Independent re-audit surfaced 11 follow-ups across two layers of review
(my fresh-eyes read + a parallel agent pass). Bundled into a single
commit because changes are small and intertwined.
Symlink / state consistency:
- FileSystem.same_symlink now uses raw readlink() instead of resolve().
Aligns the three sites that ask "is this our link?" (_load_state,
_check_overwrite_safe, remove_symlink) on a single rule: exact-readlink
match. Following symlink chains would let externally-modified links
pass as ours and be silently overwritten.
- LinkedState.from_dict raises ConfigError on missing required fields
instead of .get(..., False) silent defaults. Matches InstalledState.
- LinkOp.source is now consistently None for remove_link ops; the
service derives expected_source from current.links. Removes the
asymmetry between in-state and orphan-broken removal ops.
- _apply_plan: rename shadowing local from link_target to spec.
Fail loud:
- _xdg() now treats XDG_CONFIG_HOME="" the same as unset. Previously
an empty env var produced Path("") and state files were written to
$PWD instead of ~/.local/state/flow.
- _resolve_target raises PlanConflict when a package contains a bare
_root entry (no path components) instead of silently dropping it.
- _strip_prefix raises FlowError when a declared install path does not
start with its section's expected prefix (e.g. etc/foo under install.bin).
Speculative abstraction removed (CLAUDE.md):
- core.template.substitute (the $VAR form) had no production callers --
deleted along with its tests; only the {{var}} form remains.
- SetupModule base class -- five subclasses, no shared behaviour, no
polymorphic call site. Deleted.
- Profile.arch -- parsed but never read. Deleted.
- PackagePlan.pm_command -- set but never read. Deleted (service
recomputes pm_install_command at the call site).
- FileSystem.ensure_dir(mode=...), .copy_file(sudo=...), .read_text(
default=...) -- no callers. Deleted along with their test.
- bootstrap _execute_action: the upfront `phase not in VALID_PHASES`
check duplicated the trailing exhaustive raise. Kept the trailing
raise as the single source of truth; phase set still documented in
VALID_PHASES.
Completion ctx threading:
- Removed _config()/_manifest() helpers that re-loaded from disk on
every completion call. _list_targets, _list_namespaces, _list_platforms,
_list_bootstrap_profiles, _list_manifest_packages now take ctx and
read from ctx.config / ctx.manifest.
Test coverage and e2e:
- e2e container test exercises a real `flow dotfiles link` (no dry-run)
and asserts the resulting symlinks point into the dotfiles dir;
reruns to verify idempotency.
- New tests: LinkedState corrupt-state ConfigError, LinkedState bad-version
ConfigError, bare-_root PlanConflict, service-level _root path routing
+ skip semantics.
- 11 stale test imports removed (pyflakes clean across src/ + tests/).
357 unit tests + 1 e2e (gated) all pass.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
104 lines
3.5 KiB
Python
104 lines
3.5 KiB
Python
"""Tests for containers domain."""
|
|
|
|
from pathlib import Path
|
|
|
|
from flow.domain.containers.models import ImageRef, Mount
|
|
from flow.domain.containers.resolution import (
|
|
build_container_spec,
|
|
container_name,
|
|
parse_image_ref,
|
|
resolve_mounts,
|
|
)
|
|
|
|
|
|
class TestParseImageRef:
|
|
def test_simple_name(self):
|
|
ref = parse_image_ref("devbox")
|
|
assert ref.registry == "registry.tomastm.com"
|
|
assert ref.repo == "devbox"
|
|
assert ref.tag == "latest"
|
|
|
|
def test_with_tag(self):
|
|
ref = parse_image_ref("devbox:v2")
|
|
assert ref.tag == "v2"
|
|
|
|
def test_full_ref(self):
|
|
ref = parse_image_ref("ghcr.io/user/image:main")
|
|
assert ref.registry == "ghcr.io"
|
|
assert ref.repo == "user/image"
|
|
assert ref.tag == "main"
|
|
|
|
def test_full_image_string(self):
|
|
ref = parse_image_ref("devbox")
|
|
assert ref.full == "registry.tomastm.com/devbox:latest"
|
|
|
|
|
|
class TestContainerName:
|
|
def test_basic(self):
|
|
assert container_name("devbox") == "dev-devbox"
|
|
|
|
|
|
class TestResolveMounts:
|
|
def test_projects_mount(self, tmp_path):
|
|
projects = tmp_path / "projects"
|
|
projects.mkdir()
|
|
mounts = resolve_mounts(
|
|
tmp_path, filesystem_check=lambda p: p.exists(), project_path=str(projects),
|
|
)
|
|
project_mounts = [m for m in mounts if m.target == "/workspace"]
|
|
assert len(project_mounts) == 1
|
|
|
|
def test_dotfiles_mount(self, tmp_path):
|
|
dotfiles = tmp_path / "dotfiles"
|
|
dotfiles.mkdir()
|
|
mounts = resolve_mounts(
|
|
tmp_path, filesystem_check=lambda p: p.exists(), dotfiles_dir=dotfiles,
|
|
)
|
|
assert any(m.target.endswith("/flow/dotfiles") for m in mounts)
|
|
|
|
def test_socket_path_mount(self, tmp_path):
|
|
sock = tmp_path / "docker.sock"
|
|
sock.write_text("")
|
|
mounts = resolve_mounts(
|
|
tmp_path, filesystem_check=lambda p: p.exists(), socket_path=sock,
|
|
)
|
|
socket_mounts = [m for m in mounts if m.target == "/var/run/docker.sock"]
|
|
assert len(socket_mounts) == 1
|
|
assert socket_mounts[0].source == sock
|
|
|
|
def test_no_socket_path(self, tmp_path):
|
|
mounts = resolve_mounts(tmp_path, filesystem_check=lambda p: p.exists())
|
|
assert not any(m.target == "/var/run/docker.sock" for m in mounts)
|
|
|
|
def test_filesystem_check_controls_standard_mounts(self, tmp_path):
|
|
mounts = resolve_mounts(tmp_path, filesystem_check=lambda p: False)
|
|
# No standard mounts present when filesystem_check returns False.
|
|
assert not any(m.target == "/home/dev/.ssh" for m in mounts)
|
|
assert not any(m.target.endswith("/flow/dotfiles") for m in mounts)
|
|
|
|
|
|
class TestBuildContainerSpec:
|
|
def test_basic(self):
|
|
image = ImageRef(registry="reg", repo="img", tag="v1", label="reg/img")
|
|
spec = build_container_spec("api", image, [])
|
|
assert spec.name == "dev-api"
|
|
assert spec.labels["dev.name"] == "api"
|
|
|
|
def test_with_mounts(self):
|
|
image = ImageRef(registry="reg", repo="img", tag="v1", label="reg/img")
|
|
mounts = [Mount(source=Path("/a"), target="/b")]
|
|
spec = build_container_spec("api", image, mounts)
|
|
assert len(spec.mounts) == 1
|
|
|
|
|
|
class TestMount:
|
|
def test_fields(self):
|
|
m = Mount(source=Path("/src"), target="/dst")
|
|
assert m.source == Path("/src")
|
|
assert m.target == "/dst"
|
|
assert m.readonly is False
|
|
|
|
def test_readonly(self):
|
|
m = Mount(source=Path("/src"), target="/dst", readonly=True)
|
|
assert m.readonly is True
|