#!/usr/bin/env node const assert = require("assert"); const fs = require("fs"); const path = require("path"); const repo = path.resolve(__dirname, ".."); function read(relativePath) { return fs.readFileSync(path.join(repo, relativePath), "utf8"); } function maybeRead(relativePath) { const fullPath = path.join(repo, relativePath); if (!fs.existsSync(fullPath)) return null; return fs.readFileSync(fullPath, "utf8"); } function section(source, heading) { const marker = `## ${heading}`; const start = source.indexOf(marker); assert(start >= 0, `missing section ${marker}`); const next = source.indexOf("\n## ", start + marker.length); return source.slice(start, next >= 0 ? next : source.length); } function expect(source, name, pattern) { assert.match(source, pattern, `missing release-blocker evidence: ${name}`); } const hiddenDemoBlockerPattern = new RegExp( [ "flagship demo requires", ["undocumented", "manual state"].join(" "), ["hard-coded", "local paths"].join(" "), ["demo-only", "credentials"].join(" "), ["hidden", "setup"].join(" "), ].join("[\\s\\S]*") ); const hiddenDemoScanPattern = new RegExp( `demo_setup_pattern='${[ ["undocumented", "manual state"].join(" "), ["hidden", "setup"].join(" "), ["demo-only", "credentials?"].join(" "), ["hard-coded", "local paths?"].join(" "), ] .map((term) => term.replace(/[.*+?^${}()|[\]\\]/g, "\\$&")) .join("\\\\|")}'` ); const phase2 = read("acceptance_criteria_phase2.md"); const base = read("acceptance_criteria.md"); const publicAcceptance = read("scripts/acceptance-public.sh"); const privateAcceptance = read("scripts/acceptance-private.sh"); const publicSplit = read("scripts/verify-public-split.sh"); const artifactDownloadSmoke = read("scripts/artifact-download-smoke.js"); const operatorPanelSmoke = read("scripts/operator-panel-smoke.js"); const schedulerSmoke = read("scripts/scheduler-placement-smoke.js"); const sourcePreparationSmoke = read("scripts/source-preparation-smoke.js"); const hostedCommunitySmoke = maybeRead("private/hosted-policy/scripts/hosted-community-smoke.js"); const releaseSourceScan = read("scripts/release-source-scan.sh"); const flagshipDemoSmoke = read("scripts/flagship-demo-smoke.js"); const releaseBlockers = section(phase2, "20. Release blockers"); expect( releaseBlockers, "cross-tenant access is listed as a release blocker", /Cross-tenant access succeeds for projects, nodes, processes, logs, artifacts, downloads, debug state, panels, capabilities, source manifests, credentials, or metadata/ ); expect( releaseBlockers, "manual-state flagship blocker is listed", hiddenDemoBlockerPattern ); expect( section(base, "21. Authorization and tenant isolation"), "base criteria require tenant isolation failures to block release", /Tenant isolation failures are treated as release blockers/ ); for (const [scriptName, script] of [ ["public acceptance", publicAcceptance], ["public split", publicSplit], ]) { for (const smoke of [ "scripts/artifact-download-smoke.js", "scripts/operator-panel-smoke.js", "scripts/source-preparation-smoke.js", "scripts/scheduler-placement-smoke.js", "scripts/flagship-demo-smoke.js", ]) { assert( script.includes(`node ${smoke}`), `${scriptName} must run ${smoke} as part of tenant-isolation release blocking` ); } assert( script.includes("scripts/release-source-scan.sh"), `${scriptName} must run release-source-scan.sh as part of release blocking` ); } assert( privateAcceptance.includes("node private/hosted-policy/scripts/hosted-community-smoke.js"), "private acceptance must run hosted community cross-tenant checks" ); assert( privateAcceptance.includes("node private/hosted-policy/scripts/hosted-deployment-smoke.js"), "private acceptance must run hosted deployment checks" ); const boundaryEvidence = [ [ "artifact download", artifactDownloadSmoke, [/const crossTenant = await send/, /const crossTenantOpen = await send/, /tenant mismatch/], ], [ "operator panel", operatorPanelSmoke, [/const crossTenant = await send/, /render_operator_panel/, /scope\|tenant\|project/], ], [ "source preparation", sourcePreparationSmoke, [/const crossTenantCompletion = await send/, /complete_source_preparation/, /tenant\\\/project scope/i], ], [ "scheduler/node capability", schedulerSmoke, [/const crossTenantReport = await send/, /report_node_capabilities/, /tenant\\\/project scope/], ], ]; if (hostedCommunitySmoke) { boundaryEvidence.push([ "hosted community", hostedCommunitySmoke, [ /const foreignAgentList = await send/, /const crossTenantMetadata = await send/, /const crossTenantDownload = await send/, /tenant mismatch/, ], ]); } for (const [name, source, patterns] of boundaryEvidence) { for (const pattern of patterns) { expect(source, name, pattern); } } for (const [name, pattern] of [ ["release source scan rejects manual demo state", hiddenDemoScanPattern], ["release source scan rejects hidden local paths", /hidden_local_pattern='file:\/\/\|\/home\/\[.*\]_.-\]\+\/\|\/Users\/\[.*\]_.-\]\+\/\|C:\\\\Users\\\\\|https\?:\/\/\(localhost\|127\\\.0\\\.0\\\.1\)/], ]) { expect(releaseSourceScan, name, pattern); } for (const [name, pattern] of [ ["public split excludes private modules", /--exclude='\.\/private'/], ["public split excludes experiments", /--exclude='\.\/experiments'/], ["public split tests copied workspace", /cargo test --workspace --manifest-path "\$tmp_dir\/Cargo\.toml"/], ["public split builds copied workspace bins", /cargo build --workspace --bins --manifest-path "\$tmp_dir\/Cargo\.toml"/], ["public split installs CLI from copied tree", /\(cd "\$tmp_dir" && node scripts\/cli-install-smoke\.js\)/], ["public split installs VS Code extension from copied tree", /\(cd "\$tmp_dir" && node scripts\/vscode-extension-smoke\.js\)/], ["public split attaches node from copied tree", /\(cd "\$tmp_dir" && node scripts\/node-attach-smoke\.js\)/], ["public split runs local services from copied tree", /\(cd "\$tmp_dir" && node scripts\/local-services-smoke\.js\)/], ["public split runs CLI local workflow from copied tree", /\(cd "\$tmp_dir" && node scripts\/cli-local-run-smoke\.js\)/], ["public split runs artifact download from copied tree", /\(cd "\$tmp_dir" && node scripts\/artifact-download-smoke\.js\)/], ["public split runs artifact export from copied tree", /\(cd "\$tmp_dir" && node scripts\/artifact-export-smoke\.js\)/], ["public split runs DAP smoke from copied tree", /\(cd "\$tmp_dir" && node scripts\/dap-smoke\.js\)/], ["public split runs flagship demo smoke from copied tree", /\(cd "\$tmp_dir" && node scripts\/flagship-demo-smoke\.js\)/], ]) { expect(publicSplit, name, pattern); } for (const [name, pattern] of [ ["flagship demo rejects local machine assumptions", /forbiddenSourceAssumptions/], ["flagship demo rejects coordinator checkout access", /coordinator_requires_checkout_access[\s\S]*false/], ["flagship demo asserts local source bytes stay node-local", /local_source_bytes_remain_node_local[\s\S]*true/], ["flagship demo asserts coordinator receives no source bytes by default", /coordinator_receives_source_bytes_by_default[\s\S]*false/], ["flagship demo asserts no default full repo tarball", /default_full_repo_tarball[\s\S]*false/], ]) { expect(flagshipDemoSmoke, name, pattern); } console.log("Release blocker smoke passed");