diff options
| author | godosa <godosa@godosa.eu> | 2026-10-07 07:44:16 +0200 |
|---|---|---|
| committer | godosa <godosa@godosa.eu> | 2026-10-07 07:44:16 +0200 |
| commit | 9d5641fe6585a61894f7b7427a68c794e5efe76d (patch) | |
| tree | 79ebae3131df1c50542420db9e5ecb44e3d22076 /tests/test_publish_snapshot.py | |
| parent | 81d4e80fd5aabe4e80f58e960affa795cf7d34ec (diff) | |
| download | workflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.tar.gz workflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.zip | |
Denylist guard at commit time (pre-commit + commit-msg hooks); drop publish_snapshot
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JEAjUkQRrCYX5MZhWxdtj2
Diffstat (limited to 'tests/test_publish_snapshot.py')
| -rw-r--r-- | tests/test_publish_snapshot.py | 122 |
1 files changed, 0 insertions, 122 deletions
diff --git a/tests/test_publish_snapshot.py b/tests/test_publish_snapshot.py deleted file mode 100644 index 3243d4b..0000000 --- a/tests/test_publish_snapshot.py +++ /dev/null @@ -1,122 +0,0 @@ -import os -import subprocess -import sys -import tempfile -import unittest -from pathlib import Path - -SCRIPT = Path(__file__).resolve().parent.parent / "scripts" / "publish_snapshot.py" -ENV = {**os.environ, "GIT_AUTHOR_NAME": "t", "GIT_AUTHOR_EMAIL": "t@t", "GIT_COMMITTER_NAME": "t", - "GIT_COMMITTER_EMAIL": "t@t", "GIT_CONFIG_GLOBAL": "/dev/null"} - - -def git(cwd, *args): - return subprocess.run(["git", *args], cwd=cwd, capture_output=True, text=True, env=ENV, check=True).stdout - - -class PublishSnapshotTest(unittest.TestCase): - def setUp(self): - self.tmp = tempfile.TemporaryDirectory() - t = Path(self.tmp.name) - self.src, self.dest, self.deny = t / "tool", t / "pub", t / "deny.txt" - self.src.mkdir() - git(self.src, "init", "-q", "-b", "master") - self.put({"wf.py": "print('hi')\n", "CHANGES.md": "# Changes\n\n- 2026-01-01 first.\n", - "wflib/a.py": "x = 1\n", "docs/d.md": "doc\n", - "inbox.md": "tracked inbox\n", "out/log": "x\n", "sub/__pycache__/c.pyc": "bin\n"}) - (self.src / "wf.py").chmod(0o755) - self.commit("one") - self.deny.write_text("# private\nSecretProj\n\n") - - def tearDown(self): - self.tmp.cleanup() - - def put(self, files): - for p, text in files.items(): - f = self.src / p - f.parent.mkdir(parents=True, exist_ok=True) - f.write_text(text) - - def commit(self, msg): - git(self.src, "add", "-A") - git(self.src, "commit", "-qm", msg) - - def run_it(self, *extra): - return subprocess.run([sys.executable, str(SCRIPT), str(self.dest), "--src", str(self.src), - "--denylist", str(self.deny), *extra], capture_output=True, text=True, env=ENV) - - def files(self): - return sorted(git(self.dest, "ls-files").split()) - - def test_first_run_one_commit_excludes(self): - r = self.run_it() - self.assertEqual(r.returncode, 0, r.stderr) - self.assertEqual(self.files(), ["CHANGES.md", "docs/d.md", "wf.py", "wflib/a.py"]) - self.assertEqual(git(self.dest, "log", "--format=%s").splitlines(), ["initial public snapshot"]) - self.assertTrue(os.access(self.dest / "wf.py", os.X_OK)) - self.assertEqual(git(self.dest, "remote"), "") - - def test_denylist_hit_content_and_path_writes_nothing(self): - self.put({"docs/d.md": "doc\nsee secretproj here\n", "SecretProj.md": "x\n"}) - self.commit("leak") - r = self.run_it() - self.assertEqual(r.returncode, 1) - self.assertIn("docs/d.md:2: SecretProj", r.stderr) - self.assertIn("SecretProj.md: SecretProj (path)", r.stderr) - self.assertFalse(self.dest.exists()) - - def test_uncommitted_files_not_published(self): - (self.src / "wip.py").write_text("SecretProj\n") - r = self.run_it() - self.assertEqual(r.returncode, 0, r.stderr) - self.assertNotIn("wip.py", self.files()) - - def test_missing_or_empty_denylist_refuses(self): - self.deny.unlink() - r = self.run_it() - self.assertEqual(r.returncode, 1) - self.assertIn("no denylist", r.stderr) - self.deny.write_text("# only comments\n") - self.assertEqual(self.run_it().returncode, 1) - self.assertFalse(self.dest.exists()) - - def test_second_run_commit_message_new_changes_lines(self): - self.run_it() - self.put({"CHANGES.md": "# Changes\n\n- 2026-01-03 third.\n- 2026-01-02 second.\n- 2026-01-01 first.\n", - "wflib/b.py": "y = 2\n"}) - (self.src / "docs/d.md").unlink() - self.commit("two") - r = self.run_it() - self.assertEqual(r.returncode, 0, r.stderr) - self.assertEqual(git(self.dest, "log", "-1", "--format=%B").strip(), - "public snapshot\n\n- 2026-01-03 third.\n- 2026-01-02 second.") - self.assertEqual(self.files(), ["CHANGES.md", "wf.py", "wflib/a.py", "wflib/b.py"]) - self.assertEqual(len(git(self.dest, "log", "--format=%h").split()), 2) - - def test_no_change_no_commit(self): - self.run_it() - r = self.run_it() - self.assertEqual(r.returncode, 0, r.stderr) - self.assertIn("nothing new", r.stdout) - self.assertEqual(len(git(self.dest, "log", "--format=%h").split()), 1) - - def test_ref_option_and_never_touches_remote(self): - self.run_it() - git(self.dest, "remote", "add", "home", "/nonexistent") - self.put({"wflib/a.py": "x = 2\n"}) - self.commit("two") - self.assertEqual(self.run_it("--ref", "HEAD~1").stdout.strip(), "nothing new: no commit") - r = self.run_it() - self.assertIn("committed", r.stdout) - self.assertEqual(git(self.dest, "remote").split(), ["home"]) - - def test_nonempty_non_git_dest_refused(self): - self.dest.mkdir() - (self.dest / "keep.txt").write_text("x") - r = self.run_it() - self.assertEqual(r.returncode, 1) - self.assertIn("not a git repo", r.stderr) - - -if __name__ == "__main__": - unittest.main() |
