//! `new project ` chat command — Phase 4: `--git` clone and push credentials. //! //! Provisions a project container and registers it with the gateway. //! The command is gateway-only: //! `new project [--stack ] [--git ] [--git-token ]` //! //! Without `--stack`, the orchestrator inspects the (just-cloned or //! just-init'd) source tree for stack markers found in //! `docker/stacks//markers` files and auto-selects one, warning in //! chat if multiple stacks matched. With `--stack`, the named stack is used //! unconditionally. //! //! Stack images follow the naming convention `huskies-project-`. //! The base image (no language tooling) is `huskies-project-base`. //! //! Phase 3 (story 1108): an ed25519 SSH keypair is generated per project. //! The private key is stored at `~/.huskies//id_ed25519` on the host. //! The public key is passed to the container as `HUSKIES_SSH_PUBKEY` and //! installed in `~/.ssh/authorized_keys` by the entrypoint. The SSH server //! is bound to a host-local port in the 2200–2300 range and recorded in //! `projects.toml` as `ssh_port`. //! //! Phase 4 (story 1109): //! - `--git ` clones the URL into the host project directory instead of //! running `git init`. Clone failure aborts the bootstrap with no partial //! state left on disk. //! - The container receives `GIT_USER_NAME` and `GIT_USER_EMAIL` env vars drawn //! from `git_user_name`/`git_user_email` in the gateway's `bot.toml`, with //! fallback to the host's `git config user.name`/`user.email`. //! - The host user's SSH keys (`~/.ssh/id_ed25519`, `~/.ssh/id_rsa`) are //! bind-mounted read-only into the container so `git push` over SSH works. //! - `--git-token ` stores the HTTPS push token in the container's //! git credential store via the entrypoint; the token is never echoed in //! chat or logs. //! - After the container starts, `git ls-remote` verifies push credentials and //! surfaces success or an actionable failure message in the chat reply. //! //! Adding a new stack requires only: //! 1. `docker/stacks//Dockerfile.fragment` — overlay instructions //! 2. `docker/stacks//markers` — detection marker filenames //! No changes to this orchestration module are needed. use std::collections::BTreeMap; use std::path::Path; use std::sync::Arc; use tokio::sync::RwLock; use crate::service::gateway::config::ProjectEntry; /// Parsed result of a `new project [--stack ] [--git ] [--git-token ]` command. pub struct NewProjectCommand { /// Project name (alphanumeric, hyphens, underscores). pub name: String, /// Explicitly requested stack, or `None` for auto-detection. pub stack: Option, /// Git repository URL to clone into the project directory instead of running `git init`. /// /// When `Some`, the bootstrap runs `git clone ` instead of `git init`. /// Failure aborts the whole bootstrap with no partial state left on disk. pub git_url: Option, /// HTTPS push token for the repository. /// /// Stored in the container's git credential helper by the entrypoint. /// **Never echoed in any chat reply or log line.** pub git_token: Option, } /// Parse a `new project [--stack ] [--git ] [--git-token ]` command. /// /// Returns `Some(NewProjectCommand)` when the stripped message starts with /// "new project" (case-insensitive). An empty name (bare "new project" with /// no arg) is returned as `Some(name="")` so the handler can emit a usage /// error. Returns `None` for any other message. pub fn extract_new_project_command( message: &str, bot_name: &str, bot_user_id: &str, ) -> Option { let mention_stripped = crate::chat::util::strip_bot_mention(message, bot_name, bot_user_id); // Strip leading punctuation (e.g. colon after "@timmy: new project …") let trimmed = mention_stripped .trim() .trim_start_matches(|c: char| !c.is_alphanumeric()); let mut words = trimmed.split_whitespace(); let first = words.next()?; if !first.eq_ignore_ascii_case("new") { return None; } let second = words.next()?; if !second.eq_ignore_ascii_case("project") { return None; } let name = words.next().unwrap_or("").to_string(); let remaining: Vec<&str> = words.collect(); let stack = parse_flag(&remaining, "--stack"); let git_url = parse_flag(&remaining, "--git"); let git_token = parse_flag(&remaining, "--git-token"); Some(NewProjectCommand { name, stack, git_url, git_token, }) } /// Extract the value of `-- ` from a token slice. fn parse_flag(tokens: &[&str], flag: &str) -> Option { let mut iter = tokens.iter().peekable(); while let Some(tok) = iter.next() { if *tok == flag && let Some(val) = iter.next() { return Some(val.to_string()); } } None } /// Scan `stacks_dir` for per-stack `markers` files and detect which stacks /// match the given project directory. /// /// Returns `(selected_stack, warnings)` where `selected_stack` is the /// auto-detected stack name (or `None` if no markers matched) and `warnings` /// carries a human-readable message when multiple stacks matched. /// /// Each `stacks_dir//markers` file lists one filename per line /// (relative to the project root). Lines starting with `#` and blank lines /// are ignored. If any listed file exists in `project_path`, that stack is /// considered a match. pub fn detect_stack(project_path: &Path, stacks_dir: &Path) -> (Option, Vec) { let entries = match std::fs::read_dir(stacks_dir) { Ok(e) => e, Err(_) => return (None, vec![]), }; // (stack_name, number_of_matched_marker_files) let mut matched: Vec<(String, usize)> = Vec::new(); let mut stack_dirs: Vec<_> = entries .filter_map(|e| e.ok()) .filter(|e| e.path().is_dir()) .collect(); // Deterministic order so multi-match selection is stable. stack_dirs.sort_by_key(|e| e.file_name()); for entry in stack_dirs { let stack_name = entry.file_name().to_string_lossy().into_owned(); let markers_path = entry.path().join("markers"); let Ok(content) = std::fs::read_to_string(&markers_path) else { continue; }; let count = content .lines() .filter(|line| { let trimmed = line.trim(); !trimmed.is_empty() && !trimmed.starts_with('#') && project_path.join(trimmed).exists() }) .count(); if count > 0 { matched.push((stack_name, count)); } } match matched.len() { 0 => (None, vec![]), 1 => (Some(matched.remove(0).0), vec![]), _ => { // Dominant stack: most marker files matched; alphabetical tiebreak for stability. matched.sort_by(|a, b| b.1.cmp(&a.1).then_with(|| a.0.cmp(&b.0))); let names: Vec = matched.iter().map(|(n, _)| n.clone()).collect(); let names_str = names.join(", "); let chosen = matched.swap_remove(0).0; let warning = format!( "Multiple stacks detected ({names_str}); using **{chosen}** \ (most marker files matched). \ Pass `--stack ` to override." ); (Some(chosen), vec![warning]) } } } /// Return the Docker image name for the given stack. /// /// Stack images follow the convention `huskies-project-`. /// When no stack is specified, the base image `huskies-project-base` is used. pub fn image_for_stack(stack: Option<&str>) -> String { match stack { Some(s) => format!("huskies-project-{s}"), None => "huskies-project-base".to_string(), } } /// Read `git_user_name` and `git_user_email` from the gateway's `bot.toml`. /// /// Deserialises directly into `BotConfig` without the enabled/transport /// validation that `BotConfig::load` enforces, so the identity fields are /// always available even when the bot transport is not yet configured. async fn read_git_identity_from_bot_toml( config_dir: &std::path::Path, ) -> (Option, Option) { use crate::chat::transport::matrix::BotConfig; let path = config_dir.join(".huskies").join("bot.toml"); let Ok(content) = tokio::fs::read_to_string(&path).await else { return (None, None); }; let Ok(cfg) = toml::from_str::(&content) else { return (None, None); }; let name = cfg.git_user_name.filter(|s: &String| !s.is_empty()); let email = cfg.git_user_email.filter(|s: &String| !s.is_empty()); (name, email) } /// Read a single key from the host's global git config. async fn read_host_git_config(key: &str) -> Option { let out = tokio::process::Command::new("git") .args(["config", "--global", key]) .output() .await .ok()?; if out.status.success() { let val = String::from_utf8_lossy(&out.stdout).trim().to_string(); if val.is_empty() { None } else { Some(val) } } else { None } } /// Resolve the git identity to use for new project containers. /// /// Priority: `bot.toml` fields → host `git config` → hardcoded fallback. async fn resolve_git_identity(config_dir: &std::path::Path) -> (String, String) { let (bot_name, bot_email) = read_git_identity_from_bot_toml(config_dir).await; let name = if let Some(n) = bot_name { n } else if let Some(n) = read_host_git_config("user.name").await { n } else { "Huskies Agent".to_string() }; let email = if let Some(e) = bot_email { e } else if let Some(e) = read_host_git_config("user.email").await { e } else { "agent@huskies.local".to_string() }; (name, email) } /// Inject a token into an HTTPS git URL for credential-passing. /// /// `https://github.com/user/repo` → `https://x-access-token:@github.com/user/repo` /// The returned URL must NEVER be included in user-visible replies or logs. fn inject_token_into_url(url: &str, token: &str) -> String { if let Some(rest) = url.strip_prefix("https://") { format!("https://x-access-token:{token}@{rest}") } else if let Some(rest) = url.strip_prefix("http://") { format!("http://x-access-token:{token}@{rest}") } else { url.to_string() } } /// Verify push credentials by running `git ls-remote` against the repository. /// /// Returns `Ok(message)` on success or `Err(actionable_message)` on failure. /// The token (if any) is never included in the returned strings. async fn verify_push_credentials(git_url: &str, git_token: Option<&str>) -> Result { let url_for_cmd = match git_token { Some(token) => inject_token_into_url(git_url, token), None => git_url.to_string(), }; let mut cmd = tokio::process::Command::new("git"); cmd.arg("ls-remote").arg(&url_for_cmd); cmd.env("GIT_TERMINAL_PROMPT", "0"); if git_token.is_none() { // SSH: accept new host keys non-interactively; fail fast if no agent. cmd.env( "GIT_SSH_COMMAND", "ssh -o BatchMode=yes -o StrictHostKeyChecking=accept-new", ); } let output = cmd .output() .await .map_err(|e| format!("git ls-remote unavailable: {e}"))?; if output.status.success() { return Ok("Push credentials verified.".to_string()); } let stderr = String::from_utf8_lossy(&output.stderr).trim().to_string(); // Map common failure patterns to actionable messages (no token in output). if stderr.contains("Permission denied") || stderr.contains("publickey") { Err( "SSH key not authorised by remote — check that your public key is \ added to the repository's deploy keys or your account." .to_string(), ) } else if stderr.contains("401") || stderr.contains("403") || stderr.contains("Authentication failed") || stderr.contains("could not read Username") { Err( "Token rejected — verify that the token has read/write access \ to the repository." .to_string(), ) } else { Err(format!( "Push verification failed for `{git_url}`: {stderr}" )) } } /// Generate an ed25519 SSH keypair at `key_path` (private) and `key_path.pub` (public). /// /// Calls `ssh-keygen -t ed25519 -N "" -f ` with no passphrase. /// Returns the public key string (trimmed) on success. async fn generate_ssh_keypair(key_path: &std::path::Path) -> Result { let out = tokio::process::Command::new("ssh-keygen") .args(["-t", "ed25519", "-N", ""]) .arg("-f") .arg(key_path) .output() .await .map_err(|e| format!("ssh-keygen not available: {e}"))?; if !out.status.success() { return Err(format!( "ssh-keygen failed: {}", String::from_utf8_lossy(&out.stderr).trim() )); } let pub_path = key_path.with_extension("pub"); tokio::fs::read_to_string(&pub_path) .await .map(|s| s.trim().to_string()) .map_err(|e| format!("Cannot read public key {}: {e}", pub_path.display())) } /// Bootstrap a new project from the `new project` chat command. /// /// Creates `~/huskies//`, scaffolds `.huskies/`, runs `git clone` (when /// `git_url` is provided) or `git init`, auto-detects or honours the requested /// stack, generates an SSH keypair, launches the appropriate Docker container, /// and registers the project in the gateway's in-memory store and the CRDT. /// /// On any failure after a directory is created, the directory is removed and /// the error message includes "Partial state removed at ``". /// /// `git_token` is never echoed in any returned string or log line. pub async fn handle_new_project( name: &str, stack: Option<&str>, git_url: Option<&str>, git_token: Option<&str>, projects_store: &Arc>>, config_dir: &Path, ) -> String { let name = name.trim(); if name.is_empty() { return "Usage: `new project ` — e.g. `new project myapp`".to_string(); } if !name .chars() .all(|c| c.is_alphanumeric() || c == '-' || c == '_') { return format!( "Invalid project name `{name}`. \ Use letters, digits, hyphens, or underscores only." ); } // Name conflict — check both the in-memory store and the CRDT. { let projects = projects_store.read().await; if projects.contains_key(name) { return format!( "Project `{name}` is already registered. \ Use `switch {name}` to activate it." ); } } // Default host path: ~/huskies// let home = std::env::var("HOME").unwrap_or_else(|_| "/home/huskies".to_string()); let host_path = std::path::PathBuf::from(&home).join("huskies").join(name); if host_path.exists() { return format!( "Path `{}` already exists. \ Choose a different project name or remove the directory first.", host_path.display() ); } // ── git clone or init + scaffold ───────────────────────────────────────── // // For `--git `: git clone creates host_path itself, so we must NOT call // ensure_directory on it beforehand. Scaffold runs after a successful clone. // // For no `--git`: create host_path first, scaffold, then git init (unchanged // from Phase 3 behaviour). if let Some(url) = git_url { // Ensure the parent directory (~/.huskies/) exists but not host_path itself. if let Some(parent) = host_path.parent() && let Err(e) = crate::service::gateway::io::ensure_directory(parent) { return format!( "Failed to create parent directory `{}`: {e}", parent.display() ); } let clone_out = tokio::process::Command::new("git") .arg("clone") .arg(url) .arg(&host_path) .env("GIT_TERMINAL_PROMPT", "0") .output() .await; match clone_out { Err(e) => { return format!("git clone failed: {e}"); } Ok(out) if !out.status.success() => { let stderr = String::from_utf8_lossy(&out.stderr); let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "git clone failed: {}\n\nPartial state removed at `{}`.", stderr.trim(), host_path.display() ); } Ok(_) => {} } // Scaffold .huskies/ into the cloned repo (write_file_if_missing — safe on existing repos). if let Err(e) = crate::service::gateway::io::scaffold_project(&host_path) { let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "Scaffold failed: {e}\n\nPartial state removed at `{}`.", host_path.display() ); } crate::service::gateway::io::init_wizard_state(&host_path); } else { // No --git: create directory, scaffold, then git init. if let Err(e) = crate::service::gateway::io::ensure_directory(&host_path) { return format!("Failed to create `{}`: {e}", host_path.display()); } if let Err(e) = crate::service::gateway::io::scaffold_project(&host_path) { let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "Scaffold failed: {e}\n\nPartial state removed at `{}`.", host_path.display() ); } crate::service::gateway::io::init_wizard_state(&host_path); match tokio::process::Command::new("git") .arg("init") .arg(&host_path) .output() .await { Err(e) => { let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "git init failed: {e}\n\nPartial state removed at `{}`.", host_path.display() ); } Ok(out) if !out.status.success() => { let stderr = String::from_utf8_lossy(&out.stderr); let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "git init failed: {}\n\nPartial state removed at `{}`.", stderr.trim(), host_path.display() ); } Ok(_) => {} } } // ── Detect or validate stack ───────────────────────────────────────────── let stacks_dir = config_dir.join("docker").join("stacks"); let (resolved_stack, detect_warnings) = match stack { Some(s) => (Some(s.to_string()), vec![]), None => detect_stack(&host_path, &stacks_dir), }; let image = image_for_stack(resolved_stack.as_deref()); // ── Generate SSH keypair ───────────────────────────────────────────────── // Private key: ~/.huskies//id_ed25519 (host-side, mode 600 by ssh-keygen) // Public key: installed in the container via HUSKIES_SSH_PUBKEY env var let ssh_key_dir = std::path::PathBuf::from(&home).join(".huskies").join(name); if let Err(e) = tokio::fs::create_dir_all(&ssh_key_dir).await { let _ = tokio::fs::remove_dir_all(&host_path).await; return format!( "Failed to create SSH key directory `{}`: {e}\n\nPartial state removed at `{}`.", ssh_key_dir.display(), host_path.display() ); } let private_key_path = ssh_key_dir.join("id_ed25519"); let pubkey = match generate_ssh_keypair(&private_key_path).await { Ok(k) => k, Err(e) => { let _ = tokio::fs::remove_dir_all(&host_path).await; let _ = tokio::fs::remove_dir_all(&ssh_key_dir).await; return format!( "SSH keypair generation failed: {e}\n\nPartial state removed at `{}`.", host_path.display() ); } }; // ── Resolve git identity ───────────────────────────────────────────────── // Read from bot.toml → fallback to host git config → hardcoded default. let (git_user_name, git_user_email) = resolve_git_identity(config_dir).await; // ── Discover host SSH keys for bind-mounting ───────────────────────────── // The user's personal SSH keys are mounted read-only so `git push` over SSH // works inside the container without copying secrets into the image. let host_ssh_dir = std::path::PathBuf::from(&home).join(".ssh"); let mut ssh_key_mounts: Vec = Vec::new(); for key_name in &["id_ed25519", "id_rsa"] { let key_path = host_ssh_dir.join(key_name); if key_path.exists() { ssh_key_mounts.push(format!( "{}:/home/huskies/.ssh/{key_name}:ro", key_path.display() )); } } // ── Allocate ports and launch container ────────────────────────────────── let port = find_free_port(3100); let ssh_port = find_free_port(2200); let container_url = format!("http://127.0.0.1:{port}"); let container_name = format!("huskies-{name}"); // Build the `docker run` argument list. The token must never appear in any // string that is returned to the caller or written to a log. let mut docker_args: Vec = vec![ "run".into(), "-d".into(), "--name".into(), container_name.clone(), "-p".into(), format!("127.0.0.1:{port}:3001"), "-p".into(), format!("127.0.0.1:{ssh_port}:22"), "-e".into(), format!("HUSKIES_SSH_PUBKEY={pubkey}"), "-e".into(), format!("GIT_USER_NAME={git_user_name}"), "-e".into(), format!("GIT_USER_EMAIL={git_user_email}"), ]; // HTTPS push token: passed as env vars consumed by the entrypoint credential helper. if let Some(token) = git_token { docker_args.push("-e".into()); docker_args.push(format!("GIT_PUSH_TOKEN={token}")); if let Some(url) = git_url { docker_args.push("-e".into()); docker_args.push(format!("GIT_CLONE_URL={url}")); } } // Workspace mount. docker_args.push("-v".into()); docker_args.push(format!("{}:/workspace", host_path.display())); // SSH key bind-mounts (read-only). for mount in &ssh_key_mounts { docker_args.push("-v".into()); docker_args.push(mount.clone()); } docker_args.push("--restart".into()); docker_args.push("unless-stopped".into()); docker_args.push(image.clone()); docker_args.push("huskies".into()); docker_args.push("/workspace".into()); let docker_result = tokio::process::Command::new("docker") .args(&docker_args) .output() .await; match docker_result { Ok(out) if out.status.success() => { // Register in the CRDT (survives restarts). crate::crdt_state::write_gateway_project(name, &container_url); // Update the in-memory projects store and persist to projects.toml. { let mut projects = projects_store.write().await; projects.insert( name.to_string(), ProjectEntry { url: Some(container_url.clone()), auth_token: None, ssh_port: Some(ssh_port), }, ); crate::service::gateway::io::save_config(&projects, config_dir).await; } crate::slog!( "[new-project] Created project '{name}' at {container_url} \ ssh=127.0.0.1:{ssh_port} (image={image})" ); // ── Push credential verification ───────────────────────────────── // Only run when a git URL was provided (clone path); skip for plain // git init projects where there is no remote to verify. let push_note = if let Some(url) = git_url { match verify_push_credentials(url, git_token).await { Ok(msg) => format!("- Push credentials: {msg}\n"), Err(err) => format!("> ⚠ Push verification: {err}\n"), } } else { String::new() }; let stack_note = match resolved_stack.as_deref() { Some(s) => format!("- Stack: **{s}** (`{image}`)\n"), None => String::new(), }; let warning_block = if detect_warnings.is_empty() { String::new() } else { format!("\n> {}\n", detect_warnings.join("\n> ")) }; format!( "{warning_block}Project **{name}** is ready.\n\ - Host path: `{host}`\n\ - Container: `{container_name}` → `{container_url}`\n\ {stack_note}\ {push_note}\ - SSH: `ssh huskies@127.0.0.1 -p {ssh_port} \ -i ~/.huskies/{name}/id_ed25519`\n\ \n\ Use `switch {name}` then `status` to view the pipeline.", host = host_path.display() ) } Ok(out) => { let stderr = String::from_utf8_lossy(&out.stderr); let _ = tokio::fs::remove_dir_all(&host_path).await; let _ = tokio::fs::remove_dir_all(&ssh_key_dir).await; format!( "Docker container launch failed: {}\n\nPartial state removed at `{}`.", stderr.trim(), host_path.display() ) } Err(e) => { let _ = tokio::fs::remove_dir_all(&host_path).await; let _ = tokio::fs::remove_dir_all(&ssh_key_dir).await; format!( "Docker container launch failed: {e}\n\nPartial state removed at `{}`.", host_path.display() ) } } } /// Find a free TCP port by attempting to bind starting from `start`. /// /// Scans up to 100 ports above `start` and returns the first available one. /// Falls back to `start` if none are found (unlikely in practice). fn find_free_port(start: u16) -> u16 { for port in start..start + 100 { if std::net::TcpListener::bind(("127.0.0.1", port)).is_ok() { return port; } } start } // --------------------------------------------------------------------------- // Tests // --------------------------------------------------------------------------- #[cfg(test)] mod tests { use super::*; #[test] fn extract_parses_name() { let cmd = extract_new_project_command("@timmy new project myapp", "Timmy", "@timmy:srv.local") .unwrap(); assert_eq!(cmd.name, "myapp"); assert_eq!(cmd.stack, None); } #[test] fn extract_case_insensitive() { let cmd = extract_new_project_command("@timmy NEW PROJECT myapp", "Timmy", "@timmy:srv.local") .unwrap(); assert_eq!(cmd.name, "myapp"); } #[test] fn extract_bare_project_keyword_returns_empty_name() { let cmd = extract_new_project_command("@timmy new project", "Timmy", "@timmy:srv.local").unwrap(); assert_eq!(cmd.name, ""); } #[test] fn extract_parses_stack_flag() { let cmd = extract_new_project_command( "@timmy new project myapp --stack rust", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.name, "myapp"); assert_eq!(cmd.stack, Some("rust".to_string())); } #[test] fn extract_stack_node() { let cmd = extract_new_project_command( "@timmy new project myapp --stack node", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.stack, Some("node".to_string())); } #[test] fn extract_no_match_for_other_commands() { assert!( extract_new_project_command("@timmy status", "Timmy", "@timmy:srv.local").is_none() ); } #[test] fn extract_no_match_when_second_word_is_not_project() { assert!( extract_new_project_command("@timmy new myapp", "Timmy", "@timmy:srv.local").is_none() ); } #[test] fn extract_handles_extra_whitespace() { let cmd = extract_new_project_command( "@timmy new project myapp", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.name, "myapp"); } #[test] fn image_for_stack_rust() { assert_eq!(image_for_stack(Some("rust")), "huskies-project-rust"); } #[test] fn image_for_stack_node() { assert_eq!(image_for_stack(Some("node")), "huskies-project-node"); } #[test] fn image_for_stack_base() { assert_eq!(image_for_stack(None), "huskies-project-base"); } #[test] fn detect_stack_rust_marker() { let dir = tempfile::tempdir().unwrap(); // Create a fake project with Cargo.toml std::fs::write(dir.path().join("Cargo.toml"), "[package]").unwrap(); // Create a fake stacks dir let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("rust")).unwrap(); std::fs::write( stacks.path().join("rust/markers"), "# comment\nCargo.toml\n", ) .unwrap(); std::fs::create_dir_all(stacks.path().join("node")).unwrap(); std::fs::write( stacks.path().join("node/markers"), "package.json\ntsconfig.json\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("rust".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_node_tsconfig() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("tsconfig.json"), "{}").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("node")).unwrap(); std::fs::write( stacks.path().join("node/markers"), "package.json\ntsconfig.json\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("node".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_no_markers_returns_none() { let dir = tempfile::tempdir().unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("rust")).unwrap(); std::fs::write(stacks.path().join("rust/markers"), "Cargo.toml\n").unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, None); assert!(warnings.is_empty()); } #[test] fn detect_stack_multiple_warn() { let dir = tempfile::tempdir().unwrap(); // Both Cargo.toml and package.json exist. std::fs::write(dir.path().join("Cargo.toml"), "").unwrap(); std::fs::write(dir.path().join("package.json"), "{}").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("node")).unwrap(); std::fs::write(stacks.path().join("node/markers"), "package.json\n").unwrap(); std::fs::create_dir_all(stacks.path().join("rust")).unwrap(); std::fs::write(stacks.path().join("rust/markers"), "Cargo.toml\n").unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); // Alphabetically first: "node" < "rust" assert_eq!(stack, Some("node".to_string())); assert_eq!(warnings.len(), 1); assert!(warnings[0].contains("Multiple stacks")); } #[test] fn detect_stack_missing_stacks_dir_returns_none() { let dir = tempfile::tempdir().unwrap(); let (stack, warnings) = detect_stack(dir.path(), Path::new("/nonexistent/stacks")); assert_eq!(stack, None); assert!(warnings.is_empty()); } #[tokio::test] async fn generate_ssh_keypair_creates_key_files() { // Skip if ssh-keygen is not available in this environment. if tokio::process::Command::new("ssh-keygen") .arg("-V") .output() .await .is_err() { return; } let dir = tempfile::tempdir().unwrap(); let key_path = dir.path().join("id_ed25519"); let pubkey = generate_ssh_keypair(&key_path).await.unwrap(); // Private key file must exist and be non-empty. assert!(key_path.exists(), "private key file not created"); // Public key is returned as a trimmed string starting with the key type. assert!( pubkey.starts_with("ssh-ed25519"), "public key should start with ssh-ed25519, got: {pubkey}" ); // Public key file must also exist. let pub_path = dir.path().join("id_ed25519.pub"); assert!(pub_path.exists(), "public key file not created"); let pub_contents = std::fs::read_to_string(&pub_path).unwrap(); assert_eq!(pub_contents.trim(), pubkey); } #[test] fn find_free_port_returns_bindable_port() { let port = find_free_port(2200); // The returned port must be in range and actually bindable. assert!((2200..2300).contains(&port)); let listener = std::net::TcpListener::bind(("127.0.0.1", port)); assert!(listener.is_ok(), "returned port {port} is not bindable"); } #[test] fn detect_stack_go_mod() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("go.mod"), "module example").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("go")).unwrap(); std::fs::write(stacks.path().join("go/markers"), "go.mod\n").unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("go".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_python_pyproject() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("pyproject.toml"), "[tool.poetry]").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("python")).unwrap(); std::fs::write( stacks.path().join("python/markers"), "pyproject.toml\nrequirements.txt\nsetup.py\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("python".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_python_requirements_txt() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("requirements.txt"), "flask\n").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("python")).unwrap(); std::fs::write( stacks.path().join("python/markers"), "pyproject.toml\nrequirements.txt\nsetup.py\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("python".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_python_setup_py() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("setup.py"), "from setuptools import setup").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("python")).unwrap(); std::fs::write( stacks.path().join("python/markers"), "pyproject.toml\nrequirements.txt\nsetup.py\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("python".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_ruby_gemfile() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("Gemfile"), "source 'https://rubygems.org'").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("ruby")).unwrap(); std::fs::write(stacks.path().join("ruby/markers"), "Gemfile\n").unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("ruby".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_jvm_pom_xml() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("pom.xml"), "").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("jvm")).unwrap(); std::fs::write( stacks.path().join("jvm/markers"), "pom.xml\nbuild.gradle\nbuild.gradle.kts\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("jvm".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_jvm_build_gradle() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("build.gradle"), "plugins { }").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("jvm")).unwrap(); std::fs::write( stacks.path().join("jvm/markers"), "pom.xml\nbuild.gradle\nbuild.gradle.kts\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("jvm".to_string())); assert!(warnings.is_empty()); } #[test] fn detect_stack_jvm_build_gradle_kts() { let dir = tempfile::tempdir().unwrap(); std::fs::write(dir.path().join("build.gradle.kts"), "plugins { }").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("jvm")).unwrap(); std::fs::write( stacks.path().join("jvm/markers"), "pom.xml\nbuild.gradle\nbuild.gradle.kts\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); assert_eq!(stack, Some("jvm".to_string())); assert!(warnings.is_empty()); } // ── Phase 4: --git and --git-token flag parsing ────────────────────────── #[test] fn extract_parses_git_flag() { let cmd = extract_new_project_command( "@timmy new project myapp --git https://github.com/user/repo", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.name, "myapp"); assert_eq!( cmd.git_url, Some("https://github.com/user/repo".to_string()) ); assert_eq!(cmd.git_token, None); } #[test] fn extract_parses_git_token_flag() { let cmd = extract_new_project_command( "@timmy new project myapp --git https://github.com/user/repo --git-token ghp_secret", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!( cmd.git_url, Some("https://github.com/user/repo".to_string()) ); assert_eq!(cmd.git_token, Some("ghp_secret".to_string())); } #[test] fn extract_git_token_without_git_url() { let cmd = extract_new_project_command( "@timmy new project myapp --git-token ghp_secret", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.git_url, None); assert_eq!(cmd.git_token, Some("ghp_secret".to_string())); } #[test] fn extract_git_flag_with_stack() { let cmd = extract_new_project_command( "@timmy new project myapp --stack rust --git git@github.com:user/repo.git", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.stack, Some("rust".to_string())); assert_eq!( cmd.git_url, Some("git@github.com:user/repo.git".to_string()) ); } #[test] fn extract_no_git_flag_returns_none_fields() { let cmd = extract_new_project_command( "@timmy new project myapp --stack node", "Timmy", "@timmy:srv.local", ) .unwrap(); assert_eq!(cmd.git_url, None); assert_eq!(cmd.git_token, None); } #[test] fn inject_token_into_https_url() { let result = inject_token_into_url("https://github.com/user/repo", "mytoken"); assert_eq!( result, "https://x-access-token:mytoken@github.com/user/repo" ); } #[test] fn inject_token_into_http_url() { let result = inject_token_into_url("http://gitea.local/user/repo", "tok123"); assert_eq!(result, "http://x-access-token:tok123@gitea.local/user/repo"); } #[test] fn inject_token_into_ssh_url_passthrough() { // SSH URLs are returned unchanged — token injection only applies to HTTPS. let url = "git@github.com:user/repo.git"; let result = inject_token_into_url(url, "token"); assert_eq!(result, url); } #[tokio::test] async fn read_git_identity_from_bot_toml_reads_fields() { let dir = tempfile::tempdir().unwrap(); let huskies_dir = dir.path().join(".huskies"); std::fs::create_dir_all(&huskies_dir).unwrap(); std::fs::write( huskies_dir.join("bot.toml"), "enabled = true\ntransport = \"matrix\"\ngit_user_name = \"Test User\"\ngit_user_email = \"test@example.com\"\n", ) .unwrap(); let (name, email) = read_git_identity_from_bot_toml(dir.path()).await; assert_eq!(name, Some("Test User".to_string())); assert_eq!(email, Some("test@example.com".to_string())); } #[tokio::test] async fn read_git_identity_from_bot_toml_missing_file_returns_nones() { let dir = tempfile::tempdir().unwrap(); let (name, email) = read_git_identity_from_bot_toml(dir.path()).await; assert_eq!(name, None); assert_eq!(email, None); } #[tokio::test] async fn resolve_git_identity_uses_bot_toml_values() { let dir = tempfile::tempdir().unwrap(); let huskies_dir = dir.path().join(".huskies"); std::fs::create_dir_all(&huskies_dir).unwrap(); std::fs::write( huskies_dir.join("bot.toml"), "enabled = true\ntransport = \"matrix\"\ngit_user_name = \"Bot Name\"\ngit_user_email = \"bot@example.com\"\n", ) .unwrap(); let (name, email) = resolve_git_identity(dir.path()).await; assert_eq!(name, "Bot Name"); assert_eq!(email, "bot@example.com"); } #[tokio::test] async fn resolve_git_identity_falls_back_to_defaults_when_no_config() { let dir = tempfile::tempdir().unwrap(); // No bot.toml and git config may or may not have values on CI — we only // check that the result is non-empty strings (not panics or errors). let (name, email) = resolve_git_identity(dir.path()).await; assert!(!name.is_empty(), "name must be non-empty"); assert!(!email.is_empty(), "email must be non-empty"); } /// A polyglot repo with more Python markers than Node markers should prefer python. #[test] fn detect_stack_multiple_dominant_wins() { let dir = tempfile::tempdir().unwrap(); // Two Python markers: pyproject.toml + requirements.txt std::fs::write(dir.path().join("pyproject.toml"), "").unwrap(); std::fs::write(dir.path().join("requirements.txt"), "").unwrap(); // One Node marker: package.json (e.g. for a build tool) std::fs::write(dir.path().join("package.json"), "{}").unwrap(); let stacks = tempfile::tempdir().unwrap(); std::fs::create_dir_all(stacks.path().join("node")).unwrap(); std::fs::write( stacks.path().join("node/markers"), "package.json\ntsconfig.json\n", ) .unwrap(); std::fs::create_dir_all(stacks.path().join("python")).unwrap(); std::fs::write( stacks.path().join("python/markers"), "pyproject.toml\nrequirements.txt\nsetup.py\n", ) .unwrap(); let (stack, warnings) = detect_stack(dir.path(), stacks.path()); // python matches 2 markers, node matches 1 — python should win. assert_eq!(stack, Some("python".to_string())); assert_eq!(warnings.len(), 1); assert!(warnings[0].contains("Multiple stacks")); } }