Files
VoiceStudio/tests/backend/core/test_gatekeeper_detect.py
T
Palash DebnathandClaude Opus 4.7 c32041289d Phase 1 Wave 3: AppImage launcher + .deb ffprobe + Docker LAN + Gatekeeper probe (closes #54, #56, #76, #80) (#93)
* fix(appimage): conditional WEBKIT_DISABLE_COMPOSITING_MODE launcher (#56)

WebKitGTK 2.44.x and 2.46.x have a compositing-path regression on Wayland
that blanks the AppImage's first paint on Fedora 44 / Ubuntu 24.04. Setting
WEBKIT_DISABLE_COMPOSITING_MODE=1 forces the software fallback that works,
but blindly setting it on healthy WebKit versions (2.48+) regresses those.

This wave adds a conditional AppRun launcher that detects the WebKit
version via pkg-config and only sets the env var on the broken ranges
(plus a fail-safe when pkg-config is absent or the version is unknown).
The launcher is injected into Tauri's AppImage staging dir via a
beforeBundleCommand hook — see .planning/decisions/apprun-strategy.md for
the spike outcome and rationale (Strategy B chosen).

Phase 1 Wave 3 — Plan 01-03 Task 1. Closes #56 frontend half.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(deb): relocate bundled ffprobe out of /usr/bin to avoid conflicts (#76)

Prior versions placed the bundled ffprobe at /usr/bin/ffprobe via Tauri's
externalBin, which overwrites the system ffprobe on Ubuntu 26.04 and
collides with apt-installed media-package ffprobe.

Relocate the .deb-bundled ffprobe to /usr/lib/omnivoice-studio/bin/ffprobe
via bundle.linux.deb.files, plus defensive maintainer scripts:
  - preinst:  ensure target dir exists for upgrade flows
  - postinst: remove legacy /usr/bin/ffprobe ONLY when dpkg confirms our
              package owns it (never touches a user's distro ffprobe)
  - postrm:   clean up the relocated path tree on purge/remove

Rust side (tools.rs::resolve_ffprobe) now probes the new path on Linux,
and backend spawn (backend.rs) carries both FFPROBE_PATH (legacy alias)
and OMNIVOICE_FFPROBE_PATH (canonical) into the backend env. Python side
(ffmpeg_utils.resolve_ffprobe) reads OMNIVOICE_FFPROBE_PATH first, falls
back to FFPROBE_PATH, then to shutil.which("ffprobe").

6 new unit tests cover the env-cascade resolution.

Phase 1 Wave 3 — Plan 01-03 Task 2. Closes #76.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(frontend): centralised apiBase resolver for Docker LAN access (#80)

Docker / LAN browser users hit the preview API at the LAN host's IP, not
their local machine — the prior frontend/src/utils/media.js:20 hardcoded
http://localhost:3900, which from a LAN client resolved to the client
machine itself.

Centralise via frontend/src/utils/apiBase.ts:
  1. VITE_OMNIVOICE_API override (Docker compose / dev) always wins.
  2. Tauri webview → http://localhost:3900 (unchanged behaviour).
  3. Plain browser → ${window.location.protocol}//${window.location.hostname}:3900
     (follows the page's origin — closes #80).
  4. SSR / no-window → http://localhost:3900 (safe fallback).

Grep-sweep confirmed media.js:20 was the only hardcode site (Assumption
A4 in 01-RESEARCH.md verified). 6 new vitest cases cover the resolver.

Phase 1 Wave 3 — Plan 01-03 Task 3. Closes #80 frontend half.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(backend): macOS Gatekeeper quarantine probe + INST-01 guard (#54)

Adds backend/core/gatekeeper_detect.py which walks up from sys.executable
to find the .app bundle and runs `xattr -l` to check for the quarantine
extended attribute (com.apple.quarantine). On detection, the lifespan
startup probe logs a structured warning and emits a system_error event
through the existing event bus with error_class="GATEKEEPER_QUARANTINE",
which Wave 2's React ErrorBoundary turns into a docs deeplink.

Detection is informational only — we never auto-run `xattr -cr` (the app
itself is quarantined and cannot fix its own state per Anti-Pattern in
01-RESEARCH.md). Users get a clear pointer to the workaround docs.

GET /system/quarantine-status exposes the structured payload so the
frontend can poll on first load.

INST-01 (setuptools>=75.0 pin from PR #62) gains a PR-time guard in
tests/backend/test_pyproject.py + a user-observable smoke check in
scripts/smoke-test.sh (pkg_resources + whisperx import).

7 gatekeeper tests + 1 pyproject test added — all pass.

Phase 1 Wave 3 — Plan 01-03 Task 4. Closes #54 backend half (Wave 2 owns
the docs page + ErrorBoundary deeplink wiring).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 05:53:15 +05:30

126 lines
4.6 KiB
Python

"""Tests for backend/core/gatekeeper_detect.py (Phase 1 Wave 3, issue #54).
Covers :func:`is_app_quarantined`'s detection across platforms, missing
``xattr`` binary, timeouts, and the bundle-path walk. Also asserts the
:func:`quarantine_status` payload shape that the React ErrorBoundary
consumes via /system/quarantine-status.
"""
import subprocess
import sys
import pytest
@pytest.fixture
def detect():
"""Import the module fresh — it has no module-level state, but this
keeps tests stable if any future refactor adds caching."""
import importlib
from core import gatekeeper_detect
importlib.reload(gatekeeper_detect)
return gatekeeper_detect
def test_returns_false_on_non_macos(monkeypatch, detect):
"""On any non-Darwin platform the function returns False without ever
invoking xattr."""
monkeypatch.setattr(sys, "platform", "linux")
def _explode(*args, **kwargs): # pragma: no cover — should never be called
raise AssertionError("subprocess.run must not be called on non-darwin")
monkeypatch.setattr(subprocess, "run", _explode)
assert detect.is_app_quarantined() is False
# Status payload also reflects it.
status = detect.quarantine_status()
assert status["quarantined"] is False
assert status["error_class"] is None
def test_returns_true_when_xattr_lists_quarantine(monkeypatch, detect):
"""On Darwin with a quarantined bundle, xattr stdout contains
``com.apple.quarantine`` → returns True."""
monkeypatch.setattr(sys, "platform", "darwin")
class _Result:
stdout = "com.apple.quarantine: 0083;6450c4b8;Chrome;\nother.attr: 1\n"
stderr = ""
returncode = 0
monkeypatch.setattr(subprocess, "run", lambda *a, **kw: _Result())
# Provide an explicit bundle path so we do not depend on sys.executable.
assert detect.is_app_quarantined("/Applications/Fake.app") is True
def test_returns_false_when_xattr_absent(monkeypatch, detect):
"""xattr returns empty stdout → not quarantined."""
monkeypatch.setattr(sys, "platform", "darwin")
class _Result:
stdout = ""
stderr = ""
returncode = 0
monkeypatch.setattr(subprocess, "run", lambda *a, **kw: _Result())
assert detect.is_app_quarantined("/Applications/Fake.app") is False
def test_returns_false_when_xattr_binary_missing(monkeypatch, detect):
"""FileNotFoundError (xattr not on PATH) → safe False, no crash."""
monkeypatch.setattr(sys, "platform", "darwin")
def _raise(*a, **kw):
raise FileNotFoundError("xattr not found")
monkeypatch.setattr(subprocess, "run", _raise)
assert detect.is_app_quarantined("/Applications/Fake.app") is False
def test_returns_false_on_timeout(monkeypatch, detect):
"""xattr timeout → safe False, log warning, do not propagate."""
monkeypatch.setattr(sys, "platform", "darwin")
def _raise(*a, **kw):
raise subprocess.TimeoutExpired(cmd=["xattr"], timeout=5)
monkeypatch.setattr(subprocess, "run", _raise)
assert detect.is_app_quarantined("/Applications/Fake.app") is False
def test_quarantine_status_shape(monkeypatch, detect):
"""quarantine_status() returns the keys the frontend ErrorBoundary
expects: quarantined, bundle_path, error_class."""
monkeypatch.setattr(sys, "platform", "darwin")
class _Result:
stdout = "com.apple.quarantine: 0083;6450c4b8;Chrome;"
stderr = ""
returncode = 0
monkeypatch.setattr(subprocess, "run", lambda *a, **kw: _Result())
# Force the bundle resolver to return a known path so the assertion
# below isn't platform-dependent.
monkeypatch.setattr(detect, "_resolve_app_bundle_path", lambda: "/Applications/Fake.app")
status = detect.quarantine_status()
assert set(status.keys()) == {"quarantined", "bundle_path", "error_class"}
assert status["quarantined"] is True
assert status["bundle_path"] == "/Applications/Fake.app"
assert status["error_class"] == detect.ERROR_CLASS == "GATEKEEPER_QUARANTINE"
def test_returns_false_when_not_inside_app_bundle(monkeypatch, detect):
"""Dev runs (sys.executable not inside a .app) → returns False without
invoking xattr."""
monkeypatch.setattr(sys, "platform", "darwin")
monkeypatch.setattr(sys, "executable", "/usr/local/bin/python3.12")
def _explode(*args, **kwargs): # pragma: no cover
raise AssertionError("subprocess.run must not be called for dev runs")
monkeypatch.setattr(subprocess, "run", _explode)
# Call without passing bundle_path so _resolve_app_bundle_path runs.
assert detect.is_app_quarantined() is False