From 197b5464950764efff76631114db05737e06e4b9 Mon Sep 17 00:00:00 2001 From: "sec-check[bot]" Date: Sat, 12 Sep 2026 00:10:30 -0400 Subject: [PATCH] [architect] test: repair broken-at-birth suites surfaced by common#1105 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two suites fail on main today but are invisible because CI never runs them (12 of 33 bats suites are ungated — see #1105): - test_ujust.bats: the setup() mock brew exits 1 on any subcommand outside install/shellenv. Recipes grew 'brew bundle' calls in #1023, so all four install-ai-tools tests and the bluespeed present-case test fail. Mock now accepts bundle. - test_shared_just.bats: two powerwash tests asserted delegation to 'bctl powerwash'; that delegation was removed in #1083 five days before the tests were written. Rewritten to assert the current contract: gum double-confirmation -> sudo bootc install reset --experimental, and no bctl invocation even when bctl is on PATH. Both suites now pass locally (26/26). This is the test-side enabler for the derived-catalog CI gate proposed in #1105; the unit-tests.yml change itself is currently blocked on the App token missing the workflows scope. Refs #1105 (left open: unit-tests.yml catalog derivation and Justfile enumeration dedup still outstanding) Signed-off-by: sec-check[bot] --- tests/test_shared_just.bats | 18 +++++++++++------- tests/test_ujust.bats | 2 ++ 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/tests/test_shared_just.bats b/tests/test_shared_just.bats index bf34841a..5fa9b947 100644 --- a/tests/test_shared_just.bats +++ b/tests/test_shared_just.bats @@ -86,25 +86,29 @@ _calls() { [ "${output}" = "#!/usr/bin/bash" ] } -@test "powerwash: delegates to bctl when bctl is available" { +@test "powerwash: two confirmations run bootc install reset via sudo" { _queue_answers "Yes - wipe this machine" "Yes - wipe this machine" - _run_powerwash with-bctl + _run_powerwash [ "${status}" -eq 0 ] - run grep -Fq "bctl powerwash" <<< "$(_calls)" + run grep -Fqx "sudo bootc install reset --experimental" <<< "$(_calls)" [ "${status}" -eq 0 ] + # Both confirmations were prompted before any destructive call. + [ "$(grep -c '^gum ' <<< "$(_calls)")" -eq 2 ] } -@test "powerwash: bctl delegation skips gum prompts and sudo entirely" { +@test "powerwash: never invokes bctl even when bctl is on PATH" { + # bctl delegation was removed in #1083; the recipe owns the flow directly. _queue_answers "Yes - wipe this machine" "Yes - wipe this machine" _run_powerwash with-bctl - run grep -q "^gum " <<< "$(_calls)" - [ "${status}" -ne 0 ] - run grep -q "^sudo " <<< "$(_calls)" + [ "${status}" -eq 0 ] + run grep -q "^bctl " <<< "$(_calls)" [ "${status}" -ne 0 ] + run grep -Fqx "sudo bootc install reset --experimental" <<< "$(_calls)" + [ "${status}" -eq 0 ] } @test "powerwash: declining the first confirmation cancels without wiping" { diff --git a/tests/test_ujust.bats b/tests/test_ujust.bats index 5575bfc1..46d87c81 100644 --- a/tests/test_ujust.bats +++ b/tests/test_ujust.bats @@ -21,6 +21,8 @@ case "$1" in shellenv) printf 'export PATH="%s/bin:$PATH"\n' "${MOCK_PREFIX}" ;; + bundle) + ;; *) exit 1 ;;