#!/usr/bin/env bash set -euo pipefail REPO_ROOT=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd) tmp=$(mktemp -d) trap 'rm -rf "$tmp"' EXIT mkdir -p "$tmp/source/scripts" "$tmp/fake-bin" cd "$tmp/source" git init -q -b main git config user.name 'Content worker test' git config user.email 'content-worker-test@example.invalid' cat >scripts/sync-git-backed-content-from-origin.sh <<'EOF' #!/usr/bin/env bash set -euo pipefail printf 'pwd=%s\nrepo=%s\nstate=%s\n' "$PWD" "$CAMERON_SITE_REPO" "$CAMERON_SITE_SYNC_STATE_DIR" >"$CAMERON_SITE_SYNC_STATE_DIR/stub-receipt" EOF chmod 0755 scripts/sync-git-backed-content-from-origin.sh git add scripts/sync-git-backed-content-from-origin.sh git commit -q -m 'Add stub content worker' git clone -q --bare . "$tmp/origin.git" CAMERON_SITE_WORKER_REPO="$tmp/deploy-checkout" \ CAMERON_SITE_ORIGIN_URL="$tmp/origin.git" \ CAMERON_SITE_SYNC_STATE_DIR="$tmp/state" \ "$REPO_ROOT/scripts/run-content-sync-worker.sh" grep -Fx "pwd=$tmp/deploy-checkout" "$tmp/state/stub-receipt" >/dev/null grep -Fx "repo=$tmp/deploy-checkout" "$tmp/state/stub-receipt" >/dev/null grep -Fx "state=$tmp/state" "$tmp/state/stub-receipt" >/dev/null set +e CAMERON_SITE_WORKER_REPO="$tmp/deploy-checkout" \ CAMERON_SITE_ORIGIN_URL="$tmp/wrong-origin.git" \ CAMERON_SITE_SYNC_STATE_DIR="$tmp/state" \ "$REPO_ROOT/scripts/run-content-sync-worker.sh" >"$tmp/mismatch.log" 2>&1 mismatch_rc=$? set -e [[ $mismatch_rc -eq 2 ]] grep -F 'Deploy checkout origin mismatch.' "$tmp/mismatch.log" >/dev/null cat >"$tmp/fake-bin/systemctl" <<'EOF' #!/usr/bin/env bash printf '%s\n' "$*" >>"$CAMERON_SITE_TEST_SYSTEMCTL_LOG" if [[ "$*" == *'is-active'* ]]; then exit 1; fi exit 0 EOF chmod 0755 "$tmp/fake-bin/systemctl" CAMERON_SITE_INSTALL_ROOT="$tmp/install" \ CAMERON_SITE_WORKER_REPO="$tmp/installed-deploy-checkout" \ CAMERON_SITE_ORIGIN_URL="$tmp/origin.git" \ CAMERON_SITE_SYSTEMD_USER_DIR="$tmp/units" \ CAMERON_SITE_SYSTEMCTL="$tmp/fake-bin/systemctl" \ CAMERON_SITE_TEST_SYSTEMCTL_LOG="$tmp/systemctl.log" \ "$REPO_ROOT/deploy/systemd/install-content-sync-worker.sh" >"$tmp/installer.log" test -x "$tmp/install/bin/run-content-sync-worker.sh" test -f "$tmp/installed-deploy-checkout/.git/HEAD" test -f "$tmp/units/cameron-site-content-sync.service" test -f "$tmp/units/cameron-site-content-sync.timer" grep -Fx "ExecStart=$tmp/install/bin/run-content-sync-worker.sh" "$tmp/units/cameron-site-content-sync.service" >/dev/null grep -F -- '--user daemon-reload' "$tmp/systemctl.log" >/dev/null grep -F -- '--user enable --now cameron-site-content-sync.timer' "$tmp/systemctl.log" >/dev/null grep -F 'The installer did not start a deployment.' "$tmp/installer.log" >/dev/null set +e env -u CAMERON_BSKY_APP_PASSWORD \ CAMERON_SITE_REPO="$REPO_ROOT" \ CAMERON_SITE_SYNC_STATE_DIR="$tmp/credential-dark-state" \ "$REPO_ROOT/scripts/sync-git-backed-content-from-origin.sh" >"$tmp/credential-dark.log" 2>&1 credential_rc=$? set -e [[ $credential_rc -eq 2 ]] grep -F 'Refusing credential-dark content sync before Git, Fly, or PDS mutation.' "$tmp/credential-dark.log" >/dev/null mkdir -p "$tmp/scope-source/scripts" "$tmp/scope-source/content" "$tmp/scope-source/knowledge" "$tmp/scope-bin" cp "$REPO_ROOT/scripts/sync-git-backed-content-from-origin.sh" "$tmp/scope-source/scripts/" cat >"$tmp/scope-source/package.json" <<'EOF' {"name":"content-worker-scope-test","private":true} EOF cat >"$tmp/scope-source/package-lock.json" <<'EOF' {"name":"content-worker-scope-test","lockfileVersion":3,"packages":{}} EOF cat >"$tmp/scope-source/content/about-atproto-manifest.json" <<'EOF' {} EOF cat >"$tmp/scope-source/knowledge/atproto-manifest.json" <<'EOF' {} EOF cd "$tmp/scope-source" git init -q -b main git config user.name 'Credential scope test' git config user.email 'credential-scope-test@example.invalid' git add . git commit -q -m 'Add credential scope fixture' git clone -q --bare . "$tmp/scope-origin.git" git remote add origin "$tmp/scope-origin.git" git fetch -q origin main cat >"$tmp/scope-bin/npm" <<'EOF' #!/usr/bin/env bash [[ -z ${CAMERON_BSKY_APP_PASSWORD:-} ]] || exit 91 mkdir -p node_modules/.bin touch node_modules/.bin/tsx chmod 0755 node_modules/.bin/tsx EOF cat >"$tmp/scope-bin/fly" <<'EOF' #!/usr/bin/env bash [[ -z ${CAMERON_BSKY_APP_PASSWORD:-} ]] || exit 91 printf '%s\n' "$*" >>"$SCOPE_FLY_LOG" EOF cat >"$tmp/scope-bin/pnpm" <<'EOF' #!/usr/bin/env bash set -euo pipefail case "$*" in '--silent about:sync --apply --from-origin-main') [[ ${CAMERON_BSKY_APP_PASSWORD:-} == scope-test-secret ]] || exit 92 echo '{"counts":{"conflict":0}}' ;; '--silent knowledge:sync --all --apply --from-origin-main') [[ ${CAMERON_BSKY_APP_PASSWORD:-} == scope-test-secret ]] || exit 92 echo '{"counts":{"conflict":0}}' ;; '--silent about:sync'|'--silent knowledge:sync --all') [[ -z ${CAMERON_BSKY_APP_PASSWORD:-} ]] || exit 91 echo '{"counts":{"conflict":0}}' ;; *) [[ -z ${CAMERON_BSKY_APP_PASSWORD:-} ]] || exit 91 ;; esac EOF chmod 0755 "$tmp/scope-bin/npm" "$tmp/scope-bin/fly" "$tmp/scope-bin/pnpm" PATH="$tmp/scope-bin:$PATH" \ CAMERON_BSKY_APP_PASSWORD=scope-test-secret \ CAMERON_SITE_REPO="$tmp/scope-source" \ CAMERON_SITE_SYNC_STATE_DIR="$tmp/scope-state" \ SCOPE_FLY_LOG="$tmp/scope-state/fly.log" \ "$tmp/scope-source/scripts/sync-git-backed-content-from-origin.sh" >"$tmp/scope-run.log" test -f "$tmp/scope-state/last-run.json" grep -F '"conflict": 0' "$tmp/scope-state/last-run.json" >/dev/null grep -Fx 'deploy --depot=false' "$tmp/scope-state/fly.log" >/dev/null grep -Fx 'agent stop' "$tmp/scope-state/fly.log" >/dev/null echo 'Content sync worker tests passed.'