base.spec.ts 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263
  1. /**
  2. * The bundle's substance is its patch file: the `dsh.bundle.patch` manifest
  3. * field must name a real, parseable patch list.
  4. */
  5. import { readFileSync } from 'node:fs'
  6. import { fileURLToPath } from 'node:url'
  7. import { resolve } from 'node:path'
  8. import { describe, expect, it } from 'vitest'
  9. import * as yaml from 'js-yaml'
  10. import { entryListSchema } from '@deepseek-ai/cordis-plugin-include'
  11. describe('dsh-base bundle', () => {
  12. it('declares a parseable patch list through the dsh.bundle.patch manifest field', () => {
  13. const root = fileURLToPath(new URL('..', import.meta.url))
  14. const manifest = JSON.parse(
  15. readFileSync(resolve(root, 'package.json'), 'utf8'),
  16. ) as { dsh?: { bundle?: { patch?: string } } }
  17. expect(manifest.dsh?.bundle?.patch).toBe('./cordis.patch.yml')
  18. const parsed = yaml.load(
  19. readFileSync(resolve(root, manifest.dsh!.bundle!.patch!), 'utf8'),
  20. { schema: entryListSchema },
  21. )
  22. expect(Array.isArray(parsed)).toBe(true)
  23. // The base layer is one insert list over the empty profile root.
  24. const rows = (parsed as { insert?: { id?: string }[] }[]).flatMap(
  25. patch => patch.insert ?? [],
  26. )
  27. expect(rows.length).toBeGreaterThan(50)
  28. expect(rows.some(row => row.id === 'agent-loop')).toBe(true)
  29. })
  30. it('ships the Windows platform layer as the confined pwsh roster over the ACL runner chain', () => {
  31. const root = fileURLToPath(new URL('..', import.meta.url))
  32. const parsed = yaml.load(
  33. readFileSync(resolve(root, 'windows.cordis.patch.yml'), 'utf8'),
  34. { schema: entryListSchema },
  35. ) as {
  36. id?: string
  37. disabled?: boolean
  38. insert?: { id?: string; name?: string }[]
  39. config?: { policy?: string }
  40. }[]
  41. const disables = parsed
  42. .filter(patch => patch.disabled === true)
  43. .map(patch => patch.id)
  44. // Only the POSIX bash stack is disabled: the Windows roster confines the
  45. // pwsh executor through the ACL runner chain, so the sandbox/policy rows,
  46. // the permission switcher, fs-sandbox, and the approval service all stay
  47. // enabled exactly as on POSIX — only the shell is swapped.
  48. expect(disables).toEqual(['bash-sandbox', 'tool-bash'])
  49. const inserted = parsed
  50. .flatMap(patch => patch.insert ?? [])
  51. .map(row => row.id)
  52. expect(inserted).toEqual(['pwsh-sandbox', 'tool-pwsh'])
  53. // The patch no longer touches the permission/approval surface at all.
  54. expect(parsed.find(patch => patch.id === 'approval')).toBeUndefined()
  55. expect(parsed.find(patch => patch.id === 'permission')).toBeUndefined()
  56. expect(parsed.find(patch => patch.id === 'sandbox')).toBeUndefined()
  57. expect(parsed.find(patch => patch.id === 'sandbox-policy')).toBeUndefined()
  58. expect(parsed.find(patch => patch.id === 'fs-sandbox')).toBeUndefined()
  59. })
  60. })