Import verified skill archives
This commit is contained in:
+59
-39
@@ -3,7 +3,11 @@ set -eu
|
||||
|
||||
repo=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd -P)
|
||||
tmp=${TMPDIR:-/tmp}/ink-skills-smoke-$$
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
cleanup() {
|
||||
chmod -R u+w "$tmp" 2>/dev/null || :
|
||||
rm -rf "$tmp"
|
||||
}
|
||||
trap cleanup EXIT HUP INT TERM
|
||||
mkdir -p "$tmp/home" "$tmp/project"
|
||||
|
||||
list=$($repo/bin/ink-skills list)
|
||||
@@ -11,28 +15,34 @@ printf '%s\n' "$list" | grep '^SKILL' >/dev/null
|
||||
printf '%s\n' "$list" | grep '^audit-ink-cli' >/dev/null
|
||||
printf '%s\n' "$list" | grep '^configure-ink-agent' >/dev/null
|
||||
|
||||
HOME=$tmp/home $repo/bin/ink-skills install audit-ink-cli >"$tmp/install.tsv"
|
||||
grep "audit-ink-cli.*linked" "$tmp/install.tsv" >/dev/null
|
||||
HOME=$tmp/home $repo/bin/ink-skills link >"$tmp/link.tsv"
|
||||
grep "audit-ink-cli.*linked.*local" "$tmp/link.tsv" >/dev/null
|
||||
[ -L "$tmp/home/.ink/skills/audit-ink-cli" ]
|
||||
[ "$(readlink "$tmp/home/.ink/skills/audit-ink-cli")" = "$repo/skills/audit-ink-cli" ]
|
||||
|
||||
HOME=$tmp/home $repo/bin/ink-skills install audit-ink-cli >"$tmp/reinstall.tsv"
|
||||
grep "audit-ink-cli.*unchanged" "$tmp/reinstall.tsv" >/dev/null
|
||||
HOME=$tmp/home $repo/bin/ink-skills link "$repo/skills/audit-ink-cli" >"$tmp/relink.tsv"
|
||||
grep "audit-ink-cli.*unchanged" "$tmp/relink.tsv" >/dev/null
|
||||
|
||||
mkdir -p "$tmp/home/.ink/skills/configure-ink-agent"
|
||||
if HOME=$tmp/home $repo/bin/ink-skills install configure-ink-agent >/dev/null 2>"$tmp/collision.err"; then
|
||||
mkdir -p "$tmp/home/.ink/skills/collision"
|
||||
mkdir -p "$tmp/collision"
|
||||
cat >"$tmp/collision/SKILL.md" <<'EOF'
|
||||
---
|
||||
name: collision
|
||||
description: Fixture.
|
||||
---
|
||||
EOF
|
||||
if HOME=$tmp/home $repo/bin/ink-skills link "$tmp/collision" >/dev/null 2>"$tmp/collision.err"; then
|
||||
echo 'expected collision refusal' >&2
|
||||
exit 1
|
||||
fi
|
||||
grep 'refusing existing path' "$tmp/collision.err" >/dev/null
|
||||
|
||||
HOME=$tmp/home $repo/bin/ink-skills install --project "$tmp/project" create-ink-tool >"$tmp/project.tsv"
|
||||
HOME=$tmp/home $repo/bin/ink-skills link --project "$tmp/project" "$repo/skills/create-ink-tool" >"$tmp/project.tsv"
|
||||
[ -L "$tmp/project/.ink/skills/create-ink-tool" ]
|
||||
grep "create-ink-tool.*linked" "$tmp/project.tsv" >/dev/null
|
||||
grep "create-ink-tool.*linked.*local" "$tmp/project.tsv" >/dev/null
|
||||
|
||||
remote=$tmp/remote
|
||||
mkdir -p "$remote/skills/remote-review"
|
||||
cat >"$remote/skills/remote-review/SKILL.md" <<'EOF'
|
||||
mkdir -p "$tmp/archive-tree/skills/remote-review"
|
||||
cat >"$tmp/archive-tree/skills/remote-review/SKILL.md" <<'EOF'
|
||||
---
|
||||
name: remote-review
|
||||
description: Review one remote fixture.
|
||||
@@ -40,43 +50,53 @@ description: Review one remote fixture.
|
||||
|
||||
# Remote review
|
||||
EOF
|
||||
git -C "$remote" init -q
|
||||
git -C "$remote" config user.email ink-skills@example.invalid
|
||||
git -C "$remote" config user.name 'Ink Skills Test'
|
||||
git -C "$remote" add skills/remote-review/SKILL.md
|
||||
git -C "$remote" commit -qm fixture
|
||||
commit=$(git -C "$remote" rev-parse HEAD)
|
||||
tar -cf "$tmp/skills.tar" -C "$tmp/archive-tree" skills
|
||||
digest=$(sha256sum "$tmp/skills.tar" | awk '{print $1}')
|
||||
|
||||
mkdir -p "$tmp/remote-home"
|
||||
HOME=$tmp/remote-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills add --ref HEAD "$remote" skills/remote-review >"$tmp/add.tsv"
|
||||
remote_link=$tmp/remote-home/.ink/skills/remote-review
|
||||
mkdir -p "$tmp/import-home"
|
||||
HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$digest" "$tmp/skills.tar" >"$tmp/import.tsv"
|
||||
remote_link=$tmp/import-home/.ink/skills/remote-review
|
||||
[ -L "$remote_link" ]
|
||||
case $(readlink "$remote_link") in
|
||||
"$tmp/store/artifacts/"*"/$commit/skills/remote-review") ;;
|
||||
*) echo 'remote link is not pinned to resolved commit' >&2; exit 1 ;;
|
||||
esac
|
||||
grep "remote-review.*linked.*$commit" "$tmp/add.tsv" >/dev/null
|
||||
manifest=$tmp/remote-home/.ink/skills/.ink-skills.tsv
|
||||
[ "$(readlink "$remote_link")" = "$tmp/store/sha256/$digest/tree/skills/remote-review" ]
|
||||
grep "remote-review.*linked.*artifact.*$digest" "$tmp/import.tsv" >/dev/null
|
||||
manifest=$tmp/import-home/.ink/skills/.ink-skills.tsv
|
||||
[ "$(wc -l <"$manifest")" -eq 2 ]
|
||||
awk -F '\t' -v commit="$commit" 'NR == 2 { exit !($1 == "remote-review" && $4 == commit && length($6) == 64) }' "$manifest"
|
||||
awk -F '\t' -v digest="$digest" 'NR == 2 { exit !($1 == "remote-review" && $2 == digest && $3 == "skills/remote-review") }' "$manifest"
|
||||
|
||||
HOME=$tmp/remote-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills add --ref HEAD "$remote" skills/remote-review >"$tmp/readd.tsv"
|
||||
grep 'remote-review.*unchanged' "$tmp/readd.tsv" >/dev/null
|
||||
HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$digest" "$tmp/skills.tar" skills/remote-review >"$tmp/reimport.tsv"
|
||||
grep 'remote-review.*unchanged' "$tmp/reimport.tsv" >/dev/null
|
||||
[ "$(wc -l <"$manifest")" -eq 2 ]
|
||||
|
||||
printf '\nchanged\n' >>"$remote/skills/remote-review/SKILL.md"
|
||||
git -C "$remote" add skills/remote-review/SKILL.md
|
||||
git -C "$remote" commit -qm changed
|
||||
if HOME=$tmp/remote-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills add --ref HEAD "$remote" skills/remote-review >/dev/null 2>"$tmp/pin.err"; then
|
||||
echo 'expected provenance collision after ref moves' >&2
|
||||
zero_digest=$(awk 'BEGIN { for (i = 0; i < 64; i++) printf "0" }')
|
||||
if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$zero_digest" "$tmp/skills.tar" >/dev/null 2>"$tmp/digest.err"; then
|
||||
echo 'expected digest mismatch' >&2
|
||||
exit 1
|
||||
fi
|
||||
grep 'provenance collision' "$tmp/pin.err" >/dev/null
|
||||
grep 'SHA-256 mismatch' "$tmp/digest.err" >/dev/null
|
||||
|
||||
if HOME=$tmp/remote-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills add 'https://user:secret@example.invalid/skills.git' >/dev/null 2>"$tmp/credential.err"; then
|
||||
echo 'expected credentialed URL refusal' >&2
|
||||
printf '\nchanged\n' >>"$tmp/archive-tree/skills/remote-review/SKILL.md"
|
||||
tar -cf "$tmp/changed.tar" -C "$tmp/archive-tree" skills
|
||||
changed_digest=$(sha256sum "$tmp/changed.tar" | awk '{print $1}')
|
||||
if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$changed_digest" "$tmp/changed.tar" >/dev/null 2>"$tmp/provenance.err"; then
|
||||
echo 'expected provenance collision after artifact changes' >&2
|
||||
exit 1
|
||||
fi
|
||||
grep 'credentialed HTTP URLs are refused' "$tmp/credential.err" >/dev/null
|
||||
grep 'provenance collision' "$tmp/provenance.err" >/dev/null
|
||||
|
||||
mkdir -p "$tmp/unsafe/skills/unsafe"
|
||||
cat >"$tmp/unsafe/skills/unsafe/SKILL.md" <<'EOF'
|
||||
---
|
||||
name: unsafe
|
||||
description: Unsafe fixture.
|
||||
---
|
||||
EOF
|
||||
ln -s /etc/passwd "$tmp/unsafe/skills/unsafe/passwd"
|
||||
tar -cf "$tmp/unsafe.tar" -C "$tmp/unsafe" skills
|
||||
unsafe_digest=$(sha256sum "$tmp/unsafe.tar" | awk '{print $1}')
|
||||
if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$unsafe_digest" "$tmp/unsafe.tar" >/dev/null 2>"$tmp/unsafe.err"; then
|
||||
echo 'expected symlink archive refusal' >&2
|
||||
exit 1
|
||||
fi
|
||||
grep 'regular files and directories' "$tmp/unsafe.err" >/dev/null
|
||||
|
||||
printf 'ok\n'
|
||||
|
||||
Reference in New Issue
Block a user