CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

test_bounded_run.shskills/herdr-foreman/tests/

#!/usr/bin/env bash
# Outcome-based tests for skills/herdr-foreman/bounded-run.sh.
#
# No case waits on a clock. Every budget is an hour, far past any case; the
# expiry case ends it with SIGALRM, the runner's own documented trigger, and
# every handshake is a FIFO read that returns when the other side acts.
#
# Covers:
#   1. Pass-through   -> stdin, stdout and the exit code are the command's own.
#   2. Budget spent   -> exit 124 with a diagnostic, and a grandchild the
#                        command started is stopped with it.
#  2b. Early expiry  -> an expiry before the launch is still exit 124, with no
#                        traceback and nothing left running.
#  2d. Expiry at exit -> an expiry landing after the command exits, before the
#                        alarm is cancelled, is exit 124 with no traceback,
#                        and so is one the restored mask holds pending.
#  2c. TERM-trapping  -> a command that exits on SIGTERM leaves no grandchild:
#                        the grace-period SIGKILL reaches the whole group.
#   3. Not startable  -> exit 125 with a diagnostic.
#   4. Usage          -> a non-positive budget is exit 125.
#
# The harness drops `set -e` to aggregate results (rules/error-handling.md
# aggregate-reporting carve-out).
#
# Run: bash skills/herdr-foreman/tests/test_bounded_run.sh
set -uo pipefail

HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
RUNNER="${HERE}/../bounded-run.sh"
PASS=0
FAIL=0
TMP=""

#: A budget no case comes near; expiry is always signalled, never waited for.
HOUR=3600

die() { echo "fatal: $*" >&2; exit 2; }
pass() { PASS=$((PASS+1)); }
fail() { FAIL=$((FAIL+1)); echo "  ✗ FAIL: $1" >&2; }
cleanup() {
  if [[ -n "$TMP" ]] && ! rm -rf "$TMP"; then echo "warn: could not remove $TMP" >&2; fi
  return 0
}

main() {
  command -v python3 >/dev/null || die "python3 is required"
  TMP="$(mktemp -d)" || die "mktemp failed"
  trap cleanup EXIT
  local out rc

  echo "1. stdin, stdout and the exit code pass through"
  rc=0
  out="$(printf 'hello\n' | bash "$RUNNER" "$HOUR" bash -c 'cat; exit 7' 2>"$TMP/1.err")" || rc=$?
  if [[ $rc -eq 7 && "$out" == hello && ! -s "$TMP/1.err" ]]; then pass
  else fail "pass-through: rc=$rc out=$out err=$(cat "$TMP/1.err")"; fi

  echo "2. an ended budget is exit 124, and the command's children stop with it"
  # held: the command opens its write end before anything else, and the
  # grandchild inherits it, so a reader sees end-of-file exactly when both
  # are gone. started: the command writes its grandchild's pid after that
  # open, so the budget is never ended before the FIFO has its writers.
  mkfifo "$TMP/started" "$TMP/held" || die "mkfifo failed"
  cat "$TMP/held" > "$TMP/held.out" &
  local reader=$!
  bash "$RUNNER" "$HOUR" bash -c 'exec 3>"$0"; sleep 3600 & echo $! > "$1"; wait' "$TMP/held" "$TMP/started" 2>"$TMP/2.err" &
  local runner=$! grandchild
  read -r grandchild < "$TMP/started" || die "the command never reported its grandchild"
  kill -ALRM "$runner" || die "cannot signal the runner $runner"
  rc=0
  wait "$runner" || rc=$?
  # Returns only once every writer of `held` is gone: the grandchild included.
  wait "$reader" || die "the FIFO reader failed"
  if [[ $rc -eq 124 && -n "$grandchild" ]] && grep -q "budget" "$TMP/2.err"; then pass
  else fail "budget: rc=$rc grandchild=$grandchild err=$(cat "$TMP/2.err")"; fi

  echo "2b. an expiry that lands before the command is launched is exit 124, no traceback, nothing left running"
  rc=0
  BOUNDED_RUN_TEST_EXPIRE_BEFORE_LAUNCH=1 bash "$RUNNER" "$HOUR" bash -c 'echo $$ > "$0"; exec sleep 3600' "$TMP/early.pid" \
    2>"$TMP/2b.err" || rc=$?
  # The runner waits for its direct child before exiting, so a pid it wrote
  # names a process already reaped.
  local early_alive=0
  if [[ -s "$TMP/early.pid" ]] && kill -0 "$(cat "$TMP/early.pid")" 2>"$TMP/kill.err"; then early_alive=1; fi
  if [[ $rc -eq 124 && $early_alive -eq 0 ]] && grep -q "budget" "$TMP/2b.err" && ! grep -q "Traceback" "$TMP/2b.err"; then pass
  else fail "early expiry: rc=$rc alive=$early_alive err=$(cat "$TMP/2b.err")"; fi

  echo "2d. an expiry that lands as the command exits is exit 124, no traceback, held by the mask or not"
  local when
  for when in 1 masked; do
    rc=0
    BOUNDED_RUN_TEST_EXPIRE_AFTER_EXIT="$when" bash "$RUNNER" "$HOUR" bash -c 'exit 0' 2>"$TMP/2d.err" || rc=$?
    if [[ $rc -eq 124 ]] && grep -q "budget" "$TMP/2d.err" && ! grep -q "Traceback" "$TMP/2d.err"; then pass
    else fail "expiry at exit ($when): rc=$rc err=$(cat "$TMP/2d.err")"; fi
  done

  echo "2c. a command that exits on SIGTERM cannot leave a grandchild behind"
  # The command traps TERM and exits; its grandchild ignores TERM, and holds
  # the write end of held2, so the reader returns only once the grace-period
  # SIGKILL has reached the group.
  mkfifo "$TMP/started2" "$TMP/held2" || die "mkfifo failed"
  cat "$TMP/held2" > "$TMP/held2.out" &
  local reader2=$!
  bash "$RUNNER" "$HOUR" bash -c 'exec 3>"$0"; trap "exit 0" TERM; (trap "" TERM; exec sleep 3600) & echo $! > "$1"; wait' \
    "$TMP/held2" "$TMP/started2" 2>"$TMP/2c.err" &
  local runner2=$! stubborn
  read -r stubborn < "$TMP/started2" || die "the command never reported its grandchild"
  kill -ALRM "$runner2" || die "cannot signal the runner $runner2"
  rc=0
  wait "$runner2" || rc=$?
  wait "$reader2" || die "the FIFO reader failed"
  if [[ $rc -eq 124 && -n "$stubborn" ]] && grep -q "budget" "$TMP/2c.err"; then pass
  else fail "stubborn grandchild: rc=$rc grandchild=$stubborn err=$(cat "$TMP/2c.err")"; fi

  echo "3. a command that cannot start is exit 125 with a diagnostic"
  rc=0
  bash "$RUNNER" "$HOUR" "$TMP/no-such-command" 2>"$TMP/3.err" || rc=$?
  if [[ $rc -eq 125 ]] && grep -q "cannot start" "$TMP/3.err"; then pass
  else fail "not startable: rc=$rc err=$(cat "$TMP/3.err")"; fi

  echo "4. a budget that is not a positive integer is a usage error"
  rc=0
  bash "$RUNNER" 0 true 2>"$TMP/4.err" || rc=$?
  if [[ $rc -eq 125 ]] && grep -q "usage" "$TMP/4.err"; then pass
  else fail "usage: rc=$rc err=$(cat "$TMP/4.err")"; fi

  echo
  echo "passed=${PASS} failed=${FAIL}"
  (( FAIL == 0 ))
}

if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then
  main "$@"
fi

skills

herdr-foreman

tests

__init__.py

fakes.py

test_assign.py

test_attention.py

test_billing.py

test_bounded_run.sh

test_capabilities.py

test_capability_routing.py

test_chronology.py

test_churn.py

test_classify.sh

test_claude_native.py

test_cli.py

test_compose_briefs.sh

test_composer.py

test_composition.py

test_config.py

test_continuity_cli.py

test_cost_report.py

test_diagnostics.py

test_engagement.py

test_entrypoints.py

test_foreman_launcher.sh

test_foreman_queue.py

test_foreman_reset.py

test_foreman_seat.py

test_foreman_tier_check.py

test_freeze.py

test_herdr.py

test_historical.py

test_home.py

test_label_workspaces.sh

test_launch.py

test_legacy_recovery.py

test_load_set.py

test_measure.py

test_members.py

test_memory.py

test_oracle.py

test_parsers.py

test_partition.py

test_planner.py

test_probe.py

test_provision_worktree.sh

test_prune_remote_branches.sh

test_prune_report_caches.py

test_prune_result.py

test_prune_worktrees.sh

test_recovery_cli.py

test_recovery.py

test_renderable.py

test_report_contract.py

test_report_delivery.py

test_report_gates.py

test_report_verdict.py

test_resolve_gates.sh

test_resolve_policy_paths.py

test_restoration.py

test_retrospective_runtime.py

test_retrospective.py

test_review_package.py

test_role_clear.py

test_roster.sh

test_round_preflight.sh

test_runnable.py

test_scoring.py

test_script_dir_newline.sh

test_seat_holds.py

test_selection.py

test_skill_invocations.sh

test_slice_scope_parity.py

test_specialist_cli.py

test_specialist_delivery.py

test_specialist_recovery.py

test_specialist_retention.py

test_stale_grok_delivery.py

test_start_judge_worker.py

test_state.py

test_supervision_cli.py

test_supervision_diagnostics.py

test_supervision_gate.py

test_supervision_replay.py

test_supervision.py

test_sweep_worktrees.sh

test_tier_integration.py

test_tiers.py

test_triggers.py

test_typesafe_client.py

test_verdict_gates.py

test_verify_authority.sh

test_wait_report.sh

tier_fixture.py

bounded-run.sh

compose-briefs.sh

config.example.json

foreman-tier-check.py

foreman.sh

label-workspaces.sh

provision-worktree.sh

prune-remote-branches.sh

prune-report-caches.py

prune-worktrees.sh

resolve-gates.sh

resolve-policy-paths.sh

review-package.sh

roster.sh

round-preflight.sh

SKILL.md

start-judge-worker.sh

state-schema.md

sweep-worktrees.sh

verify-authority.sh

wait-report.sh

README.md

tile.json