Files
hyperframes/skills/media-use/scripts/lib/registry.test.mjs
T
Miguel Ángel 401dd1d27f fix: media-use bug-bash fixes (codex gate, id race, provider/reuse/adopt guards) + CLI unknown-flag rejection (#2033)
* fix(media-use): codex gate misfires as 'not logged in' when piped

codexUnavailableReason() gated generation on parsing `codex login status`
stdout, but that command prints 'Logged in using ChatGPT' to stderr and
exits 0 — so the piped stdout media-use captures (execFileSync returns
stdout only on success) was empty, and the gate falsely reported 'not
logged in'. Every headless / CI / agent run was blocked from codex image
gen even when fully authed.

Gate on the durable credentials file ($CODEX_HOME/auth.json) instead of
the TTY/stderr-only human text. Token validity is still proven by the
exec, which fails cleanly on a stale login. The stdout `features list`
capability check is unchanged.

Verified: reproduced the false 'not logged in' block, then after the fix
generated end-to-end via `resolve -t image --provider codex` (valid
1254x1254 PNG, source=generated, provider=codex.image_gen).

* fix(media-use): bug-bash fixes — id race, provider/reuse/adopt guards

From the bug-bash against main:

- MU-23 (HIGH): concurrent resolves raced on nextId (read-max-then-append,
  non-atomic), so parallel agents got duplicate ids and clobbered each
  other's files. Add allocateId(): a coarse per-project lock (.media/.lock,
  15s stale-steal) around id allocation that scans the manifest AND the
  type dir for reserved ids, then O_EXCL-creates a placeholder file so the
  slow download between allocate and append can't collide. 5 parallel
  resolves now yield 5 distinct ids + files.
- X4: --reuse imported across a type mismatch (bgm asset under images/).
  Apply typesMatch on the --reuse path; reject mismatches (icon<->image
  still interchangeable).
- X5: --provider silently overrode --local-only and made a network call.
  --local-only is now a hard guard: network providers are skipped even
  under a forced provider; the miss message explains the conflict.
- BUG-2: --provider ignored the exact-cache floor and could hand back an
  asset from a different provider. A forced --provider now bypasses all
  reuse rungs (regenerate with THIS provider); the unforced floor is intact.
- MU-26/X6: 0-byte assets accepted. --adopt skips 0-byte files (loud); ingest
  refuses a 0-byte local file (freezeUrl already rejects empty responses).
- BUG-4: unknown/unavailable --provider now errors with the available list
  instead of a generic 'no provider could resolve' (typo != catalog miss).
- BUG-5: --reuse "" gave the wrong 'type and intent required' error; it now
  routes to a clear empty-sha message.
- BUG-3: voice duration leaked an unrounded float into index.md; round all
  durations to 0.1s centrally at record build (matches probe).
- Nits: whitespace-only --intent is rejected; nudge grammar (exists/exist).

Tests: allocateId reservation + registry local-only-wins added; full
media-use suite green. All fixes verified e2e.

* fix(cli): reject unknown flags instead of silently ignoring them

citty is permissive: an unrecognized flag was dropped, not rejected — so
`render . --out x` (the flag is --output/-o) silently ignored --out and
rendered to the default renders/<name>.mp4 path. A mistyped flag read as a
render/catalog miss.

Add assertKnownFlags(): validate every dash-prefixed token against the
command's declared args + aliases + the global set (help/version/json)
before the command runs, in the shared trackCommandFailures run-wrapper so
every leaf command is covered. Handles --flag=value, --no-<bool> negation,
camelCase<->kebab arg names, and combined shorts; stops at --; positionals
and flag values pass through.

Verified: `render . --out x` -> 'Error: Unknown flag: --out'; --output/-o/
--json/--help still accepted. Unit tests added.

* docs(skills): install with --full-depth so agents get current main

The documented `npx skills add heygen-com/hyperframes` fetched the
skills.sh registry blob, which lags GitHub main by hours — so users
following the docs got a stale skill (e.g. media-use v1: no --candidates,
voice stubbed). The CLI's own `hyperframes skills` command already forces
a full clone via --full-depth to bypass this; the docs didn't pass it.

Add --full-depth to every documented install command (README, CLAUDE.md,
docs/guides/skills.mdx) with a one-line note on the lag. Addresses the
user-facing half of the publish/registry lag (#2034).

* chore(media-use): collapse resolve.mjs import to satisfy oxfmt --check

* fix(cli): extract longFlagName to keep flag validator under complexity gate

Also regenerate skills-manifest.json (resolve.mjs formatting change re-hashed
the media-use skill). Fixes the Fallow audit + skills-manifest-in-sync CI gates.
2026-07-07 19:19:28 -04:00

166 lines
6.2 KiB
JavaScript

import { strict as assert } from "node:assert";
import { test } from "node:test";
import { getProviders, getProvider, listTypes, runProviders, runCapability } from "./registry.mjs";
// --- registry shape -------------------------------------------------------
test("listTypes exposes the v2 media types", () => {
const types = listTypes();
for (const t of ["bgm", "sfx", "image", "icon", "voice", "brand"]) {
assert.ok(types.includes(t), `missing type: ${t}`);
}
});
test("heygen provider is first for every type it serves", () => {
for (const t of ["bgm", "sfx", "image", "icon"]) {
const first = getProviders(t)[0];
assert.ok(first, `no enabled provider for ${t}`);
assert.match(first.name, /^heygen/, `${t} first provider is ${first.name}`);
}
});
test("sanctioned providers only: heygen, local mflux/kokoro, codex, design spec", () => {
const allowed = /^heygen|^mflux\.local$|^kokoro\.local$|^codex\.image_gen$|^design_spec$/;
for (const t of listTypes()) {
for (const p of getProviders(t)) {
assert.ok(allowed.test(p.name), `${t} lists unsanctioned provider: ${p.name}`);
}
}
});
test("image cascade: heygen catalog, then local mflux, then the codex upsell", () => {
const ps = getProviders("image");
assert.match(ps[0].name, /^heygen/, "heygen catalog first");
const names = ps.map((p) => p.name);
const mflux = ps.find((p) => p.name === "mflux.local");
const codex = ps.find((p) => p.name === "codex.image_gen");
assert.ok(mflux && typeof mflux.generate === "function", "local mflux registered");
assert.ok(codex && typeof codex.generate === "function", "codex upsell registered");
assert.ok(names.indexOf("mflux.local") < names.indexOf("codex.image_gen"), "local before codex");
assert.ok(!mflux.network, "local mflux is kept under --local-only");
assert.ok(codex.network, "codex is network (skipped under --local-only)");
});
test("voice cascade: local Kokoro first (free), HeyGen TTS as the paid upsell", () => {
const ps = getProviders("voice");
assert.equal(ps[0].name, "kokoro.local", "local Kokoro comes first now (HeyGen TTS is paid)");
assert.ok(!ps[0].network, "local Kokoro kept under --local-only");
assert.ok(!ps[0].paid, "local Kokoro is free");
const heygen = ps.find((p) => p.name === "heygen.tts");
assert.ok(heygen && heygen.paid, "HeyGen TTS is the paid upsell");
assert.ok(heygen.network, "HeyGen TTS is network (skipped under --local-only)");
});
test("ctx.provider forces one generator (e.g. 'make an image WITH codex')", async () => {
const providers = [
{ name: "heygen.asset.search", network: true, search: async () => null },
{ name: "mflux.local", generate: async () => ({ hit: "local" }) },
{ name: "codex.image_gen", network: true, generate: async () => ({ hit: "codex" }) },
];
// no override: local wins (first generate to return non-null)
assert.deepEqual(await runProviders(providers, "generate", "x", {}), { hit: "local" });
// override to codex: skip local, use codex even though local would have worked
assert.deepEqual(await runProviders(providers, "generate", "x", { provider: "codex" }), {
hit: "codex",
});
// override matches the full name too
assert.deepEqual(
await runProviders(providers, "generate", "x", { provider: "codex.image_gen" }),
{ hit: "codex" },
);
// --local-only wins even over a forced network provider: no network call,
// clean miss (the caller surfaces the conflict). A forced LOCAL provider under
// --local-only still runs.
assert.equal(
await runProviders(providers, "generate", "x", { provider: "codex", localOnly: true }),
null,
);
assert.deepEqual(
await runProviders(providers, "generate", "x", { provider: "mflux", localOnly: true }),
{ hit: "local" },
);
});
test("getProvider returns the first provider with its type, throws for unknown", () => {
const p = getProvider("bgm");
assert.equal(p.type, "bgm");
assert.equal(typeof p.search, "function");
assert.throws(() => getProvider("unknown_type"), /unknown media type/);
});
test("getProviders throws for unknown type", () => {
assert.throws(() => getProviders("nope"), /unknown media type/);
});
// --- deterministic capability execution (runProviders core) ---------------
test("runProviders calls providers in order and returns the first non-null", async () => {
const calls = [];
const providers = [
{
name: "a",
enabled: true,
search: async () => {
calls.push("a");
return null;
},
},
{
name: "b",
enabled: true,
search: async () => {
calls.push("b");
return { hit: "b" };
},
},
{
name: "c",
enabled: true,
search: async () => {
calls.push("c");
return { hit: "c" };
},
},
];
const res = await runProviders(providers, "search", "x", {});
assert.deepEqual(res, { hit: "b" });
assert.deepEqual(calls, ["a", "b"], "must stop at first non-null, never call c");
});
test("runProviders skips providers missing the requested capability", async () => {
const providers = [
{ name: "a", enabled: true /* no search */ },
{ name: "b", enabled: true, search: async () => ({ hit: "b" }) },
];
const res = await runProviders(providers, "search", "x", {});
assert.deepEqual(res, { hit: "b" });
});
test("runProviders returns null when no provider yields a result", async () => {
const providers = [{ name: "a", enabled: true, search: async () => null }];
assert.equal(await runProviders(providers, "search", "x", {}), null);
});
test("runCapability('bgm','process') is null — process slot is graceful when unfilled", async () => {
assert.equal(await runCapability("bgm", "process", "x", {}), null);
});
test("--local-only skips every network provider (even free remote ones)", async () => {
let remoteRan = false;
const providers = [
{
name: "heygen",
network: true,
search: async () => {
remoteRan = true;
return { hit: "net" };
},
},
{ name: "local", search: async () => ({ hit: "local" }) },
];
assert.deepEqual(await runProviders(providers, "search", "x", { localOnly: true }), {
hit: "local",
});
assert.equal(remoteRan, false, "the remote provider must not be called offline");
});