@@ -46,6 +46,14 @@ async function fixture({ artifact = Buffer.from("#!/bin/sh\necho loader\n"), tar
4646
4747const fetchArchive = ( archive ) => async ( ) => ( { ok : true , arrayBuffer : async ( ) => archive } ) ;
4848
49+ async function makeSourceWorkspace ( root ) {
50+ const packageRoot = path . join ( root , "apps" , "context-loader" ) ;
51+ await mkdir ( packageRoot , { recursive : true } ) ;
52+ await writeFile ( path . join ( root , "pnpm-workspace.yaml" ) , "packages: []\n" ) ;
53+ await writeFile ( path . join ( packageRoot , "SOURCE_WORKSPACE" ) , "source marker\n" ) ;
54+ return packageRoot ;
55+ }
56+
4957test ( "installs a digest-verified darwin-arm64 binary atomically and records canonical state" , async ( ) => {
5058 const { root, archive, artifact } = await fixture ( ) ;
5159 const first = await installContextLoader ( { packageRoot : root , fetchImpl : fetchArchive ( archive ) , platform : "darwin" , arch : "arm64" } ) ;
@@ -123,23 +131,24 @@ test("refuses a same-bytes external binary during reuse and a bin-directory link
123131 assert . deepEqual ( await readdir ( externalDir ) , [ "wren-context-loader" ] ) ;
124132} ) ;
125133
126- test ( "skips only the tracked source checkout, never a lookalike git repository or packed copy" , async ( ) => {
127- const sourcePackage = path . resolve ( path . dirname ( fileURLToPath ( import . meta. url ) ) , ".." ) ;
128- assert . equal ( await isRepositorySourcePackage ( sourcePackage ) , true ) ;
129-
130- const fakeRoot = await mkdtemp ( path . join ( os . tmpdir ( ) , "context-loader-fake-source-" ) ) ;
131- const fakePackage = path . join ( fakeRoot , "apps" , "context-loader" ) ;
132- await mkdir ( path . join ( fakeRoot , "core" , "wren" ) , { recursive : true } ) ;
133- await mkdir ( fakePackage , { recursive : true } ) ;
134- await writeFile ( path . join ( fakePackage , "package.json" ) , "{}\n" ) ;
135- await writeFile ( path . join ( fakeRoot , "pnpm-workspace.yaml" ) , "packages: []\n" ) ;
136- await writeFile ( path . join ( fakeRoot , "core" , "wren" , "pyproject.toml" ) , "[project]\nname = \"wren\"\n" ) ;
137- execFileSync ( "git" , [ "init" , fakeRoot ] ) ;
138- execFileSync ( "git" , [ "-C" , fakeRoot , "add" , "apps/context-loader/package.json" , "pnpm-workspace.yaml" , "core/wren/pyproject.toml" ] ) ;
139- execFileSync ( "git" , [ "-C" , fakeRoot , "remote" , "add" , "origin" , "https://example.invalid/lookalike.git" ] ) ;
140- assert . equal ( await isRepositorySourcePackage ( fakePackage ) , false ) ;
141-
142- const packedCopy = path . join ( fakeRoot , "node_modules" , "@wrenai" , "context-loader" ) ;
143- await mkdir ( packedCopy , { recursive : true } ) ;
144- assert . equal ( await isRepositorySourcePackage ( packedCopy ) , false ) ;
134+ test ( "recognizes fork and source-archive workspaces, while npm-packed copies cannot bypass" , async ( ) => {
135+ const forkRoot = await mkdtemp ( path . join ( os . tmpdir ( ) , "context-loader-fork-" ) ) ;
136+ const forkPackage = await makeSourceWorkspace ( forkRoot ) ;
137+ execFileSync ( "git" , [ "init" , forkRoot ] ) ;
138+ execFileSync ( "git" , [ "-C" , forkRoot , "remote" , "add" , "origin" , "https://example.invalid/fork.git" ] ) ;
139+ assert . equal ( await isRepositorySourcePackage ( forkPackage ) , true ) ;
140+
141+ const sourceArchiveRoot = await mkdtemp ( path . join ( os . tmpdir ( ) , "context-loader-source-archive-" ) ) ;
142+ const sourceArchivePackage = await makeSourceWorkspace ( sourceArchiveRoot ) ;
143+ assert . equal ( await isRepositorySourcePackage ( sourceArchivePackage ) , true ) ;
144+
145+ const actualPackageRoot = path . resolve ( path . dirname ( fileURLToPath ( import . meta. url ) ) , ".." ) ;
146+ const packed = JSON . parse ( execFileSync ( "npm" , [ "pack" , "--json" , "--dry-run" ] , { cwd : actualPackageRoot , encoding : "utf8" } ) ) ;
147+ assert . equal ( packed [ 0 ] . files . some ( ( entry ) => entry . path === "SOURCE_WORKSPACE" ) , false ) ;
148+
149+ const unpackedRoot = await mkdtemp ( path . join ( os . tmpdir ( ) , "context-loader-unpacked-" ) ) ;
150+ const unpackedPackage = path . join ( unpackedRoot , "apps" , "context-loader" ) ;
151+ await mkdir ( unpackedPackage , { recursive : true } ) ;
152+ await writeFile ( path . join ( unpackedRoot , "pnpm-workspace.yaml" ) , "packages: []\n" ) ;
153+ assert . equal ( await isRepositorySourcePackage ( unpackedPackage ) , false ) ;
145154} ) ;
0 commit comments