#!/usr/bin/env bash # Regression harness for pr-review.sh's -r/--repo and -H/--host overrides, # the -r repo-exists preflight, and the mosaic-pr-review User-Agent header # (patch family 5/5c, part of #891). # # -r/--repo and -H/--host skip git-remote slug/host inference entirely, for # reviewer worktrees whose origin is nonstandard, wrong, or missing (mirrors # the -r convention of the sibling wrappers pr-view.sh/pr-diff.sh/pr-ci-wait.sh, # #867). When -r is given, the resolved repo is preflighted (GET # .../repos/) BEFORE any write, so a wrong-host cross-wire surfaces as a # clear preflight error instead of an opaque write-404. Every Gitea curl call # (preflight, write, read-back, /user, PR-head) must carry a # `User-Agent: mosaic-pr-review` header, since some Cloudflare-fronted Gitea # hosts intermittently reject curl's default User-Agent. # # Round 2 (post-review): the approve/request-changes/comment dispatch bodies # each independently called a BARE `host=$(get_remote_host)` (only for a # best-effort tea-login guess) that ignored -H/--host entirely and, under # `set -e`, DIED SILENTLY (exit 1, zero stdout/stderr) whenever no git origin # existed — exactly the case -r/-H exist to support. The "no git origin at # all" fixture below must be a directory TRULY outside any .git ancestry (a # subdirectory with no .git of its own still resolves `git remote get-url # origin` UPWARD to an enclosing repo's origin — a real flaw in the first # version of this fixture, since the test tree itself sits inside the # mosaicstack/stack checkout). It is created via `mktemp -d` under the SYSTEM # /tmp and additionally bounded with GIT_CEILING_DIRECTORIES, so `git rev-parse # --show-toplevel`/`git remote get-url origin` cannot walk past it under any # circumstance. set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-review-repo-host-override}" BIN_DIR="$WORK_DIR/bin" STATE_DIR="$WORK_DIR/state" CURL_LOG="$WORK_DIR/curl.log" UA_LOG="$WORK_DIR/ua.log" OUTPUT_FILE="$WORK_DIR/output.log" TMP_SCRATCH="$WORK_DIR/scratch" CREDENTIALS_FILE="$WORK_DIR/credentials.json" # A TRUE no-git-origin fixture: created under the system /tmp (NOT under # $WORK_DIR, which sits inside this very checkout's .git ancestry), so that # `git remote get-url origin` run from inside it cannot resolve upward to the # mosaicstack/stack checkout's own real origin. NO_GIT_DIR="$(mktemp -d "${TMPDIR:-/tmp}/pr-review-no-origin.XXXXXX")" cleanup() { rm -rf "$WORK_DIR" "$NO_GIT_DIR" } trap cleanup EXIT HOST_OVERRIDE_VAL="pr-review-override.test" REPO_OVERRIDE_VAL="acme/widgets" TOKEN_VAL="override-token-xyz" ACTING_LOGIN="override-bot" HEAD_SHA_VAL="feedfacecafebabe0000000000000000000000" mkdir -p "$BIN_DIR" "$STATE_DIR" "$TMP_SCRATCH" # tea stub: deterministic tea-absent behavior regardless of whether the host # actually has a real `tea` binary on PATH. -r/--repo + -H/--host must not # NEED a resolvable tea login to work — the wrapper falls back to the # host-scoped GITEA_TOKEN credential when no tea login resolves. cat > "$BIN_DIR/tea" <<'SH' #!/usr/bin/env bash exit 1 SH chmod +x "$BIN_DIR/tea" # curl stub: models the target Gitea instance for the OVERRIDDEN host/repo # only. Any request to a DIFFERENT host/repo (i.e. one derived from git-remote # inference instead of the override) is unexpected and fails the run. cat > "$BIN_DIR/curl" <> "$CURL_LOG" printf '%s %s\n' "\$ua_seen" "\$url" >> "$UA_LOG" write_response() { local status="\$1" body="\$2" [[ -n "\$output_file" ]] || exit 96 printf '%s' "\$body" > "\$output_file" printf '%s' "\$status" } mode="\$(cat "$STATE_DIR/mode" 2>/dev/null || true)" web_base="https://$HOST_OVERRIDE_VAL" repo="$REPO_OVERRIDE_VAL" case "\$url" in "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL") if [[ "\$mode" == "repo-missing" ]]; then write_response 404 '{"message":"not found"}' else write_response 200 "{\\"full_name\\":\\"$REPO_OVERRIDE_VAL\\"}" fi ;; "https://$HOST_OVERRIDE_VAL/api/v1/user") write_response 200 "{\\"login\\":\\"$ACTING_LOGIN\\"}" ;; "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL/pulls/123") write_response 200 "{\\"head\\":{\\"sha\\":\\"$HEAD_SHA_VAL\\"}}" ;; "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL/pulls/123/reviews") PR_REVIEW_PAYLOAD="\$payload" PR_REVIEW_ACTING="$ACTING_LOGIN" \ python3 -c ' import json, os p = json.loads(os.environ["PR_REVIEW_PAYLOAD"]) record = { "id": 501, "state": p.get("event"), "commit_id": p.get("commit_id"), "body": p.get("body"), "user": {"login": os.environ["PR_REVIEW_ACTING"]}, } with open("$STATE_DIR/review.json", "w", encoding="utf-8") as fh: json.dump(record, fh) ' write_response 201 "\$(cat "$STATE_DIR/review.json")" ;; "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL/pulls/123/reviews/501") write_response 200 "\$(cat "$STATE_DIR/review.json")" ;; "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL/issues/123/comments") write_response 201 "{\\"id\\":456,\\"body\\":\\"durable-body\\",\\"user\\":{\\"login\\":\\"$ACTING_LOGIN\\"},\\"issue_url\\":\\"\\",\\"pull_request_url\\":\\"\${web_base}/\${repo}/pulls/123\\"}" ;; "https://$HOST_OVERRIDE_VAL/api/v1/repos/$REPO_OVERRIDE_VAL/issues/comments/456") write_response 200 "{\\"id\\":456,\\"body\\":\\"durable-body\\",\\"user\\":{\\"login\\":\\"$ACTING_LOGIN\\"},\\"issue_url\\":\\"\\",\\"pull_request_url\\":\\"\${web_base}/\${repo}/pulls/123\\"}" ;; *) echo "Unexpected curl request (host/repo not from the override — inference leaked through?): \$method \$url" >&2 exit 97 ;; esac SH chmod +x "$BIN_DIR/curl" run() { local repo_dir="$1"; shift : > "$CURL_LOG" : > "$UA_LOG" : > "$OUTPUT_FILE" ( cd "$repo_dir" PATH="$BIN_DIR:$PATH" \ TMPDIR="$TMP_SCRATCH" \ MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \ GITEA_TOKEN="$TOKEN_VAL" \ GITEA_URL="https://$HOST_OVERRIDE_VAL" \ GIT_CEILING_DIRECTORIES="$(dirname "$NO_GIT_DIR")" \ "$SCRIPT_DIR/pr-review.sh" "$@" ) > "$OUTPUT_FILE" 2>&1 } set_mode() { printf '%s' "$1" > "$STATE_DIR/mode" } # A run must not silently die: exit 1 with a COMPLETELY EMPTY combined # stdout+stderr is precisely the pre-fix signature of the dispatch-level bare # `host=$(get_remote_host)` call dying under `set -e` when there was no git # origin at all. Whatever the outcome, the wrapper must always emit SOME # diagnostic (success line, or an "Error: ..." line). assert_not_silently_dead() { local context="$1" exit_code="$2" if [[ "$exit_code" -ne 0 && ! -s "$OUTPUT_FILE" ]]; then echo "FAIL: pr-review.sh died SILENTLY (exit $exit_code, zero output) in a true no-origin dir ($context)" >&2 exit 1 fi } # Sanity-check the fixture itself BEFORE relying on it: from inside NO_GIT_DIR, # `git remote get-url origin` must fail outright — proving this directory is # truly outside any .git ancestry (the flaw this harness had before: a bare # subdirectory of the checkout resolves `origin` UPWARD to the checkout's own # real remote instead of failing). if (cd "$NO_GIT_DIR" && GIT_CEILING_DIRECTORIES="$(dirname "$NO_GIT_DIR")" git remote get-url origin) 2>/dev/null; then echo "FAIL: NO_GIT_DIR fixture is not actually outside any git ancestry — 'git remote get-url origin' resolved upward" >&2 exit 1 fi # --- Case 1: -r/--repo and -H/--host are recognized flags (regression lock on # the previous "Unknown option: -r" / "Unknown option: -H" failure). Use a # bogus ACTION so the run fails cheaply, WITHOUT any network I/O, at the # platform-dispatch unknown-action branch rather than at argument parsing — # proving both flags were consumed as options, not rejected. set_mode "repo-ok" if run "$NO_GIT_DIR" -n 123 -a bogus-action -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL"; then echo "FAIL: bogus action unexpectedly succeeded" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi if grep -q 'Unknown option' "$OUTPUT_FILE"; then echo "FAIL: -r/--repo or -H/--host was not recognized as a valid flag" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi grep -q 'Unknown action: bogus-action' "$OUTPUT_FILE" # --- Case 2: -h/--help documents both overrides. HELP_TEXT="$("$SCRIPT_DIR/pr-review.sh" -h)" echo "$HELP_TEXT" | grep -q -- '-r, --repo' echo "$HELP_TEXT" | grep -q -- '-H, --host' # --- Case 3 (comment): a TRUE no-git-origin dir + -r/-H must not silently die # and must not fail with "not a git repository or no origin remote" either. set_mode "repo-ok" comment_rc=0 run "$NO_GIT_DIR" -n 123 -a comment -c durable-body -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL" || comment_rc=$? assert_not_silently_dead "comment" "$comment_rc" if grep -qi 'not a git repository or no origin remote' "$OUTPUT_FILE"; then echo "FAIL: -r/--repo did not tolerate a missing git origin" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi grep -q 'Added and verified comment on Gitea PR #123' "$OUTPUT_FILE" # --- Case 3b (approve): same true no-origin dir, the `approve` dispatch body # (its OWN, previously-unguarded `host=$(get_remote_host)` call) must not # silently die either. set_mode "repo-ok" approve_rc=0 run "$NO_GIT_DIR" -n 123 -a approve -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL" || approve_rc=$? assert_not_silently_dead "approve" "$approve_rc" if grep -qi 'not a git repository or no origin remote' "$OUTPUT_FILE"; then echo "FAIL: approve's -r/--repo did not tolerate a missing git origin" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi grep -q 'Approved and verified Gitea PR #123 (review ID 501)' "$OUTPUT_FILE" # --- Case 3c (request-changes): same true no-origin dir, the # `request-changes` dispatch body's OWN previously-unguarded # `host=$(get_remote_host)` call must not silently die either. set_mode "repo-ok" request_changes_rc=0 run "$NO_GIT_DIR" -n 123 -a request-changes -c please-fix -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL" || request_changes_rc=$? assert_not_silently_dead "request-changes" "$request_changes_rc" if grep -qi 'not a git repository or no origin remote' "$OUTPUT_FILE"; then echo "FAIL: request-changes's -r/--repo did not tolerate a missing git origin" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi grep -q 'Requested changes and verified on Gitea PR #123 (review ID 501)' "$OUTPUT_FILE" # --- Case 4: -r/--repo and -H/--host WIN over git-remote inference, not just # tolerate its absence — set up a real git repo whose origin points at a # COMPLETELY DIFFERENT host/repo and confirm the override, not the remote, is # what gets used (the curl stub only answers for the override host/repo; any # request derived from the wrong remote is an unexpected request and fails # the stub with exit 97). WRONG_REMOTE_DIR="$WORK_DIR/wrong-remote-repo" mkdir -p "$WRONG_REMOTE_DIR" git -C "$WRONG_REMOTE_DIR" init -q git -C "$WRONG_REMOTE_DIR" remote add origin https://git.wrong-inferred-host.example/wrong/repo.git set_mode "repo-ok" run "$WRONG_REMOTE_DIR" -n 123 -a comment -c durable-body -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL" grep -q 'Added and verified comment on Gitea PR #123' "$OUTPUT_FILE" if grep -q 'wrong-inferred-host' "$CURL_LOG"; then echo "FAIL: -r/--repo + -H/--host did not override git-remote inference" >&2 cat "$CURL_LOG" >&2 exit 1 fi # --- Case 5 (5c): the repo-exists preflight runs BEFORE any write and fails # closed with a clear diagnostic when the resolved repo is unreachable at the # resolved host — proving a wrong-host cross-wire surfaces here, not as an # opaque write-404. set_mode "repo-missing" if run "$NO_GIT_DIR" -n 123 -a comment -c durable-body -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL"; then echo "FAIL: preflight did not fail closed on a missing repo" >&2 cat "$OUTPUT_FILE" >&2 exit 1 fi grep -q "repo '$REPO_OVERRIDE_VAL' not reachable" "$OUTPUT_FILE" if grep -q '/issues/123/comments' "$CURL_LOG"; then echo "FAIL: wrapper posted a comment despite a failed repo preflight" >&2 cat "$CURL_LOG" >&2 exit 1 fi # --- Case 6 (5): every Gitea curl call (preflight, /user, comment write, # comment read-back) carries the User-Agent: mosaic-pr-review header. set_mode "repo-ok" run "$NO_GIT_DIR" -n 123 -a comment -c durable-body -r "$REPO_OVERRIDE_VAL" -H "$HOST_OVERRIDE_VAL" grep -q 'Added and verified comment on Gitea PR #123' "$OUTPUT_FILE" call_count="$(wc -l < "$CURL_LOG" | tr -d ' ')" ua_count="$(awk '$1 == "1"' "$UA_LOG" | wc -l | tr -d ' ')" if [[ "$call_count" -lt 4 ]]; then echo "FAIL: expected at least 4 curl calls (preflight, /user, write, read-back), got $call_count" >&2 cat "$CURL_LOG" >&2 exit 1 fi if [[ "$ua_count" != "$call_count" ]]; then echo "FAIL: not every curl call carried User-Agent: mosaic-pr-review ($ua_count/$call_count)" >&2 cat "$UA_LOG" >&2 exit 1 fi echo "pr-review.sh -r/--repo + -H/--host override + preflight + User-Agent regression passed"