Files
OmniRoute/tests/unit/cli-tools-apply-container-422.test.ts
Diego Rodrigues de Sa e Souza 3d4f3e4960 test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966) (#11968)
* test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966)

Two shards on release/v3.8.51 went red in one day with the same signature —
"ENOTEMPTY, Directory not empty: /tmp/omniroute-<test>-XXXXXX" — from
combo-same-provider-cascade (Unit Tests fast-path 4/4, on a PR that touches only
.github/) and auth-policy-embeddings-webfetch-7785 (the 20k-test TIA step). Both pass
alone and on re-run: the cleanup races something still writing into the directory
(SQLite WAL/-shm checkpoint, a worker, the backup) and under a loaded hosted runner
the window opens. 1154 test files do their own cleanup with
fs.rmSync(dir, { recursive: true, force: true }); 57 already asked for retries.

One-shot codemod (scripts/ad-hoc/codemod-rm-maxretries.mjs, kept for the record):
every rm / rmSync / rmdirSync option object with `recursive: true` and no
`maxRetries` gains `maxRetries: 5, retryDelay: 100` — Node itself then retries
ENOTEMPTY/EBUSY/EPERM for up to ~0.5 s before giving up. 2243 call sites in 1292
files under tests/, the shared tests/_setup/isolateDataDir.ts exit hook included.
Only the option object changes: no call site, assertion or import is touched.

Validation: prettier and ESLint (with the frozen suppressions) clean on all 1292
files; a random 20-file sample runs green (quota-redis-store hangs identically on
the untouched tree — it needs a Redis on localhost, an environment matter). The
four unit shards on this PR are the full run.

* fix(quality): let check-forgotten-sibling-tests read a 1,000-file diff

The gate shells out to `git diff` through execFileSync with Node's default 1 MB
maxBuffer; the 1,292-file codemod in this PR is the first diff large enough to
overflow it, and the gate died with `spawnSync git ENOBUFS` before comparing
anything. 64 MB is far above any real PR and costs nothing when unused.
2026-08-29 01:17:40 -03:00

166 lines
6.0 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { pathToFileURL } from "node:url";
/**
* POST /api/cli-tools/apply writes host CLI config files. Inside a container
* with no bind mount that write is thrown away with the container, so the route
* must refuse with a structured 422 instead of reporting success.
*/
const routePath = path.join(process.cwd(), "src/app/api/cli-tools/apply/route.ts");
const originalEnv = { ...process.env };
const tempDirs = new Set<string>();
async function importRoute(label: string) {
return import(`${pathToFileURL(routePath).href}?case=${label}-${Date.now()}-${Math.random()}`);
}
function restoreEnv() {
for (const key of Object.keys(process.env)) {
if (!(key in originalEnv)) delete process.env[key];
}
Object.assign(process.env, originalEnv);
}
test.afterEach(restoreEnv);
// The auth guard reads settings, which opens the SQLite singleton. Releasing it
// before the temp dirs go away keeps the node:test runner from hanging on an
// open handle (see AGENTS.md → "Database Handles in Tests").
test.after(async () => {
try {
const { resetDbInstance } = await import("../../src/lib/db/core.ts");
resetDbInstance();
} catch {
// the DB was never opened
}
for (const dir of tempDirs)
fs.rmSync(dir, { recursive: true, force: true, maxRetries: 5, retryDelay: 100 });
});
function applyRequest(body: Record<string, unknown>) {
return new Request("http://localhost:20128/api/cli-tools/apply", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ toolId: "codex", apiKey: "sk-test", ...body }),
});
}
test("refuses with 422 and does not write when the target is container-ephemeral", async () => {
// OMNIROUTE_CONTAINER forces detection; the fake HOME has no bind mount, so
// the target classifies as ephemeral.
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-apply-ephemeral-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "1";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
delete process.env.OMNIROUTE_ALLOW_CONTAINER_CONFIG_WRITE;
const { POST } = await importRoute("ephemeral");
const response = await POST(applyRequest({}));
assert.equal(response.status, 422);
const body = await response.json();
assert.equal(body.containerEphemeralTarget, true);
assert.equal(body.hostSetupCommand, "omniroute setup-codex");
assert.match(body.error, /Refusing to write/);
assert.match(body.error, /omniroute connect/);
// Nothing may hit disk.
assert.equal(fs.existsSync(path.join(fakeHome, ".codex")), false);
});
test("the 422 body carries no stack trace", async () => {
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-apply-stack-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "1";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
const { POST } = await importRoute("nostack");
const body = await (await POST(applyRequest({}))).json();
assert.ok(!body.error.includes("at /"), "error must not leak a stack trace");
assert.ok(!body.error.includes(".ts:"), "error must not leak source locations");
});
test("dry-run still previews the config inside a container", async () => {
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-apply-dry-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "1";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
const { POST } = await importRoute("dryrun");
const response = await POST(applyRequest({ dryRun: true }));
assert.equal(response.status, 200);
const body = await response.json();
assert.equal(body.dryRun, true);
});
test("OMNIROUTE_ALLOW_CONTAINER_CONFIG_WRITE lets the write through", async () => {
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-apply-override-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "1";
process.env.OMNIROUTE_ALLOW_CONTAINER_CONFIG_WRITE = "true";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
const { POST } = await importRoute("override");
const response = await POST(applyRequest({}));
assert.equal(response.status, 200);
const body = await response.json();
assert.equal(body.success, true);
assert.ok(fs.existsSync(body.configPath), `expected ${body.configPath} to be written`);
});
test("the dashboard's guide-settings writer refuses the same way", async () => {
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-guide-ephemeral-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "1";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
delete process.env.OMNIROUTE_ALLOW_CONTAINER_CONFIG_WRITE;
const guideRoute = path.join(
process.cwd(),
"src/app/api/cli-tools/guide-settings/[toolId]/route.ts"
);
const { POST } = await import(`${pathToFileURL(guideRoute).href}?case=guide-${Date.now()}`);
const response = await POST(
new Request("http://localhost:20128/api/cli-tools/guide-settings/continue", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ baseUrl: "http://localhost:20128/v1", model: "glm/glm-5.2" }),
}),
{ params: Promise.resolve({ toolId: "continue" }) }
);
assert.equal(response.status, 422);
const body = await response.json();
assert.equal(body.containerEphemeralTarget, true);
assert.equal(body.hostSetupCommand, "omniroute setup-continue");
assert.equal(fs.existsSync(path.join(fakeHome, ".continue")), false);
});
test("a host environment applies the config normally", async () => {
const fakeHome = fs.mkdtempSync(path.join(os.tmpdir(), "or-apply-host-"));
tempDirs.add(fakeHome);
process.env.OMNIROUTE_CONTAINER = "0";
process.env.HOME = fakeHome;
process.env.USERPROFILE = fakeHome;
const { POST } = await importRoute("host");
const response = await POST(applyRequest({}));
assert.equal(response.status, 200);
const body = await response.json();
assert.equal(body.success, true);
});