Files
OmniRoute/tests/unit/radar-intel-routes.test.ts
Diego Rodrigues de Sa e Souza 3d4f3e4960 test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966) (#11968)
* test(infra): retry recursive temp-dir removal instead of failing a shard on ENOTEMPTY (#11966)

Two shards on release/v3.8.51 went red in one day with the same signature —
"ENOTEMPTY, Directory not empty: /tmp/omniroute-<test>-XXXXXX" — from
combo-same-provider-cascade (Unit Tests fast-path 4/4, on a PR that touches only
.github/) and auth-policy-embeddings-webfetch-7785 (the 20k-test TIA step). Both pass
alone and on re-run: the cleanup races something still writing into the directory
(SQLite WAL/-shm checkpoint, a worker, the backup) and under a loaded hosted runner
the window opens. 1154 test files do their own cleanup with
fs.rmSync(dir, { recursive: true, force: true }); 57 already asked for retries.

One-shot codemod (scripts/ad-hoc/codemod-rm-maxretries.mjs, kept for the record):
every rm / rmSync / rmdirSync option object with `recursive: true` and no
`maxRetries` gains `maxRetries: 5, retryDelay: 100` — Node itself then retries
ENOTEMPTY/EBUSY/EPERM for up to ~0.5 s before giving up. 2243 call sites in 1292
files under tests/, the shared tests/_setup/isolateDataDir.ts exit hook included.
Only the option object changes: no call site, assertion or import is touched.

Validation: prettier and ESLint (with the frozen suppressions) clean on all 1292
files; a random 20-file sample runs green (quota-redis-store hangs identically on
the untouched tree — it needs a Redis on localhost, an environment matter). The
four unit shards on this PR are the full run.

* fix(quality): let check-forgotten-sibling-tests read a 1,000-file diff

The gate shells out to `git diff` through execFileSync with Node's default 1 MB
maxBuffer; the 1,292-file codemod in this PR is the first diff large enough to
overflow it, and the gate died with `spawnSync git ENOBUFS` before comparing
anything. 64 MB is far above any real PR and costs nothing when unused.
2026-08-29 01:17:40 -03:00

157 lines
5.9 KiB
TypeScript

import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import test from "node:test";
import { SignJWT } from "jose";
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-radar-intel-routes-"));
process.env.DATA_DIR = TEST_DATA_DIR;
process.env.STORAGE_ENCRYPTION_KEY = "test-encryption-key-for-radar-intel-routes-32b!";
process.env.JWT_SECRET = "test-jwt-secret-for-radar-intel-routes";
process.env.INITIAL_PASSWORD = "test-bootstrap-password-for-radar-intel-routes";
const core = await import("../../src/lib/db/core.ts");
const radarDb = await import("../../src/lib/db/radar.ts");
async function authHeaders(): Promise<Record<string, string>> {
const token = await new SignJWT({ authenticated: true })
.setProtectedHeader({ alg: "HS256" })
.setIssuedAt()
.setExpirationTime("1h")
.sign(new TextEncoder().encode(process.env.JWT_SECRET));
return { Cookie: `auth_token=${token}` };
}
function request(pathname: string, method: "GET" | "POST", headers: Record<string, string> = {}) {
return new Request(`http://localhost:20128${pathname}`, { method, headers });
}
function resetStorage(): void {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true, maxRetries: 5, retryDelay: 100 });
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
}
test.after(() => {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true, maxRetries: 5, retryDelay: 100 });
delete process.env.RADAR_ENABLED;
});
test("Intel, status, and aggregate sync routes are 404 before auth when flag is off", async () => {
resetStorage();
delete process.env.RADAR_ENABLED;
const intel = await import("../../src/app/api/radar/intel/route.ts");
const intelSync = await import("../../src/app/api/radar/intel/sync/route.ts");
const status = await import("../../src/app/api/radar/status/route.ts");
const syncAll = await import("../../src/app/api/radar/sync-all/route.ts");
assert.equal((await intel.GET(request("/api/radar/intel", "GET"))).status, 404);
assert.equal((await intelSync.POST(request("/api/radar/intel/sync", "POST"))).status, 404);
assert.equal((await status.GET(request("/api/radar/status", "GET"))).status, 404);
assert.equal((await syncAll.POST(request("/api/radar/sync-all", "POST"))).status, 404);
});
test("verified local Intel is returned without supporter identity or key material", async () => {
resetStorage();
process.env.RADAR_ENABLED = "true";
const payload = fs.readFileSync(
path.resolve(process.cwd(), "tests/fixtures/radar-intel-canonical.json"),
"utf8"
);
radarDb.setRadarIntelCache({
version: "2026.08.09.1",
tier: "live",
payload,
signature: "fixture-signature",
supporterIdentity: `radar:${"a".repeat(64)}`,
fetchedAt: "2026-08-09T12:05:00.000Z",
});
const { GET } = await import("../../src/app/api/radar/intel/route.ts");
const response = await GET(request("/api/radar/intel", "GET", await authHeaders()));
const body = await response.json();
assert.equal(response.status, 200);
assert.equal(body.intel.rankings.length, 2);
assert.equal(body.meta.supporterVerified, true);
assert.ok(!JSON.stringify(body).includes("radar:"));
assert.ok(!JSON.stringify(body).includes("omr_"));
});
test("Radar status is read-only and aggregate sync reports each feed separately", async () => {
resetStorage();
process.env.RADAR_ENABLED = "true";
const headers = await authHeaders();
const statusRoute = await import("../../src/app/api/radar/status/route.ts");
const status = await statusRoute.GET(request("/api/radar/status", "GET", headers));
const statusBody = await status.json();
assert.deepEqual(statusBody.settings, { optIn: false, hasSupporterKey: false });
assert.deepEqual(Object.keys(statusBody.feeds).sort(), [
"catalog",
"intel",
"offers",
"referrals",
]);
const syncAllRoute = await import("../../src/app/api/radar/sync-all/route.ts");
const synced = await syncAllRoute.POST(request("/api/radar/sync-all", "POST", headers));
const syncBody = await synced.json();
assert.deepEqual(syncBody, {
catalog: { status: "opt_out" },
referrals: { status: "opt_out" },
offers: { status: "opt_out" },
intel: { status: "opt_out" },
});
});
test("aggregate sync rejects an arbitrary JSON body before invoking any feed", async () => {
resetStorage();
process.env.RADAR_ENABLED = "true";
const syncAllRoute = await import("../../src/app/api/radar/sync-all/route.ts");
const response = await syncAllRoute.POST(
new Request("http://localhost:20128/api/radar/sync-all", {
method: "POST",
headers: { ...(await authHeaders()), "content-type": "application/json" },
body: JSON.stringify({ unexpected: true }),
})
);
assert.equal(response.status, 400);
assert.deepEqual(await response.json(), {
error: { message: "Invalid request body", type: "invalid_request_error", code: "bad_request" },
});
});
test("aggregate sync returns sanitized errors for oversized and failed body streams", async () => {
resetStorage();
process.env.RADAR_ENABLED = "true";
const syncAllRoute = await import("../../src/app/api/radar/sync-all/route.ts");
const headers = await authHeaders();
const oversized = await syncAllRoute.POST(
new Request("http://localhost:20128/api/radar/sync-all", {
method: "POST",
headers,
body: " ".repeat(1025),
})
);
const failedStream = new ReadableStream<Uint8Array>({
start(controller) {
controller.error(new Error("transport-secret"));
},
});
const failed = await syncAllRoute.POST(
new Request("http://localhost:20128/api/radar/sync-all", {
method: "POST",
headers,
body: failedStream,
duplex: "half",
} as RequestInit & { duplex: "half" })
);
assert.equal(oversized.status, 413);
assert.equal(failed.status, 400);
assert.doesNotMatch(JSON.stringify(await failed.json()), /transport-secret|stack/i);
});