Files
Linux_post_install/tests/README.md
T
Your Name d817c37652
gates / consistency-and-conventions (push) Successful in 26s
fix: stabilization pass — fail-closed auth, ai flag validation, lint/config/security hardening, regression tests
17-point code-level audit executed via Explorer->Architect->Builder->Tester->Reviewer;
Reviewer accepted (APPROVE_WITH_NOTES; 3 block-list items resolved):

- security: telegram sender-owner AND-gate + TELEGRAM_OWNER_ID, matrix
  MATRIX_ROOM_ID fail-closed, gpg --passphrase-fd 3 (no argv secret),
  /dev/tcp positional-arg form (checkport/smb-client/share-lib/NET_PROBE),
  eval deny-by-default + --no-command-execution carried by both chat bridges,
  tty-gated --trust; config/{telegram,matrix}.env reference templates
- ai: all ExecStart flags validated against installed llama.cpp
  (requested->error, default->omit+warn, CONFIG_REQUESTED_FLAGS); single-file
  hf download failure rc=1 + no .hf-meta; LLAMACPP_HOST coherent;
  POS_SUBCMDS + metadata gaps closed
- tooling: lint-conventions Bash-native rewrite (~24-30x faster, rules and
  output byte-identical, :num restored); pos system uninstall covers all 12
  libs + scale-tail + flags dir + systemd user units (|| true) + plugin
  markers; anchored .bash_completion/.bashrc removal replaces sed -i '/pos/d'
- config: canonical load_env_file in lib/config-ui.sh (CRLF strip, env-wins,
  XDG, LOADED_ENV_KEYS); 9 tools migrated; entertainment-lib collapsed to
  wrappers; docker-compose deliberately unmigrated (source semantics)
- tests: first committed regression suite — tests/run-tests.sh zero-dep
  runner + make test; 12 files / 179 checks / 0 skip / ~52s; hard skip
  contract; systemd-analyze verify on generated unit PASS

Verified: make gen idempotent; make check green; make lint 0 FAIL, 0 WARN;
make test green; bash -n clean; git diff --check clean. Audit deliverables +
agent reports + AGENT_TODO Done entry included.
2026-09-06 07:25:44 -04:00

2.8 KiB

tests/ — regression test suite

Zero-dependency Bash regression tests for the Linux_post_install repository.

Run

make test          # discover tests/t-*.sh, run everything
./tests/run-tests.sh                     # same
./tests/run-tests.sh t-telegram-auth.sh  # run one file

Exit code is non-zero if any check failed. The suite is designed to be deterministic: tests stub every external dependency they touch (curl, gpg, sudo, systemctl, llama-server, nvidia-smi…) and run against sandbox temp dirs. No network, no sudo, no system changes.

Adding a test

  1. Create tests/t-<what>.sh with a run_test() function. set -euo pipefail is already active (the runner re-asserts it); $ROOT is the repo root, $TEST_TMP a per-test temp dir that is cleaned automatically.
  2. Use the helpers in tests/test-lib.sh for every assertion: check, check_eq, check_rc, check_contains, check_not_contains, check_file_exists, check_file_absent, test_run / test_run_env, mksandbox, tracked_tree_copy, count_token.
  3. If a case cannot run in the current environment (missing binary, missing analyzer), call skip_case "<desc>" "<reason>" — never fake a pass and never silently return.
  4. Keep total suite runtime under 90 seconds.

Skip contract (hard)

A test that cannot run must say [SKIP] reason. The runner counts skips in the summary and a file whose run_test() produced zero checks and zero skips is reported as FAIL ("no assertions") — a broken harness can never pass silently.

Suite contents

File What it verifies
t-ai-server-flags.sh pos-ai-server ExecStart flag set: defaults, CLI, config, dedupe, one-token-per-flag
t-ai-hf-download.sh pos ai hf download success + failure honesty (no .hf-meta on partial failure, rc != 0)
t-ai-llama-detect.sh pos ai-server status version detection, "unknown", missing-binary failure
t-unsupported-flags.sh unsupported-option handling: CLI/config/env hard errors, dropped defaults, word-boundary match
t-systemd-unit.sh generated unit: one ExecStart, quoted paths, systemd-analyze verify
t-telegram-auth.sh Telegram listener chat+owner gate and owner-unset fail-closed
t-matrix-auth.sh Matrix listener room+owner gate and room-unset fail-closed
t-gpg-password.sh backup passphrase on fd 3 (never argv), plaintext/corrupt cleanup
t-config-precedence.sh load_env_file contract + CLI > env > file > defaults across tools
t-uninstall-manifest.sh install.sh ↔ POS_LIBS symmetry, user-unit discovery, marker-driven plugin removal
t-gen-docs-drift.sh make gen idempotence on a pristine tracked tree (CI drift gate)
t-lint-gate.sh make lint green on the real tree; planted violations are caught and named