100 lines
3.8 KiB
Python
100 lines
3.8 KiB
Python
|
|
"""AUDIT-WP-0009-T10. Make the §5 conformance check total rather than vacuous.
|
||
|
|
|
||
|
|
`layer.yaml` declares `tooling_contacts: []`, which is true under §5 as
|
||
|
|
written — audit-core is an Engine and holds no key-cape or OpenBao client. The
|
||
|
|
companion asks that uncatalogued infrastructure be listed anyway, and a list
|
||
|
|
nobody checks decays into a list nobody updates. These tests make the claim of
|
||
|
|
totality mechanical.
|
||
|
|
"""
|
||
|
|
|
||
|
|
from pathlib import Path
|
||
|
|
|
||
|
|
import pytest
|
||
|
|
|
||
|
|
yaml = pytest.importorskip("yaml")
|
||
|
|
|
||
|
|
ROOT = Path(__file__).parents[1]
|
||
|
|
LAYER = yaml.safe_load((ROOT / "layer.yaml").read_text())
|
||
|
|
|
||
|
|
|
||
|
|
def _listed() -> set[str]:
|
||
|
|
return {row["id"] for row in LAYER.get("uncatalogued_infrastructure", [])}
|
||
|
|
|
||
|
|
|
||
|
|
def test_the_declaration_states_the_layer_and_role():
|
||
|
|
assert LAYER["layer"] == "engine"
|
||
|
|
assert LAYER["role"] == "evidence"
|
||
|
|
assert LAYER["decision_surfaces_exposed"] == "none"
|
||
|
|
# §9.4, normative and permanent.
|
||
|
|
assert LAYER["approval_validity_query"] == "forbidden"
|
||
|
|
|
||
|
|
|
||
|
|
def test_the_evidence_bound_never_claims_occurrence():
|
||
|
|
bound = LAYER["evidence_bound"]
|
||
|
|
does_not = " ".join(bound["does_not_prove"]).lower()
|
||
|
|
assert "ever sent" in does_not
|
||
|
|
assert "non-occurrence" in does_not
|
||
|
|
proves = " ".join(bound["proves"]).lower()
|
||
|
|
# The archive's claim is about records it holds, never about the world.
|
||
|
|
assert "altered" in proves and "truncated" in proves
|
||
|
|
assert set(bound["not_claimed"]) >= {"WORM", "object-lock", "archival-custody"}
|
||
|
|
|
||
|
|
|
||
|
|
def test_every_infrastructure_contact_is_listed():
|
||
|
|
"""The totality claim, checked rather than asserted.
|
||
|
|
|
||
|
|
Each probe below names a contact that exists in `deploy/`. When a new one
|
||
|
|
appears, this fails and the list gets a row — which is the whole point of
|
||
|
|
the companion's carve-out being total.
|
||
|
|
"""
|
||
|
|
listed = _listed()
|
||
|
|
assert "platform-pg" in listed
|
||
|
|
assert "state-hub" in listed
|
||
|
|
assert "kube-apiserver" in listed
|
||
|
|
assert "forgejo.coulomb.social" in listed
|
||
|
|
|
||
|
|
|
||
|
|
def test_a_new_egress_destination_must_appear_in_the_declaration():
|
||
|
|
"""Derived from the manifests, so drift fails here rather than at review."""
|
||
|
|
policies = (ROOT / "deploy" / "networkpolicies.yaml").read_text()
|
||
|
|
# Namespaces audit-core is permitted to egress to, by name.
|
||
|
|
for namespace, expected in [("databases", "platform-pg"), ("kube-system", None)]:
|
||
|
|
assert f"kubernetes.io/metadata.name: {namespace}" in policies
|
||
|
|
if expected:
|
||
|
|
assert expected in _listed()
|
||
|
|
# The attest job's API-server reach is real infrastructure and is declared.
|
||
|
|
assert "port: 6443" in policies
|
||
|
|
assert "kube-apiserver" in _listed()
|
||
|
|
|
||
|
|
|
||
|
|
def test_the_registry_pinned_in_deploy_is_declared():
|
||
|
|
manifests = "".join(
|
||
|
|
path.read_text() for path in (ROOT / "deploy").glob("*.yaml")
|
||
|
|
)
|
||
|
|
for row in LAYER["uncatalogued_infrastructure"]:
|
||
|
|
if row["id"] == "forgejo.coulomb.social":
|
||
|
|
break
|
||
|
|
else:
|
||
|
|
pytest.fail("registry not declared")
|
||
|
|
assert "forgejo.coulomb.social" in manifests
|
||
|
|
# Pinned by digest, never by tag: a mutable tag makes the registry able to
|
||
|
|
# change what runs without any change here.
|
||
|
|
images = [
|
||
|
|
line.strip() for line in manifests.splitlines()
|
||
|
|
if line.strip().startswith("image:")
|
||
|
|
]
|
||
|
|
assert images
|
||
|
|
assert all("@sha256:" in image for image in images)
|
||
|
|
assert not any(":latest" in image for image in images)
|
||
|
|
|
||
|
|
|
||
|
|
def test_the_receiver_has_no_api_server_egress():
|
||
|
|
"""The separation T02 depends on, asserted rather than assumed."""
|
||
|
|
documents = (ROOT / "deploy" / "networkpolicies.yaml").read_text().split("\n---\n")
|
||
|
|
receiver = next(d for d in documents if "name: audit-core-egress" in d)
|
||
|
|
assert "component: receiver" in receiver
|
||
|
|
assert "6443" not in receiver
|
||
|
|
attest = next(d for d in documents if "name: audit-core-attest-egress" in d)
|
||
|
|
assert "component: attest" in attest
|
||
|
|
assert "6443" in attest
|