run-tests.fish executes under the config it tests, which shadows cp, rm and cat. The real hazard is cp: the config aliases it to 'cp -i', which on a non-empty destination reads EOF in a non-interactive runner, silently skips the copy and exits 0 -- a sandbox missing config files, reported as success. rm -rf and cat were measured and behave correctly as-is (the rm wrapper bails to command rm on any non-recursive flag, so -rf really deletes and does not trash). Prefixed anyway: a test runner must not depend on the configuration under test.
146 lines
6.0 KiB
Fish
Executable File
146 lines
6.0 KiB
Fish
Executable File
#!/usr/bin/env fish
|
|
# Copyright (C) 2026 Rootiest
|
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
|
#
|
|
# CI test runner for this fish configuration.
|
|
# 1. Syntax-lints every tracked .fish file (fish -n).
|
|
# 2. Copies the config-relevant files into a throwaway sandbox (never
|
|
# the live checkout -- this repo doubles as a real ~/.config/fish,
|
|
# so a symlinked sandbox would let universal-variable writes like
|
|
# first-run's escape into the real, gitignored fish_variables file)
|
|
# and loads it as an isolated interactive session.
|
|
# 3. Runs the functional checks in tests/functional.fish inside that
|
|
# loaded session.
|
|
# 4. Runs tests/test-agents-vault.fish as its own process; that suite
|
|
# builds its own throwaway repos and needs no loaded config.
|
|
#
|
|
# Usage: fish tests/run-tests.fish
|
|
|
|
set -l script_dir (realpath (dirname (status filename)))
|
|
set -l repo_root (realpath $script_dir/..)
|
|
set -l overall_failed 0
|
|
|
|
# ---- Phase 1: syntax lint ------------------------------------------------
|
|
echo "== Syntax lint =="
|
|
set -l lint_files $repo_root/config.fish
|
|
for dir in functions conf.d completions integrations
|
|
set -a lint_files (find $repo_root/$dir -name '*.fish' | sort)
|
|
end
|
|
|
|
set -l lint_failed 0
|
|
for f in $lint_files
|
|
set -l out (fish -n $f 2>&1)
|
|
if test $status -ne 0
|
|
echo " FAIL "(string replace $repo_root/ '' $f)
|
|
printf '%s\n' $out
|
|
set lint_failed (math $lint_failed + 1)
|
|
end
|
|
end
|
|
set -l lint_total (count $lint_files)
|
|
echo (math $lint_total - $lint_failed)"/$lint_total files passed lint"
|
|
if test $lint_failed -ne 0
|
|
set overall_failed 1
|
|
end
|
|
|
|
# ---- Phase 2: isolated load + functional checks --------------------------
|
|
echo ""
|
|
echo "== Sandboxed load + functional checks =="
|
|
|
|
set -l sandbox (mktemp -d)
|
|
set -l sandbox_cfg $sandbox/xdgcfg/fish
|
|
mkdir -p $sandbox_cfg
|
|
# path-setup only adds directories that already exist (fish_add_path is a
|
|
# no-op on missing paths), so give it $HOME/.local/bin to find.
|
|
mkdir -p $sandbox/home/.local/bin
|
|
|
|
# Every utility below goes through `command`. This driver runs under the
|
|
# very config it tests, which shadows these: `cp` is an alias for `cp -i`,
|
|
# `rm` is a trash wrapper, `cat` resolves to bat. Only `cp` is an actual
|
|
# hazard today -- `-i` on a non-empty destination reads EOF in a
|
|
# non-interactive runner and SILENTLY SKIPS the copy while exiting 0,
|
|
# which would leave the sandbox missing config files and report success.
|
|
# `rm -rf` and `cat` were measured and behave correctly as-is (the rm
|
|
# wrapper bails to `command rm` on any non-recursive flag, so -rf really
|
|
# deletes and does not trash). Prefixed anyway: a test runner must not
|
|
# depend on the configuration under test.
|
|
command cp $repo_root/config.fish $sandbox_cfg/
|
|
test -f $repo_root/fish_plugins
|
|
and command cp $repo_root/fish_plugins $sandbox_cfg/
|
|
for d in functions conf.d completions integrations themes data
|
|
test -d $repo_root/$d
|
|
and command cp -r $repo_root/$d $sandbox_cfg/
|
|
end
|
|
|
|
set -l err_file (mktemp)
|
|
env -i \
|
|
HOME=$sandbox/home \
|
|
XDG_CONFIG_HOME=$sandbox/xdgcfg \
|
|
PATH="$PATH" \
|
|
TERM=xterm \
|
|
__fish_config_op_autoexec=off \
|
|
fish -i -c "source $repo_root/tests/functional.fish; functional_test_main" \
|
|
2>$err_file
|
|
set -l functional_status $status
|
|
|
|
set -l stderr_out (command cat $err_file)
|
|
command rm -rf $sandbox $err_file
|
|
|
|
if test -n "$stderr_out"
|
|
# Diagnostic only, not a gate: on machines with vendor fish configs
|
|
# (e.g. CachyOS's cachyos-fish-config, which this repo's config.fish
|
|
# sources when present) unrelated vendor warnings can land here. Real
|
|
# breakage in this repo's own code is caught by the assertions below.
|
|
echo " Session stderr output (informational):"
|
|
printf '%s\n' $stderr_out
|
|
end
|
|
|
|
if test $functional_status -ne 0
|
|
set overall_failed 1
|
|
end
|
|
|
|
# ---- Phase 3: hermetic vault helper tests --------------------------------
|
|
# Run as its own fish process rather than inside the sandboxed session:
|
|
# the suite builds its own throwaway git repos and binds the vault, claude
|
|
# and agy roots to them, so it needs no loaded config and must never see
|
|
# the real ~/.claude.
|
|
#
|
|
# HOME is deliberately NOT overridden here. Read this before "improving" it.
|
|
#
|
|
# Overriding XDG_CONFIG_HOME/XDG_DATA_HOME plus --no-config is what makes
|
|
# this run isolated: the universal-variable file fish can reach is a fresh
|
|
# empty one, and no config.fish/conf.d is loaded. Without that, an
|
|
# "isolated" suite runs against the user's LIVE config and real universal
|
|
# variables -- this repo doubles as a real ~/.config/fish -- so a test
|
|
# doing `set -e __fish_config_op_logging` would erase a real universal
|
|
# variable out of the running shell. Measured:
|
|
# $__fish_config_op_registry_keys has 65 entries under a plain `fish`, 0
|
|
# under `fish --no-config`.
|
|
#
|
|
# `env -i HOME=$sandbox` was tried and REJECTED. It looks strictly more
|
|
# hermetic, but test-agents-vault.fish's hermeticity floor snapshots the
|
|
# real $HOME/.claude/memory and $HOME/.gemini/antigravity-cli and asserts
|
|
# them unchanged at the end. Point HOME at a sandbox and both snapshots
|
|
# read "absent" before and after: the assertions still pass while
|
|
# asserting nothing. A change that turns a real assertion into a tautology
|
|
# without turning anything red is the worst failure mode a test harness
|
|
# has. Keeping HOME real is what keeps those two assertions biting.
|
|
#
|
|
# Overriding XDG_DATA_HOME is a hermeticity gain on top of the isolation:
|
|
# _agents_vault_dir falls back to
|
|
# ${XDG_DATA_HOME:-$HOME/.local/share}/agent-vault, so a vault path that
|
|
# no test overrode lands in a temp dir instead of the user's real
|
|
# ~/.local/share/agent-vault.
|
|
echo ""
|
|
echo "== Vault helper tests =="
|
|
set -l vault_xdg (mktemp -d)
|
|
env XDG_CONFIG_HOME=$vault_xdg/cfg XDG_DATA_HOME=$vault_xdg/data \
|
|
fish --no-config $repo_root/tests/test-agents-vault.fish
|
|
if test $status -ne 0
|
|
set overall_failed 1
|
|
end
|
|
# `command rm`, not bare `rm`: this driver runs under the config it tests,
|
|
# which shadows rm/cp/cat. See the Phase 2 note for the full reasoning.
|
|
command rm -rf $vault_xdg
|
|
|
|
exit $overall_failed
|