fix(deploy): stub git status in the simulation harness
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m37s
CI / tests-unit (push) Successful in 1m39s
CI / tests-ui (push) Successful in 2m20s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 3m6s

The clean-tree guard in ci-deploy.sh aborts the release when
`git status --porcelain` prints anything. The harness stubs `git` as a
shell function that only special-cases `rev-parse`; every other
subcommand fell through to its `ls-remote`-shaped printf, so `git status`
emitted a fake refs/heads/main line and the guard failed on every
scenario.

Introduced in fdb7af7e, which added the guard without teaching the
harness about it, so all 21 deploy tests have been failing since. This
stubs `status` to report a clean tree, and adds a scenario that asserts
the guard actually stops a release before it builds, migrates or starts
anything — the guard itself had no coverage, which is how it could break
silently in the first place.
This commit is contained in:
openhands committed 2026-10-10 17:26:12 +02:00
1 parent adffac7360
commit 6793f77733
2 files changed
+19

No files matched your search

+11
View File
@@ -169,6 +169,17 @@ describe("deployment transaction", () => {
expect(result.output).toContain("No previous container exists");
expect(result.app).toBeNull();
});
// The image is tagged with the commit SHA, so a dirty tree would ship
// uncommitted code under a label that claims otherwise. The guard has to
// stop the release before anything is built or migrated.
it("refuses to release from a dirty working tree", () => {
const result = simulate("dirty-tree");
expect(result.status, result.output).not.toBe(0);
expect(result.output).toContain("de werkboom is niet schoon");
expect(result.calls).not.toContain("docker build");
expect(result.calls).not.toContain("pnpm db:migrate");
expect(result.calls).not.toContain("docker run");
});
});
describe("legacy and CI container coexistence", () => {
+8
View File
@@ -1,6 +1,14 @@
# Sourced only by the deployment simulation tests; no external services are used.
git() {
if [ "$1" = rev-parse ]; then printf '%s\n' "$TEST_SHA"; return; fi
# `git status --porcelain` is the script's clean-tree guard: empty stdout
# means clean, any output aborts the release before it builds an image. It
# needs its own stub — falling through to the ls-remote-shaped printf below
# would always report a dirty tree and fail every scenario.
if [ "$1" = status ]; then
[ "$SCENARIO" = dirty-tree ] && printf ' M src/leaked-file.ts\n'
return 0
fi
local n=0
if [ -f "$TEST_DIR/remote-count" ]; then read -r n < "$TEST_DIR/remote-count"; fi
n=$((n+1)); printf '%s\n' "$n" > "$TEST_DIR/remote-count"