> For the complete documentation index, see [llms.txt](https://docs.pal.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pal.aic.io/engineering-and-delivery/testing.md).

# Testing

The PAL repository contains focused unit, contract, architecture, generation, compatibility, integration, performance, and native authentication tests. Applications should add acceptance tests for their enrollment, Ontology, permissions, and deployment profile.

## Run the repository tests

```powershell
dotnet test src/PAL.Platform.sln --configuration Release
```

The solution includes tests for:

* options and configuration validation;
* transport cancellation, retries, streaming, and redaction;
* platform operation and generated catalog behavior;
* Ontology, dataset, SQL, and AIP façade clients;
* compatibility source loading, scanning, and mapping;
* deterministic model/binding generation;
* dependency registration and architecture boundaries;
* native authentication and local administrator seeding;
* live enrollment smoke behavior where credentials are available;
* processing performance and cancellation.

## Unit-test a capability client

Capability clients depend on `IPalPlatformOperationClient`. Supply a fake implementation that records the operation descriptor and request, then returns a representative `PalantirTransportResponse` or `PalantirStreamingResponse`. Assert:

* path and query encoding;
* request body and media type;
* scope and operation mapping;
* validation before the fake transport is called;
* response deserialization;
* cancellation propagation;
* response disposal for streaming paths.

## Test the shared pipeline

Replace:

```csharp
services.AddSingleton<TimeProvider>(fakeTime);
services.AddSingleton<IPalantirJitterSource>(fixedJitter);
services.AddScoped<IPalantirTransport, RecordingTransport>();
services.AddScoped<IPalantirAccessTokenProvider, TestTokenProvider>();
services.AddSingleton<IPalantirLicenseGuard, TestLicenseGuard>();
```

Never use a real token or entitlement in unit tests. Contract and live smoke tests must use a dedicated enrollment and redacted CI secrets.

## Generator determinism

Run generation twice from the same normalized source and compare file hashes. The generator should produce identical line endings, ordering, manifests, schema/binding hashes, and operation counts. A changed upstream source revision should create an intentional evidence change, not an unexplained generated diff.

## Security assertions

Tests should verify that token values, client secrets, authorization headers, licence contents, and arbitrary upstream parameter values do not appear in logs, exception messages, diagnostics, or serialized safe error records.

## Acceptance tests

For each supported deployment profile, test:

{% stepper %}
{% step %}

## Startup

Startup with valid local configuration and no network call.
{% endstep %}

{% step %}

## Token acquisition and scope selection

Token acquisition and scope selection.
{% endstep %}

{% step %}

## Entitlement and enrollment host

Valid entitlement and the expected enrollment host.
{% endstep %}

{% step %}

## Representative operations

A representative read, mutation, pagination, and streaming operation.
{% endstep %}

{% step %}

## Cancellation

Cancellation during token, request, retry delay, polling, page enumeration, and stream consumption.
{% endstep %}

{% step %}

## Entitlement and permissions failures

Expired/missing entitlement and insufficient permissions.
{% endstep %}

{% step %}

## Provenance and evidence

Package provenance and generated evidence checks.
{% endstep %}
{% endstepper %}
