flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/scripts/runner-release.test.mjs

42 lines2,069 bytesCodeBlame
1// node --test scripts/runner-release.test.mjs
2import assert from "node:assert/strict";
3import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
4import { tmpdir } from "node:os";
5import { join } from "node:path";
6import { test } from "node:test";
7import { createPrivateKey } from "node:crypto";
8
9import { TARGETS, keygen, manifest, sha256, signBytes, verifyBytes, version } from "./runner-release.mjs";
10
11test("a release is signed with the private key and checked with the raw public key", () => {
12 const keys = keygen();
13 assert.equal(Buffer.from(keys.public, "base64").length, 32);
14 const key = createPrivateKey({ key: Buffer.from(keys.private, "base64"), format: "der", type: "pkcs8" });
15 const bytes = Buffer.from('{"version":"0.2.0","files":{}}');
16 const signature = signBytes(bytes, key);
17 assert.equal(Buffer.from(signature, "base64").length, 64);
18 assert.ok(verifyBytes(bytes, signature, keys.public));
19 assert.ok(!verifyBytes(Buffer.from('{"version":"9.9.9","files":{}}'), signature, keys.public));
20 assert.ok(!verifyBytes(bytes, signature, keygen().public));
21});
22
23test("the manifest names each binary that was built, with its SHA-256", () => {
24 const dir = mkdtempSync(join(tmpdir(), "runner-release-"));
25 try {
26 writeFileSync(join(dir, TARGETS["linux-x64"].file), "linux");
27 writeFileSync(join(dir, TARGETS["windows-x64"].file), "windows");
28 const m = manifest(dir, "0.2.0", "example/agent:0.2.0");
29 assert.equal(m.version, "0.2.0");
30 assert.equal(m.agent_image, "example/agent:0.2.0");
31 assert.deepEqual(Object.keys(m.files).sort(), ["linux-x64", "windows-x64"]);
32 assert.equal(m.files["linux-x64"].sha256, sha256(Buffer.from("linux")));
33 assert.equal(m.files["windows-x64"].name, "g1t-runner-windows-x64.exe");
34 } finally {
35 rmSync(dir, { recursive: true, force: true });
36 }
37});
38
39test("platforms are named as the runner names them", () => {
40 assert.deepEqual(Object.keys(TARGETS).sort(), ["linux-arm64", "linux-x64", "macos-arm64", "macos-x64", "windows-x64"]);
41 assert.match(version(), /^\d+\.\d+\.\d+/);
42});