"""#84185: a Windows gateway cold-started after update that dies immediately
(e.g. a job object denying breakaway) must not be reported as started.

``_cold_start_windows_gateway_after_update`` used to print the success line
straight off a successful ``Popen`` return, which only proves the process was
created, not that it survived. This asserts the observable output: the
success line is gated on the process actually being found alive afterwards,
same as every other ``_spawn_detached`` caller.
"""

from __future__ import annotations

import pytest

from hermes_cli import gateway as hermes_gateway
from hermes_cli import gateway_windows
from hermes_cli import main as cli_main
import hermes_cli.main_install_repair as main_install_repair
from hermes_cli import update_cmd


def _run_cold_start(monkeypatch, capsys, *, surviving_pids):
    monkeypatch.setattr(cli_main, "_is_windows", lambda: True)
    monkeypatch.setattr(main_install_repair, "_is_windows", lambda: True)

    # The pre-spawn re-check (``all_profiles=True``) must find nothing
    # running so the cold-start path proceeds and actually spawns.
    monkeypatch.setattr(
        hermes_gateway,
        "find_gateway_pids",
        lambda all_profiles=False: [] if all_profiles else surviving_pids,
    )
    # This fixture exercises a standalone cold start, not Desktop ownership.
    # A live Desktop for this install must not short-circuit the liveness poll.
    monkeypatch.setattr(update_cmd, "_desktop_owns_gateway_lifecycle", lambda: False)
    monkeypatch.setattr(gateway_windows, "_spawn_detached", lambda: 4242)
    # Avoid the real 6s/0.4s poll loop in _report_gateway_start.
    monkeypatch.setattr(
        gateway_windows, "_wait_for_gateway_ready", lambda *a, **k: surviving_pids
    )

    update_cmd._cold_start_windows_gateway_after_update()

    return capsys.readouterr().out


def test_cold_start_raises_when_process_does_not_survive(monkeypatch, capsys):
    with pytest.raises(RuntimeError, match="did not become ready"):
        _run_cold_start(monkeypatch, capsys, surviving_pids=[])

    assert "✓ Starting Windows gateway after update" not in capsys.readouterr().out


def test_failed_readiness_keeps_the_dead_attestation_for_the_retry(monkeypatch, tmp_path, capsys):
    """#110020 review: the attestation is the retry's only authority to spawn under Desktop
    ownership, so a spawn that returns a PID but never becomes ready must NOT consume it —
    otherwise the registered retry sees ownership with no marker and "succeeds" with no gateway."""
    monkeypatch.setattr("hermes_cli.config.get_hermes_home", lambda: str(tmp_path))
    gateway_windows._write_start_attestation([555], "direct spawn (PID 555)")
    marker = tmp_path / "state" / "gateway.start-attestation.json"

    with pytest.raises(RuntimeError, match="did not become ready"):
        _run_cold_start(monkeypatch, capsys, surviving_pids=[])
    assert marker.exists()
    assert gateway_windows.attested_death_generation(current_pids=[]) is not None


def test_cold_start_reports_success_when_process_survives(monkeypatch, capsys):
    out = _run_cold_start(monkeypatch, capsys, surviving_pids=[4242])

    assert "✓ Gateway started via cold-start after update" in out
