Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
d68c6d4
guard activation and refresh tests with deterministic seams
TheGreenCedar Sep 28, 2026
f606477
merge guard-activation-tests
TheGreenCedar Sep 28, 2026
9938b94
bind symbol source reads to the indexed content hash
TheGreenCedar Sep 28, 2026
510efe1
merge source-bound-hydration
TheGreenCedar Sep 28, 2026
8155928
admit retained reads by operation class and stamp runtime freshness
TheGreenCedar Sep 28, 2026
ef21bb5
merge read-class-admission
TheGreenCedar Sep 28, 2026
47e840b
drop unused binding in multi-project contract test
TheGreenCedar Sep 28, 2026
a5aea5b
merge read-class-admission test cleanup
TheGreenCedar Sep 28, 2026
afed338
wait for a peer writer during activation refresh
TheGreenCedar Sep 28, 2026
2f5ef5c
merge peer-writer-wait
TheGreenCedar Sep 28, 2026
2bdb81d
index proof-resolution foreign keys before incremental cleanup
TheGreenCedar Sep 28, 2026
5982228
drop indexes conditionally in the staged-clone test
TheGreenCedar Sep 28, 2026
e55d84e
keep the legacy provenance control on the same proof index set
TheGreenCedar Sep 28, 2026
5a30aa8
preserve causal gaps through the public budget envelope
TheGreenCedar Sep 28, 2026
30eb7d2
merge proof-fact-fk-indexes
TheGreenCedar Sep 28, 2026
3b10499
merge kernel-budget-gap-projection
TheGreenCedar Sep 28, 2026
3aaece0
isolate runtime tests from ambient cache and scope retention to the r…
TheGreenCedar Sep 28, 2026
f061791
merge runtime-isolation
TheGreenCedar Sep 28, 2026
0791968
retarget retired-path tests at live search and coverage contracts
TheGreenCedar Sep 28, 2026
cace7f3
isolate ambient convenience-api tests from the process cache
TheGreenCedar Sep 28, 2026
8622819
repair publication test coverage and remove empty core stage dirs
TheGreenCedar Sep 28, 2026
abef326
merge runtime-retired-paths
TheGreenCedar Sep 28, 2026
61eb64c
merge runtime-publication
TheGreenCedar Sep 28, 2026
7d30f13
strengthen runtime assertion fixtures
TheGreenCedar Sep 28, 2026
d7ddd6f
make entry evidence decisive in orientation ranking fixture
TheGreenCedar Sep 28, 2026
192d1c7
pin ordinary-call censuses and receiver-spec results in indexer tests
TheGreenCedar Sep 28, 2026
19ddba8
merge runtime-assertions
TheGreenCedar Sep 28, 2026
c1f4714
merge indexer-call-census
TheGreenCedar Sep 28, 2026
69f3412
test: repair indexer audit rows and consolidate duplicates
TheGreenCedar Sep 28, 2026
daebe9a
merge indexer-rest
TheGreenCedar Sep 28, 2026
4cc85d8
test: repair store audit rows against live publication contracts
TheGreenCedar Sep 28, 2026
01186d2
merge store
TheGreenCedar Sep 28, 2026
be1a59c
recover stale-schema indexes, harden diagnostics, warn on scale envelope
TheGreenCedar Sep 28, 2026
3284b6d
format stdio_transport
TheGreenCedar Sep 28, 2026
d1f5293
merge issue-2531-recoverability
TheGreenCedar Sep 28, 2026
1c68983
report suppressed core gc, reclaim retired generation dirs, type peer…
TheGreenCedar Sep 29, 2026
0d25b14
prove non-recursive removal and writer-lock exclusion boundaries
TheGreenCedar Sep 29, 2026
5a1aa05
assert lock exclusion survives a writer timeout
TheGreenCedar Sep 29, 2026
5d7048e
keep owner records out of retention marker enumeration
TheGreenCedar Sep 29, 2026
2478022
log suppressed core retention after rehydrate
TheGreenCedar Sep 29, 2026
1e0cec1
merge issue-2531-retention-liveness
TheGreenCedar Sep 29, 2026
9405926
strengthen retrieval test contracts and fix windows path expectations
TheGreenCedar Sep 29, 2026
2bba936
gate test-support-only helpers and imports in retrieval tests
TheGreenCedar Sep 29, 2026
8976a31
normalize f013 measurement fixture vectors
TheGreenCedar Sep 29, 2026
adbdd45
merge retrieval
TheGreenCedar Sep 29, 2026
3eeef4e
isolate workspace git fixtures and strengthen finding repairs
TheGreenCedar Sep 29, 2026
6c2a2c1
derive expected workspace hash from a vector-validated reference fnv-1a
TheGreenCedar Sep 29, 2026
86a1eaa
pin rewrite-boundary rows to literal byte sizes
TheGreenCedar Sep 29, 2026
ed8354d
cover bare git literal in the plugin spawn-family scan
TheGreenCedar Sep 29, 2026
0fbe1b2
qualify unix-only isolated git imports
TheGreenCedar Sep 29, 2026
2459b0b
make the fsmonitor positive control viable on native windows
TheGreenCedar Sep 29, 2026
a43e026
make the fsmonitor positive control viable on native windows
TheGreenCedar Sep 29, 2026
521a033
merge workspace
TheGreenCedar Sep 29, 2026
d864b58
strengthen cli test contracts and unignore bounded runtime flows
TheGreenCedar Sep 29, 2026
eb0cf95
strengthen contracts, llama, bench and harness test proofs
TheGreenCedar Sep 29, 2026
6c7c6f4
merge cli
TheGreenCedar Sep 29, 2026
31c19f2
merge contracts-llama-bench
TheGreenCedar Sep 29, 2026
a090a5a
strengthen plugin, installer, and proof-harness test contracts
TheGreenCedar Sep 29, 2026
9f3efc2
fix windows-native plugin-static assertions for uri path form and sym…
TheGreenCedar Sep 29, 2026
faa1fe9
resolve npm.cmd absolutely so its self-prefix survives quoted invocation
TheGreenCedar Sep 29, 2026
0d78e09
merge plugin-scripts
TheGreenCedar Sep 29, 2026
af5c50a
repair final-gate drift, lint debt, and ambient gc lock leak
TheGreenCedar Sep 29, 2026
1919335
merge final-gate-fixes
TheGreenCedar Sep 29, 2026
88c904a
isolate retrieval unit tests from the ambient cache root
TheGreenCedar Sep 29, 2026
111795b
merge retrieval-test-root-isolation
TheGreenCedar Sep 29, 2026
1cae7db
canonicalize gix workdir and open mtime fixtures for write
TheGreenCedar Sep 29, 2026
d79090e
canonicalize go module test root for inventory spelling
TheGreenCedar Sep 29, 2026
44efb8b
prove temp-name collision skip with a planted occupied block
TheGreenCedar Sep 29, 2026
956c010
merge windows-workspace-identity
TheGreenCedar Sep 29, 2026
3e65fca
merge deterministic-collision-test
TheGreenCedar Sep 29, 2026
3cf13c4
keep staged replacement writable on windows
TheGreenCedar Sep 29, 2026
5bf92c4
retry managed cli staging rename on transient win32 holds
TheGreenCedar Sep 29, 2026
33f7988
pin trail story scope contract at its runtime producer
TheGreenCedar Sep 29, 2026
a540ddf
merge windows-immutable-replace
TheGreenCedar Sep 29, 2026
72f81dd
merge windows-provision-rename-retry
TheGreenCedar Sep 29, 2026
1f7754e
merge cli-trail-story-tests
TheGreenCedar Sep 29, 2026
37d9375
note windows fixes in changelog
TheGreenCedar Sep 29, 2026
ecc06ed
rename incremental probe stage to search index location
TheGreenCedar Sep 29, 2026
1f1ff84
merge probe-stage-rename
TheGreenCedar Sep 29, 2026
c50ed4a
give windows seals native file identity
TheGreenCedar Sep 29, 2026
eff77d2
clear linked replacement's read-only bit on windows
TheGreenCedar Sep 29, 2026
43173d5
merge windows-seal-fidelity
TheGreenCedar Sep 29, 2026
c4bf343
merge windows-vector-retry-replace
TheGreenCedar Sep 29, 2026
1c42601
note windows seal and retry fixes in changelog
TheGreenCedar Sep 29, 2026
3b929b8
fix review regressions for 0.17.7
TheGreenCedar Sep 29, 2026
94f18bc
gate writer hold support imports
TheGreenCedar Sep 29, 2026
cd6d608
preserve newer-schema diagnostic recovery
TheGreenCedar Sep 29, 2026
517d9a3
Merge pull request #2533 from TheGreenCedar/codex/0.17.7-remediation
TheGreenCedar Sep 29, 2026
c9db434
prepare 0.17.7 calibration source
TheGreenCedar Sep 29, 2026
0384641
Merge pull request #2535 from TheGreenCedar/codex/0.17.7-release-source
TheGreenCedar Sep 29, 2026
3264c0e
freeze 0.17.7 runtime constants
TheGreenCedar Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 34 additions & 1 deletion .github/scripts/build-marketplace-fixture.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,19 @@ test("the fixture catalog carries the fields the resolver requires", () => {
const [plugin] = catalog.plugins;
assert.deepEqual(Object.keys(plugin).sort(), PLUGIN_KEYS);
assert.equal(plugin.name, "codestory");
assert.deepEqual(plugin.policy, {
installation: "AVAILABLE",
authentication: "ON_INSTALL",
});
assert.equal(plugin.category, "Developer Tools");
assert.deepEqual(Object.keys(plugin.source).sort(), SOURCE_KEYS);
// Key sets alone do not pin a delivery: a wrong source kind or repository
// URL resolves a different (or no) plugin while passing every key check.
assert.equal(plugin.source.source, "git-subdir");
assert.equal(
plugin.source.url,
"https://github.com/TheGreenCedar/CodeStory.git",
);
assert.equal(plugin.source.sha, commit);
assert.equal(plugin.source.path, "plugins/codestory");
} finally {
Expand Down Expand Up @@ -96,8 +108,29 @@ test("the fixture identifies itself and the commit it pins", () => {
assert.equal(marker.schema_version, 1);
assert.equal(marker.purpose, "codestory-candidate-pinned-marketplace-fixture");
assert.equal(marker.pinned_commit, commit);
// The consumer requires the marker's version to be the pinned commit's own
// plugin version; compare it, do not only require the key to exist.
const pinnedManifest = JSON.parse(
execFileSync(
"git",
[
"-C",
repositoryRoot,
"show",
`${commit}:plugins/codestory/.codex-plugin/plugin.json`,
],
{ encoding: "utf8" },
),
);
assert.equal(marker.plugin_version, pinnedManifest.version);
// The marker must be committed, or a clean-tree check would pass over a fixture that had
// been re-marked after the fact.
// been re-marked after the fact. ls-files --error-unmatch proves the marker is in the
// committed tree -- a gitignored marker leaves status clean while never being delivered.
execFileSync(
"git",
["-C", out, "ls-files", "--error-unmatch", ".codestory-marketplace-fixture.json"],
{ encoding: "utf8" },
);
assert.equal(
execFileSync("git", ["-C", out, "status", "--porcelain"], { encoding: "utf8" }).trim(),
"",
Expand Down
39 changes: 39 additions & 0 deletions .github/scripts/cargo-build-artifacts.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -684,6 +684,22 @@ test("rejects debug-profile output even when the target name matches", () => {
assert.throws(() => build(input), /not built with the release profile/u);
});

// Each release-profile predicate is an independent admission check: a row that
// trips several at once cannot tell whether a dropped check would still fail.
for (const [field, value] of [
["opt_level", "0"],
["debug_assertions", true],
["overflow_checks", true],
]) {
test(`rejects a release-directory executable whose only debug marker is profile.${field}`, () => {
const input = fixture();
input.messages[1].profile[field] = value;
input.jsonLines = input.messages.map((message) => JSON.stringify(message)).join("\n");

assert.throws(() => build(input), /not built with the release profile/u);
});
}

test("rejects a production binary actually built with the test profile", () => {
const input = fixture();
input.messages[1].profile.test = true;
Expand Down Expand Up @@ -824,6 +840,29 @@ test("rejects bytes changed after Cargo emitted the authenticated executable", (
);
});

test("rejects a same-length rewrite of the authenticated executable", () => {
const { input, manifest } = build();
// Appending drifts size and digest together, so a size check alone would
// still catch it. Flip bytes in place: size, inode and link count are
// unchanged and only the digest can expose the rewrite.
const executable = input.artifacts[0].executable;
const bytes = fs.readFileSync(executable);
bytes[0] = bytes[0] === 0 ? 1 : 0;
fs.writeFileSync(executable, bytes);

assert.throws(
() =>
verifyCargoArtifactManifest({
exactSha: SOURCE_SHA,
exactTree: SOURCE_TREE,
manifest,
rustTarget: RUST_TARGET,
workspaceRoot: input.root,
}),
/no longer matches its authenticated build output/u,
);
});

test("rejects a hardlink added after Cargo artifact selection", () => {
const { input, manifest } = build();
const alias = path.join(input.root, "cross-graph-cli.exe");
Expand Down
34 changes: 20 additions & 14 deletions .github/scripts/check-workflow-policy.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -498,14 +498,16 @@ export function retrievalGeneralizationSuitePolicyViolations(
const expectedFilesystemMemberCounts = {
existsSync: 1,
mkdirSync: 7,
mkdtempSync: 1,
// The hostile matrix owns one tree; the ranker counterexample owns a
// second. Both are mkdtempSync under os.tmpdir(), removed on exit.
mkdtempSync: 2,
// Two of these read the shipped pending inventory and the registry document it points at,
// so the claim-profile ratchet is checked against the tree that ships, not a synthetic one.
readFileSync: 6,
readFileSync: 5,
readdirSync: 4,
readlinkSync: 1,
rmSync: 1,
writeFileSync: 1,
rmSync: 2,
writeFileSync: 2,
};
const filesystemMemberCounts = new Map();
for (const name of filesystemMemberReferences) {
Expand All @@ -515,8 +517,8 @@ export function retrievalGeneralizationSuitePolicyViolations(
);
}
const fixtureFilesystemShapeIsExact =
fsReferenceCount === 24
&& filesystemMemberReferences.length === 22
fsReferenceCount === 26
&& filesystemMemberReferences.length === 24
&& Object.entries(expectedFilesystemMemberCounts).every(
([name, count]) => (filesystemMemberCounts.get(name) ?? 0) === count,
)
Expand Down Expand Up @@ -550,7 +552,7 @@ export function retrievalGeneralizationSuitePolicyViolations(
&& writeFirstArguments.length === writeReferenceCount
&& writeFirstArguments.every((root) => registeredWriteRoots.has(root));
const fixturePathReferenceShapeIsExact =
repositoryRootReferenceCount === 14
repositoryRootReferenceCount === 15
&& fixtureRootReferenceCount === 10
&& productionRepositoryRootReferenceCount === 5;
const protectedRetrievalWorkflow = `.github/workflows/${retrievalFile}`;
Expand Down Expand Up @@ -605,8 +607,8 @@ export function retrievalGeneralizationSuitePolicyViolations(
);
add(
violations,
invocationCount === 1 && lintReferenceCount === 2,
`${retrievalGeneralizationSuiteFile} must execute the hostile fixture matrix through one in-process lint invocation`,
invocationCount === 2 && lintReferenceCount === 3,
`${retrievalGeneralizationSuiteFile} must execute the hostile matrix and the ranker probes through in-process lint invocations only`,
);
add(
violations,
Expand Down Expand Up @@ -635,16 +637,19 @@ export function retrievalGeneralizationSuitePolicyViolations(
source.includes(
'fs.mkdtempSync(path.join(os.tmpdir(), "codestory-generalization-"))',
)
&& temporaryRootCount === 1
&& temporaryTreeCount === 1
&& source.includes(
'fs.mkdtempSync(path.join(os.tmpdir(), "ranker-literal-"))',
)
&& temporaryRootCount === 2
&& temporaryTreeCount === 2
&& source.includes(
'assert.ok(\n path.relative(repositoryRoot, fixtureRoot).startsWith(".."),',
)
&& source.includes("const productionRepositoryRoot = path.join(\n fixtureRoot,")
&& source.includes("const extraRustRoot = path.join(fixtureRoot,")
&& source.includes("const nonRustRoot = path.join(fixtureRoot,")
&& source.includes("const taskRoot = path.join(fixtureRoot,"),
`${retrievalGeneralizationSuiteFile} must keep every mutable hostile fixture under one temporary tree outside the checkout`,
`${retrievalGeneralizationSuiteFile} must keep every mutable hostile fixture under its declared temporary trees outside the checkout`,
);
add(
violations,
Expand All @@ -667,8 +672,9 @@ export function retrievalGeneralizationSuitePolicyViolations(
);
add(
violations,
source.includes("fs.rmSync(fixtureRoot, { recursive: true, force: true });"),
`${retrievalGeneralizationSuiteFile} must remove its isolated fixture tree after the matrix`,
source.includes("fs.rmSync(fixtureRoot, { recursive: true, force: true });")
&& source.includes("fs.rmSync(rankerRoot, { recursive: true, force: true });"),
`${retrievalGeneralizationSuiteFile} must remove its isolated fixture trees after the matrix`,
);
return violations;
}
Expand Down
12 changes: 6 additions & 6 deletions .github/scripts/check-workflow-policy.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -6045,15 +6045,15 @@ await import("node:worker_threads");
`, {}, /must not create subprocesses, workers, or clusters/u],
["matrix calls the lint twice", `${source}
runRetrievalGeneralizationLint({});
`, {}, /through one in-process lint invocation/u],
`, {}, /through in-process lint invocations/u],
["matrix aliases the lint for a second invocation", source.replace(
" const result = runRetrievalGeneralizationLint({",
[
" const invokeAgain = runRetrievalGeneralizationLint;",
" invokeAgain({});",
" const result = runRetrievalGeneralizationLint({",
].join("\n"),
), {}, /through one in-process lint invocation/u],
), {}, /through in-process lint invocations/u],
["global file lock returns", `${source}
fs.openSync(path.join(os.tmpdir(), "retrieval-generalization.lock"), "wx");
`, {}, /must not restore a global or cross-process fixture lock/u],
Expand All @@ -6069,15 +6069,15 @@ fs.openSync(path.join(os.tmpdir(), "retrieval-generalization.lock"), "wx");
["second global temporary root returns", `${source}
const sharedRoot = fs.mkdtempSync(path.join(os.tmpdir(), "shared-suite-"));
fs.mkdirSync(path.join(sharedRoot, "sentinel"));
`, {}, /under one temporary tree outside the checkout/u],
`, {}, /declared temporary trees outside the checkout/u],
["second sibling temporary root returns", `${source}
const sharedRoot = fs.mkdtempSync(path.join(path.dirname(fixtureRoot), "shared-suite-"));
fs.mkdirSync(path.join(sharedRoot, "sentinel"));
`, {}, /under one temporary tree outside the checkout/u],
`, {}, /declared temporary trees outside the checkout/u],
["fixtures move into the checkout", source.replace(
'fs.mkdtempSync(path.join(os.tmpdir(), "codestory-generalization-"))',
'fs.mkdtempSync(path.join(repositoryRoot, "codestory-generalization-"))',
), {}, /under one temporary tree outside the checkout/u],
), {}, /declared temporary trees outside the checkout/u],
["checkout read-only comparison is removed", source.replace(
"const checkoutBefore = treeDigest(repositoryRoot);",
"const checkoutBefore = null;",
Expand Down Expand Up @@ -6110,7 +6110,7 @@ fs.mkdirSync(path.join(sharedRoot, "sentinel"));
["fixture cleanup is removed", source.replace(
"fs.rmSync(fixtureRoot, { recursive: true, force: true });",
"",
), {}, /remove its isolated fixture tree/u],
), {}, /remove its isolated fixture trees/u],
];

for (const [name, candidate, options, expectedReason] of mutations) {
Expand Down
63 changes: 43 additions & 20 deletions .github/scripts/install-codestory-marketplace-proof.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import {
mkdtempSync,
mkdirSync,
readFileSync,
readdirSync,
realpathSync,
rmSync,
writeFileSync,
Expand Down Expand Up @@ -89,12 +90,21 @@ test("Windows executes a command shim whose path and arguments contain spaces",
}
});

function run(executable, args, options = {}) {
const result = spawnSync(executable, args, {
// Spawning through a shell breaks on spaced executable paths (node.exe under
// "C:\Program Files\nodejs" dies as 'C:\Program' is not recognized). Route
// every child through the production planner: real executables spawn
// directly, only .cmd/.bat shims go through comspec.
function spawnPlan(executable, args, options = {}) {
const { command, commandArgs, spawnOptions = {} } = commandPlan(executable, args);
return spawnSync(command, commandArgs, {
...options,
...spawnOptions,
encoding: "utf8",
shell: process.platform === "win32",
});
}

function run(executable, args, options = {}) {
const result = spawnPlan(executable, args, options);
assert.equal(
result.status,
0,
Expand Down Expand Up @@ -153,28 +163,46 @@ function proofArgs({
];
}

function assertFailedProof(args, message) {
const result = spawnSync(process.execPath, args, {
encoding: "utf8",
shell: process.platform === "win32",
});
function assertFailedProof(args, message, options = {}) {
const result = spawnPlan(process.execPath, args, options);
assert.notEqual(result.status, 0);
assert.match(result.stderr, message);
}

test("pinned Codex installs a local marketplace fixture into the attested cache", () => {
const root = mkdtempSync(path.join(tmpdir(), "codestory-marketplace-proof-"));
try {
// Every child of this test runs against owned state: an npm cache and a
// HOME under the fixture root. Inheriting ambient npm config/cache or the
// developer's HOME makes the outcome depend on machine state.
const packageRoot = path.join(root, "codex-package");
const npm = process.platform === "win32" ? "npm.cmd" : "npm";
const npmCache = path.join(root, "npm-cache");
const personalHome = path.join(root, "personal-home");
const childEnv = {
...process.env,
HOME: personalHome,
USERPROFILE: personalHome,
npm_config_cache: npmCache,
};
// Resolve npm.cmd to an absolute path: commandPlan quotes the command
// name, and a quoted bare name leaves cmd's %0 unexpanded, so npm.cmd
// would compute %~dp0 (its install prefix) from the cwd.
const npm = process.platform === "win32"
? spawnSync("where.exe", ["npm.cmd"], { encoding: "utf8" }).stdout.trim()
.split(/\r?\n/u)[0]
: "npm";
run(npm, [
"install",
"--prefix",
packageRoot,
"--no-audit",
"--no-fund",
`@openai/codex@${codexVersion}`,
]);
], { env: childEnv });
assert.ok(
readdirSync(npmCache).length > 0,
"npm install did not use the fixture-owned cache",
);

const marketplaceRoot = path.join(root, "marketplace");
const pluginSourceRoot = path.join(root, "plugin-source");
Expand Down Expand Up @@ -209,7 +237,6 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
const marketplaceRevision = commitFixture(marketplaceRoot, "fixture", {
init: true,
});
const personalHome = path.join(root, "personal-home");
mkdirSync(path.join(personalHome, ".agents", "plugins"), { recursive: true });
writeFileSync(
path.join(personalHome, ".agents", "plugins", "marketplace.json"),
Expand Down Expand Up @@ -245,12 +272,7 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
marketplaceRevision,
expectedVersion: pluginManifest.version,
sourceRepository: pluginSourceRoot,
}), {
env: {
...process.env,
HOME: personalHome,
},
});
}), { env: childEnv });

const attestation = JSON.parse(readFileSync(attestationPath));
const expectedPluginRoot = path.join(
Expand Down Expand Up @@ -320,9 +342,7 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
"--installation-source",
"codex_marketplace_restored_fixture",
);
run(process.execPath, restoredArgs, {
env: { ...process.env, HOME: personalHome },
});
run(process.execPath, restoredArgs, { env: childEnv });
const restoredAttestation = JSON.parse(
readFileSync(path.join(restoredRoot, "attestation.json")),
);
Expand All @@ -349,6 +369,7 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
sourceRepository: pluginSourceRoot,
}),
/installed plugin bytes do not match the checked-out CodeStory package/u,
{ env: childEnv },
);
commitFixture(pluginSourceRoot, "change release tree");
assertFailedProof(
Expand All @@ -361,6 +382,7 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
sourceRepository: pluginSourceRoot,
}),
/pinned marketplace plugin source does not match the release source tree/u,
{ env: childEnv },
);

const catalogPath = path.join(
Expand All @@ -386,6 +408,7 @@ test("pinned Codex installs a local marketplace fixture into the attested cache"
sourceRepository: pluginSourceRoot,
}),
/marketplace plugin source is not pinned to one immutable commit/u,
{ env: childEnv },
);
} finally {
rmSync(root, { recursive: true, force: true });
Expand Down
Loading
Loading