Skip to content

test(mirror): cover mirrorArtworkUrls' non-regular-file destination arm - #1165

Merged
mrbobbytables merged 1 commit into
mainfrom
quality/test-mirror-artwork-irregular-destination
Oct 8, 2026
Merged

mrbobbytables merged 1 commit into
mainfrom
quality/test-mirror-artwork-irregular-destination

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

What this changes

mirrorArtworkUrls() (scripts/lib/architecture-content.mjs:153) refuses to
write fetched third-party bytes to a destination it does not own:

if (existing?.isSymbolicLink() || (existing && !existing.isFile())) {

The symlink arm was pinned by
tests/architecture-content-mirror.test.mjs:59, and the pass-through case by
tests/architecture-content-mirror.test.mjs:87. The second operand — an entry
that exists and is neither a symlink nor a regular file — had no test, and was
the only uncovered region in the file.

This adds two tests for it, placed directly beneath the symlink pair so both
arms of the one guard are read together. No production code changes.

  • "mirrorArtworkUrls skips a destination that is not a regular file" — puts a
    directory on the mirror path and asserts exactly one
    destination is not a regular file warning. Skipping has to be audible: a
    silent continue would leave the asset missing with nothing in the import
    log saying why.
  • "mirrorArtworkUrls leaves an irregular destination byte-for-byte alone" —
    asserts the destination is still a directory, still holds only its original
    entry, and that the entry's contents are unchanged.

Why a directory, and why this arm matters

It needs no adversary. A directory on a mirror path is what an interrupted run
leaves behind, or what an upstream asset renamed from <name> to
<name>/<name> produces, and
.github/workflows/import-architectures.yml reruns npm run import:architectures daily over whatever the previous run left on disk.
Without the guard, writeFileSync() raises EISDIR and aborts the whole
import rather than skipping the single asset it cannot mirror — the arm is the
difference between one missing logo and a failed daily job.

A symlink cannot stand in for it: lstatSync() reports a symlink and a
directory differently, and only the second operand rejects the directory.

Verification

Run locally against main at 03cfcfe, node v26.10.0 / npm 11.19.1:

  • npm run test:unit — 2027 passed, 0 failed (2025 before).
  • npm run test:unit:coverage — scripts/lib/architecture-content.mjs goes
    from 100.00 | 97.78 | | 155 to 100.00 | 100.00. Repository src files
    regions rise from 99.92% (2545/2547) to 99.96% (2544/2545); the sole
    remaining sub-100% file is scripts/lib/svg-active-content.mjs:251, a
    separate already-tracked gap this PR deliberately does not touch.
  • npm run test:unit:coverage:check — passes.
  • npx prettier --check tests/architecture-content-mirror.test.mjs — clean.

End-to-end coverage is not claimed either way here:
scripts/lib/architecture-content.mjs is a Node build-time module that never
enters the browser bundle Playwright V8 coverage observes, so it does not
appear in the e2e-coverage report's sources and no mechanism in this
repository could put it there.

Coordination

Touches exactly one file, tests/architecture-content-mirror.test.mjs, adding
to it without editing any existing test. Disjoint from open hold-gated
#1161 (npm audit gate) and #1163
(tests/tools/e2e-coverage-report.mjs, tests/e2e-coverage-report.test.mjs).

Related Issue

Closes #1164


Human review required.

— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88

mirrorArtworkUrls() guards its destination with
`existing?.isSymbolicLink() || (existing && !existing.isFile())`. The symlink
arm and the pass-through case were pinned; the second operand -- an entry that
exists and is neither a symlink nor a regular file -- was the one uncovered
region in scripts/lib/architecture-content.mjs.

A directory on a mirror path needs no adversary: an interrupted run, or an
upstream asset renamed from <name> to <name>/<name>, leaves one behind, and the
import is scheduled daily over whatever the last run left. Without the guard
writeFileSync() raises EISDIR and aborts the whole import instead of skipping
the single asset it cannot mirror.

Two tests: one that the asset is skipped with exactly one audible warning, and
one that the occupied destination is left byte-for-byte alone.

Closes #1164

Signed-off-by: quality <quality@hive.kubestellar.io>
@hivecommons-hive hivecommons-hive Bot added the hold label Oct 7, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

CI note: the Validate repository run (37673380908) on head 7222ef8 was cancelled and no replacement run is queued. Agent-tier credentials cannot re-run Actions jobs (POST rerun-failed-jobs → 403), and pushing to retrigger is not permitted. Human reviewer: please use Re-run failed jobs on that run when you pick this PR up.


🐝 Hive Agent: ci-maintainer | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=ci-maintainer backend=copilot model=kimi-k3 copilot=1.0.88

@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

The newest Validate repository run on this head (run 37673380908) is cancelled with no queued or in-progress replacement; CodeQL on the same head is green. ci-maintainer attempted gh run rerun --failed and the REST rerun-failed-jobs endpoint, both of which are blocked at this agent's permission tier.

Maintainer action needed: re-run the cancelled job (gh run rerun 37673380908 --failed) so the required check reports on the current head. No branch changes are required.


🐝 Hive Agent: ci-maintainer | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=ci-maintainer backend=copilot model=kimi-k3 copilot=1.0.88

@mrbobbytables
mrbobbytables added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 22360fe Oct 8, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[quality] mirrorArtworkUrls' non-regular-file destination arm is the one untested region in architecture-content.mjs

1 participant