44//! dry-run flag-propagation branches each command's `run` has.
55
66use std:: path:: { Path , PathBuf } ;
7- use std:: process:: Command ;
87
98use sha2:: { Digest , Sha256 } ;
109
@@ -95,11 +94,9 @@ fn make_applicable_npm_patch(root: &Path) {
9594fn apply_dry_run_empty_manifest_emits_dry_run_envelope ( ) {
9695 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
9796 make_socket_with_empty_manifest ( tmp. path ( ) ) ;
98- let out = Command :: new ( binary ( ) )
97+ let out = crate :: common :: hermetic_command ( & binary ( ) )
9998 . args ( [ "apply" , "--json" , "--dry-run" ] )
10099 . current_dir ( tmp. path ( ) )
101- . env_remove ( "SOCKET_API_TOKEN" )
102- . env_remove ( "SOCKET_CLI_API_TOKEN" )
103100 . output ( )
104101 . expect ( "run apply" ) ;
105102 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -165,11 +162,9 @@ fn apply_dry_run_with_real_patch_verifies_without_mutating() {
165162 ) ;
166163
167164 // ---- DRY RUN ----
168- let out = Command :: new ( binary ( ) )
165+ let out = crate :: common :: hermetic_command ( & binary ( ) )
169166 . args ( [ "apply" , "--json" , "--dry-run" , "--offline" ] )
170167 . current_dir ( tmp. path ( ) )
171- . env_remove ( "SOCKET_API_TOKEN" )
172- . env_remove ( "SOCKET_CLI_API_TOKEN" )
173168 . output ( )
174169 . expect ( "run apply --dry-run" ) ;
175170 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -249,11 +244,9 @@ fn apply_dry_run_with_real_patch_verifies_without_mutating() {
249244 // This guarantees the dry-run assertions above are non-vacuous: the
250245 // patch really is applicable, so "nothing changed" under --dry-run is a
251246 // meaningful result rather than an artifact of an inapplicable fixture.
252- let out2 = Command :: new ( binary ( ) )
247+ let out2 = crate :: common :: hermetic_command ( & binary ( ) )
253248 . args ( [ "apply" , "--json" , "--offline" ] )
254249 . current_dir ( tmp. path ( ) )
255- . env_remove ( "SOCKET_API_TOKEN" )
256- . env_remove ( "SOCKET_CLI_API_TOKEN" )
257250 . output ( )
258251 . expect ( "run apply (real)" ) ;
259252 let stdout2 = String :: from_utf8_lossy ( & out2. stdout ) ;
@@ -335,11 +328,9 @@ fn apply_dry_run_human_count_excludes_vendored() {
335328 // Prove the fixture is non-vacuous first: in JSON mode the vendored
336329 // entry must classify as skipped/vendored (if the vendor ledger were
337330 // unreadable it would fail open and this test would assert nothing).
338- let out = Command :: new ( binary ( ) )
331+ let out = crate :: common :: hermetic_command ( & binary ( ) )
339332 . args ( [ "apply" , "--json" , "--dry-run" , "--offline" ] )
340333 . current_dir ( tmp. path ( ) )
341- . env_remove ( "SOCKET_API_TOKEN" )
342- . env_remove ( "SOCKET_CLI_API_TOKEN" )
343334 . output ( )
344335 . expect ( "run apply --json --dry-run" ) ;
345336 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -366,11 +357,9 @@ fn apply_dry_run_human_count_excludes_vendored() {
366357
367358 // The human summary must agree with that classification: only the
368359 // genuinely applicable package counts as patchable.
369- let out = Command :: new ( binary ( ) )
360+ let out = crate :: common :: hermetic_command ( & binary ( ) )
370361 . args ( [ "apply" , "--dry-run" , "--offline" ] )
371362 . current_dir ( tmp. path ( ) )
372- . env_remove ( "SOCKET_API_TOKEN" )
373- . env_remove ( "SOCKET_CLI_API_TOKEN" )
374363 . output ( )
375364 . expect ( "run apply --dry-run" ) ;
376365 assert_eq ! ( out. status. code( ) , Some ( 0 ) ) ;
@@ -387,11 +376,9 @@ fn apply_dry_run_human_count_excludes_vendored() {
387376fn repair_dry_run_offline_emits_dry_run_envelope ( ) {
388377 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
389378 make_socket_with_empty_manifest ( tmp. path ( ) ) ;
390- let out = Command :: new ( binary ( ) )
379+ let out = crate :: common :: hermetic_command ( & binary ( ) )
391380 . args ( [ "repair" , "--json" , "--dry-run" , "--offline" ] )
392381 . current_dir ( tmp. path ( ) )
393- . env_remove ( "SOCKET_API_TOKEN" )
394- . env_remove ( "SOCKET_CLI_API_TOKEN" )
395382 . output ( )
396383 . expect ( "run repair" ) ;
397384 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -415,11 +402,9 @@ fn repair_dry_run_offline_emits_dry_run_envelope() {
415402fn rollback_with_empty_manifest_emits_envelope ( ) {
416403 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
417404 make_socket_with_empty_manifest ( tmp. path ( ) ) ;
418- let out = Command :: new ( binary ( ) )
405+ let out = crate :: common :: hermetic_command ( & binary ( ) )
419406 . args ( [ "rollback" , "--json" , "--offline" ] )
420407 . current_dir ( tmp. path ( ) )
421- . env_remove ( "SOCKET_API_TOKEN" )
422- . env_remove ( "SOCKET_CLI_API_TOKEN" )
423408 . output ( )
424409 . expect ( "run rollback" ) ;
425410 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -449,7 +434,7 @@ fn rollback_with_empty_manifest_emits_envelope() {
449434fn remove_with_no_socket_dir_emits_manifest_not_found ( ) {
450435 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
451436 // NO .socket/ directory at all.
452- let out = Command :: new ( binary ( ) )
437+ let out = crate :: common :: hermetic_command ( & binary ( ) )
453438 . args ( [
454439 "remove" ,
455440 "11111111-1111-4111-8111-111111111111" ,
@@ -458,8 +443,6 @@ fn remove_with_no_socket_dir_emits_manifest_not_found() {
458443 "--skip-rollback" ,
459444 ] )
460445 . current_dir ( tmp. path ( ) )
461- . env_remove ( "SOCKET_API_TOKEN" )
462- . env_remove ( "SOCKET_CLI_API_TOKEN" )
463446 . output ( )
464447 . expect ( "run remove" ) ;
465448 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -483,11 +466,9 @@ fn remove_with_no_socket_dir_emits_manifest_not_found() {
483466fn list_with_empty_manifest_emits_empty_envelope ( ) {
484467 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
485468 make_socket_with_empty_manifest ( tmp. path ( ) ) ;
486- let out = Command :: new ( binary ( ) )
469+ let out = crate :: common :: hermetic_command ( & binary ( ) )
487470 . args ( [ "list" , "--json" ] )
488471 . current_dir ( tmp. path ( ) )
489- . env_remove ( "SOCKET_API_TOKEN" )
490- . env_remove ( "SOCKET_CLI_API_TOKEN" )
491472 . output ( )
492473 . expect ( "run list" ) ;
493474 let stdout = String :: from_utf8_lossy ( & out. stdout ) ;
@@ -511,11 +492,9 @@ fn list_with_empty_manifest_emits_empty_envelope() {
511492#[ test]
512493fn apply_silent_no_manifest_produces_no_output ( ) {
513494 let tmp = tempfile:: tempdir ( ) . expect ( "tempdir" ) ;
514- let out = Command :: new ( binary ( ) )
495+ let out = crate :: common :: hermetic_command ( & binary ( ) )
515496 . args ( [ "apply" , "--silent" ] )
516497 . current_dir ( tmp. path ( ) )
517- . env_remove ( "SOCKET_API_TOKEN" )
518- . env_remove ( "SOCKET_CLI_API_TOKEN" )
519498 . output ( )
520499 . expect ( "run apply" ) ;
521500 assert_eq ! ( out. status. code( ) , Some ( 0 ) ) ;
0 commit comments