Files
orca/config/scripts/codex-index-heal-contract-workflow.test.mjs
T
Jinwoo Hong 9f4311598f fix(codex): trust the worktree Codex starts in, not a guessed repo root (#23937)
* fix(codex): trust the path Codex checks for bare-repo worktrees

Codex keys a linked worktree's trust on the main checkout only when that
checkout's .git leads back to the common git dir; otherwise (bare repo,
--separate-git-dir) it keys on the worktree itself. Orca always wrote the
main-checkout key, so Codex showed its trust prompt and worker-start
failed at agent_readiness.

Mirror trust.rs exactly, and pin it with a real-binary contract that
runs in the existing Codex contract CI job.

Fixes #23847

* fix(codex): trust the worktree path itself instead of mirroring trust.rs

Codex looks up the cwd's own [projects] entry before any repo root
(config_toml.rs get_active_project, loader decision_for_dir), so trusting
the workspace realpath satisfies every git layout. Drops the
resolve_root_git_project_for_trust mirror: simpler, cannot drift from
Codex, and never widens trust past the folder Orca launched in. Cost is
one config entry per worktree; entries older Orca wrote on main
checkouts stay valid.

The six real-git layout tests now assert the workspace key and, under
the contract, that real Codex starts workspaceWrite for each. The
contract probes the binary version once and fails at load when required
but missing; its CI path filter now includes config-toml-trust.
2026-09-29 20:27:02 -04:00

68 lines
3.3 KiB
JavaScript

import { readFileSync } from 'node:fs'
import { parse } from 'yaml'
import { describe, expect, it } from 'vitest'
describe('Codex index-heal contract PR gate', () => {
const workflow = parse(readFileSync('.github/workflows/pr.yml', 'utf8'))
const job = workflow.jobs.codex_index_heal_contract
it('installs and verifies against one pinned Codex version', () => {
const install = job.steps.find((step) => step.name === 'Install pinned Codex CLI')
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
// Why one source: the install and the runtime version assertion drifting apart is
// the failure that would leave this job verifying a Codex nobody declared.
expect(job.env.CODEX_CLI_VERSION).toMatch(/^\d+\.\d+\.\d+$/)
expect(install.run).toContain('"@openai/codex@$CODEX_CLI_VERSION"')
expect(verify.env.ORCA_CODEX_CONTRACT_VERSION).toBe('${{ env.CODEX_CLI_VERSION }}')
// The install prefix and the binary the test is pointed at must be the same tree.
expect(install.run).toContain('--prefix "$RUNNER_TEMP/codex-cli"')
expect(verify.run).toContain(
'ORCA_CODEX_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli/node_modules/.bin/codex"'
)
expect(verify.run).toContain('src/main/codex/codex-index-heal-binary-contract.test.ts')
})
it('fails rather than skipping when the Codex binary is missing', () => {
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
// Why asserted: the contract skips itself without a binary, so a failed install
// would otherwise turn this job into a green no-op that verifies nothing.
expect(verify.env.ORCA_CODEX_CONTRACT_REQUIRED).toBe('1')
expect(job.steps.find((step) => step.name === 'Install pinned Codex CLI').run).toContain(
'set -euo pipefail'
)
})
it('pins the --no-daemon contract to one Codex version and fails when it is missing', () => {
const install = job.steps.find((step) => step.name === 'Install pinned no-daemon Codex CLI')
const verify = job.steps.find((step) => step.name === 'Verify Codex --no-daemon contract')
expect(job.env.CODEX_NO_DAEMON_CLI_VERSION).toMatch(/^\d+\.\d+\.\d+$/)
expect(install.run).toContain('"@openai/codex@$CODEX_NO_DAEMON_CLI_VERSION"')
expect(verify.env.ORCA_CODEX_NO_DAEMON_CONTRACT_VERSION).toBe(
'${{ env.CODEX_NO_DAEMON_CLI_VERSION }}'
)
expect(verify.env.ORCA_CODEX_NO_DAEMON_CONTRACT_REQUIRED).toBe('1')
expect(install.run).toContain('--prefix "$RUNNER_TEMP/codex-cli-no-daemon"')
expect(verify.run).toContain(
'ORCA_CODEX_NO_DAEMON_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli-no-daemon/node_modules/.bin/codex"'
)
expect(verify.run).toContain('src/main/pty/codex-no-daemon-binary-contract.test.ts')
})
it('pins the project-trust contract to the no-daemon Codex and fails when it is missing', () => {
const verify = job.steps.find((step) => step.name === 'Verify Codex project-trust contract')
expect(verify.env.ORCA_CODEX_TRUST_CONTRACT_VERSION).toBe(
'${{ env.CODEX_NO_DAEMON_CLI_VERSION }}'
)
expect(verify.env.ORCA_CODEX_TRUST_CONTRACT_REQUIRED).toBe('1')
expect(verify.run).toContain(
'ORCA_CODEX_TRUST_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli-no-daemon/node_modules/.bin/codex"'
)
expect(verify.run).toContain('src/main/agent-trust-presets.test.ts')
})
})