package installplan import ( "strings" "testing" "server-deploy/internal/inspect" "server-deploy/internal/preflight" ) func TestDraftPreservesSafetyBlockersAndBindsInputs(t *testing.T) { r := preflight.Report{Runtime: inspect.Report{OS: "linux", Architecture: "amd64"}, Distribution: preflight.Distribution{State: "observed", ID: "ubuntu", Version: "26.04", Codename: "resolute"}} d, err := Build(r, lockFixture()) if err != nil || d.Executable || d.RepositoryAuthenticated || len(d.Blockers) == 0 || !strings.HasPrefix(d.LockDigest, "sha256:") || !strings.HasPrefix(d.ObservationDigest, "sha256:") { t.Fatalf("unsafe draft %+v %v", d, err) } for _, want := range []string{"repository_trust_unverified", "dependency_transaction_unresolved", "artifact_bytes_unverified"} { found := false for _, b := range d.Blockers { if b == want { found = true } } if !found { t.Fatalf("missing blocker %s", want) } } r.Privilege = "non_root" d2, _ := Build(r, lockFixture()) if d2.ObservationDigest == d.ObservationDigest { t.Fatal("report change not bound") } l := lockFixture() r.Distribution.Version = "24.04" r.Distribution.Codename = "noble" if _, err := Build(r, l); err == nil { t.Fatal("host and lock mismatch accepted") } }