mirror of
https://github.com/stablyai/orca.git
synced 2026-10-02 00:02:05 +00:00
* fix(codex): trust the path Codex checks for bare-repo worktrees Codex keys a linked worktree's trust on the main checkout only when that checkout's .git leads back to the common git dir; otherwise (bare repo, --separate-git-dir) it keys on the worktree itself. Orca always wrote the main-checkout key, so Codex showed its trust prompt and worker-start failed at agent_readiness. Mirror trust.rs exactly, and pin it with a real-binary contract that runs in the existing Codex contract CI job. Fixes #23847 * fix(codex): trust the worktree path itself instead of mirroring trust.rs Codex looks up the cwd's own [projects] entry before any repo root (config_toml.rs get_active_project, loader decision_for_dir), so trusting the workspace realpath satisfies every git layout. Drops the resolve_root_git_project_for_trust mirror: simpler, cannot drift from Codex, and never widens trust past the folder Orca launched in. Cost is one config entry per worktree; entries older Orca wrote on main checkouts stay valid. The six real-git layout tests now assert the workspace key and, under the contract, that real Codex starts workspaceWrite for each. The contract probes the binary version once and fails at load when required but missing; its CI path filter now includes config-toml-trust.
68 lines
3.3 KiB
JavaScript
68 lines
3.3 KiB
JavaScript
import { readFileSync } from 'node:fs'
|
|
import { parse } from 'yaml'
|
|
import { describe, expect, it } from 'vitest'
|
|
|
|
describe('Codex index-heal contract PR gate', () => {
|
|
const workflow = parse(readFileSync('.github/workflows/pr.yml', 'utf8'))
|
|
const job = workflow.jobs.codex_index_heal_contract
|
|
|
|
it('installs and verifies against one pinned Codex version', () => {
|
|
const install = job.steps.find((step) => step.name === 'Install pinned Codex CLI')
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
|
|
|
|
// Why one source: the install and the runtime version assertion drifting apart is
|
|
// the failure that would leave this job verifying a Codex nobody declared.
|
|
expect(job.env.CODEX_CLI_VERSION).toMatch(/^\d+\.\d+\.\d+$/)
|
|
expect(install.run).toContain('"@openai/codex@$CODEX_CLI_VERSION"')
|
|
expect(verify.env.ORCA_CODEX_CONTRACT_VERSION).toBe('${{ env.CODEX_CLI_VERSION }}')
|
|
|
|
// The install prefix and the binary the test is pointed at must be the same tree.
|
|
expect(install.run).toContain('--prefix "$RUNNER_TEMP/codex-cli"')
|
|
expect(verify.run).toContain(
|
|
'ORCA_CODEX_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli/node_modules/.bin/codex"'
|
|
)
|
|
expect(verify.run).toContain('src/main/codex/codex-index-heal-binary-contract.test.ts')
|
|
})
|
|
|
|
it('fails rather than skipping when the Codex binary is missing', () => {
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
|
|
|
|
// Why asserted: the contract skips itself without a binary, so a failed install
|
|
// would otherwise turn this job into a green no-op that verifies nothing.
|
|
expect(verify.env.ORCA_CODEX_CONTRACT_REQUIRED).toBe('1')
|
|
expect(job.steps.find((step) => step.name === 'Install pinned Codex CLI').run).toContain(
|
|
'set -euo pipefail'
|
|
)
|
|
})
|
|
|
|
it('pins the --no-daemon contract to one Codex version and fails when it is missing', () => {
|
|
const install = job.steps.find((step) => step.name === 'Install pinned no-daemon Codex CLI')
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex --no-daemon contract')
|
|
|
|
expect(job.env.CODEX_NO_DAEMON_CLI_VERSION).toMatch(/^\d+\.\d+\.\d+$/)
|
|
expect(install.run).toContain('"@openai/codex@$CODEX_NO_DAEMON_CLI_VERSION"')
|
|
expect(verify.env.ORCA_CODEX_NO_DAEMON_CONTRACT_VERSION).toBe(
|
|
'${{ env.CODEX_NO_DAEMON_CLI_VERSION }}'
|
|
)
|
|
expect(verify.env.ORCA_CODEX_NO_DAEMON_CONTRACT_REQUIRED).toBe('1')
|
|
expect(install.run).toContain('--prefix "$RUNNER_TEMP/codex-cli-no-daemon"')
|
|
expect(verify.run).toContain(
|
|
'ORCA_CODEX_NO_DAEMON_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli-no-daemon/node_modules/.bin/codex"'
|
|
)
|
|
expect(verify.run).toContain('src/main/pty/codex-no-daemon-binary-contract.test.ts')
|
|
})
|
|
|
|
it('pins the project-trust contract to the no-daemon Codex and fails when it is missing', () => {
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex project-trust contract')
|
|
|
|
expect(verify.env.ORCA_CODEX_TRUST_CONTRACT_VERSION).toBe(
|
|
'${{ env.CODEX_NO_DAEMON_CLI_VERSION }}'
|
|
)
|
|
expect(verify.env.ORCA_CODEX_TRUST_CONTRACT_REQUIRED).toBe('1')
|
|
expect(verify.run).toContain(
|
|
'ORCA_CODEX_TRUST_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli-no-daemon/node_modules/.bin/codex"'
|
|
)
|
|
expect(verify.run).toContain('src/main/agent-trust-presets.test.ts')
|
|
})
|
|
})
|