|
LIBRARY="$TEST_ROOT/marker.so"
|
||||||
FIXTURE_READY="$TEST_ROOT/loader-ready"
|
|
||||||
FIXTURE_FIFO="$TEST_ROOT/loader-block"
|
|
||||||
HOLDER_HOME="$TEST_ROOT/holder-home"
|
HOLDER_HOME="$TEST_ROOT/holder-home"
|
||||||
mkfifo "$FIXTURE_FIFO"
|
|
||||||
mkdir -p "$HOLDER_HOME/.config/mosaic/fleet/run"
|
mkdir -p "$HOLDER_HOME/.config/mosaic/fleet/run"
|
||||||
chmod 700 "$HOLDER_HOME/.config" "$HOLDER_HOME/.config/mosaic" \
|
chmod 700 "$HOLDER_HOME/.config" "$HOLDER_HOME/.config/mosaic" \
|
||||||
"$HOLDER_HOME/.config/mosaic/fleet" "$HOLDER_HOME/.config/mosaic/fleet/run"
|
"$HOLDER_HOME/.config/mosaic/fleet" "$HOLDER_HOME/.config/mosaic/fleet/run"
|
||||||
@@ -90,17 +87,7 @@ __attribute__((constructor)) static void mark_loader(void) {
|
|||||||
EOF
|
EOF
|
||||||
cc -shared -fPIC -o "$LIBRARY" "$TEST_ROOT/marker.c"
|
cc -shared -fPIC -o "$LIBRARY" "$TEST_ROOT/marker.c"
|
||||||
MOSAIC_LOADER_MARKER="$MARKER" LD_PRELOAD="$LIBRARY" \
|
MOSAIC_LOADER_MARKER="$MARKER" LD_PRELOAD="$LIBRARY" \
|
||||||
tmux -L "$TEST_SOCKET" new-session -d -s _holder \
|
tmux -L "$TEST_SOCKET" new-session -d -s _holder 'sleep 60'
|
||||||
"touch '$FIXTURE_READY'; read _ < '$FIXTURE_FIFO'"
|
|
||||||
# tmux starts the pane asynchronously. Wait until its contaminated shell has
|
|
||||||
# loaded the constructor and reached a builtin-only FIFO barrier before
|
|
||||||
# clearing the marker; otherwise that expected constructor can race with the
|
|
||||||
# clean holder assertion below and create a false failure.
|
|
||||||
for _attempt in {1..100}; do
|
|
||||||
[ -e "$FIXTURE_READY" ] && break
|
|
||||||
sleep 0.01
|
|
||||||
done
|
|
||||||
[ -e "$FIXTURE_READY" ] || fail "contaminated fixture pane did not become ready"
|
|
||||||
[ -s "$MARKER" ] || fail "contaminated fixture did not execute loader constructor"
|
[ -s "$MARKER" ] || fail "contaminated fixture did not execute loader constructor"
|
||||||
server_pid=$(tmux -L "$TEST_SOCKET" display-message -p '#{pid}')
|
server_pid=$(tmux -L "$TEST_SOCKET" display-message -p '#{pid}')
|
||||||
: > "$MARKER"
|
: > "$MARKER"
|
||||||
@@ -125,7 +112,6 @@ EOF
|
|||||||
chmod 700 "$AGENT_HOME/fleet/agents"
|
chmod 700 "$AGENT_HOME/fleet/agents"
|
||||||
cat > "$AGENT_HOME/fleet/agents/$AGENT_NAME.env.generated" <<EOF
|
cat > "$AGENT_HOME/fleet/agents/$AGENT_NAME.env.generated" <<EOF
|
||||||
MOSAIC_AGENT_NAME=$AGENT_NAME
|
MOSAIC_AGENT_NAME=$AGENT_NAME
|
||||||
MOSAIC_GIT_IDENTITY=$AGENT_NAME
|
|
||||||
MOSAIC_AGENT_CLASS=code
|
MOSAIC_AGENT_CLASS=code
|
||||||
MOSAIC_AGENT_RUNTIME=pi
|
MOSAIC_AGENT_RUNTIME=pi
|
||||||
MOSAIC_AGENT_MODEL=
|
MOSAIC_AGENT_MODEL=
|
||||||
@@ -158,8 +144,7 @@ EOF
|
|||||||
/usr/bin/env -i HOME="$HOLDER_HOME" PATH=/usr/bin:/bin \
|
/usr/bin/env -i HOME="$HOLDER_HOME" PATH=/usr/bin:/bin \
|
||||||
MOSAIC_TMUX_SOCKET="$TEST_SOCKET" MOSAIC_TMUX_HOLDER=_holder "$HOLDER_START"
|
MOSAIC_TMUX_SOCKET="$TEST_SOCKET" MOSAIC_TMUX_HOLDER=_holder "$HOLDER_START"
|
||||||
tmux -L "$TEST_SOCKET" has-session -t '=_holder:0.0' || fail "fresh holder was not created"
|
tmux -L "$TEST_SOCKET" has-session -t '=_holder:0.0' || fail "fresh holder was not created"
|
||||||
ld_preload_env="$(tmux -L "$TEST_SOCKET" show-environment -g LD_PRELOAD 2>/dev/null)" || true
|
if tmux -L "$TEST_SOCKET" show-environment -g LD_PRELOAD 2>/dev/null | grep -q '^LD_PRELOAD='; then
|
||||||
if grep -q '^LD_PRELOAD=' <<<"$ld_preload_env"; then
|
|
||||||
fail "fresh holder retained LD_PRELOAD"
|
fail "fresh holder retained LD_PRELOAD"
|
||||||
fi
|
fi
|
||||||
/usr/bin/env -i HOME="$HOLDER_HOME" PATH=/usr/bin:/bin MOSAIC_HOME="$AGENT_HOME" \
|
/usr/bin/env -i HOME="$HOLDER_HOME" PATH=/usr/bin:/bin MOSAIC_HOME="$AGENT_HOME" \
|
||||||
|
|||||||
@@ -69,7 +69,7 @@ if [[ -n "$GROUP" ]]; then
|
|||||||
group_response=$(curl -sk \
|
group_response=$(curl -sk \
|
||||||
-H "Authorization: Bearer $TOKEN" \
|
-H "Authorization: Bearer $TOKEN" \
|
||||||
"${AUTHENTIK_URL}/api/v3/core/groups/?search=${GROUP}")
|
"${AUTHENTIK_URL}/api/v3/core/groups/?search=${GROUP}")
|
||||||
group_pk=$(jq -r "first(.results[] | select(.name == \"$GROUP\") | .pk) // empty" <<<"$group_response")
|
group_pk=$(echo "$group_response" | jq -r ".results[] | select(.name == \"$GROUP\") | .pk" | head -1)
|
||||||
if [[ -n "$group_pk" ]]; then
|
if [[ -n "$group_pk" ]]; then
|
||||||
payload=$(echo "$payload" | jq --arg gk "$group_pk" '. + {groups: [$gk]}')
|
payload=$(echo "$payload" | jq --arg gk "$group_pk" '. + {groups: [$gk]}')
|
||||||
else
|
else
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ is_sensitive_key() {
|
|||||||
|
|
||||||
is_generated_key() {
|
is_generated_key() {
|
||||||
case "$1" in
|
case "$1" in
|
||||||
MOSAIC_AGENT_NAME|MOSAIC_GIT_IDENTITY|MOSAIC_AGENT_CLASS|MOSAIC_AGENT_RUNTIME|MOSAIC_AGENT_MODEL|MOSAIC_AGENT_REASONING|MOSAIC_AGENT_TOOL_POLICY|MOSAIC_AGENT_WORKDIR|MOSAIC_TMUX_SOCKET) return 0 ;;
|
MOSAIC_AGENT_NAME|MOSAIC_AGENT_CLASS|MOSAIC_AGENT_RUNTIME|MOSAIC_AGENT_MODEL|MOSAIC_AGENT_REASONING|MOSAIC_AGENT_TOOL_POLICY|MOSAIC_AGENT_WORKDIR|MOSAIC_TMUX_SOCKET) return 0 ;;
|
||||||
*) return 1 ;;
|
*) return 1 ;;
|
||||||
esac
|
esac
|
||||||
}
|
}
|
||||||
@@ -114,7 +114,6 @@ validate_generated_value() {
|
|||||||
local value="$2"
|
local value="$2"
|
||||||
case "$key" in
|
case "$key" in
|
||||||
MOSAIC_AGENT_NAME) safe_agent_name "$value" || fail_env unsafe-agent-name "$key" "$value" ;;
|
MOSAIC_AGENT_NAME) safe_agent_name "$value" || fail_env unsafe-agent-name "$key" "$value" ;;
|
||||||
MOSAIC_GIT_IDENTITY) safe_agent_name "$value" || fail_env unsafe-git-identity "$key" "$value" ;;
|
|
||||||
MOSAIC_AGENT_CLASS) safe_policy_name "$value" || fail_env unsafe-class "$key" "$value" ;;
|
MOSAIC_AGENT_CLASS) safe_policy_name "$value" || fail_env unsafe-class "$key" "$value" ;;
|
||||||
MOSAIC_AGENT_RUNTIME)
|
MOSAIC_AGENT_RUNTIME)
|
||||||
case "$value" in claude|codex|opencode|pi) ;; *) fail_env unsupported-runtime "$key" "$value" ;; esac
|
case "$value" in claude|codex|opencode|pi) ;; *) fail_env unsupported-runtime "$key" "$value" ;; esac
|
||||||
@@ -176,7 +175,7 @@ load_environment_file() {
|
|||||||
|
|
||||||
load_environment_file "$GENERATED_ENV" generated
|
load_environment_file "$GENERATED_ENV" generated
|
||||||
for required_key in \
|
for required_key in \
|
||||||
MOSAIC_AGENT_NAME MOSAIC_GIT_IDENTITY MOSAIC_AGENT_CLASS MOSAIC_AGENT_RUNTIME MOSAIC_AGENT_MODEL \
|
MOSAIC_AGENT_NAME MOSAIC_AGENT_CLASS MOSAIC_AGENT_RUNTIME MOSAIC_AGENT_MODEL \
|
||||||
MOSAIC_AGENT_REASONING MOSAIC_AGENT_TOOL_POLICY MOSAIC_AGENT_WORKDIR MOSAIC_TMUX_SOCKET; do
|
MOSAIC_AGENT_REASONING MOSAIC_AGENT_TOOL_POLICY MOSAIC_AGENT_WORKDIR MOSAIC_TMUX_SOCKET; do
|
||||||
[ -n "${GENERATED_VALUES[$required_key]+set}" ] || fail_env missing-key "$required_key" ''
|
[ -n "${GENERATED_VALUES[$required_key]+set}" ] || fail_env missing-key "$required_key" ''
|
||||||
done
|
done
|
||||||
@@ -184,15 +183,12 @@ load_environment_file "$LOCAL_ENV" local
|
|||||||
|
|
||||||
[ "${GENERATED_VALUES[MOSAIC_AGENT_NAME]}" = "$AGENT_NAME" ] || \
|
[ "${GENERATED_VALUES[MOSAIC_AGENT_NAME]}" = "$AGENT_NAME" ] || \
|
||||||
fail_env agent-name-mismatch MOSAIC_AGENT_NAME "${GENERATED_VALUES[MOSAIC_AGENT_NAME]}"
|
fail_env agent-name-mismatch MOSAIC_AGENT_NAME "${GENERATED_VALUES[MOSAIC_AGENT_NAME]}"
|
||||||
[ "${GENERATED_VALUES[MOSAIC_GIT_IDENTITY]}" = "$AGENT_NAME" ] || \
|
|
||||||
fail_env git-identity-mismatch MOSAIC_GIT_IDENTITY "${GENERATED_VALUES[MOSAIC_GIT_IDENTITY]}"
|
|
||||||
|
|
||||||
MOSAIC_TMUX_SOCKET=${GENERATED_VALUES[MOSAIC_TMUX_SOCKET]}
|
MOSAIC_TMUX_SOCKET=${GENERATED_VALUES[MOSAIC_TMUX_SOCKET]}
|
||||||
MOSAIC_AGENT_RUNTIME=${GENERATED_VALUES[MOSAIC_AGENT_RUNTIME]}
|
MOSAIC_AGENT_RUNTIME=${GENERATED_VALUES[MOSAIC_AGENT_RUNTIME]}
|
||||||
MOSAIC_AGENT_MODEL=${GENERATED_VALUES[MOSAIC_AGENT_MODEL]}
|
MOSAIC_AGENT_MODEL=${GENERATED_VALUES[MOSAIC_AGENT_MODEL]}
|
||||||
MOSAIC_AGENT_REASONING=${GENERATED_VALUES[MOSAIC_AGENT_REASONING]}
|
MOSAIC_AGENT_REASONING=${GENERATED_VALUES[MOSAIC_AGENT_REASONING]}
|
||||||
MOSAIC_AGENT_WORKDIR=${GENERATED_VALUES[MOSAIC_AGENT_WORKDIR]}
|
MOSAIC_AGENT_WORKDIR=${GENERATED_VALUES[MOSAIC_AGENT_WORKDIR]}
|
||||||
MOSAIC_GIT_IDENTITY=${GENERATED_VALUES[MOSAIC_GIT_IDENTITY]}
|
|
||||||
MOSAIC_AGENT_CLASS=${GENERATED_VALUES[MOSAIC_AGENT_CLASS]}
|
MOSAIC_AGENT_CLASS=${GENERATED_VALUES[MOSAIC_AGENT_CLASS]}
|
||||||
MOSAIC_AGENT_TOOL_POLICY=${GENERATED_VALUES[MOSAIC_AGENT_TOOL_POLICY]}
|
MOSAIC_AGENT_TOOL_POLICY=${GENERATED_VALUES[MOSAIC_AGENT_TOOL_POLICY]}
|
||||||
MOSAIC_RUNTIME_BIN=${LOCAL_VALUES[MOSAIC_RUNTIME_BIN]:-}
|
MOSAIC_RUNTIME_BIN=${LOCAL_VALUES[MOSAIC_RUNTIME_BIN]:-}
|
||||||
@@ -347,7 +343,6 @@ LAUNCH_ENV=(
|
|||||||
"PATH=$PANE_PATH"
|
"PATH=$PANE_PATH"
|
||||||
"MOSAIC_HOME=$MOSAIC_HOME"
|
"MOSAIC_HOME=$MOSAIC_HOME"
|
||||||
"MOSAIC_AGENT_NAME=$AGENT_NAME"
|
"MOSAIC_AGENT_NAME=$AGENT_NAME"
|
||||||
"MOSAIC_GIT_IDENTITY=$MOSAIC_GIT_IDENTITY"
|
|
||||||
"MOSAIC_AGENT_CLASS=$MOSAIC_AGENT_CLASS"
|
"MOSAIC_AGENT_CLASS=$MOSAIC_AGENT_CLASS"
|
||||||
"MOSAIC_AGENT_RUNTIME=$MOSAIC_AGENT_RUNTIME"
|
"MOSAIC_AGENT_RUNTIME=$MOSAIC_AGENT_RUNTIME"
|
||||||
"MOSAIC_AGENT_MODEL=$MOSAIC_AGENT_MODEL"
|
"MOSAIC_AGENT_MODEL=$MOSAIC_AGENT_MODEL"
|
||||||
|
|||||||
@@ -14,82 +14,6 @@ fail() {
|
|||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|
||||||
pane_command_clears_environment() {
|
|
||||||
local calls_file="$1"
|
|
||||||
local -a argv=()
|
|
||||||
local index
|
|
||||||
mapfile -d '' -t argv < "$calls_file"
|
|
||||||
for ((index = 0; index + 1 < ${#argv[@]}; index++)); do
|
|
||||||
if [ "${argv[$index]}" = /usr/bin/env ] && [ "${argv[$((index + 1))]}" = -i ]; then
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
print_pane_argv() {
|
|
||||||
local calls_file="$1"
|
|
||||||
local -a argv=()
|
|
||||||
local bytes index
|
|
||||||
mapfile -d '' -t argv < "$calls_file"
|
|
||||||
bytes=$(wc -c < "$calls_file")
|
|
||||||
printf 'observed pane argv: records=%s bytes=%s\n' "${#argv[@]}" "$bytes" >&2
|
|
||||||
for ((index = 0; index < ${#argv[@]}; index++)); do
|
|
||||||
printf ' [%03d] %q\n' "$index" "${argv[$index]}" >&2
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
check_pane_environment_boundary() {
|
|
||||||
local calls_file="$1"
|
|
||||||
if pane_command_clears_environment "$calls_file"; then
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
print_pane_argv "$calls_file"
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
contains_literal() {
|
|
||||||
grep -F -- "$2" <<< "$1" >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
contains_line() {
|
|
||||||
grep -xF -- "$2" <<< "$1" >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
# Portability regression: inspect the authoritative NUL-delimited argv instead
|
|
||||||
# of piping a newline reconstruction through `grep -q` under pipefail. The old
|
|
||||||
# pipeline could report failure after a successful match when an upstream
|
|
||||||
# producer received SIGPIPE. A large trailing argument keeps that failure class
|
|
||||||
# covered without making stream size part of the semantic contract.
|
|
||||||
PORTABILITY_CALLS="$ROOT/portability-calls"
|
|
||||||
printf -v PORTABILITY_PADDING '%*s' 32768 ''
|
|
||||||
PORTABILITY_PADDING=${PORTABILITY_PADDING// /x}
|
|
||||||
printf '%s\0' /usr/bin/env -i "$PORTABILITY_PADDING" > "$PORTABILITY_CALLS"
|
|
||||||
pane_command_clears_environment "$PORTABILITY_CALLS" || \
|
|
||||||
fail "valid large pane argv was rejected by the environment-boundary assertion"
|
|
||||||
|
|
||||||
assert_pane_boundary_rejected() {
|
|
||||||
local case_name="$1"
|
|
||||||
local expected_records="$2"
|
|
||||||
local diagnostic
|
|
||||||
if diagnostic=$(check_pane_environment_boundary "$PORTABILITY_CALLS" 2>&1); then
|
|
||||||
fail "pane boundary accepted invalid $case_name fixture"
|
|
||||||
fi
|
|
||||||
contains_literal "$diagnostic" "records=$expected_records bytes=" || \
|
|
||||||
fail "pane argv diagnostic omitted counts for $case_name fixture"
|
|
||||||
contains_literal "$diagnostic" '[000]' || \
|
|
||||||
fail "pane argv diagnostic omitted indexed arguments for $case_name fixture"
|
|
||||||
}
|
|
||||||
|
|
||||||
printf '%s\0' tmux -i > "$PORTABILITY_CALLS"
|
|
||||||
assert_pane_boundary_rejected missing-env 2
|
|
||||||
printf '%s\0' /usr/bin/env HOME=/untrusted > "$PORTABILITY_CALLS"
|
|
||||||
assert_pane_boundary_rejected missing-i 2
|
|
||||||
printf '%s\0' /usr/bin/env HOME=/untrusted -i > "$PORTABILITY_CALLS"
|
|
||||||
assert_pane_boundary_rejected non-adjacent-i 3
|
|
||||||
printf '%s\0' -i /usr/bin/env > "$PORTABILITY_CALLS"
|
|
||||||
assert_pane_boundary_rejected reversed-boundary 2
|
|
||||||
|
|
||||||
cat > "$FAKE_BIN/tmux" <<'SHIM'
|
cat > "$FAKE_BIN/tmux" <<'SHIM'
|
||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
@@ -138,19 +62,6 @@ env -0 > "${MOSAIC_HOME:?}/fleet/pane-environment"
|
|||||||
SHIM
|
SHIM
|
||||||
chmod +x "$FAKE_BIN/mosaic"
|
chmod +x "$FAKE_BIN/mosaic"
|
||||||
|
|
||||||
# Freeze numeric epoch reads only when a test arm supplies an observation bound.
|
|
||||||
# Formatting reads still use the real BusyBox/POSIX date implementation.
|
|
||||||
cat > "$FAKE_BIN/date" <<'SHIM'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
if [ -n "${MOSAIC_TEST_FIXED_EPOCH:-}" ] && [ "${1:-}" = '+%s' ]; then
|
|
||||||
printf '%s\n' "$MOSAIC_TEST_FIXED_EPOCH"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
exec /bin/date "$@"
|
|
||||||
SHIM
|
|
||||||
chmod +x "$FAKE_BIN/date"
|
|
||||||
|
|
||||||
write_generated() {
|
write_generated() {
|
||||||
local home="$1"
|
local home="$1"
|
||||||
local agent="$2"
|
local agent="$2"
|
||||||
@@ -160,7 +71,6 @@ write_generated() {
|
|||||||
chmod 600 "$home/fleet/run/holder-owner"
|
chmod 600 "$home/fleet/run/holder-owner"
|
||||||
cat > "$home/fleet/agents/$agent.env.generated" <<EOF
|
cat > "$home/fleet/agents/$agent.env.generated" <<EOF
|
||||||
MOSAIC_AGENT_NAME=$agent
|
MOSAIC_AGENT_NAME=$agent
|
||||||
MOSAIC_GIT_IDENTITY=$agent
|
|
||||||
MOSAIC_AGENT_CLASS=code
|
MOSAIC_AGENT_CLASS=code
|
||||||
MOSAIC_AGENT_RUNTIME=pi
|
MOSAIC_AGENT_RUNTIME=pi
|
||||||
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
|
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
|
||||||
@@ -178,7 +88,6 @@ run_start() {
|
|||||||
local agent="$2"
|
local agent="$2"
|
||||||
HOME="$home" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
HOME="$home" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
||||||
MOSAIC_TEST_PANE_PID="${MOSAIC_TEST_PANE_PID:-}" \
|
MOSAIC_TEST_PANE_PID="${MOSAIC_TEST_PANE_PID:-}" \
|
||||||
MOSAIC_TEST_FIXED_EPOCH="${MOSAIC_TEST_FIXED_EPOCH:-}" \
|
|
||||||
MOSAIC_TEST_HOME="$home" \
|
MOSAIC_TEST_HOME="$home" \
|
||||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||||
MOSAIC_HOME="$home" "$START" "$agent"
|
MOSAIC_HOME="$home" "$START" "$agent"
|
||||||
@@ -191,55 +100,19 @@ AGENT_VALID="coder0"
|
|||||||
write_generated "$HOME_VALID" "$AGENT_VALID"
|
write_generated "$HOME_VALID" "$AGENT_VALID"
|
||||||
run_start "$HOME_VALID" "$AGENT_VALID"
|
run_start "$HOME_VALID" "$AGENT_VALID"
|
||||||
valid_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
valid_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
contains_literal "$valid_args" new-session || fail "valid generated projection did not reach tmux"
|
echo "$valid_args" | grep -qF new-session || fail "valid generated projection did not reach tmux"
|
||||||
contains_literal "$valid_args" mosaic || fail "fixed mosaic launcher command missing"
|
echo "$valid_args" | grep -qF 'mosaic' || fail "fixed mosaic launcher command missing"
|
||||||
contains_literal "$valid_args" yolo || fail "fixed yolo launcher command missing"
|
echo "$valid_args" | grep -qF 'yolo' || fail "fixed yolo launcher command missing"
|
||||||
contains_literal "$valid_args" pi || fail "roster runtime missing"
|
echo "$valid_args" | grep -qF 'pi' || fail "roster runtime missing"
|
||||||
if contains_literal "$valid_args" 'bash -c'; then
|
if echo "$valid_args" | grep -qF 'bash -c'; then
|
||||||
fail "launcher constructed a shell command payload"
|
fail "launcher constructed a shell command payload"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# The pane must start through an absolute clean-environment boundary. Its
|
# The pane must start through an absolute clean-environment boundary. Its
|
||||||
# runtime command remains an argv vector, but no holder/session environment
|
# runtime command remains an argv vector, but no holder/session environment
|
||||||
# control variable can pass through the pane command.
|
# control variable can pass through the pane command.
|
||||||
check_pane_environment_boundary "$TMUX_CALLS" || \
|
echo "$valid_args" | grep -qxF '/usr/bin/env' || fail "pane does not use absolute env"
|
||||||
fail "pane command did not use an adjacent /usr/bin/env -i boundary"
|
echo "$valid_args" | grep -qxF -- '-i' || fail "pane environment is not cleared"
|
||||||
|
|
||||||
# Git identity is generated authority, not an optional or independently mutable
|
|
||||||
# local value. Each invalid form must fail before fake tmux receives a call.
|
|
||||||
assert_git_identity_rejected() {
|
|
||||||
local case_name="$1"
|
|
||||||
local expected_code="$2"
|
|
||||||
local home="$ROOT/git-identity-$case_name"
|
|
||||||
local agent="coder-git-identity-$case_name"
|
|
||||||
local generated="$home/fleet/agents/$agent.env.generated"
|
|
||||||
write_generated "$home" "$agent"
|
|
||||||
|
|
||||||
case "$case_name" in
|
|
||||||
missing) grep -v '^MOSAIC_GIT_IDENTITY=' "$generated" > "$generated.next" && mv "$generated.next" "$generated" ;;
|
|
||||||
unsafe) sed -i 's|^MOSAIC_GIT_IDENTITY=.*$|MOSAIC_GIT_IDENTITY=bad/identity|' "$generated" ;;
|
|
||||||
mismatch) sed -i 's|^MOSAIC_GIT_IDENTITY=.*$|MOSAIC_GIT_IDENTITY=other-agent|' "$generated" ;;
|
|
||||||
local-shadow)
|
|
||||||
printf 'MOSAIC_GIT_IDENTITY=%s\n' "$agent" > "$home/fleet/agents/$agent.env.local"
|
|
||||||
chmod 600 "$home/fleet/agents/$agent.env.local"
|
|
||||||
;;
|
|
||||||
*) fail "unknown Git identity rejection case: $case_name" ;;
|
|
||||||
esac
|
|
||||||
chmod 600 "$generated"
|
|
||||||
|
|
||||||
: > "$TMUX_CALLS"
|
|
||||||
if output=$(run_start "$home" "$agent" 2>&1); then
|
|
||||||
fail "Git identity case $case_name was accepted"
|
|
||||||
fi
|
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before Git identity $case_name rejection"
|
|
||||||
contains_literal "$output" "code=$expected_code" || \
|
|
||||||
fail "Git identity $case_name diagnostic omitted code $expected_code"
|
|
||||||
}
|
|
||||||
|
|
||||||
assert_git_identity_rejected missing missing-key
|
|
||||||
assert_git_identity_rejected unsafe unsafe-git-identity
|
|
||||||
assert_git_identity_rejected mismatch git-identity-mismatch
|
|
||||||
assert_git_identity_rejected local-shadow generated-key-shadow
|
|
||||||
|
|
||||||
# The generated-file parent is a security boundary too: even a private regular
|
# The generated-file parent is a security boundary too: even a private regular
|
||||||
# file is untrusted if its parent can be replaced or written by another user.
|
# file is untrusted if its parent can be replaced or written by another user.
|
||||||
@@ -252,7 +125,7 @@ if output=$(run_start "$HOME_UNSAFE_PARENT" coder-parent 2>&1); then
|
|||||||
fail "generated file under a world-writable parent was accepted"
|
fail "generated file under a world-writable parent was accepted"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before unsafe parent rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before unsafe parent rejection"
|
||||||
contains_literal "$output" 'code=unsafe-permissions' || fail "unsafe parent diagnostic missing"
|
echo "$output" | grep -qF 'code=unsafe-permissions' || fail "unsafe parent diagnostic missing"
|
||||||
|
|
||||||
: > "$TMUX_CALLS"
|
: > "$TMUX_CALLS"
|
||||||
HOME_SYMLINK_PARENT="$ROOT/symlink-parent"
|
HOME_SYMLINK_PARENT="$ROOT/symlink-parent"
|
||||||
@@ -263,7 +136,7 @@ if output=$(run_start "$HOME_SYMLINK_PARENT" coder-symlink-parent 2>&1); then
|
|||||||
fail "generated file under a symlinked parent was accepted"
|
fail "generated file under a symlinked parent was accepted"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before symlinked parent rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before symlinked parent rejection"
|
||||||
contains_literal "$output" 'code=unsafe-directory' || fail "symlinked parent diagnostic missing"
|
echo "$output" | grep -qF 'code=unsafe-directory' || fail "symlinked parent diagnostic missing"
|
||||||
|
|
||||||
# Every managed ancestor is a boundary: MOSAIC_HOME, fleet, and agents. A
|
# Every managed ancestor is a boundary: MOSAIC_HOME, fleet, and agents. A
|
||||||
# symlink or group/world-writable ancestor must fail before environment parsing,
|
# symlink or group/world-writable ancestor must fail before environment parsing,
|
||||||
@@ -301,8 +174,8 @@ assert_managed_ancestor_rejected() {
|
|||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before $hazard $ancestor rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before $hazard $ancestor rejection"
|
||||||
[ ! -e "$home/work" ] || fail "workdir was created before $hazard $ancestor rejection"
|
[ ! -e "$home/work" ] || fail "workdir was created before $hazard $ancestor rejection"
|
||||||
contains_literal "$output" 'code=unsafe-' || fail "managed ancestor diagnostic missing"
|
echo "$output" | grep -qF "code=unsafe-" || fail "managed ancestor diagnostic missing"
|
||||||
if contains_literal "$output" 'key=MOSAIC_AGENT_COMMAND'; then
|
if echo "$output" | grep -qF 'key=MOSAIC_AGENT_COMMAND'; then
|
||||||
fail "environment parsing ran before $hazard $ancestor rejection"
|
fail "environment parsing ran before $hazard $ancestor rejection"
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
@@ -323,9 +196,9 @@ if output=$(run_start "$HOME_SHADOW" coder1 2>&1); then
|
|||||||
fail "generated-key shadow was accepted"
|
fail "generated-key shadow was accepted"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before generated-key shadow rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before generated-key shadow rejection"
|
||||||
contains_literal "$output" 'key=MOSAIC_AGENT_RUNTIME' || fail "shadow diagnostic omitted key"
|
echo "$output" | grep -qF 'key=MOSAIC_AGENT_RUNTIME' || fail "shadow diagnostic omitted key"
|
||||||
contains_literal "$output" 'sha256=' || fail "shadow diagnostic omitted hash"
|
echo "$output" | grep -qF 'sha256=' || fail "shadow diagnostic omitted hash"
|
||||||
if contains_literal "$output" codex; then
|
if echo "$output" | grep -qF 'codex'; then
|
||||||
fail "shadow diagnostic leaked value"
|
fail "shadow diagnostic leaked value"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -341,9 +214,9 @@ if output=$(run_start "$HOME_COMMAND" coder2 2>&1); then
|
|||||||
fail "arbitrary command override was accepted"
|
fail "arbitrary command override was accepted"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before command rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before command rejection"
|
||||||
contains_literal "$output" 'key=MOSAIC_AGENT_COMMAND' || fail "command diagnostic omitted key"
|
echo "$output" | grep -qF 'key=MOSAIC_AGENT_COMMAND' || fail "command diagnostic omitted key"
|
||||||
contains_literal "$output" 'sha256=' || fail "command diagnostic omitted hash"
|
echo "$output" | grep -qF 'sha256=' || fail "command diagnostic omitted hash"
|
||||||
if contains_literal "$output" "$COMMAND_VALUE"; then
|
if echo "$output" | grep -qF "$COMMAND_VALUE"; then
|
||||||
fail "command diagnostic leaked command value"
|
fail "command diagnostic leaked command value"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -357,7 +230,7 @@ if output=$(run_start "$HOME_PERMS" coder3 2>&1); then
|
|||||||
fail "world-readable local input was accepted"
|
fail "world-readable local input was accepted"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before permissions rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before permissions rejection"
|
||||||
contains_literal "$output" 'code=unsafe-permissions' || fail "permission diagnostic missing"
|
echo "$output" | grep -qF 'code=unsafe-permissions' || fail "permission diagnostic missing"
|
||||||
|
|
||||||
# A unit/holder-like clean bootstrap must yield a pane with trusted HOME and
|
# A unit/holder-like clean bootstrap must yield a pane with trusted HOME and
|
||||||
# computed PATH only. The pane command itself must not carry loader, shell
|
# computed PATH only. The pane command itself must not carry loader, shell
|
||||||
@@ -387,35 +260,25 @@ PATH="$PANE_STALE_PATH" \
|
|||||||
MOSAIC_TEST_EXECUTE_PANE=1 \
|
MOSAIC_TEST_EXECUTE_PANE=1 \
|
||||||
"$START" coder-pane-boundary
|
"$START" coder-pane-boundary
|
||||||
pane_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
pane_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
contains_line "$pane_args" "HOME=$PANE_TRUSTED_HOME" || \
|
echo "$pane_args" | grep -qxF "HOME=$PANE_TRUSTED_HOME" || \
|
||||||
fail "pane did not restore trusted HOME"
|
fail "pane did not restore trusted HOME"
|
||||||
contains_literal "$pane_args" "HOME=$PANE_STALE_HOME" && \
|
echo "$pane_args" | grep -qF "HOME=$PANE_STALE_HOME" && \
|
||||||
fail "pane inherited stale HOME"
|
fail "pane inherited stale HOME"
|
||||||
contains_literal "$pane_args" "$PANE_STALE_PATH" && fail "pane inherited stale PATH"
|
echo "$pane_args" | grep -qF "$PANE_STALE_PATH" && fail "pane inherited stale PATH"
|
||||||
for blocked in LD_PRELOAD= BASH_ENV= MOSAIC_UNTRUSTED_SENTINEL=; do
|
for blocked in LD_PRELOAD= BASH_ENV= MOSAIC_UNTRUSTED_SENTINEL=; do
|
||||||
contains_literal "$pane_args" "$blocked" && fail "pane inherited $blocked"
|
echo "$pane_args" | grep -qF "$blocked" && fail "pane inherited $blocked"
|
||||||
done
|
done
|
||||||
|
|
||||||
check_pane_environment_boundary "$TMUX_CALLS" || \
|
after_pane_env=$(printf '%s\n' "$pane_args" | grep -n -m1 -F '/usr/bin/env' | cut -d: -f1)
|
||||||
fail "pane command did not use an adjacent /usr/bin/env -i boundary"
|
[ -n "$after_pane_env" ] || fail "pane command did not use absolute env"
|
||||||
|
printf '%s\n' "$pane_args" | tail -n +"$after_pane_env" | grep -qxF -- '-i' || \
|
||||||
|
fail "pane command did not clear its environment"
|
||||||
pane_environment=$(tr '\0' '\n' < "$HOME_PANE_BOUNDARY/fleet/pane-environment")
|
pane_environment=$(tr '\0' '\n' < "$HOME_PANE_BOUNDARY/fleet/pane-environment")
|
||||||
# Exercise the repository launcher at $START, not the independently installed
|
echo "$pane_environment" | grep -qxF "HOME=$PANE_TRUSTED_HOME" || \
|
||||||
# host copy. Set-compare every declared generated projection entry with the
|
|
||||||
# launched process environment so a newly declared identity cannot be omitted
|
|
||||||
# by a hand-maintained per-variable assertion.
|
|
||||||
declared_generated_environment=$(sort "$HOME_PANE_BOUNDARY/fleet/agents/coder-pane-boundary.env.generated")
|
|
||||||
missing_or_changed_generated_environment=$(comm -23 \
|
|
||||||
<(printf '%s\n' "$declared_generated_environment") \
|
|
||||||
<(printf '%s\n' "$pane_environment" | sort))
|
|
||||||
if [ -n "$missing_or_changed_generated_environment" ]; then
|
|
||||||
missing_or_changed_keys=$(printf '%s\n' "$missing_or_changed_generated_environment" | cut -d= -f1 | paste -sd, -)
|
|
||||||
fail "runtime pane omitted or changed generated environment keys: $missing_or_changed_keys"
|
|
||||||
fi
|
|
||||||
contains_line "$pane_environment" "HOME=$PANE_TRUSTED_HOME" || \
|
|
||||||
fail "runtime pane did not receive trusted HOME"
|
fail "runtime pane did not receive trusted HOME"
|
||||||
contains_literal "$pane_environment" "$PANE_STALE_PATH" && fail "runtime pane received stale PATH"
|
echo "$pane_environment" | grep -qF "$PANE_STALE_PATH" && fail "runtime pane received stale PATH"
|
||||||
for blocked in LD_PRELOAD= BASH_ENV= MOSAIC_UNTRUSTED_SENTINEL=; do
|
for blocked in LD_PRELOAD= BASH_ENV= MOSAIC_UNTRUSTED_SENTINEL=; do
|
||||||
contains_literal "$pane_environment" "$blocked" && fail "runtime pane received $blocked"
|
echo "$pane_environment" | grep -qF "$blocked" && fail "runtime pane received $blocked"
|
||||||
done
|
done
|
||||||
|
|
||||||
write_interaction_generated() {
|
write_interaction_generated() {
|
||||||
@@ -427,7 +290,6 @@ write_interaction_generated() {
|
|||||||
chmod 600 "$home/fleet/run/holder-owner"
|
chmod 600 "$home/fleet/run/holder-owner"
|
||||||
cat > "$home/fleet/agents/$agent.env.generated" <<EOF
|
cat > "$home/fleet/agents/$agent.env.generated" <<EOF
|
||||||
MOSAIC_AGENT_NAME=$agent
|
MOSAIC_AGENT_NAME=$agent
|
||||||
MOSAIC_GIT_IDENTITY=$agent
|
|
||||||
MOSAIC_AGENT_CLASS=operator-interaction
|
MOSAIC_AGENT_CLASS=operator-interaction
|
||||||
MOSAIC_AGENT_RUNTIME=pi
|
MOSAIC_AGENT_RUNTIME=pi
|
||||||
MOSAIC_AGENT_MODEL=openai/gpt-5.6-sol
|
MOSAIC_AGENT_MODEL=openai/gpt-5.6-sol
|
||||||
@@ -490,12 +352,8 @@ write_generated "$HOME_NATIVE_STALE" "coder-native-stale"
|
|||||||
write_heartbeat_local "$HOME_NATIVE_STALE" "coder-native-stale"
|
write_heartbeat_local "$HOME_NATIVE_STALE" "coder-native-stale"
|
||||||
STALE_HB="$HOME_NATIVE_STALE/run/coder-native-stale.hb"
|
STALE_HB="$HOME_NATIVE_STALE/run/coder-native-stale.hb"
|
||||||
printf 'ts=native\npid=1\nstatus=busy\nmodel=stale-model\n' > "$STALE_HB"
|
printf 'ts=native\npid=1\nstatus=busy\nmodel=stale-model\n' > "$STALE_HB"
|
||||||
touch -t 200001010000.00 "$STALE_HB.native"
|
touch -d '10 seconds ago' "$STALE_HB.native"
|
||||||
# Hold the sidecar's observation epoch constant: assertion runtime must not age
|
MOSAIC_TEST_PANE_PID=$$ run_start "$HOME_NATIVE_STALE" coder-native-stale
|
||||||
# a fresh-marker mutant into the stale state that this fixture must distinguish.
|
|
||||||
STALE_OBSERVATION_EPOCH=$(date +%s)
|
|
||||||
MOSAIC_TEST_FIXED_EPOCH="$STALE_OBSERVATION_EPOCH" \
|
|
||||||
MOSAIC_TEST_PANE_PID=$$ run_start "$HOME_NATIVE_STALE" coder-native-stale
|
|
||||||
wait_for_sidecar_status "$STALE_HB"
|
wait_for_sidecar_status "$STALE_HB"
|
||||||
|
|
||||||
HOME_NATIVE_ABSENT="$ROOT/native-absent"
|
HOME_NATIVE_ABSENT="$ROOT/native-absent"
|
||||||
@@ -516,22 +374,22 @@ if output=$(run_interaction "$HOME_INTERACTION_MALFORMED" interaction-malformed
|
|||||||
fail "interaction wrapper accepted malformed generated data"
|
fail "interaction wrapper accepted malformed generated data"
|
||||||
fi
|
fi
|
||||||
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before interaction strict-parser rejection"
|
[ ! -s "$TMUX_CALLS" ] || fail "tmux ran before interaction strict-parser rejection"
|
||||||
contains_literal "$output" 'code=unknown-key' || fail "interaction did not use shared strict parser first"
|
echo "$output" | grep -qF 'code=unknown-key' || fail "interaction did not use shared strict parser first"
|
||||||
|
|
||||||
# A syntactically valid but policy-incompatible projection reaches the pinned
|
# A syntactically valid but policy-incompatible projection reaches the pinned
|
||||||
# interaction policy check only after strict parsing and never starts tmux.
|
# interaction policy check only after strict parsing and never starts tmux.
|
||||||
: > "$TMUX_CALLS"
|
: > "$TMUX_CALLS"
|
||||||
HOME_INTERACTION_POLICY="$ROOT/interaction-policy"
|
HOME_INTERACTION_POLICY="$ROOT/interaction-policy"
|
||||||
write_interaction_generated "$HOME_INTERACTION_POLICY" "interaction-policy"
|
write_interaction_generated "$HOME_INTERACTION_POLICY" "interaction-policy"
|
||||||
sed -i 's|^MOSAIC_AGENT_RUNTIME=pi$|MOSAIC_AGENT_RUNTIME=codex|' \
|
perl -0pi -e 's/MOSAIC_AGENT_RUNTIME=pi/MOSAIC_AGENT_RUNTIME=codex/' \
|
||||||
"$HOME_INTERACTION_POLICY/fleet/agents/interaction-policy.env.generated"
|
"$HOME_INTERACTION_POLICY/fleet/agents/interaction-policy.env.generated"
|
||||||
if output=$(run_interaction "$HOME_INTERACTION_POLICY" interaction-policy 2>&1); then
|
if output=$(run_interaction "$HOME_INTERACTION_POLICY" interaction-policy 2>&1); then
|
||||||
fail "interaction wrapper accepted a policy-incompatible projection"
|
fail "interaction wrapper accepted a policy-incompatible projection"
|
||||||
fi
|
fi
|
||||||
interaction_policy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
interaction_policy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
contains_literal "$interaction_policy_args" new-session && \
|
echo "$interaction_policy_args" | grep -qF 'new-session' && \
|
||||||
fail "interaction pinned-policy rejection created a tmux session"
|
fail "interaction pinned-policy rejection created a tmux session"
|
||||||
contains_literal "$output" 'operator interaction service requires runtime pi' || \
|
echo "$output" | grep -qF 'operator interaction service requires runtime pi' || \
|
||||||
fail "interaction pinned-policy check did not follow strict parsing"
|
fail "interaction pinned-policy check did not follow strict parsing"
|
||||||
|
|
||||||
# Exact stop derives the socket exclusively from the validated generated
|
# Exact stop derives the socket exclusively from the validated generated
|
||||||
@@ -544,10 +402,10 @@ HOME="$HOME_STOP" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
|||||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||||
MOSAIC_HOME="$HOME_STOP" MOSAIC_TMUX_SOCKET=ambient-socket "$START" --stop coder-stop
|
MOSAIC_HOME="$HOME_STOP" MOSAIC_TMUX_SOCKET=ambient-socket "$START" --stop coder-stop
|
||||||
stop_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
stop_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
contains_line "$stop_args" mosaic-test || fail "exact stop did not use the validated generated socket"
|
echo "$stop_args" | grep -qxF 'mosaic-test' || fail "exact stop did not use the validated generated socket"
|
||||||
contains_line "$stop_args" kill-session || fail "exact stop did not request session termination"
|
echo "$stop_args" | grep -qxF 'kill-session' || fail "exact stop did not request session termination"
|
||||||
contains_line "$stop_args" '=coder-stop' || fail "exact stop did not exact-match the generated agent name"
|
echo "$stop_args" | grep -qxF '=coder-stop' || fail "exact stop did not exact-match the generated agent name"
|
||||||
if contains_literal "$stop_args" ambient-socket; then
|
if echo "$stop_args" | grep -qF 'ambient-socket'; then
|
||||||
fail "exact stop trusted an ambient socket"
|
fail "exact stop trusted an ambient socket"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -5,10 +5,7 @@
|
|||||||
|
|
||||||
detect_platform() {
|
detect_platform() {
|
||||||
local remote_url
|
local remote_url
|
||||||
# `|| true` is load-bearing under `set -e`: outside a git repo this returns 128 and
|
remote_url=$(git remote get-url origin 2>/dev/null)
|
||||||
# kills the CALLER before the -z check below can run, so the error message that is
|
|
||||||
# already written here was unreachable. Same idiom as get_gitea_repo_args() below.
|
|
||||||
remote_url=$(git remote get-url origin 2>/dev/null) || true
|
|
||||||
|
|
||||||
if [[ -z "$remote_url" ]]; then
|
if [[ -z "$remote_url" ]]; then
|
||||||
echo "error: not a git repository or no origin remote" >&2
|
echo "error: not a git repository or no origin remote" >&2
|
||||||
@@ -42,10 +39,7 @@ detect_platform() {
|
|||||||
|
|
||||||
get_repo_info() {
|
get_repo_info() {
|
||||||
local remote_url
|
local remote_url
|
||||||
# `|| true` is load-bearing under `set -e`: outside a git repo this returns 128 and
|
remote_url=$(git remote get-url origin 2>/dev/null)
|
||||||
# kills the CALLER before the -z check below can run, so the error message that is
|
|
||||||
# already written here was unreachable. Same idiom as get_gitea_repo_args() below.
|
|
||||||
remote_url=$(git remote get-url origin 2>/dev/null) || true
|
|
||||||
|
|
||||||
if [[ -z "$remote_url" ]]; then
|
if [[ -z "$remote_url" ]]; then
|
||||||
echo "error: not a git repository or no origin remote" >&2
|
echo "error: not a git repository or no origin remote" >&2
|
||||||
@@ -246,21 +240,6 @@ PY
|
|||||||
} >&2
|
} >&2
|
||||||
}
|
}
|
||||||
|
|
||||||
# Explain tea's most misleading failure. `user does not exist [uid: 0, name: ]` reads
|
|
||||||
# as a missing account; it almost always means a REVOKED OR STALE TOKEN. `tea login`
|
|
||||||
# keeps its OWN COPY of the token, so rotating the credential store does not update it.
|
|
||||||
# Diagnostic only -- stderr, no control flow, no exit.
|
|
||||||
explain_tea_user_does_not_exist() {
|
|
||||||
cat >&2 <<'MSG'
|
|
||||||
NOTE: `user does not exist [uid: 0, name: ]` from tea usually means a REVOKED OR STALE TOKEN,
|
|
||||||
not a missing account. A `tea login` stores its OWN COPY of the token; rotating the
|
|
||||||
credential store does NOT update it.
|
|
||||||
CHECK: the login's cached copy (`tea login list` -- read the FULL table, never `| head`),
|
|
||||||
then re-register that login against the current token.
|
|
||||||
DO NOT probe capability with a mutating request; a POST is the action, not a check.
|
|
||||||
MSG
|
|
||||||
}
|
|
||||||
|
|
||||||
get_gitea_login_for_host() {
|
get_gitea_login_for_host() {
|
||||||
local host="${1:-}"
|
local host="${1:-}"
|
||||||
local login
|
local login
|
||||||
|
|||||||
@@ -91,32 +91,13 @@ elif [[ "$PLATFORM" == "gitea" ]]; then
|
|||||||
GITEA_LOGIN_NAME=$(get_gitea_login || true)
|
GITEA_LOGIN_NAME=$(get_gitea_login || true)
|
||||||
if [[ -n "$GITEA_LOGIN_NAME" ]]; then
|
if [[ -n "$GITEA_LOGIN_NAME" ]]; then
|
||||||
if [[ -n "$COMMENT" ]]; then
|
if [[ -n "$COMMENT" ]]; then
|
||||||
# `tea issue comment` is NOT a subcommand -- tea 0.11.x lists only
|
tea issue comment "$ISSUE_NUMBER" "$COMMENT" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME"
|
||||||
# list/create/edit/reopen/close under `tea issue`. Comments are the
|
|
||||||
# TOP-LEVEL `tea comment`, which takes the same --repo/--login flags.
|
|
||||||
# The old call therefore always failed, was unchecked, and the script
|
|
||||||
# closed the issue anyway, losing the record of WHY.
|
|
||||||
#
|
|
||||||
# Use `tea comment` rather than the API helper so the comment and the
|
|
||||||
# close are made by the SAME principal ($GITEA_LOGIN_NAME). Routing the
|
|
||||||
# comment through the token-authenticated helper here would attribute the
|
|
||||||
# comment to the token holder and the close to the tea login -- two
|
|
||||||
# principals for one operation.
|
|
||||||
tea comment "$ISSUE_NUMBER" "$COMMENT" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" || {
|
|
||||||
echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
fi
|
fi
|
||||||
tea issue close "$ISSUE_NUMBER" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME"
|
tea issue close "$ISSUE_NUMBER" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME"
|
||||||
else
|
else
|
||||||
echo "No tea login configured for $(get_remote_host); using authenticated Gitea API fallback." >&2
|
echo "No tea login configured for $(get_remote_host); using authenticated Gitea API fallback." >&2
|
||||||
if [[ -n "$COMMENT" ]]; then
|
if [[ -n "$COMMENT" ]]; then
|
||||||
# Fail closed here too: an unchecked comment lets the issue close without its
|
gitea_issue_comment_api
|
||||||
# audit trail, which is the same defect as the tea path above.
|
|
||||||
gitea_issue_comment_api || {
|
|
||||||
echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
fi
|
fi
|
||||||
gitea_issue_close_api
|
gitea_issue_close_api
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -156,7 +156,6 @@ case "$PLATFORM" in
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
echo "Warning: tea issue create failed, trying Gitea API fallback..." >&2
|
echo "Warning: tea issue create failed, trying Gitea API fallback..." >&2
|
||||||
{ declare -F explain_tea_user_does_not_exist >/dev/null && explain_tea_user_does_not_exist; } || true
|
|
||||||
fi
|
fi
|
||||||
gitea_issue_create_api
|
gitea_issue_create_api
|
||||||
;;
|
;;
|
||||||
|
|||||||
@@ -71,7 +71,6 @@ elif [[ "$PLATFORM" == "gitea" ]]; then
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
echo "Warning: tea issue view failed, trying Gitea API fallback..." >&2
|
echo "Warning: tea issue view failed, trying Gitea API fallback..." >&2
|
||||||
{ declare -F explain_tea_user_does_not_exist >/dev/null && explain_tea_user_does_not_exist; } || true
|
|
||||||
fi
|
fi
|
||||||
gitea_issue_view_api
|
gitea_issue_view_api
|
||||||
else
|
else
|
||||||
|
|||||||
@@ -84,7 +84,7 @@ cp "$TARGET" "$BAK"
|
|||||||
export MOSAIC_TEST_WORK_DIR="$WORK/.work"
|
export MOSAIC_TEST_WORK_DIR="$WORK/.work"
|
||||||
|
|
||||||
# --- where the prose lives: usage() { ... EOF ---------------------------------
|
# --- where the prose lives: usage() { ... EOF ---------------------------------
|
||||||
PROSE_LO="$(grep -n -m1 '^usage() {' "$BAK" | cut -d: -f1)"
|
PROSE_LO="$(grep -n '^usage() {' "$BAK" | head -1 | cut -d: -f1)"
|
||||||
PROSE_HI="$(awk -v lo="$PROSE_LO" 'NR > lo && /^EOF$/ { print NR; exit }' "$BAK")"
|
PROSE_HI="$(awk -v lo="$PROSE_LO" 'NR > lo && /^EOF$/ { print NR; exit }' "$BAK")"
|
||||||
if [[ -z "$PROSE_LO" || -z "$PROSE_HI" ]]; then
|
if [[ -z "$PROSE_LO" || -z "$PROSE_HI" ]]; then
|
||||||
echo "!! cannot locate the usage() heredoc -- the prose guard would be inert; refusing" >&2
|
echo "!! cannot locate the usage() heredoc -- the prose guard would be inert; refusing" >&2
|
||||||
|
|||||||
@@ -219,7 +219,6 @@ case "$PLATFORM" in
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
echo "Warning: tea pr create failed, trying Gitea API fallback..." >&2
|
echo "Warning: tea pr create failed, trying Gitea API fallback..." >&2
|
||||||
{ declare -F explain_tea_user_does_not_exist >/dev/null && explain_tea_user_does_not_exist; } || true
|
|
||||||
gitea_pr_create_api
|
gitea_pr_create_api
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# pr-merge.sh - Merge pull requests on Gitea or GitHub
|
# pr-merge.sh - Merge pull requests on Gitea or GitHub
|
||||||
# Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d] [--expect-head SHA] [--co-author-trailers --escalate-to PRINCIPAL]
|
# Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d]
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -14,8 +14,6 @@ MERGE_METHOD="squash"
|
|||||||
DELETE_BRANCH=false
|
DELETE_BRANCH=false
|
||||||
DRY_RUN=false
|
DRY_RUN=false
|
||||||
EXPECT_HEAD=""
|
EXPECT_HEAD=""
|
||||||
CO_AUTHOR_TRAILERS=false
|
|
||||||
ESCALATE_TO=""
|
|
||||||
|
|
||||||
usage() {
|
usage() {
|
||||||
cat <<EOF
|
cat <<EOF
|
||||||
@@ -29,16 +27,12 @@ Options:
|
|||||||
-d, --delete-branch Delete the head branch after merge
|
-d, --delete-branch Delete the head branch after merge
|
||||||
--dry-run Run metadata/login preflight without merging
|
--dry-run Run metadata/login preflight without merging
|
||||||
--expect-head SHA Refuse unless the PR head matches this full commit SHA
|
--expect-head SHA Refuse unless the PR head matches this full commit SHA
|
||||||
--co-author-trailers Build verified trailers from linked PR commit authors
|
|
||||||
--escalate-to NAME Named principal for an unresolved-author BLOCK
|
|
||||||
-h, --help Show this help message
|
-h, --help Show this help message
|
||||||
|
|
||||||
Examples:
|
Examples:
|
||||||
$(basename "$0") -n 42 # Merge PR #42
|
$(basename "$0") -n 42 # Merge PR #42
|
||||||
$(basename "$0") -n 42 -m squash # Squash merge
|
$(basename "$0") -n 42 -m squash # Squash merge
|
||||||
$(basename "$0") -n 42 -d # Squash merge and delete branch
|
$(basename "$0") -n 42 -d # Squash merge and delete branch
|
||||||
$(basename "$0") -n 42 --expect-head 0123456789abcdef0123456789abcdef01234567
|
|
||||||
$(basename "$0") -n 42 --co-author-trailers --escalate-to tl-mosaic
|
|
||||||
EOF
|
EOF
|
||||||
exit "${1:-1}"
|
exit "${1:-1}"
|
||||||
}
|
}
|
||||||
@@ -63,25 +57,9 @@ while [[ $# -gt 0 ]]; do
|
|||||||
shift
|
shift
|
||||||
;;
|
;;
|
||||||
--expect-head)
|
--expect-head)
|
||||||
if [[ $# -lt 2 ]]; then
|
|
||||||
echo "Error: --expect-head requires one full commit SHA." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
EXPECT_HEAD="$2"
|
EXPECT_HEAD="$2"
|
||||||
shift 2
|
shift 2
|
||||||
;;
|
;;
|
||||||
--co-author-trailers)
|
|
||||||
CO_AUTHOR_TRAILERS=true
|
|
||||||
shift
|
|
||||||
;;
|
|
||||||
--escalate-to)
|
|
||||||
if [[ $# -lt 2 ]]; then
|
|
||||||
echo "Error: --escalate-to requires one principal name." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
ESCALATE_TO="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-h|--help)
|
-h|--help)
|
||||||
usage 0
|
usage 0
|
||||||
;;
|
;;
|
||||||
@@ -110,30 +88,17 @@ if [[ -n "$EXPECT_HEAD" && ! "$EXPECT_HEAD" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
|||||||
echo "Error: --expect-head must be a full 40-character hexadecimal commit SHA." >&2
|
echo "Error: --expect-head must be a full 40-character hexadecimal commit SHA." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
if [[ "$CO_AUTHOR_TRAILERS" == true && -z "$ESCALATE_TO" ]]; then
|
|
||||||
echo "Error: --co-author-trailers requires --escalate-to with a named principal." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -n "$ESCALATE_TO" && ! "$ESCALATE_TO" =~ ^[A-Za-z0-9_.-]+$ ]]; then
|
|
||||||
echo "Error: --escalate-to must be one exact principal name." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ "$CO_AUTHOR_TRAILERS" != true && -n "$ESCALATE_TO" ]]; then
|
|
||||||
echo "Error: --escalate-to is valid only with --co-author-trailers." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
PR_METADATA="$("$SCRIPT_DIR/pr-metadata.sh" -n "$PR_NUMBER")"
|
PR_METADATA="$("$SCRIPT_DIR/pr-metadata.sh" -n "$PR_NUMBER")"
|
||||||
BASE_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("baseRefName") or "").strip())')"
|
BASE_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("baseRefName") or "").strip())')"
|
||||||
HEAD_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefName") or "").strip())')"
|
HEAD_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefName") or "").strip())')"
|
||||||
HEAD_SHA="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefOid") or "").strip())')"
|
HEAD_SHA="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefOid") or "").strip())')"
|
||||||
HEAD_REPO="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; value=json.load(sys.stdin).get("headRepository") or ""; print((value.get("nameWithOwner") or value.get("full_name") or "") if isinstance(value, dict) else str(value).strip())')"
|
HEAD_REPO="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; value=json.load(sys.stdin).get("headRepository") or ""; print((value.get("nameWithOwner") or value.get("full_name") or "") if isinstance(value, dict) else str(value).strip())')"
|
||||||
PR_TITLE="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("title") or "").strip())')"
|
|
||||||
PR_AUTHOR="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; value=json.load(sys.stdin).get("author") or ""; print((value.get("login") or "").strip() if isinstance(value, dict) else str(value).strip())')"
|
|
||||||
if [[ "$BASE_BRANCH" != "main" ]]; then
|
if [[ "$BASE_BRANCH" != "main" ]]; then
|
||||||
echo "Error: Mosaic policy allows merges only for PRs targeting 'main' (found '$BASE_BRANCH')." >&2
|
echo "Error: Mosaic policy allows merges only for PRs targeting 'main' (found '$BASE_BRANCH')." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -z "$HEAD_BRANCH" || -z "$HEAD_REPO" || ! "$HEAD_SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
if [[ -z "$HEAD_BRANCH" || -z "$HEAD_REPO" || ! "$HEAD_SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
||||||
echo "Error: Could not resolve the PR head branch, repository, and full commit SHA for queue inspection." >&2
|
echo "Error: Could not resolve the PR head branch, repository, and full commit SHA for queue inspection." >&2
|
||||||
exit 1
|
exit 1
|
||||||
@@ -157,442 +122,70 @@ PLATFORM=$(detect_platform)
|
|||||||
OWNER=$(get_repo_owner)
|
OWNER=$(get_repo_owner)
|
||||||
REPO=$(get_repo_name)
|
REPO=$(get_repo_name)
|
||||||
|
|
||||||
write_curl_auth_config() {
|
merge_gitea_with_api() {
|
||||||
local mode="$1" credential="$2"
|
local host="$1" api_url token basic_auth body_file raw_code payload
|
||||||
printf '%s' "$credential" | python3 -c '
|
|
||||||
import sys
|
|
||||||
mode = sys.argv[1]
|
|
||||||
credential = sys.stdin.read()
|
|
||||||
if not credential or any(char in credential for char in "\r\n"):
|
|
||||||
raise SystemExit(1)
|
|
||||||
escaped = credential.replace("\\", "\\\\").replace("\"", "\\\"")
|
|
||||||
if mode == "token":
|
|
||||||
print(f"header = \"Authorization: token {escaped}\"")
|
|
||||||
elif mode == "basic":
|
|
||||||
print(f"user = \"{escaped}\"")
|
|
||||||
else:
|
|
||||||
raise SystemExit(1)
|
|
||||||
' "$mode"
|
|
||||||
}
|
|
||||||
|
|
||||||
LAST_GITEA_HTTP_CODE="000"
|
|
||||||
LAST_GITEA_ERROR=""
|
|
||||||
MERGE_TEMP_DIRS=()
|
|
||||||
GITEA_CURL_MAX_BYTES="${MOSAIC_GITEA_CURL_MAX_BYTES:-1048576}"
|
|
||||||
GITEA_CURL_MAX_TIME="${MOSAIC_GITEA_CURL_MAX_TIME_SEC:-30}"
|
|
||||||
GITEA_CURL_CONNECT_TIMEOUT="${MOSAIC_GITEA_CURL_CONNECT_TIMEOUT_SEC:-10}"
|
|
||||||
for bound in "$GITEA_CURL_MAX_BYTES" "$GITEA_CURL_MAX_TIME" "$GITEA_CURL_CONNECT_TIMEOUT"; do
|
|
||||||
if [[ ! "$bound" =~ ^[1-9][0-9]*$ ]]; then
|
|
||||||
echo "Error: Gitea curl bounds must be positive integers; refusing request." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
GITEA_CURL_BOUNDS=(
|
|
||||||
--max-filesize "$GITEA_CURL_MAX_BYTES"
|
|
||||||
--max-time "$GITEA_CURL_MAX_TIME"
|
|
||||||
--connect-timeout "$GITEA_CURL_CONNECT_TIMEOUT"
|
|
||||||
)
|
|
||||||
|
|
||||||
format_gitea_error_response() {
|
|
||||||
local response_file="$1"
|
|
||||||
python3 - "$response_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
|
|
||||||
with open(sys.argv[1], "rb") as handle:
|
|
||||||
raw = handle.read(65536)
|
|
||||||
try:
|
|
||||||
response = json.loads(raw.decode("utf-8", errors="replace"))
|
|
||||||
except (UnicodeDecodeError, json.JSONDecodeError):
|
|
||||||
message = "non-JSON response omitted"
|
|
||||||
else:
|
|
||||||
if isinstance(response, dict):
|
|
||||||
message = response.get("message") or response.get("error")
|
|
||||||
if not message and response.get("errors") is not None:
|
|
||||||
message = json.dumps(response["errors"], separators=(",", ":"))
|
|
||||||
else:
|
|
||||||
message = None
|
|
||||||
if not message:
|
|
||||||
message = "JSON response contained no error message"
|
|
||||||
message = str(message)
|
|
||||||
if len(message) > 500:
|
|
||||||
message = message[:500] + "..."
|
|
||||||
print(ascii(message))
|
|
||||||
PY
|
|
||||||
}
|
|
||||||
|
|
||||||
cleanup_merge_temp_dirs() {
|
|
||||||
local path
|
|
||||||
for path in "${MERGE_TEMP_DIRS[@]}"; do
|
|
||||||
[[ -n "$path" ]] && rm -rf -- "$path"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
trap cleanup_merge_temp_dirs EXIT
|
|
||||||
trap 'exit 130' INT
|
|
||||||
trap 'exit 143' TERM
|
|
||||||
|
|
||||||
fetch_gitea_pr_head() {
|
|
||||||
local host="$1" auth_mode="$2" credential="$3" work_root="$4"
|
|
||||||
local response_file raw_code api_url auth_config curl_rc
|
|
||||||
response_file=$(mktemp "$work_root/pr-merge-pr.XXXXXX")
|
|
||||||
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}"
|
|
||||||
if ! auth_config=$(write_curl_auth_config "$auth_mode" "$credential"); then
|
|
||||||
echo "Error: Could not construct Gitea authentication config; refusing request." >&2
|
|
||||||
rm -f "$response_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
raw_code=$(curl -sS -K - "${GITEA_CURL_BOUNDS[@]}" -w '%{http_code}' -o "$response_file" \
|
|
||||||
-H "User-Agent: curl/8" "$api_url" <<<"$auth_config")
|
|
||||||
curl_rc=$?
|
|
||||||
LAST_GITEA_HTTP_CODE="${raw_code:-000}"
|
|
||||||
if [[ "$curl_rc" -ne 0 ]]; then
|
|
||||||
LAST_GITEA_ERROR="curl transport failed (rc=$curl_rc)"
|
|
||||||
rm -f "$response_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if [[ ! "$raw_code" =~ ^2 ]]; then
|
|
||||||
LAST_GITEA_ERROR=$(format_gitea_error_response "$response_file")
|
|
||||||
rm -f "$response_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if ! python3 - "$response_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import re
|
|
||||||
import sys
|
|
||||||
|
|
||||||
with open(sys.argv[1], encoding="utf-8") as handle:
|
|
||||||
pull = json.load(handle)
|
|
||||||
head = pull.get("head") if isinstance(pull, dict) else None
|
|
||||||
sha = str(head.get("sha") or "") if isinstance(head, dict) else ""
|
|
||||||
if not re.fullmatch(r"[0-9a-fA-F]{40}", sha):
|
|
||||||
raise SystemExit(1)
|
|
||||||
print(sha)
|
|
||||||
PY
|
|
||||||
then
|
|
||||||
echo "Error: Gitea PR response has no valid head SHA; refusing merge." >&2
|
|
||||||
rm -f "$response_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
rm -f "$response_file"
|
|
||||||
}
|
|
||||||
|
|
||||||
fetch_gitea_pr_commits() {
|
|
||||||
local host="$1" auth_mode="$2" credential="$3" work_root="$4"
|
|
||||||
local page page_file combined_file merged_file raw_code page_count api_url auth_config curl_rc
|
|
||||||
mkdir -p "$work_root"
|
|
||||||
if ! auth_config=$(write_curl_auth_config "$auth_mode" "$credential"); then
|
|
||||||
echo "Error: Could not construct Gitea authentication config; refusing request." >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
combined_file=$(mktemp "$work_root/pr-merge-commits.XXXXXX")
|
|
||||||
printf '[]' > "$combined_file"
|
|
||||||
|
|
||||||
page=1
|
|
||||||
while true; do
|
|
||||||
page_file=$(mktemp "$work_root/pr-merge-commits-page.XXXXXX")
|
|
||||||
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}/commits?limit=50&page=${page}"
|
|
||||||
raw_code=$(curl -sS -K - "${GITEA_CURL_BOUNDS[@]}" -w '%{http_code}' -o "$page_file" \
|
|
||||||
-H "User-Agent: curl/8" "$api_url" <<<"$auth_config")
|
|
||||||
curl_rc=$?
|
|
||||||
LAST_GITEA_HTTP_CODE="${raw_code:-000}"
|
|
||||||
if [[ "$curl_rc" -ne 0 ]]; then
|
|
||||||
LAST_GITEA_ERROR="curl transport failed (rc=$curl_rc)"
|
|
||||||
rm -f "$page_file" "$combined_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if [[ ! "$raw_code" =~ ^2 ]]; then
|
|
||||||
LAST_GITEA_ERROR=$(format_gitea_error_response "$page_file")
|
|
||||||
rm -f "$page_file" "$combined_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! page_count=$(python3 - "$page_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
|
|
||||||
with open(sys.argv[1], encoding="utf-8") as handle:
|
|
||||||
page = json.load(handle)
|
|
||||||
if not isinstance(page, list):
|
|
||||||
raise SystemExit(1)
|
|
||||||
print(len(page))
|
|
||||||
PY
|
|
||||||
); then
|
|
||||||
echo "Error: Gitea PR commits response is not a JSON array; refusing merge." >&2
|
|
||||||
rm -f "$page_file" "$combined_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
merged_file=$(mktemp "$work_root/pr-merge-commits-merged.XXXXXX")
|
|
||||||
if ! python3 - "$combined_file" "$page_file" > "$merged_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
|
|
||||||
with open(sys.argv[1], encoding="utf-8") as handle:
|
|
||||||
combined = json.load(handle)
|
|
||||||
with open(sys.argv[2], encoding="utf-8") as handle:
|
|
||||||
page = json.load(handle)
|
|
||||||
json.dump(combined + page, sys.stdout, separators=(",", ":"))
|
|
||||||
PY
|
|
||||||
then
|
|
||||||
echo "Error: Could not combine paginated PR commit metadata; refusing merge." >&2
|
|
||||||
rm -f "$page_file" "$combined_file" "$merged_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
mv "$merged_file" "$combined_file"
|
|
||||||
rm -f "$page_file"
|
|
||||||
|
|
||||||
if [[ "$page_count" -lt 50 ]]; then
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
page=$((page + 1))
|
|
||||||
if [[ "$page" -gt 1000 ]]; then
|
|
||||||
echo "Error: PR commit pagination exceeded 1000 pages; refusing merge." >&2
|
|
||||||
rm -f "$combined_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
cat "$combined_file"
|
|
||||||
rm -f "$combined_file"
|
|
||||||
}
|
|
||||||
|
|
||||||
# LIMITATION: author.login resolution proves the commit address maps to a registered account.
|
|
||||||
# It does NOT prove the named principal authored the commit — git author metadata is self-asserted.
|
|
||||||
# This gate checks ATTRIBUTION LINKAGE, not AUTHORSHIP. Commit signing is out of scope and unadopted.
|
|
||||||
build_coauthor_message_fields() {
|
|
||||||
local commits_file="$1" context_file="$2" head_file="$3"
|
|
||||||
python3 - "$commits_file" "$context_file" "$head_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import re
|
|
||||||
import sys
|
|
||||||
|
|
||||||
commits_path, context_path, head_path = sys.argv[1:]
|
|
||||||
with open(commits_path, encoding="utf-8") as handle:
|
|
||||||
commits = json.load(handle)
|
|
||||||
head_sha = open(head_path, encoding="utf-8").read().strip()
|
|
||||||
context_parts = open(context_path, "rb").read().split(b"\0")
|
|
||||||
if len(context_parts) != 4 or context_parts[-1] != b"":
|
|
||||||
raise SystemExit(1)
|
|
||||||
poster, title, principal = (part.decode("utf-8") for part in context_parts[:3])
|
|
||||||
|
|
||||||
if not isinstance(commits, list) or not commits:
|
|
||||||
print(
|
|
||||||
f"BLOCK: provider returned no PR commits; author identity is unmeasurable. "
|
|
||||||
f"Refusing merge; escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
if not poster:
|
|
||||||
print(
|
|
||||||
f"BLOCK: PR poster login is empty; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
|
|
||||||
if not re.fullmatch(r"[0-9a-fA-F]{40}", head_sha):
|
|
||||||
print(
|
|
||||||
f"BLOCK: inspected PR head SHA is invalid; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
|
|
||||||
seen = set()
|
|
||||||
trailers = []
|
|
||||||
head_seen = False
|
|
||||||
for item in commits:
|
|
||||||
if not isinstance(item, dict):
|
|
||||||
print(f"BLOCK: malformed PR commit metadata; escalate to named principal '{principal}'.", file=sys.stderr)
|
|
||||||
raise SystemExit(75)
|
|
||||||
sha = str(item.get("sha") or "<unknown>")
|
|
||||||
if sha == head_sha:
|
|
||||||
head_seen = True
|
|
||||||
commit = item.get("commit") if isinstance(item.get("commit"), dict) else {}
|
|
||||||
commit_author = commit.get("author") if isinstance(commit.get("author"), dict) else {}
|
|
||||||
email = str(commit_author.get("email") or "").strip()
|
|
||||||
provider_author = item.get("author") if isinstance(item.get("author"), dict) else {}
|
|
||||||
login = str(provider_author.get("login") or "").strip()
|
|
||||||
|
|
||||||
if not login:
|
|
||||||
diagnostic_email = email or "<missing>"
|
|
||||||
print(
|
|
||||||
f"BLOCK: commit {sha!r} has author.login=NULL while "
|
|
||||||
f"commit.author.email={diagnostic_email!r}; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
if (
|
|
||||||
not email.isascii()
|
|
||||||
or not email.isprintable()
|
|
||||||
or not re.fullmatch(r"[A-Za-z0-9_.-]+", login)
|
|
||||||
or not re.fullmatch(r"[^<>\s]+@[^<>\s]+", email)
|
|
||||||
):
|
|
||||||
print(
|
|
||||||
f"BLOCK: commit {sha!r} has unusable linked identity "
|
|
||||||
f"author.login={login!r}, commit.author.email={email!r}; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
if login == poster or login in seen:
|
|
||||||
continue
|
|
||||||
seen.add(login)
|
|
||||||
trailers.append(f"Co-authored-by: {login} <{email}>")
|
|
||||||
|
|
||||||
if not head_seen:
|
|
||||||
print(
|
|
||||||
f"BLOCK: inspected PR head is absent from commit enumeration; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
if not trailers:
|
|
||||||
print("{}")
|
|
||||||
raise SystemExit(0)
|
|
||||||
if not title:
|
|
||||||
print(
|
|
||||||
f"BLOCK: PR title is empty; refusing merge; escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
if not title.isprintable() or re.match(r"^[A-Za-z-]+-[Bb]y:", title):
|
|
||||||
print(
|
|
||||||
f"BLOCK: PR title is not one printable, non-trailer line; refusing merge; "
|
|
||||||
f"escalate to named principal '{principal}'.",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(75)
|
|
||||||
|
|
||||||
print(json.dumps({
|
|
||||||
"MergeTitleField": title,
|
|
||||||
"MergeMessageField": "\n".join(trailers),
|
|
||||||
}, separators=(",", ":")))
|
|
||||||
PY
|
|
||||||
}
|
|
||||||
|
|
||||||
merge_gitea_api_attempt() {
|
|
||||||
local host="$1" auth_mode="$2" credential="$3"
|
|
||||||
local api_url attempt_dir body_file raw_code commits_file fields_file context_file head_file payload_file work_root attempt_rc auth_config curl_rc
|
|
||||||
LAST_GITEA_HTTP_CODE="000"
|
|
||||||
LAST_GITEA_ERROR=""
|
|
||||||
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}/merge"
|
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}/merge"
|
||||||
work_root="${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}"
|
mkdir -p "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}"
|
||||||
mkdir -p "$work_root"
|
body_file=$(mktemp "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}/pr-merge-api-response.XXXXXX")
|
||||||
attempt_dir=$(mktemp -d "$work_root/pr-merge-attempt.XXXXXX")
|
payload=$(python3 - "$HEAD_SHA" "$DELETE_BRANCH" <<'PY'
|
||||||
chmod 0700 "$attempt_dir"
|
|
||||||
MERGE_TEMP_DIRS+=("$attempt_dir")
|
|
||||||
body_file=$(mktemp "$attempt_dir/api-response.XXXXXX")
|
|
||||||
fields_file=$(mktemp "$attempt_dir/message-fields.XXXXXX")
|
|
||||||
payload_file=$(mktemp "$attempt_dir/payload.XXXXXX")
|
|
||||||
printf '{}' > "$fields_file"
|
|
||||||
|
|
||||||
if [[ "$CO_AUTHOR_TRAILERS" == true ]]; then
|
|
||||||
commits_file=$(mktemp "$attempt_dir/pr-merge-commits-input.XXXXXX")
|
|
||||||
context_file=$(mktemp "$attempt_dir/pr-merge-message-context.XXXXXX")
|
|
||||||
head_file=$(mktemp "$attempt_dir/pr-merge-head-input.XXXXXX")
|
|
||||||
printf '%s\0%s\0%s\0' "$PR_AUTHOR" "$PR_TITLE" "$ESCALATE_TO" > "$context_file"
|
|
||||||
if fetch_gitea_pr_head "$host" "$auth_mode" "$credential" "$attempt_dir" > "$head_file"; then
|
|
||||||
:
|
|
||||||
else
|
|
||||||
attempt_rc=$?
|
|
||||||
rm -f "$body_file" "$fields_file" "$payload_file" "$commits_file" "$context_file" "$head_file"
|
|
||||||
return "$attempt_rc"
|
|
||||||
fi
|
|
||||||
if [[ "$(<"$head_file")" != "$HEAD_SHA" ]]; then
|
|
||||||
echo "BLOCK: authenticated PR head moved from reviewed $HEAD_SHA to $(<"$head_file"); refusing merge; escalate to named principal '$ESCALATE_TO'." >&2
|
|
||||||
rm -f "$body_file" "$fields_file" "$payload_file" "$commits_file" "$context_file" "$head_file"
|
|
||||||
return 75
|
|
||||||
fi
|
|
||||||
if fetch_gitea_pr_commits "$host" "$auth_mode" "$credential" "$attempt_dir" > "$commits_file"; then
|
|
||||||
:
|
|
||||||
else
|
|
||||||
attempt_rc=$?
|
|
||||||
rm -f "$body_file" "$fields_file" "$payload_file" "$commits_file" "$context_file" "$head_file"
|
|
||||||
return "$attempt_rc"
|
|
||||||
fi
|
|
||||||
if build_coauthor_message_fields "$commits_file" "$context_file" "$head_file" > "$fields_file"; then
|
|
||||||
:
|
|
||||||
else
|
|
||||||
attempt_rc=$?
|
|
||||||
rm -f "$body_file" "$fields_file" "$payload_file" "$commits_file" "$context_file" "$head_file"
|
|
||||||
return "$attempt_rc"
|
|
||||||
fi
|
|
||||||
rm -f "$commits_file" "$context_file" "$head_file"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! python3 - "$fields_file" "$HEAD_SHA" "$DELETE_BRANCH" > "$payload_file" <<'PY'
|
|
||||||
import json
|
import json
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
with open(sys.argv[1], encoding="utf-8") as handle:
|
head_sha, delete_branch = sys.argv[1:]
|
||||||
fields = json.load(handle)
|
|
||||||
head_sha, delete_branch = sys.argv[2:]
|
|
||||||
payload = {"Do": "squash", "head_commit_id": head_sha}
|
payload = {"Do": "squash", "head_commit_id": head_sha}
|
||||||
if delete_branch == "true":
|
if delete_branch == "true":
|
||||||
payload["delete_branch_after_merge"] = True
|
payload["delete_branch_after_merge"] = True
|
||||||
payload.update(fields)
|
|
||||||
allowed = {"Do", "head_commit_id", "delete_branch_after_merge", "MergeTitleField", "MergeMessageField"}
|
|
||||||
if payload.get("Do") != "squash" or set(payload) - allowed:
|
|
||||||
raise SystemExit(1)
|
|
||||||
print(json.dumps(payload, separators=(",", ":")))
|
print(json.dumps(payload, separators=(",", ":")))
|
||||||
PY
|
PY
|
||||||
then
|
)
|
||||||
rm -f "$body_file" "$fields_file" "$payload_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
rm -f "$fields_file"
|
|
||||||
|
|
||||||
if ! auth_config=$(write_curl_auth_config "$auth_mode" "$credential"); then
|
token=$(get_gitea_token "$host" || true)
|
||||||
echo "Error: Could not construct Gitea authentication config; refusing request." >&2
|
if [[ -n "$token" ]]; then
|
||||||
rm -f "$body_file" "$payload_file"
|
raw_code=$(curl -sS -w '%{http_code}' -o "$body_file" \
|
||||||
return 1
|
-X POST \
|
||||||
|
-H "User-Agent: curl/8" \
|
||||||
|
-H "Authorization: token $token" \
|
||||||
|
-H 'Content-Type: application/json' \
|
||||||
|
-d "$payload" \
|
||||||
|
"$api_url" || true)
|
||||||
|
if [[ "$raw_code" =~ ^2 ]]; then
|
||||||
|
rm -f "$body_file"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
raw_code=$(curl -sS -K - "${GITEA_CURL_BOUNDS[@]}" -w '%{http_code}' -o "$body_file" \
|
|
||||||
-X POST -H "User-Agent: curl/8" \
|
|
||||||
-H 'Content-Type: application/json' \
|
|
||||||
--data-binary "@$payload_file" "$api_url" <<<"$auth_config")
|
|
||||||
curl_rc=$?
|
|
||||||
LAST_GITEA_HTTP_CODE="${raw_code:-000}"
|
|
||||||
if [[ "$curl_rc" -ne 0 ]]; then
|
|
||||||
LAST_GITEA_ERROR="curl transport failed (rc=$curl_rc)"
|
|
||||||
rm -f "$body_file" "$payload_file"
|
|
||||||
rm -rf -- "$attempt_dir"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if [[ ! "$raw_code" =~ ^2 ]]; then
|
|
||||||
LAST_GITEA_ERROR=$(format_gitea_error_response "$body_file")
|
|
||||||
fi
|
|
||||||
rm -f "$body_file" "$payload_file"
|
|
||||||
rm -rf -- "$attempt_dir"
|
|
||||||
[[ "$raw_code" =~ ^2 ]]
|
|
||||||
}
|
|
||||||
|
|
||||||
merge_gitea_with_api() {
|
basic_auth=$(get_gitea_basic_auth "$host" || true)
|
||||||
local host="$1" token attempt_rc
|
if [[ -n "$basic_auth" ]]; then
|
||||||
|
raw_code=$(curl -sS -w '%{http_code}' -o "$body_file" \
|
||||||
|
-X POST \
|
||||||
|
-u "$basic_auth" \
|
||||||
|
-H "User-Agent: curl/8" \
|
||||||
|
-H 'Content-Type: application/json' \
|
||||||
|
-d "$payload" \
|
||||||
|
"$api_url" || true)
|
||||||
|
if [[ "$raw_code" =~ ^2 ]]; then
|
||||||
|
rm -f "$body_file"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
if ! token=$(get_gitea_token "$host"); then
|
python3 - "${raw_code:-000}" "$body_file" <<'PY' >&2
|
||||||
echo "Error: Could not resolve the required Gitea token; refusing merge without changing principals." >&2
|
import json
|
||||||
return 1
|
import sys
|
||||||
fi
|
code, path = sys.argv[1], sys.argv[2]
|
||||||
if [[ -z "$token" ]]; then
|
try:
|
||||||
echo "Error: Required Gitea token resolved empty; refusing merge without changing principals." >&2
|
with open(path, encoding="utf-8", errors="replace") as handle:
|
||||||
return 1
|
raw = handle.read(500)
|
||||||
fi
|
data = json.loads(raw) if raw else {}
|
||||||
if merge_gitea_api_attempt "$host" token "$token"; then
|
message = data.get("message") or data.get("error") or raw or "empty response"
|
||||||
return 0
|
except Exception:
|
||||||
else
|
try:
|
||||||
attempt_rc=$?
|
message = open(path, encoding="utf-8", errors="replace").read(500) or "empty response"
|
||||||
fi
|
except Exception:
|
||||||
if [[ "$attempt_rc" -eq 75 ]]; then
|
message = "unreadable response"
|
||||||
return 75
|
print(f"Error: Gitea API merge failed with HTTP {code}: {message}")
|
||||||
fi
|
PY
|
||||||
if [[ "$LAST_GITEA_HTTP_CODE" != "401" ]]; then
|
rm -f "$body_file"
|
||||||
echo "Error: Gitea API merge failed with the identity-bound token (HTTP ${LAST_GITEA_HTTP_CODE:-000}).${LAST_GITEA_ERROR:+ Provider response: $LAST_GITEA_ERROR}" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo "Error: Gitea API rejected the identity-bound token with HTTP 401; refusing cross-principal credential fallback." >&2
|
|
||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -602,10 +195,11 @@ if [[ "$DRY_RUN" == true ]]; then
|
|||||||
echo "Error: Cannot determine host from origin remote URL" >&2
|
echo "Error: Cannot determine host from origin remote URL" >&2
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
if [[ "$CO_AUTHOR_TRAILERS" == true ]]; then
|
TEA_LOGIN="$(get_gitea_login_for_host "$HOST" || true)"
|
||||||
echo "Dry run: would verify PR commit authors and merge PR #$PR_NUMBER on $HOST with authenticated Gitea API message fields (base=$BASE_BRANCH, method=squash)."
|
if [[ -n "$TEA_LOGIN" ]]; then
|
||||||
|
echo "Dry run: would merge PR #$PR_NUMBER on $HOST with tea login '$TEA_LOGIN' (base=$BASE_BRANCH, method=squash)."
|
||||||
else
|
else
|
||||||
echo "Dry run: would merge PR #$PR_NUMBER on $HOST with the authenticated exact-head Gitea API path (base=$BASE_BRANCH, method=squash)."
|
echo "Dry run: would merge PR #$PR_NUMBER on $HOST with authenticated Gitea API fallback (base=$BASE_BRANCH, method=squash)."
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "Dry run: would merge PR #$PR_NUMBER on $PLATFORM (base=$BASE_BRANCH, method=squash)."
|
echo "Dry run: would merge PR #$PR_NUMBER on $PLATFORM (base=$BASE_BRANCH, method=squash)."
|
||||||
@@ -615,10 +209,6 @@ fi
|
|||||||
|
|
||||||
case "$PLATFORM" in
|
case "$PLATFORM" in
|
||||||
github)
|
github)
|
||||||
if [[ "$CO_AUTHOR_TRAILERS" == true ]]; then
|
|
||||||
echo "Error: --co-author-trailers currently requires the Gitea REST message-field contract." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
cmd=(gh pr merge "$PR_NUMBER" --squash --match-head-commit "$HEAD_SHA")
|
cmd=(gh pr merge "$PR_NUMBER" --squash --match-head-commit "$HEAD_SHA")
|
||||||
[[ "$DELETE_BRANCH" == true ]] && cmd+=(--delete-branch)
|
[[ "$DELETE_BRANCH" == true ]] && cmd+=(--delete-branch)
|
||||||
"${cmd[@]}"
|
"${cmd[@]}"
|
||||||
@@ -629,7 +219,7 @@ case "$PLATFORM" in
|
|||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
# Gitea's API head_commit_id is an atomic compare-and-merge precondition.
|
# Gitea's API head_commit_id is an atomic compare-and-merge precondition.
|
||||||
# tea cannot express it, so every Gitea merge uses the authenticated API path.
|
# tea cannot express it, so exact-head merges use the authenticated API path.
|
||||||
merge_gitea_with_api "$HOST"
|
merge_gitea_with_api "$HOST"
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
|
|||||||
@@ -9,51 +9,10 @@ WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/ci-queue-wait-tristate}
|
|||||||
REPO_DIR="$WORK_DIR/repo"
|
REPO_DIR="$WORK_DIR/repo"
|
||||||
STUB_DIR="$WORK_DIR/stubs"
|
STUB_DIR="$WORK_DIR/stubs"
|
||||||
AUDIT_LOG="$WORK_DIR/audit/ci-queue-wait.jsonl"
|
AUDIT_LOG="$WORK_DIR/audit/ci-queue-wait.jsonl"
|
||||||
STATUS_OBSERVED="$WORK_DIR/status-observed"
|
|
||||||
CLOCK_LOG="$WORK_DIR/clock.log"
|
|
||||||
WATCHDOG_PYTHON="/usr/bin/python3"
|
|
||||||
WATCHDOG_SCRIPT="$WORK_DIR/real-clock-watchdog.py"
|
|
||||||
WATCHDOG_TIMEOUT_SEC=5
|
|
||||||
WATCHDOG_EXIT=90
|
|
||||||
FEATURE_BRANCH="fix/rm-03-fixture"
|
FEATURE_BRANCH="fix/rm-03-fixture"
|
||||||
|
|
||||||
if [[ ! -x "$WATCHDOG_PYTHON" ]]; then
|
|
||||||
echo "FAIL setup: required real-clock watchdog runtime is unavailable at $WATCHDOG_PYTHON" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
rm -rf "$WORK_DIR"
|
rm -rf "$WORK_DIR"
|
||||||
mkdir -p "$REPO_DIR" "$STUB_DIR"
|
mkdir -p "$REPO_DIR" "$STUB_DIR"
|
||||||
cat > "$WATCHDOG_SCRIPT" <<'PY'
|
|
||||||
import os
|
|
||||||
import signal
|
|
||||||
import subprocess
|
|
||||||
import sys
|
|
||||||
|
|
||||||
if len(sys.argv) < 3:
|
|
||||||
raise SystemExit(2)
|
|
||||||
|
|
||||||
timeout_seconds = float(sys.argv[1])
|
|
||||||
process = subprocess.Popen(sys.argv[2:], start_new_session=True)
|
|
||||||
try:
|
|
||||||
return_code = process.wait(timeout=timeout_seconds)
|
|
||||||
except subprocess.TimeoutExpired:
|
|
||||||
try:
|
|
||||||
os.killpg(process.pid, signal.SIGKILL)
|
|
||||||
except ProcessLookupError:
|
|
||||||
pass
|
|
||||||
process.wait()
|
|
||||||
print(
|
|
||||||
f"FAIL HANG watchdog: subject exceeded {timeout_seconds:g}s "
|
|
||||||
"before completing its intended path",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(90)
|
|
||||||
|
|
||||||
if return_code < 0:
|
|
||||||
raise SystemExit(128 - return_code)
|
|
||||||
raise SystemExit(return_code)
|
|
||||||
PY
|
|
||||||
git -C "$REPO_DIR" init -q
|
git -C "$REPO_DIR" init -q
|
||||||
git -C "$REPO_DIR" checkout -q -b "$FEATURE_BRANCH"
|
git -C "$REPO_DIR" checkout -q -b "$FEATURE_BRANCH"
|
||||||
git -C "$REPO_DIR" remote add origin https://git.example.test/acme/widgets.git
|
git -C "$REPO_DIR" remote add origin https://git.example.test/acme/widgets.git
|
||||||
@@ -74,9 +33,6 @@ printf '%s\n' "$url" >> "${MOSAIC_STUB_URL_LOG:?}"
|
|||||||
|
|
||||||
case "$url" in
|
case "$url" in
|
||||||
*/branches/*)
|
*/branches/*)
|
||||||
if [[ "${MOSAIC_STUB_BRANCH_MODE:-ok}" == "hang-before-provider" ]]; then
|
|
||||||
while :; do :; done
|
|
||||||
fi
|
|
||||||
if [[ "${MOSAIC_STUB_BRANCH_MODE:-ok}" == "unreachable" ]]; then
|
if [[ "${MOSAIC_STUB_BRANCH_MODE:-ok}" == "unreachable" ]]; then
|
||||||
exit 7
|
exit 7
|
||||||
fi
|
fi
|
||||||
@@ -88,7 +44,6 @@ case "$url" in
|
|||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
*/status)
|
*/status)
|
||||||
: > "${MOSAIC_STUB_STATUS_OBSERVED:?}"
|
|
||||||
case "${MOSAIC_STUB_STATUS_MODE:?}" in
|
case "${MOSAIC_STUB_STATUS_MODE:?}" in
|
||||||
success) printf '%s' '{"state":"success","statuses":[{"status":"success"}]}' ;;
|
success) printf '%s' '{"state":"success","statuses":[{"status":"success"}]}' ;;
|
||||||
pending) printf '%s' '{"state":"pending","statuses":[{"status":"pending","context":"ci/test"}]}' ;;
|
pending) printf '%s' '{"state":"pending","statuses":[{"status":"pending","context":"ci/test"}]}' ;;
|
||||||
@@ -108,31 +63,7 @@ case "$url" in
|
|||||||
*) echo "unexpected curl URL: $url" >&2; exit 2 ;;
|
*) echo "unexpected curl URL: $url" >&2; exit 2 ;;
|
||||||
esac
|
esac
|
||||||
SH
|
SH
|
||||||
|
chmod +x "$STUB_DIR/curl"
|
||||||
cat > "$STUB_DIR/date" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
if [[ "$#" -ne 1 || "$1" != "+%s" ]]; then
|
|
||||||
echo "unexpected date invocation: $*" >&2
|
|
||||||
exit 2
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ -e "${MOSAIC_STUB_STATUS_OBSERVED:?}" ]]; then
|
|
||||||
printf 'date-phase=after-status\n' >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
printf '1002\n'
|
|
||||||
else
|
|
||||||
printf 'date-phase=before-status\n' >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
printf '1000\n'
|
|
||||||
fi
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$STUB_DIR/sleep" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
printf 'sleep-after-status=%s\n' "$*" >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
SH
|
|
||||||
chmod +x "$STUB_DIR/curl" "$STUB_DIR/date" "$STUB_DIR/sleep"
|
|
||||||
|
|
||||||
run_guard() {
|
run_guard() {
|
||||||
local status_mode="$1"
|
local status_mode="$1"
|
||||||
@@ -152,46 +83,13 @@ run_guard() {
|
|||||||
export GITEA_URL=https://git.example.test
|
export GITEA_URL=https://git.example.test
|
||||||
export MOSAIC_STUB_STATUS_MODE="$status_mode"
|
export MOSAIC_STUB_STATUS_MODE="$status_mode"
|
||||||
fi
|
fi
|
||||||
rm -f "$STATUS_OBSERVED" "$CLOCK_LOG"
|
|
||||||
export MOSAIC_STUB_URL_LOG="$WORK_DIR/urls.log"
|
export MOSAIC_STUB_URL_LOG="$WORK_DIR/urls.log"
|
||||||
export MOSAIC_STUB_STATUS_OBSERVED="$STATUS_OBSERVED"
|
|
||||||
export MOSAIC_STUB_CLOCK_LOG="$CLOCK_LOG"
|
|
||||||
export MOSAIC_CI_QUEUE_AUDIT_LOG="$audit_log"
|
export MOSAIC_CI_QUEUE_AUDIT_LOG="$audit_log"
|
||||||
# Provider observation is the synchronization event. The one-second
|
"$SCRIPT_DIR/ci-queue-wait.sh" --purpose "${MOSAIC_TEST_PURPOSE:-push}" -t 0 -i 0 "$@"
|
||||||
# timeout is subject semantics under virtual time, never a wall wait.
|
|
||||||
# The absolute Python runtime uses an internal monotonic wait and kills
|
|
||||||
# the subject's isolated process group. Neither operation can resolve
|
|
||||||
# to the virtual date/sleep stubs at the front of PATH.
|
|
||||||
local subject_rc
|
|
||||||
if "$WATCHDOG_PYTHON" "$WATCHDOG_SCRIPT" "$WATCHDOG_TIMEOUT_SEC" \
|
|
||||||
"$SCRIPT_DIR/ci-queue-wait.sh" --purpose "${MOSAIC_TEST_PURPOSE:-push}" -t 1 -i 1 "$@"; then
|
|
||||||
subject_rc=0
|
|
||||||
else
|
|
||||||
subject_rc=$?
|
|
||||||
fi
|
|
||||||
return "$subject_rc"
|
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
failures=0
|
failures=0
|
||||||
assert_provider_observed() {
|
|
||||||
local name="$1" require_expiration="${2:-0}"
|
|
||||||
if [[ ! -e "$STATUS_OBSERVED" ]]; then
|
|
||||||
echo "FAIL $name: status provider was not observed" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ ! -s "$CLOCK_LOG" ]] || ! grep -q '^date-phase=before-status$' "$CLOCK_LOG"; then
|
|
||||||
echo "FAIL $name: virtual clock interception did not run before provider observation" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$require_expiration" -eq 1 ]]; then
|
|
||||||
if ! grep -q '^sleep-after-status=' "$CLOCK_LOG" || ! grep -q '^date-phase=after-status$' "$CLOCK_LOG"; then
|
|
||||||
echo "FAIL $name: pending path did not expire after provider observation" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
run_assertion() {
|
run_assertion() {
|
||||||
local name="$1" expected_rc="$2" status_mode="$3" required_text="$4"
|
local name="$1" expected_rc="$2" status_mode="$3" required_text="$4"
|
||||||
local output rc
|
local output rc
|
||||||
@@ -226,13 +124,6 @@ run_assertion() {
|
|||||||
printf '%s\n' "$output" >&2
|
printf '%s\n' "$output" >&2
|
||||||
failures=$((failures + 1))
|
failures=$((failures + 1))
|
||||||
fi
|
fi
|
||||||
if [[ "$status_mode" != "credential-unresolvable" ]]; then
|
|
||||||
if [[ "$status_mode" == "pending" ]]; then
|
|
||||||
assert_provider_observed "$name" 1
|
|
||||||
else
|
|
||||||
assert_provider_observed "$name"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
}
|
}
|
||||||
|
|
||||||
set -e
|
set -e
|
||||||
@@ -249,27 +140,6 @@ run_assertion large-payload not126 large-success 'state=terminal-success'
|
|||||||
run_assertion credential-unresolvable zero credential-unresolvable 'CANNOT_ASSERT'
|
run_assertion credential-unresolvable zero credential-unresolvable 'CANNOT_ASSERT'
|
||||||
run_assertion provider-unreachable zero unreachable 'CANNOT_ASSERT'
|
run_assertion provider-unreachable zero unreachable 'CANNOT_ASSERT'
|
||||||
|
|
||||||
# Positive liveness control: a subject mutant hangs before the branch lookup
|
|
||||||
# can reach the status provider. Only the independent real-clock watchdog may
|
|
||||||
# terminate it, and its failure must be distinct from subject timeout rc=124.
|
|
||||||
set +e
|
|
||||||
watchdog_output=$(MOSAIC_STUB_BRANCH_MODE=hang-before-provider run_guard success "$AUDIT_LOG" 2>&1)
|
|
||||||
watchdog_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$watchdog_rc" -ne "$WATCHDOG_EXIT" ]]; then
|
|
||||||
echo "FAIL watchdog-control: expected hang-specific rc=$WATCHDOG_EXIT, got rc=$watchdog_rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$watchdog_output" != *"FAIL HANG watchdog:"* ]]; then
|
|
||||||
echo "FAIL watchdog-control: expected distinct hang-specific diagnostic" >&2
|
|
||||||
printf '%s\n' "$watchdog_output" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ -e "$STATUS_OBSERVED" ]]; then
|
|
||||||
echo "FAIL watchdog-control: hanging mutant unexpectedly reached the status provider" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ ! -s "$AUDIT_LOG" ]] || ! grep -q '"outcome":"CANNOT_ASSERT"' "$AUDIT_LOG"; then
|
if [[ ! -s "$AUDIT_LOG" ]] || ! grep -q '"outcome":"CANNOT_ASSERT"' "$AUDIT_LOG"; then
|
||||||
echo "FAIL provider-unreachable-audit: expected durable CANNOT_ASSERT JSONL record" >&2
|
echo "FAIL provider-unreachable-audit: expected durable CANNOT_ASSERT JSONL record" >&2
|
||||||
failures=$((failures + 1))
|
failures=$((failures + 1))
|
||||||
@@ -290,7 +160,6 @@ if [[ "$merge_unreachable_output" != *"CANNOT_ASSERT"* ]]; then
|
|||||||
echo "FAIL merge-provider-unreachable: expected loud CANNOT_ASSERT diagnostic" >&2
|
echo "FAIL merge-provider-unreachable: expected loud CANNOT_ASSERT diagnostic" >&2
|
||||||
failures=$((failures + 1))
|
failures=$((failures + 1))
|
||||||
fi
|
fi
|
||||||
assert_provider_observed merge-provider-unreachable
|
|
||||||
merge_audit_lines_after=$(wc -l < "$AUDIT_LOG")
|
merge_audit_lines_after=$(wc -l < "$AUDIT_LOG")
|
||||||
if [[ "$merge_audit_lines_after" -le "$merge_audit_lines_before" ]]; then
|
if [[ "$merge_audit_lines_after" -le "$merge_audit_lines_before" ]]; then
|
||||||
echo "FAIL merge-provider-unreachable: expected an additional audit record" >&2
|
echo "FAIL merge-provider-unreachable: expected an additional audit record" >&2
|
||||||
@@ -354,7 +223,6 @@ if [[ "$audit_failure_output" != *"audit"* ]]; then
|
|||||||
echo "FAIL audit-unavailable: expected loud audit failure diagnostic" >&2
|
echo "FAIL audit-unavailable: expected loud audit failure diagnostic" >&2
|
||||||
failures=$((failures + 1))
|
failures=$((failures + 1))
|
||||||
fi
|
fi
|
||||||
assert_provider_observed audit-unavailable
|
|
||||||
|
|
||||||
if [[ "$failures" -ne 0 ]]; then
|
if [[ "$failures" -ne 0 ]]; then
|
||||||
echo "ci-queue-wait tri-state regression failed ($failures assertions)" >&2
|
echo "ci-queue-wait tri-state regression failed ($failures assertions)" >&2
|
||||||
|
|||||||
@@ -1,58 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
# Regression: detect_platform / get_repo_info must FAIL LOUDLY outside a git repo,
|
|
||||||
# not kill the caller silently.
|
|
||||||
#
|
|
||||||
# Both functions already contained the right error path:
|
|
||||||
# if [[ -z "$remote_url" ]]; then echo "error: not a git repository..." >&2; return 1; fi
|
|
||||||
# but under `set -e` -- which every wrapper in this directory uses -- the preceding
|
|
||||||
# assignment `remote_url=$(git remote get-url origin 2>/dev/null)` returns git's 128
|
|
||||||
# outside a repo and terminates the CALLER first. The message was unreachable.
|
|
||||||
#
|
|
||||||
# Observed cost: pr-review.sh invoked from a non-repo cwd exits 128 with NO stdout and
|
|
||||||
# NO stderr, even when -r/--repo and -H/--host are supplied -- the flags documented as
|
|
||||||
# "skips git-remote inference". Two reviewer seats hit this and correctly reported
|
|
||||||
# `blocked` with no diagnostic to report.
|
|
||||||
#
|
|
||||||
# The control that matters is the LOUD one: asserting "rc != 0" passes on the broken
|
|
||||||
# build too, because 128 is also non-zero. The test must assert the MESSAGE.
|
|
||||||
set -uo pipefail
|
|
||||||
fail=0
|
|
||||||
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT
|
|
||||||
|
|
||||||
run_outside() { # $1=function name -> "rc:sawmessage"
|
|
||||||
local fn="$1" out rc
|
|
||||||
out=$( cd "$TMP" && bash -c "set -e; source '$HERE/detect-platform.sh'; $fn" 2>&1 ); rc=$?
|
|
||||||
printf '%s:%s' "$rc" "$(grep -qi 'not a git repository' <<<"$out" && echo yes || echo no)"
|
|
||||||
}
|
|
||||||
check() { if [ "$2" = "$3" ]; then echo " PASS $1 ($2)"; else echo " FAIL $1: got $2, want $3"; fail=1; fi; }
|
|
||||||
|
|
||||||
# $TMP must not be inside a git repo. Do not SKIP on failure: be-coder-07 showed the
|
|
||||||
# original SKIP exited 0, so pointing TMPDIR beneath a git worktree made this test PASS
|
|
||||||
# against unchanged main. A skip that exits 0 is indistinguishable from a pass.
|
|
||||||
# GIT_CEILING_DIRECTORIES stops git walking above $TMP, making the condition hold
|
|
||||||
# regardless of where TMPDIR lives, rather than merely detecting when it does not.
|
|
||||||
# GIT_CEILING_DIRECTORIES is matched against the PHYSICAL path -- a symlinked TMPDIR
|
|
||||||
# (/tmp is commonly one) makes the logical path never match, and the ceiling silently
|
|
||||||
# does nothing. Resolve it before exporting.
|
|
||||||
TMP="$(cd "$TMP" && pwd -P)"
|
|
||||||
export GIT_CEILING_DIRECTORIES="$TMP"
|
|
||||||
if ( cd "$TMP" && git rev-parse --git-dir >/dev/null 2>&1 ); then
|
|
||||||
echo " FAIL scratch dir is inside a git repo even with GIT_CEILING_DIRECTORIES set;"
|
|
||||||
echo " the outside-a-repo precondition cannot be established -- refusing to report a result"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "== outside a git repo: rc=1 AND the diagnostic is emitted =="
|
|
||||||
check "detect_platform" "$(run_outside detect_platform)" "1:yes"
|
|
||||||
check "get_repo_info" "$(run_outside get_repo_info)" "1:yes"
|
|
||||||
|
|
||||||
echo "== inside a git repo the functions still work =="
|
|
||||||
git init -q "$TMP/repo" 2>/dev/null
|
|
||||||
git -C "$TMP/repo" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git 2>/dev/null
|
|
||||||
out=$( cd "$TMP/repo" && bash -c "set -e; source '$HERE/detect-platform.sh'; detect_platform" 2>&1 ); rc=$?
|
|
||||||
if [ "$rc" -eq 0 ] && grep -qi 'gitea' <<<"$out"; then echo " PASS detect_platform in-repo (rc=0, $out)"
|
|
||||||
else echo " FAIL detect_platform in-repo: rc=$rc out=$out"; fail=1; fi
|
|
||||||
|
|
||||||
[ "$fail" -eq 0 ] && echo "OK detect-platform fails loudly outside a repo" || echo "FAILED"
|
|
||||||
exit "$fail"
|
|
||||||
@@ -1,64 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
# Regression: the tea-failure diagnostic must be STATUS-NEUTRAL.
|
|
||||||
#
|
|
||||||
# Found by be-coder-08 reviewing PR #1086. At all three call sites the diagnostic is emitted
|
|
||||||
# immediately BEFORE the Gitea API fallback. Written as the last command of an && list:
|
|
||||||
# declare -F explain_... >/dev/null && explain_...
|
|
||||||
# under `set -e` a FAILING diagnostic exits and the fallback never runs -- a diagnostic that
|
|
||||||
# suppresses the recovery path it exists to explain. It misbehaves ONLY when the helper is
|
|
||||||
# PRESENT, so the helper-absent path (pre-#1086 behaviour) keeps working and reads as a
|
|
||||||
# passing control.
|
|
||||||
#
|
|
||||||
# TWO DEFECTS IN THE FIRST VERSION OF THIS TEST, both found by be-coder-08:
|
|
||||||
# 1. `out=$( ... ) 2>"$errto"` applies the redirection to the ASSIGNMENT, not to the
|
|
||||||
# command substitution, so the probe's stderr was never actually pointed at /dev/full
|
|
||||||
# and the /dev/full rows proved nothing. Verified: `out=$(echo x >&2) 2>/dev/full`
|
|
||||||
# leaks to the terminal and returns 0; the redirect must be INSIDE the substitution.
|
|
||||||
# 2. `eval "$CONSTRUCT"` changes `set -e` semantics for a bare && list, so the probe did
|
|
||||||
# not exercise the construct as the shipped file executes it. It now writes the line
|
|
||||||
# into a real script and runs it -- same parse, same set -e rules, no eval.
|
|
||||||
# The construct is still LIFTED FROM THE SHIPPED FILE: retyping the fixed form makes the
|
|
||||||
# probe pass on a build whose real call sites still carry the bare && form.
|
|
||||||
set -uo pipefail
|
|
||||||
fail=0
|
|
||||||
GIT_DIR_UNDER_TEST="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT
|
|
||||||
|
|
||||||
probe() { # $1=present|absent $2=stderr target $3=source file -> "rc:fallback"
|
|
||||||
local helper="$1" errto="$2" src="$3" construct script out rc
|
|
||||||
construct=$(grep -m1 'explain_tea_user_does_not_exist' "$GIT_DIR_UNDER_TEST/$src" | sed 's/^[[:space:]]*//')
|
|
||||||
[ -n "$construct" ] || { printf 'no-construct:no'; return; }
|
|
||||||
script="$TMP/probe.sh"
|
|
||||||
{
|
|
||||||
echo '#!/bin/bash'
|
|
||||||
echo 'set -e'
|
|
||||||
echo 'explain_tea_user_does_not_exist() { echo "diagnostic" >&2; }'
|
|
||||||
[ "$helper" = absent ] && echo 'unset -f explain_tea_user_does_not_exist'
|
|
||||||
echo "$construct" # the shipped line, parsed by a real shell
|
|
||||||
echo 'echo FALLBACK_REACHED'
|
|
||||||
} > "$script"
|
|
||||||
# redirect INSIDE the substitution so the subshell's stderr really is $errto
|
|
||||||
out=$( bash "$script" 2>"$errto" ); rc=$?
|
|
||||||
printf '%s:%s' "$rc" "$(grep -q FALLBACK_REACHED <<<"$out" && echo yes || echo no)"
|
|
||||||
}
|
|
||||||
|
|
||||||
check() { if [ "$2" = "$3" ]; then echo " PASS $1 ($2)"; else echo " FAIL $1: got $2, want $3"; fail=1; fi; }
|
|
||||||
|
|
||||||
echo "== diagnostic must not alter exit status or skip the fallback =="
|
|
||||||
# /dev/full makes every stderr write fail -- the real-world shape is a closed or full fd.
|
|
||||||
for src in pr-create.sh issue-view.sh issue-create.sh; do
|
|
||||||
check "$src stderr OK / helper present" "$(probe present /dev/null "$src")" "0:yes"
|
|
||||||
check "$src stderr OK / helper absent " "$(probe absent /dev/null "$src")" "0:yes"
|
|
||||||
check "$src stderr FAILING / helper present" "$(probe present /dev/full "$src")" "0:yes"
|
|
||||||
check "$src stderr FAILING / helper absent " "$(probe absent /dev/full "$src")" "0:yes"
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "== all three call sites use the status-neutral form =="
|
|
||||||
for f in pr-create.sh issue-view.sh issue-create.sh; do
|
|
||||||
p="$GIT_DIR_UNDER_TEST/$f"
|
|
||||||
grep -q '{ declare -F explain_tea_user_does_not_exist >/dev/null && explain_tea_user_does_not_exist; } || true' "$p" \
|
|
||||||
&& echo " PASS $f guarded" || { echo " FAIL $f: diagnostic is not status-neutral"; fail=1; }
|
|
||||||
done
|
|
||||||
|
|
||||||
[ "$fail" -eq 0 ] && echo "OK diagnostic is status-neutral" || echo "FAILED"
|
|
||||||
exit "$fail"
|
|
||||||
@@ -1,150 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Regression: issue-close.sh must NOT close an issue when the closing comment could not
|
|
||||||
# be posted, and comment+close must be made by ONE principal.
|
|
||||||
#
|
|
||||||
# Guards two defects fixed together (see #1081):
|
|
||||||
# 1. `tea issue comment` is not a subcommand -- tea exposes comments as the TOP-LEVEL
|
|
||||||
# `tea comment`. The old call always failed, was unchecked, and the issue closed
|
|
||||||
# anyway, losing the record of WHY it was closed.
|
|
||||||
# 2. Routing the comment through the token-authenticated API helper while the close
|
|
||||||
# used --login would attribute one operation to two principals.
|
|
||||||
#
|
|
||||||
# SAFETY (rev-974, #1085 review 130): this test previously ran under `set -uo pipefail`
|
|
||||||
# with unchecked mkdir/redirect/cd, then prepended a possibly-nonexistent $MOCK_BIN to
|
|
||||||
# PATH -- while `git remote add origin` names the REAL repository. Forcing setup failure
|
|
||||||
# with an unwritable AGENT_WORK_ROOT made it `git init` in its CALLER's directory and
|
|
||||||
# invoke the real, provider-mutating issue-close.sh. Setup now fails closed, and both
|
|
||||||
# `tea` and `curl` are asserted to resolve INSIDE $MOCK_BIN before any target run.
|
|
||||||
set -euo pipefail
|
|
||||||
# NOTE: with `set -e`, `grep -q X && fail "..."` is a trap -- the ABSENT case (grep rc=1,
|
|
||||||
# which is the PASSING case for a must-not-appear assertion) is the last command of an &&
|
|
||||||
# list and silently terminates the script with no message. Every must-not-appear check
|
|
||||||
# below is therefore an if-block. This is the same set -e + &&-list defect be-coder-08
|
|
||||||
# found in #1086, reintroduced here by adding `set -e` for the sandbox-safety fix.
|
|
||||||
|
|
||||||
WORK_ROOT="${AGENT_WORK_ROOT:-${TMPDIR:-/tmp}}"
|
|
||||||
SANDBOX="$WORK_ROOT/issue-close-fail-closed-test-$$"
|
|
||||||
MOCK_BIN="$SANDBOX/bin"; REPO_DIR="$SANDBOX/repo"; CALLS="$SANDBOX/calls.log"
|
|
||||||
cleanup() { rm -rf "$SANDBOX"; }
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
TARGET="$SCRIPT_DIR/issue-close.sh"
|
|
||||||
[ -f "$TARGET" ] || { echo "FAIL: issue-close.sh not found beside this test"; exit 1; }
|
|
||||||
fail() { echo "FAIL: $*"; exit 1; }
|
|
||||||
|
|
||||||
# Every setup step is checked. Under `set -e` these abort; the explicit || fail keeps the
|
|
||||||
# reason legible instead of a bare non-zero exit.
|
|
||||||
mkdir -p "$MOCK_BIN" "$REPO_DIR" || fail "setup: cannot create sandbox under $WORK_ROOT"
|
|
||||||
: > "$CALLS" || fail "setup: cannot write calls log at $CALLS"
|
|
||||||
cd "$REPO_DIR" || fail "setup: cannot cd into $REPO_DIR"
|
|
||||||
git init -q || fail "setup: git init failed"
|
|
||||||
git remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git || fail "setup: git remote add failed"
|
|
||||||
export PATH="$MOCK_BIN:$PATH" CALLS
|
|
||||||
export GITEA_URL="https://git.mosaicstack.dev"
|
|
||||||
export GITEA_TOKEN="redacted-test-token"
|
|
||||||
|
|
||||||
cat > "$MOCK_BIN/curl" <<'EOF'
|
|
||||||
#!/bin/bash
|
|
||||||
method=GET; url=""
|
|
||||||
while [ $# -gt 0 ]; do
|
|
||||||
case "$1" in
|
|
||||||
-X) method="$2"; shift 2 ;;
|
|
||||||
http*|https*) url="$1"; shift ;;
|
|
||||||
*) shift ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
printf 'curl %s %s\n' "$method" "$url" >> "$CALLS"
|
|
||||||
[ "${MOCK_CURL_FAIL:-}" = "1" ] && [ "$method" = "POST" ] && exit 22
|
|
||||||
exit 0
|
|
||||||
EOF
|
|
||||||
chmod +x "$MOCK_BIN/curl"
|
|
||||||
|
|
||||||
mk_tea() { # $1 = exit code for a comment attempt; $2 = login list (empty => no login)
|
|
||||||
local rc="$1" login="${2-}"
|
|
||||||
cat > "$MOCK_BIN/tea" <<EOF
|
|
||||||
#!/bin/bash
|
|
||||||
printf 'tea %s\n' "\$*" >> "$CALLS"
|
|
||||||
if [[ "\$*" == *"login list"* ]]; then
|
|
||||||
printf '%s\n' '${login}'; exit 0
|
|
||||||
fi
|
|
||||||
# Fail ANY comment attempt -- both the correct top-level \`tea comment\` and the broken
|
|
||||||
# \`tea issue comment\` -- so an unfixed script exercises the DEFECT rather than tripping
|
|
||||||
# a setup assertion.
|
|
||||||
if [[ "\$1" == "comment" || ( "\$1" == "issue" && "\$2" == "comment" ) ]]; then exit $rc; fi
|
|
||||||
exit 0
|
|
||||||
EOF
|
|
||||||
chmod +x "$MOCK_BIN/tea"
|
|
||||||
}
|
|
||||||
LOGIN_JSON='[{"name":"git.mosaicstack.dev","url":"https://git.mosaicstack.dev"}]'
|
|
||||||
|
|
||||||
# The mocks must be the ones that run. Without this, a failed setup silently falls through
|
|
||||||
# to the real tea/curl and the "test" mutates the real provider.
|
|
||||||
assert_mocked() {
|
|
||||||
local w
|
|
||||||
for w in tea curl; do
|
|
||||||
p=$(command -v "$w" || true)
|
|
||||||
[ -n "$p" ] || fail "SAFETY: $w does not resolve at all"
|
|
||||||
case "$p" in
|
|
||||||
"$MOCK_BIN"/*) : ;;
|
|
||||||
*) fail "SAFETY: $w resolves to $p, OUTSIDE the sandbox -- refusing to invoke the target" ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
run_target() { # never let a target failure abort the test; we assert on rc
|
|
||||||
# Call sites MUST use `rc=0; run_target ... || rc=$?` -- a bare `run_target ...; rc=$?`
|
|
||||||
# lets the non-zero RETURN trip set -e in the CALLER before rc is ever read.
|
|
||||||
set +e; bash "$TARGET" "$@" >/dev/null 2>&1; local rc=$?; set -e; return $rc
|
|
||||||
}
|
|
||||||
|
|
||||||
# ── tea path ────────────────────────────────────────────────────────────────────────
|
|
||||||
# 1. NEGATIVE (the regression): comment fails => must NOT close, must exit non-zero
|
|
||||||
mk_tea 1 "$LOGIN_JSON"; : > "$CALLS"; assert_mocked
|
|
||||||
rc=0; run_target -i 42 -c "closing note" || rc=$?
|
|
||||||
grep -qE 'tea (issue )?comment' "$CALLS" || fail "no comment attempt -- setup did not reach the tea branch"
|
|
||||||
if grep -q 'tea issue close' "$CALLS"; then fail "ISSUE CLOSED AFTER THE COMMENT FAILED -- the regression"; fi
|
|
||||||
[ "$rc" -ne 0 ] || fail "comment failed but issue-close exited 0 -- FAIL-OPEN"
|
|
||||||
|
|
||||||
# 2. POSITIVE: comment succeeds => close proceeds, exit 0
|
|
||||||
mk_tea 0 "$LOGIN_JSON"; : > "$CALLS"; assert_mocked
|
|
||||||
rc=0; run_target -i 42 -c "closing note" || rc=$?
|
|
||||||
[ "$rc" -eq 0 ] || fail "comment succeeded but issue-close exited $rc"
|
|
||||||
grep -q 'tea issue close' "$CALLS" || fail "issue not closed even though the comment succeeded"
|
|
||||||
|
|
||||||
# 3. must use top-level `tea comment`, never `tea issue comment`
|
|
||||||
if grep -q 'tea issue comment' "$CALLS"; then fail "used 'tea issue comment' -- not a valid subcommand"; fi
|
|
||||||
|
|
||||||
# 4. ONE PRINCIPAL: comment and close must carry the SAME --login
|
|
||||||
c=$(grep -m1 '^tea comment' "$CALLS" | grep -o -- '--login [^ ]*' | awk '{print $2}')
|
|
||||||
k=$(grep -m1 '^tea issue close' "$CALLS" | grep -o -- '--login [^ ]*' | awk '{print $2}')
|
|
||||||
[ -n "$c" ] || fail "comment carried no --login"
|
|
||||||
[ "$c" = "$k" ] || fail "MIXED PRINCIPALS: comment=$c close=$k"
|
|
||||||
|
|
||||||
# ── no-login / API fallback path ────────────────────────────────────────────────────
|
|
||||||
# rev-974: the delta also adds fail-closed behaviour to this branch, and the suite never
|
|
||||||
# reached it -- replacing the whole fallback contract with an unconditional close still
|
|
||||||
# passed. These assert the POSTCONDITION (which HTTP calls happened, in what order),
|
|
||||||
# not merely that a command ran.
|
|
||||||
# 5. no login + comment FAILS => POST attempted, NO PATCH, non-zero
|
|
||||||
mk_tea 0 ""; : > "$CALLS"; assert_mocked
|
|
||||||
rc=0; MOCK_CURL_FAIL=1 run_target -i 42 -c "closing note" || rc=$?
|
|
||||||
grep -q 'curl POST' "$CALLS" || fail "API path: no comment POST attempted"
|
|
||||||
if grep -q 'curl PATCH' "$CALLS"; then fail "API path: ISSUE CLOSED (PATCH) AFTER THE COMMENT POST FAILED"; fi
|
|
||||||
[ "$rc" -ne 0 ] || fail "API path: comment failed but exited 0 -- FAIL-OPEN"
|
|
||||||
|
|
||||||
# 6. no login + comment SUCCEEDS => POST strictly BEFORE PATCH, exit 0
|
|
||||||
mk_tea 0 ""; : > "$CALLS"; assert_mocked
|
|
||||||
rc=0; run_target -i 42 -c "closing note" || rc=$?
|
|
||||||
[ "$rc" -eq 0 ] || fail "API path: comment succeeded but exited $rc"
|
|
||||||
order=$(grep -oE 'curl (POST|PATCH)' "$CALLS" | awk '{print $2}' | paste -sd, -)
|
|
||||||
[ "$order" = "POST,PATCH" ] || fail "API path: expected POST,PATCH -- got '${order:-<none>}'"
|
|
||||||
|
|
||||||
# 7. no login + NO comment => PATCH only, never a POST
|
|
||||||
mk_tea 0 ""; : > "$CALLS"; assert_mocked
|
|
||||||
rc=0; run_target -i 42 || rc=$?
|
|
||||||
[ "$rc" -eq 0 ] || fail "API path: no-comment close exited $rc"
|
|
||||||
if grep -q 'curl POST' "$CALLS"; then fail "API path: posted a comment when none was requested"; fi
|
|
||||||
grep -q 'curl PATCH' "$CALLS" || fail "API path: issue not closed when no comment was requested"
|
|
||||||
|
|
||||||
echo "issue-close.sh fail-closed + single-principal regression passed"
|
|
||||||
@@ -280,10 +280,7 @@ print("201")
|
|||||||
print(json.dumps(record))
|
print(json.dumps(record))
|
||||||
PY
|
PY
|
||||||
)
|
)
|
||||||
response_status="${result%%$'\n'*}"
|
write_response "$(printf '%s' "$result" | head -n1)" "$(printf '%s' "$result" | tail -n +2)"
|
||||||
response_body=""
|
|
||||||
[[ "$result" == *$'\n'* ]] && response_body="${result#*$'\n'}"
|
|
||||||
write_response "$response_status" "$response_body"
|
|
||||||
elif [[ "$method" == "GET" && "$path" == "$ISSUE_COMMENT_API_BASE"/issues/comments/* ]]; then
|
elif [[ "$method" == "GET" && "$path" == "$ISSUE_COMMENT_API_BASE"/issues/comments/* ]]; then
|
||||||
result=$(ISSUE_COMMENT_GET_ID="${path##*/}" python3 - <<'PY'
|
result=$(ISSUE_COMMENT_GET_ID="${path##*/}" python3 - <<'PY'
|
||||||
import json
|
import json
|
||||||
@@ -302,10 +299,7 @@ else:
|
|||||||
print(json.dumps(match))
|
print(json.dumps(match))
|
||||||
PY
|
PY
|
||||||
)
|
)
|
||||||
response_status="${result%%$'\n'*}"
|
write_response "$(printf '%s' "$result" | head -n1)" "$(printf '%s' "$result" | tail -n +2)"
|
||||||
response_body=""
|
|
||||||
[[ "$result" == *$'\n'* ]] && response_body="${result#*$'\n'}"
|
|
||||||
write_response "$response_status" "$response_body"
|
|
||||||
else
|
else
|
||||||
echo "Unexpected curl request: $method $url" >&2
|
echo "Unexpected curl request: $method $url" >&2
|
||||||
exit 97
|
exit 97
|
||||||
|
|||||||
@@ -69,7 +69,7 @@ section_nums() { # $1 = output $2 = header-prefix
|
|||||||
}
|
}
|
||||||
|
|
||||||
fail() { echo "FAIL: $1" >&2; exit 1; }
|
fail() { echo "FAIL: $1" >&2; exit 1; }
|
||||||
contains() { grep -qx "$2" <<<"$1"; }
|
contains() { printf '%s\n' "$1" | grep -qx "$2"; }
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# Fixed (current) script behavior
|
# Fixed (current) script behavior
|
||||||
|
|||||||
@@ -51,23 +51,22 @@ for arg in "$@"; do
|
|||||||
prev=""
|
prev=""
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
if [[ "$prev" == "data" ]]; then
|
if [[ "$prev" == "-d" ]]; then
|
||||||
post_data="$arg"
|
post_data="$arg"
|
||||||
[[ "$post_data" == @* ]] && post_data=$(<"${post_data#@}")
|
|
||||||
prev=""
|
prev=""
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
if [[ "$prev" == "config" ]]; then
|
if [[ "$arg" == "-o" ]]; then
|
||||||
[[ "$arg" == "-" ]] && cat >/dev/null
|
prev="-o"
|
||||||
prev=""
|
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
case "$arg" in
|
if [[ "$arg" == "-d" ]]; then
|
||||||
-o) prev="-o" ;;
|
prev="-d"
|
||||||
-d|--data|--data-binary) prev="data" ;;
|
continue
|
||||||
-K|--config) prev="config" ;;
|
fi
|
||||||
-w) write_code=true ;;
|
if [[ "$arg" == "-w" ]]; then
|
||||||
esac
|
write_code=true
|
||||||
|
fi
|
||||||
done
|
done
|
||||||
emit_response() {
|
emit_response() {
|
||||||
local body="$1"
|
local body="$1"
|
||||||
|
|||||||
@@ -36,30 +36,13 @@ cat > "$WORK_DIR/gitea/curl" <<'SH'
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
payload=""
|
payload=""
|
||||||
out_file=""
|
for ((i=1; i<=$#; i++)); do
|
||||||
while [[ $# -gt 0 ]]; do
|
if [[ "${!i}" == "-d" ]]; then
|
||||||
case "$1" in
|
j=$((i + 1))
|
||||||
-d|--data|--data-binary)
|
payload="${!j}"
|
||||||
payload="$2"
|
fi
|
||||||
[[ "$payload" == @* ]] && payload=$(<"${payload#@}")
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-o)
|
|
||||||
out_file="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-K|--config)
|
|
||||||
[[ "$2" == "-" ]] && cat >/dev/null
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-w|-X|-H)
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
*) shift ;;
|
|
||||||
esac
|
|
||||||
done
|
done
|
||||||
printf '%s' "$payload" > "${MOSAIC_MERGE_PAYLOAD_LOG:?}"
|
printf '%s' "$payload" > "${MOSAIC_MERGE_PAYLOAD_LOG:?}"
|
||||||
[[ -n "$out_file" ]] && printf '{}' > "$out_file"
|
|
||||||
printf '200'
|
printf '200'
|
||||||
SH
|
SH
|
||||||
chmod +x "$WORK_DIR/gitea/curl"
|
chmod +x "$WORK_DIR/gitea/curl"
|
||||||
|
|||||||
@@ -1,541 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Regression harness for the optional, identity-checked Gitea squash message.
|
|
||||||
|
|
||||||
set -u
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
SUBJECT="${MOSAIC_TEST_SUBJECT:-$SCRIPT_DIR/pr-merge.sh}"
|
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-merge-message-field}"
|
|
||||||
ORIG_PATH="$PATH"
|
|
||||||
failures=0
|
|
||||||
|
|
||||||
rm -rf "$WORK_DIR"
|
|
||||||
mkdir -p "$WORK_DIR"
|
|
||||||
|
|
||||||
fail() {
|
|
||||||
echo "FAIL $1" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
}
|
|
||||||
|
|
||||||
make_case() {
|
|
||||||
local name="$1" case_dir
|
|
||||||
case_dir="$WORK_DIR/$name"
|
|
||||||
mkdir -p "$case_dir/bin" "$case_dir/agent"
|
|
||||||
cp "$SUBJECT" "$case_dir/pr-merge.sh"
|
|
||||||
chmod +x "$case_dir/pr-merge.sh"
|
|
||||||
|
|
||||||
cat > "$case_dir/detect-platform.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
detect_platform() { PLATFORM=gitea; printf 'gitea\n'; }
|
|
||||||
get_repo_owner() { printf 'acme\n'; }
|
|
||||||
get_repo_name() { printf 'widgets\n'; }
|
|
||||||
get_remote_host() { printf 'git.example.test\n'; }
|
|
||||||
get_gitea_token() {
|
|
||||||
printf 'resolved\n' >> "${MOSAIC_TEST_TOKEN_RESOLUTION_LOG:?}"
|
|
||||||
if [[ "${MOSAIC_TEST_TOKEN_AVAILABLE:-true}" != "true" ]]; then
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
printf 'fixture-token\n'
|
|
||||||
}
|
|
||||||
get_gitea_basic_auth() {
|
|
||||||
printf 'resolved\n' >> "${MOSAIC_TEST_BASIC_RESOLUTION_LOG:?}"
|
|
||||||
if [[ "${MOSAIC_TEST_BASIC_AVAILABLE:-false}" == "true" ]]; then
|
|
||||||
printf 'fixture-user:fixture-password\n'
|
|
||||||
return "${MOSAIC_TEST_BASIC_RC:-0}"
|
|
||||||
fi
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
get_gitea_login_for_host() { return 1; }
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$case_dir/pr-metadata.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
if [[ "${MOSAIC_TEST_TITLE_MODE:-safe}" == "injection" ]]; then
|
|
||||||
title='Preserve authors\n\nCo-authored-by: victim <[email protected]>'
|
|
||||||
else
|
|
||||||
title='Preserve both branch authors'
|
|
||||||
fi
|
|
||||||
case "${MOSAIC_TEST_COMMITS_MODE:?}" in
|
|
||||||
verified) head_sha=2222222222222222222222222222222222222222 ;;
|
|
||||||
null-login|unsafe-identity) head_sha=3333333333333333333333333333333333333333 ;;
|
|
||||||
single) head_sha=1111111111111111111111111111111111111111 ;;
|
|
||||||
*) echo "unknown commits mode" >&2; exit 2 ;;
|
|
||||||
esac
|
|
||||||
printf '{"number":42,"title":"%s","author":"poster","baseRefName":"main","headRefName":"feature/fixture","headRefOid":"%s","headRepository":"acme/widgets"}\n' "$title" "$head_sha"
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$case_dir/ci-queue-wait.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
exit 0
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$case_dir/bin/python3" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
for arg in "$@"; do
|
|
||||||
case "$arg" in
|
|
||||||
*"Preserve both branch authors"*|*"[email protected]"*)
|
|
||||||
: > "${MOSAIC_TEST_METADATA_ARGV_MARKER:?}"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
exec "${MOSAIC_TEST_REAL_PYTHON:?}" "$@"
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$case_dir/bin/curl" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -eu
|
|
||||||
|
|
||||||
for arg in "$@"; do
|
|
||||||
case "$arg" in
|
|
||||||
*"Preserve both branch authors"*|*"[email protected]"*)
|
|
||||||
: > "${MOSAIC_TEST_METADATA_ARGV_MARKER:?}"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
url=""
|
|
||||||
method="GET"
|
|
||||||
out_file=""
|
|
||||||
data=""
|
|
||||||
config=""
|
|
||||||
auth_mode="none"
|
|
||||||
has_max_filesize=0
|
|
||||||
has_max_time=0
|
|
||||||
has_connect_timeout=0
|
|
||||||
while [[ $# -gt 0 ]]; do
|
|
||||||
case "$1" in
|
|
||||||
-o)
|
|
||||||
out_file="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-w)
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-X)
|
|
||||||
method="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-d|--data|--data-binary)
|
|
||||||
data="$2"
|
|
||||||
if [[ "$data" == @* ]]; then
|
|
||||||
data=$(<"${data#@}")
|
|
||||||
fi
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-K|--config)
|
|
||||||
if [[ "$2" == "-" ]]; then
|
|
||||||
config=$(cat)
|
|
||||||
fi
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
--max-filesize)
|
|
||||||
has_max_filesize=1
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
--max-time)
|
|
||||||
has_max_time=1
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
--connect-timeout)
|
|
||||||
has_connect_timeout=1
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-H|--header|-u|--user)
|
|
||||||
if [[ "$2" == *"fixture-token"* ]]; then
|
|
||||||
: > "${MOSAIC_TEST_TOKEN_ARGV_MARKER:?}"
|
|
||||||
fi
|
|
||||||
if [[ "$2" == *"fixture-password"* ]]; then
|
|
||||||
: > "${MOSAIC_TEST_BASIC_ARGV_MARKER:?}"
|
|
||||||
fi
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
http://*|https://*)
|
|
||||||
url="$1"
|
|
||||||
shift
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
shift
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if [[ "$config" == *"Authorization: token fixture-token"* ]]; then
|
|
||||||
auth_mode="token"
|
|
||||||
: > "${MOSAIC_TEST_AUTH_CONFIG_MARKER:?}"
|
|
||||||
elif [[ "$config" == *"user = \"fixture-user:fixture-password\""* ]]; then
|
|
||||||
auth_mode="basic"
|
|
||||||
: > "${MOSAIC_TEST_BASIC_CONFIG_MARKER:?}"
|
|
||||||
fi
|
|
||||||
printf '%s %s %s\n' "$method" "$auth_mode" "$url" >> "${MOSAIC_TEST_CURL_LOG:?}"
|
|
||||||
printf '%s:%s:%s\n' "$has_max_filesize" "$has_max_time" "$has_connect_timeout" >> "${MOSAIC_TEST_CURL_BOUNDS_LOG:?}"
|
|
||||||
|
|
||||||
case "$url" in
|
|
||||||
*/pulls/42)
|
|
||||||
case "${MOSAIC_TEST_COMMITS_MODE:?}" in
|
|
||||||
verified) head_sha=2222222222222222222222222222222222222222 ;;
|
|
||||||
null-login|unsafe-identity) head_sha=3333333333333333333333333333333333333333 ;;
|
|
||||||
single) head_sha=1111111111111111111111111111111111111111 ;;
|
|
||||||
*) echo "unknown commits mode" >&2; exit 2 ;;
|
|
||||||
esac
|
|
||||||
if [[ "${MOSAIC_TEST_HEAD_MODE:-stable}" == "moved" ]]; then
|
|
||||||
head_sha=4444444444444444444444444444444444444444
|
|
||||||
fi
|
|
||||||
body="{\"head\":{\"sha\":\"$head_sha\"}}"
|
|
||||||
code=200
|
|
||||||
if [[ "${MOSAIC_TEST_FALLBACK_MODE:-none}" == "inspection" && "$auth_mode" == "token" ]]; then
|
|
||||||
body='{"message":"token rejected"}'
|
|
||||||
code=401
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
*/pulls/42/commits*)
|
|
||||||
case "${MOSAIC_TEST_COMMITS_MODE:?}" in
|
|
||||||
verified)
|
|
||||||
if [[ "${MOSAIC_TEST_EMAIL_MODE:-safe}" == "escape" ]]; then
|
|
||||||
body='[{"sha":"2222222222222222222222222222222222222222","commit":{"author":{"name":"Alice","email":"alice+\u001b[[email protected]"}},"author":{"login":"alice"}},{"sha":"1111111111111111111111111111111111111111","commit":{"author":{"name":"Poster","email":"[email protected]"}},"author":{"login":"poster"}}]'
|
|
||||||
else
|
|
||||||
body='[{"sha":"2222222222222222222222222222222222222222","commit":{"author":{"name":"Alice","email":"[email protected]"}},"author":{"login":"alice"}},{"sha":"1111111111111111111111111111111111111111","commit":{"author":{"name":"Poster","email":"[email protected]"}},"author":{"login":"poster"}}]'
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
null-login)
|
|
||||||
body='[{"sha":"1111111111111111111111111111111111111111","commit":{"author":{"name":"Poster","email":"[email protected]"}},"author":{"login":"poster"}},{"sha":"3333333333333333333333333333333333333333","commit":{"author":{"name":"Unresolved Author","email":"[email protected]\n\u001b[31m"}},"author":null}]'
|
|
||||||
;;
|
|
||||||
unsafe-identity)
|
|
||||||
body='[{"sha":"unsafe\n\u001b[31m","commit":{"author":{"name":"Unsafe","email":"not-an-email"}},"author":{"login":"unsafe"}},{"sha":"3333333333333333333333333333333333333333","commit":{"author":{"name":"Poster","email":"[email protected]"}},"author":{"login":"poster"}}]'
|
|
||||||
;;
|
|
||||||
single)
|
|
||||||
body='[{"sha":"1111111111111111111111111111111111111111","commit":{"author":{"name":"Poster","email":"[email protected]"}},"author":{"login":"poster"}}]'
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
echo "unknown commits mode" >&2
|
|
||||||
exit 2
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
code=200
|
|
||||||
if [[ "${MOSAIC_TEST_FALLBACK_MODE:-none}" == "inspection" && "$auth_mode" == "token" ]]; then
|
|
||||||
body='{"message":"token rejected"}'
|
|
||||||
code=401
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
*/pulls/42/merge)
|
|
||||||
body='{}'
|
|
||||||
code=200
|
|
||||||
if [[ "${MOSAIC_TEST_FALLBACK_MODE:-none}" == "merge" && "$auth_mode" == "token" ]]; then
|
|
||||||
body='{"message":"token rejected"}'
|
|
||||||
code=401
|
|
||||||
elif [[ "${MOSAIC_TEST_FALLBACK_MODE:-none}" == "provider-error" ]]; then
|
|
||||||
body='{"message":"branch policy rejected\n\u001b[31m"}'
|
|
||||||
code=409
|
|
||||||
elif [[ "${MOSAIC_TEST_FALLBACK_MODE:-none}" == "forbidden" ]]; then
|
|
||||||
body='{"message":"permission denied"}'
|
|
||||||
code=403
|
|
||||||
else
|
|
||||||
printf '%s' "$data" > "${MOSAIC_TEST_MERGE_PAYLOAD:?}"
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
*/users/*)
|
|
||||||
body='{"message":"not found"}'
|
|
||||||
code=404
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
body='{"message":"unexpected URL"}'
|
|
||||||
code=500
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
if [[ -n "$out_file" ]]; then
|
|
||||||
printf '%s' "$body" > "$out_file"
|
|
||||||
else
|
|
||||||
printf '%s' "$body"
|
|
||||||
fi
|
|
||||||
printf '%s' "$code"
|
|
||||||
case "${MOSAIC_TEST_CURL_FAILURE:-none}" in
|
|
||||||
oversize) exit 63 ;;
|
|
||||||
stalled) exit 28 ;;
|
|
||||||
esac
|
|
||||||
SH
|
|
||||||
|
|
||||||
chmod +x "$case_dir/detect-platform.sh" "$case_dir/pr-metadata.sh" \
|
|
||||||
"$case_dir/ci-queue-wait.sh" "$case_dir/bin/curl" "$case_dir/bin/python3"
|
|
||||||
printf '%s\n' "$case_dir"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_case() {
|
|
||||||
local case_dir="$1" mode="$2"
|
|
||||||
shift 2
|
|
||||||
MOSAIC_TEST_COMMITS_MODE="$mode" \
|
|
||||||
MOSAIC_TEST_CURL_LOG="$case_dir/curl.log" \
|
|
||||||
MOSAIC_TEST_CURL_BOUNDS_LOG="$case_dir/curl-bounds.log" \
|
|
||||||
MOSAIC_TEST_MERGE_PAYLOAD="$case_dir/merge-payload.json" \
|
|
||||||
MOSAIC_TEST_TOKEN_ARGV_MARKER="$case_dir/token-in-argv" \
|
|
||||||
MOSAIC_TEST_BASIC_ARGV_MARKER="$case_dir/basic-in-argv" \
|
|
||||||
MOSAIC_TEST_AUTH_CONFIG_MARKER="$case_dir/auth-via-config" \
|
|
||||||
MOSAIC_TEST_BASIC_CONFIG_MARKER="$case_dir/basic-via-config" \
|
|
||||||
MOSAIC_TEST_TOKEN_RESOLUTION_LOG="$case_dir/token-resolution.log" \
|
|
||||||
MOSAIC_TEST_BASIC_RESOLUTION_LOG="$case_dir/basic-resolution.log" \
|
|
||||||
MOSAIC_TEST_METADATA_ARGV_MARKER="$case_dir/metadata-in-argv" \
|
|
||||||
MOSAIC_TEST_REAL_PYTHON="$(command -v python3)" \
|
|
||||||
AGENT_WORK_ROOT="$case_dir/agent" \
|
|
||||||
PATH="$case_dir/bin:$ORIG_PATH" \
|
|
||||||
"$case_dir/pr-merge.sh" -n 42 "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Verified multi-author path: the non-poster trailer is built from one commit's
|
|
||||||
# linked author.login and that same commit's author email. No /users lookup.
|
|
||||||
verified_dir=$(make_case verified)
|
|
||||||
set +e
|
|
||||||
verified_output=$(run_case "$verified_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
verified_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$verified_rc" -ne 0 ]]; then
|
|
||||||
fail "verified multi-author merge expected rc=0, got rc=$verified_rc: $verified_output"
|
|
||||||
elif [[ ! -s "$verified_dir/merge-payload.json" ]]; then
|
|
||||||
fail "verified multi-author merge did not reach the API payload"
|
|
||||||
else
|
|
||||||
python3 - "$verified_dir/merge-payload.json" <<'PY' || fail "verified payload did not preserve squash and exact message fields"
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
payload = json.load(open(sys.argv[1], encoding="utf-8"))
|
|
||||||
assert payload == {
|
|
||||||
"Do": "squash",
|
|
||||||
"head_commit_id": "2222222222222222222222222222222222222222",
|
|
||||||
"MergeTitleField": "Preserve both branch authors",
|
|
||||||
"MergeMessageField": "Co-authored-by: alice <[email protected]>",
|
|
||||||
}, payload
|
|
||||||
PY
|
|
||||||
fi
|
|
||||||
[[ -e "$verified_dir/auth-via-config" ]] || fail "verified path did not authenticate curl through stdin config"
|
|
||||||
[[ ! -e "$verified_dir/token-in-argv" ]] || fail "verified path placed the Gitea token in curl argv"
|
|
||||||
[[ ! -e "$verified_dir/metadata-in-argv" ]] || fail "verified path placed PR title or contributor email in child argv"
|
|
||||||
[[ "$(wc -l < "$verified_dir/token-resolution.log")" -eq 1 ]] || fail "verified path did not bind inspection and merge to one credential resolution"
|
|
||||||
if grep -q '/users/' "$verified_dir/curl.log" 2>/dev/null; then
|
|
||||||
fail "verified path performed a forbidden second /users lookup"
|
|
||||||
fi
|
|
||||||
if grep -qv '^1:1:1$' "$verified_dir/curl-bounds.log"; then
|
|
||||||
fail "verified path did not apply size/max-time/connect-time bounds to every provider download"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# A linked email containing a terminal escape must block before mutation.
|
|
||||||
escape_email_dir=$(make_case escape-email)
|
|
||||||
set +e
|
|
||||||
escape_email_output=$(MOSAIC_TEST_EMAIL_MODE=escape run_case "$escape_email_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
escape_email_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$escape_email_rc" -ne 0 ]] || fail "control-byte email unexpectedly passed"
|
|
||||||
[[ "$escape_email_output" == *"unusable linked identity"* ]] || fail "control-byte email refusal lost its diagnostic"
|
|
||||||
[[ ! -e "$escape_email_dir/merge-payload.json" ]] || fail "control-byte email reached the merge API"
|
|
||||||
|
|
||||||
# Curl transfer and duration failures must remain failures even with HTTP 200.
|
|
||||||
for failure_mode in oversize stalled; do
|
|
||||||
failure_dir=$(make_case "curl-$failure_mode")
|
|
||||||
set +e
|
|
||||||
failure_output=$(MOSAIC_TEST_CURL_FAILURE="$failure_mode" run_case "$failure_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
failure_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$failure_rc" -ne 0 ]] || fail "curl $failure_mode failure was discarded: $failure_output"
|
|
||||||
[[ ! -e "$failure_dir/merge-payload.json" ]] || fail "curl $failure_mode failure reached the merge API"
|
|
||||||
done
|
|
||||||
|
|
||||||
# The authenticated head is re-read under the mutation credential but cannot
|
|
||||||
# replace the canonical preflight/review head. A move blocks before enumeration
|
|
||||||
# or mutation even though the provider returned a valid new SHA.
|
|
||||||
moved_dir=$(make_case moved-head)
|
|
||||||
set +e
|
|
||||||
moved_output=$(MOSAIC_TEST_HEAD_MODE=moved \
|
|
||||||
run_case "$moved_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
moved_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$moved_rc" -ne 0 ]] || fail "moved authenticated head unexpectedly passed"
|
|
||||||
[[ "$moved_output" == *"authenticated PR head moved from reviewed"* ]] || fail "moved head refusal lost its diagnostic"
|
|
||||||
[[ "$moved_output" == *"tl-mosaic"* ]] || fail "moved head refusal omitted the named escalation principal"
|
|
||||||
[[ ! -e "$moved_dir/merge-payload.json" ]] || fail "moved head refusal reached the merge API"
|
|
||||||
moved_sequence=$(awk '{print $1 ":" $2}' "$moved_dir/curl.log" | paste -sd, -)
|
|
||||||
[[ "$moved_sequence" == "GET:token" ]] || fail "moved head refusal performed post-move inspection/mutation (calls=$moved_sequence)"
|
|
||||||
|
|
||||||
# Token resolution failure is not an authentication response. It must fail
|
|
||||||
# closed instead of borrowing a Basic credential under a different principal.
|
|
||||||
token_missing_dir=$(make_case token-missing)
|
|
||||||
set +e
|
|
||||||
token_missing_output=$(MOSAIC_TEST_TOKEN_AVAILABLE=false MOSAIC_TEST_BASIC_AVAILABLE=true \
|
|
||||||
run_case "$token_missing_dir" single 2>&1)
|
|
||||||
token_missing_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$token_missing_rc" -ne 0 ]] || fail "missing token unexpectedly borrowed Basic Auth"
|
|
||||||
[[ "$token_missing_output" == *"required Gitea token"* ]] || fail "missing token refusal lost its diagnostic"
|
|
||||||
[[ ! -e "$token_missing_dir/basic-resolution.log" ]] || fail "missing token resolved Basic Auth after identity failure"
|
|
||||||
[[ ! -e "$token_missing_dir/curl.log" ]] || fail "missing token reached a provider request"
|
|
||||||
|
|
||||||
# A failed Basic resolver must never use its nonempty output or reach mutation.
|
|
||||||
basic_rc_dir=$(make_case basic-resolver-rc)
|
|
||||||
set +e
|
|
||||||
basic_rc_output=$(MOSAIC_TEST_BASIC_AVAILABLE=true MOSAIC_TEST_BASIC_RC=91 MOSAIC_TEST_FALLBACK_MODE=inspection \
|
|
||||||
run_case "$basic_rc_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
basic_rc_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$basic_rc_rc" -ne 0 ]] || fail "failed Basic resolver output unexpectedly authorized a merge: $basic_rc_output"
|
|
||||||
[[ ! -e "$basic_rc_dir/merge-payload.json" ]] || fail "failed Basic resolver reached the merge API"
|
|
||||||
|
|
||||||
# HTTP 401 never changes principals: inspection rejection fails closed without
|
|
||||||
# resolving or attempting Basic Auth.
|
|
||||||
fallback_inspect_dir=$(make_case fallback-inspection)
|
|
||||||
set +e
|
|
||||||
fallback_inspect_output=$(MOSAIC_TEST_BASIC_AVAILABLE=true MOSAIC_TEST_FALLBACK_MODE=inspection \
|
|
||||||
run_case "$fallback_inspect_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
fallback_inspect_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$fallback_inspect_rc" -ne 0 ]] || fail "inspection token rejection unexpectedly changed principals"
|
|
||||||
[[ "$fallback_inspect_output" == *"refusing cross-principal credential fallback"* ]] || fail "inspection token rejection lost its refusal diagnostic"
|
|
||||||
[[ ! -e "$fallback_inspect_dir/basic-resolution.log" ]] || fail "inspection token rejection resolved Basic Auth"
|
|
||||||
[[ ! -e "$fallback_inspect_dir/merge-payload.json" ]] || fail "inspection token rejection reached merge mutation"
|
|
||||||
inspect_sequence=$(awk '{print $1 ":" $2}' "$fallback_inspect_dir/curl.log" | paste -sd, -)
|
|
||||||
[[ "$inspect_sequence" == "GET:token" ]] || fail "inspection rejection made unexpected provider calls (calls=$inspect_sequence)"
|
|
||||||
|
|
||||||
# Token rejection at merge likewise fails closed without cross-principal retry.
|
|
||||||
fallback_merge_dir=$(make_case fallback-merge)
|
|
||||||
set +e
|
|
||||||
fallback_merge_output=$(MOSAIC_TEST_BASIC_AVAILABLE=true MOSAIC_TEST_FALLBACK_MODE=merge \
|
|
||||||
run_case "$fallback_merge_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
fallback_merge_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$fallback_merge_rc" -ne 0 ]] || fail "merge token rejection unexpectedly changed principals"
|
|
||||||
[[ "$fallback_merge_output" == *"refusing cross-principal credential fallback"* ]] || fail "merge token rejection lost its refusal diagnostic"
|
|
||||||
[[ ! -e "$fallback_merge_dir/basic-resolution.log" ]] || fail "merge token rejection resolved Basic Auth"
|
|
||||||
[[ ! -e "$fallback_merge_dir/merge-payload.json" ]] || fail "merge token rejection recorded a successful payload"
|
|
||||||
merge_sequence=$(awk '{print $1 ":" $2}' "$fallback_merge_dir/curl.log" | paste -sd, -)
|
|
||||||
[[ "$merge_sequence" == "GET:token,GET:token,POST:token" ]] || fail "merge rejection made unexpected provider calls (calls=$merge_sequence)"
|
|
||||||
|
|
||||||
# BLOCK path: a commit email exists but author.login is null. It must name both
|
|
||||||
# facts, name the escalation principal, and never reach the merge endpoint.
|
|
||||||
null_dir=$(make_case null-login)
|
|
||||||
set +e
|
|
||||||
null_output=$(run_case "$null_dir" null-login --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
null_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$null_rc" -ne 0 ]] || fail "null-login author expected a non-zero BLOCK"
|
|
||||||
[[ "$null_output" == *"BLOCK"* ]] || fail "null-login author omitted BLOCK diagnostic"
|
|
||||||
[[ "$null_output" == *"author.login=NULL"* ]] || fail "null-login author omitted the null provider fact"
|
|
||||||
[[ "$null_output" == *"[email protected]"* ]] || fail "null-login author omitted the commit email fact"
|
|
||||||
[[ "$null_output" == *'\n\x1b[31m'* ]] || fail "null-login author diagnostic did not escape control characters"
|
|
||||||
[[ "$null_output" != *$'\033'* ]] || fail "null-login author diagnostic emitted a raw terminal escape"
|
|
||||||
[[ "$(printf '%s\n' "$null_output" | wc -l)" -eq 1 ]] || fail "null-login author diagnostic permitted newline injection"
|
|
||||||
[[ "$null_output" == *"tl-mosaic"* ]] || fail "null-login author omitted the named escalation principal"
|
|
||||||
[[ ! -e "$null_dir/merge-payload.json" ]] || fail "null-login BLOCK still reached the merge API"
|
|
||||||
|
|
||||||
# Every provider-derived field in alternate BLOCK diagnostics is log-safe too,
|
|
||||||
# including an invalid non-head SHA that contains control characters.
|
|
||||||
unsafe_dir=$(make_case unsafe-identity)
|
|
||||||
set +e
|
|
||||||
unsafe_output=$(run_case "$unsafe_dir" unsafe-identity --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
unsafe_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$unsafe_rc" -ne 0 ]] || fail "unsafe identity expected a non-zero BLOCK"
|
|
||||||
[[ "$unsafe_output" == *"unusable linked identity"* ]] || fail "unsafe identity omitted its BLOCK reason"
|
|
||||||
[[ "$unsafe_output" == *'\n\x1b[31m'* ]] || fail "unsafe identity SHA did not escape control characters"
|
|
||||||
[[ "$unsafe_output" != *$'\033'* ]] || fail "unsafe identity diagnostic emitted a raw terminal escape"
|
|
||||||
[[ "$(printf '%s\n' "$unsafe_output" | wc -l)" -eq 1 ]] || fail "unsafe identity diagnostic permitted newline injection"
|
|
||||||
[[ ! -e "$unsafe_dir/merge-payload.json" ]] || fail "unsafe identity BLOCK still reached the merge API"
|
|
||||||
|
|
||||||
# The provider PR title cannot add an unchecked trailer outside the constructed
|
|
||||||
# message field: multi-line and trailer-shaped titles block before mutation.
|
|
||||||
title_dir=$(make_case title-injection)
|
|
||||||
set +e
|
|
||||||
title_output=$(MOSAIC_TEST_TITLE_MODE=injection \
|
|
||||||
run_case "$title_dir" verified --co-author-trailers --escalate-to tl-mosaic 2>&1)
|
|
||||||
title_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$title_rc" -ne 0 ]] || fail "title trailer injection unexpectedly passed"
|
|
||||||
[[ "$title_output" == *"not one printable, non-trailer line"* ]] || fail "title injection refusal lost its diagnostic"
|
|
||||||
[[ ! -e "$title_dir/merge-payload.json" ]] || fail "title injection reached the merge API"
|
|
||||||
|
|
||||||
# Provider failures remain diagnosable after their temporary response file is
|
|
||||||
# removed, but provider-controlled control characters stay log-safe.
|
|
||||||
error_dir=$(make_case provider-error)
|
|
||||||
set +e
|
|
||||||
error_output=$(MOSAIC_TEST_BASIC_AVAILABLE=true MOSAIC_TEST_FALLBACK_MODE=provider-error \
|
|
||||||
run_case "$error_dir" single 2>&1)
|
|
||||||
error_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$error_rc" -ne 0 ]] || fail "provider error unexpectedly passed"
|
|
||||||
[[ "$error_output" == *"HTTP 409"* ]] || fail "provider error omitted the HTTP status"
|
|
||||||
[[ "$error_output" == *"branch policy rejected"* ]] || fail "provider error response was discarded"
|
|
||||||
[[ "$error_output" == *'\n\x1b[31m'* ]] || fail "provider error response did not escape control characters"
|
|
||||||
[[ "$error_output" != *$'\033'* ]] || fail "provider error response emitted a raw terminal escape"
|
|
||||||
[[ "$error_output" != *"Basic Auth fallback"* ]] || fail "provider error advertised removed Basic Auth fallback"
|
|
||||||
[[ ! -e "$error_dir/basic-resolution.log" ]] || fail "HTTP 409 policy denial incorrectly triggered Basic Auth fallback"
|
|
||||||
|
|
||||||
# Authorization denials likewise fail closed instead of changing principals.
|
|
||||||
forbidden_dir=$(make_case forbidden)
|
|
||||||
set +e
|
|
||||||
forbidden_output=$(MOSAIC_TEST_BASIC_AVAILABLE=true MOSAIC_TEST_FALLBACK_MODE=forbidden \
|
|
||||||
run_case "$forbidden_dir" single 2>&1)
|
|
||||||
forbidden_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$forbidden_rc" -ne 0 ]] || fail "HTTP 403 authorization denial unexpectedly passed"
|
|
||||||
[[ "$forbidden_output" == *"HTTP 403"* ]] || fail "authorization denial omitted the HTTP status"
|
|
||||||
[[ "$forbidden_output" != *"Basic Auth fallback"* ]] || fail "authorization denial advertised removed Basic Auth fallback"
|
|
||||||
[[ ! -e "$forbidden_dir/basic-resolution.log" ]] || fail "HTTP 403 authorization denial incorrectly triggered Basic Auth fallback"
|
|
||||||
|
|
||||||
# The BLOCK destination cannot be generic or inferred after failure: opting in
|
|
||||||
# without a named principal is refused before any provider operation.
|
|
||||||
principal_dir=$(make_case missing-principal)
|
|
||||||
set +e
|
|
||||||
principal_output=$(run_case "$principal_dir" verified --co-author-trailers 2>&1)
|
|
||||||
principal_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$principal_rc" -ne 0 ]] || fail "co-author mode without a named principal unexpectedly passed"
|
|
||||||
[[ "$principal_output" == *"requires --escalate-to with a named principal"* ]] || fail "missing-principal refusal lost its diagnostic"
|
|
||||||
[[ ! -e "$principal_dir/merge-payload.json" ]] || fail "missing-principal refusal reached the merge API"
|
|
||||||
|
|
||||||
# A trailing value-taking option receives a stable CLI diagnostic instead of a
|
|
||||||
# set -u unbound-variable crash.
|
|
||||||
value_dir=$(make_case missing-principal-value)
|
|
||||||
set +e
|
|
||||||
value_output=$(run_case "$value_dir" verified --co-author-trailers --escalate-to 2>&1)
|
|
||||||
value_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$value_rc" -ne 0 ]] || fail "missing --escalate-to value unexpectedly passed"
|
|
||||||
[[ "$value_output" == *"--escalate-to requires one principal name"* ]] || fail "missing --escalate-to value lost its diagnostic"
|
|
||||||
[[ "$value_output" != *"unbound variable"* ]] || fail "missing --escalate-to value crashed under set -u"
|
|
||||||
[[ ! -e "$value_dir/merge-payload.json" ]] || fail "missing --escalate-to value reached the merge API"
|
|
||||||
|
|
||||||
# Negative control: ordinary single-author merge remains byte-for-byte payload
|
|
||||||
# compatible and hardcoded to squash, with no optional message fields.
|
|
||||||
single_dir=$(make_case single)
|
|
||||||
set +e
|
|
||||||
single_output=$(run_case "$single_dir" single 2>&1)
|
|
||||||
single_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$single_rc" -ne 0 ]]; then
|
|
||||||
fail "ordinary single-author merge expected rc=0, got rc=$single_rc: $single_output"
|
|
||||||
elif [[ ! -s "$single_dir/merge-payload.json" ]]; then
|
|
||||||
fail "ordinary single-author merge did not reach the API payload"
|
|
||||||
else
|
|
||||||
python3 - "$single_dir/merge-payload.json" <<'PY' || fail "ordinary single-author payload changed"
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
payload = json.load(open(sys.argv[1], encoding="utf-8"))
|
|
||||||
assert payload == {
|
|
||||||
"Do": "squash",
|
|
||||||
"head_commit_id": "1111111111111111111111111111111111111111",
|
|
||||||
}, payload
|
|
||||||
PY
|
|
||||||
fi
|
|
||||||
[[ -e "$single_dir/auth-via-config" ]] || fail "ordinary path did not authenticate curl through stdin config"
|
|
||||||
[[ ! -e "$single_dir/token-in-argv" ]] || fail "ordinary path placed the Gitea token in curl argv"
|
|
||||||
[[ "$(wc -l < "$single_dir/token-resolution.log")" -eq 1 ]] || fail "ordinary path did not use exactly one credential resolution"
|
|
||||||
|
|
||||||
# Squash is not defaultable: an explicit non-squash method must remain refused.
|
|
||||||
method_dir=$(make_case method-refusal)
|
|
||||||
set +e
|
|
||||||
method_output=$(run_case "$method_dir" single -m merge 2>&1)
|
|
||||||
method_rc=$?
|
|
||||||
set -e
|
|
||||||
[[ "$method_rc" -ne 0 ]] || fail "non-squash method unexpectedly passed"
|
|
||||||
[[ "$method_output" == *"enforces squash merge only"* ]] || fail "non-squash refusal lost its policy diagnostic"
|
|
||||||
[[ ! -e "$method_dir/merge-payload.json" ]] || fail "non-squash refusal reached the merge API"
|
|
||||||
|
|
||||||
if [[ "$failures" -ne 0 ]]; then
|
|
||||||
echo "pr-merge message-field regression failed ($failures assertions)" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "pr-merge message-field regression passed (verified, BLOCK, and unchanged squash control)"
|
|
||||||
@@ -225,10 +225,7 @@ write_response() {
|
|||||||
emit() {
|
emit() {
|
||||||
# Split a two-line "status\n<json body>" python result into the response.
|
# Split a two-line "status\n<json body>" python result into the response.
|
||||||
local result="$1"
|
local result="$1"
|
||||||
response_status="${result%%$'\n'*}"
|
write_response "$(printf '%s' "$result" | head -n1)" "$(printf '%s' "$result" | tail -n +2)"
|
||||||
response_body=""
|
|
||||||
[[ "$result" == *$'\n'* ]] && response_body="${result#*$'\n'}"
|
|
||||||
write_response "$response_status" "$response_body"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
mode="${PR_REVIEW_TEST_MODE:-}"
|
mode="${PR_REVIEW_TEST_MODE:-}"
|
||||||
|
|||||||
@@ -222,8 +222,8 @@ grep -q 'Unknown action: bogus-action' "$OUTPUT_FILE"
|
|||||||
|
|
||||||
# --- Case 2: -h/--help documents both overrides.
|
# --- Case 2: -h/--help documents both overrides.
|
||||||
HELP_TEXT="$("$SCRIPT_DIR/pr-review.sh" -h)"
|
HELP_TEXT="$("$SCRIPT_DIR/pr-review.sh" -h)"
|
||||||
grep -q -- '-r, --repo' <<<"$HELP_TEXT"
|
echo "$HELP_TEXT" | grep -q -- '-r, --repo'
|
||||||
grep -q -- '-H, --host' <<<"$HELP_TEXT"
|
echo "$HELP_TEXT" | grep -q -- '-H, --host'
|
||||||
|
|
||||||
# --- Case 3 (comment): a TRUE no-git-origin dir + -r/-H must not silently die
|
# --- Case 3 (comment): a TRUE no-git-origin dir + -r/-H must not silently die
|
||||||
# and must not fail with "not a git repository or no origin remote" either.
|
# and must not fail with "not a git repository or no origin remote" either.
|
||||||
|
|||||||
@@ -91,12 +91,10 @@ fi
|
|||||||
|
|
||||||
if [[ -n "$dirty_files" ]]; then
|
if [[ -n "$dirty_files" ]]; then
|
||||||
echo " Modified files:"
|
echo " Modified files:"
|
||||||
mapfile -t dirty_lines <<<"$dirty_files"
|
echo "$dirty_files" | head -20 | while IFS= read -r line; do
|
||||||
file_count="${#dirty_lines[@]}"
|
echo " $line"
|
||||||
display_count=$((file_count < 20 ? file_count : 20))
|
|
||||||
for ((i = 0; i < display_count; i++)); do
|
|
||||||
echo " ${dirty_lines[$i]}"
|
|
||||||
done
|
done
|
||||||
|
file_count="$(echo "$dirty_files" | wc -l)"
|
||||||
if (( file_count > 20 )); then
|
if (( file_count > 20 )); then
|
||||||
echo " ... and $(( file_count - 20 )) more"
|
echo " ... and $(( file_count - 20 )) more"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -64,12 +64,12 @@ if jq -e '.next_task == "T-001"' "$capsule_file" >/dev/null 2>&1; then pass_case
|
|||||||
if grep -Fq 'Target runtime:** codex' <<< "$codex_continue_output"; then pass_case "continue prompt contains target runtime codex"; else fail_case "continue prompt contains target runtime codex"; fi
|
if grep -Fq 'Target runtime:** codex' <<< "$codex_continue_output"; then pass_case "continue prompt contains target runtime codex"; else fail_case "continue prompt contains target runtime codex"; fi
|
||||||
|
|
||||||
codex_run_prompt="$(MOSAIC_COORD_RUNTIME=codex bash "$SCRIPT_DIR/session-run.sh" --project "$tmp_project" --print)"
|
codex_run_prompt="$(MOSAIC_COORD_RUNTIME=codex bash "$SCRIPT_DIR/session-run.sh" --project "$tmp_project" --print)"
|
||||||
if [[ "${codex_run_prompt%%$'\n'*}" == "Now initiating Orchestrator mode..." ]]; then pass_case "codex run prompt first line is mode declaration"; else fail_case "codex run prompt first line is mode declaration"; fi
|
if [[ "$(printf '%s\n' "$codex_run_prompt" | head -n1)" == "Now initiating Orchestrator mode..." ]]; then pass_case "codex run prompt first line is mode declaration"; else fail_case "codex run prompt first line is mode declaration"; fi
|
||||||
if grep -Fq 'Do NOT ask clarifying questions before your first tool actions' <<< "$codex_run_prompt"; then pass_case "codex run prompt includes no-questions hard gate"; else fail_case "codex run prompt includes no-questions hard gate"; fi
|
if grep -Fq 'Do NOT ask clarifying questions before your first tool actions' <<< "$codex_run_prompt"; then pass_case "codex run prompt includes no-questions hard gate"; else fail_case "codex run prompt includes no-questions hard gate"; fi
|
||||||
if grep -Fq '"next_task": "T-001"' <<< "$codex_run_prompt"; then pass_case "codex run prompt embeds capsule json"; else fail_case "codex run prompt embeds capsule json"; fi
|
if grep -Fq '"next_task": "T-001"' <<< "$codex_run_prompt"; then pass_case "codex run prompt embeds capsule json"; else fail_case "codex run prompt embeds capsule json"; fi
|
||||||
|
|
||||||
claude_run_prompt="$(MOSAIC_COORD_RUNTIME=claude bash "$SCRIPT_DIR/session-run.sh" --project "$tmp_project" --print)"
|
claude_run_prompt="$(MOSAIC_COORD_RUNTIME=claude bash "$SCRIPT_DIR/session-run.sh" --project "$tmp_project" --print)"
|
||||||
if [[ "${claude_run_prompt%%$'\n'*}" == "## Continuation Mission" ]]; then pass_case "claude run prompt remains continuation prompt format"; else fail_case "claude run prompt remains continuation prompt format"; fi
|
if [[ "$(printf '%s\n' "$claude_run_prompt" | head -n1)" == "## Continuation Mission" ]]; then pass_case "claude run prompt remains continuation prompt format"; else fail_case "claude run prompt remains continuation prompt format"; fi
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "Smoke test summary: pass=$PASS fail=$FAIL"
|
echo "Smoke test summary: pass=$PASS fail=$FAIL"
|
||||||
|
|||||||
@@ -96,8 +96,8 @@ L="$WORK/live5.md"; G="$WORK/ledger5.md"; echo "# LEDGER" > "$G"
|
|||||||
make_board "$L" 6 1 400
|
make_board "$L" 6 1 400
|
||||||
before_l=$(cat "$L"); before_g=$(cat "$G")
|
before_l=$(cat "$L"); before_g=$(cat "$G")
|
||||||
out=$(bash "$SUT" --live "$L" --ledger "$G" --cap 2000 --dry-run 2>&1) || note "dry-run exited nonzero: $out"
|
out=$(bash "$SUT" --live "$L" --ledger "$G" --cap 2000 --dry-run 2>&1) || note "dry-run exited nonzero: $out"
|
||||||
grep -qi "dry run" <<<"$out" || note "dry-run did not announce itself"
|
echo "$out" | grep -qi "dry run" || note "dry-run did not announce itself"
|
||||||
grep -q "would roll" <<<"$out" || note "dry-run did not report a plan"
|
echo "$out" | grep -q "would roll" || note "dry-run did not report a plan"
|
||||||
[[ "$(cat "$L")" == "$before_l" ]] || note "dry-run modified LIVE"
|
[[ "$(cat "$L")" == "$before_l" ]] || note "dry-run modified LIVE"
|
||||||
[[ "$(cat "$G")" == "$before_g" ]] || note "dry-run modified LEDGER"
|
[[ "$(cat "$G")" == "$before_g" ]] || note "dry-run modified LEDGER"
|
||||||
|
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ present=0
|
|||||||
|
|
||||||
for entry in "${PRDY_REQUIRED_SECTIONS[@]}"; do
|
for entry in "${PRDY_REQUIRED_SECTIONS[@]}"; do
|
||||||
pattern="${entry#*|}"
|
pattern="${entry#*|}"
|
||||||
if grep -qiE "$pattern" <<<"$PRD_CONTENT"; then
|
if echo "$PRD_CONTENT" | grep -qiE "$pattern"; then
|
||||||
present=$((present + 1))
|
present=$((present + 1))
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -169,13 +169,13 @@ main() {
|
|||||||
# classify_surface PATH → surface name (highest-risk match wins, mirrors TS)
|
# classify_surface PATH → surface name (highest-risk match wins, mirrors TS)
|
||||||
classify_surface() {
|
classify_surface() {
|
||||||
local p="$1"
|
local p="$1"
|
||||||
if grep -qiE 'auth|login|session|token|permission|rbac|credential|secret' <<<"$p"; then echo auth; return; fi
|
if printf '%s' "$p" | grep -qiE 'auth|login|session|token|permission|rbac|credential|secret'; then echo auth; return; fi
|
||||||
if grep -qiE 'migration|prisma|schema|\.sql|entity|repository|seed' <<<"$p"; then echo data; return; fi
|
if printf '%s' "$p" | grep -qiE 'migration|prisma|schema|\.sql|entity|repository|seed'; then echo data; return; fi
|
||||||
if grep -qiE 'docker|\.woodpecker|compose|traefik|deploy|helm|k8s|terraform' <<<"$p"; then echo infra; return; fi
|
if printf '%s' "$p" | grep -qiE 'docker|\.woodpecker|compose|traefik|deploy|helm|k8s|terraform'; then echo infra; return; fi
|
||||||
if grep -qiE 'package\.json|tsconfig|turbo\.json|pnpm-|\.config\.|eslint|vite' <<<"$p"; then echo build; return; fi
|
if printf '%s' "$p" | grep -qiE 'package\.json|tsconfig|turbo\.json|pnpm-|\.config\.|eslint|vite'; then echo build; return; fi
|
||||||
if grep -qE '\.tsx|\.css|components/|apps/web/' <<<"$p"; then echo ui; return; fi
|
if printf '%s' "$p" | grep -qE '\.tsx|\.css|components/|apps/web/'; then echo ui; return; fi
|
||||||
if grep -qE '\.spec\.|\.test\.|__tests__/' <<<"$p"; then echo test; return; fi
|
if printf '%s' "$p" | grep -qE '\.spec\.|\.test\.|__tests__/'; then echo test; return; fi
|
||||||
if grep -qE '\.md$|docs/' <<<"$p"; then echo docs; return; fi
|
if printf '%s' "$p" | grep -qE '\.md$|docs/'; then echo docs; return; fi
|
||||||
echo none
|
echo none
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -13,12 +13,7 @@ JSON_INPUT=$(cat)
|
|||||||
if command -v jq &>/dev/null; then
|
if command -v jq &>/dev/null; then
|
||||||
FILE_PATH=$(echo "$JSON_INPUT" | jq -r '.tool_input.file_path // .tool_response.filePath // .file_path // empty' 2>/dev/null || echo "")
|
FILE_PATH=$(echo "$JSON_INPUT" | jq -r '.tool_input.file_path // .tool_response.filePath // .file_path // empty' 2>/dev/null || echo "")
|
||||||
else
|
else
|
||||||
file_path_pattern='"file_path"[[:space:]]*:[[:space:]]*"([^"]*)"'
|
FILE_PATH=$(echo "$JSON_INPUT" | grep -o '"file_path"[[:space:]]*:[[:space:]]*"[^"]*"' | sed 's/.*"\([^"]*\)"$/\1/' | head -1)
|
||||||
if [[ "$JSON_INPUT" =~ $file_path_pattern ]]; then
|
|
||||||
FILE_PATH="${BASH_REMATCH[1]}"
|
|
||||||
else
|
|
||||||
FILE_PATH=""
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Only check TypeScript files
|
# Only check TypeScript files
|
||||||
@@ -58,7 +53,7 @@ OUTPUT=$(npx tsc --noEmit --pretty --maxNodeModuleJsDepth 0 2>&1) || STATUS=$?
|
|||||||
if [ "${STATUS:-0}" -ne 0 ]; then
|
if [ "${STATUS:-0}" -ne 0 ]; then
|
||||||
# Filter output to only show errors related to the edited file (if possible)
|
# Filter output to only show errors related to the edited file (if possible)
|
||||||
BASENAME=$(basename "$FILE_PATH")
|
BASENAME=$(basename "$FILE_PATH")
|
||||||
RELEVANT=$(grep -A2 "$BASENAME" <<<"$OUTPUT" 2>/dev/null || sed -n '1,20p' <<<"$OUTPUT")
|
RELEVANT=$(echo "$OUTPUT" | grep -A2 "$BASENAME" 2>/dev/null || echo "$OUTPUT" | head -20)
|
||||||
|
|
||||||
echo "TypeScript type errors detected after editing $FILE_PATH:"
|
echo "TypeScript type errors detected after editing $FILE_PATH:"
|
||||||
echo "$RELEVANT"
|
echo "$RELEVANT"
|
||||||
|
|||||||
@@ -26,9 +26,6 @@ chk "F1 fresh: CONSTITUTION/AGENTS/STANDARDS/TOOLS seeded" \
|
|||||||
"[ -f '$T1/CONSTITUTION.md' ] && [ -f '$T1/AGENTS.md' ] && [ -f '$T1/STANDARDS.md' ] && [ -f '$T1/TOOLS.md' ]"
|
"[ -f '$T1/CONSTITUTION.md' ] && [ -f '$T1/AGENTS.md' ] && [ -f '$T1/STANDARDS.md' ] && [ -f '$T1/TOOLS.md' ]"
|
||||||
chk "F1 fresh: AGENTS == shipped default" "cmp -s '$T1/AGENTS.md' '$DEFA/AGENTS.md'"
|
chk "F1 fresh: AGENTS == shipped default" "cmp -s '$T1/AGENTS.md' '$DEFA/AGENTS.md'"
|
||||||
chk "F1 fresh: framework-version stamped 3" "[ \"\$(cat '$T1/.framework-version' 2>/dev/null)\" = 3 ]"
|
chk "F1 fresh: framework-version stamped 3" "[ \"\$(cat '$T1/.framework-version' 2>/dev/null)\" = 3 ]"
|
||||||
chk "F1 fresh: Pi goal extension deploys under Mosaic runtime" \
|
|
||||||
"cmp -s '$T1/runtime/pi/goal-extension.ts' '$FW/runtime/pi/goal-extension.ts'"
|
|
||||||
chk "F1 fresh: installer creates no nested main Pi config" "[ ! -e '$T1/.pi' ]"
|
|
||||||
|
|
||||||
# F2 — legacy install with a user-edited AGENTS.md (the sanctioned pre-constitution customization)
|
# F2 — legacy install with a user-edited AGENTS.md (the sanctioned pre-constitution customization)
|
||||||
T2=$(mktemp -d); mkdir -p "$T2/credentials"
|
T2=$(mktemp -d); mkdir -p "$T2/credentials"
|
||||||
@@ -92,8 +89,6 @@ chk "F6 reseed: per-agent env bytes survive" "cmp -s '$T6/fleet/agents/coder0.en
|
|||||||
chk "F6 reseed: heartbeat bytes survive" "cmp -s '$T6/fleet/run/coder0.hb' '$E6/run.expected'"
|
chk "F6 reseed: heartbeat bytes survive" "cmp -s '$T6/fleet/run/coder0.hb' '$E6/run.expected'"
|
||||||
chk "F6 reseed: framework examples are refreshed" "grep -q orchestrator '$T6/fleet/examples/general.yaml'"
|
chk "F6 reseed: framework examples are refreshed" "grep -q orchestrator '$T6/fleet/examples/general.yaml'"
|
||||||
chk "F6 reseed: framework roster schema is refreshed" "cmp -s '$T6/fleet/roster.schema.json' '$FW/fleet/roster.schema.json'"
|
chk "F6 reseed: framework roster schema is refreshed" "cmp -s '$T6/fleet/roster.schema.json' '$FW/fleet/roster.schema.json'"
|
||||||
chk "F6 reseed: Pi goal extension is refreshed from framework source" \
|
|
||||||
"cmp -s '$T6/runtime/pi/goal-extension.ts' '$FW/runtime/pi/goal-extension.ts'"
|
|
||||||
|
|
||||||
rm -rf "$T1" "$T2" "$T3" "$T4" "$T5" "$T6" "$E6"
|
rm -rf "$T1" "$T2" "$T3" "$T4" "$T5" "$T6" "$E6"
|
||||||
echo
|
echo
|
||||||
|
|||||||
@@ -176,12 +176,8 @@ run_snap() {
|
|||||||
|
|
||||||
# Resolve the single pre-update-* snapshot dir under a state dir (newest if many).
|
# Resolve the single pre-update-* snapshot dir under a state dir (newest if many).
|
||||||
snap_dir() {
|
snap_dir() {
|
||||||
local -a snapshots=()
|
find "$1/mosaic/backups" -maxdepth 1 -type d -name 'pre-update-*' 2>/dev/null \
|
||||||
mapfile -t snapshots < <(
|
| LC_ALL=C sort -r | head -1
|
||||||
find "$1/mosaic/backups" -maxdepth 1 -type d -name 'pre-update-*' 2>/dev/null \
|
|
||||||
| LC_ALL=C sort -r
|
|
||||||
)
|
|
||||||
printf '%s\n' "${snapshots[0]:-}"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
echo "── Part 1/2/3: durable snapshot scope, perms, no-leak ──────────────────"
|
echo "── Part 1/2/3: durable snapshot scope, perms, no-leak ──────────────────"
|
||||||
|
|||||||
@@ -39,12 +39,11 @@ ORIG_PATH="$PATH"
|
|||||||
# loop — which would make the control a false negative. A root dotfile is
|
# loop — which would make the control a false negative. A root dotfile is
|
||||||
# operator-owned (unknown→operator), so the sync loop skips it. Clean up on exit.
|
# operator-owned (unknown→operator), so the sync loop skips it. Clean up on exit.
|
||||||
STRIPPED="$FW/.install-rollback-control.tmp.sh"
|
STRIPPED="$FW/.install-rollback-control.tmp.sh"
|
||||||
SIGNALED="$FW/.install-signal-control.tmp.sh"
|
|
||||||
NOEXIT="$FW/.install-noexit-control.tmp.sh"
|
NOEXIT="$FW/.install-noexit-control.tmp.sh"
|
||||||
D1CTRL="$FW/.install-d1guard-control.tmp.sh"
|
D1CTRL="$FW/.install-d1guard-control.tmp.sh"
|
||||||
D2CTRL="$FW/.install-d2guard-control.tmp.sh"
|
D2CTRL="$FW/.install-d2guard-control.tmp.sh"
|
||||||
rm -f "$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
rm -f "$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
||||||
trap 'rm -f "$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"' EXIT
|
trap 'rm -f "$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"' EXIT
|
||||||
|
|
||||||
pass=0; fail=0
|
pass=0; fail=0
|
||||||
chk() { if eval "$2"; then echo " ✓ $1"; pass=$((pass + 1)); else echo " ✗ $1"; fail=$((fail + 1)); fi; }
|
chk() { if eval "$2"; then echo " ✓ $1"; pass=$((pass + 1)); else echo " ✗ $1"; fail=$((fail + 1)); fi; }
|
||||||
@@ -181,86 +180,41 @@ chk "[control] without -E the mid-sync corruption survives (no rollback)" \
|
|||||||
# ── Part C: an INT/TERM interrupt must terminate, not resume (blocker-A) ──────
|
# ── Part C: an INT/TERM interrupt must terminate, not resume (blocker-A) ──────
|
||||||
# A bash signal trap that merely returns lets the script continue past the
|
# A bash signal trap that merely returns lets the script continue past the
|
||||||
# interrupt — restoring the snapshot, then resuming the sync and reporting
|
# interrupt — restoring the snapshot, then resuming the sync and reporting
|
||||||
# success. The earlier test used a child cp shim to signal its parent, making
|
# success. We inject a SIGTERM mid-sync with a cp that SUCCEEDS (so set -e never
|
||||||
# child completion race Bash's interrupted wait. Concurrency is not part of the
|
# fires and ONLY the signal path governs), and assert the shipped installer
|
||||||
# guarded property: sync_framework_keep() runs in the installer's own Bash
|
# restores AND exits without reporting success. The control strips `exit 1` from
|
||||||
# process, and `kill` is a builtin. Generate two installer fixtures that signal
|
# the trap and shows the buggy resume-to-success.
|
||||||
# themselves at the same known mid-sync point. Their TERM handlers emit the same
|
make_term_shim() {
|
||||||
# observable before diverging, so missing signal delivery fails BOTH arms rather
|
local dir="$1"
|
||||||
# than manufacturing a pass. The only semantic difference between fixtures is
|
cat > "$dir/cp" <<SHIM
|
||||||
# the explicit `exit 1` whose load-bearing behavior this control proves.
|
#!/usr/bin/env bash
|
||||||
TERM_MARKER='[test-control] TERM handler entered'
|
dest="\${@: -1}"
|
||||||
HANDLER_WITH_EXIT="trap 'echo \"$TERM_MARKER\" >&2; restore_snapshot; exit 1' TERM # TEST-TERM-HANDLER"
|
case "\$dest" in
|
||||||
HANDLER_WITHOUT_EXIT="trap 'echo \"$TERM_MARKER\" >&2; restore_snapshot' TERM # TEST-TERM-HANDLER"
|
*/$POISON_REL)
|
||||||
|
kill -TERM "\$PPID" 2>/dev/null # signal install.sh; the copy still succeeds
|
||||||
make_signal_installer() {
|
exec env PATH="$ORIG_PATH" cp "\$@" ;;
|
||||||
local output="$1" handler="$2"
|
esac
|
||||||
local target_trap="trap 'restore_snapshot; exit 1' ERR INT TERM"
|
exec env PATH="$ORIG_PATH" cp "\$@"
|
||||||
local target_cp=' cp "$abs" "$dst/$rel"'
|
SHIM
|
||||||
local inject_open=" if [[ \"\$rel\" == \"$POISON_REL\" ]]; then"
|
chmod +x "$dir/cp"
|
||||||
local inject_kill=' kill -TERM "$$" # TEST-TERM-INJECTION'
|
|
||||||
local inject_close=' fi'
|
|
||||||
|
|
||||||
if ! awk \
|
|
||||||
-v target_trap="$target_trap" -v target_cp="$target_cp" \
|
|
||||||
-v handler="$handler" -v inject_open="$inject_open" \
|
|
||||||
-v inject_kill="$inject_kill" -v inject_close="$inject_close" '
|
|
||||||
$0 == target_cp {
|
|
||||||
print inject_open
|
|
||||||
print inject_kill
|
|
||||||
print inject_close
|
|
||||||
injection_sites++
|
|
||||||
}
|
|
||||||
{ print }
|
|
||||||
$0 == target_trap {
|
|
||||||
print handler
|
|
||||||
handler_sites++
|
|
||||||
}
|
|
||||||
END {
|
|
||||||
if (handler_sites != 1 || injection_sites != 1) exit 42
|
|
||||||
}
|
|
||||||
' "$INSTALL" > "$output"; then
|
|
||||||
rm -f "$output"
|
|
||||||
fail "Could not construct the self-TERM control installer at the exact trap/copy sites"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
chmod +x "$output"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
make_signal_installer "$SIGNALED" "$HANDLER_WITH_EXIT"
|
# Run one keep-mode upgrade with the SIGTERM shim. Echoes "<exit>\t<out>\t<home>".
|
||||||
make_signal_installer "$NOEXIT" "$HANDLER_WITHOUT_EXIT"
|
|
||||||
signal_fixture_ready() {
|
|
||||||
local fixture="$1" expected_handler="$2"
|
|
||||||
[[ "$(grep -cF '# TEST-TERM-INJECTION' "$fixture")" -eq 1 ]] \
|
|
||||||
&& [[ "$(grep -cF '# TEST-TERM-HANDLER' "$fixture")" -eq 1 ]] \
|
|
||||||
&& grep -Fqx "$expected_handler" "$fixture"
|
|
||||||
}
|
|
||||||
signaled_fixture_ready() { signal_fixture_ready "$SIGNALED" "$HANDLER_WITH_EXIT"; }
|
|
||||||
noexit_fixture_ready() { signal_fixture_ready "$NOEXIT" "$HANDLER_WITHOUT_EXIT"; }
|
|
||||||
chk "[signal] shipped fixture has exactly one self-TERM injection and marked handler" \
|
|
||||||
"signaled_fixture_ready"
|
|
||||||
chk "[control] no-exit fixture has exactly one self-TERM injection and marked handler" \
|
|
||||||
"noexit_fixture_ready"
|
|
||||||
chk "[control] removing the explicit TERM exit changes the fixture" \
|
|
||||||
"! cmp -s '$SIGNALED' '$NOEXIT'"
|
|
||||||
|
|
||||||
# Run one keep-mode upgrade whose own shell delivers SIGTERM synchronously at
|
|
||||||
# the selected copy. Echoes "<exit>\t<out>\t<home>".
|
|
||||||
run_signal_upgrade() {
|
run_signal_upgrade() {
|
||||||
local installer="$1" H OUT rc
|
local installer="$1" H OUT SHIM rc
|
||||||
H=$(mktemp -d); OUT=$(mktemp)
|
H=$(mktemp -d); OUT=$(mktemp); SHIM=$(mktemp -d)
|
||||||
seed_home "$H"
|
seed_home "$H"
|
||||||
|
make_term_shim "$SHIM"
|
||||||
set +e
|
set +e
|
||||||
PATH="$ORIG_PATH" \
|
PATH="$SHIM:$ORIG_PATH" \
|
||||||
MOSAIC_HOME="$H" MOSAIC_INSTALL_MODE=keep MOSAIC_SYNC_ONLY=1 bash "$installer" >"$OUT" 2>&1
|
MOSAIC_HOME="$H" MOSAIC_INSTALL_MODE=keep MOSAIC_SYNC_ONLY=1 bash "$installer" >"$OUT" 2>&1
|
||||||
rc=$?
|
rc=$?
|
||||||
set -e 2>/dev/null || true
|
set -e 2>/dev/null || true
|
||||||
|
rm -rf "$SHIM"
|
||||||
printf '%s\t%s\t%s\n' "$rc" "$OUT" "$H"
|
printf '%s\t%s\t%s\n' "$rc" "$OUT" "$H"
|
||||||
}
|
}
|
||||||
|
|
||||||
IFS=$'\t' read -r rcC OUTC HC < <(run_signal_upgrade "$SIGNALED")
|
IFS=$'\t' read -r rcC OUTC HC < <(run_signal_upgrade "$INSTALL")
|
||||||
chk "[signal] TERM handler observable fires exactly once" \
|
|
||||||
"[ \"\$(grep -cF '$TERM_MARKER' '$OUTC')\" -eq 1 ]"
|
|
||||||
chk "[signal] SIGTERM mid-sync aborts non-zero (trap exits, does not resume)" \
|
chk "[signal] SIGTERM mid-sync aborts non-zero (trap exits, does not resume)" \
|
||||||
"[ '$rcC' -ne 0 ]"
|
"[ '$rcC' -ne 0 ]"
|
||||||
chk "[signal] restore_snapshot fires on the interrupt" \
|
chk "[signal] restore_snapshot fires on the interrupt" \
|
||||||
@@ -268,13 +222,13 @@ chk "[signal] restore_snapshot fires on the interrupt" \
|
|||||||
chk "[signal] does NOT resume to report sync success after the interrupt" \
|
chk "[signal] does NOT resume to report sync success after the interrupt" \
|
||||||
"! grep -q 'file phase complete' '$OUTC'"
|
"! grep -q 'file phase complete' '$OUTC'"
|
||||||
|
|
||||||
IFS=$'\t' read -r rcD OUTD HD < <(run_signal_upgrade "$NOEXIT")
|
# Control: strip `exit 1` from the signal trap → the handler returns, the script
|
||||||
chk "[control] TERM handler observable fires exactly once" \
|
# resumes past the interrupt and wrongly reports success. In $FW so SOURCE_DIR resolves.
|
||||||
"[ \"\$(grep -cF '$TERM_MARKER' '$OUTD')\" -eq 1 ]"
|
sed "s/trap 'restore_snapshot; exit 1' ERR INT TERM/trap 'restore_snapshot' ERR INT TERM/" \
|
||||||
chk "[control] without 'exit 1' the handler restores before returning" \
|
"$INSTALL" > "$NOEXIT"
|
||||||
"grep -q 'restoring previous state from snapshot' '$OUTD'"
|
chk "[control] the exit-strip actually changed the installer" \
|
||||||
chk "[control] without 'exit 1' the installer exits zero after resuming" \
|
"! cmp -s '$INSTALL' '$NOEXIT'"
|
||||||
"[ '$rcD' -eq 0 ]"
|
IFS=$'\t' read -r _rcD OUTD HD < <(run_signal_upgrade "$NOEXIT")
|
||||||
chk "[control] without 'exit 1' the trap resumes and reports sync success (the bug)" \
|
chk "[control] without 'exit 1' the trap resumes and reports sync success (the bug)" \
|
||||||
"grep -q 'file phase complete' '$OUTD'"
|
"grep -q 'file phase complete' '$OUTD'"
|
||||||
|
|
||||||
@@ -336,7 +290,7 @@ chk "[reset-fail] the manual-recovery pointer is emitted (not a silent set -e ex
|
|||||||
"grep -q 'Snapshot restore could not reset' '$OUTG'"
|
"grep -q 'Snapshot restore could not reset' '$OUTG'"
|
||||||
chk "[reset-fail] the recovery message points at a preserved snapshot dir" \
|
chk "[reset-fail] the recovery message points at a preserved snapshot dir" \
|
||||||
"grep -q 'preserved at: .*mosaic-snapshot' '$OUTG'"
|
"grep -q 'preserved at: .*mosaic-snapshot' '$OUTG'"
|
||||||
SNAP_E="$(grep -m1 -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTG")"
|
SNAP_E="$(grep -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTG" | head -1)"
|
||||||
chk "[reset-fail] the named snapshot directory actually survives for recovery" \
|
chk "[reset-fail] the named snapshot directory actually survives for recovery" \
|
||||||
"[ -n '$SNAP_E' ] && [ -d '$SNAP_E' ]"
|
"[ -n '$SNAP_E' ] && [ -d '$SNAP_E' ]"
|
||||||
chk "[reset-fail] operator secret value never appears in installer output" \
|
chk "[reset-fail] operator secret value never appears in installer output" \
|
||||||
@@ -353,13 +307,12 @@ chk "[control] without the D2 recovery line the operator gets no snapshot pointe
|
|||||||
"! grep -q 'Snapshot restore could not reset' '$OUTH'"
|
"! grep -q 'Snapshot restore could not reset' '$OUTH'"
|
||||||
[ -n "${SNAP_E:-}" ] && rm -rf "$SNAP_E"
|
[ -n "${SNAP_E:-}" ] && rm -rf "$SNAP_E"
|
||||||
# Reap any snapshot the reset-fail runs left in /tmp (reset failed → never cleaned).
|
# Reap any snapshot the reset-fail runs left in /tmp (reset failed → never cleaned).
|
||||||
orphan_snapshot="$(grep -m1 -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTH" 2>/dev/null || true)"
|
grep -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTH" 2>/dev/null | head -1 | while read -r s; do rm -rf "$s"; done
|
||||||
[ -n "$orphan_snapshot" ] && rm -rf "$orphan_snapshot"
|
|
||||||
|
|
||||||
# Cleanup (generated installer controls are also removed by the EXIT trap).
|
# Cleanup ($STRIPPED / $NOEXIT / $D1CTRL / $D2CTRL are also removed by the EXIT trap).
|
||||||
for d in "$HA" "$REFA" "$HB" "$REFB" "$HC" "$HD" "$HE" "$REFE" "$HF" "$REFF" "$HG" "$HH"; do rm -rf "$d"; done
|
for d in "$HA" "$REFA" "$HB" "$REFB" "$HC" "$HD" "$HE" "$REFE" "$HF" "$REFF" "$HG" "$HH"; do rm -rf "$d"; done
|
||||||
rm -f "$OUTA" "$OUTB" "$OUTC" "$OUTD" "$OUTE" "$OUTF" "$OUTG" "$OUTH" \
|
rm -f "$OUTA" "$OUTB" "$OUTC" "$OUTD" "$OUTE" "$OUTF" "$OUTG" "$OUTH" \
|
||||||
"$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
"$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
||||||
|
|
||||||
echo
|
echo
|
||||||
echo "RESULT: $pass passed, $fail failed"
|
echo "RESULT: $pass passed, $fail failed"
|
||||||
|
|||||||
@@ -32,6 +32,7 @@ packages/mosaic/framework/tools/tmux/test-send-message-socket.sh | requires a re
|
|||||||
packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh | requires real tmux-pane fixtures on a throwaway socket; CI image ships no tmux; #1017 burndown (same condition as its sibling)
|
packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh | requires real tmux-pane fixtures on a throwaway socket; CI image ships no tmux; #1017 burndown (same condition as its sibling)
|
||||||
|
|
||||||
# --- single-suite directories: unmeasured in CI ---
|
# --- single-suite directories: unmeasured in CI ---
|
||||||
|
packages/mosaic/framework/tools/fleet/test-start-agent-session.sh | unmeasured in CI image; stubs tmux via a fake bin dir, likely CI-fit; #1017 burndown
|
||||||
packages/mosaic/framework/tools/glpi/test-list-http-status.sh | unmeasured in CI image; stub-based (#807 regression harness), likely CI-fit; #1017 burndown
|
packages/mosaic/framework/tools/glpi/test-list-http-status.sh | unmeasured in CI image; stub-based (#807 regression harness), likely CI-fit; #1017 burndown
|
||||||
packages/mosaic/framework/tools/orchestrator/test-board-roll.sh | unmeasured in CI image; file-fixture based, likely CI-fit; #1017 burndown
|
packages/mosaic/framework/tools/orchestrator/test-board-roll.sh | unmeasured in CI image; file-fixture based, likely CI-fit; #1017 burndown
|
||||||
packages/mosaic/framework/tools/woodpecker/test-ci-wait-exit-matrix.sh | unmeasured in CI image; drives ci-wait.sh against a stub pipeline-status.sh, likely CI-fit; #1017 burndown
|
packages/mosaic/framework/tools/woodpecker/test-ci-wait-exit-matrix.sh | unmeasured in CI image; drives ci-wait.sh against a stub pipeline-status.sh, likely CI-fit; #1017 burndown
|
||||||
|
|||||||
@@ -110,7 +110,7 @@ for attempt in $(seq 1 $((RETRIES + 1))); do
|
|||||||
sleep 1.2
|
sleep 1.2
|
||||||
pane=$("${tmux_cmd[@]}" capture-pane -t "$EFFECTIVE_TARGET" -p 2>/dev/null)
|
pane=$("${tmux_cmd[@]}" capture-pane -t "$EFFECTIVE_TARGET" -p 2>/dev/null)
|
||||||
|
|
||||||
if grep -qF "$QUEUED_RE" <<<"$pane"; then
|
if printf '%s' "$pane" | grep -qF "$QUEUED_RE"; then
|
||||||
status="queued"; break
|
status="queued"; break
|
||||||
fi
|
fi
|
||||||
# Locate the REPL input box (prompt glyph). If we cannot see it, we have NO
|
# Locate the REPL input box (prompt glyph). If we cannot see it, we have NO
|
||||||
@@ -121,7 +121,7 @@ for attempt in $(seq 1 $((RETRIES + 1))); do
|
|||||||
fi
|
fi
|
||||||
# Input box located AND still carrying our tail => unsubmitted draft. Flush + retry.
|
# Input box located AND still carrying our tail => unsubmitted draft. Flush + retry.
|
||||||
# (Submitted messages scroll up into history; a draft stays on the ❯ line.)
|
# (Submitted messages scroll up into history; a draft stays on the ❯ line.)
|
||||||
if [ -n "$snippet" ] && grep -qF "$snippet" <<<"$promptline"; then
|
if [ -n "$snippet" ] && printf '%s' "$promptline" | grep -qF "$snippet"; then
|
||||||
status="draft"; continue
|
status="draft"; continue
|
||||||
fi
|
fi
|
||||||
# Input box located AND clear of our tail => positively submitted. This is the
|
# Input box located AND clear of our tail => positively submitted. This is the
|
||||||
|
|||||||
@@ -34,20 +34,16 @@ tmux new-session -d -s "$DEFAULT_TARGET" -c "$TMPDIR" 'PS1="❯ " exec bash --no
|
|||||||
|
|
||||||
"$SEND_MESSAGE" -L "$SOCKET" -t "=$TARGET" -m "named socket hello" >/tmp/send-message-named.out
|
"$SEND_MESSAGE" -L "$SOCKET" -t "=$TARGET" -m "named socket hello" >/tmp/send-message-named.out
|
||||||
sleep 0.2
|
sleep 0.2
|
||||||
named_pane="$(capture_named)" || fail "could not capture named socket pane"
|
capture_named | grep -qF "named socket hello" || fail "send-message.sh did not deliver to named socket"
|
||||||
grep -qF "named socket hello" <<<"$named_pane" || fail "send-message.sh did not deliver to named socket"
|
if capture_default | grep -qF "named socket hello"; then
|
||||||
default_pane="$(capture_default)" || fail "could not capture default socket pane"
|
|
||||||
if grep -qF "named socket hello" <<<"$default_pane"; then
|
|
||||||
fail "send-message.sh leaked named-socket message to default tmux server"
|
fail "send-message.sh leaked named-socket message to default tmux server"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
"$AGENT_SEND" -L "$SOCKET" -S "tester:source" -s "=$TARGET" -m "agent socket hello" >/tmp/agent-send-named.out
|
"$AGENT_SEND" -L "$SOCKET" -S "tester:source" -s "=$TARGET" -m "agent socket hello" >/tmp/agent-send-named.out
|
||||||
sleep 0.2
|
sleep 0.2
|
||||||
named_pane="$(capture_named)" || fail "could not capture named socket pane"
|
capture_named | grep -qF "[tester:source ->" || fail "agent-send.sh did not include preamble"
|
||||||
grep -qF "[tester:source ->" <<<"$named_pane" || fail "agent-send.sh did not include preamble"
|
capture_named | grep -qF "agent socket hello" || fail "agent-send.sh did not deliver to named socket"
|
||||||
grep -qF "agent socket hello" <<<"$named_pane" || fail "agent-send.sh did not deliver to named socket"
|
if capture_default | grep -qF "agent socket hello"; then
|
||||||
default_pane="$(capture_default)" || fail "could not capture default socket pane"
|
|
||||||
if grep -qF "agent socket hello" <<<"$default_pane"; then
|
|
||||||
fail "agent-send.sh leaked named-socket message to default tmux server"
|
fail "agent-send.sh leaked named-socket message to default tmux server"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -69,11 +65,11 @@ done
|
|||||||
sleep 0.2
|
sleep 0.2
|
||||||
for i in $(seq 1 "$CONC_N"); do
|
for i in $(seq 1 "$CONC_N"); do
|
||||||
pane=$(tmux -L "$SOCKET" capture-pane -t "=conc-$i:0.0" -p)
|
pane=$(tmux -L "$SOCKET" capture-pane -t "=conc-$i:0.0" -p)
|
||||||
grep -qF "CONCPAYLOAD-${i}-END" <<<"$pane" \
|
printf '%s' "$pane" | grep -qF "CONCPAYLOAD-${i}-END" \
|
||||||
|| fail "concurrent send dropped payload for pane conc-$i"
|
|| fail "concurrent send dropped payload for pane conc-$i"
|
||||||
for j in $(seq 1 "$CONC_N"); do
|
for j in $(seq 1 "$CONC_N"); do
|
||||||
[ "$j" = "$i" ] && continue
|
[ "$j" = "$i" ] && continue
|
||||||
if grep -qF "CONCPAYLOAD-${j}-END" <<<"$pane"; then
|
if printf '%s' "$pane" | grep -qF "CONCPAYLOAD-${j}-END"; then
|
||||||
fail "concurrent send cross-delivered payload $j to pane conc-$i"
|
fail "concurrent send cross-delivered payload $j to pane conc-$i"
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ tmux -L "$SOCKET" new-session -d -s repl -c "$TMP" \
|
|||||||
'PS1="❯ " exec bash --noprofile --norc -i'
|
'PS1="❯ " exec bash --noprofile --norc -i'
|
||||||
sleep 0.3
|
sleep 0.3
|
||||||
out=$("$SEND" -L "$SOCKET" -t "=repl" -m "verdict fixture one delivered ok" 2>"$TMP/e1"); rc=$?
|
out=$("$SEND" -L "$SOCKET" -t "=repl" -m "verdict fixture one delivered ok" 2>"$TMP/e1"); rc=$?
|
||||||
if [ "$rc" -eq 0 ] && grep -qF "✓ delivered" <<<"$out"; then
|
if [ "$rc" -eq 0 ] && printf '%s' "$out" | grep -qF "✓ delivered"; then
|
||||||
ok "delivered: ❯-prompt REPL that submits => exit 0 ✓ delivered"
|
ok "delivered: ❯-prompt REPL that submits => exit 0 ✓ delivered"
|
||||||
else
|
else
|
||||||
no "delivered: ❯-prompt REPL that submits => exit 0 ✓ delivered" "rc=$rc out=[$out] err=[$(cat "$TMP/e1")]"
|
no "delivered: ❯-prompt REPL that submits => exit 0 ✓ delivered" "rc=$rc out=[$out] err=[$(cat "$TMP/e1")]"
|
||||||
|
|||||||
@@ -123,7 +123,7 @@ _manifest_val() {
|
|||||||
# _manifest_val KEY — echo VALUE for KEY=VALUE in the manifest (blank if none).
|
# _manifest_val KEY — echo VALUE for KEY=VALUE in the manifest (blank if none).
|
||||||
local key="$1"
|
local key="$1"
|
||||||
[ -f "$MANIFEST" ] || return 0
|
[ -f "$MANIFEST" ] || return 0
|
||||||
awk -v key="$key" 'index($0, key "=") == 1 { sub(/^[^=]*=/, ""); gsub(/[[:space:]]/, ""); print; exit }' "$MANIFEST"
|
sed -n "s/^${key}=//p" "$MANIFEST" | head -n1 | tr -d '[:space:]'
|
||||||
}
|
}
|
||||||
|
|
||||||
# _load_watchlist — validate the watch-list path + JSON + schema_version range.
|
# _load_watchlist — validate the watch-list path + JSON + schema_version range.
|
||||||
@@ -267,7 +267,7 @@ _poll_source() {
|
|||||||
if snap_json="$(jq -ce '.' <<<"$rawmeta" 2>/dev/null)"; then
|
if snap_json="$(jq -ce '.' <<<"$rawmeta" 2>/dev/null)"; then
|
||||||
snap_sha="$(jq -r 'if (.snapshot_sha|type) == "string" then .snapshot_sha else "" end' <<<"$snap_json")"
|
snap_sha="$(jq -r 'if (.snapshot_sha|type) == "string" then .snapshot_sha else "" end' <<<"$snap_json")"
|
||||||
snap_ts="$(jq -r 'if (.snapshot_ts|type) == "number" then (.snapshot_ts|floor|tostring) else "" end' <<<"$snap_json")"
|
snap_ts="$(jq -r 'if (.snapshot_ts|type) == "number" then (.snapshot_ts|floor|tostring) else "" end' <<<"$snap_json")"
|
||||||
if [ -n "$snap_sha" ] && ! grep -Eq '^[0-9a-f]{7,64}$' <<<"$snap_sha"; then
|
if [ -n "$snap_sha" ] && ! printf '%s' "$snap_sha" | grep -Eq '^[0-9a-f]{7,64}$'; then
|
||||||
echo "detector.sh: source '$kind/$id' snapshot_sha rejected (not a 7-64 char lowercase-hex git sha) — snapshot metadata DROPPED, poll continues (#940)." >&2
|
echo "detector.sh: source '$kind/$id' snapshot_sha rejected (not a 7-64 char lowercase-hex git sha) — snapshot metadata DROPPED, poll continues (#940)." >&2
|
||||||
snap_sha=""
|
snap_sha=""
|
||||||
snap_ts=""
|
snap_ts=""
|
||||||
@@ -275,7 +275,7 @@ _poll_source() {
|
|||||||
# A ts must be a sane positive epoch BEFORE any arithmetic touches it: a
|
# A ts must be a sane positive epoch BEFORE any arithmetic touches it: a
|
||||||
# negative or absurdly large value would make the shell integer comparison
|
# negative or absurdly large value would make the shell integer comparison
|
||||||
# below error out and silently KEEP the bad ts — validate first, compare after.
|
# below error out and silently KEEP the bad ts — validate first, compare after.
|
||||||
if [ -n "$snap_ts" ] && ! grep -Eq '^[0-9]{1,12}$' <<<"$snap_ts"; then
|
if [ -n "$snap_ts" ] && ! printf '%s' "$snap_ts" | grep -Eq '^[0-9]{1,12}$'; then
|
||||||
echo "detector.sh: source '$kind/$id' snapshot_ts rejected (not a sane positive epoch) — snapshot_ts DROPPED, poll continues (#940)." >&2
|
echo "detector.sh: source '$kind/$id' snapshot_ts rejected (not a sane positive epoch) — snapshot_ts DROPPED, poll continues (#940)." >&2
|
||||||
snap_ts=""
|
snap_ts=""
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -644,8 +644,7 @@ cmd_render() {
|
|||||||
oseq="$(jq -r '.observed_seq // "?"' <<<"$line")"
|
oseq="$(jq -r '.observed_seq // "?"' <<<"$line")"
|
||||||
oclass="$(jq -r '.class // "actionable"' <<<"$line")"
|
oclass="$(jq -r '.class // "actionable"' <<<"$line")"
|
||||||
oloc="$(jq -c '.locators // {}' <<<"$line")"
|
oloc="$(jq -c '.locators // {}' <<<"$line")"
|
||||||
olabel="$(_locator_line "$oloc")"
|
olabel="$(_locator_line "$oloc" | head -n1)"
|
||||||
olabel="${olabel%%$'\n'*}"
|
|
||||||
printf ' * seq %s [%s] %s\n' "$oseq" "$(_scrub_inline "$oclass")" "$olabel"
|
printf ' * seq %s [%s] %s\n' "$oseq" "$(_scrub_inline "$oclass")" "$olabel"
|
||||||
done <<<"$pending"
|
done <<<"$pending"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -146,7 +146,7 @@ EOF
|
|||||||
_manifest_val() {
|
_manifest_val() {
|
||||||
local key="$1"
|
local key="$1"
|
||||||
[ -f "$MANIFEST" ] || return 0
|
[ -f "$MANIFEST" ] || return 0
|
||||||
awk -v key="$key" 'index($0, key "=") == 1 { sub(/^[^=]*=/, ""); gsub(/[[:space:]]/, ""); print; exit }' "$MANIFEST"
|
sed -n "s/^${key}=//p" "$MANIFEST" | head -n1 | tr -d '[:space:]'
|
||||||
}
|
}
|
||||||
|
|
||||||
# _load_watchlist — validate path + JSON + shape + Gate B schema range (mirrors
|
# _load_watchlist — validate path + JSON + shape + Gate B schema range (mirrors
|
||||||
|
|||||||
@@ -25,7 +25,7 @@
|
|||||||
"lint": "eslint src",
|
"lint": "eslint src",
|
||||||
"typecheck": "tsc --noEmit",
|
"typecheck": "tsc --noEmit",
|
||||||
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
||||||
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && bash framework/tools/fleet/test-start-agent-session.sh && bash framework/systemd/user/test-fleet-units.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-pr-merge-message-field.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/git/test-explain-diagnostic-status-neutral.sh && bash framework/tools/git/test-detect-platform-outside-repo.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
|
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@mosaicstack/brain": "workspace:*",
|
"@mosaicstack/brain": "workspace:*",
|
||||||
|
|||||||
@@ -131,14 +131,13 @@ async function exists(path: string): Promise<boolean> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
describe('projectRosterV2AgentGeneratedEnv', (): void => {
|
describe('projectRosterV2AgentGeneratedEnv', (): void => {
|
||||||
it('maps a roster-v2 agent to exactly the nine generated projection keys', (): void => {
|
it('maps a roster-v2 agent to exactly the eight generated projection keys', (): void => {
|
||||||
const roster = parseRosterV2(rosterYaml, 'yaml');
|
const roster = parseRosterV2(rosterYaml, 'yaml');
|
||||||
const agent = roster.agents.find((candidate) => candidate.name === 'coder0');
|
const agent = roster.agents.find((candidate) => candidate.name === 'coder0');
|
||||||
expect(agent).toBeDefined();
|
expect(agent).toBeDefined();
|
||||||
const values = projectRosterV2AgentGeneratedEnv(roster, agent!);
|
const values = projectRosterV2AgentGeneratedEnv(roster, agent!);
|
||||||
expect(values).toEqual({
|
expect(values).toEqual({
|
||||||
MOSAIC_AGENT_NAME: 'coder0',
|
MOSAIC_AGENT_NAME: 'coder0',
|
||||||
MOSAIC_GIT_IDENTITY: 'coder0',
|
|
||||||
MOSAIC_AGENT_CLASS: 'code',
|
MOSAIC_AGENT_CLASS: 'code',
|
||||||
MOSAIC_AGENT_RUNTIME: 'pi',
|
MOSAIC_AGENT_RUNTIME: 'pi',
|
||||||
MOSAIC_AGENT_MODEL: 'gpt-5.6-sol',
|
MOSAIC_AGENT_MODEL: 'gpt-5.6-sol',
|
||||||
|
|||||||
@@ -422,7 +422,6 @@ describe('fleet roster parsing', () => {
|
|||||||
expect(generateAgentEnv(roster, getRosterAgent(roster, 'coder0'))).toBe(
|
expect(generateAgentEnv(roster, getRosterAgent(roster, 'coder0'))).toBe(
|
||||||
[
|
[
|
||||||
'MOSAIC_AGENT_NAME=coder0',
|
'MOSAIC_AGENT_NAME=coder0',
|
||||||
'MOSAIC_GIT_IDENTITY=coder0',
|
|
||||||
// Reflects the roster's canonicalized compatibility class (A3a).
|
// Reflects the roster's canonicalized compatibility class (A3a).
|
||||||
'MOSAIC_AGENT_CLASS=code',
|
'MOSAIC_AGENT_CLASS=code',
|
||||||
'MOSAIC_AGENT_RUNTIME=codex',
|
'MOSAIC_AGENT_RUNTIME=codex',
|
||||||
@@ -3800,7 +3799,6 @@ describe('fleet add command', () => {
|
|||||||
'utf8',
|
'utf8',
|
||||||
);
|
);
|
||||||
expect(envContent).toContain('MOSAIC_AGENT_NAME=coder0');
|
expect(envContent).toContain('MOSAIC_AGENT_NAME=coder0');
|
||||||
expect(envContent).toContain('MOSAIC_GIT_IDENTITY=coder0');
|
|
||||||
expect(envContent).toContain('MOSAIC_AGENT_RUNTIME=codex');
|
expect(envContent).toContain('MOSAIC_AGENT_RUNTIME=codex');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -484,7 +484,6 @@ function generateAgentEnvValues(
|
|||||||
const workingDirectory = agent.workingDirectory ?? roster.defaults.workingDirectory;
|
const workingDirectory = agent.workingDirectory ?? roster.defaults.workingDirectory;
|
||||||
return {
|
return {
|
||||||
MOSAIC_AGENT_NAME: agent.name,
|
MOSAIC_AGENT_NAME: agent.name,
|
||||||
MOSAIC_GIT_IDENTITY: agent.name,
|
|
||||||
MOSAIC_AGENT_CLASS: agent.className,
|
MOSAIC_AGENT_CLASS: agent.className,
|
||||||
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
||||||
MOSAIC_AGENT_MODEL: agent.modelHint ?? '',
|
MOSAIC_AGENT_MODEL: agent.modelHint ?? '',
|
||||||
|
|||||||
@@ -5,7 +5,6 @@ import { tmpdir } from 'node:os';
|
|||||||
import { join } from 'node:path';
|
import { join } from 'node:path';
|
||||||
import {
|
import {
|
||||||
buildPiSkillArgs,
|
buildPiSkillArgs,
|
||||||
discoverPiExtensionArgs,
|
|
||||||
enumerateSkillDirs,
|
enumerateSkillDirs,
|
||||||
piForceSkillNames,
|
piForceSkillNames,
|
||||||
registerRuntimeLaunchers,
|
registerRuntimeLaunchers,
|
||||||
@@ -179,52 +178,6 @@ describe('buildPiSkillArgs', () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe('discoverPiExtensionArgs', () => {
|
|
||||||
it('loads the core and goal extensions in deterministic order from Mosaic home', () => {
|
|
||||||
const root = mkdtempSync(join(tmpdir(), 'mosaic-pi-extensions-'));
|
|
||||||
const runtimeDir = join(root, 'runtime', 'pi');
|
|
||||||
mkdirSync(runtimeDir, { recursive: true });
|
|
||||||
writeFileSync(join(runtimeDir, 'goal-extension.ts'), '// goal\n');
|
|
||||||
writeFileSync(join(runtimeDir, 'mosaic-extension.ts'), '// core\n');
|
|
||||||
|
|
||||||
try {
|
|
||||||
expect(discoverPiExtensionArgs(root)).toEqual([
|
|
||||||
'--extension',
|
|
||||||
join(runtimeDir, 'mosaic-extension.ts'),
|
|
||||||
'--extension',
|
|
||||||
join(runtimeDir, 'goal-extension.ts'),
|
|
||||||
]);
|
|
||||||
} finally {
|
|
||||||
rmSync(root, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('remains backward-compatible when the optional goal extension is absent', () => {
|
|
||||||
const root = mkdtempSync(join(tmpdir(), 'mosaic-pi-extensions-'));
|
|
||||||
const runtimeDir = join(root, 'runtime', 'pi');
|
|
||||||
mkdirSync(runtimeDir, { recursive: true });
|
|
||||||
writeFileSync(join(runtimeDir, 'mosaic-extension.ts'), '// core\n');
|
|
||||||
|
|
||||||
try {
|
|
||||||
expect(discoverPiExtensionArgs(root)).toEqual([
|
|
||||||
'--extension',
|
|
||||||
join(runtimeDir, 'mosaic-extension.ts'),
|
|
||||||
]);
|
|
||||||
} finally {
|
|
||||||
rmSync(root, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('emits no extension arguments when Mosaic runtime assets are absent', () => {
|
|
||||||
const root = mkdtempSync(join(tmpdir(), 'mosaic-pi-extensions-'));
|
|
||||||
try {
|
|
||||||
expect(discoverPiExtensionArgs(root)).toEqual([]);
|
|
||||||
} finally {
|
|
||||||
rmSync(root, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('enumerateSkillDirs (real FS)', () => {
|
describe('enumerateSkillDirs (real FS)', () => {
|
||||||
let root: string;
|
let root: string;
|
||||||
|
|
||||||
|
|||||||
@@ -715,15 +715,9 @@ export function buildPiSkillArgs(
|
|||||||
return ['--no-skills', ...forcedSkillArgs];
|
return ['--no-skills', ...forcedSkillArgs];
|
||||||
}
|
}
|
||||||
|
|
||||||
const PI_EXTENSION_FILES = ['mosaic-extension.ts', 'goal-extension.ts'] as const;
|
function discoverPiExtension(): string[] {
|
||||||
|
const ext = join(MOSAIC_HOME, 'runtime', 'pi', 'mosaic-extension.ts');
|
||||||
export function discoverPiExtensionArgs(mosaicHome: string = MOSAIC_HOME): string[] {
|
return existsSync(ext) ? ['--extension', ext] : [];
|
||||||
const args: string[] = [];
|
|
||||||
for (const fileName of PI_EXTENSION_FILES) {
|
|
||||||
const extensionPath = join(mosaicHome, 'runtime', 'pi', fileName);
|
|
||||||
if (existsSync(extensionPath)) args.push('--extension', extensionPath);
|
|
||||||
}
|
|
||||||
return args;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// ─── Launch functions ────────────────────────────────────────────────────────
|
// ─── Launch functions ────────────────────────────────────────────────────────
|
||||||
@@ -798,7 +792,7 @@ function launchRuntime(runtime: RuntimeName, args: string[], yolo: boolean): nev
|
|||||||
const prompt = buildRuntimePrompt('pi');
|
const prompt = buildRuntimePrompt('pi');
|
||||||
const cliArgs = ['--append-system-prompt', prompt];
|
const cliArgs = ['--append-system-prompt', prompt];
|
||||||
cliArgs.push(...buildPiSkillArgs(args));
|
cliArgs.push(...buildPiSkillArgs(args));
|
||||||
cliArgs.push(...discoverPiExtensionArgs());
|
cliArgs.push(...discoverPiExtension());
|
||||||
if (hasMissionNoArgs) {
|
if (hasMissionNoArgs) {
|
||||||
cliArgs.push(missionPrompt);
|
cliArgs.push(missionPrompt);
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -209,20 +209,6 @@ describe('FileConfigAdapter.syncFramework — defaults seeding', () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
it('deploys the Mosaic-owned Pi goal extension only inside the Mosaic runtime tree', async () => {
|
|
||||||
const sourceRuntime = join(fixture.sourceDir, 'runtime', 'pi');
|
|
||||||
mkdirSync(sourceRuntime, { recursive: true });
|
|
||||||
writeFileSync(join(sourceRuntime, 'goal-extension.ts'), '// persistent goal extension\n');
|
|
||||||
|
|
||||||
const adapter = new FileConfigAdapter(fixture.mosaicHome, fixture.sourceDir);
|
|
||||||
await adapter.syncFramework('fresh');
|
|
||||||
|
|
||||||
expect(
|
|
||||||
readFileSync(join(fixture.mosaicHome, 'runtime', 'pi', 'goal-extension.ts'), 'utf-8'),
|
|
||||||
).toBe('// persistent goal extension\n');
|
|
||||||
expect(existsSync(join(fixture.mosaicHome, '.pi'))).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('is a no-op for seeding when defaults/ dir does not exist', async () => {
|
it('is a no-op for seeding when defaults/ dir does not exist', async () => {
|
||||||
rmSync(fixture.defaultsDir, { recursive: true });
|
rmSync(fixture.defaultsDir, { recursive: true });
|
||||||
|
|
||||||
|
|||||||
@@ -358,7 +358,6 @@ function generatedValues(
|
|||||||
): Readonly<Record<string, string>> {
|
): Readonly<Record<string, string>> {
|
||||||
return {
|
return {
|
||||||
MOSAIC_AGENT_NAME: agent.name,
|
MOSAIC_AGENT_NAME: agent.name,
|
||||||
MOSAIC_GIT_IDENTITY: agent.name,
|
|
||||||
MOSAIC_AGENT_CLASS: agent.className,
|
MOSAIC_AGENT_CLASS: agent.className,
|
||||||
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
||||||
MOSAIC_AGENT_MODEL: agent.model,
|
MOSAIC_AGENT_MODEL: agent.model,
|
||||||
|
|||||||
@@ -380,7 +380,7 @@ const COMMAND_RECORDS: Readonly<Record<string, RegExp>> = {
|
|||||||
|
|
||||||
const DATA_PROFILE_BODIES: Readonly<Record<string, string>> = {
|
const DATA_PROFILE_BODIES: Readonly<Record<string, string>> = {
|
||||||
'DATA.DOTENV.FLEET_LAUNCH':
|
'DATA.DOTENV.FLEET_LAUNCH':
|
||||||
'MOSAIC_AGENT_NAME=<roster name>\nMOSAIC_GIT_IDENTITY=<roster name>\nMOSAIC_AGENT_CLASS=<roster class>\nMOSAIC_AGENT_RUNTIME=<roster runtime>\nMOSAIC_AGENT_MODEL=<roster model hint>\nMOSAIC_AGENT_REASONING=<roster reasoning>\nMOSAIC_AGENT_TOOL_POLICY=<roster tool policy>\nMOSAIC_AGENT_WORKDIR=<absolute roster work directory>\nMOSAIC_TMUX_SOCKET=<roster socket or empty>',
|
'MOSAIC_AGENT_NAME=<roster name>\nMOSAIC_AGENT_CLASS=<roster class>\nMOSAIC_AGENT_RUNTIME=<roster runtime>\nMOSAIC_AGENT_MODEL=<roster model hint>\nMOSAIC_AGENT_REASONING=<roster reasoning>\nMOSAIC_AGENT_TOOL_POLICY=<roster tool policy>\nMOSAIC_AGENT_WORKDIR=<absolute roster work directory>\nMOSAIC_TMUX_SOCKET=<roster socket or empty>',
|
||||||
'DATA.TEXT_TABLE.FLEET_TASKS':
|
'DATA.TEXT_TABLE.FLEET_TASKS':
|
||||||
'| W-FLEET | in-progress | Fleet (agent-session execution layer) | Phase 2/5 | docs/fleet/TASKS.md | observability dogfooded on live stub fleet; control plane rides federation (W1) |',
|
'| W-FLEET | in-progress | Fleet (agent-session execution layer) | Phase 2/5 | docs/fleet/TASKS.md | observability dogfooded on live stub fleet; control plane rides federation (W1) |',
|
||||||
'DATA.TEXT_DIAGRAM.BACKLOG_FLOW':
|
'DATA.TEXT_DIAGRAM.BACKLOG_FLOW':
|
||||||
@@ -406,7 +406,7 @@ const DATA_PROFILE_BODIES: Readonly<Record<string, string>> = {
|
|||||||
'DATA.JSON.MUTATION_RESULT':
|
'DATA.JSON.MUTATION_RESULT':
|
||||||
'{\n "applied": false,\n "authoritativeRoster": "committed",\n "projections": "incomplete",\n "recovery": {\n "code": "projection-apply-failed",\n "action": "regenerate-projections-from-roster"\n }\n}',
|
'{\n "applied": false,\n "authoritativeRoster": "committed",\n "projections": "incomplete",\n "recovery": {\n "code": "projection-apply-failed",\n "action": "regenerate-projections-from-roster"\n }\n}',
|
||||||
'DATA.DOTENV.GENERATED_ENV':
|
'DATA.DOTENV.GENERATED_ENV':
|
||||||
'MOSAIC_AGENT_NAME=<roster name>\nMOSAIC_GIT_IDENTITY=<roster name>\nMOSAIC_AGENT_CLASS=<roster class>\nMOSAIC_AGENT_RUNTIME=<roster runtime>\nMOSAIC_AGENT_MODEL=<roster model hint>\nMOSAIC_AGENT_REASONING=<roster reasoning>\nMOSAIC_AGENT_TOOL_POLICY=<roster tool policy>\nMOSAIC_AGENT_WORKDIR=<absolute roster work directory>\nMOSAIC_TMUX_SOCKET=<roster socket or empty>',
|
'MOSAIC_AGENT_NAME=<roster name>\nMOSAIC_AGENT_CLASS=<roster class>\nMOSAIC_AGENT_RUNTIME=<roster runtime>\nMOSAIC_AGENT_MODEL=<roster model hint>\nMOSAIC_AGENT_REASONING=<roster reasoning>\nMOSAIC_AGENT_TOOL_POLICY=<roster tool policy>\nMOSAIC_AGENT_WORKDIR=<absolute roster work directory>\nMOSAIC_TMUX_SOCKET=<roster socket or empty>',
|
||||||
'DATA.YAML.ROSTER_FIELDS':
|
'DATA.YAML.ROSTER_FIELDS':
|
||||||
'version: 2\ngeneration: 1\ntransport: tmux\ntmux:\n socket_name: mosaic-fleet\n holder_session: _holder\ndefaults:\n working_directory: ~/src\n runtime: pi\nruntimes:\n pi:\n reset_command: /new\nagents:\n - name: coder0\n alias: Coder 0\n class: code\n runtime: pi\n provider: openai\n model: gpt-5.6-sol\n reasoning: high\n tool_policy: code\n working_directory: ~/src\n persistent_persona: false\n reset_between_tasks: true\n lifecycle:\n enabled: true\n desired_state: stopped\n launch:\n yolo: true',
|
'version: 2\ngeneration: 1\ntransport: tmux\ntmux:\n socket_name: mosaic-fleet\n holder_session: _holder\ndefaults:\n working_directory: ~/src\n runtime: pi\nruntimes:\n pi:\n reset_command: /new\nagents:\n - name: coder0\n alias: Coder 0\n class: code\n runtime: pi\n provider: openai\n model: gpt-5.6-sol\n reasoning: high\n tool_policy: code\n working_directory: ~/src\n persistent_persona: false\n reset_between_tasks: true\n lifecycle:\n enabled: true\n desired_state: stopped\n launch:\n yolo: true',
|
||||||
};
|
};
|
||||||
@@ -922,8 +922,8 @@ describe('fleet operator documentation', (): void => {
|
|||||||
);
|
);
|
||||||
expect(
|
expect(
|
||||||
surfaces.filter((surface): boolean => surface.category === 'InlineLiteral'),
|
surfaces.filter((surface): boolean => surface.category === 'InlineLiteral'),
|
||||||
).toHaveLength(863);
|
).toHaveLength(858);
|
||||||
expect(surfaces).toHaveLength(887);
|
expect(surfaces).toHaveLength(882);
|
||||||
|
|
||||||
const rosterSource = await readFile(join(fleetDocs, 'examples', 'roster-v2.yaml'), 'utf8');
|
const rosterSource = await readFile(join(fleetDocs, 'examples', 'roster-v2.yaml'), 'utf8');
|
||||||
const auxiliary: CodeSurface = {
|
const auxiliary: CodeSurface = {
|
||||||
|
|||||||
@@ -597,7 +597,6 @@ export function projectRosterV2AgentGeneratedEnv(
|
|||||||
): Readonly<Record<string, string>> {
|
): Readonly<Record<string, string>> {
|
||||||
return {
|
return {
|
||||||
MOSAIC_AGENT_NAME: agent.name,
|
MOSAIC_AGENT_NAME: agent.name,
|
||||||
MOSAIC_GIT_IDENTITY: agent.name,
|
|
||||||
MOSAIC_AGENT_CLASS: agent.className,
|
MOSAIC_AGENT_CLASS: agent.className,
|
||||||
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
||||||
MOSAIC_AGENT_MODEL: agent.model,
|
MOSAIC_AGENT_MODEL: agent.model,
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ import {
|
|||||||
|
|
||||||
const generatedValues = {
|
const generatedValues = {
|
||||||
MOSAIC_AGENT_NAME: 'coder0',
|
MOSAIC_AGENT_NAME: 'coder0',
|
||||||
MOSAIC_GIT_IDENTITY: 'coder0',
|
|
||||||
MOSAIC_AGENT_CLASS: 'code',
|
MOSAIC_AGENT_CLASS: 'code',
|
||||||
MOSAIC_AGENT_RUNTIME: 'pi',
|
MOSAIC_AGENT_RUNTIME: 'pi',
|
||||||
MOSAIC_AGENT_MODEL: 'openai-codex/gpt-5.6-sol',
|
MOSAIC_AGENT_MODEL: 'openai-codex/gpt-5.6-sol',
|
||||||
@@ -46,7 +45,6 @@ describe('generated fleet agent environment boundary', (): void => {
|
|||||||
expect(renderGeneratedAgentEnvironment(generatedValues)).toBe(
|
expect(renderGeneratedAgentEnvironment(generatedValues)).toBe(
|
||||||
[
|
[
|
||||||
'MOSAIC_AGENT_NAME=coder0',
|
'MOSAIC_AGENT_NAME=coder0',
|
||||||
'MOSAIC_GIT_IDENTITY=coder0',
|
|
||||||
'MOSAIC_AGENT_CLASS=code',
|
'MOSAIC_AGENT_CLASS=code',
|
||||||
'MOSAIC_AGENT_RUNTIME=pi',
|
'MOSAIC_AGENT_RUNTIME=pi',
|
||||||
'MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol',
|
'MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol',
|
||||||
@@ -80,22 +78,6 @@ describe('generated fleet agent environment boundary', (): void => {
|
|||||||
expect(String(error)).toMatch(/key=.*sha256=/);
|
expect(String(error)).toMatch(/key=.*sha256=/);
|
||||||
});
|
});
|
||||||
|
|
||||||
it.each([
|
|
||||||
['unsafe-git-identity', 'other/identity'],
|
|
||||||
['git-identity-mismatch', 'reviewer0'],
|
|
||||||
])('rejects %s before any launch consumer can use it', (code: string, identity: string): void => {
|
|
||||||
expect((): void => {
|
|
||||||
renderGeneratedAgentEnvironment({
|
|
||||||
...generatedValues,
|
|
||||||
MOSAIC_GIT_IDENTITY: identity,
|
|
||||||
});
|
|
||||||
}).toThrow(
|
|
||||||
expect.objectContaining({
|
|
||||||
diagnostic: expect.objectContaining({ code, key: 'MOSAIC_GIT_IDENTITY' }),
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects unsafe generated paths before any launch consumer can use them', (): void => {
|
it('rejects unsafe generated paths before any launch consumer can use them', (): void => {
|
||||||
expect((): void => {
|
expect((): void => {
|
||||||
renderGeneratedAgentEnvironment({
|
renderGeneratedAgentEnvironment({
|
||||||
|
|||||||
@@ -73,7 +73,6 @@ export class AgentEnvBoundaryError extends Error {
|
|||||||
|
|
||||||
export const GENERATED_AGENT_ENV_KEYS = [
|
export const GENERATED_AGENT_ENV_KEYS = [
|
||||||
'MOSAIC_AGENT_NAME',
|
'MOSAIC_AGENT_NAME',
|
||||||
'MOSAIC_GIT_IDENTITY',
|
|
||||||
'MOSAIC_AGENT_CLASS',
|
'MOSAIC_AGENT_CLASS',
|
||||||
'MOSAIC_AGENT_RUNTIME',
|
'MOSAIC_AGENT_RUNTIME',
|
||||||
'MOSAIC_AGENT_MODEL',
|
'MOSAIC_AGENT_MODEL',
|
||||||
@@ -403,7 +402,6 @@ function assertGeneratedValues(values: Readonly<Record<string, string>>): void {
|
|||||||
if (value === undefined) throw new AgentEnvBoundaryError('missing-key', key, '');
|
if (value === undefined) throw new AgentEnvBoundaryError('missing-key', key, '');
|
||||||
}
|
}
|
||||||
const name = requiredGeneratedValue(values, 'MOSAIC_AGENT_NAME');
|
const name = requiredGeneratedValue(values, 'MOSAIC_AGENT_NAME');
|
||||||
const gitIdentity = requiredGeneratedValue(values, 'MOSAIC_GIT_IDENTITY');
|
|
||||||
const className = requiredGeneratedValue(values, 'MOSAIC_AGENT_CLASS');
|
const className = requiredGeneratedValue(values, 'MOSAIC_AGENT_CLASS');
|
||||||
const runtime = requiredGeneratedValue(values, 'MOSAIC_AGENT_RUNTIME');
|
const runtime = requiredGeneratedValue(values, 'MOSAIC_AGENT_RUNTIME');
|
||||||
const model = requiredGeneratedValue(values, 'MOSAIC_AGENT_MODEL');
|
const model = requiredGeneratedValue(values, 'MOSAIC_AGENT_MODEL');
|
||||||
@@ -414,12 +412,6 @@ function assertGeneratedValues(values: Readonly<Record<string, string>>): void {
|
|||||||
|
|
||||||
if (!AGENT_NAME.test(name))
|
if (!AGENT_NAME.test(name))
|
||||||
throw new AgentEnvBoundaryError('unsafe-agent-name', 'MOSAIC_AGENT_NAME', name);
|
throw new AgentEnvBoundaryError('unsafe-agent-name', 'MOSAIC_AGENT_NAME', name);
|
||||||
if (!AGENT_NAME.test(gitIdentity)) {
|
|
||||||
throw new AgentEnvBoundaryError('unsafe-git-identity', 'MOSAIC_GIT_IDENTITY', gitIdentity);
|
|
||||||
}
|
|
||||||
if (gitIdentity !== name) {
|
|
||||||
throw new AgentEnvBoundaryError('git-identity-mismatch', 'MOSAIC_GIT_IDENTITY', gitIdentity);
|
|
||||||
}
|
|
||||||
if (!POLICY_NAME.test(className)) {
|
if (!POLICY_NAME.test(className)) {
|
||||||
throw new AgentEnvBoundaryError('unsafe-class', 'MOSAIC_AGENT_CLASS', className);
|
throw new AgentEnvBoundaryError('unsafe-class', 'MOSAIC_AGENT_CLASS', className);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1405,7 +1405,6 @@ function generatedValues(
|
|||||||
): Readonly<Record<string, string>> {
|
): Readonly<Record<string, string>> {
|
||||||
return {
|
return {
|
||||||
MOSAIC_AGENT_NAME: agent.name,
|
MOSAIC_AGENT_NAME: agent.name,
|
||||||
MOSAIC_GIT_IDENTITY: agent.name,
|
|
||||||
MOSAIC_AGENT_CLASS: agent.className,
|
MOSAIC_AGENT_CLASS: agent.className,
|
||||||
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
MOSAIC_AGENT_RUNTIME: agent.runtime,
|
||||||
MOSAIC_AGENT_MODEL: agent.model,
|
MOSAIC_AGENT_MODEL: agent.model,
|
||||||
|
|||||||
@@ -1,796 +0,0 @@
|
|||||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
|
||||||
|
|
||||||
interface FakeEntry {
|
|
||||||
type: string;
|
|
||||||
customType?: string;
|
|
||||||
data?: unknown;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface SentMessage {
|
|
||||||
message: {
|
|
||||||
customType: string;
|
|
||||||
content: string;
|
|
||||||
display: boolean;
|
|
||||||
};
|
|
||||||
options?: {
|
|
||||||
triggerTurn?: boolean;
|
|
||||||
deliverAs?: 'steer' | 'followUp' | 'nextTurn';
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
interface FakeContext {
|
|
||||||
cwd: string;
|
|
||||||
ui: {
|
|
||||||
notifications: Array<{ message: string; level?: string }>;
|
|
||||||
statuses: Map<string, string | undefined>;
|
|
||||||
notify(message: string, level?: string): void;
|
|
||||||
setStatus(key: string, value: string | undefined): void;
|
|
||||||
};
|
|
||||||
sessionManager: {
|
|
||||||
getBranch(): FakeEntry[];
|
|
||||||
};
|
|
||||||
isIdle(): boolean;
|
|
||||||
hasPendingMessages(): boolean;
|
|
||||||
abort(): void;
|
|
||||||
}
|
|
||||||
|
|
||||||
type EventHandler = (
|
|
||||||
event: Record<string, unknown>,
|
|
||||||
context: FakeContext,
|
|
||||||
) => unknown | Promise<unknown>;
|
|
||||||
|
|
||||||
type CommandHandler = (args: string, context: FakeContext) => unknown | Promise<unknown>;
|
|
||||||
|
|
||||||
interface FakeToolResult {
|
|
||||||
content: Array<{ type: string; text: string }>;
|
|
||||||
details?: unknown;
|
|
||||||
terminate?: boolean;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface FakeTool {
|
|
||||||
name: string;
|
|
||||||
execute(
|
|
||||||
toolCallId: string,
|
|
||||||
params: Record<string, unknown>,
|
|
||||||
signal: AbortSignal | undefined,
|
|
||||||
onUpdate: undefined,
|
|
||||||
context: FakeContext,
|
|
||||||
): Promise<FakeToolResult>;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface GoalExtensionFactory {
|
|
||||||
(api: FakePiApi): void;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface GoalExtensionModule {
|
|
||||||
default: GoalExtensionFactory;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface FakePiApi {
|
|
||||||
on(event: string, handler: EventHandler): void;
|
|
||||||
registerCommand(name: string, options: { description: string; handler: CommandHandler }): void;
|
|
||||||
registerTool(tool: FakeTool): void;
|
|
||||||
appendEntry(customType: string, data?: unknown): void;
|
|
||||||
sendMessage(message: SentMessage['message'], options?: SentMessage['options']): void;
|
|
||||||
}
|
|
||||||
|
|
||||||
function isGoalExtensionModule(value: unknown): value is GoalExtensionModule {
|
|
||||||
if (typeof value !== 'object' || value === null) return false;
|
|
||||||
return typeof Reflect.get(value, 'default') === 'function';
|
|
||||||
}
|
|
||||||
|
|
||||||
const goalExtensionUrl = new URL('../../framework/runtime/pi/goal-extension.ts', import.meta.url)
|
|
||||||
.href;
|
|
||||||
const importedGoalExtension: unknown = await import(goalExtensionUrl);
|
|
||||||
if (!isGoalExtensionModule(importedGoalExtension)) {
|
|
||||||
throw new Error('Pi goal extension must export a default registration function');
|
|
||||||
}
|
|
||||||
const registerGoalExtension = importedGoalExtension.default;
|
|
||||||
|
|
||||||
function isRecord(value: unknown): value is Record<string, unknown> {
|
|
||||||
return typeof value === 'object' && value !== null && !Array.isArray(value);
|
|
||||||
}
|
|
||||||
|
|
||||||
class FakePi {
|
|
||||||
readonly handlers = new Map<string, EventHandler[]>();
|
|
||||||
readonly commands = new Map<string, CommandHandler>();
|
|
||||||
readonly tools = new Map<string, FakeTool>();
|
|
||||||
readonly entries: FakeEntry[] = [];
|
|
||||||
readonly sentMessages: SentMessage[] = [];
|
|
||||||
readonly notifications: Array<{ message: string; level?: string }> = [];
|
|
||||||
readonly statuses = new Map<string, string | undefined>();
|
|
||||||
branch: FakeEntry[] = [];
|
|
||||||
idle = true;
|
|
||||||
pending = false;
|
|
||||||
abortCount = 0;
|
|
||||||
|
|
||||||
readonly context: FakeContext = {
|
|
||||||
cwd: '/tmp/project',
|
|
||||||
ui: {
|
|
||||||
notifications: this.notifications,
|
|
||||||
statuses: this.statuses,
|
|
||||||
notify: (message: string, level?: string): void => {
|
|
||||||
this.notifications.push({ message, level });
|
|
||||||
},
|
|
||||||
setStatus: (key: string, value: string | undefined): void => {
|
|
||||||
this.statuses.set(key, value);
|
|
||||||
},
|
|
||||||
},
|
|
||||||
sessionManager: {
|
|
||||||
getBranch: (): FakeEntry[] => [...this.branch],
|
|
||||||
},
|
|
||||||
isIdle: (): boolean => this.idle,
|
|
||||||
hasPendingMessages: (): boolean => this.pending,
|
|
||||||
abort: (): void => {
|
|
||||||
this.abortCount += 1;
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
readonly api: FakePiApi = {
|
|
||||||
on: (event: string, handler: EventHandler): void => {
|
|
||||||
this.handlers.set(event, [...(this.handlers.get(event) ?? []), handler]);
|
|
||||||
},
|
|
||||||
registerCommand: (
|
|
||||||
name: string,
|
|
||||||
options: { description: string; handler: CommandHandler },
|
|
||||||
): void => {
|
|
||||||
this.commands.set(name, options.handler);
|
|
||||||
},
|
|
||||||
registerTool: (tool: FakeTool): void => {
|
|
||||||
this.tools.set(tool.name, tool);
|
|
||||||
},
|
|
||||||
appendEntry: (customType: string, data?: unknown): void => {
|
|
||||||
const entry: FakeEntry = { type: 'custom', customType, data };
|
|
||||||
this.entries.push(entry);
|
|
||||||
this.branch.push(entry);
|
|
||||||
},
|
|
||||||
sendMessage: (message: SentMessage['message'], options?: SentMessage['options']): void => {
|
|
||||||
this.sentMessages.push({ message, options });
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
constructor(initialBranch: FakeEntry[] = []) {
|
|
||||||
this.branch = [...initialBranch];
|
|
||||||
registerGoalExtension(this.api);
|
|
||||||
}
|
|
||||||
|
|
||||||
async emit(event: string, value: Record<string, unknown> = {}): Promise<unknown[]> {
|
|
||||||
const results: unknown[] = [];
|
|
||||||
for (const handler of this.handlers.get(event) ?? []) {
|
|
||||||
results.push(await handler(value, this.context));
|
|
||||||
}
|
|
||||||
return results;
|
|
||||||
}
|
|
||||||
|
|
||||||
async goal(args: string): Promise<void> {
|
|
||||||
const handler = this.commands.get('goal');
|
|
||||||
if (handler === undefined) throw new Error('/goal was not registered');
|
|
||||||
await handler(args, this.context);
|
|
||||||
}
|
|
||||||
|
|
||||||
async report(params: Record<string, unknown>): Promise<FakeToolResult> {
|
|
||||||
const tool = this.tools.get('mosaic_goal_report');
|
|
||||||
if (tool === undefined) throw new Error('mosaic_goal_report was not registered');
|
|
||||||
return await tool.execute('goal-report-1', params, undefined, undefined, this.context);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function latestGoalStateData(pi: FakePi): Record<string, unknown> {
|
|
||||||
for (let index = pi.entries.length - 1; index >= 0; index -= 1) {
|
|
||||||
const entry = pi.entries[index];
|
|
||||||
if (entry?.customType === 'mosaic-goal-state' && isRecord(entry.data)) return entry.data;
|
|
||||||
}
|
|
||||||
throw new Error('No persisted Mosaic goal state found');
|
|
||||||
}
|
|
||||||
|
|
||||||
function stateField(pi: FakePi, field: string): unknown {
|
|
||||||
return latestGoalStateData(pi)[field];
|
|
||||||
}
|
|
||||||
|
|
||||||
function activeGoalStatementFromContext(result: unknown): string {
|
|
||||||
if (!isRecord(result)) throw new Error('Context handler did not return an object');
|
|
||||||
const messages = result['messages'];
|
|
||||||
if (!Array.isArray(messages)) throw new Error('Context result did not include messages');
|
|
||||||
const goalMessage = messages.find(
|
|
||||||
(message: unknown): boolean =>
|
|
||||||
isRecord(message) && message['customType'] === 'mosaic-goal-context',
|
|
||||||
);
|
|
||||||
if (!isRecord(goalMessage) || typeof goalMessage['content'] !== 'string') {
|
|
||||||
throw new Error('Goal context message was not injected');
|
|
||||||
}
|
|
||||||
return goalMessage['content'];
|
|
||||||
}
|
|
||||||
|
|
||||||
afterEach(() => {
|
|
||||||
vi.useRealTimers();
|
|
||||||
vi.unstubAllEnvs();
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('Mosaic Pi goal extension commands', () => {
|
|
||||||
it('shows help and handles controls safely when no goal exists', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal('');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('/goal set');
|
|
||||||
await pi.goal('status');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('No Mosaic goal is set');
|
|
||||||
|
|
||||||
for (const command of ['pause', 'resume', 'cancel']) {
|
|
||||||
await pi.goal(command);
|
|
||||||
expect(pi.notifications.at(-1)?.level).toBe('warning');
|
|
||||||
}
|
|
||||||
expect(pi.entries).toHaveLength(0);
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('sets, reports, pauses, resumes, and cancels a bounded goal', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal('set Deliver the local goal extension with tests');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(stateField(pi, 'statement')).toBe('Deliver the local goal extension with tests');
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
expect(pi.sentMessages[0]?.options?.triggerTurn).toBe(true);
|
|
||||||
|
|
||||||
await pi.goal('status');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('Deliver the local goal extension');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('active');
|
|
||||||
|
|
||||||
await pi.goal('pause');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('paused');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
|
|
||||||
await pi.goal('resume');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
|
|
||||||
await pi.goal('cancel');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('cancelled');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('accepts /goal <statement> shorthand but refuses to replace an active goal', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal('First goal');
|
|
||||||
const firstGoalId = stateField(pi, 'goalId');
|
|
||||||
await pi.goal('set Second goal');
|
|
||||||
|
|
||||||
expect(stateField(pi, 'goalId')).toBe(firstGoalId);
|
|
||||||
expect(stateField(pi, 'statement')).toBe('First goal');
|
|
||||||
expect(pi.notifications.at(-1)?.level).toBe('warning');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('/goal cancel');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects invalid phase transitions, aborts busy work, and supports clear as cancel', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Preserve transition safety');
|
|
||||||
|
|
||||||
await pi.goal('resume');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('cannot be resumed');
|
|
||||||
pi.idle = false;
|
|
||||||
await pi.goal('pause maintenance window');
|
|
||||||
expect(stateField(pi, 'stopReason')).toBe('maintenance window');
|
|
||||||
expect(pi.abortCount).toBe(1);
|
|
||||||
await pi.goal('pause');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('cannot be paused');
|
|
||||||
await pi.goal('clear');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('cancelled');
|
|
||||||
expect(pi.abortCount).toBe(2);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects empty and oversized goal statements without starting a run', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal('set');
|
|
||||||
await pi.goal(`set ${'x'.repeat(8_001)}`);
|
|
||||||
|
|
||||||
expect(pi.entries).toHaveLength(0);
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
expect(pi.notifications.at(-1)?.level).toBe('warning');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('Mosaic Pi goal lifecycle', () => {
|
|
||||||
it('injects one fresh active contract before every model context', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Keep the agent oriented');
|
|
||||||
|
|
||||||
const existingGoalContext = {
|
|
||||||
role: 'custom',
|
|
||||||
customType: 'mosaic-goal-context',
|
|
||||||
content: 'stale',
|
|
||||||
};
|
|
||||||
const existingContinuation = {
|
|
||||||
role: 'custom',
|
|
||||||
customType: 'mosaic-goal-continuation',
|
|
||||||
content: 'stale continuation',
|
|
||||||
};
|
|
||||||
const first = await pi.emit('context', {
|
|
||||||
messages: [existingGoalContext, existingContinuation],
|
|
||||||
});
|
|
||||||
const second = await pi.emit('context', { messages: [] });
|
|
||||||
|
|
||||||
expect(activeGoalStatementFromContext(first[0])).toContain('Keep the agent oriented');
|
|
||||||
expect(activeGoalStatementFromContext(first[0])).toContain('mosaic_goal_report');
|
|
||||||
expect(activeGoalStatementFromContext(first[0])).not.toContain('stale');
|
|
||||||
if (!isRecord(first[0]) || !Array.isArray(first[0]['messages'])) {
|
|
||||||
throw new Error('Expected filtered context messages');
|
|
||||||
}
|
|
||||||
expect(first[0]['messages']).toHaveLength(1);
|
|
||||||
expect(activeGoalStatementFromContext(second[0])).toContain('Keep the agent oriented');
|
|
||||||
|
|
||||||
await pi.goal('cancel');
|
|
||||||
expect(
|
|
||||||
await pi.emit('context', {
|
|
||||||
messages: [existingGoalContext, existingContinuation],
|
|
||||||
}),
|
|
||||||
).toEqual([{ messages: [] }]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('lets an existing busy run adopt the goal and waits behind a pending message', async () => {
|
|
||||||
const busy = new FakePi();
|
|
||||||
busy.idle = false;
|
|
||||||
await busy.goal('set Join the current run safely');
|
|
||||||
expect(busy.sentMessages).toHaveLength(0);
|
|
||||||
|
|
||||||
busy.pending = true;
|
|
||||||
await busy.emit('agent_settled');
|
|
||||||
expect(busy.sentMessages).toHaveLength(0);
|
|
||||||
busy.pending = false;
|
|
||||||
busy.idle = true;
|
|
||||||
await busy.emit('agent_settled');
|
|
||||||
expect(busy.sentMessages).toHaveLength(1);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('records every turn and continues once when an active run settles', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Finish all acceptance criteria');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
|
|
||||||
await pi.emit('turn_end', { turnIndex: 0, message: {}, toolResults: [] });
|
|
||||||
expect(stateField(pi, 'turnCount')).toBe(1);
|
|
||||||
expect(stateField(pi, 'lastCheckSource')).toBe('turn');
|
|
||||||
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
expect(pi.sentMessages[0]?.message.content).toContain('Goal remains active');
|
|
||||||
|
|
||||||
await pi.emit('agent_start');
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(2);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('requires two consecutive evidence-bearing achievement reports', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Prove the feature works');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
|
|
||||||
const first = await pi.report({
|
|
||||||
status: 'achieved',
|
|
||||||
summary: 'Focused tests pass',
|
|
||||||
evidence: ['pnpm test: 12 passed'],
|
|
||||||
});
|
|
||||||
expect(first.terminate).toBe(true);
|
|
||||||
expect(stateField(pi, 'phase')).toBe('verifying');
|
|
||||||
expect(stateField(pi, 'verificationPasses')).toBe(1);
|
|
||||||
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
expect(pi.sentMessages[0]?.message.content).toContain('verification pass');
|
|
||||||
|
|
||||||
await pi.emit('agent_start');
|
|
||||||
const second = await pi.report({
|
|
||||||
status: 'achieved',
|
|
||||||
summary: 'Independent recheck confirms completion',
|
|
||||||
evidence: ['rerun: 12 passed', 'framework path verified'],
|
|
||||||
});
|
|
||||||
expect(second.terminate).toBe(true);
|
|
||||||
expect(stateField(pi, 'phase')).toBe('achieved');
|
|
||||||
expect(stateField(pi, 'verificationPasses')).toBe(2);
|
|
||||||
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects malformed progress reports and reports submitted without an active goal', async () => {
|
|
||||||
const noGoal = new FakePi();
|
|
||||||
await expect(
|
|
||||||
noGoal.report({ status: 'continue', summary: 'work', evidence: [] }),
|
|
||||||
).rejects.toThrow(/No active Mosaic goal/);
|
|
||||||
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Validate report boundaries');
|
|
||||||
const invalidReports: Record<string, unknown>[] = [
|
|
||||||
{},
|
|
||||||
{ status: 'invalid', summary: 'work', evidence: [] },
|
|
||||||
{ status: 'continue', evidence: [] },
|
|
||||||
{ status: 'continue', summary: ' ', evidence: [] },
|
|
||||||
{ status: 'continue', summary: 'x'.repeat(2_001), evidence: [] },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: 'not-an-array' },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: Array.from({ length: 21 }, () => 'x') },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: [4] },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: [''] },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: ['x'.repeat(1_001)] },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: [], nextStep: 4 },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: [], nextStep: ' ' },
|
|
||||||
{ status: 'continue', summary: 'work', evidence: [], nextStep: 'x'.repeat(2_001) },
|
|
||||||
];
|
|
||||||
for (const report of invalidReports) {
|
|
||||||
await expect(pi.report(report)).rejects.toThrow();
|
|
||||||
}
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects an achievement claim without evidence', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Require evidence');
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
pi.report({ status: 'achieved', summary: 'Trust me', evidence: [] }),
|
|
||||||
).rejects.toThrow(/evidence/i);
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('redacts credential-shaped goal and report text before persistence or display', async () => {
|
|
||||||
const githubToken = `ghp_${'a'.repeat(32)}`;
|
|
||||||
const anthropicKey = `sk-ant-api03-${'b'.repeat(40)}`;
|
|
||||||
const bearerToken = 'header.payload.signature-canary';
|
|
||||||
const databaseUrl = 'postgresql://mosaic:[email protected]/mosaic';
|
|
||||||
const password = 'password-canary';
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal(`set Rotate ${githubToken} without retaining it`);
|
|
||||||
const context = await pi.emit('context', { messages: [] });
|
|
||||||
expect(activeGoalStatementFromContext(context[0])).not.toContain(githubToken);
|
|
||||||
|
|
||||||
const result = await pi.report({
|
|
||||||
status: 'achieved',
|
|
||||||
summary: `Validated ${anthropicKey}`,
|
|
||||||
evidence: [`Authorization: Bearer ${bearerToken}`, `DATABASE_URL=${databaseUrl}`],
|
|
||||||
nextStep: `password=${password}`,
|
|
||||||
});
|
|
||||||
await pi.goal('status');
|
|
||||||
|
|
||||||
const persisted = JSON.stringify(latestGoalStateData(pi));
|
|
||||||
const displayed = pi.notifications.at(-1)?.message ?? '';
|
|
||||||
const toolOutput = JSON.stringify(result);
|
|
||||||
for (const secret of [githubToken, anthropicKey, bearerToken, databaseUrl, password]) {
|
|
||||||
expect(persisted).not.toContain(secret);
|
|
||||||
expect(displayed).not.toContain(secret);
|
|
||||||
expect(toolOutput).not.toContain(secret);
|
|
||||||
}
|
|
||||||
expect(persisted).toContain('[REDACTED-SECRET]');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('preserves ordinary typed fields that resemble sensitive assignment names', async () => {
|
|
||||||
const typedFields = 'token: string, password: boolean, secret: false';
|
|
||||||
const pi = new FakePi();
|
|
||||||
|
|
||||||
await pi.goal(`set Preserve TypeScript fields: ${typedFields}`);
|
|
||||||
await pi.report({
|
|
||||||
status: 'continue',
|
|
||||||
summary: `Schema still contains ${typedFields}`,
|
|
||||||
evidence: [`interface Config { ${typedFields} }`],
|
|
||||||
nextStep: `Keep ${typedFields} unchanged`,
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(stateField(pi, 'statement')).toContain(typedFields);
|
|
||||||
expect(JSON.stringify(stateField(pi, 'lastReport'))).toContain(typedFields);
|
|
||||||
expect(JSON.stringify(latestGoalStateData(pi))).not.toContain('[REDACTED-SECRET]');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('stops autonomous continuation when the max-turn limit is reached', async () => {
|
|
||||||
vi.stubEnv('MOSAIC_GOAL_MAX_TURNS', '2');
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Bound this run');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
|
|
||||||
await pi.emit('turn_end', { turnIndex: 0, message: {}, toolResults: [] });
|
|
||||||
await pi.emit('turn_end', { turnIndex: 1, message: {}, toolResults: [] });
|
|
||||||
|
|
||||||
expect(stateField(pi, 'phase')).toBe('exhausted');
|
|
||||||
expect(pi.abortCount).toBe(1);
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('resets the no-progress sequence when a continuation report changes', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Track changing progress');
|
|
||||||
|
|
||||||
await pi.report({
|
|
||||||
status: 'continue',
|
|
||||||
summary: 'First checkpoint',
|
|
||||||
evidence: ['file A changed'],
|
|
||||||
nextStep: 'Run focused tests',
|
|
||||||
});
|
|
||||||
await pi.report({
|
|
||||||
status: 'continue',
|
|
||||||
summary: 'Second checkpoint',
|
|
||||||
evidence: ['focused tests passed'],
|
|
||||||
nextStep: 'Review the diff',
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(stateField(pi, 'noProgressReports')).toBe(1);
|
|
||||||
await pi.goal('status');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('Next step: Review the diff');
|
|
||||||
expect(pi.notifications.at(-1)?.message).toContain('focused tests passed');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('stops after a bounded number of identical no-progress reports', async () => {
|
|
||||||
vi.stubEnv('MOSAIC_GOAL_MAX_NO_PROGRESS', '2');
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Detect stalled work');
|
|
||||||
|
|
||||||
const report = {
|
|
||||||
status: 'continue',
|
|
||||||
summary: 'No change yet',
|
|
||||||
evidence: ['same observation'],
|
|
||||||
nextStep: 'Try again',
|
|
||||||
};
|
|
||||||
await pi.report(report);
|
|
||||||
await pi.report(report);
|
|
||||||
|
|
||||||
expect(stateField(pi, 'phase')).toBe('exhausted');
|
|
||||||
expect(stateField(pi, 'noProgressReports')).toBe(2);
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a goal report mixed with another tool result in the same turn', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Require a sole final report');
|
|
||||||
await pi.report({
|
|
||||||
status: 'achieved',
|
|
||||||
summary: 'Premature mixed claim',
|
|
||||||
evidence: ['one observation'],
|
|
||||||
});
|
|
||||||
|
|
||||||
await pi.emit('turn_end', {
|
|
||||||
turnIndex: 0,
|
|
||||||
message: {},
|
|
||||||
toolResults: [{ toolName: 'mosaic_goal_report' }, { toolName: 'read' }],
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(stateField(pi, 'verificationPasses')).toBe(0);
|
|
||||||
expect(stateField(pi, 'lastCheckOutcome')).toBe('mixed-goal-report-rejected');
|
|
||||||
expect(pi.notifications.at(-1)?.level).toBe('warning');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('marks blocked reports terminal until the operator resumes', async () => {
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Stop on a real blocker');
|
|
||||||
|
|
||||||
await pi.report({
|
|
||||||
status: 'blocked',
|
|
||||||
summary: 'Missing required access',
|
|
||||||
evidence: ['provider returned 403'],
|
|
||||||
});
|
|
||||||
expect(stateField(pi, 'phase')).toBe('blocked');
|
|
||||||
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
|
|
||||||
await pi.goal('resume');
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(stateField(pi, 'turnCount')).toBe(0);
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('Mosaic Pi goal compaction and restoration', () => {
|
|
||||||
it('resets provisional verification and defers manual-compaction continuation until idle', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Survive compaction');
|
|
||||||
await pi.report({
|
|
||||||
status: 'achieved',
|
|
||||||
summary: 'Initial claim',
|
|
||||||
evidence: ['focused test passed'],
|
|
||||||
});
|
|
||||||
expect(stateField(pi, 'phase')).toBe('verifying');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
|
|
||||||
await pi.emit('session_compact', { reason: 'manual', willRetry: false });
|
|
||||||
expect(stateField(pi, 'phase')).toBe('active');
|
|
||||||
expect(stateField(pi, 'verificationPasses')).toBe(0);
|
|
||||||
expect(stateField(pi, 'compactionCount')).toBe(1);
|
|
||||||
expect(stateField(pi, 'lastCheckSource')).toBe('compact');
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
|
|
||||||
await vi.runAllTimersAsync();
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
expect(pi.sentMessages[0]?.message.content).toContain('compaction');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('does not re-enter an active automatic compaction and relies on the settled backstop', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Avoid compaction races');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
pi.idle = false;
|
|
||||||
|
|
||||||
await pi.emit('session_compact', { reason: 'threshold', willRetry: false });
|
|
||||||
await vi.runAllTimersAsync();
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
|
|
||||||
pi.idle = true;
|
|
||||||
await pi.emit('agent_settled');
|
|
||||||
expect(pi.sentMessages).toHaveLength(1);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('restores branch-specific state on session start and tree navigation', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const source = new FakePi();
|
|
||||||
await source.goal('set Restore this exact branch goal');
|
|
||||||
const activeState = latestGoalStateData(source);
|
|
||||||
|
|
||||||
const restored = new FakePi([
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: activeState },
|
|
||||||
]);
|
|
||||||
await restored.emit('session_start', { reason: 'resume' });
|
|
||||||
expect(restored.statuses.get('mosaic-goal')).toContain('active');
|
|
||||||
const context = await restored.emit('context', { messages: [] });
|
|
||||||
expect(activeGoalStatementFromContext(context[0])).toContain('Restore this exact branch goal');
|
|
||||||
|
|
||||||
await restored.goal('pause');
|
|
||||||
const pausedState = latestGoalStateData(restored);
|
|
||||||
restored.branch = [{ type: 'custom', customType: 'mosaic-goal-state', data: pausedState }];
|
|
||||||
await restored.emit('session_tree', {});
|
|
||||||
await vi.runAllTimersAsync();
|
|
||||||
expect(stateField(restored, 'phase')).toBe('paused');
|
|
||||||
expect(restored.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('restores only fully valid persisted states and ignores malformed entries', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const source = new FakePi();
|
|
||||||
await source.goal('set Validate persisted branch state');
|
|
||||||
await source.report({
|
|
||||||
status: 'continue',
|
|
||||||
summary: 'Valid report',
|
|
||||||
evidence: ['valid evidence'],
|
|
||||||
nextStep: 'Continue validation',
|
|
||||||
});
|
|
||||||
const valid = latestGoalStateData(source);
|
|
||||||
|
|
||||||
const validRestore = new FakePi([
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: valid },
|
|
||||||
]);
|
|
||||||
await validRestore.emit('session_start', { reason: 'resume' });
|
|
||||||
expect(stateField(validRestore, 'statement')).toBe('Validate persisted branch state');
|
|
||||||
await validRestore.emit('session_shutdown', { reason: 'reload' });
|
|
||||||
|
|
||||||
const validReport = latestGoalStateData(source)['lastReport'];
|
|
||||||
if (!isRecord(validReport)) throw new Error('Expected a valid persisted report fixture');
|
|
||||||
const integerFields = [
|
|
||||||
'turnCount',
|
|
||||||
'reportCount',
|
|
||||||
'verificationPasses',
|
|
||||||
'requiredVerificationPasses',
|
|
||||||
'noProgressReports',
|
|
||||||
'maxTurns',
|
|
||||||
'maxNoProgressReports',
|
|
||||||
'compactionCount',
|
|
||||||
];
|
|
||||||
const corruptions: Array<(state: Record<string, unknown>) => unknown> = [
|
|
||||||
(): unknown => null,
|
|
||||||
(state): unknown => ({ ...state, version: 99 }),
|
|
||||||
(state): unknown => ({ ...state, goalId: '' }),
|
|
||||||
(state): unknown => ({ ...state, statement: '' }),
|
|
||||||
(state): unknown => ({ ...state, statement: 'x'.repeat(8_001) }),
|
|
||||||
(state): unknown => ({ ...state, phase: 'unknown' }),
|
|
||||||
(state): unknown => ({ ...state, lastCheckSource: 'unknown' }),
|
|
||||||
(state): unknown => ({ ...state, startedAt: 4 }),
|
|
||||||
(state): unknown => ({ ...state, lastCheckAt: 4 }),
|
|
||||||
(state): unknown => ({ ...state, lastReport: null }),
|
|
||||||
(state): unknown => ({ ...state, lastProgressFingerprint: 4 }),
|
|
||||||
(state): unknown => ({ ...state, stopReason: 4 }),
|
|
||||||
...integerFields.map((field: string) => (state: Record<string, unknown>): unknown => ({
|
|
||||||
...state,
|
|
||||||
[field]: -1,
|
|
||||||
})),
|
|
||||||
];
|
|
||||||
|
|
||||||
corruptions.push(
|
|
||||||
(state: Record<string, unknown>): unknown => ({ ...state, maxTurns: 501 }),
|
|
||||||
(state: Record<string, unknown>): unknown => ({ ...state, maxNoProgressReports: 101 }),
|
|
||||||
(state: Record<string, unknown>): unknown => ({ ...state, requiredVerificationPasses: 3 }),
|
|
||||||
);
|
|
||||||
const reportCorruptions: Array<Record<string, unknown>> = [
|
|
||||||
{ ...validReport, status: 'bad' },
|
|
||||||
{ ...validReport, summary: '' },
|
|
||||||
{ ...validReport, evidence: 'bad' },
|
|
||||||
{ ...validReport, evidence: [4] },
|
|
||||||
{ ...validReport, fingerprint: '' },
|
|
||||||
{ ...validReport, reportedAt: '' },
|
|
||||||
{ ...validReport, nextStep: 4 },
|
|
||||||
];
|
|
||||||
for (const corruptReport of reportCorruptions) {
|
|
||||||
corruptions.push((state: Record<string, unknown>): unknown => ({
|
|
||||||
...state,
|
|
||||||
lastReport: corruptReport,
|
|
||||||
}));
|
|
||||||
}
|
|
||||||
|
|
||||||
for (const corrupt of corruptions) {
|
|
||||||
const candidate = corrupt(structuredClone(valid));
|
|
||||||
const restored = new FakePi([
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: candidate },
|
|
||||||
]);
|
|
||||||
await restored.emit('session_start', { reason: 'resume' });
|
|
||||||
expect(restored.statuses.get('mosaic-goal')).toBeUndefined();
|
|
||||||
expect(await restored.emit('context', { messages: [] })).toEqual([undefined]);
|
|
||||||
}
|
|
||||||
|
|
||||||
const failClosed = new FakePi([
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: valid },
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: { ...valid, version: 99 } },
|
|
||||||
]);
|
|
||||||
await failClosed.emit('session_start', { reason: 'resume' });
|
|
||||||
expect(failClosed.statuses.get('mosaic-goal')).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('fails closed instead of reusing credential-bearing legacy branch state', async () => {
|
|
||||||
const source = new FakePi();
|
|
||||||
await source.goal('set Build a valid restore fixture');
|
|
||||||
const cleanState = latestGoalStateData(source);
|
|
||||||
const legacyState = structuredClone(cleanState);
|
|
||||||
legacyState['statement'] = `Legacy secret ghp_${'z'.repeat(32)}`;
|
|
||||||
|
|
||||||
const restored = new FakePi([
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: legacyState },
|
|
||||||
{ type: 'custom', customType: 'mosaic-goal-state', data: cleanState },
|
|
||||||
]);
|
|
||||||
await restored.emit('session_start', { reason: 'resume' });
|
|
||||||
|
|
||||||
expect(restored.statuses.get('mosaic-goal')).toBeUndefined();
|
|
||||||
expect(await restored.emit('context', { messages: [] })).toEqual([undefined]);
|
|
||||||
expect(restored.notifications.at(-1)?.level).toBe('warning');
|
|
||||||
expect(restored.notifications.at(-1)?.message).toContain('was not restored');
|
|
||||||
expect(restored.entries).toHaveLength(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('schedules an active tree-restored goal and preserves terminal state through compaction', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const source = new FakePi();
|
|
||||||
await source.goal('set Restore active tree work');
|
|
||||||
const active = latestGoalStateData(source);
|
|
||||||
|
|
||||||
const restored = new FakePi();
|
|
||||||
restored.branch = [{ type: 'custom', customType: 'mosaic-goal-state', data: active }];
|
|
||||||
await restored.emit('session_tree', {});
|
|
||||||
await vi.runAllTimersAsync();
|
|
||||||
expect(restored.sentMessages).toHaveLength(1);
|
|
||||||
expect(restored.sentMessages[0]?.message.content).toContain('tree navigation');
|
|
||||||
|
|
||||||
await restored.goal('cancel');
|
|
||||||
await restored.emit('session_compact', { reason: 'manual', willRetry: false });
|
|
||||||
expect(stateField(restored, 'phase')).toBe('cancelled');
|
|
||||||
expect(stateField(restored, 'compactionCount')).toBe(1);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('cancels deferred continuation when the session shuts down', async () => {
|
|
||||||
vi.useFakeTimers();
|
|
||||||
const pi = new FakePi();
|
|
||||||
await pi.goal('set Do not leak a stale timer');
|
|
||||||
pi.sentMessages.length = 0;
|
|
||||||
|
|
||||||
await pi.emit('session_compact', { reason: 'manual', willRetry: false });
|
|
||||||
await pi.emit('session_shutdown', { reason: 'reload' });
|
|
||||||
await vi.runAllTimersAsync();
|
|
||||||
|
|
||||||
expect(pi.sentMessages).toHaveLength(0);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -72,9 +72,8 @@ elif [[ -n "$DATA_DIR" ]]; then
|
|||||||
while IFS= read -r file; do
|
while IFS= read -r file; do
|
||||||
[[ -z "$file" ]] && continue
|
[[ -z "$file" ]] && continue
|
||||||
done_total=$((done_total + 1))
|
done_total=$((done_total + 1))
|
||||||
history_rc=0
|
if git -C "$DATA_DIR" log --since="${WINDOW_DAYS} days ago" --pretty='%s' -- "$file" 2>/dev/null \
|
||||||
history="$(git -C "$DATA_DIR" log --since="${WINDOW_DAYS} days ago" --pretty='%s' -- "$file" 2>/dev/null)" || history_rc=$?
|
| grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo'; then
|
||||||
if [[ "$history_rc" -eq 0 ]] && grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo' <<<"$history"; then
|
|
||||||
detectable=$((detectable + 1))
|
detectable=$((detectable + 1))
|
||||||
fi
|
fi
|
||||||
done < <(find "$DATA_DIR" -type f -name '*.json' 2>/dev/null)
|
done < <(find "$DATA_DIR" -type f -name '*.json' 2>/dev/null)
|
||||||
|
|||||||
@@ -64,9 +64,9 @@ for line in "${LINES[@]}"; do
|
|||||||
# - build/test/lint/type/ci signals → CI would have caught it
|
# - build/test/lint/type/ci signals → CI would have caught it
|
||||||
# - security/auth/permission/data/migration → human review would flag it
|
# - security/auth/permission/data/migration → human review would flag it
|
||||||
# - everything else (logic/UX/assumption/edge) → only-self-reflection bucket
|
# - everything else (logic/UX/assumption/edge) → only-self-reflection bucket
|
||||||
if grep -qiE 'test|lint|type|build|ci|compile|typo' <<<"$subj"; then
|
if printf '%s' "$subj" | grep -qiE 'test|lint|type|build|ci|compile|typo'; then
|
||||||
ci=$((ci + 1))
|
ci=$((ci + 1))
|
||||||
elif grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection' <<<"$subj"; then
|
elif printf '%s' "$subj" | grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection'; then
|
||||||
human=$((human + 1))
|
human=$((human + 1))
|
||||||
else
|
else
|
||||||
selfonly=$((selfonly + 1))
|
selfonly=$((selfonly + 1))
|
||||||
|
|||||||
@@ -1,28 +0,0 @@
|
|||||||
[
|
|
||||||
"tools/matrix-presence-harness/run.sh:TSX_CLI=\"$(ls -d \"${REPO}\"/node_modules/.pnpm/tsx@*/node_modules/tsx/dist/cli.mjs 2>/dev/null | head -1)\"",
|
|
||||||
"tools/e2e-install-test.sh:if ! mosaic gateway --help 2>&1 | grep -q 'verify'; then",
|
|
||||||
"tools/install.sh:EXTRACTED_DIR=\"$(find \"$WORK_DIR\" -maxdepth 1 -mindepth 1 -type d | head -1)\"",
|
|
||||||
"scripts/analysis/reflect-board-history.sh:if git -C \"$DATA_DIR\" log --since=\"${WINDOW_DAYS} days ago\" --pretty='%s' -- \"$file\" 2>/dev/null | grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo'; then",
|
|
||||||
"scripts/analysis/reflect-git-history.sh:if printf '%s' \"$subj\" | grep -qiE 'test|lint|type|build|ci|compile|typo'; then",
|
|
||||||
"scripts/analysis/reflect-git-history.sh:elif printf '%s' \"$subj\" | grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection'; then",
|
|
||||||
"packages/mosaic/framework/tools/authentik/user-create.sh:group_pk=$(echo \"$group_response\" | jq -r \".results[] | select(.name == \\\"$GROUP\\\") | .pk\" | head -1)",
|
|
||||||
"packages/mosaic/framework/tools/git/mutate-push-guard.sh:PROSE_LO=\"$(grep -n '^usage() {' \"$BAK\" | head -1 | cut -d: -f1)\"",
|
|
||||||
"packages/mosaic/framework/tools/orchestrator/session-resume.sh:echo \"$dirty_files\" | head -20 | while IFS= read -r line; do",
|
|
||||||
"packages/mosaic/framework/tools/prdy/prdy-status.sh:if echo \"$PRD_CONTENT\" | grep -qiE \"$pattern\"; then",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'auth|login|session|token|permission|rbac|credential|secret'; then echo auth; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'migration|prisma|schema|\\.sql|entity|repository|seed'; then echo data; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'docker|\\.woodpecker|compose|traefik|deploy|helm|k8s|terraform'; then echo infra; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'package\\.json|tsconfig|turbo\\.json|pnpm-|\\.config\\.|eslint|vite'; then echo build; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.tsx|\\.css|components/|apps/web/'; then echo ui; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.spec\\.|\\.test\\.|__tests__/'; then echo test; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.md$|docs/'; then echo docs; return; fi",
|
|
||||||
"packages/mosaic/framework/tools/qa/typecheck-hook.sh:FILE_PATH=$(echo \"$JSON_INPUT\" | grep -o '\"file_path\"[[:space:]]*:[[:space:]]*\"[^\"]*\"' | sed 's/.*\"\\([^\"]*\\)\"$/\\1/' | head -1)",
|
|
||||||
"packages/mosaic/framework/tools/qa/typecheck-hook.sh:RELEVANT=$(echo \"$OUTPUT\" | grep -A2 \"$BASENAME\" 2>/dev/null || echo \"$OUTPUT\" | head -20)",
|
|
||||||
"packages/mosaic/framework/tools/tmux/send-message.sh:if printf '%s' \"$pane\" | grep -qF \"$QUEUED_RE\"; then",
|
|
||||||
"packages/mosaic/framework/tools/tmux/send-message.sh:if [ -n \"$snippet\" ] && printf '%s' \"$promptline\" | grep -qF \"$snippet\"; then",
|
|
||||||
"packages/mosaic/framework/tools/wake/detector.sh:sed -n \"s/^${key}=//p\" \"$MANIFEST\" | head -n1 | tr -d '[:space:]'",
|
|
||||||
"packages/mosaic/framework/tools/wake/detector.sh:if [ -n \"$snap_sha\" ] && ! printf '%s' \"$snap_sha\" | grep -Eq '^[0-9a-f]{7,64}$'; then",
|
|
||||||
"packages/mosaic/framework/tools/wake/detector.sh:if [ -n \"$snap_ts\" ] && ! printf '%s' \"$snap_ts\" | grep -Eq '^[0-9]{1,12}$'; then",
|
|
||||||
"packages/mosaic/framework/tools/wake/digest.sh:olabel=\"$(_locator_line \"$oloc\" | head -n1)\"",
|
|
||||||
"packages/mosaic/framework/tools/wake/reconcile.sh:sed -n \"s/^${key}=//p\" \"$MANIFEST\" | head -n1 | tr -d '[:space:]'"
|
|
||||||
]
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
[
|
|
||||||
"packages/mosaic/framework/systemd/user/test-fleet-units.sh:if tmux -L \"$TEST_SOCKET\" show-environment -g LD_PRELOAD 2>/dev/null | grep -q '^LD_PRELOAD='; then",
|
|
||||||
"packages/mosaic/framework/tools/git/test-issue-comment-readback.sh:write_response \"$(printf '%s' \"$result\" | head -n1)\" \"$(printf '%s' \"$result\" | tail -n +2)\"",
|
|
||||||
"packages/mosaic/framework/tools/git/test-issue-comment-readback.sh:write_response \"$(printf '%s' \"$result\" | head -n1)\" \"$(printf '%s' \"$result\" | tail -n +2)\"",
|
|
||||||
"packages/mosaic/framework/tools/git/test-lane-brief-pr-linkage.sh:contains() { printf '%s\\n' \"$1\" | grep -qx \"$2\"; }",
|
|
||||||
"packages/mosaic/framework/tools/git/test-pr-review-gitea-comment.sh:write_response \"$(printf '%s' \"$result\" | head -n1)\" \"$(printf '%s' \"$result\" | tail -n +2)\"",
|
|
||||||
"packages/mosaic/framework/tools/git/test-pr-review-repo-host-override.sh:echo \"$HELP_TEXT\" | grep -q -- '-r, --repo'",
|
|
||||||
"packages/mosaic/framework/tools/git/test-pr-review-repo-host-override.sh:echo \"$HELP_TEXT\" | grep -q -- '-H, --host'",
|
|
||||||
"packages/mosaic/framework/tools/orchestrator/smoke-test.sh:if [[ \"$(printf '%s\\n' \"$codex_run_prompt\" | head -n1)\" == \"Now initiating Orchestrator mode...\" ]]; then pass_case \"codex run prompt first line is mode declaration\"; else fail_case \"codex run prompt first line is mode declaration\"; fi",
|
|
||||||
"packages/mosaic/framework/tools/orchestrator/smoke-test.sh:if [[ \"$(printf '%s\\n' \"$claude_run_prompt\" | head -n1)\" == \"## Continuation Mission\" ]]; then pass_case \"claude run prompt remains continuation prompt format\"; else fail_case \"claude run prompt remains continuation prompt format\"; fi",
|
|
||||||
"packages/mosaic/framework/tools/orchestrator/test-board-roll.sh:echo \"$out\" | grep -qi \"dry run\" || note \"dry-run did not announce itself\"",
|
|
||||||
"packages/mosaic/framework/tools/orchestrator/test-board-roll.sh:echo \"$out\" | grep -q \"would roll\" || note \"dry-run did not report a plan\"",
|
|
||||||
"packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh:find \"$1/mosaic/backups\" -maxdepth 1 -type d -name 'pre-update-*' 2>/dev/null | LC_ALL=C sort -r | head -1",
|
|
||||||
"packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh:SNAP_E=\"$(grep -o '/[^ ]*mosaic-snapshot[^ ]*' \"$OUTG\" | head -1)\"",
|
|
||||||
"packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh:grep -o '/[^ ]*mosaic-snapshot[^ ]*' \"$OUTH\" 2>/dev/null | head -1 | while read -r s; do rm -rf \"$s\"; done",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:capture_named | grep -qF \"named socket hello\" || fail \"send-message.sh did not deliver to named socket\"",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:if capture_default | grep -qF \"named socket hello\"; then",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:capture_named | grep -qF \"[tester:source ->\" || fail \"agent-send.sh did not include preamble\"",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:capture_named | grep -qF \"agent socket hello\" || fail \"agent-send.sh did not deliver to named socket\"",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:if capture_default | grep -qF \"agent socket hello\"; then",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:printf '%s' \"$pane\" | grep -qF \"CONCPAYLOAD-${i}-END\" || fail \"concurrent send dropped payload for pane conc-$i\"",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-socket.sh:if printf '%s' \"$pane\" | grep -qF \"CONCPAYLOAD-${j}-END\"; then",
|
|
||||||
"packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh:if [ \"$rc\" -eq 0 ] && printf '%s' \"$out\" | grep -qF \"✓ delivered\"; then"
|
|
||||||
]
|
|
||||||
@@ -1,160 +0,0 @@
|
|||||||
import assert from 'node:assert/strict';
|
|
||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import { chmod, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import path from 'node:path';
|
|
||||||
import test from 'node:test';
|
|
||||||
|
|
||||||
const ROOT = new URL('../', import.meta.url);
|
|
||||||
const EXPECTED_BASELINE_SITES = 26;
|
|
||||||
const EXPECTED_TEST_BASELINE_SITES = 22;
|
|
||||||
const TARGETS = [
|
|
||||||
'tools/matrix-presence-harness/run.sh',
|
|
||||||
'tools/e2e-install-test.sh',
|
|
||||||
'tools/install.sh',
|
|
||||||
'scripts/agent/session-start.sh',
|
|
||||||
'scripts/analysis/reflect-board-history.sh',
|
|
||||||
'scripts/analysis/reflect-git-history.sh',
|
|
||||||
'packages/mosaic/framework/templates/repo/scripts/agent/session-start.sh',
|
|
||||||
'packages/mosaic/framework/tools/authentik/user-create.sh',
|
|
||||||
'packages/mosaic/framework/tools/git/mutate-push-guard.sh',
|
|
||||||
'packages/mosaic/framework/tools/orchestrator/session-resume.sh',
|
|
||||||
'packages/mosaic/framework/tools/prdy/prdy-status.sh',
|
|
||||||
'packages/mosaic/framework/tools/qa/reflect-stop-hook.sh',
|
|
||||||
'packages/mosaic/framework/tools/qa/typecheck-hook.sh',
|
|
||||||
'packages/mosaic/framework/tools/tmux/send-message.sh',
|
|
||||||
'packages/mosaic/framework/tools/wake/detector.sh',
|
|
||||||
'packages/mosaic/framework/tools/wake/digest.sh',
|
|
||||||
'packages/mosaic/framework/tools/wake/reconcile.sh',
|
|
||||||
'packages/mosaic/framework/systemd/user/test-fleet-units.sh',
|
|
||||||
'packages/mosaic/framework/tools/git/test-issue-comment-readback.sh',
|
|
||||||
'packages/mosaic/framework/tools/git/test-lane-brief-pr-linkage.sh',
|
|
||||||
'packages/mosaic/framework/tools/git/test-pr-review-gitea-comment.sh',
|
|
||||||
'packages/mosaic/framework/tools/git/test-pr-review-repo-host-override.sh',
|
|
||||||
'packages/mosaic/framework/tools/orchestrator/smoke-test.sh',
|
|
||||||
'packages/mosaic/framework/tools/orchestrator/test-board-roll.sh',
|
|
||||||
'packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh',
|
|
||||||
'packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh',
|
|
||||||
'packages/mosaic/framework/tools/tmux/test-send-message-socket.sh',
|
|
||||||
'packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh',
|
|
||||||
];
|
|
||||||
|
|
||||||
// These statuses are explicitly non-load-bearing or unreachable at designed input.
|
|
||||||
// They remain inventoried until the final #1099 tranche records every verdict.
|
|
||||||
const ACCEPTED = [
|
|
||||||
['tools/install.sh', 'mosaic-bak-', '|| true'],
|
|
||||||
['tools/install.sh', 'mosaicstack-mosaic-*.tgz', 'head -1'],
|
|
||||||
['tools/install.sh', 'mosaicstack-gateway-*.tgz', 'head -1'],
|
|
||||||
['scripts/agent/session-start.sh', 'docs/scratchpads/*.md', '|| true'],
|
|
||||||
[
|
|
||||||
'packages/mosaic/framework/templates/repo/scripts/agent/session-start.sh',
|
|
||||||
'docs/scratchpads/*.md',
|
|
||||||
'|| true',
|
|
||||||
],
|
|
||||||
];
|
|
||||||
|
|
||||||
const earlyExit =
|
|
||||||
/(?<!\|)\|(?!\|)[^;\n]*(?:grep\b[^;\n]*(?:-[A-Za-z]*q|--quiet|-m\s*1)|head\b(?:\s|$))/;
|
|
||||||
|
|
||||||
function scan(sources) {
|
|
||||||
const found = [];
|
|
||||||
for (const [file, rawSource] of sources) {
|
|
||||||
const source = rawSource.replace(/\\\n\s*/g, ' ');
|
|
||||||
for (const rawLine of source.split('\n')) {
|
|
||||||
const line = rawLine.trim();
|
|
||||||
if (!earlyExit.test(line)) continue;
|
|
||||||
const accepted = ACCEPTED.some(
|
|
||||||
([acceptedFile, ...fragments]) =>
|
|
||||||
acceptedFile === file && fragments.every((item) => line.includes(item)),
|
|
||||||
);
|
|
||||||
if (!accepted) found.push(`${file}:${line}`);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return found;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function currentSources() {
|
|
||||||
return Promise.all(
|
|
||||||
TARGETS.map(async (file) => [file, await readFile(new URL(file, ROOT), 'utf8')]),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function assertBaselineFixture(file, expectedCount, expectedUnique = expectedCount) {
|
|
||||||
const baseline = JSON.parse(await readFile(new URL(file, ROOT), 'utf8'));
|
|
||||||
assert.equal(baseline.length, expectedCount);
|
|
||||||
assert.equal(new Set(baseline).size, expectedUnique);
|
|
||||||
const fixtureSources = baseline.map((site) => {
|
|
||||||
const separator = site.indexOf(':');
|
|
||||||
assert.ok(separator > 0, `invalid baseline site: ${site}`);
|
|
||||||
return [site.slice(0, separator), site.slice(separator + 1)];
|
|
||||||
});
|
|
||||||
assert.deepEqual(scan(fixtureSources), baseline);
|
|
||||||
}
|
|
||||||
|
|
||||||
test('the registered runtime baseline denominator is exactly 26 unsafe sites', async () => {
|
|
||||||
await assertBaselineFixture(
|
|
||||||
'scripts/fixtures/pipefail-early-exit-baseline.json',
|
|
||||||
EXPECTED_BASELINE_SITES,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('the registered test baseline denominator is exactly 22 unsafe sites', async () => {
|
|
||||||
await assertBaselineFixture(
|
|
||||||
'scripts/fixtures/pipefail-early-exit-test-baseline.json',
|
|
||||||
EXPECTED_TEST_BASELINE_SITES,
|
|
||||||
21,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('load-bearing pipefail paths do not pipe into early-exiting consumers', async () => {
|
|
||||||
assert.deepEqual(scan(await currentSources()), []);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('gateway verify capability preserves the complete help-probe truth table', async () => {
|
|
||||||
const directory = await mkdtemp(path.join(tmpdir(), 'gateway-help-probe-'));
|
|
||||||
const mosaic = path.join(directory, 'mosaic');
|
|
||||||
const probe = new URL('tools/e2e-gateway-verify-supported.sh', ROOT).pathname;
|
|
||||||
try {
|
|
||||||
await writeFile(
|
|
||||||
mosaic,
|
|
||||||
'#!/usr/bin/env bash\nprintf \'%s\\n\' "${MOCK_HELP_OUTPUT:-}"\nexit "${MOCK_HELP_RC:-0}"\n',
|
|
||||||
);
|
|
||||||
await chmod(mosaic, 0o755);
|
|
||||||
const run = (rc, output) =>
|
|
||||||
spawnSync('bash', [probe], {
|
|
||||||
env: {
|
|
||||||
...process.env,
|
|
||||||
PATH: `${directory}:${process.env.PATH}`,
|
|
||||||
MOCK_HELP_RC: String(rc),
|
|
||||||
MOCK_HELP_OUTPUT: output,
|
|
||||||
},
|
|
||||||
}).status;
|
|
||||||
|
|
||||||
assert.equal(run(0, 'commands: verify'), 0);
|
|
||||||
assert.equal(run(0, 'commands: install'), 1);
|
|
||||||
assert.equal(run(1, 'commands: verify'), 1);
|
|
||||||
} finally {
|
|
||||||
await rm(directory, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
test('board-history preserves non-git data-dir as a non-detectable result', async () => {
|
|
||||||
const directory = await mkdtemp(path.join(tmpdir(), 'reflect-board-non-git-'));
|
|
||||||
try {
|
|
||||||
await writeFile(path.join(directory, 'task.json'), '{}\n');
|
|
||||||
const result = spawnSync(
|
|
||||||
'bash',
|
|
||||||
[
|
|
||||||
new URL('scripts/analysis/reflect-board-history.sh', ROOT).pathname,
|
|
||||||
'--data-dir',
|
|
||||||
directory,
|
|
||||||
],
|
|
||||||
{ encoding: 'utf8' },
|
|
||||||
);
|
|
||||||
assert.equal(result.status, 0, result.stderr);
|
|
||||||
assert.match(result.stdout, /"done_tasks": 1/);
|
|
||||||
assert.match(result.stdout, /"detectable_outcomes": 0/);
|
|
||||||
} finally {
|
|
||||||
await rm(directory, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Exit 0 only when the capability probe itself succeeds and advertises verify.
|
|
||||||
# A failed help command and a successful response without verify are both
|
|
||||||
# unsupported, matching the historical e2e-install-test.sh conditional.
|
|
||||||
set -uo pipefail
|
|
||||||
|
|
||||||
gateway_help_rc=0
|
|
||||||
gateway_help="$(mosaic gateway --help 2>&1)" || gateway_help_rc=$?
|
|
||||||
[[ "$gateway_help_rc" -eq 0 ]] || exit 1
|
|
||||||
grep -q 'verify' <<<"$gateway_help"
|
|
||||||
+339
-163
@@ -1,184 +1,360 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# ─── Mosaic Stack — End-to-End Install Test ────────────────────────────────────
|
# Greenfield installer acceptance fixture.
|
||||||
#
|
#
|
||||||
# Runs a clean-container install test to verify the full first-run flow:
|
# The fixture itself is intentionally RED until the C2-C5 phase owners repair
|
||||||
# tools/install.sh -> mosaic wizard (non-interactive)
|
# their postconditions. C1's CI gate executes it and validates that the RED is
|
||||||
# -> mosaic gateway install
|
# attributable (including the discriminating P3 PASS); it does not turn the
|
||||||
# -> mosaic gateway verify
|
# failed install into a false green.
|
||||||
#
|
|
||||||
# Usage:
|
|
||||||
# bash tools/e2e-install-test.sh
|
|
||||||
#
|
|
||||||
# Requirements:
|
|
||||||
# - Docker (skips gracefully if not available)
|
|
||||||
# - Run from the repository root
|
|
||||||
#
|
|
||||||
# How it works:
|
|
||||||
# 1. Mounts the repository into a node:22-alpine container.
|
|
||||||
# 2. Installs prerequisites (bash, curl, jq, git) inside the container.
|
|
||||||
# 3. Runs `bash tools/install.sh --yes --no-auto-launch` to install the
|
|
||||||
# framework and CLI from the Gitea registry.
|
|
||||||
# 4. Runs `mosaic wizard --non-interactive` to set up SOUL/USER.
|
|
||||||
# 5. Runs `mosaic gateway install` with piped defaults (non-interactive).
|
|
||||||
# 6. Runs `mosaic gateway verify` and checks its exit code.
|
|
||||||
# NOTE: `mosaic gateway verify` is a new command added in the
|
|
||||||
# feat/mosaic-first-run-ux branch. If the installed CLI version
|
|
||||||
# pre-dates this branch (does not have `gateway verify`), the test
|
|
||||||
# marks this step as EXPECTED-SKIP and reports the installed version.
|
|
||||||
# 7. Reports PASS or FAIL with a summary.
|
|
||||||
#
|
|
||||||
# To run manually:
|
|
||||||
# cd /path/to/mosaic-stack
|
|
||||||
# bash tools/e2e-install-test.sh
|
|
||||||
#
|
|
||||||
# ──────────────────────────────────────────────────────────────────────────────
|
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
IMAGE="node:22-alpine"
|
LANE="${MOSAIC_INSTALL_LANE:-next}"
|
||||||
CONTAINER_NAME="mosaic-e2e-install-$$"
|
SOURCE="${MOSAIC_INSTALL_SOURCE:-checkout}"
|
||||||
|
IMAGE="${MOSAIC_INSTALL_IMAGE:-node:22-bookworm-slim}"
|
||||||
|
GIT_MODE="${MOSAIC_INSTALL_GIT_MODE:-present}"
|
||||||
|
INSTALLER_FILE="${MOSAIC_FIXTURE_INSTALLER_FILE:-$ROOT/tools/install.sh}"
|
||||||
|
IN_CLEAN_CONTAINER="${MOSAIC_GREENFIELD_CONTAINER:-0}"
|
||||||
|
|
||||||
# ─── Colour helpers ───────────────────────────────────────────────────────────
|
usage() {
|
||||||
if [[ -t 1 ]]; then
|
cat <<'EOF'
|
||||||
R=$'\033[0;31m' G=$'\033[0;32m' Y=$'\033[0;33m' BOLD=$'\033[1m' RESET=$'\033[0m'
|
Usage: tools/e2e-install-test.sh [--lane next|main] [--source checkout|remote] [--git present|absent]
|
||||||
else
|
|
||||||
R="" G="" Y="" BOLD="" RESET=""
|
|
||||||
fi
|
|
||||||
|
|
||||||
info() { echo "${BOLD}[e2e]${RESET} $*"; }
|
Runs the documented installer command from zero in Debian/glibc as a non-root
|
||||||
ok() { echo "${G}[PASS]${RESET} $*"; }
|
uid with an isolated HOME. The fixture exits non-zero when any P0-P8
|
||||||
fail() { echo "${R}[FAIL]${RESET} $*" >&2; }
|
postcondition fails. `next` is always selected with the --next installer flag.
|
||||||
warn() { echo "${Y}[WARN]${RESET} $*"; }
|
EOF
|
||||||
|
|
||||||
# ─── Docker availability check ────────────────────────────────────────────────
|
|
||||||
if ! command -v docker &>/dev/null; then
|
|
||||||
warn "Docker not found — skipping e2e install test."
|
|
||||||
warn "Install Docker and re-run this script to exercise the full install flow."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! docker info &>/dev/null 2>&1; then
|
|
||||||
warn "Docker daemon is not running or not accessible — skipping e2e install test."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
info "Docker available — proceeding with e2e install test."
|
|
||||||
info "Repo root: ${REPO_ROOT}"
|
|
||||||
info "Container image: ${IMAGE}"
|
|
||||||
|
|
||||||
# ─── Inline script that runs INSIDE the container ────────────────────────────
|
|
||||||
INNER_SCRIPT="$(mktemp /tmp/mosaic-e2e-inner-XXXXXX.sh)"
|
|
||||||
trap 'rm -f "$INNER_SCRIPT"' EXIT
|
|
||||||
|
|
||||||
cat > "$INNER_SCRIPT" <<'INNER_SCRIPT_EOF'
|
|
||||||
#!/bin/sh
|
|
||||||
# Bootstrap: /bin/sh until bash is installed, then re-exec.
|
|
||||||
set -e
|
|
||||||
|
|
||||||
echo "=== [inner] Installing system prerequisites ==="
|
|
||||||
apk add --no-cache bash curl jq git 2>/dev/null || \
|
|
||||||
apt-get install -y -q bash curl jq git 2>/dev/null || true
|
|
||||||
|
|
||||||
# Re-exec under bash.
|
|
||||||
if [ -z "${BASH_VERSION:-}" ] && command -v bash >/dev/null 2>&1; then
|
|
||||||
exec bash "$0" "$@"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ── bash from here ────────────────────────────────────────────────────────────
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
echo "=== [inner] Node.js / npm versions ==="
|
|
||||||
node --version
|
|
||||||
npm --version
|
|
||||||
|
|
||||||
echo "=== [inner] Setting up npm global prefix ==="
|
|
||||||
export NPM_PREFIX="/root/.npm-global"
|
|
||||||
mkdir -p "$NPM_PREFIX/bin"
|
|
||||||
npm config set prefix "$NPM_PREFIX" 2>/dev/null || true
|
|
||||||
export PATH="$NPM_PREFIX/bin:$PATH"
|
|
||||||
|
|
||||||
echo "=== [inner] Running install.sh --yes --no-auto-launch ==="
|
|
||||||
# Install both framework and CLI from the Gitea registry.
|
|
||||||
MOSAIC_SKIP_SKILLS_SYNC=1 \
|
|
||||||
MOSAIC_ASSUME_YES=1 \
|
|
||||||
bash /repo/tools/install.sh --yes --no-auto-launch
|
|
||||||
|
|
||||||
INSTALLED_VERSION="$(mosaic --version 2>/dev/null || echo 'unknown')"
|
|
||||||
echo "[inner] mosaic CLI installed: ${INSTALLED_VERSION}"
|
|
||||||
|
|
||||||
echo "=== [inner] Running mosaic wizard (non-interactive) ==="
|
|
||||||
mosaic wizard \
|
|
||||||
--non-interactive \
|
|
||||||
--name "test-agent" \
|
|
||||||
--user-name "tester" \
|
|
||||||
--pronouns "they/them" \
|
|
||||||
--timezone "UTC" || {
|
|
||||||
echo "[WARN] mosaic wizard exited non-zero — continuing"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
echo "=== [inner] Running mosaic gateway install ==="
|
while [[ $# -gt 0 ]]; do
|
||||||
# Feed non-interactive answers:
|
case "$1" in
|
||||||
# "1" → storage tier: local
|
--lane) LANE="${2:-}"; shift 2 ;;
|
||||||
# "" → port: accept default (14242)
|
--source) SOURCE="${2:-}"; shift 2 ;;
|
||||||
# "" → ANTHROPIC_API_KEY: skip
|
--git) GIT_MODE="${2:-}"; shift 2 ;;
|
||||||
# "" → CORS origin: accept default
|
-h|--help) usage; exit 0 ;;
|
||||||
# Then admin bootstrap: name, email, password
|
*) echo "[fixture] unknown argument: $1" >&2; usage >&2; exit 2 ;;
|
||||||
printf '1\n\n\n\nTest Admin\[email protected]\ntestpassword123\n' \
|
esac
|
||||||
| mosaic gateway install
|
done
|
||||||
INSTALL_EXIT="$?"
|
|
||||||
if [ "${INSTALL_EXIT}" -ne 0 ]; then
|
case "$LANE" in next|main) ;; *) echo "[fixture] unsupported lane '$LANE' (expected next|main)" >&2; exit 2 ;; esac
|
||||||
echo "[ERR] mosaic gateway install exited ${INSTALL_EXIT}"
|
case "$SOURCE" in checkout|remote) ;; *) echo "[fixture] unsupported source '$SOURCE' (expected checkout|remote)" >&2; exit 2 ;; esac
|
||||||
mosaic gateway status 2>/dev/null || true
|
case "$GIT_MODE" in present|absent) ;; *) echo "[fixture] unsupported git mode '$GIT_MODE' (expected present|absent)" >&2; exit 2 ;; esac
|
||||||
exit "${INSTALL_EXIT}"
|
|
||||||
|
if [[ "$IN_CLEAN_CONTAINER" != "1" ]]; then
|
||||||
|
if ! command -v docker >/dev/null 2>&1; then
|
||||||
|
echo "[fixture] FAIL: Docker is required; greenfield validation was NOT RUN." >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
if ! docker info >/dev/null 2>&1; then
|
||||||
|
echo "[fixture] FAIL: Docker daemon is unavailable; greenfield validation was NOT RUN." >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "=== [inner] Running mosaic gateway verify ==="
|
installer_b64=""
|
||||||
# `gateway verify` was added in feat/mosaic-first-run-ux.
|
framework_payload_count="NOT-MEASURED"
|
||||||
# If the installed version pre-dates this, skip gracefully.
|
repo_root_count="NOT-MEASURED"
|
||||||
if ! bash /repo/tools/e2e-gateway-verify-supported.sh; then
|
checkout_archive=""
|
||||||
echo "[SKIP] 'mosaic gateway verify' not available in installed version ${INSTALLED_VERSION}."
|
checkout_digest=""
|
||||||
echo "[SKIP] This command was added in the feat/mosaic-first-run-ux release."
|
checkout_content_id=""
|
||||||
echo "[SKIP] Re-run after the new version is published to validate this step."
|
if [[ "$SOURCE" == "checkout" ]]; then
|
||||||
# Treat as pass — the install flow itself worked.
|
installer_b64="$(base64 -w0 "$INSTALLER_FILE")"
|
||||||
exit 0
|
[[ -d "$ROOT/packages/mosaic/framework/skills" ]] \
|
||||||
|
&& framework_payload_count="$(find "$ROOT/packages/mosaic/framework/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
|
||||||
|
[[ -d "$ROOT/skills" ]] \
|
||||||
|
&& repo_root_count="$(find "$ROOT/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
|
||||||
|
checkout_archive="$(mktemp "${TMPDIR:-/tmp}/mosaic-greenfield-checkout.XXXXXX.tar.gz")"
|
||||||
|
repo_parent="$(dirname "$ROOT")"
|
||||||
|
repo_name="$(basename "$ROOT")"
|
||||||
|
tar -C "$repo_parent" \
|
||||||
|
--exclude='*/.git' --exclude='*/node_modules' --exclude='*/dist' \
|
||||||
|
--exclude='*/coverage' --exclude='*/.turbo' --exclude='*/.mosaic-test-work' \
|
||||||
|
--exclude='*/.env' --exclude='*/.env.*' \
|
||||||
|
-czf "$checkout_archive" "$repo_name"
|
||||||
|
checkout_digest="$(sha256sum "$checkout_archive" | awk '{print $1}')"
|
||||||
|
checkout_content_id="${checkout_digest:0:40}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mosaic gateway verify
|
inner="$(mktemp "${TMPDIR:-/tmp}/mosaic-greenfield-inner.XXXXXX.sh")"
|
||||||
VERIFY_EXIT="$?"
|
trap 'rm -f "$inner" "$checkout_archive"' EXIT
|
||||||
echo "=== [inner] verify exit code: ${VERIFY_EXIT} ==="
|
cat > "$inner" <<'INNER'
|
||||||
exit "${VERIFY_EXIT}"
|
#!/usr/bin/env bash
|
||||||
INNER_SCRIPT_EOF
|
set -euo pipefail
|
||||||
|
|
||||||
chmod +x "$INNER_SCRIPT"
|
export DEBIAN_FRONTEND=noninteractive
|
||||||
|
apt-get update -qq
|
||||||
|
packages=(bash ca-certificates curl jq passwd python3 util-linux)
|
||||||
|
[[ "$FIXTURE_GIT_MODE" == "present" ]] && packages+=(git)
|
||||||
|
apt-get install -y -qq "${packages[@]}" >/dev/null
|
||||||
|
|
||||||
# ─── Pull image ───────────────────────────────────────────────────────────────
|
if [[ "$FIXTURE_SOURCE" == "checkout" ]]; then
|
||||||
info "Pulling ${IMAGE}…"
|
awk 'found { print } /^__MOSAIC_CHECKOUT_ARCHIVE__$/ { found=1; next }' "$0" | base64 -d > /tmp/source-checkout.tar.gz
|
||||||
docker pull "${IMAGE}" --quiet
|
actual_checkout_digest="$(sha256sum /tmp/source-checkout.tar.gz | awk '{print $1}')"
|
||||||
|
if [[ "$actual_checkout_digest" != "$FIXTURE_CHECKOUT_SHA256" ]]; then
|
||||||
|
echo "[fixture] checkout archive transport digest mismatch" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# ─── Run container ────────────────────────────────────────────────────────────
|
useradd --create-home --uid 1001 --shell /bin/bash mosaic
|
||||||
info "Starting container ${CONTAINER_NAME}…"
|
install -d -o mosaic -g mosaic /home/mosaic/work
|
||||||
|
|
||||||
EXIT_CODE=0
|
case "$FIXTURE_SOURCE" in
|
||||||
docker run --rm \
|
checkout)
|
||||||
--name "${CONTAINER_NAME}" \
|
printf '%s' "$FIXTURE_INSTALLER_B64" | base64 -d > /tmp/install.sh
|
||||||
--volume "${REPO_ROOT}:/repo:ro" \
|
;;
|
||||||
--volume "${INNER_SCRIPT}:/e2e-inner.sh:ro" \
|
remote)
|
||||||
--network host \
|
curl -fsSL "https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/${FIXTURE_LANE}/tools/install.sh" > /tmp/install.sh
|
||||||
"${IMAGE}" \
|
;;
|
||||||
/bin/sh /e2e-inner.sh \
|
esac
|
||||||
|| EXIT_CODE=$?
|
chmod 0755 /tmp/install.sh
|
||||||
|
sha256sum /tmp/install.sh | sed 's/^/[fixture] installer sha256: /'
|
||||||
|
|
||||||
# ─── Report ───────────────────────────────────────────────────────────────────
|
cat > /tmp/run-as-target.sh <<'TARGET'
|
||||||
echo ""
|
#!/usr/bin/env bash
|
||||||
if [[ "$EXIT_CODE" -eq 0 ]]; then
|
set -uo pipefail
|
||||||
ok "End-to-end install test PASSED (exit ${EXIT_CODE})"
|
|
||||||
|
lane="$FIXTURE_LANE"
|
||||||
|
home="$HOME"
|
||||||
|
prefix="$home/.npm-global"
|
||||||
|
mosaic_home="$home/.config/mosaic"
|
||||||
|
install_log="$home/install.log"
|
||||||
|
failures=0
|
||||||
|
|
||||||
|
phase_pass() { printf '[%s] PASS: %s\n' "$1" "$2"; }
|
||||||
|
phase_fail() { printf '[%s] FAIL: %s\n' "$1" "$2"; failures=$((failures + 1)); }
|
||||||
|
|
||||||
|
lane_args=()
|
||||||
|
resolved_spec='@mosaicstack/mosaic'
|
||||||
|
if [[ "$lane" == "next" ]]; then
|
||||||
|
lane_args+=(--next)
|
||||||
|
resolved_spec='@mosaicstack/mosaic@next'
|
||||||
|
fi
|
||||||
|
|
||||||
|
resolved_version="$(npm view "$resolved_spec" version --registry=https://git.mosaicstack.dev/api/packages/mosaicstack/npm/ 2>/dev/null || true)"
|
||||||
|
printf '[fixture] resolved lane=%s package=%s version=%s\n' "$lane" "$resolved_spec" "${resolved_version:-UNRESOLVED}"
|
||||||
|
|
||||||
|
set +e
|
||||||
|
MOSAIC_NO_COLOR=1 MOSAIC_ASSUME_YES=1 \
|
||||||
|
bash /tmp/install.sh "${lane_args[@]}" --yes --no-auto-launch >"$install_log" 2>&1
|
||||||
|
install_status=$?
|
||||||
|
set -e
|
||||||
|
cat "$install_log"
|
||||||
|
printf '[fixture] installer_exit=%d done_claims=%s\n' \
|
||||||
|
"$install_status" "$(grep -cF 'Done.' "$install_log" || true)"
|
||||||
|
|
||||||
|
# P0 Resolve context
|
||||||
|
shell="$(getent passwd "$(id -u)" | cut -d: -f7)"
|
||||||
|
if [[ "$(id -u)" -ne 0 && "$home" == "/home/mosaic" && "$shell" == "/bin/bash" ]] \
|
||||||
|
&& ldd --version 2>&1 | grep -i 'glibc\|gnu libc' >/dev/null \
|
||||||
|
&& [[ "$(node -p 'Number(process.versions.node.split(".")[0])')" -ge 20 ]]; then
|
||||||
|
phase_pass P0 "target=mosaic uid=$(id -u) HOME=$home shell=$shell libc=glibc node=$(node --version)"
|
||||||
else
|
else
|
||||||
fail "End-to-end install test FAILED (exit ${EXIT_CODE})"
|
phase_fail P0 "context unresolved or unsupported (uid=$(id -u) HOME=$home shell=${shell:-unknown})"
|
||||||
echo ""
|
fi
|
||||||
echo " Troubleshooting:"
|
|
||||||
echo " - Review the output above for the failing step."
|
# P1 Preflight
|
||||||
echo " - Re-run with bash -x tools/e2e-install-test.sh for verbose trace."
|
missing_tools=()
|
||||||
echo " - Run mosaic gateway logs inside a manual container for daemon output."
|
for tool in bash curl git node npm python3 tar; do
|
||||||
|
command -v "$tool" >/dev/null 2>&1 || missing_tools+=("$tool")
|
||||||
|
done
|
||||||
|
if [[ "${#missing_tools[@]}" -eq 0 && -n "$resolved_version" && -w "$home" ]]; then
|
||||||
|
phase_pass P1 "required tools present (including downstream git); target HOME writable; registry lane resolved"
|
||||||
|
else
|
||||||
|
phase_fail P1 "undeclared/missing prerequisite(s)=${missing_tools[*]:-none}; target_writable=$([[ -w "$home" ]] && echo yes || echo no) registry_resolved=$([[ -n "$resolved_version" ]] && echo yes || echo no)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P2 Acquire artifacts
|
||||||
|
if [[ -n "$resolved_version" ]] && grep -qF "$resolved_version" "$install_log"; then
|
||||||
|
phase_pass P2 "lane=$lane pinned_version=$resolved_version recorded in installer transcript"
|
||||||
|
else
|
||||||
|
phase_fail P2 "lane=$lane did not resolve and record a pinned artifact version"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P3 Install CLI — the discriminating row. Use the known absolute path only.
|
||||||
|
cli="$prefix/bin/mosaic"
|
||||||
|
cli_version=""
|
||||||
|
if [[ -x "$cli" ]]; then
|
||||||
|
cli_version="$($cli --version 2>/dev/null | tail -n 1 | tr -d '\r' || true)"
|
||||||
|
fi
|
||||||
|
if [[ -x "$cli" && "$cli_version" == "$resolved_version" ]]; then
|
||||||
|
phase_pass P3 "absolute_path=$cli version=$cli_version equals resolved lane version"
|
||||||
|
else
|
||||||
|
phase_fail P3 "absolute_path=$cli executable=$([[ -x "$cli" ]] && echo yes || echo no) got=${cli_version:-missing} expected=${resolved_version:-unresolved}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P4 Framework + skills. C1 does not choose among the four disagreeing
|
||||||
|
# candidate populations. It requires the installer to publish a lane/versioned
|
||||||
|
# shipped-set declaration that a checkout-free install can resolve; C5 owns its
|
||||||
|
# contents. Without that artifact P4 is NOT-MEASURED, never a fabricated count.
|
||||||
|
declared_set="$mosaic_home/.install-shipped-skills.json"
|
||||||
|
sync_store_count=0
|
||||||
|
runtime_link_count=0
|
||||||
|
[[ -d "$mosaic_home/skills" ]] \
|
||||||
|
&& sync_store_count="$(find "$mosaic_home/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
|
||||||
|
[[ -d "$home/.pi/agent/skills" ]] \
|
||||||
|
&& runtime_link_count="$(find "$home/.pi/agent/skills" -mindepth 1 -maxdepth 1 \( -type d -o -type l \) | wc -l | tr -d ' ')"
|
||||||
|
printf '[P4-EVIDENCE] candidate_populations framework_payload=%s repo_root=%s sync_store=%s jarvis_W-jarvis_observation=7 runtime_links=%s\n' \
|
||||||
|
"$FIXTURE_FRAMEWORK_PAYLOAD_COUNT" "$FIXTURE_REPO_ROOT_COUNT" "$sync_store_count" "$runtime_link_count"
|
||||||
|
if [[ ! -s "$declared_set" ]]; then
|
||||||
|
phase_fail P4 "NOT-MEASURED / UNDECLARED: installer published no checkout-free, lane/versioned shipped-set artifact at $declared_set"
|
||||||
|
elif EXPECTED_LANE="$([[ "$lane" == next ]] && echo next || echo latest)" EXPECTED_VERSION="$resolved_version" \
|
||||||
|
MOSAIC_SKILLS_ROOT="$mosaic_home/skills" node - "$declared_set" <<'NODE'
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const data = JSON.parse(fs.readFileSync(process.argv[2], 'utf8'));
|
||||||
|
const root = path.resolve(process.env.MOSAIC_SKILLS_ROOT);
|
||||||
|
if (!data || data.lane !== process.env.EXPECTED_LANE || data.version !== process.env.EXPECTED_VERSION ||
|
||||||
|
!Array.isArray(data.skills) || data.skills.length === 0) process.exit(1);
|
||||||
|
for (const name of data.skills) {
|
||||||
|
if (typeof name !== 'string' || !/^[A-Za-z0-9][A-Za-z0-9._-]*$/.test(name)) process.exit(1);
|
||||||
|
const skill = path.join(root, name, 'SKILL.md');
|
||||||
|
let real;
|
||||||
|
try { real = fs.realpathSync(skill); } catch { process.exit(1); }
|
||||||
|
const text = fs.readFileSync(real, 'utf8');
|
||||||
|
const declaredName = text.match(/^---\s*$[\s\S]*?^name:\s*([^\s]+)\s*$/m)?.[1];
|
||||||
|
if (!real.startsWith(root + path.sep) || !fs.statSync(real).isFile() || !text || declaredName !== name) process.exit(1);
|
||||||
|
}
|
||||||
|
NODE
|
||||||
|
then
|
||||||
|
declared_count="$(node -p "require('$declared_set').skills.length")"
|
||||||
|
if [[ -s "$mosaic_home/.install-manifest.json" ]] \
|
||||||
|
&& [[ "$(node -p "require('$mosaic_home/.install-manifest.json').phaseOutcomes?.P4 || 'committed'")" == failed ]]; then
|
||||||
|
phase_fail P4 "declared skills are present but the required framework/skills action reported failure"
|
||||||
|
else
|
||||||
|
phase_pass P4 "declared shipped-set matches lane/version and all $declared_count skill(s) are contained and loadable"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
phase_fail P4 "shipped-set artifact is malformed, wrong-lane/version, or its declared skills are not contained and loadable"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P5 Identity
|
||||||
|
identity_ok=true
|
||||||
|
identity_reason=()
|
||||||
|
for f in SOUL.md USER.md; do
|
||||||
|
path="$mosaic_home/$f"
|
||||||
|
if [[ ! -s "$path" ]]; then
|
||||||
|
identity_ok=false; identity_reason+=("$f missing-or-empty"); continue
|
||||||
|
fi
|
||||||
|
owner="$(stat -c '%u' "$path")"; mode="$(stat -c '%a' "$path")"
|
||||||
|
if [[ "$owner" != "$(id -u)" || "$mode" =~ [2367]$ ]]; then
|
||||||
|
identity_ok=false; identity_reason+=("$f owner=$owner mode=$mode")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [[ "$identity_ok" == true ]]; then
|
||||||
|
phase_pass P5 "SOUL.md and USER.md are non-empty and target-user owned with non-world-writable modes"
|
||||||
|
else
|
||||||
|
phase_fail P5 "${identity_reason[*]}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P6 Runtime linking / activation. #869 must remain unwired without its broker.
|
||||||
|
manifest="$mosaic_home/.install-manifest.json"
|
||||||
|
broker_present=false
|
||||||
|
[[ -S "${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/mosaic-lease/broker.sock" ]] && broker_present=true
|
||||||
|
dead_hooks=0
|
||||||
|
if [[ -f "$home/.claude/settings.json" ]]; then
|
||||||
|
dead_hooks="$(grep -Ec 'mutator-gate\.py|receipt-observer-client\.py' "$home/.claude/settings.json" || true)"
|
||||||
|
fi
|
||||||
|
p6_action_failed=false
|
||||||
|
if [[ -s "$manifest" ]]; then
|
||||||
|
p6_action_failed="$(node -p "require('$manifest').phaseOutcomes?.P6 === 'failed' ? 'true' : 'false'" 2>/dev/null || echo true)"
|
||||||
|
fi
|
||||||
|
if [[ "$p6_action_failed" == true ]]; then
|
||||||
|
phase_fail P6 "runtime linking/activation action reported a required failure"
|
||||||
|
elif [[ "$broker_present" == false && "$dead_hooks" -eq 0 ]]; then
|
||||||
|
phase_pass P6 "broker absent and #869 enforcement hooks remain inactive"
|
||||||
|
elif [[ "$broker_present" == true ]]; then
|
||||||
|
phase_pass P6 "activation broker present; hook state is evaluable"
|
||||||
|
else
|
||||||
|
phase_fail P6 "broker absent but dead enforcement hooks are active (count=$dead_hooks)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# P7 Services — none requested by --no-auto-launch.
|
||||||
|
phase_pass P7 "no services requested by this fixture"
|
||||||
|
|
||||||
|
# P8 Shell discoverability — actual target shell, fresh login and non-login.
|
||||||
|
base_env=(env -i HOME="$home" USER=mosaic LOGNAME=mosaic SHELL=/bin/bash PATH=/usr/local/bin:/usr/bin:/bin)
|
||||||
|
login_path="$("${base_env[@]}" /bin/bash -lc 'command -v mosaic' 2>/dev/null || true)"
|
||||||
|
nonlogin_path="$("${base_env[@]}" /bin/bash -c 'command -v mosaic' 2>/dev/null || true)"
|
||||||
|
if [[ "$login_path" == "$cli" && "$nonlogin_path" == "$cli" ]]; then
|
||||||
|
phase_pass P8 "login=$login_path nonlogin=$nonlogin_path equals P3 path"
|
||||||
|
else
|
||||||
|
phase_fail P8 "fresh bash login=${login_path:-missing} nonlogin=${nonlogin_path:-missing} expected=$cli"
|
||||||
|
fi
|
||||||
|
|
||||||
|
manifest="$mosaic_home/.install-manifest.json"
|
||||||
|
p0_p8_failures="$failures"
|
||||||
|
if [[ "$p0_p8_failures" -eq 0 && -s "$manifest" ]]; then
|
||||||
|
phase_pass P9 "P0-P8 reasserted; manifest present"
|
||||||
|
else
|
||||||
|
phase_fail P9 "P0-P8_failed_postconditions=$p0_p8_failures manifest=$([[ -s "$manifest" ]] && echo present || echo missing); install must not certify success"
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf '[fixture] P0-P9_failed_rows=%d (includes P9 aggregate row)\n' "$failures"
|
||||||
|
if [[ "$failures" -ne 0 ]]; then
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
TARGET
|
||||||
|
chmod 0755 /tmp/run-as-target.sh
|
||||||
|
chown mosaic:mosaic /tmp/run-as-target.sh
|
||||||
|
|
||||||
|
exec runuser -u mosaic -- env -i \
|
||||||
|
HOME=/home/mosaic USER=mosaic LOGNAME=mosaic SHELL=/bin/bash \
|
||||||
|
PATH=/usr/local/bin:/usr/bin:/bin \
|
||||||
|
FIXTURE_LANE="$FIXTURE_LANE" \
|
||||||
|
FIXTURE_GIT_MODE="$FIXTURE_GIT_MODE" \
|
||||||
|
FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$FIXTURE_FRAMEWORK_PAYLOAD_COUNT" \
|
||||||
|
FIXTURE_REPO_ROOT_COUNT="$FIXTURE_REPO_ROOT_COUNT" \
|
||||||
|
MOSAIC_INSTALL_LOCAL_SOURCE_ARCHIVE="$([[ "$FIXTURE_SOURCE" == "checkout" ]] && echo /tmp/source-checkout.tar.gz)" \
|
||||||
|
MOSAIC_INSTALL_LOCAL_SOURCE_COMMIT="$FIXTURE_CHECKOUT_CONTENT_ID" \
|
||||||
|
MOSAIC_INSTALL_LOCAL_SOURCE_SHA256="$FIXTURE_CHECKOUT_SHA256" \
|
||||||
|
/bin/bash /tmp/run-as-target.sh
|
||||||
|
INNER
|
||||||
|
if [[ "$SOURCE" == "checkout" ]]; then
|
||||||
|
{
|
||||||
|
printf '\n__MOSAIC_CHECKOUT_ARCHIVE__\n'
|
||||||
|
base64 "$checkout_archive"
|
||||||
|
} >> "$inner"
|
||||||
|
fi
|
||||||
|
chmod 0755 "$inner"
|
||||||
|
|
||||||
|
printf '[fixture] platform=Debian/glibc image=%s target_uid=1001 lane=%s source=%s git=%s\n' "$IMAGE" "$LANE" "$SOURCE" "$GIT_MODE"
|
||||||
|
printf '[fixture] host inheritance: no bind mounts, no host HOME, no npm cache, no credentials\n'
|
||||||
|
|
||||||
|
if [[ "$IN_CLEAN_CONTAINER" == "1" ]]; then
|
||||||
|
# Woodpecker already supplies the clean Debian container. The target install
|
||||||
|
# still runs through runuser + env -i, so CI variables/credentials do not
|
||||||
|
# enter the target user's process.
|
||||||
|
FIXTURE_LANE="$LANE" \
|
||||||
|
FIXTURE_SOURCE="$SOURCE" \
|
||||||
|
FIXTURE_GIT_MODE="$GIT_MODE" \
|
||||||
|
FIXTURE_INSTALLER_B64="$installer_b64" \
|
||||||
|
FIXTURE_CHECKOUT_SHA256="$checkout_digest" \
|
||||||
|
FIXTURE_CHECKOUT_CONTENT_ID="$checkout_content_id" \
|
||||||
|
FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$framework_payload_count" \
|
||||||
|
FIXTURE_REPO_ROOT_COUNT="$repo_root_count" \
|
||||||
|
/bin/bash "$inner"
|
||||||
|
else
|
||||||
|
# Copy the self-contained script+archive into a stopped container instead of
|
||||||
|
# bind-mounting the checkout or passing host paths. The target runtime still
|
||||||
|
# inherits no host HOME/cache/credentials, and the multi-megabyte checkout
|
||||||
|
# payload avoids argv/environment size limits.
|
||||||
|
fixture_cid="$(docker create \
|
||||||
|
--network bridge \
|
||||||
|
--env FIXTURE_LANE="$LANE" \
|
||||||
|
--env FIXTURE_SOURCE="$SOURCE" \
|
||||||
|
--env FIXTURE_GIT_MODE="$GIT_MODE" \
|
||||||
|
--env FIXTURE_INSTALLER_B64="$installer_b64" \
|
||||||
|
--env FIXTURE_CHECKOUT_SHA256="$checkout_digest" \
|
||||||
|
--env FIXTURE_CHECKOUT_CONTENT_ID="$checkout_content_id" \
|
||||||
|
--env FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$framework_payload_count" \
|
||||||
|
--env FIXTURE_REPO_ROOT_COUNT="$repo_root_count" \
|
||||||
|
"$IMAGE" /bin/bash /tmp/mosaic-greenfield-fixture.sh)"
|
||||||
|
docker cp "$inner" "$fixture_cid:/tmp/mosaic-greenfield-fixture.sh"
|
||||||
|
set +e
|
||||||
|
docker start -a "$fixture_cid"
|
||||||
|
fixture_status=$?
|
||||||
|
set -e
|
||||||
|
docker rm "$fixture_cid" >/dev/null
|
||||||
|
exit "$fixture_status"
|
||||||
|
fi
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# Pinned C1 expected-RED contract. Updating a verdict/reason requires review by the owning remediation lane.
|
||||||
|
# case kind key/value
|
||||||
|
next-git-present exit 1
|
||||||
|
next-git-present phase P0=PASS
|
||||||
|
next-git-present phase P1=PASS
|
||||||
|
next-git-present phase P2=PASS
|
||||||
|
next-git-present phase P3=PASS
|
||||||
|
next-git-present phase P4=FAIL
|
||||||
|
next-git-present phase P5=FAIL
|
||||||
|
next-git-present phase P6=FAIL
|
||||||
|
next-git-present phase P7=PASS
|
||||||
|
next-git-present phase P8=FAIL
|
||||||
|
next-git-present phase P9=FAIL
|
||||||
|
next-git-present require ^\[fixture\] resolved lane=next .*version=[0-9]+\.[0-9]+\.[0-9]+-next\.
|
||||||
|
next-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
|
||||||
|
next-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
|
||||||
|
next-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
|
||||||
|
next-git-present require ^\[P6\] FAIL:
|
||||||
|
next-git-present forbid Done\.
|
||||||
|
main-git-present exit 1
|
||||||
|
main-git-present phase P0=PASS
|
||||||
|
main-git-present phase P1=PASS
|
||||||
|
main-git-present phase P2=PASS
|
||||||
|
main-git-present phase P3=PASS
|
||||||
|
main-git-present phase P4=FAIL
|
||||||
|
main-git-present phase P5=FAIL
|
||||||
|
main-git-present phase P6=FAIL
|
||||||
|
main-git-present phase P7=PASS
|
||||||
|
main-git-present phase P8=FAIL
|
||||||
|
main-git-present phase P9=FAIL
|
||||||
|
main-git-present require ^\[fixture\] resolved lane=main .*version=[0-9]+\.[0-9]+\.[0-9]+$
|
||||||
|
main-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
|
||||||
|
main-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
|
||||||
|
main-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
|
||||||
|
main-git-present require ^\[P6\] FAIL:
|
||||||
|
main-git-present forbid Done\.
|
||||||
|
next-git-absent exit 1
|
||||||
|
next-git-absent phase P0=PASS
|
||||||
|
next-git-absent phase P1=FAIL
|
||||||
|
next-git-absent phase P2=FAIL
|
||||||
|
next-git-absent phase P3=FAIL
|
||||||
|
next-git-absent phase P4=FAIL
|
||||||
|
next-git-absent phase P5=FAIL
|
||||||
|
next-git-absent phase P6=PASS
|
||||||
|
next-git-absent phase P7=PASS
|
||||||
|
next-git-absent phase P8=FAIL
|
||||||
|
next-git-absent phase P9=FAIL
|
||||||
|
next-git-absent require ^\[fixture\] installer_exit=1 done_claims=0$
|
||||||
|
next-git-absent require ^\[P1\] FAIL: undeclared/missing prerequisite\(s\)=git;
|
||||||
|
next-git-absent require ^\[P3\] FAIL: .*executable=no
|
||||||
|
next-git-absent forbid Done\.
|
||||||
|
Executable
+359
@@ -0,0 +1,359 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
|
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-next-install-test-XXXXXX")"
|
||||||
|
trap 'rm -rf "$TMP"' EXIT
|
||||||
|
|
||||||
|
FAKE_BIN="$TMP/bin"
|
||||||
|
HOME_DIR="$TMP/home"
|
||||||
|
PREFIX="$HOME_DIR/prefix"
|
||||||
|
MOSAIC_HOME="$HOME_DIR/mosaic"
|
||||||
|
STATE="$TMP/state"
|
||||||
|
LOG="$TMP/npm.log"
|
||||||
|
mkdir -p "$FAKE_BIN" "$HOME_DIR" "$STATE"
|
||||||
|
|
||||||
|
cat > "$FAKE_BIN/npm" <<'FAKE_NPM'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
LOG="${MOSAIC_TEST_NPM_LOG:?}"
|
||||||
|
STATE="${MOSAIC_TEST_STATE:?}"
|
||||||
|
echo "$*" >> "$LOG"
|
||||||
|
|
||||||
|
if [[ "${1:-}" == "--version" ]]; then
|
||||||
|
echo "10.6.2"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
install_cli() {
|
||||||
|
local version="$1"
|
||||||
|
echo "$version" > "$STATE/mosaic"
|
||||||
|
mkdir -p "${MOSAIC_PREFIX:?}/bin"
|
||||||
|
cat > "$MOSAIC_PREFIX/bin/mosaic" <<CLI
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
printf '%s\\n' '$version'
|
||||||
|
CLI
|
||||||
|
chmod +x "$MOSAIC_PREFIX/bin/mosaic"
|
||||||
|
}
|
||||||
|
|
||||||
|
if [[ "$1" == "view" ]]; then
|
||||||
|
if [[ "${MOSAIC_TEST_FAIL_NPM_VIEW:-0}" == "1" ]]; then
|
||||||
|
echo "forced registry metadata failure" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
case "$2 $3" in
|
||||||
|
"@mosaicstack/mosaic@next version") echo "0.0.49-next.999" ;;
|
||||||
|
"@mosaicstack/gateway@next version") echo "${MOSAIC_TEST_GATEWAY_NEXT_VERSION:-0.0.7-next.999}" ;;
|
||||||
|
"@mosaicstack/mosaic version") echo "0.0.48" ;;
|
||||||
|
*) echo "unexpected npm view: $*" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$1" == "install" ]]; then
|
||||||
|
case "$*" in
|
||||||
|
*"@mosaicstack/[email protected]"*)
|
||||||
|
install_cli "0.0.49-next.999"
|
||||||
|
;;
|
||||||
|
*"@mosaicstack/[email protected]"*)
|
||||||
|
if [[ "${MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL:-0}" == "1" ]]; then
|
||||||
|
echo "forced gateway install failure" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "0.0.7-next.999" > "$STATE/gateway"
|
||||||
|
;;
|
||||||
|
*"mosaicstack-mosaic-0.0.0-source.tgz"*)
|
||||||
|
install_cli "0.0.0-source"
|
||||||
|
;;
|
||||||
|
*"mosaicstack-gateway-0.0.0-source.tgz"*)
|
||||||
|
echo "0.0.0-source" > "$STATE/gateway"
|
||||||
|
;;
|
||||||
|
*) echo "unexpected npm install: $*" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$1" == "ls" ]]; then
|
||||||
|
cli="$(cat "$STATE/mosaic" 2>/dev/null || true)"
|
||||||
|
gateway="$(cat "$STATE/gateway" 2>/dev/null || true)"
|
||||||
|
node -e '
|
||||||
|
const cli = process.argv[1];
|
||||||
|
const gateway = process.argv[2];
|
||||||
|
const dependencies = {};
|
||||||
|
if (cli) dependencies["@mosaicstack/mosaic"] = { version: cli };
|
||||||
|
if (gateway) dependencies["@mosaicstack/gateway"] = { version: gateway };
|
||||||
|
process.stdout.write(JSON.stringify({ dependencies }));
|
||||||
|
' "$cli" "$gateway"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "unexpected npm command: $*" >&2
|
||||||
|
exit 1
|
||||||
|
FAKE_NPM
|
||||||
|
chmod +x "$FAKE_BIN/npm"
|
||||||
|
|
||||||
|
cat > "$FAKE_BIN/curl" <<'FAKE_CURL'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
headers=""; output=""; url=""
|
||||||
|
while [[ $# -gt 0 ]]; do
|
||||||
|
case "$1" in
|
||||||
|
-D) headers="$2"; shift 2 ;;
|
||||||
|
-o) output="$2"; shift 2 ;;
|
||||||
|
--max-filesize) shift 2 ;;
|
||||||
|
-*) shift ;;
|
||||||
|
*) url="$1"; shift ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
case "$url" in
|
||||||
|
*/api/v1/repos/mosaicstack/stack/commits?sha=*)
|
||||||
|
printf 'HTTP/1.1 200 OK\r\ncontent-type: application/json; charset=utf-8\r\n\r\n' > "$headers"
|
||||||
|
printf '[{"sha":"1111111111111111111111111111111111111111"}]\n' > "$output"
|
||||||
|
;;
|
||||||
|
*/archive/*.tar.gz)
|
||||||
|
if [[ "${MOSAIC_TEST_CORRUPT_ARCHIVE:-0}" == "1" ]]; then
|
||||||
|
printf 'not-a-tarball\n' > "$output"
|
||||||
|
else
|
||||||
|
archive_root="$(mktemp -d)"
|
||||||
|
mkdir -p "$archive_root/stack"
|
||||||
|
printf 'fixture\n' > "$archive_root/stack/.fixture"
|
||||||
|
/bin/tar czf "$output" -C "$archive_root" stack
|
||||||
|
rm -rf "$archive_root"
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
FAKE_CURL
|
||||||
|
chmod +x "$FAKE_BIN/curl"
|
||||||
|
|
||||||
|
cat > "$FAKE_BIN/tar" <<'FAKE_TAR'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
dest=""; list=false
|
||||||
|
while [[ $# -gt 0 ]]; do
|
||||||
|
case "$1" in
|
||||||
|
-C) dest="$2"; shift 2 ;;
|
||||||
|
-*t*|t*) list=true; shift ;;
|
||||||
|
*) shift ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
[[ "$list" == true ]] && exit 0
|
||||||
|
if [[ -z "$dest" ]]; then
|
||||||
|
echo "fake tar missing -C destination" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
mkdir -p "$dest/stack/packages/mosaic" "$dest/stack/apps/gateway"
|
||||||
|
FAKE_TAR
|
||||||
|
chmod +x "$FAKE_BIN/tar"
|
||||||
|
|
||||||
|
cat > "$FAKE_BIN/pnpm" <<'FAKE_PNPM'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
LOG="${MOSAIC_TEST_NPM_LOG:?}"
|
||||||
|
echo "pnpm $*" >> "$LOG"
|
||||||
|
|
||||||
|
if [[ "$1" == "pack" ]]; then
|
||||||
|
out=""
|
||||||
|
while [[ $# -gt 0 ]]; do
|
||||||
|
case "$1" in
|
||||||
|
--pack-destination) out="$2"; shift 2 ;;
|
||||||
|
*) shift ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
if [[ -z "$out" ]]; then
|
||||||
|
echo "fake pnpm pack missing destination" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
mkdir -p "$out"
|
||||||
|
case "$PWD" in
|
||||||
|
*/apps/gateway) touch "$out/mosaicstack-gateway-0.0.0-source.tgz" ;;
|
||||||
|
*/packages/mosaic) touch "$out/mosaicstack-mosaic-0.0.0-source.tgz" ;;
|
||||||
|
*) echo "unexpected pnpm pack cwd: $PWD" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "${MOSAIC_TEST_FAIL_PNPM_INSTALL:-0}" == "1" && "$1" == "install" ]]; then
|
||||||
|
echo "forced pnpm install failure" >&2
|
||||||
|
exit 42
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Other install/build commands are no-ops in this harness.
|
||||||
|
exit 0
|
||||||
|
FAKE_PNPM
|
||||||
|
chmod +x "$FAKE_BIN/pnpm"
|
||||||
|
|
||||||
|
reset_state() {
|
||||||
|
: > "$LOG"
|
||||||
|
rm -f "$STATE"/*
|
||||||
|
}
|
||||||
|
|
||||||
|
prefix_fingerprint() {
|
||||||
|
if [[ ! -d "$PREFIX" ]]; then printf 'ABSENT\n'; return; fi
|
||||||
|
(
|
||||||
|
cd "$PREFIX"
|
||||||
|
find . -mindepth 1 -printf '%P|%y|%m|%l\n' | LC_ALL=C sort
|
||||||
|
find . -type f -print0 | LC_ALL=C sort -z | xargs -0 -r sha256sum
|
||||||
|
) | sha256sum | awk '{print $1}'
|
||||||
|
}
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] --next fast path pins resolved package versions"
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
|
||||||
|
)"
|
||||||
|
|
||||||
|
grep -qF 'Installed @next packages: CLI 0.0.49-next.999, gateway 0.0.7-next.999' <<<"$OUTPUT"
|
||||||
|
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
|
||||||
|
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
|
||||||
|
if grep -qE '^install -g .+@next( |$)' "$LOG"; then
|
||||||
|
echo "expected exact-version installs, found mutable @next install" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if grep -qF 'Downloading source ref next at pinned commit' <<<"$OUTPUT"; then
|
||||||
|
echo "fast path unexpectedly fell back to source" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ACTIVE="$HOME_DIR/.local/state/mosaic/install/active.json"
|
||||||
|
[[ "$(node -p "require('$ACTIVE').status")" == "committed" ]]
|
||||||
|
JOURNAL="$(node -p "require('$ACTIVE').journal")"
|
||||||
|
[[ "$(stat -c '%a' "$JOURNAL")" == "444" ]]
|
||||||
|
( cd "$(dirname "$JOURNAL")" && sha256sum -c "$(basename "$JOURNAL").sha256" >/dev/null )
|
||||||
|
grep -q '"event":"mutation".*"phase":"P3".*path=.*prior=.*reverse=' "$JOURNAL"
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] fast path failure falls back to source build"
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
|
||||||
|
)"
|
||||||
|
|
||||||
|
grep -qF 'Fast gateway @next install failed.' <<<"$OUTPUT"
|
||||||
|
grep -qF 'Falling back to source build at ref next; --next will not hard-fail on registry issues.' <<<"$OUTPUT"
|
||||||
|
grep -qF 'Downloading source ref next at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
|
||||||
|
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
|
||||||
|
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
|
||||||
|
grep -qE 'install -g .*/mosaicstack-gateway-0\.0\.0-source\.tgz' "$LOG"
|
||||||
|
grep -qE 'install -g .*/mosaicstack-mosaic-0\.0\.0-source\.tgz' "$LOG"
|
||||||
|
[[ "$(cat "$STATE/mosaic")" == "0.0.0-source" ]]
|
||||||
|
[[ "$(cat "$STATE/gateway")" == "0.0.0-source" ]]
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] source-build failure is fatal and restores the pre-install prefix"
|
||||||
|
before_prefix="$(prefix_fingerprint)"
|
||||||
|
set +e
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
|
||||||
|
MOSAIC_TEST_FAIL_PNPM_INSTALL=1 \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
|
||||||
|
)"
|
||||||
|
FAIL_STATUS=$?
|
||||||
|
set -e
|
||||||
|
[[ "$FAIL_STATUS" -ne 0 ]]
|
||||||
|
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
|
||||||
|
grep -qF 'forced pnpm install failure' <<<"$OUTPUT"
|
||||||
|
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] corrupt source archive is fatal and restores the pre-install prefix"
|
||||||
|
before_prefix="$(prefix_fingerprint)"
|
||||||
|
set +e
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
|
||||||
|
MOSAIC_TEST_CORRUPT_ARCHIVE=1 \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
|
||||||
|
)"
|
||||||
|
FAIL_STATUS=$?
|
||||||
|
set -e
|
||||||
|
[[ "$FAIL_STATUS" -ne 0 ]]
|
||||||
|
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
|
||||||
|
grep -qF 'archive safety/integrity check failed' <<<"$OUTPUT"
|
||||||
|
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] --dev source install does not require registry version resolution"
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
MOSAIC_TEST_FAIL_NPM_VIEW=1 \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --cli --dev --ref feature-x --yes --no-auto-launch
|
||||||
|
)"
|
||||||
|
grep -qF 'Downloading source ref feature-x at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
|
||||||
|
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
|
||||||
|
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] explicit --ref keeps source lane and avoids @next lookup"
|
||||||
|
set +e
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --cli --next --ref feature-x
|
||||||
|
)"
|
||||||
|
CHECK_STATUS=$?
|
||||||
|
set -e
|
||||||
|
[[ "$CHECK_STATUS" -ne 0 ]]
|
||||||
|
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
|
||||||
|
if grep -qF '@next version' "$LOG"; then
|
||||||
|
echo "explicit ref should not query @next dist-tags" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
reset_state
|
||||||
|
echo "[test] --check --next rejects mismatched prerelease pipeline suffixes"
|
||||||
|
set +e
|
||||||
|
OUTPUT="$(
|
||||||
|
HOME="$HOME_DIR" \
|
||||||
|
MOSAIC_HOME="$MOSAIC_HOME" \
|
||||||
|
MOSAIC_PREFIX="$PREFIX" \
|
||||||
|
MOSAIC_NO_COLOR=1 \
|
||||||
|
MOSAIC_TEST_NPM_LOG="$LOG" \
|
||||||
|
MOSAIC_TEST_STATE="$STATE" \
|
||||||
|
MOSAIC_TEST_GATEWAY_NEXT_VERSION="0.0.7-next.1000" \
|
||||||
|
PATH="$FAKE_BIN:$PATH" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --cli --next
|
||||||
|
)"
|
||||||
|
CHECK_STATUS=$?
|
||||||
|
set -e
|
||||||
|
[[ "$CHECK_STATUS" -ne 0 ]]
|
||||||
|
grep -q '^\[P2\] FAIL: resolved_version=unavailable' <<<"$OUTPUT"
|
||||||
|
|
||||||
|
echo "[test] installer next lane tests passed"
|
||||||
Executable
+338
@@ -0,0 +1,338 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Red-first acceptance checks for #1050. This file is committed before the
|
||||||
|
# installer implementation. Do not weaken these properties to make it green.
|
||||||
|
|
||||||
|
# pass_case always returns zero and fail_case records the aggregate failure;
|
||||||
|
# the compact A&&pass||fail assertions are intentional.
|
||||||
|
# shellcheck disable=SC2015
|
||||||
|
set -uo pipefail
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
|
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-install-state-test.XXXXXX")"
|
||||||
|
trap 'rm -rf "$TMP"' EXIT
|
||||||
|
failures=0
|
||||||
|
COMPAT_BIN="$TMP/compat-bin"
|
||||||
|
mkdir -p "$COMPAT_BIN"
|
||||||
|
cat > "$COMPAT_BIN/realpath" <<'REALPATH'
|
||||||
|
#!/usr/bin/env python3
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
|
||||||
|
args = sys.argv[1:]
|
||||||
|
mode = args.pop(0) if args and args[0] in ("-e", "-m") else "-m"
|
||||||
|
if args and args[0] == "--":
|
||||||
|
args.pop(0)
|
||||||
|
if len(args) != 1 or (mode == "-e" and not os.path.exists(args[0])):
|
||||||
|
raise SystemExit(1)
|
||||||
|
print(os.path.realpath(args[0]))
|
||||||
|
REALPATH
|
||||||
|
chmod 0755 "$COMPAT_BIN/realpath"
|
||||||
|
|
||||||
|
fail_case() { printf '[test] FAIL: %s\n' "$*" >&2; failures=$((failures + 1)); }
|
||||||
|
pass_case() { printf '[test] PASS: %s\n' "$*"; }
|
||||||
|
|
||||||
|
fingerprint() {
|
||||||
|
local dir="$1"
|
||||||
|
if [[ ! -d "$dir" ]]; then printf 'ABSENT\n'; return; fi
|
||||||
|
python3 - "$dir" <<'PY'
|
||||||
|
import hashlib
|
||||||
|
import os
|
||||||
|
import stat
|
||||||
|
import sys
|
||||||
|
|
||||||
|
root = os.path.abspath(sys.argv[1])
|
||||||
|
rows = []
|
||||||
|
for current, dirs, files in os.walk(root, topdown=True, followlinks=False):
|
||||||
|
for name in dirs + files:
|
||||||
|
path = os.path.join(current, name)
|
||||||
|
rel = os.path.relpath(path, root)
|
||||||
|
meta = os.lstat(path)
|
||||||
|
target = os.readlink(path) if stat.S_ISLNK(meta.st_mode) else ""
|
||||||
|
digest = ""
|
||||||
|
if stat.S_ISREG(meta.st_mode):
|
||||||
|
with open(path, "rb") as handle:
|
||||||
|
digest = hashlib.sha256(handle.read()).hexdigest()
|
||||||
|
rows.append((rel, stat.S_IFMT(meta.st_mode), stat.S_IMODE(meta.st_mode), meta.st_uid, meta.st_gid, target, digest))
|
||||||
|
payload = "\n".join("|".join(map(str, row)) for row in sorted(rows)).encode()
|
||||||
|
print(hashlib.sha256(payload).hexdigest())
|
||||||
|
PY
|
||||||
|
}
|
||||||
|
|
||||||
|
make_fake_npm() {
|
||||||
|
local bin="$1"
|
||||||
|
mkdir -p "$bin"
|
||||||
|
cat > "$bin/npm" <<'FAKE'
|
||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
if [[ "${1:-}" == "--version" ]]; then echo '10.6.2'; exit 0; fi
|
||||||
|
case "${1:-} ${2:-} ${3:-}" in
|
||||||
|
'view @mosaicstack/mosaic@next version') echo '0.0.50-next.999' ;;
|
||||||
|
'view @mosaicstack/gateway@next version') echo '0.0.7-next.999' ;;
|
||||||
|
'view @mosaicstack/mosaic version') echo '0.0.49' ;;
|
||||||
|
'ls -g --depth=0'|'ls -g --json') echo '{"dependencies":{"@mosaicstack/mosaic":{"version":"0.0.50-next.999"},"@mosaicstack/gateway":{"version":"0.0.7-next.999"}}}' ;;
|
||||||
|
ls*) echo '{"dependencies":{"@mosaicstack/mosaic":{"version":"0.0.50-next.999"},"@mosaicstack/gateway":{"version":"0.0.7-next.999"}}}' ;;
|
||||||
|
*) echo "unexpected fake npm command: $*" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
FAKE
|
||||||
|
chmod 0755 "$bin/npm"
|
||||||
|
}
|
||||||
|
|
||||||
|
printf '[test] case: --check enumerates exactly P0-P8, discriminates, and mutates nothing\n'
|
||||||
|
check_home="$TMP/check-home"
|
||||||
|
check_bin="$TMP/check-bin"
|
||||||
|
mkdir -p "$check_home/.config/mosaic/skills/alpha" "$check_home/.npm-global/bin" "$check_bin"
|
||||||
|
printf '# framework\n' > "$check_home/.config/mosaic/AGENTS.md"
|
||||||
|
printf '# skill\n' > "$check_home/.config/mosaic/skills/alpha/SKILL.md"
|
||||||
|
cat > "$check_home/.npm-global/bin/mosaic" <<'CLI'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
printf '0.0.50-next.999\n'
|
||||||
|
CLI
|
||||||
|
chmod 0755 "$check_home/.npm-global/bin/mosaic"
|
||||||
|
make_fake_npm "$check_bin"
|
||||||
|
before="$(fingerprint "$check_home")"
|
||||||
|
set +e
|
||||||
|
HOME="$check_home" MOSAIC_HOME="$check_home/.config/mosaic" MOSAIC_PREFIX="$check_home/.npm-global" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$check_bin:/usr/local/bin:/usr/bin:/bin" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --next >"$TMP/check.log" 2>&1
|
||||||
|
check_status=$?
|
||||||
|
set -e
|
||||||
|
after="$(fingerprint "$check_home")"
|
||||||
|
|
||||||
|
[[ "$before" == "$after" ]] && pass_case '--check left the complete HOME fingerprint unchanged' \
|
||||||
|
|| fail_case "--check mutated HOME (before=$before after=$after)"
|
||||||
|
[[ "$check_status" -ne 0 ]] && pass_case '--check exited non-zero for failed P4/P5/P8 predicates' \
|
||||||
|
|| fail_case '--check returned zero on the deliberately broken host'
|
||||||
|
|
||||||
|
phase_rows=0
|
||||||
|
for phase in P0 P1 P2 P3 P4 P5 P6 P7 P8; do
|
||||||
|
count="$(grep -Ec "^\[$phase\] (PASS|FAIL):" "$TMP/check.log" || true)"
|
||||||
|
[[ "$count" -eq 1 ]] || fail_case "$phase expected exactly one PASS/FAIL row, got $count"
|
||||||
|
phase_rows=$((phase_rows + count))
|
||||||
|
done
|
||||||
|
[[ "$phase_rows" -eq 9 ]] && pass_case '--check emitted exactly nine P0-P8 result rows' \
|
||||||
|
|| fail_case "--check emitted $phase_rows canonical rows instead of 9"
|
||||||
|
grep -q '^\[P3\] PASS:.*0\.0\.50-next\.999' "$TMP/check.log" \
|
||||||
|
&& pass_case 'P3 preserves the absolute-path exact-version discriminator' \
|
||||||
|
|| fail_case 'P3 did not PASS with the exact resolved next-lane version'
|
||||||
|
grep -q '^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:' "$TMP/check.log" \
|
||||||
|
&& pass_case 'P4 refuses fabricated precision when no shipped-set declaration exists' \
|
||||||
|
|| fail_case 'P4 did not report the declared-set population as NOT-MEASURED / UNDECLARED'
|
||||||
|
for phase in P5 P8; do
|
||||||
|
grep -q "^\[$phase\] FAIL:" "$TMP/check.log" \
|
||||||
|
&& pass_case "$phase remains an attributable expected RED" \
|
||||||
|
|| fail_case "$phase did not report its own expected failure"
|
||||||
|
done
|
||||||
|
|
||||||
|
printf '[test] case: --check discriminates a constructed good host without mutation\n'
|
||||||
|
good_home="$TMP/good-home"
|
||||||
|
good_bin="$TMP/good-bin"
|
||||||
|
good_prefix="$good_home/.npm-global"
|
||||||
|
good_mosaic="$good_home/.config/mosaic"
|
||||||
|
mkdir -p "$good_bin" "$good_prefix/bin" "$good_mosaic/skills/declared-skill"
|
||||||
|
make_fake_npm "$good_bin"
|
||||||
|
cp "$COMPAT_BIN/realpath" "$good_bin/realpath"
|
||||||
|
cat > "$good_bin/id" <<'ID'
|
||||||
|
#!/bin/bash
|
||||||
|
case "${1:-}" in
|
||||||
|
-u) echo 1001 ;;
|
||||||
|
-g) echo 1001 ;;
|
||||||
|
-un) echo fixture-user ;;
|
||||||
|
*) exec /bin/id "$@" ;;
|
||||||
|
esac
|
||||||
|
ID
|
||||||
|
cat > "$good_bin/stat" <<'STAT'
|
||||||
|
#!/bin/bash
|
||||||
|
if [[ "${1:-} ${2:-}" == '-c %u' ]]; then echo 1001; exit 0; fi
|
||||||
|
exec /bin/stat "$@"
|
||||||
|
STAT
|
||||||
|
cat > "$good_bin/curl" <<'CURL'
|
||||||
|
#!/bin/bash
|
||||||
|
exit 0
|
||||||
|
CURL
|
||||||
|
cat > "$good_bin/ldd" <<'LDD'
|
||||||
|
#!/bin/bash
|
||||||
|
echo 'ldd (GNU libc) 2.36'
|
||||||
|
LDD
|
||||||
|
chmod 0755 "$good_bin/id" "$good_bin/stat" "$good_bin/curl" "$good_bin/ldd"
|
||||||
|
cat > "$good_prefix/bin/mosaic" <<'CLI'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
printf '0.0.50-next.999\n'
|
||||||
|
CLI
|
||||||
|
chmod 0755 "$good_prefix/bin/mosaic"
|
||||||
|
cat > "$good_bin/getent" <<GETENT
|
||||||
|
#!/bin/bash
|
||||||
|
printf '%s:x:%s:%s::%s:%s\\n' '$(id -un)' '$(id -u)' '$(id -g)' '$good_home' '$good_bin/bash'
|
||||||
|
GETENT
|
||||||
|
cat > "$good_bin/bash" <<SHELL
|
||||||
|
#!/bin/bash
|
||||||
|
if [[ "\${*: -1}" == 'command -v mosaic' ]]; then
|
||||||
|
printf '%s\\n' '$good_prefix/bin/mosaic'
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
exec /bin/bash "\$@"
|
||||||
|
SHELL
|
||||||
|
chmod 0755 "$good_bin/getent" "$good_bin/bash"
|
||||||
|
printf '# Soul\n\nConfigured.\n' > "$good_mosaic/SOUL.md"
|
||||||
|
printf '# User\n\nConfigured.\n' > "$good_mosaic/USER.md"
|
||||||
|
chmod 0600 "$good_mosaic/SOUL.md" "$good_mosaic/USER.md"
|
||||||
|
cat > "$good_mosaic/skills/declared-skill/SKILL.md" <<'SKILL'
|
||||||
|
---
|
||||||
|
name: declared-skill
|
||||||
|
description: Constructed loadable acceptance skill.
|
||||||
|
---
|
||||||
|
|
||||||
|
# Declared skill
|
||||||
|
SKILL
|
||||||
|
printf '{"lane":"next","version":"0.0.50-next.999","skills":["declared-skill"]}\n' > "$good_mosaic/.install-shipped-skills.json"
|
||||||
|
printf '{\n "lane": "next",\n "cliVersion": "0.0.50-next.999"\n}\n' > "$good_mosaic/.install-manifest.json"
|
||||||
|
before="$(fingerprint "$good_home")"
|
||||||
|
set +e
|
||||||
|
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --next >"$TMP/good-check.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
after="$(fingerprint "$good_home")"
|
||||||
|
[[ "$status" -eq 0 ]] && pass_case 'good-host --check exited zero' || fail_case "good-host --check exited $status"
|
||||||
|
[[ "$before" == "$after" ]] && pass_case 'good-host --check left HOME unchanged' || fail_case 'good-host --check mutated HOME'
|
||||||
|
good_rows="$(grep -Ec '^\[P[0-8]\] PASS:' "$TMP/good-check.log" || true)"
|
||||||
|
[[ "$good_rows" -eq 9 ]] && pass_case 'good-host --check emitted nine PASS rows' \
|
||||||
|
|| { cat "$TMP/good-check.log" >&2; fail_case "good-host --check emitted $good_rows PASS rows"; }
|
||||||
|
|
||||||
|
printf '[test] case: persisted required-action failures remain blocking\n'
|
||||||
|
for blocked_phase in P4 P6; do
|
||||||
|
node -e '
|
||||||
|
const fs=require("fs"); const p=process.argv[1]; const phase=process.argv[2];
|
||||||
|
const m=JSON.parse(fs.readFileSync(p,"utf8")); m.phaseOutcomes={P4:"committed",P6:"committed"};
|
||||||
|
m.phaseOutcomes[phase]="failed"; fs.writeFileSync(p,JSON.stringify(m)+"\n");
|
||||||
|
' "$good_mosaic/.install-manifest.json" "$blocked_phase"
|
||||||
|
set +e
|
||||||
|
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --next >"$TMP/action-$blocked_phase.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
[[ "$status" -ne 0 ]] || fail_case "$blocked_phase action failure returned zero"
|
||||||
|
grep -q "^\[$blocked_phase\] FAIL:.*action reported a required $blocked_phase failure" "$TMP/action-$blocked_phase.log" \
|
||||||
|
&& pass_case "$blocked_phase action failure remained blocking in a later --check" \
|
||||||
|
|| fail_case "$blocked_phase persisted action failure was not attributed"
|
||||||
|
done
|
||||||
|
printf '{\n "lane": "next",\n "cliVersion": "0.0.50-next.999",\n "phaseOutcomes": {"P4":"committed","P6":"committed"}\n}\n' > "$good_mosaic/.install-manifest.json"
|
||||||
|
|
||||||
|
printf '[test] case: per-phase P2-P8 fault injection restores representative host mutations\n'
|
||||||
|
for phase in P2 P3 P4 P5 P6 P7 P8; do
|
||||||
|
home="$TMP/fault-$phase/home"
|
||||||
|
state="$TMP/fault-$phase/state"
|
||||||
|
mkdir -p "$home/.config/mosaic" "$home/.npm-global/bin" "$home/.claude" "$state"
|
||||||
|
printf 'operator-framework-sentinel\n' > "$home/.config/mosaic/operator.txt"
|
||||||
|
printf '@scope:registry=https://pre.example.invalid/\n' > "$home/.npmrc"
|
||||||
|
printf 'old-cli\n' > "$home/.npm-global/bin/mosaic"
|
||||||
|
printf '{"hooks":{"safe":true}}\n' > "$home/.claude/settings.json"
|
||||||
|
before="$(fingerprint "$home")"
|
||||||
|
set +e
|
||||||
|
HOME="$home" MOSAIC_HOME="$home/.config/mosaic" MOSAIC_PREFIX="$home/.npm-global" \
|
||||||
|
MOSAIC_INSTALL_STATE_DIR="$state" MOSAIC_INSTALL_FAULT_AFTER="$phase" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$COMPAT_BIN:$PATH" bash "$ROOT/tools/install.sh" --state-machine-self-test \
|
||||||
|
>"$TMP/fault-$phase.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
after="$(fingerprint "$home")"
|
||||||
|
[[ "$status" -ne 0 ]] || fail_case "$phase injected fault returned zero"
|
||||||
|
grep -q "phase=$phase" "$TMP/fault-$phase.log" \
|
||||||
|
|| fail_case "$phase fault transcript did not name the injected phase"
|
||||||
|
[[ "$before" == "$after" ]] \
|
||||||
|
&& pass_case "$phase rollback restored framework/npmrc/prefix/runtime representative state" \
|
||||||
|
|| fail_case "$phase rollback mismatch (before=$before after=$after)"
|
||||||
|
if find "$state" -type f -exec grep -l '"status"[[:space:]]*:[[:space:]]*"in-progress"' {} + 2>/dev/null | grep -q .; then
|
||||||
|
fail_case "$phase left a journal in-progress"
|
||||||
|
else
|
||||||
|
pass_case "$phase left no journal falsely in-progress"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
printf '[test] case: unsafe and overlapping rollback roots fail before mutation\n'
|
||||||
|
unsafe_home="$TMP/unsafe-home"
|
||||||
|
mkdir -p "$unsafe_home"
|
||||||
|
for case_name in root-target home-target overlap-target; do
|
||||||
|
case "$case_name" in
|
||||||
|
root-target) unsafe_mosaic=/; unsafe_prefix="$unsafe_home/.npm-global" ;;
|
||||||
|
home-target) unsafe_mosaic="$unsafe_home"; unsafe_prefix="$unsafe_home/.npm-global" ;;
|
||||||
|
overlap-target) unsafe_mosaic="$unsafe_home/.config"; unsafe_prefix="$unsafe_home/.config/mosaic/prefix" ;;
|
||||||
|
esac
|
||||||
|
before="$(fingerprint "$unsafe_home")"
|
||||||
|
set +e
|
||||||
|
HOME="$unsafe_home" MOSAIC_HOME="$unsafe_mosaic" MOSAIC_PREFIX="$unsafe_prefix" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --next >"$TMP/$case_name.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
after="$(fingerprint "$unsafe_home")"
|
||||||
|
[[ "$status" -ne 0 ]] || fail_case "$case_name unsafe path returned zero"
|
||||||
|
grep -q '^\[P0\] FAIL:.*unsafe context' "$TMP/$case_name.log" \
|
||||||
|
&& pass_case "$case_name was rejected by P0" || fail_case "$case_name lacked an attributable P0 failure"
|
||||||
|
[[ "$before" == "$after" ]] || fail_case "$case_name mutated HOME"
|
||||||
|
done
|
||||||
|
|
||||||
|
symlink_home="$TMP/symlink-home"
|
||||||
|
symlink_outside="$TMP/symlink-outside"
|
||||||
|
mkdir -p "$symlink_home" "$symlink_outside"
|
||||||
|
ln -s "$symlink_outside" "$symlink_home/.config"
|
||||||
|
set +e
|
||||||
|
HOME="$symlink_home" MOSAIC_HOME="$symlink_home/.config/mosaic" MOSAIC_PREFIX="$symlink_home/.npm-global" \
|
||||||
|
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
|
||||||
|
bash "$ROOT/tools/install.sh" --check --next >"$TMP/symlink-target.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
[[ "$status" -ne 0 ]] || fail_case 'symlink-parent unsafe path returned zero'
|
||||||
|
grep -q '^\[P0\] FAIL:.*unsafe context' "$TMP/symlink-target.log" \
|
||||||
|
&& pass_case 'symlinked rollback parent was rejected by P0' \
|
||||||
|
|| fail_case 'symlinked rollback parent lacked an attributable P0 failure'
|
||||||
|
[[ -z "$(find "$symlink_outside" -mindepth 1 -print -quit)" ]] || fail_case 'symlink target was mutated'
|
||||||
|
|
||||||
|
printf '[test] case: stale in-progress projection does not impersonate a live OS lock\n'
|
||||||
|
stale_home="$TMP/stale/home"
|
||||||
|
stale_state="$TMP/stale/state"
|
||||||
|
mkdir -p "$stale_home/.config/mosaic" "$stale_state"
|
||||||
|
printf '{"status":"in-progress","journal":"%s"}\n' "$stale_state/dead-run/journal.ndjson" > "$stale_state/active.json"
|
||||||
|
set +e
|
||||||
|
HOME="$stale_home" MOSAIC_HOME="$stale_home/.config/mosaic" MOSAIC_PREFIX="$stale_home/.npm-global" \
|
||||||
|
MOSAIC_INSTALL_STATE_DIR="$stale_state" MOSAIC_INSTALL_FAULT_AFTER=P2 MOSAIC_NO_COLOR=1 \
|
||||||
|
PATH="$COMPAT_BIN:$PATH" bash "$ROOT/tools/install.sh" --state-machine-self-test >"$TMP/stale.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
[[ "$status" -eq 97 ]] || fail_case "stale projection recovery expected injected status 97, got $status"
|
||||||
|
if find "$stale_state" -name prior-active.json -type f -print -quit | grep -q .; then
|
||||||
|
pass_case 'stale projection was preserved and superseded after the free OS lock was acquired'
|
||||||
|
else
|
||||||
|
fail_case 'stale projection was not preserved for recovery evidence'
|
||||||
|
fi
|
||||||
|
[[ "$(node -p "require('$stale_state/active.json').status")" == "rolled-back" ]] \
|
||||||
|
|| fail_case 'stale retry did not reach an honest rolled-back terminal state'
|
||||||
|
|
||||||
|
printf '[test] case: journal initialization failure is fatal before mutation\n'
|
||||||
|
journal_home="$TMP/journal-failure/home"
|
||||||
|
mkdir -p "$journal_home/.config/mosaic"
|
||||||
|
printf 'journal-sentinel\n' > "$journal_home/.config/mosaic/operator.txt"
|
||||||
|
before="$(fingerprint "$journal_home")"
|
||||||
|
set +e
|
||||||
|
HOME="$journal_home" MOSAIC_HOME="$journal_home/.config/mosaic" MOSAIC_PREFIX="$journal_home/.npm-global" \
|
||||||
|
MOSAIC_INSTALL_STATE_DIR="/proc/mosaic-journal-denied-$$" MOSAIC_INSTALL_FAULT_AFTER=P2 \
|
||||||
|
MOSAIC_NO_COLOR=1 bash "$ROOT/tools/install.sh" --state-machine-self-test \
|
||||||
|
>"$TMP/journal-failure.log" 2>&1
|
||||||
|
status=$?
|
||||||
|
set -e
|
||||||
|
after="$(fingerprint "$journal_home")"
|
||||||
|
[[ "$status" -ne 0 ]] && pass_case 'unwritable journal directory failed non-zero' \
|
||||||
|
|| fail_case 'unwritable journal directory returned zero'
|
||||||
|
grep -q 'cannot create private journal directory' "$TMP/journal-failure.log" \
|
||||||
|
&& pass_case 'journal initialization failure was named' \
|
||||||
|
|| fail_case 'journal initialization failure lacked a named diagnostic'
|
||||||
|
[[ "$before" == "$after" ]] && pass_case 'journal failure occurred before target mutation' \
|
||||||
|
|| fail_case "journal failure mutated target HOME (before=$before after=$after)"
|
||||||
|
|
||||||
|
if [[ "$failures" -ne 0 ]]; then
|
||||||
|
printf '[test] install state-machine acceptance RED: %d failed assertion(s)\n' "$failures" >&2
|
||||||
|
printf '[test] --check transcript: %s\n' "$TMP/check.log" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
printf '[test] installer state-machine acceptance passed\n'
|
||||||
+1151
-68
File diff suppressed because it is too large
Load Diff
@@ -35,10 +35,7 @@ export DARK_THRESHOLD_MS="${DARK_THRESHOLD_MS:-6000}"
|
|||||||
export AGENT_SLUGS="${AGENT_SLUGS:-alpha,bravo,charlie}"
|
export AGENT_SLUGS="${AGENT_SLUGS:-alpha,bravo,charlie}"
|
||||||
export VICTIM_SLUG="${VICTIM_SLUG:-charlie}"
|
export VICTIM_SLUG="${VICTIM_SLUG:-charlie}"
|
||||||
|
|
||||||
shopt -s nullglob
|
TSX_CLI="$(ls -d "${REPO}"/node_modules/.pnpm/tsx@*/node_modules/tsx/dist/cli.mjs 2>/dev/null | head -1)"
|
||||||
TSX_CANDIDATES=("${REPO}"/node_modules/.pnpm/tsx@*/node_modules/tsx/dist/cli.mjs)
|
|
||||||
shopt -u nullglob
|
|
||||||
TSX_CLI="${TSX_CANDIDATES[0]:-}"
|
|
||||||
if [[ -z "${TSX_CLI}" ]]; then
|
if [[ -z "${TSX_CLI}" ]]; then
|
||||||
echo "run.sh: tsx not found under node_modules — run pnpm install first" >&2
|
echo "run.sh: tsx not found under node_modules — run pnpm install first" >&2
|
||||||
exit 1
|
exit 1
|
||||||
|
|||||||
Executable
+63
@@ -0,0 +1,63 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Verify that the detector found exactly the pinned C1 phase verdicts. The
|
||||||
|
# fixture is expected to exit non-zero; this verifier is the green CI contract.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
|
MANIFEST="${MOSAIC_EXPECTED_RED_MANIFEST:-$ROOT/tools/fixtures/greenfield-expected-red.tsv}"
|
||||||
|
CASE="${1:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
|
||||||
|
LOG="${2:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
|
||||||
|
FIXTURE_EXIT="${3:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
|
||||||
|
|
||||||
|
[[ -r "$MANIFEST" ]] || { echo "expected-RED manifest is unreadable: $MANIFEST" >&2; exit 2; }
|
||||||
|
[[ -r "$LOG" ]] || { echo "fixture log is unreadable: $LOG" >&2; exit 2; }
|
||||||
|
[[ "$FIXTURE_EXIT" =~ ^[0-9]+$ ]] || { echo "fixture exit is not numeric: $FIXTURE_EXIT" >&2; exit 2; }
|
||||||
|
|
||||||
|
checks=0
|
||||||
|
failures=0
|
||||||
|
while IFS=$'\t' read -r case_name kind expectation; do
|
||||||
|
[[ -n "$case_name" && "${case_name:0:1}" != "#" ]] || continue
|
||||||
|
[[ "$case_name" == "$CASE" ]] || continue
|
||||||
|
checks=$((checks + 1))
|
||||||
|
case "$kind" in
|
||||||
|
exit)
|
||||||
|
if [[ "$FIXTURE_EXIT" != "$expectation" ]]; then
|
||||||
|
echo "expected-RED mismatch: case=$CASE fixture_exit=$FIXTURE_EXIT expected=$expectation" >&2
|
||||||
|
failures=$((failures + 1))
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
phase)
|
||||||
|
phase="${expectation%%=*}"
|
||||||
|
expected_verdict="${expectation#*=}"
|
||||||
|
last_row="$(grep -E "^\[$phase\] (PASS|FAIL):" "$LOG" | tail -n 1 || true)"
|
||||||
|
actual_verdict="$(printf '%s\n' "$last_row" | sed -n "s/^\[$phase\] \(PASS\|FAIL\):.*/\1/p")"
|
||||||
|
if [[ "$actual_verdict" != "$expected_verdict" ]]; then
|
||||||
|
echo "expected-RED mismatch: case=$CASE phase=$phase got=${actual_verdict:-missing} expected=$expected_verdict" >&2
|
||||||
|
failures=$((failures + 1))
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
require)
|
||||||
|
if ! grep -Eq -- "$expectation" "$LOG"; then
|
||||||
|
echo "expected-RED missing required evidence: case=$CASE regex=$expectation" >&2
|
||||||
|
failures=$((failures + 1))
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
forbid)
|
||||||
|
if grep -Eq -- "$expectation" "$LOG"; then
|
||||||
|
echo "expected-RED found forbidden evidence: case=$CASE regex=$expectation" >&2
|
||||||
|
failures=$((failures + 1))
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "invalid expected-RED manifest kind: case=$case_name kind=$kind" >&2
|
||||||
|
exit 2
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done < "$MANIFEST"
|
||||||
|
|
||||||
|
[[ "$checks" -gt 0 ]] || { echo "expected-RED manifest has no checks for case=$CASE" >&2; exit 2; }
|
||||||
|
if [[ "$failures" -ne 0 ]]; then
|
||||||
|
echo "expected-RED verification failed: case=$CASE failures=$failures checks=$checks" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
printf 'expected-RED verification passed: case=%s checks=%d\n' "$CASE" "$checks"
|
||||||
Executable
+36
@@ -0,0 +1,36 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
|
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-expected-red-test.XXXXXX")"
|
||||||
|
trap 'rm -rf "$TMP"' EXIT
|
||||||
|
|
||||||
|
cat > "$TMP/match.log" <<'LOG'
|
||||||
|
[fixture] resolved lane=next package=@mosaicstack/mosaic@next version=0.0.50-next.999
|
||||||
|
[fixture] installer_exit=1 done_claims=0
|
||||||
|
[P0] PASS: supported context
|
||||||
|
[P1] PASS: preflight complete
|
||||||
|
[P2] PASS: pinned artifact
|
||||||
|
[P3] PASS: absolute_path=/home/test/.npm-global/bin/mosaic version=0.0.50-next.999 equals resolved lane version
|
||||||
|
[P4] FAIL: NOT-MEASURED / UNDECLARED: declaration absent
|
||||||
|
[P5] FAIL: identity absent
|
||||||
|
[P6] FAIL: activation unavailable
|
||||||
|
[P7] PASS: no services requested
|
||||||
|
[P8] FAIL: shell path absent
|
||||||
|
[P9] FAIL: aggregate refusal
|
||||||
|
LOG
|
||||||
|
|
||||||
|
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null
|
||||||
|
printf '[test] PASS: matching detector findings make the CI verifier green\n'
|
||||||
|
|
||||||
|
sed 's/^\[P4\] FAIL:/[P4] PASS:/' "$TMP/match.log" > "$TMP/drift.log"
|
||||||
|
if bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/drift.log" 1 >/dev/null 2>&1; then
|
||||||
|
echo '[test] FAIL: changed P4 verdict did not invalidate the pinned manifest' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
printf '[test] PASS: changed phase verdict requires a deliberate manifest update\n'
|
||||||
|
|
||||||
|
if bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 0 >/dev/null 2>&1; then
|
||||||
|
echo '[test] FAIL: unexpected fixture exit did not invalidate the pinned manifest' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
printf '[test] PASS: unexpected fixture exit remains blocking\n'
|
||||||
Reference in New Issue
Block a user