test: match historical hosted native prerequisite repair

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
DottaandPaperclip committed 2026-10-03 00:00:29 -05:00
1 parent 00a761b967
commit e74ed61a69
5 files changed
+24 -7

No files matched your search

@@ -40,9 +40,11 @@ describe("native completion credential-free admission", () => {
expect(spawn).toHaveBeenCalledTimes(1);
});
it("retains credential-free prerequisites inside the exact campaign root and verifies them", () => {
const sourceSha = "c".repeat(40);
vi.stubEnv("PAPERCLIP_RUNNER_E2E_SOURCE_SHA", sourceSha);
vi.stubEnv("OPENAI_API_KEY", "secret"); vi.stubEnv("UNLISTED_PROVIDER_CREDENTIAL", "secret");
spawn.mockReturnValueOnce({ status: 0 } as ReturnType<typeof spawnSync>);
spawn.mockReturnValueOnce({ status: 0, stdout: '{"passed":true}' } as ReturnType<typeof spawnSync>);
spawn.mockReturnValueOnce({ status: 0, stdout: JSON.stringify({ passed: true, sourceSha }) } as ReturnType<typeof spawnSync>);
const receipt = prepareNativeCompletionPreflight(campaignDirectory);
expect(receipt).toMatch(/^\/fixture\/results\/gha-1-1-native-completion\.fixture\/native-completion-prerequisites\/[^/]+\/preflight.json$/);
expect(spawn.mock.calls[1]?.[1]).toContain(`--verify=${receipt}`);
@@ -71,6 +71,11 @@ export function gradeNativeCompletionDiscovery(output, exitCode) {
rows.every(row => row.length === 6 && row[1] === "native-completion" && row[2] === "native" && row[4]?.trim() && row[5]?.trim()),
executionIds: ids, expectedCells: 6, expectedTurns: 6, maximumAttemptsPerCell: 1 };
}
/** capture() stores compact provenance JSON on its first line, then diagnostics. */
export function gradeNativeCompletionHostedRunnerdEvidence(text, expected) {
try { return JSON.stringify(JSON.parse(text.split(/\r?\n/, 1)[0])) === JSON.stringify(expected); }
catch { return false; }
}
export function gradeNativeCompletionRustCarrier(output, exitCode) {
return exitCode === 0 && /^test provider_events::tests::preserves_closed_compatibility_terminal_tool_identity \.\.\. ok$/m.test(output) &&
/test result: ok\. 1 passed; 0 failed;/.test(output);
@@ -199,7 +204,7 @@ export function main(args = process.argv.slice(2)) {
throw new Error("Missing passing retained Rust terminal-tool carrier calibration.");
if (id === "NC-hosted-runnerd" && (retained.executed !== false || retained.calibration !== "not_executed" ||
retained.total !== 0 || retained.passedTests !== 0 ||
JSON.stringify(JSON.parse(text.split("\n\n")[0])) !== JSON.stringify(report.setup.runnerdProvenance)))
!gradeNativeCompletionHostedRunnerdEvidence(text, report.setup.runnerdProvenance)))
throw new Error("Hosted runnerd reuse must retain exact binary proof and report Rust calibration not executed.");
if (id === "NC-manifest" && manifestCommands(env).some(run => run.status !== 0))
throw new Error("Generated native capability manifests are stale.");
@@ -4,7 +4,7 @@ import { mkdtempSync, writeFileSync, rmSync } from "node:fs";
import { join } from "node:path";
import { tmpdir } from "node:os";
import {
nativeCompletionGates, gradeNativeCompletionGate, gradeNativeCompletionDiscovery, gradeNativeCompletionRustCarrier,
nativeCompletionGates, gradeNativeCompletionGate, gradeNativeCompletionDiscovery, gradeNativeCompletionRustCarrier, gradeNativeCompletionHostedRunnerdEvidence,
assertNativeCompletionPreflightReceipt, assertRetainedNativeCompletionEvidence, nativeCompletionPrerequisiteEnvironment,
NATIVE_COMPLETION_PREFLIGHT_SCHEMA, NATIVE_COMPLETION_CELL_IDS, NATIVE_COMPLETION_COMMAND_GATE_IDS, nativeCompletionCommandGateIds,
} from "./native-completion-checks.mjs";
@@ -170,3 +170,13 @@ for (const [name, mutate] of [
r.gates.sort((a,b) => a.id === "NC-hosted-runnerd" ? 1 : b.id === "NC-hosted-runnerd" ? -1 : 0);
mutate(r); assert.throws(() => assertNativeCompletionPreflightReceipt(r,c));
});
test("hosted runnerd evidence verifies the exact compact JSON capture before its diagnostic line", () => {
const proof = hostedFixture().c.runnerdProvenance;
const capture = `${JSON.stringify(proof)}\nRust unit calibration must be qualified by the separate exact-source local receipt and normal CI.`;
assert.equal(gradeNativeCompletionHostedRunnerdEvidence(capture, proof), true);
assert.equal(gradeNativeCompletionHostedRunnerdEvidence(capture.replace("\n", "\r\n"), proof), true);
assert.equal(gradeNativeCompletionHostedRunnerdEvidence(capture, { ...proof, binarySha256: "f".repeat(64) }), false);
assert.equal(gradeNativeCompletionHostedRunnerdEvidence(`not-json\n${JSON.stringify(proof)}`, proof), false);
assert.equal(gradeNativeCompletionHostedRunnerdEvidence("", proof), false);
});
@@ -8,8 +8,8 @@ export const NATIVE_COMPLETION_SOURCE_CONTRACT = {
"baseSha": "59c07ede72dc08b8aba149a01cc11e0b7a204621",
"archiveSha": "9138f570c341c251a5727c32d6615ce238bc8e03",
"shallowParentAnchors": {
"candidate": "b603222b8496c234b64c0642ca3ca4d5d8990318",
"historical": "e68a7edc569f73ba1eb26b5a47f6a22ce536babc"
"candidate": "0a9c5a75164cd0b02115ff12273aadb6a86c9464",
"historical": "00a761b967f9f73b0f45069c0ba828fae277a76e"
},
"variants": {
"candidate": {
@@ -67,8 +67,8 @@ test("native source contract binds exactly five production and six variant asser
assert.equal(original.baseSha, "59c07ede72dc08b8aba149a01cc11e0b7a204621");
assert.equal(original.archiveSha, "9138f570c341c251a5727c32d6615ce238bc8e03");
assert.deepEqual(original.shallowParentAnchors, {
candidate: "b603222b8496c234b64c0642ca3ca4d5d8990318",
historical: "e68a7edc569f73ba1eb26b5a47f6a22ce536babc",
candidate: "0a9c5a75164cd0b02115ff12273aadb6a86c9464",
historical: "00a761b967f9f73b0f45069c0ba828fae277a76e",
});
assert.ok(!NATIVE_COMPLETION_SOURCE_FILES.some(file => file.includes("stock-harness") || file.endsWith("issue-documents.md")));
});