Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
758659ddf9 | ||
|
|
59e2c46076 | ||
|
|
9b4fb6b548 | ||
|
|
23204978e1 | ||
|
|
bee24fbdd6 | ||
|
|
7d620ea288 | ||
|
|
e1e70a9966 | ||
|
|
e2a9b1ca59 |
+1
-24
@@ -30,19 +30,6 @@ steps:
|
|||||||
# the baked pnpm store.
|
# the baked pnpm store.
|
||||||
- pnpm install --frozen-lockfile --prefer-offline
|
- pnpm install --frozen-lockfile --prefer-offline
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
|
||||||
# The steps below (sanitization, upgrade-guard, typecheck, lint, format,
|
|
||||||
# test) are the COMPLETE mandatory verification set. SDLC-D-034 mirrors them
|
|
||||||
# one-for-one in the canonical terminal verification command — root
|
|
||||||
# `pnpm verify:release` (scripts/verify-release.mjs) — which the publish
|
|
||||||
# pipeline (.woodpecker/publish.yml `verify` step) runs before ANY publish
|
|
||||||
# effect. These lines stay direct (not routed through the runner) because the
|
|
||||||
# #1017 test-enumeration guard audits framework tool paths through THIS
|
|
||||||
# surface; scripts/verify-release.test.mjs enforces that the runner's stage
|
|
||||||
# table keeps matching these commands exactly, so the two cannot drift.
|
|
||||||
# ---------------------------------------------------------------------------
|
|
||||||
|
|
||||||
# Canonical verify:release stage `sanitization`.
|
|
||||||
# Blocking gate: public framework package must contain no operator-specific
|
# Blocking gate: public framework package must contain no operator-specific
|
||||||
# personal data or private $HOME defaults. Runs early (no node_modules needed).
|
# personal data or private $HOME defaults. Runs early (no node_modules needed).
|
||||||
sanitization:
|
sanitization:
|
||||||
@@ -60,7 +47,6 @@ steps:
|
|||||||
# with everything it guards; this direct line keeps one instrument running.
|
# with everything it guards; this direct line keeps one instrument running.
|
||||||
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
||||||
|
|
||||||
# Canonical verify:release stage `upgrade-guard`.
|
|
||||||
# Blocking gate (#791): a framework upgrade must never write or delete an
|
# Blocking gate (#791): a framework upgrade must never write or delete an
|
||||||
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
||||||
# survives a keep-mode reseed byte-identical (with rsync present AND absent —
|
# survives a keep-mode reseed byte-identical (with rsync present AND absent —
|
||||||
@@ -82,8 +68,6 @@ steps:
|
|||||||
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
|
||||||
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
|
||||||
|
|
||||||
# Canonical verify:release stage `typecheck` — the same `pnpm typecheck`
|
|
||||||
# invocation (which runs the checkout preflight first, then turbo).
|
|
||||||
typecheck:
|
typecheck:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -94,8 +78,7 @@ steps:
|
|||||||
- sanitization
|
- sanitization
|
||||||
- upgrade-guard
|
- upgrade-guard
|
||||||
|
|
||||||
# lint, format, and test are independent — run in parallel after typecheck.
|
# lint, format, and test are independent — run in parallel after typecheck
|
||||||
# Each runs exactly its canonical verify:release stage command.
|
|
||||||
lint:
|
lint:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -112,12 +95,6 @@ steps:
|
|||||||
depends_on:
|
depends_on:
|
||||||
- typecheck
|
- typecheck
|
||||||
|
|
||||||
# Canonical verify:release stage `test` — the `pnpm test` line below is the
|
|
||||||
# shared command; everything else in this step is PIPELINE-LEVEL
|
|
||||||
# prerequisite the canonical command expects its caller to provide (SDLC-D-034):
|
|
||||||
# the ci-postgres service + pg_isready wait + db:migrate (postgres path),
|
|
||||||
# `apk add openssl`, and the pinned pi install. None of those can move into
|
|
||||||
# the runner (it must also work locally on the PGlite path with no database).
|
|
||||||
test:
|
test:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -1,19 +1,5 @@
|
|||||||
# Build, publish npm packages, and push Docker images
|
# Build, publish npm packages, and push Docker images
|
||||||
# Runs on main for stable publishes and on next for integration-line prereleases/images
|
# Runs on main for stable publishes and on next for integration-line prereleases/images
|
||||||
#
|
|
||||||
# SDLC-D-034 publish gate: every publish effect (publish-npm, publish-next-npm,
|
|
||||||
# and every image build/push step) depends DIRECTLY on the `verify` step below.
|
|
||||||
# `verify` (a) asserts the provider's commit identity matches the actual
|
|
||||||
# checkout (CI_COMMIT_SHA == git rev-parse HEAD, fail closed on mismatch or
|
|
||||||
# emptiness) and (b) runs the canonical terminal verification command
|
|
||||||
# (`pnpm verify:release`), which mirrors the PR CI pipeline's complete
|
|
||||||
# mandatory set (sanitization, upgrade-guard, preflight+typecheck, lint,
|
|
||||||
# format:check, test, build) — see scripts/verify-release.mjs. A missing,
|
|
||||||
# failed, skipped, cancelled, or inconclusive verification therefore skips the
|
|
||||||
# dependent publish effects (fail closed). Path-filtered short-circuits may
|
|
||||||
# skip publish EFFECTS (e.g. docs-only merges) but never bypass `verify` for a
|
|
||||||
# publish that does run: `verify` itself carries no path filter.
|
|
||||||
# scripts/verify-release.test.mjs enforces this DAG invariant at checkout time.
|
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
||||||
@@ -62,45 +48,6 @@ steps:
|
|||||||
# Resolve from the baked pnpm store instead of a cold network fetch.
|
# Resolve from the baked pnpm store instead of a cold network fetch.
|
||||||
- pnpm install --frozen-lockfile --prefer-offline
|
- pnpm install --frozen-lockfile --prefer-offline
|
||||||
|
|
||||||
# SDLC-D-034 exact-commit publish gate. No `when`/path filter on purpose: it
|
|
||||||
# runs for every event this pipeline serves so no publish effect can ever
|
|
||||||
# start without it. Fails closed on commit-identity mismatch (or either SHA
|
|
||||||
# being empty) and on any incomplete verification.
|
|
||||||
verify:
|
|
||||||
image: *node_image
|
|
||||||
commands:
|
|
||||||
- *enable_pnpm
|
|
||||||
# (a) Commit identity: the provider's claimed SHA must equal the actual
|
|
||||||
# checkout HEAD — verification of anything else must never authorize a
|
|
||||||
# publish of this commit.
|
|
||||||
- |
|
|
||||||
if [ -z "$CI_COMMIT_SHA" ]; then
|
|
||||||
echo "[verify] FATAL: CI_COMMIT_SHA is empty — cannot certify commit identity" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
CHECKOUT_SHA="$(git rev-parse HEAD 2>/dev/null || true)"
|
|
||||||
if [ -z "$CHECKOUT_SHA" ]; then
|
|
||||||
echo "[verify] FATAL: git rev-parse HEAD returned nothing — cannot certify commit identity" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [ "$CI_COMMIT_SHA" != "$CHECKOUT_SHA" ]; then
|
|
||||||
echo "[verify] FATAL: provider commit ($CI_COMMIT_SHA) != checkout HEAD ($CHECKOUT_SHA)" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "[verify] commit identity confirmed: $CHECKOUT_SHA"
|
|
||||||
# (b) Canonical terminal verification. Caller-provided prerequisites the
|
|
||||||
# runner expects (see .woodpecker/ci.yml comments): bash/rsync for the
|
|
||||||
# guard stages, openssl + the pinned pi binary for the test stage. git is
|
|
||||||
# baked into ci-base but re-asserted here so the identity check above can
|
|
||||||
# never silently depend on a stale baked image. DATABASE_URL is
|
|
||||||
# deliberately NOT set: the canonical command must hold on the PGlite
|
|
||||||
# path too and never sets or requires a database itself.
|
|
||||||
- apk add --no-cache bash rsync openssl git
|
|
||||||
- npm install -g @earendil-works/[email protected]
|
|
||||||
- pnpm verify:release
|
|
||||||
depends_on:
|
|
||||||
- install
|
|
||||||
|
|
||||||
build:
|
build:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -108,7 +55,6 @@ steps:
|
|||||||
- pnpm build
|
- pnpm build
|
||||||
depends_on:
|
depends_on:
|
||||||
- install
|
- install
|
||||||
- verify
|
|
||||||
|
|
||||||
publish-npm:
|
publish-npm:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
@@ -168,7 +114,6 @@ steps:
|
|||||||
exit 1
|
exit 1
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
- verify
|
|
||||||
|
|
||||||
publish-next-npm:
|
publish-next-npm:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
@@ -247,7 +192,6 @@ steps:
|
|||||||
echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION"
|
echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION"
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
- verify
|
|
||||||
|
|
||||||
# TODO: Uncomment when ready to publish to npmjs.org
|
# TODO: Uncomment when ready to publish to npmjs.org
|
||||||
# publish-npmjs:
|
# publish-npmjs:
|
||||||
@@ -261,7 +205,6 @@ steps:
|
|||||||
# - bash scripts/publish-npmjs.sh
|
# - bash scripts/publish-npmjs.sh
|
||||||
# depends_on:
|
# depends_on:
|
||||||
# - build
|
# - build
|
||||||
# - verify
|
|
||||||
# when:
|
# when:
|
||||||
# - event: [tag]
|
# - event: [tag]
|
||||||
|
|
||||||
@@ -299,7 +242,6 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
- verify
|
|
||||||
|
|
||||||
build-appservice:
|
build-appservice:
|
||||||
image: gcr.io/kaniko-project/executor:debug
|
image: gcr.io/kaniko-project/executor:debug
|
||||||
@@ -326,7 +268,6 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
- verify
|
|
||||||
|
|
||||||
build-web:
|
build-web:
|
||||||
image: gcr.io/kaniko-project/executor:debug
|
image: gcr.io/kaniko-project/executor:debug
|
||||||
@@ -353,4 +294,3 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
- verify
|
|
||||||
|
|||||||
@@ -9,7 +9,6 @@
|
|||||||
"preflight": "node scripts/preflight.mjs",
|
"preflight": "node scripts/preflight.mjs",
|
||||||
"clean:generated": "node scripts/clean-generated.mjs",
|
"clean:generated": "node scripts/clean-generated.mjs",
|
||||||
"typecheck": "pnpm preflight && turbo run typecheck",
|
"typecheck": "pnpm preflight && turbo run typecheck",
|
||||||
"verify:release": "node scripts/verify-release.mjs",
|
|
||||||
"test:checkout": "node --test scripts/*.test.mjs",
|
"test:checkout": "node --test scripts/*.test.mjs",
|
||||||
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
|
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
|
||||||
"test:installer": "bash tools/install-next-lane.test.sh",
|
"test:installer": "bash tools/install-next-lane.test.sh",
|
||||||
|
|||||||
@@ -12,33 +12,6 @@ The default tmux socket is `mosaic-fleet` so fleet commands do not touch the
|
|||||||
default tmux server. The roster is the desired-state authority; generated environment files are
|
default tmux server. The roster is the desired-state authority; generated environment files are
|
||||||
rebuildable projections, never a second source of configuration.
|
rebuildable projections, never a second source of configuration.
|
||||||
|
|
||||||
## Brain-home split (fleet state vs framework templates)
|
|
||||||
|
|
||||||
When a mosaic-brain clone is present, fleet **state** resolves from the brain
|
|
||||||
home while framework templates and dispatch state stay in the config home
|
|
||||||
(three-tree model, canon `docs/STRUCTURE-CANON.md` §2):
|
|
||||||
|
|
||||||
| Path | Without brain (legacy) | With brain |
|
|
||||||
| ------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------ |
|
|
||||||
| `fleet/agents/<seat>.env.*` | `~/.config/mosaic/fleet/agents/` | `~/.mosaic/fleet/agents/` |
|
|
||||||
| `fleet/roles.local/` (overrides) | `~/.config/mosaic/fleet/roles.local/` | `~/.mosaic/fleet/roles.local/` |
|
|
||||||
| `fleet/profiles/` (working copies) | `~/.config/mosaic/fleet/profiles/` | `~/.mosaic/fleet/profiles/` |
|
|
||||||
| `fleet/roster.yaml`, `fleet/roles/` (baseline), `fleet/run/`, `fleet/services/` | `~/.config/mosaic/fleet/…` | unchanged (config home) |
|
|
||||||
|
|
||||||
Activation (`packages/mosaic/src/fleet/brain-home.ts`, mirrored in
|
|
||||||
`tools/fleet/start-agent-session.sh`):
|
|
||||||
|
|
||||||
1. `MOSAIC_BRAIN_HOME` env var — explicit, always wins.
|
|
||||||
2. Canonical `~/.mosaic` — adopted only when `MOSAIC_HOME` is the default
|
|
||||||
`~/.config/mosaic` AND `~/.mosaic/fleet/agents` exists. Custom
|
|
||||||
`--mosaic-home` values (tests, sandboxes, canaries) never adopt, keeping
|
|
||||||
them hermetic.
|
|
||||||
3. Otherwise the config home (legacy single-tree behavior).
|
|
||||||
|
|
||||||
Seat env dirs under a brain are subject to the same privacy boundary (0700
|
|
||||||
dirs, 0600 files); `.env.generated` files are structure-valuable and tracked
|
|
||||||
in the brain repo, hand-maintained `.env`/`.env.local` stay ignored and private.
|
|
||||||
|
|
||||||
## Examples
|
## Examples
|
||||||
|
|
||||||
- `examples/minimal.yaml` starts one local canary slot.
|
- `examples/minimal.yaml` starts one local canary slot.
|
||||||
|
|||||||
@@ -80,26 +80,6 @@ safe_path "$MOSAIC_HOME" || fail_env unsafe-path MOSAIC_HOME "$MOSAIC_HOME"
|
|||||||
|
|
||||||
FLEET_DIR="$MOSAIC_HOME/fleet"
|
FLEET_DIR="$MOSAIC_HOME/fleet"
|
||||||
AGENT_ENV_DIR="$FLEET_DIR/agents"
|
AGENT_ENV_DIR="$FLEET_DIR/agents"
|
||||||
|
|
||||||
# Brain-home split (canon docs/STRUCTURE-CANON.md §2): seat launch envs live
|
|
||||||
# under the brain home's fleet/agents when a brain is active; roster, roles
|
|
||||||
# baseline, and runtime state (fleet/run) stay under MOSAIC_HOME.
|
|
||||||
# Resolution mirrors packages/mosaic/src/fleet/brain-home.ts:
|
|
||||||
# 1. MOSAIC_BRAIN_HOME env (explicit, always wins)
|
|
||||||
# 2. ~/.mosaic — adopted only when MOSAIC_HOME is the default config home AND
|
|
||||||
# ~/.mosaic/fleet/agents exists
|
|
||||||
# 3. MOSAIC_HOME (legacy single-tree)
|
|
||||||
BRAIN_HOME="${MOSAIC_BRAIN_HOME:-}"
|
|
||||||
if [ -z "$BRAIN_HOME" ]; then
|
|
||||||
BRAIN_HOME="$MOSAIC_HOME"
|
|
||||||
if [ "$(cd "$MOSAIC_HOME" 2>/dev/null && pwd -P)" = "$HOME/.config/mosaic" ] \
|
|
||||||
&& [ -d "$HOME/.mosaic/fleet/agents" ]; then
|
|
||||||
BRAIN_HOME="$HOME/.mosaic"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
if [ "$BRAIN_HOME" != "$MOSAIC_HOME" ]; then
|
|
||||||
AGENT_ENV_DIR="$BRAIN_HOME/fleet/agents"
|
|
||||||
fi
|
|
||||||
assert_managed_directory "$MOSAIC_HOME"
|
assert_managed_directory "$MOSAIC_HOME"
|
||||||
assert_managed_directory "$FLEET_DIR"
|
assert_managed_directory "$FLEET_DIR"
|
||||||
assert_private_directory "$AGENT_ENV_DIR"
|
assert_private_directory "$AGENT_ENV_DIR"
|
||||||
|
|||||||
@@ -167,54 +167,6 @@ if echo "$valid_args" | grep -qF 'bash -c'; then
|
|||||||
fail "launcher constructed a shell command payload"
|
fail "launcher constructed a shell command payload"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ── Brain-home split (canon §2) ─────────────────────────────────────────
|
|
||||||
# When MOSAIC_HOME is the default config home under $HOME and the host carries
|
|
||||||
# $HOME/.mosaic/fleet/agents, seat envs resolve from the brain tree; the config
|
|
||||||
# home still owns fleet/run (holder-owner) and remains a managed boundary.
|
|
||||||
: > "$TMUX_CALLS"
|
|
||||||
HOME_BRAIN="$ROOT/brain-home"
|
|
||||||
CONFIG_HOME="$HOME_BRAIN/.config/mosaic"
|
|
||||||
BRAIN="$HOME_BRAIN/.mosaic"
|
|
||||||
mkdir -p "$CONFIG_HOME/fleet/run" "$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
|
||||||
chmod 700 "$CONFIG_HOME" "$CONFIG_HOME/fleet" "$CONFIG_HOME/fleet/run" \
|
|
||||||
"$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
|
||||||
printf '123e4567-e89b-12d3-a456-426614174000\n' > "$CONFIG_HOME/fleet/run/holder-owner"
|
|
||||||
chmod 600 "$CONFIG_HOME/fleet/run/holder-owner"
|
|
||||||
cat > "$BRAIN/fleet/agents/coder-brain.env.generated" <<EOF
|
|
||||||
MOSAIC_AGENT_NAME=coder-brain
|
|
||||||
MOSAIC_AGENT_CLASS=code
|
|
||||||
MOSAIC_AGENT_RUNTIME=pi
|
|
||||||
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
|
|
||||||
MOSAIC_AGENT_REASONING=high
|
|
||||||
MOSAIC_AGENT_TOOL_POLICY=code
|
|
||||||
MOSAIC_AGENT_WORKDIR=$HOME_BRAIN/work
|
|
||||||
MOSAIC_TMUX_SOCKET=mosaic-test
|
|
||||||
EOF
|
|
||||||
chmod 600 "$BRAIN/fleet/agents/coder-brain.env.generated"
|
|
||||||
install_pane_binaries "$HOME_BRAIN"
|
|
||||||
HOME="$HOME_BRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
|
||||||
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_BRAIN" \
|
|
||||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
|
||||||
MOSAIC_HOME="$CONFIG_HOME" "$START" coder-brain
|
|
||||||
brain_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
|
||||||
echo "$brain_args" | grep -qF new-session || fail "brain-home generated projection did not reach tmux"
|
|
||||||
echo "$brain_args" | grep -qF 'coder-brain' || fail "brain-home agent env was not the launch source"
|
|
||||||
[ -f "$BRAIN/fleet/agents/coder-brain.env.generated" ] || fail "brain generated env vanished"
|
|
||||||
|
|
||||||
# Negative control: the SAME default-config-home shape but without
|
|
||||||
# ~/.mosaic/fleet/agents — the config-home env tree is used directly (legacy).
|
|
||||||
: > "$TMUX_CALLS"
|
|
||||||
HOME_NOBRAIN="$ROOT/brainless-home"
|
|
||||||
CONFIG_HOME_NOBRAIN="$HOME_NOBRAIN/.config/mosaic"
|
|
||||||
write_generated "$CONFIG_HOME_NOBRAIN" "coder-legacy"
|
|
||||||
install_pane_binaries "$HOME_NOBRAIN"
|
|
||||||
HOME="$HOME_NOBRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
|
||||||
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_NOBRAIN" \
|
|
||||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
|
||||||
MOSAIC_HOME="$CONFIG_HOME_NOBRAIN" "$START" coder-legacy
|
|
||||||
legacy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
|
||||||
echo "$legacy_args" | grep -qF new-session || fail "legacy single-tree launch regressed"
|
|
||||||
|
|
||||||
# The pane must start through an absolute clean-environment boundary. Its
|
# The pane must start through an absolute clean-environment boundary. Its
|
||||||
# runtime command remains an argv vector, but no holder/session environment
|
# runtime command remains an argv vector, but no holder/session environment
|
||||||
# control variable can pass through the pane command.
|
# control variable can pass through the pane command.
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
import { readFile } from 'node:fs/promises';
|
import { readFile } from 'node:fs/promises';
|
||||||
import { join, resolve } from 'node:path';
|
import { join, resolve } from 'node:path';
|
||||||
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
executeFleetAgentMutation,
|
executeFleetAgentMutation,
|
||||||
@@ -150,9 +149,9 @@ async function executeCommand(
|
|||||||
request,
|
request,
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
rosterPath,
|
rosterPath,
|
||||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||||
rolesDir: join(mosaicHome, 'fleet', 'roles'),
|
rolesDir: join(mosaicHome, 'fleet', 'roles'),
|
||||||
overrideDir: fleetRolesLocalDir(mosaicHome),
|
overrideDir: join(mosaicHome, 'fleet', 'roles.local'),
|
||||||
dryRun: forceDryRun || opts.dryRun === true,
|
dryRun: forceDryRun || opts.dryRun === true,
|
||||||
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
|
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
import { readFile } from 'node:fs/promises';
|
import { readFile } from 'node:fs/promises';
|
||||||
import { join } from 'node:path';
|
import { join } from 'node:path';
|
||||||
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
parseV1MigrationObservations,
|
parseV1MigrationObservations,
|
||||||
@@ -121,11 +120,11 @@ export function registerFleetMigrationCommand(
|
|||||||
observations,
|
observations,
|
||||||
personaDirs: {
|
personaDirs: {
|
||||||
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
|
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
|
||||||
overrideDir: deps.overrideDir ?? fleetRolesLocalDir(mosaicHome),
|
overrideDir: deps.overrideDir ?? join(mosaicHome, 'fleet', 'roles.local'),
|
||||||
},
|
},
|
||||||
environment: {
|
environment: {
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
printJson(preview);
|
printJson(preview);
|
||||||
|
|||||||
@@ -30,21 +30,19 @@ import { lstat, readFile, readdir, stat } from 'node:fs/promises';
|
|||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { basename, isAbsolute, join, sep } from 'node:path';
|
import { basename, isAbsolute, join, sep } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import { fleetRolesLocalDir } from '../fleet/brain-home.js';
|
|
||||||
|
|
||||||
function defaultMosaicHome(): string {
|
function defaultMosaicHome(): string {
|
||||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Baseline persona role contracts (reseeded on update; config home — framework). */
|
/** Baseline persona role contracts (reseeded on update). */
|
||||||
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return join(mosaicHome, 'fleet', 'roles');
|
return join(mosaicHome, 'fleet', 'roles');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** PRESERVE-protected override layer (survives update; wins on merge).
|
/** PRESERVE-protected override layer (survives update; wins on merge). */
|
||||||
* Brain home (`~/.mosaic/fleet/roles.local`) when a brain is active. */
|
|
||||||
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return fleetRolesLocalDir(mosaicHome);
|
return join(mosaicHome, 'fleet', 'roles.local');
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -25,7 +25,6 @@ import { homedir } from 'node:os';
|
|||||||
import { basename, join } from 'node:path';
|
import { basename, join } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import YAML from 'yaml';
|
import YAML from 'yaml';
|
||||||
import { fleetProfilesDir } from '../fleet/brain-home.js';
|
|
||||||
import {
|
import {
|
||||||
defaultOverrideDir,
|
defaultOverrideDir,
|
||||||
extractClassesFromDir,
|
extractClassesFromDir,
|
||||||
@@ -37,10 +36,9 @@ function defaultMosaicHome(): string {
|
|||||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Directory holding the seeded profile yaml files — brain home when active
|
/** Directory holding the seeded profile yaml files. */
|
||||||
* (user working copies, committed), else the config home seed. */
|
|
||||||
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return fleetProfilesDir(mosaicHome);
|
return join(mosaicHome, 'fleet', 'profiles');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Directory holding the persona role contracts. */
|
/** Directory holding the persona role contracts. */
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ import { homedir } from 'node:os';
|
|||||||
import { join, relative, resolve } from 'node:path';
|
import { join, relative, resolve } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import type { CommandRunner } from './fleet.js';
|
import type { CommandRunner } from './fleet.js';
|
||||||
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
|
||||||
import {
|
import {
|
||||||
applyPreparedGeneratedAgentEnvironmentProjection,
|
applyPreparedGeneratedAgentEnvironmentProjection,
|
||||||
prepareGeneratedAgentEnvironmentProjection,
|
prepareGeneratedAgentEnvironmentProjection,
|
||||||
@@ -154,7 +153,7 @@ export async function executeFleetRegen(
|
|||||||
options: FleetRegenOptions,
|
options: FleetRegenOptions,
|
||||||
): Promise<FleetRegenResult> {
|
): Promise<FleetRegenResult> {
|
||||||
const mosaicHome = defaultMosaicHome(deps);
|
const mosaicHome = defaultMosaicHome(deps);
|
||||||
const agentEnvDir = fleetAgentEnvDir(mosaicHome);
|
const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
|
||||||
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
|
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
|
||||||
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
|
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
|
||||||
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
|
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
|
||||||
|
|||||||
@@ -13,7 +13,6 @@ import {
|
|||||||
import { randomUUID } from 'node:crypto';
|
import { randomUUID } from 'node:crypto';
|
||||||
import { homedir, hostname, userInfo } from 'node:os';
|
import { homedir, hostname, userInfo } from 'node:os';
|
||||||
import { dirname, join, resolve } from 'node:path';
|
import { dirname, join, resolve } from 'node:path';
|
||||||
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
|
||||||
import { fileURLToPath } from 'node:url';
|
import { fileURLToPath } from 'node:url';
|
||||||
import { spawn } from 'node:child_process';
|
import { spawn } from 'node:child_process';
|
||||||
import * as readline from 'node:readline';
|
import * as readline from 'node:readline';
|
||||||
@@ -159,7 +158,7 @@ export function resolveFleetPaths(mosaicHome = defaultMosaicHome()): FleetPaths
|
|||||||
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
|
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
|
||||||
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
|
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
|
||||||
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
|
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
|
||||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -349,90 +349,3 @@ describe('registerRuntimeLaunchers — claudex (EXPERIMENTAL overlay)', () => {
|
|||||||
expect(mockExit).not.toHaveBeenCalled();
|
expect(mockExit).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
// ─── Seat harness homes (MOSAIC-D-002, brain-home split) ────────────────────
|
|
||||||
|
|
||||||
import { activeSeatDir, seatPersonaOverlay } from './launch.js';
|
|
||||||
|
|
||||||
describe('activeSeatDir — per-agent harness home resolution', () => {
|
|
||||||
let root: string;
|
|
||||||
const savedAgentName = process.env['MOSAIC_AGENT_NAME'];
|
|
||||||
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
|
|
||||||
beforeEach(() => {
|
|
||||||
root = mkdtempSync(join(tmpdir(), 'mosaic-seat-home-'));
|
|
||||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
});
|
|
||||||
|
|
||||||
afterEach(() => {
|
|
||||||
rmSync(root, { recursive: true, force: true });
|
|
||||||
if (savedAgentName === undefined) {
|
|
||||||
delete process.env['MOSAIC_AGENT_NAME'];
|
|
||||||
} else {
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = savedAgentName;
|
|
||||||
}
|
|
||||||
if (savedBrainHome !== undefined) {
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
|
||||||
} else {
|
|
||||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('resolves the seat dir when MOSAIC_BRAIN_HOME carries the seat', () => {
|
|
||||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
|
||||||
mkdirSync(seat, { recursive: true });
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
|
||||||
|
|
||||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBe(seat);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('returns undefined without an agent name (bare launches stay shared)', () => {
|
|
||||||
delete process.env['MOSAIC_AGENT_NAME'];
|
|
||||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('returns undefined when the seat dir does not exist in the brain', () => {
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = 'ghost';
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
|
||||||
mkdirSync(join(root, 'brain', 'fleet', 'agents'), { recursive: true });
|
|
||||||
|
|
||||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['../escape', 'a/b', '.hidden-start', '', 'spaced name'])(
|
|
||||||
'rejects unsafe agent name %j (path traversal cannot leave the seat store)',
|
|
||||||
(name: string) => {
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = name;
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
|
||||||
|
|
||||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('seatPersonaOverlay renders the seat SOUL.md as an overlay block', () => {
|
|
||||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
|
||||||
mkdirSync(seat, { recursive: true });
|
|
||||||
writeFileSync(join(seat, 'SOUL.md'), '# coder0 — code seat persona\n\nShips tested code.\n');
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
|
||||||
|
|
||||||
const overlay = seatPersonaOverlay(join(root, 'config', 'mosaic'));
|
|
||||||
expect(overlay).toContain('## Seat Persona');
|
|
||||||
expect(overlay).toContain('coder0 — code seat persona');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('seatPersonaOverlay is empty when the seat carries no SOUL.md', () => {
|
|
||||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
|
||||||
mkdirSync(seat, { recursive: true });
|
|
||||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
|
||||||
|
|
||||||
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('seatPersonaOverlay is empty when no agent name is set', () => {
|
|
||||||
delete process.env['MOSAIC_AGENT_NAME'];
|
|
||||||
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ import {
|
|||||||
import { createHash, randomBytes } from 'node:crypto';
|
import { createHash, randomBytes } from 'node:crypto';
|
||||||
import { createRequire } from 'node:module';
|
import { createRequire } from 'node:module';
|
||||||
import { homedir, hostname } from 'node:os';
|
import { homedir, hostname } from 'node:os';
|
||||||
import { join, dirname, resolve } from 'node:path';
|
import { join, dirname } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
buildResolvedFleetCommsBlock,
|
buildResolvedFleetCommsBlock,
|
||||||
@@ -29,7 +29,6 @@ import {
|
|||||||
import { readRegularFileSecure } from '../fleet/secure-file.js';
|
import { readRegularFileSecure } from '../fleet/secure-file.js';
|
||||||
import { readPersonaContractBlock } from '../fleet/persona-contract.js';
|
import { readPersonaContractBlock } from '../fleet/persona-contract.js';
|
||||||
import { canonicalizeRoleClass } from './fleet-personas.js';
|
import { canonicalizeRoleClass } from './fleet-personas.js';
|
||||||
import { resolveBrainHome } from '../fleet/brain-home.js';
|
|
||||||
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
|
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
|
||||||
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
|
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
|
||||||
|
|
||||||
@@ -65,46 +64,9 @@ const HARNESS_HOME_ENV: Record<RuntimeName, string> = {
|
|||||||
opencode: 'XDG_CONFIG_HOME',
|
opencode: 'XDG_CONFIG_HOME',
|
||||||
};
|
};
|
||||||
|
|
||||||
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime>.
|
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime> */
|
||||||
* With an active brain seat (MOSAIC_AGENT_NAME + seat dir in the brain home)
|
function harnessHome(runtime: RuntimeName): string {
|
||||||
* the home is per-agent instead: <brainHome>/fleet/agents/<seat>/.<runtime> —
|
return join(MOSAIC_HOME, `.${runtime}`);
|
||||||
* per-agent sessions, settings, and auth inside the seat dir (canon §2,
|
|
||||||
* MOSAIC-D-002). Seat runtime dirs are dot-named so the brain's ignore policy
|
|
||||||
* (per-seat .pi/.claude/.codex dirs) keeps credential material untracked. */
|
|
||||||
const SEAT_AGENT_NAME_RE = /^[a-zA-Z0-9][a-zA-Z0-9._-]*$/;
|
|
||||||
|
|
||||||
export function activeSeatDir(mosaicHome: string = MOSAIC_HOME): string | undefined {
|
|
||||||
const agent = process.env['MOSAIC_AGENT_NAME']?.trim();
|
|
||||||
if (
|
|
||||||
agent === undefined ||
|
|
||||||
agent === '' ||
|
|
||||||
!SEAT_AGENT_NAME_RE.test(agent) ||
|
|
||||||
agent.includes('..')
|
|
||||||
) {
|
|
||||||
return undefined;
|
|
||||||
}
|
|
||||||
const brain = resolveBrainHome(mosaicHome);
|
|
||||||
if (resolve(brain) === resolve(mosaicHome)) return undefined; // no brain
|
|
||||||
const seat = join(brain, 'fleet', 'agents', agent);
|
|
||||||
return existsSync(seat) ? seat : undefined;
|
|
||||||
}
|
|
||||||
|
|
||||||
function harnessHome(runtime: RuntimeName, mosaicHome: string = MOSAIC_HOME): string {
|
|
||||||
const seat = activeSeatDir(mosaicHome);
|
|
||||||
if (seat !== undefined) return join(seat, `.${runtime}`);
|
|
||||||
return join(mosaicHome, `.${runtime}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
/** Seat persona block: with an active brain seat, <seat>/SOUL.md layers
|
|
||||||
* persona on the root generic base (canon invariant; MOSAIC-D-002). The base
|
|
||||||
* SOUL stays load-on-demand — only the seat delta is injected by value.
|
|
||||||
* Empty string when no seat is active or the seat carries no SOUL.md. */
|
|
||||||
export function seatPersonaOverlay(mosaicHome: string = MOSAIC_HOME): string {
|
|
||||||
const seatDir = activeSeatDir(mosaicHome);
|
|
||||||
if (seatDir === undefined) return '';
|
|
||||||
const seatSoul = readOptional(join(seatDir, 'SOUL.md'));
|
|
||||||
if (!seatSoul.trim()) return '';
|
|
||||||
return '## Seat Persona\n\n' + seatSoul.trim();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -220,8 +182,6 @@ function recordLaunch(runtime: RuntimeName, cliArgs: string[], yolo: boolean): v
|
|||||||
cli_version: CLI_VERSION,
|
cli_version: CLI_VERSION,
|
||||||
config_home: harnessHome(runtime),
|
config_home: harnessHome(runtime),
|
||||||
config_home_isolated: true,
|
config_home_isolated: true,
|
||||||
config_home_kind: activeSeatDir() !== undefined ? 'seat' : 'runtime-shared',
|
|
||||||
agent_name: process.env['MOSAIC_AGENT_NAME']?.trim() || null,
|
|
||||||
config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
|
config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
|
||||||
argv: redactArgv(cliArgs),
|
argv: redactArgv(cliArgs),
|
||||||
normative_fragments: normativeFragmentDigests(runtime),
|
normative_fragments: normativeFragmentDigests(runtime),
|
||||||
@@ -609,11 +569,6 @@ For required push/merge/issue-close/release actions, execute without routine con
|
|||||||
if (soulLocal.trim()) {
|
if (soulLocal.trim()) {
|
||||||
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
|
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
|
||||||
}
|
}
|
||||||
// Seat persona (MOSAIC-D-002): per-seat SOUL.md layers on the generic base.
|
|
||||||
const seatPersona = seatPersonaOverlay(mosaicHome);
|
|
||||||
if (seatPersona !== '') {
|
|
||||||
overlayBlocks.push(seatPersona);
|
|
||||||
}
|
|
||||||
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
|
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
|
||||||
if (standardsLocal.trim()) {
|
if (standardsLocal.trim()) {
|
||||||
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
|
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
|
||||||
|
|||||||
@@ -1,114 +0,0 @@
|
|||||||
import { mkdir, mkdtemp, rm } from 'node:fs/promises';
|
|
||||||
import { homedir, tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
|
||||||
import {
|
|
||||||
brainHomeIsActive,
|
|
||||||
fleetAgentEnvDir,
|
|
||||||
fleetProfilesDir,
|
|
||||||
fleetRolesLocalDir,
|
|
||||||
fleetStateDir,
|
|
||||||
resolveBrainHome,
|
|
||||||
type BrainHomeOptions,
|
|
||||||
} from './brain-home.js';
|
|
||||||
|
|
||||||
describe('fleet brain-home resolution', (): void => {
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
|
|
||||||
const savedBrainEnv = process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
|
|
||||||
beforeEach((): void => {
|
|
||||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
});
|
|
||||||
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (savedBrainEnv === undefined) {
|
|
||||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
} else {
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainEnv;
|
|
||||||
}
|
|
||||||
if (cleanup !== undefined) {
|
|
||||||
await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
async function makeTmp(): Promise<string> {
|
|
||||||
const root = await mkdtemp(join(tmpdir(), 'mosaic-brain-home-'));
|
|
||||||
cleanup = root;
|
|
||||||
return root;
|
|
||||||
}
|
|
||||||
|
|
||||||
it('MOSAIC_BRAIN_HOME env wins over every other signal', (): void => {
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = '/explicit/brain';
|
|
||||||
expect(resolveBrainHome('/any/mosaic-home')).toBe('/explicit/brain');
|
|
||||||
expect(fleetAgentEnvDir('/any/mosaic-home')).toBe('/explicit/brain/fleet/agents');
|
|
||||||
expect(brainHomeIsActive('/any/mosaic-home')).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('injected envBrainHome wins identically (test seam)', (): void => {
|
|
||||||
const opts: BrainHomeOptions = { envBrainHome: '/injected/brain' };
|
|
||||||
expect(resolveBrainHome('/any/mosaic-home', opts)).toBe('/injected/brain');
|
|
||||||
expect(fleetAgentEnvDir('/any/mosaic-home', opts)).toBe('/injected/brain/fleet/agents');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('a non-default mosaicHome never adopts the canonical brain (hermetic legacy)', (): void => {
|
|
||||||
const mosaicHome = '/tmp/not-the-default-config-home';
|
|
||||||
expect(resolveBrainHome(mosaicHome)).toBe(mosaicHome);
|
|
||||||
expect(brainHomeIsActive(mosaicHome)).toBe(false);
|
|
||||||
expect(fleetAgentEnvDir(mosaicHome)).toBe(join(mosaicHome, 'fleet', 'agents'));
|
|
||||||
});
|
|
||||||
|
|
||||||
it('the default config home adopts the brain when it carries fleet/agents', async (): Promise<void> => {
|
|
||||||
const root = await makeTmp();
|
|
||||||
const brain = join(root, 'brain');
|
|
||||||
await mkdir(join(brain, 'fleet', 'agents'), { recursive: true });
|
|
||||||
const configHome = join(root, 'config', 'mosaic');
|
|
||||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
|
||||||
|
|
||||||
expect(resolveBrainHome(configHome, opts)).toBe(brain);
|
|
||||||
expect(fleetAgentEnvDir(configHome, opts)).toBe(join(brain, 'fleet', 'agents'));
|
|
||||||
expect(fleetRolesLocalDir(configHome, opts)).toBe(join(brain, 'fleet', 'roles.local'));
|
|
||||||
expect(fleetProfilesDir(configHome, opts)).toBe(join(brain, 'fleet', 'profiles'));
|
|
||||||
expect(fleetStateDir(configHome, opts)).toBe(join(brain, 'fleet'));
|
|
||||||
expect(brainHomeIsActive(configHome, opts)).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('the default config home stays legacy when no brain exists', async (): Promise<void> => {
|
|
||||||
const root = await makeTmp();
|
|
||||||
const configHome = join(root, 'config', 'mosaic');
|
|
||||||
const opts: BrainHomeOptions = {
|
|
||||||
homes: { brain: join(root, 'brain'), configDefault: configHome },
|
|
||||||
};
|
|
||||||
|
|
||||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
|
||||||
expect(brainHomeIsActive(configHome, opts)).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('an empty MOSAIC_BRAIN_HOME is ignored, not treated as set', (): void => {
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = ' ';
|
|
||||||
expect(resolveBrainHome('/tmp/legacy-home')).toBe('/tmp/legacy-home');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('adoption requires fleet/agents specifically, not any brain content', async (): Promise<void> => {
|
|
||||||
const root = await makeTmp();
|
|
||||||
const brain = join(root, 'brain');
|
|
||||||
await mkdir(join(brain, 'fleet'), { recursive: true }); // fleet without agents
|
|
||||||
const configHome = join(root, 'config', 'mosaic');
|
|
||||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
|
||||||
|
|
||||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('real-home control: a host brain is adopted only through the default home', (): void => {
|
|
||||||
// Control on the un-injected path: this host carries ~/.mosaic/fleet/agents,
|
|
||||||
// so the default config home resolves to the brain or legacy — both valid
|
|
||||||
// canonical endpoints — while a non-default home never adopts.
|
|
||||||
const defaultHome = join(homedir(), '.config', 'mosaic');
|
|
||||||
const resolved = resolveBrainHome(defaultHome);
|
|
||||||
expect([defaultHome, join(homedir(), '.mosaic')]).toContain(resolved);
|
|
||||||
expect(resolveBrainHome(join(homedir(), 'elsewhere', 'mosaic'))).toBe(
|
|
||||||
join(homedir(), 'elsewhere', 'mosaic'),
|
|
||||||
);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
import { existsSync } from 'node:fs';
|
|
||||||
import { homedir } from 'node:os';
|
|
||||||
import { join, resolve } from 'node:path';
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Overridable resolution inputs (tests inject tmp homes; production reads
|
|
||||||
* the environment and the real home directory).
|
|
||||||
*/
|
|
||||||
export interface BrainHomeOptions {
|
|
||||||
/** Explicit brain home; defaults to `MOSAIC_BRAIN_HOME`. */
|
|
||||||
readonly envBrainHome?: string;
|
|
||||||
/**
|
|
||||||
* Canonical homes used for adoption. Defaults derive from the real
|
|
||||||
* `homedir()`: `{ brain: ~/.mosaic, configDefault: ~/.config/mosaic }`.
|
|
||||||
*/
|
|
||||||
readonly homes?: { readonly brain: string; readonly configDefault: string };
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Brain-home resolution — the three-tree fleet split (stack canon
|
|
||||||
* `docs/STRUCTURE-CANON.md` §2, first carried by the USC estate brain):
|
|
||||||
*
|
|
||||||
* config home (~/.config/mosaic) framework templates + dispatch state:
|
|
||||||
* fleet/roles (baseline), fleet/roster.yaml,
|
|
||||||
* fleet/run (heartbeats), fleet/services
|
|
||||||
* brain home (~/.mosaic) user-owned fleet state, committed:
|
|
||||||
* fleet/agents/<seat>.env.*, fleet/roles.local,
|
|
||||||
* fleet/profiles working copies
|
|
||||||
*
|
|
||||||
* Resolution order:
|
|
||||||
* 1. `MOSAIC_BRAIN_HOME` env (explicit, always wins)
|
|
||||||
* 2. canonical `~/.mosaic` — adopted ONLY when mosaicHome is the real
|
|
||||||
* default config home AND `~/.mosaic/fleet/agents` exists. Custom
|
|
||||||
* `--mosaic-home` values (tests, sandboxes, canaries) never trigger
|
|
||||||
* adoption, keeping them hermetic and deterministic.
|
|
||||||
* 3. mosaicHome itself (legacy single-tree behavior).
|
|
||||||
*/
|
|
||||||
export function resolveBrainHome(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
|
||||||
const explicit = options.envBrainHome ?? process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
if (explicit !== undefined && explicit.trim() !== '') {
|
|
||||||
return explicit;
|
|
||||||
}
|
|
||||||
const homes = options.homes ?? {
|
|
||||||
brain: join(homedir(), '.mosaic'),
|
|
||||||
configDefault: join(homedir(), '.config', 'mosaic'),
|
|
||||||
};
|
|
||||||
if (resolve(mosaicHome) !== resolve(homes.configDefault)) {
|
|
||||||
return mosaicHome;
|
|
||||||
}
|
|
||||||
return existsSync(join(homes.brain, 'fleet', 'agents')) ? homes.brain : mosaicHome;
|
|
||||||
}
|
|
||||||
|
|
||||||
/** True when fleet state resolves somewhere other than the config home. */
|
|
||||||
export function brainHomeIsActive(mosaicHome: string, options: BrainHomeOptions = {}): boolean {
|
|
||||||
return resolve(resolveBrainHome(mosaicHome, options)) !== resolve(mosaicHome);
|
|
||||||
}
|
|
||||||
|
|
||||||
/** Fleet state root (brain home when active, else the config home). */
|
|
||||||
export function fleetStateDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
|
||||||
return join(resolveBrainHome(mosaicHome, options), 'fleet');
|
|
||||||
}
|
|
||||||
|
|
||||||
/** Seat launch envs — `<brainHome>/fleet/agents` when a brain is active. */
|
|
||||||
export function fleetAgentEnvDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
|
||||||
return join(fleetStateDir(mosaicHome, options), 'agents');
|
|
||||||
}
|
|
||||||
|
|
||||||
/** PRESERVE-protected persona override layer — `<brainHome>/fleet/roles.local`. */
|
|
||||||
export function fleetRolesLocalDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
|
||||||
return join(fleetStateDir(mosaicHome, options), 'roles.local');
|
|
||||||
}
|
|
||||||
|
|
||||||
/** System-type profiles (user working copies) — `<brainHome>/fleet/profiles`. */
|
|
||||||
export function fleetProfilesDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
|
||||||
return join(fleetStateDir(mosaicHome, options), 'profiles');
|
|
||||||
}
|
|
||||||
@@ -3,7 +3,6 @@ import { lstat, open, readFile, unlink, type FileHandle } from 'node:fs/promises
|
|||||||
import { randomUUID } from 'node:crypto';
|
import { randomUUID } from 'node:crypto';
|
||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { join } from 'node:path';
|
import { join } from 'node:path';
|
||||||
import { fleetAgentEnvDir } from './brain-home.js';
|
|
||||||
import {
|
import {
|
||||||
applyPreparedAgentEnvironmentProjection,
|
applyPreparedAgentEnvironmentProjection,
|
||||||
prepareAgentEnvironmentProjection,
|
prepareAgentEnvironmentProjection,
|
||||||
@@ -618,7 +617,7 @@ function defaultPrepareProjections(
|
|||||||
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
||||||
prepareAgentEnvironmentProjection({
|
prepareAgentEnvironmentProjection({
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||||
agentName: agent.name,
|
agentName: agent.name,
|
||||||
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -176,52 +176,6 @@ describe('generated fleet agent environment boundary', (): void => {
|
|||||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||||
});
|
});
|
||||||
|
|
||||||
it('brain home: accepts and writes projections under MOSAIC_BRAIN_HOME/fleet/agents', async (): Promise<void> => {
|
|
||||||
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
try {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
|
||||||
const mosaicHome = join(cleanup, 'config-home');
|
|
||||||
const brainHome = join(cleanup, 'brain');
|
|
||||||
const agentEnvDir = join(brainHome, 'fleet', 'agents');
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = brainHome;
|
|
||||||
|
|
||||||
const result = await writeAgentEnvironmentProjection({
|
|
||||||
mosaicHome,
|
|
||||||
agentEnvDir,
|
|
||||||
agentName: 'coder0',
|
|
||||||
generated: generatedValues,
|
|
||||||
});
|
|
||||||
|
|
||||||
// Projection landed in the brain tree, not under the config home.
|
|
||||||
expect(result.generatedPath).toBe(join(agentEnvDir, 'coder0.env.generated'));
|
|
||||||
expect((await stat(join(brainHome, 'fleet'))).mode & 0o777).toBe(0o700);
|
|
||||||
expect((await stat(agentEnvDir)).mode & 0o777).toBe(0o700);
|
|
||||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
|
||||||
await expect(stat(join(mosaicHome, 'fleet'))).rejects.toThrow();
|
|
||||||
|
|
||||||
// A config-home agentEnvDir is now REJECTED while the brain is active —
|
|
||||||
// the boundary must not silently split state across two trees.
|
|
||||||
let rejected: unknown;
|
|
||||||
try {
|
|
||||||
await writeAgentEnvironmentProjection({
|
|
||||||
mosaicHome,
|
|
||||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
|
||||||
agentName: 'coder1',
|
|
||||||
generated: { ...generatedValues, MOSAIC_AGENT_NAME: 'coder1' },
|
|
||||||
});
|
|
||||||
} catch (caught: unknown) {
|
|
||||||
rejected = caught;
|
|
||||||
}
|
|
||||||
expect(rejected).toBeInstanceOf(AgentEnvBoundaryError);
|
|
||||||
} finally {
|
|
||||||
if (savedBrainHome === undefined) {
|
|
||||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
|
||||||
} else {
|
|
||||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||||
const mosaicHome = join(cleanup, 'mosaic');
|
const mosaicHome = join(cleanup, 'mosaic');
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ import { createHash, randomUUID } from 'node:crypto';
|
|||||||
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { dirname, join, resolve } from 'node:path';
|
import { dirname, join, resolve } from 'node:path';
|
||||||
import { fleetAgentEnvDir, resolveBrainHome } from './brain-home.js';
|
|
||||||
import { compareCodePoints } from './deterministic-order.js';
|
import { compareCodePoints } from './deterministic-order.js';
|
||||||
|
|
||||||
export type AgentEnvironmentKind = 'generated' | 'local';
|
export type AgentEnvironmentKind = 'generated' | 'local';
|
||||||
@@ -529,15 +528,12 @@ async function validatePrivateProjectionDirectory(
|
|||||||
mosaicHome: string,
|
mosaicHome: string,
|
||||||
agentEnvDir: string,
|
agentEnvDir: string,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
// Brain-home split (canon §2): seat envs live under the brain home's
|
const fleetDir = join(mosaicHome, 'fleet');
|
||||||
// fleet/agents when a brain is active; roster + templates stay config-home.
|
const expectedAgentEnvDir = join(fleetDir, 'agents');
|
||||||
const expectedAgentEnvDir = fleetAgentEnvDir(mosaicHome);
|
|
||||||
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
||||||
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
||||||
}
|
}
|
||||||
const stateHome = resolveBrainHome(mosaicHome);
|
await assertManagedDirectoryIfPresent(mosaicHome, false);
|
||||||
const fleetDir = join(stateHome, 'fleet');
|
|
||||||
await assertManagedDirectoryIfPresent(stateHome, false);
|
|
||||||
await assertManagedDirectoryIfPresent(fleetDir, false);
|
await assertManagedDirectoryIfPresent(fleetDir, false);
|
||||||
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
||||||
}
|
}
|
||||||
@@ -547,9 +543,8 @@ async function ensurePrivateProjectionDirectory(
|
|||||||
agentEnvDir: string,
|
agentEnvDir: string,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
||||||
const stateHome = resolveBrainHome(mosaicHome);
|
const fleetDir = join(mosaicHome, 'fleet');
|
||||||
const fleetDir = join(stateHome, 'fleet');
|
await ensureManagedDirectory(mosaicHome, false);
|
||||||
await ensureManagedDirectory(stateHome, false);
|
|
||||||
await ensureManagedDirectory(fleetDir, false);
|
await ensureManagedDirectory(fleetDir, false);
|
||||||
await ensureManagedDirectory(agentEnvDir, true);
|
await ensureManagedDirectory(agentEnvDir, true);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,45 +0,0 @@
|
|||||||
# RI-1-002 — Publish-gate negative controls (SDLC-D-034 second half)
|
|
||||||
|
|
||||||
- Task: RI-1-002 (docs/release-integrity workstream, PRD item RI-N1), issue ref #1275
|
|
||||||
- Branch: `test/ri-050-publish-gate-negative` (base `origin/next` @ d8e0aec9 = PR #1277, RI-1-001)
|
|
||||||
- Budget: worker estimate ~45K tokens; keep scoped to the two test files + scratchpad.
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Checked-in negative-control tests that PROVE the publish gate fails when it must:
|
|
||||||
|
|
||||||
1. Broken mandatory check blocks every publish step (structural DAG proof from `.woodpecker/publish.yml`).
|
|
||||||
2. Bypass shapes fail the checker: missing edge, hidden effect (non-`publish` name), detached verify, always-pass verify (`failure: ignore` / `success` override), conditional verify (`when`).
|
|
||||||
3. Exact-commit identity: no HEAD-moving step between verify and publish effects; legitimate re-checkout requires verify to re-run after it.
|
|
||||||
4. `verify-release.mjs` composition control: a SUBSET stage list fails the composition check.
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
- NEW `scripts/publish-gate-structure.test.mjs` — self-contained structural checker (`assertPublishGateBlocksOnVerify`) + positive control on the real pipeline + one negative-control test per bypass shape (S1–S6, documented in file header) + positive control for the legitimate re-checkout shape.
|
|
||||||
- EXTEND `scripts/verify-release.test.mjs` — refactor the stage-mirror test body into `assertStagesMirrorCi(stages, ci)`; add negative control dropping each stage one at a time (subset must throw).
|
|
||||||
|
|
||||||
## Conventions confirmed
|
|
||||||
|
|
||||||
- Root `test:checkout` = `node --test scripts/*.test.mjs` → new file auto-joins `pnpm test`.
|
|
||||||
- Test-enumeration guard population is `*test*.sh` under `packages/mosaic/framework/tools/` only → unaffected.
|
|
||||||
- Root eslint covers only `**/*.{ts,tsx}` → .mjs files need Prettier style only (printWidth 100, singleQuote, semi, trailingComma all).
|
|
||||||
- Do NOT touch docs/TASKS.md, docs/release-integrity/TASKS.md, docs/scratchpads/.
|
|
||||||
|
|
||||||
## Progress log
|
|
||||||
|
|
||||||
- [x] Base verified: publish.yml `verify` step + verify-release.mjs present; HEAD contains origin/next.
|
|
||||||
- [x] Wrote scripts/publish-gate-structure.test.mjs
|
|
||||||
- [x] Extended scripts/verify-release.test.mjs (mirror fn + subset negative control)
|
|
||||||
- [x] Gates: node --test scripts (31 tests pass), prettier clean on touched files, pnpm typecheck PASS, pnpm lint PASS, pnpm format:check PASS
|
|
||||||
- [x] Committed ff585b88 + pushed, PR #1305 → next (no conflicts). Stopped before merge per task instruction.
|
|
||||||
|
|
||||||
## Evidence
|
|
||||||
|
|
||||||
- `node --test scripts/verify-release.test.mjs scripts/publish-gate-structure.test.mjs` → 31 tests, 0 fail.
|
|
||||||
- Mutation sanity: temporarily removing the `verify` edge from build-gateway in publish.yml → structure test goes red (verified manually during dev, then reverted).
|
|
||||||
- Gates run from repo root on this worktree; results in Progress log.
|
|
||||||
|
|
||||||
## Risks / notes
|
|
||||||
|
|
||||||
- Effect detection (`isPublishCommand`) is deliberately over-broad (any npm/pnpm/yarn command mentioning `publish`, any kaniko/docker-push/`--destination`) — fail-closed: a false positive forces justification, a false negative is the actual hazard.
|
|
||||||
- `git fetch` flagged as HEAD-moving even though fetch alone doesn't move HEAD — fail-closed on the classic `fetch && reset` pair.
|
|
||||||
@@ -1,310 +0,0 @@
|
|||||||
import assert from 'node:assert/strict';
|
|
||||||
import { readFile } from 'node:fs/promises';
|
|
||||||
import { createRequire } from 'node:module';
|
|
||||||
import path from 'node:path';
|
|
||||||
import test from 'node:test';
|
|
||||||
|
|
||||||
// RI-1-002 / RI-N1 publish-gate NEGATIVE CONTROLS (SDLC-D-034).
|
|
||||||
//
|
|
||||||
// scripts/verify-release.test.mjs pins the POSITIVE structure of the publish
|
|
||||||
// gate: every publish effect declares a direct `depends_on: verify` edge and
|
|
||||||
// the verify step asserts commit identity + runs the canonical command. This
|
|
||||||
// suite is the negative-control set: each test feeds a structural gate
|
|
||||||
// checker a pipeline in which the gate is bypassed by ONE specific shape and
|
|
||||||
// asserts the checker goes RED. The controls prove from the pipeline FILE —
|
|
||||||
// never by executing Woodpecker — that a verify step that FAILS (nonzero
|
|
||||||
// exit) blocks every publish effect.
|
|
||||||
//
|
|
||||||
// Woodpecker semantics these controls rely on:
|
|
||||||
// - A step that exits nonzero FAILS, and every step that transitively
|
|
||||||
// depends on a failed step is SKIPPED — never run. That skip is the only
|
|
||||||
// thing standing between a failed mandatory check and a publish effect.
|
|
||||||
// - `detach: true` removes the step from the wait graph: the pipeline does
|
|
||||||
// not wait for detached steps, so their failure can never block anything.
|
|
||||||
// - `failure: ignore` reports a failed step as success to the DAG.
|
|
||||||
// - `success: [codes...]` overrides which exit codes count as success;
|
|
||||||
// admitting any nonzero code launders a failed verification into green.
|
|
||||||
// - `when` on the verify step would skip verification entirely on some
|
|
||||||
// event/path classes while publish effects still run.
|
|
||||||
//
|
|
||||||
// Bypass shapes covered (one negative-control test each):
|
|
||||||
// S1 Missing edge — a publish effect whose dependency closure does not
|
|
||||||
// contain `verify` (a refactor drops the depends_on entry).
|
|
||||||
// S2 Hidden effect — a step whose NAME does not start with `publish` but
|
|
||||||
// whose COMMANDS publish npm packages or push images. Effects are
|
|
||||||
// classified by commands, so renaming a step cannot un-gate it.
|
|
||||||
// S3 Detached verify — `verify: { detach: true }`: publish steps no longer
|
|
||||||
// wait for verify, so the depends_on edge is decorative.
|
|
||||||
// S4 Always-pass verify — `failure: ignore`, or a `success` override
|
|
||||||
// admitting nonzero exit codes: verify fails, the DAG sees success.
|
|
||||||
// S5 Conditional verify — a `when`/path filter on verify itself.
|
|
||||||
// S6 Exact-commit drift — a HEAD-moving step (git checkout/switch/reset/
|
|
||||||
// clean/pull/clone/fetch) ordered between `verify` and a publish
|
|
||||||
// effect: the verified commit would not be the published commit. A
|
|
||||||
// LEGITIMATE re-checkout is allowed only when `verify` itself runs
|
|
||||||
// after it — positive control included.
|
|
||||||
// S7 Gate removal — the verify step deleted or renamed away entirely.
|
|
||||||
|
|
||||||
// Reuse the monorepo's existing YAML parser (@mosaicstack/mosaic's direct
|
|
||||||
// dependency) instead of adding a root dependency or vendoring a parser.
|
|
||||||
const mosaicRequire = createRequire(
|
|
||||||
path.resolve(process.cwd(), 'packages', 'mosaic', 'package.json'),
|
|
||||||
);
|
|
||||||
const { parse: parseYaml } = mosaicRequire('yaml');
|
|
||||||
|
|
||||||
const publishYmlPath = path.join(process.cwd(), '.woodpecker', 'publish.yml');
|
|
||||||
|
|
||||||
async function readPublishPipeline() {
|
|
||||||
return parseYaml(await readFile(publishYmlPath, 'utf8'));
|
|
||||||
}
|
|
||||||
|
|
||||||
// A command has a publish EFFECT when it publishes npm packages (`publish`
|
|
||||||
// anywhere after a package-manager token — `pnpm --filter "@x/*" publish`
|
|
||||||
// puts flags and quoted filters between the binary and the subcommand) or
|
|
||||||
// pushes an image (kaniko, docker push, or a registry --destination).
|
|
||||||
// Deliberately over-broad: a false positive forces justification, a false
|
|
||||||
// negative is the actual hazard.
|
|
||||||
function isPublishCommand(command) {
|
|
||||||
return (
|
|
||||||
/(^|\s)\/kaniko\/executor\b/.test(command) ||
|
|
||||||
/(^|\s)docker\s+push\b/.test(command) ||
|
|
||||||
/(^|\s)--destination(\s|=)/.test(command) ||
|
|
||||||
(/\bpublish\b/.test(command) && /(^|\s)(npm|pnpm|yarn)(\s|$)/.test(command))
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function hasPublishEffect(step) {
|
|
||||||
return (step.commands ?? []).some(isPublishCommand);
|
|
||||||
}
|
|
||||||
|
|
||||||
// A step is a publish effect when its name says so OR (S2) when any of its
|
|
||||||
// commands does — classification must not depend on the name alone.
|
|
||||||
function publishEffectSteps(pipeline) {
|
|
||||||
return Object.entries(pipeline.steps ?? {})
|
|
||||||
.filter(([name, step]) => name.startsWith('publish') || hasPublishEffect(step))
|
|
||||||
.map(([name]) => name);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Transitive closure of a step's depends_on graph.
|
|
||||||
function dependencyClosure(pipeline, stepName, seen = new Set()) {
|
|
||||||
const dependencies = pipeline.steps?.[stepName]?.depends_on ?? [];
|
|
||||||
for (const dependency of dependencies) {
|
|
||||||
if (seen.has(dependency)) continue;
|
|
||||||
seen.add(dependency);
|
|
||||||
dependencyClosure(pipeline, dependency, seen);
|
|
||||||
}
|
|
||||||
return seen;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Deliberately over-broad: `git fetch` alone does not move HEAD, but the
|
|
||||||
// classic re-checkout pair is `git fetch && git reset --hard <remote>`; a
|
|
||||||
// fetch step sitting between verify and a publish effect deserves scrutiny,
|
|
||||||
// so the gate fails closed on it.
|
|
||||||
function movesHead(step) {
|
|
||||||
return (step.commands ?? []).some((command) =>
|
|
||||||
/(^|\s)git\s+(checkout|switch|reset|clean|pull|clone|fetch)\b/.test(command),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// The structural gate checker: green only when a failed (nonzero-exit)
|
|
||||||
// verify provably blocks every publish effect on the same commit.
|
|
||||||
function assertPublishGateBlocksOnVerify(pipeline) {
|
|
||||||
assert.ok(pipeline.steps, 'publish pipeline must define steps');
|
|
||||||
const verify = pipeline.steps.verify;
|
|
||||||
assert.ok(verify, 'publish pipeline must define a `verify` step (S7)');
|
|
||||||
|
|
||||||
// S5: a skipped verification authorizes publishes exactly as much as a
|
|
||||||
// failed one — verify must be unconditional.
|
|
||||||
assert.equal(verify.when, undefined, '`verify` must not carry a when/path filter (S5)');
|
|
||||||
|
|
||||||
// S3/S4: the depends_on edges are only meaningful if verify's own failure
|
|
||||||
// is both awaited and terminal for the DAG.
|
|
||||||
assert.equal(verify.detach, undefined, '`verify` must not be detached (S3)');
|
|
||||||
assert.equal(
|
|
||||||
verify.failure,
|
|
||||||
undefined,
|
|
||||||
'`verify` must not tolerate its own failure (S4: failure: ignore launders a failed gate into success)',
|
|
||||||
);
|
|
||||||
assert.equal(
|
|
||||||
verify.success,
|
|
||||||
undefined,
|
|
||||||
'`verify` must not override success exit codes (S4: nonzero codes would make failed verification pass)',
|
|
||||||
);
|
|
||||||
|
|
||||||
const effects = publishEffectSteps(pipeline);
|
|
||||||
assert.ok(effects.length > 0, 'publish pipeline must contain publish effect steps to guard');
|
|
||||||
|
|
||||||
const verifyClosure = dependencyClosure(pipeline, 'verify');
|
|
||||||
for (const stepName of effects) {
|
|
||||||
// S1: only the failure-skip semantics of the DAG stand between a failed
|
|
||||||
// verify and this effect — the verify edge in its closure is the proof.
|
|
||||||
const closure = dependencyClosure(pipeline, stepName);
|
|
||||||
assert.ok(
|
|
||||||
closure.has('verify'),
|
|
||||||
`publish effect '${stepName}' must transitively depend on verify (S1) — a failed verify must skip it`,
|
|
||||||
);
|
|
||||||
|
|
||||||
// S6: any step ordered after verify (outside its closure) but inside the
|
|
||||||
// effect's chain must not be able to move HEAD. If the pipeline
|
|
||||||
// legitimately re-checks-out, verify must run after the re-checkout.
|
|
||||||
for (const chainStep of closure) {
|
|
||||||
if (chainStep === 'verify' || verifyClosure.has(chainStep)) continue;
|
|
||||||
assert.ok(
|
|
||||||
!movesHead(pipeline.steps[chainStep]),
|
|
||||||
`step '${chainStep}' sits between verify and publish effect '${stepName}' and can move HEAD (S6)` +
|
|
||||||
' — verify must re-run after any re-checkout',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return effects;
|
|
||||||
}
|
|
||||||
|
|
||||||
// A minimal but healthy gate used as the base for every negative-control
|
|
||||||
// mutation: verify (identity + canonical command) → build → publish-npm,
|
|
||||||
// with the publish effect blocked by verify both directly and through build.
|
|
||||||
const HEALTHY_GATE_YAML = `
|
|
||||||
steps:
|
|
||||||
verify:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- |
|
|
||||||
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
|
|
||||||
echo "identity mismatch" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- pnpm verify:release
|
|
||||||
build:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm build
|
|
||||||
depends_on:
|
|
||||||
- verify
|
|
||||||
publish-npm:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- npm publish
|
|
||||||
depends_on:
|
|
||||||
- build
|
|
||||||
- verify
|
|
||||||
`;
|
|
||||||
|
|
||||||
// Fresh parse per call so every negative control mutates its own object.
|
|
||||||
function healthyPipeline() {
|
|
||||||
return parseYaml(HEALTHY_GATE_YAML);
|
|
||||||
}
|
|
||||||
|
|
||||||
test('the real publish pipeline: a failed verify provably blocks every publish effect', async () => {
|
|
||||||
const pipeline = await readPublishPipeline();
|
|
||||||
const effects = assertPublishGateBlocksOnVerify(pipeline);
|
|
||||||
assert.deepEqual(effects.sort(), [
|
|
||||||
'build-appservice',
|
|
||||||
'build-gateway',
|
|
||||||
'build-web',
|
|
||||||
'publish-next-npm',
|
|
||||||
'publish-npm',
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('fixture sanity: the healthy gate base passes the checker unmutated', () => {
|
|
||||||
assertPublishGateBlocksOnVerify(healthyPipeline());
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S1 negative control: a publish effect with no verify edge fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps['publish-npm'].depends_on = ['build'];
|
|
||||||
pipeline.steps.build.depends_on = [];
|
|
||||||
assert.throws(
|
|
||||||
() => assertPublishGateBlocksOnVerify(pipeline),
|
|
||||||
/publish-npm.*must transitively depend on verify/s,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S2 negative control: an npm publish hidden behind a non-publish step name fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
delete pipeline.steps['publish-npm'];
|
|
||||||
pipeline.steps.build.depends_on = [];
|
|
||||||
pipeline.steps.deploy = {
|
|
||||||
image: 'node:24-alpine',
|
|
||||||
commands: ['npm publish'],
|
|
||||||
depends_on: ['build'],
|
|
||||||
};
|
|
||||||
// Detection must be by COMMAND: the name says "deploy", the commands say
|
|
||||||
// publish — an un-gated effect under either reading.
|
|
||||||
assert.throws(
|
|
||||||
() => assertPublishGateBlocksOnVerify(pipeline),
|
|
||||||
/deploy.*must transitively depend on verify/s,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S2 negative control: a kaniko image push under a build-* name fails the checker when ungated', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
delete pipeline.steps['publish-npm'];
|
|
||||||
pipeline.steps.build.depends_on = [];
|
|
||||||
pipeline.steps['push-platform-image'] = {
|
|
||||||
image: 'gcr.io/kaniko-project/executor:debug',
|
|
||||||
commands: ['/kaniko/executor --context . --destination reg.example/img:latest'],
|
|
||||||
depends_on: ['build'],
|
|
||||||
};
|
|
||||||
assert.throws(
|
|
||||||
() => assertPublishGateBlocksOnVerify(pipeline),
|
|
||||||
/push-platform-image.*must transitively depend on verify/s,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S3 negative control: a detached verify fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.verify.detach = true;
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /detached \(S3\)/);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S4 negative control: failure: ignore on verify fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.verify.failure = 'ignore';
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /tolerate its own failure/);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S4 negative control: a success override admitting nonzero exit codes fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.verify.success = [0, 1];
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /success exit codes/);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S5 negative control: a when filter on verify fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.verify.when = [{ event: 'push' }];
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /when\/path filter \(S5\)/);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S6 negative control: a HEAD-moving step between verify and publish fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.resync = {
|
|
||||||
image: 'node:24-alpine',
|
|
||||||
commands: ['git fetch origin', 'git reset --hard origin/main'],
|
|
||||||
depends_on: [],
|
|
||||||
};
|
|
||||||
pipeline.steps.build.depends_on = ['verify', 'resync'];
|
|
||||||
// resync sits AFTER verify in the publish chain (verify does not depend on
|
|
||||||
// it), so the verified commit could be replaced before publishing.
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /resync.*can move HEAD/s);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S6 positive control: a legitimate re-checkout passes when verify re-runs after it', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
pipeline.steps.resync = {
|
|
||||||
image: 'node:24-alpine',
|
|
||||||
commands: ['git fetch origin', 'git reset --hard origin/main'],
|
|
||||||
depends_on: [],
|
|
||||||
};
|
|
||||||
pipeline.steps.verify.depends_on = ['resync'];
|
|
||||||
pipeline.steps.build.depends_on = ['verify'];
|
|
||||||
// resync precedes verify in the chain, so verification covers the
|
|
||||||
// re-checked-out HEAD — the exact-commit contract holds.
|
|
||||||
assertPublishGateBlocksOnVerify(pipeline);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('S7 negative control: deleting the verify step entirely fails the checker', () => {
|
|
||||||
const pipeline = healthyPipeline();
|
|
||||||
delete pipeline.steps.verify;
|
|
||||||
pipeline.steps['publish-npm'].depends_on = ['build'];
|
|
||||||
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /`verify` step/);
|
|
||||||
});
|
|
||||||
@@ -1,166 +0,0 @@
|
|||||||
#!/usr/bin/env node
|
|
||||||
// verify-release.mjs — the ONE canonical terminal verification command
|
|
||||||
// (SDLC-D-034, `pnpm verify:release`).
|
|
||||||
//
|
|
||||||
// Publication (.woodpecker/publish.yml `verify` step) is bound to terminal
|
|
||||||
// verification of the exact commit through this command, which is composed
|
|
||||||
// from the SAME commands the PR CI pipeline (.woodpecker/ci.yml) runs — CI and
|
|
||||||
// publish share one semantic checklist:
|
|
||||||
//
|
|
||||||
// stage | mirrors ci.yml step | commands
|
|
||||||
// --------------|---------------------|------------------------------------------
|
|
||||||
// sanitization | sanitization | verify-sanitized.sh, check-resident-
|
|
||||||
// | | budget.sh (--self-test + run),
|
|
||||||
// | | check-test-enumeration.sh
|
|
||||||
// upgrade-guard | upgrade-guard | test-upgrade-manifest-guard.sh,
|
|
||||||
// | | test-upgrade-rollback.sh,
|
|
||||||
// | | test-upgrade-durable-snapshot.sh,
|
|
||||||
// | | test-install-migration.sh
|
|
||||||
// typecheck | typecheck | pnpm typecheck (runs the checkout
|
|
||||||
// | | preflight, then turbo typecheck)
|
|
||||||
// lint | lint | pnpm lint
|
|
||||||
// format | format | pnpm format:check
|
|
||||||
// test | test | pnpm test
|
|
||||||
// build | publish.yml build | pnpm build
|
|
||||||
//
|
|
||||||
// Caller-provided prerequisites (kept at the pipeline level — see the comments
|
|
||||||
// in .woodpecker/ci.yml): `bash` + `rsync` for the guard stages, `openssl` and
|
|
||||||
// the pinned @earendil-works/pi-coding-agent for the test stage, and — on the
|
|
||||||
// postgres path only — the ci-postgres service plus
|
|
||||||
// `pnpm --filter @mosaicstack/db run db:migrate` before the test stage.
|
|
||||||
//
|
|
||||||
// This command works with DATABASE_URL set (CI postgres path) or unset (local
|
|
||||||
// PGlite path); it never sets, exports, or requires a database itself.
|
|
||||||
//
|
|
||||||
// scripts/verify-release.test.mjs enforces that this stage table keeps
|
|
||||||
// matching .woodpecker/ci.yml step-for-step, so the two surfaces cannot drift
|
|
||||||
// apart silently.
|
|
||||||
|
|
||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import path from 'node:path';
|
|
||||||
import { fileURLToPath } from 'node:url';
|
|
||||||
|
|
||||||
export const STAGES = [
|
|
||||||
{
|
|
||||||
name: 'sanitization',
|
|
||||||
// Mirror of the .woodpecker/ci.yml `sanitization` step (minus its
|
|
||||||
// `apk add` environment prep). Kept as direct command strings here: the
|
|
||||||
// #1017 test-enumeration guard audits these paths through the ci.yml
|
|
||||||
// surface, so indirection from ci.yml into this file is not possible.
|
|
||||||
commands: [
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/verify-sanitized.sh',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh --self-test',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh',
|
|
||||||
],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: 'upgrade-guard',
|
|
||||||
// Mirror of the .woodpecker/ci.yml `upgrade-guard` step (minus its
|
|
||||||
// `apk add` environment prep).
|
|
||||||
commands: [
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-manifest-guard.sh',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh',
|
|
||||||
'bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh',
|
|
||||||
],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
// `pnpm typecheck` is `pnpm preflight && turbo run typecheck`, so the
|
|
||||||
// checkout preflight (scripts/preflight.mjs) is part of this stage exactly
|
|
||||||
// as it is part of the ci.yml `typecheck` step.
|
|
||||||
name: 'typecheck',
|
|
||||||
commands: ['pnpm typecheck'],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: 'lint',
|
|
||||||
commands: ['pnpm lint'],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: 'format',
|
|
||||||
commands: ['pnpm format:check'],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
// Requires `openssl` and the pinned `pi` binary on the pipeline path; see
|
|
||||||
// the caller-provided prerequisites above.
|
|
||||||
name: 'test',
|
|
||||||
commands: ['pnpm test'],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: 'build',
|
|
||||||
commands: ['pnpm build'],
|
|
||||||
},
|
|
||||||
];
|
|
||||||
|
|
||||||
export function stageByName(name) {
|
|
||||||
return STAGES.find((stage) => stage.name === name);
|
|
||||||
}
|
|
||||||
|
|
||||||
function missingBinaries(bins) {
|
|
||||||
return bins.filter(
|
|
||||||
(bin) => spawnSync('sh', ['-c', `command -v ${bin} >/dev/null 2>&1`]).status !== 0,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function runCommand(command) {
|
|
||||||
const result = spawnSync(command, { shell: true, stdio: 'inherit' });
|
|
||||||
if (result.error) {
|
|
||||||
console.error(`[verify:release] failed to launch '${command}': ${result.error.message}`);
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
if (result.status !== 0) {
|
|
||||||
const reason = result.signal ? `terminated by ${result.signal}` : `exited ${result.status}`;
|
|
||||||
console.error(`[verify:release] command '${command}' ${reason}`);
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Runs the complete mandatory verification set (or, with --stage <name>, the
|
|
||||||
// single named stage — used for wiring/smoke-testing, not for gating: only a
|
|
||||||
// run of every stage is a terminal verification). Fails fast: the first
|
|
||||||
// failing command aborts with a non-zero exit code. Returns the exit code.
|
|
||||||
export function verifyRelease({ stages = STAGES } = {}) {
|
|
||||||
const missing = missingBinaries(['bash', 'rsync']);
|
|
||||||
if (missing.length > 0) {
|
|
||||||
console.error(
|
|
||||||
`[verify:release] FATAL: required binaries missing from PATH: ${missing.join(', ')}. ` +
|
|
||||||
'The caller provides them (ci-base bakes bash; pipelines apk add rsync).',
|
|
||||||
);
|
|
||||||
return 1;
|
|
||||||
}
|
|
||||||
for (const stage of stages) {
|
|
||||||
console.log(`\n[verify:release] === stage: ${stage.name} ===`);
|
|
||||||
for (const command of stage.commands) {
|
|
||||||
console.log(`[verify:release] $ ${command}`);
|
|
||||||
if (!runCommand(command)) {
|
|
||||||
console.error(
|
|
||||||
`[verify:release] FATAL: stage '${stage.name}' failed — verification inconclusive`,
|
|
||||||
);
|
|
||||||
return 1;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
console.log(`\n[verify:release] all ${stages.length} stage(s) passed`);
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
function main(argv) {
|
|
||||||
const stageFlagIndex = argv.indexOf('--stage');
|
|
||||||
if (stageFlagIndex !== -1) {
|
|
||||||
const name = argv[stageFlagIndex + 1];
|
|
||||||
const stage = stageByName(name);
|
|
||||||
if (!stage) {
|
|
||||||
console.error(
|
|
||||||
`[verify:release] unknown stage '${name ?? ''}' — expected one of: ${STAGES.map((entry) => entry.name).join(', ')}`,
|
|
||||||
);
|
|
||||||
process.exit(2);
|
|
||||||
}
|
|
||||||
process.exit(verifyRelease({ stages: [stage] }));
|
|
||||||
}
|
|
||||||
process.exit(verifyRelease());
|
|
||||||
}
|
|
||||||
|
|
||||||
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
|
|
||||||
main(process.argv.slice(2));
|
|
||||||
}
|
|
||||||
@@ -1,303 +0,0 @@
|
|||||||
import assert from 'node:assert/strict';
|
|
||||||
import { readFile } from 'node:fs/promises';
|
|
||||||
import { createRequire } from 'node:module';
|
|
||||||
import path from 'node:path';
|
|
||||||
import test from 'node:test';
|
|
||||||
|
|
||||||
import { STAGES } from './verify-release.mjs';
|
|
||||||
|
|
||||||
// SDLC-D-034 checkout invariant: publication in .woodpecker/publish.yml is
|
|
||||||
// bound to exact-commit terminal verification. This suite parses the real
|
|
||||||
// pipeline files and fails red when the gate is bypassed, weakened, or drifts
|
|
||||||
// out of sync with the canonical `pnpm verify:release` command. The negative
|
|
||||||
// controls for pipeline DAG/bypass shapes live in
|
|
||||||
// scripts/publish-gate-structure.test.mjs (RI-1-002); this file owns the
|
|
||||||
// canonical-command composition controls.
|
|
||||||
|
|
||||||
// Reuse the monorepo's existing YAML parser (@mosaicstack/mosaic's direct
|
|
||||||
// dependency) instead of adding a root dependency or vendoring a parser.
|
|
||||||
const mosaicRequire = createRequire(
|
|
||||||
path.resolve(process.cwd(), 'packages', 'mosaic', 'package.json'),
|
|
||||||
);
|
|
||||||
const { parse: parseYaml } = mosaicRequire('yaml');
|
|
||||||
|
|
||||||
const publishYmlPath = path.join(process.cwd(), '.woodpecker', 'publish.yml');
|
|
||||||
const ciYmlPath = path.join(process.cwd(), '.woodpecker', 'ci.yml');
|
|
||||||
|
|
||||||
async function readPublishPipeline() {
|
|
||||||
return parseYaml(await readFile(publishYmlPath, 'utf8'));
|
|
||||||
}
|
|
||||||
|
|
||||||
// A step has an external publication effect when its name starts with
|
|
||||||
// `publish` or when any command pushes an image to a registry.
|
|
||||||
function pushesImage(step) {
|
|
||||||
return (step.commands ?? []).some((command) =>
|
|
||||||
/(^|\s)(\/kaniko\/executor|docker push)\b|--destination/.test(command),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function publishEffectSteps(pipeline) {
|
|
||||||
return Object.entries(pipeline.steps ?? {})
|
|
||||||
.filter(([name, step]) => name.startsWith('publish') || pushesImage(step))
|
|
||||||
.map(([name]) => name);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Transitive closure of a step's depends_on graph.
|
|
||||||
function dependencyClosure(pipeline, stepName, seen = new Set()) {
|
|
||||||
const dependencies = pipeline.steps?.[stepName]?.depends_on ?? [];
|
|
||||||
for (const dependency of dependencies) {
|
|
||||||
if (seen.has(dependency)) continue;
|
|
||||||
seen.add(dependency);
|
|
||||||
dependencyClosure(pipeline, dependency, seen);
|
|
||||||
}
|
|
||||||
return seen;
|
|
||||||
}
|
|
||||||
|
|
||||||
function verifyCommands(pipeline) {
|
|
||||||
const verify = pipeline.steps?.verify;
|
|
||||||
assert.ok(verify, 'publish pipeline must define a `verify` step');
|
|
||||||
assert.ok(Array.isArray(verify.commands), '`verify` step must have commands');
|
|
||||||
return verify.commands;
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertCommitIdentityAssertion(commands) {
|
|
||||||
const text = commands.join('\n');
|
|
||||||
assert.match(
|
|
||||||
text,
|
|
||||||
/CI_COMMIT_SHA/,
|
|
||||||
'`verify` must compare the provider commit identity (CI_COMMIT_SHA)',
|
|
||||||
);
|
|
||||||
assert.match(text, /git rev-parse HEAD/, '`verify` must compare against git rev-parse HEAD');
|
|
||||||
assert.match(
|
|
||||||
text,
|
|
||||||
/exit 1/,
|
|
||||||
'`verify` must fail closed (exit 1) on identity mismatch or emptiness',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertCanonicalCommand(commands) {
|
|
||||||
assert.ok(
|
|
||||||
commands.some((command) => /^pnpm verify:release\b/.test(command.trim())),
|
|
||||||
'`verify` must run the canonical terminal verification command `pnpm verify:release`',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertPublishGate(pipeline) {
|
|
||||||
assert.ok(pipeline.steps, 'publish pipeline must define steps');
|
|
||||||
|
|
||||||
const commands = verifyCommands(pipeline);
|
|
||||||
assertCommitIdentityAssertion(commands);
|
|
||||||
assertCanonicalCommand(commands);
|
|
||||||
|
|
||||||
const effects = publishEffectSteps(pipeline);
|
|
||||||
assert.ok(effects.length > 0, 'publish pipeline must contain publish effect steps to guard');
|
|
||||||
|
|
||||||
for (const stepName of effects) {
|
|
||||||
const step = pipeline.steps[stepName];
|
|
||||||
assert.ok(
|
|
||||||
Array.isArray(step.depends_on) && step.depends_on.includes('verify'),
|
|
||||||
`publish effect '${stepName}' must depend DIRECTLY on the verify step (SDLC-D-034: transitively through build is not enough)`,
|
|
||||||
);
|
|
||||||
assert.ok(
|
|
||||||
dependencyClosure(pipeline, stepName).has('verify'),
|
|
||||||
`publish effect '${stepName}' must depend on a chain that includes verify`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return effects;
|
|
||||||
}
|
|
||||||
|
|
||||||
test('the publish pipeline gates every publish effect behind exact-commit verification', async () => {
|
|
||||||
const pipeline = await readPublishPipeline();
|
|
||||||
const effects = assertPublishGate(pipeline);
|
|
||||||
assert.deepEqual(effects.sort(), [
|
|
||||||
'build-appservice',
|
|
||||||
'build-gateway',
|
|
||||||
'build-web',
|
|
||||||
'publish-next-npm',
|
|
||||||
'publish-npm',
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('the verify step carries no path/event short-circuit of its own', async () => {
|
|
||||||
const pipeline = await readPublishPipeline();
|
|
||||||
// A `when` filter on `verify` would let a publish effect fire on an event
|
|
||||||
// class that skipped verification — the gate must be unconditional.
|
|
||||||
assert.equal(pipeline.steps.verify.when, undefined);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a publish step that bypasses verify fails the gate checker', () => {
|
|
||||||
// Negative fixture: a plausible publish pipeline where `publish-npm` hangs
|
|
||||||
// off `build` only and `build` never chains to `verify` — the exact bypass
|
|
||||||
// class SDLC-D-034 closes. The checker must go red on it.
|
|
||||||
const bypassingPipeline = `
|
|
||||||
steps:
|
|
||||||
install:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm install --frozen-lockfile
|
|
||||||
verify:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- |
|
|
||||||
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
|
|
||||||
echo "identity mismatch" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- pnpm verify:release
|
|
||||||
depends_on:
|
|
||||||
- install
|
|
||||||
build:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm build
|
|
||||||
depends_on:
|
|
||||||
- install
|
|
||||||
publish-npm:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm publish
|
|
||||||
depends_on:
|
|
||||||
- build
|
|
||||||
`;
|
|
||||||
assert.throws(
|
|
||||||
() => assertPublishGate(parseYaml(bypassingPipeline)),
|
|
||||||
/publish-npm.*DIRECTLY.*verify/s,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a publish step chained to verify only transitively fails the gate checker', () => {
|
|
||||||
// Negative fixture: `build` depends on verify but `publish-npm` does not
|
|
||||||
// carry the direct edge — weaker than SDLC-D-034 requires of the real DAG.
|
|
||||||
const transitiveOnlyPipeline = `
|
|
||||||
steps:
|
|
||||||
install:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm install --frozen-lockfile
|
|
||||||
verify:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- |
|
|
||||||
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
|
|
||||||
echo "identity mismatch" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- pnpm verify:release
|
|
||||||
depends_on:
|
|
||||||
- install
|
|
||||||
build:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm build
|
|
||||||
depends_on:
|
|
||||||
- install
|
|
||||||
- verify
|
|
||||||
publish-npm:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm publish
|
|
||||||
depends_on:
|
|
||||||
- build
|
|
||||||
`;
|
|
||||||
assert.throws(
|
|
||||||
() => assertPublishGate(parseYaml(transitiveOnlyPipeline)),
|
|
||||||
/publish-npm.*DIRECTLY.*verify/s,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a verify step without the commit-identity assertion fails the gate checker', () => {
|
|
||||||
const noIdentityPipeline = `
|
|
||||||
steps:
|
|
||||||
verify:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm verify:release
|
|
||||||
publish-npm:
|
|
||||||
image: node:24-alpine
|
|
||||||
commands:
|
|
||||||
- pnpm publish
|
|
||||||
depends_on:
|
|
||||||
- verify
|
|
||||||
`;
|
|
||||||
assert.throws(() => assertPublishGate(parseYaml(noIdentityPipeline)), /CI_COMMIT_SHA/);
|
|
||||||
});
|
|
||||||
|
|
||||||
// The composition check: the canonical stage table must mirror the PR CI
|
|
||||||
// pipeline's complete mandatory set. Parameterized by the stage list so the
|
|
||||||
// subset negative control below can prove a dropped stage goes red (RI-1-002:
|
|
||||||
// the canonical command cannot silently lose a check).
|
|
||||||
function assertStagesMirrorCi(stages, ci) {
|
|
||||||
const canonical = Object.fromEntries(stages.map((stage) => [stage.name, stage.commands]));
|
|
||||||
|
|
||||||
// The complete mandatory set, in gate order.
|
|
||||||
assert.deepEqual(
|
|
||||||
stages.map((stage) => stage.name),
|
|
||||||
['sanitization', 'upgrade-guard', 'typecheck', 'lint', 'format', 'test', 'build'],
|
|
||||||
);
|
|
||||||
|
|
||||||
// Guard stages: ci.yml commands minus its `apk add` environment prep must be
|
|
||||||
// exactly the canonical stage commands (order included).
|
|
||||||
for (const stageName of ['sanitization', 'upgrade-guard']) {
|
|
||||||
assert.deepEqual(
|
|
||||||
ci.steps[stageName].commands.filter((command) => !command.startsWith('apk add')),
|
|
||||||
canonical[stageName],
|
|
||||||
`canonical '${stageName}' stage must match the ci.yml step`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// pnpm stages: ci.yml commands minus `corepack enable` must be exactly the
|
|
||||||
// canonical stage commands.
|
|
||||||
for (const stepName of ['typecheck', 'lint', 'format']) {
|
|
||||||
assert.deepEqual(
|
|
||||||
ci.steps[stepName].commands.filter((command) => command !== 'corepack enable'),
|
|
||||||
canonical[stepName],
|
|
||||||
`canonical '${stepName}' stage must match the ci.yml step`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// The test stage is shared, but ci.yml wraps it in pipeline-level
|
|
||||||
// prerequisites the canonical command expects its caller to provide
|
|
||||||
// (SDLC-D-034): the postgres service + readiness wait + db:migrate, openssl,
|
|
||||||
// and the pinned pi runtime. None of those may be dropped silently.
|
|
||||||
for (const command of canonical.test) {
|
|
||||||
assert.ok(
|
|
||||||
ci.steps.test.commands.includes(command),
|
|
||||||
`ci.yml test step must run the canonical test stage command '${command}'`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
for (const fragment of [
|
|
||||||
'pg_isready -h ci-postgres',
|
|
||||||
'pnpm --filter @mosaicstack/db run db:migrate',
|
|
||||||
'npm install -g @earendil-works/[email protected]',
|
|
||||||
]) {
|
|
||||||
assert.ok(
|
|
||||||
ci.steps.test.commands.some((command) => command.includes(fragment)),
|
|
||||||
`ci.yml test step must keep its pipeline-level prerequisite '${fragment}'`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
test('the canonical verify:release stages mirror the PR CI pipeline one-for-one', async () => {
|
|
||||||
const ci = parseYaml(await readFile(ciYmlPath, 'utf8'));
|
|
||||||
assertStagesMirrorCi(STAGES, ci);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a subset stage list fails the composition check — a dropped stage cannot pass silently', async () => {
|
|
||||||
const ci = parseYaml(await readFile(ciYmlPath, 'utf8'));
|
|
||||||
// Drop each stage one at a time: every stage is load-bearing, so every drop
|
|
||||||
// must go red. If any drop went green, a refactor could silently delete a
|
|
||||||
// mandatory check from the canonical command.
|
|
||||||
for (const stage of STAGES) {
|
|
||||||
const subset = STAGES.filter((entry) => entry.name !== stage.name);
|
|
||||||
assert.throws(
|
|
||||||
() => assertStagesMirrorCi(subset, ci),
|
|
||||||
Error,
|
|
||||||
`composition check must fail when the '${stage.name}' stage is dropped from the table`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
test('the root package.json exposes verify:release as the canonical command', async () => {
|
|
||||||
const packageJson = JSON.parse(await readFile(path.join(process.cwd(), 'package.json'), 'utf8'));
|
|
||||||
assert.match(packageJson.scripts['verify:release'], /scripts\/verify-release\.mjs/);
|
|
||||||
});
|
|
||||||
Reference in New Issue
Block a user