Files
stack/packages/mosaic/framework/tools/git/test-verify-clean-clone.sh
T
installer-7andClaude Opus 5 8fdc8738ed
ci/woodpecker/pr/ci Pipeline was successful
fix(git): push-guard harness — resolve three re-review blockers + two corrections
Authored by installer-7; committed by mos-claude (no credential for this remote).
push-guard.sh and test-push-guard.sh are BYTE-IDENTICAL to the previously cleared
versions — every change this round is in the harness, confirming the reviewer's
framing that none of the three blockers was in the guard itself.

B1 verify-clean-clone.sh could not verify the artifact in its real monorepo location:
  it resolved ROOT but kept artifacts as bare basenames, so running it in place
  reported all artifacts NOT TRACKED. Its own suite missed this because every
  fixture installed artifacts at fixture ROOT — a fixture encoding a layout the
  real subject does not have. PREFIX now comes from 'git rev-parse --show-prefix'
  and is threaded through the ls-tree pathspec, the cloned stat, and the suite cwd;
  the verifier PRINTS the prefix. Three needles: nested-layout pass, prefix-reported
  (else a green only means the prefix was ignored harmlessly), and mode-needle-still-
  bites-nested (a prefix threaded into the clone but not ls-tree would silently stop
  checking modes).
B2 the generator reported full coverage and exited 0 on a RED baseline — any
  pre-existing failure marked every mutant killed. Now refuses unless baseline is
  exit 0 with zero failures, prints the actual tally on refusal, emits no table, and
  scores kills by NAMED DELTA rather than a raw red count.
B3 the generator mutated the reviewed source in place; SIGKILL stranded a mutant and
  contaminated a following run. Guard and suite are now copied into a temp dir and
  mutations apply to that copy — no restore step to fail. The author's first control
  for this was itself vacuous (a 3s kill lands during baseline, before any mutation,
  so it passed against the unfixed mechanism too); the real control drives the kill
  from inside the run on the second suite invocation, plus a needle proving the
  reconstructed pre-fix mechanism DOES strand.
Corrections: 'shellcheck clean' had been measured at -S warning and published
  unqualified — a filtered measurement stated as an unfiltered claim. Now clean at
  DEFAULT severity across six files with one scoped, documented SC2016 disable.
  ARTIFACTS extended five -> six so the test files no longer omit themselves.

Verified before commit: six files sha256-matched to the author's hashes; shellcheck
exit 0 at default severity; push-guard 46/46 and verifier 9/9 run directly; the
in-place verifier resolved the real nested prefix against this tree.

Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01YKj59Qadrb2WBLaePvkM7H
2026-07-30 22:02:29 -05:00

145 lines
6.8 KiB
Bash
Executable File

#!/usr/bin/env bash
# test-verify-clean-clone.sh -- needles for the verifier itself.
#
# v1 of the verifier passed while the real repository recorded 100644, because it
# asserted a SCRATCH repo built by cp. There was no needle that could have caught
# that: every case ran against a tree whose modes came off my filesystem.
# So the load-bearing needle here is w2 -- SOURCE GIT MODE 100644, DISK MODE 755.
# That is the exact contaminated state, and v1 exits 0 on it while v2 must refuse.
# A verifier without this needle is the same shape as the defect it verifies.
set -uo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
VERIFY="$HERE/verify-clean-clone.sh"
ARTIFACTS=(push-guard.sh test-push-guard.sh verify-clean-clone.sh mutate-push-guard.sh
test-mutate-push-guard.sh
test-verify-clean-clone.sh)
# THE REAL DEPLOYED LAYOUT. Every fixture in the first version of this file
# installed the artifacts at the fixture ROOT, so 6/6 green proved flat-layout
# operation and said NOTHING about the path these files actually ship at. The
# verifier was unusable in place and the suite could not see it, because THE
# FIXTURE ENCODED A LAYOUT THAT DOES NOT EXIST. A fixture is a claim about the
# world; an untested fixture is an unreviewed one.
readonly REAL_PREFIX="packages/mosaic/framework/tools/git"
PASS=0; FAIL=0
TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT
# Build a source repo whose COMMITTED modes are 100755 and whose disk modes are
# executable -- the honest state.
# mkrepo <repo-root> [subdir]
# With a subdir the artifacts are committed at repo/<subdir>/, which is how they
# really ship. Echoes the directory the artifacts landed in -- that is what gets
# passed as --repo, so the caller never has to reconstruct the path.
mkrepo() {
local d="$1" sub="${2:-}"
local dest="$d${sub:+/$sub}"
mkdir -p "$dest"
local f
for f in "${ARTIFACTS[@]}"; do
install -m 755 "$HERE/$f" "$dest/$f"
done
git -C "$d" init -q .
git -C "$d" config user.email "[email protected]"
git -C "$d" config user.name "Verifier Needles"
git -C "$d" add -A
git -C "$d" commit -q -m "artifacts"
printf '%s\n' "$dest"
}
run_case() {
local name="$1" want_rc="$2" want_txt="$3" repo="$4"
local out rc
out="$("$VERIFY" --repo "$repo" 2>&1)"; rc=$?
if (( rc == want_rc )) && [[ "$out" == *"$want_txt"* ]]; then
printf ' ok [%-14s]\n' "$name"; PASS=$(( PASS + 1 ))
else
printf ' FAIL [%-14s] wanted rc=%d containing %q; got rc=%d\n%s\n' \
"$name" "$want_rc" "$want_txt" "$rc" "$out"; FAIL=$(( FAIL + 1 ))
fi
}
echo "== POSITIVE CONTROL: an honestly-committed artifact must PASS =="
# Without this, every case below could be passing because the verifier always
# refuses -- a wall, not a gate.
mkrepo "$TMP/good" >/dev/null
run_case w1-honest 0 "the COMMITTED artifact ran and passed" "$TMP/good"
echo
echo "== THE DEPLOYED LAYOUT: artifacts NESTED, not at the repository root =="
# The blocker: ls-tree was given a bare basename, which is a ROOT-relative
# pathspec, so in the real tree every artifact came back NOT TRACKED and the
# verifier refused to run at all. This control fails against that version and
# passes only when the committed PREFIX is threaded through ls-tree, the cloned
# stat, and the suite's working directory.
w6dir="$(mkrepo "$TMP/nested" "$REAL_PREFIX")"
run_case w6-nested 0 "the COMMITTED artifact ran and passed" "$w6dir"
# ...and prove the run actually happened DOWN THERE rather than at the root, or
# a passing w6 would only mean the prefix was ignored harmlessly.
#
# Captured into a variable rather than piped into `grep -q` ON PURPOSE. grep -q
# exits at the FIRST match, the verifier then dies of SIGPIPE, and under
# `pipefail` the pipeline reports that 141 -- so A SUCCESSFUL MATCH READS AS A
# FAILED ASSERTION. This cost me a red w6-prefix against a verifier that was
# printing the right prefix all along. Same family as the pipefail/process-
# substitution note already on record: the exit status being consulted is not
# the status of the thing being asserted.
w6out="$("$VERIFY" --repo "$w6dir" 2>&1)"
if [[ "$w6out" == *"prefix $REAL_PREFIX/"* ]]; then
printf ' ok [%-14s] verifier reported prefix %s/\n' "w6-prefix" "$REAL_PREFIX"; PASS=$(( PASS + 1 ))
else
printf ' FAIL [%-14s] verifier did not report the nested prefix -- it may have\n' "w6-prefix"
printf ' passed by looking at the root, which is the blocker unfixed\n'; FAIL=$(( FAIL + 1 ))
fi
# And the mode needle must ALSO bite in the nested layout: a prefix threaded
# into the clone but not into ls-tree would silently stop checking modes.
w7dir="$(mkrepo "$TMP/nested-laundered" "$REAL_PREFIX")"
git -C "$TMP/nested-laundered" update-index --chmod=-x "$REAL_PREFIX/push-guard.sh"
git -C "$TMP/nested-laundered" commit -q -m "drop exec bit in git only"
run_case w7-nested-mode 1 "committed 100644, needs 100755" "$w7dir"
echo
echo "== THE B1 NEEDLE: source git mode 100644, DISK MODE STILL 755 =="
# This is the reviewer's exact reproduction. v1 of the verifier exits 0 here.
mkrepo "$TMP/laundered" >/dev/null
git -C "$TMP/laundered" update-index --chmod=-x push-guard.sh test-push-guard.sh
git -C "$TMP/laundered" commit -q -m "drop exec bit in git only"
# PROVE THE FIXTURE IS THE CONTAMINATED STATE, not merely a broken repo: git must
# say 100644 while the filesystem still says executable. If the disk bit were
# gone too, the needle would be testing something easier than the real defect.
src_mode="$(git -C "$TMP/laundered" ls-tree HEAD -- push-guard.sh | awk '{print $1}')"
disk_mode="$(stat -c '%a' "$TMP/laundered/push-guard.sh")"
if [[ "$src_mode" == "100644" && "$disk_mode" == "755" ]]; then
printf ' ok [%-14s] fixture is git=%s disk=%s\n' "w2-fixture" "$src_mode" "$disk_mode"; PASS=$(( PASS + 1 ))
else
printf ' FAIL [%-14s] fixture wrong: git=%s disk=%s -- needle would not test the defect\n' \
"w2-fixture" "$src_mode" "$disk_mode"; FAIL=$(( FAIL + 1 ))
fi
run_case w2-laundered 1 "committed 100644, needs 100755" "$TMP/laundered"
echo
echo "== the artifact must be COMMITTED, or there is no mode to verify =="
mkrepo "$TMP/untracked" >/dev/null
git -C "$TMP/untracked" rm -q --cached push-guard.sh
git -C "$TMP/untracked" commit -q -m "untrack the guard"
run_case w3-untracked 1 "NOT TRACKED" "$TMP/untracked"
echo
echo "== a committed SYMLINK is a path, not the reviewed code =="
mkrepo "$TMP/symlink" >/dev/null
( cd "$TMP/symlink" && rm -f push-guard.sh && ln -s /dev/null push-guard.sh \
&& git add push-guard.sh && git commit -q -m "symlink the guard" )
run_case w4-symlink 1 "SYMLINK" "$TMP/symlink"
echo
echo "== not a repository at all: REFUSE, never pass =="
mkdir -p "$TMP/bare"
for f in "${ARTIFACTS[@]}"; do install -m 755 "$HERE/$f" "$TMP/bare/$f"; done
run_case w5-norepo 1 "not inside a git repository" "$TMP/bare"
echo
printf '%d passed, %d failed\n' "$PASS" "$FAIL"
(( FAIL == 0 ))