#!/bin/sh set -eu repo=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd -P) tmp=${TMPDIR:-/tmp}/ink-skills-smoke-$$ cleanup() { chmod -R u+w "$tmp" 2>/dev/null || : rm -rf "$tmp" } trap cleanup EXIT HUP INT TERM mkdir -p "$tmp/home" "$tmp/project" list=$($repo/bin/ink-skills list) printf '%s\n' "$list" | grep '^SKILL' >/dev/null printf '%s\n' "$list" | grep '^audit-ink-cli' >/dev/null printf '%s\n' "$list" | grep '^configure-ink-agent' >/dev/null HOME=$tmp/home $repo/bin/ink-skills link >"$tmp/link.tsv" grep "audit-ink-cli.*linked.*local" "$tmp/link.tsv" >/dev/null [ -L "$tmp/home/.ink/skills/audit-ink-cli" ] [ "$(readlink "$tmp/home/.ink/skills/audit-ink-cli")" = "$repo/skills/audit-ink-cli" ] HOME=$tmp/home $repo/bin/ink-skills link "$repo/skills/audit-ink-cli" >"$tmp/relink.tsv" grep "audit-ink-cli.*unchanged" "$tmp/relink.tsv" >/dev/null mkdir -p "$tmp/home/.ink/skills/collision" mkdir -p "$tmp/collision" cat >"$tmp/collision/SKILL.md" <<'EOF' --- name: collision description: Fixture. --- EOF if HOME=$tmp/home $repo/bin/ink-skills link "$tmp/collision" >/dev/null 2>"$tmp/collision.err"; then echo 'expected collision refusal' >&2 exit 1 fi grep 'refusing existing path' "$tmp/collision.err" >/dev/null HOME=$tmp/home $repo/bin/ink-skills link --project "$tmp/project" "$repo/skills/create-ink-tool" >"$tmp/project.tsv" [ -L "$tmp/project/.ink/skills/create-ink-tool" ] grep "create-ink-tool.*linked.*local" "$tmp/project.tsv" >/dev/null mkdir -p "$tmp/archive-tree/skills/remote-review" cat >"$tmp/archive-tree/skills/remote-review/SKILL.md" <<'EOF' --- name: remote-review description: Review one remote fixture. --- # Remote review EOF tar -cf "$tmp/skills.tar" -C "$tmp/archive-tree" skills digest=$(sha256sum "$tmp/skills.tar" | awk '{print $1}') mkdir -p "$tmp/import-home" HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$digest" "$tmp/skills.tar" >"$tmp/import.tsv" remote_link=$tmp/import-home/.ink/skills/remote-review [ -L "$remote_link" ] [ "$(readlink "$remote_link")" = "$tmp/store/sha256/$digest/tree/skills/remote-review" ] grep "remote-review.*linked.*artifact.*$digest" "$tmp/import.tsv" >/dev/null manifest=$tmp/import-home/.ink/skills/.ink-skills.tsv [ "$(wc -l <"$manifest")" -eq 2 ] awk -F '\t' -v digest="$digest" 'NR == 2 { exit !($1 == "remote-review" && $2 == digest && $3 == "skills/remote-review") }' "$manifest" HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$digest" "$tmp/skills.tar" skills/remote-review >"$tmp/reimport.tsv" grep 'remote-review.*unchanged' "$tmp/reimport.tsv" >/dev/null [ "$(wc -l <"$manifest")" -eq 2 ] zero_digest=$(awk 'BEGIN { for (i = 0; i < 64; i++) printf "0" }') if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$zero_digest" "$tmp/skills.tar" >/dev/null 2>"$tmp/digest.err"; then echo 'expected digest mismatch' >&2 exit 1 fi grep 'SHA-256 mismatch' "$tmp/digest.err" >/dev/null printf '\nchanged\n' >>"$tmp/archive-tree/skills/remote-review/SKILL.md" tar -cf "$tmp/changed.tar" -C "$tmp/archive-tree" skills changed_digest=$(sha256sum "$tmp/changed.tar" | awk '{print $1}') if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$changed_digest" "$tmp/changed.tar" >/dev/null 2>"$tmp/provenance.err"; then echo 'expected provenance collision after artifact changes' >&2 exit 1 fi grep 'provenance collision' "$tmp/provenance.err" >/dev/null mkdir -p "$tmp/unsafe/skills/unsafe" cat >"$tmp/unsafe/skills/unsafe/SKILL.md" <<'EOF' --- name: unsafe description: Unsafe fixture. --- EOF ln -s /etc/passwd "$tmp/unsafe/skills/unsafe/passwd" tar -cf "$tmp/unsafe.tar" -C "$tmp/unsafe" skills unsafe_digest=$(sha256sum "$tmp/unsafe.tar" | awk '{print $1}') if HOME=$tmp/import-home INK_SKILLS_STORE=$tmp/store $repo/bin/ink-skills import "sha256:$unsafe_digest" "$tmp/unsafe.tar" >/dev/null 2>"$tmp/unsafe.err"; then echo 'expected symlink archive refusal' >&2 exit 1 fi grep 'regular files and directories' "$tmp/unsafe.err" >/dev/null printf 'ok\n'