CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

test_release_helpers.shskills/release/tests/

#!/usr/bin/env bash
# The two wrappers that keep release rc-dispatch out of a Markdown example.
#
# Each exists because the logic it owns has a failure mode a caller retyping it
# gets wrong: an empty baseline passes the registry-advance conjunct vacuously,
# and collapsing rc 2 into rc 1 reports an unreachable tool as a failed publish
# (jbaruch/coding-policy#450).
#
# `set -e` is dropped so every check runs and the suite reports an aggregate;
# each check captures its own status (rules/error-handling.md
# aggregate-reporting carve-out).
set -uo pipefail

HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
RELEASE="$(cd "${HERE}/.." && pwd)"
PASS=0
FAIL=0
pass() { PASS=$((PASS+1)); }
fail() { FAIL=$((FAIL+1)); echo "  ✗ FAIL: $1" >&2; }
die() { echo "fatal: $*" >&2; exit 2; }

main() {
  TMP="$(mktemp -d "${TMPDIR:-/tmp}/release-helpers.XXXXXX")" || die "could not make a temp dir"
  cleanup() { rm -rf "$TMP"; return 0; }
  trap cleanup EXIT

  run_baseline() { # runs registry-baseline.sh against the stubbed capture helper
    OUT="$(bash "$TMP/registry-baseline.sh" ws plug 2>"$TMP/err")"
    RC=$?
    ERRTEXT="$(cat "$TMP/err")"
  }

  run_landed() {
    OUT="$(bash "$TMP/confirm-tessl-landed.sh" ws plug 0.0.1 42 2>"$TMP/err")"
    RC=$?
    ERRTEXT="$(cat "$TMP/err")"
  }

  # Copy each wrapper beside a stubbed sibling, since both resolve helpers next
  # to themselves.
  install_wrapper() { # <wrapper> <sibling> <sibling-exit> <sibling-stdout> [stderr]
    cp "$RELEASE/$1" "$TMP/$1" || die "could not copy $1"
    {
      printf '#!/bin/sh\n'
      printf 'printf %%s %s\n' "$(printf '%q' "$4")"
      if [ -n "${5:-}" ]; then printf 'printf %%s %s >&2\n' "$(printf '%q' "$5")"; fi
      printf 'exit %s\n' "$3"
    } > "$TMP/$2" || die "could not write the sibling stub"
    chmod +x "$TMP/$2" || die "could not chmod the sibling stub"
  }

  echo "▶ registry-baseline.sh" >&2

  install_wrapper registry-baseline.sh capture-registry-baseline.sh 0 '{"version":"0.3.9"}'
  run_baseline
  if [[ $RC -eq 0 && "$OUT" == "0.3.9" ]]; then pass; else fail "a good baseline prints its version, got RC=$RC OUT=$OUT"; fi

  install_wrapper registry-baseline.sh capture-registry-baseline.sh 2 '' 'registry unreachable'
  run_baseline
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "could not read the registry baseline"; then
    pass; else fail "a failing capture exits 2, got RC=$RC OUT=$OUT"; fi

  install_wrapper registry-baseline.sh capture-registry-baseline.sh 0 '{"other":"field"}'
  run_baseline
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -qF "carries no .version"; then
    pass; else fail "a payload without .version exits 2, got RC=$RC OUT=$OUT ERR=$ERRTEXT"; fi

  install_wrapper registry-baseline.sh capture-registry-baseline.sh 0 'not json'
  run_baseline
  if [[ $RC -eq 2 && -z "$OUT" ]]; then pass; else fail "a non-JSON payload exits 2, got RC=$RC OUT=$OUT"; fi

  echo "▶ confirm-tessl-landed.sh" >&2

  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 0 '{"ok":true,"current":"0.3.10"}'
  run_landed
  if [[ $RC -eq 0 && "$OUT" == "0.3.10" ]]; then pass; else fail "a landed publish prints its version, got RC=$RC OUT=$OUT"; fi

  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 1 '{"ok":false,"reason":"registry did not advance"}'
  run_landed
  if [[ $RC -eq 1 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "did not land — registry did not advance"; then
    pass; else fail "rc 1 stays a did-not-land verdict, got RC=$RC ERR=$ERRTEXT"; fi

  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 2 '' 'run still in flight'
  run_landed
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "cannot tell whether the publish landed"; then
    pass; else fail "rc 2 stays indeterminate rather than a failed publish, got RC=$RC ERR=$ERRTEXT"; fi

  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 0 '{"ok":true}'
  run_landed
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -qF "carries no .current"; then
    pass; else fail "a payload without .current exits 2, got RC=$RC ERR=$ERRTEXT"; fi

  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 0 'not json'
  run_landed
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "is not JSON"; then
    pass; else fail "a non-JSON landed payload names the parse, not a missing .current, got RC=$RC ERR=$ERRTEXT"; fi

  # `jq` shadowed by a stub that is not on PATH: the wrapper must say so rather
  # than blame the envelope it never managed to read.
  install_wrapper confirm-tessl-landed.sh verify-publish-landed.sh 0 '{"ok":true,"current":"0.3.10"}'
  mkdir -p "$TMP/nojq" || die "could not make the jq-less dir"
  for tool in bash sh printf grep mktemp rm cat chmod mkdir dirname pwd; do
    target="$(command -v "$tool" 2>/dev/null)" || continue
    ln -sf "$target" "$TMP/nojq/$tool" || die "could not link $tool"
  done
  OUT="$(PATH="$TMP/nojq" bash "$TMP/confirm-tessl-landed.sh" ws plug 0.0.1 42 2>"$TMP/err")"
  RC=$?
  ERRTEXT="$(cat "$TMP/err")"
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "jq is not installed"; then
    pass; else fail "an absent jq exits 2 naming jq, got RC=$RC ERR=$ERRTEXT"; fi

  # `registry-baseline.sh` carries the same guard and was uncovered: the suite
  # proved the absent-jq path for one wrapper and assumed it for the other.
  install_wrapper registry-baseline.sh capture-registry-baseline.sh 0 '{"version":"0.3.9"}'
  OUT="$(PATH="$TMP/nojq" bash "$TMP/registry-baseline.sh" ws plug 2>"$TMP/err")"
  RC=$?
  ERRTEXT="$(cat "$TMP/err")"
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -qF "jq is not installed"; then
    pass; else fail "an absent jq exits 2 naming jq for the baseline, got RC=$RC ERR=$ERRTEXT"; fi

  echo "─────────────────────────────────────────────" >&2
  if [[ $FAIL -gt 0 ]]; then echo "FAILED: ${FAIL} failed, ${PASS} passed" >&2; exit 1; fi
  echo "PASSED: all ${PASS} checks" >&2
}

[[ "${BASH_SOURCE[0]}" == "${0}" ]] && main "$@"

skills

README.md

tile.json