"""AUDIT-WP-0009-T10. Make the §5 conformance check total rather than vacuous. `layer.yaml` declares `tooling_contacts: []`, which is true under §5 as written — audit-core is an Engine and holds no key-cape or OpenBao client. The companion asks that uncatalogued infrastructure be listed anyway, and a list nobody checks decays into a list nobody updates. These tests make the claim of totality mechanical. """ from pathlib import Path import pytest yaml = pytest.importorskip("yaml") ROOT = Path(__file__).parents[1] LAYER = yaml.safe_load((ROOT / "layer.yaml").read_text()) def _listed() -> set[str]: return {row["id"] for row in LAYER.get("uncatalogued_infrastructure", [])} def test_the_declaration_states_the_layer_and_role(): assert LAYER["layer"] == "engine" assert LAYER["role"] == "evidence" assert LAYER["decision_surfaces_exposed"] == "none" # §9.4, normative and permanent. assert LAYER["approval_validity_query"] == "forbidden" def test_the_evidence_bound_never_claims_occurrence(): bound = LAYER["evidence_bound"] does_not = " ".join(bound["does_not_prove"]).lower() assert "ever sent" in does_not assert "non-occurrence" in does_not proves = " ".join(bound["proves"]).lower() # The archive's claim is about records it holds, never about the world. assert "altered" in proves and "truncated" in proves assert set(bound["not_claimed"]) >= {"WORM", "object-lock", "archival-custody"} def test_every_infrastructure_contact_is_listed(): """The totality claim, checked rather than asserted. Each probe below names a contact that exists in `deploy/`. When a new one appears, this fails and the list gets a row — which is the whole point of the companion's carve-out being total. """ listed = _listed() assert "platform-pg" in listed assert "state-hub" in listed assert "kube-apiserver" in listed assert "forgejo.coulomb.social" in listed def test_a_new_egress_destination_must_appear_in_the_declaration(): """Derived from the manifests, so drift fails here rather than at review.""" policies = (ROOT / "deploy" / "networkpolicies.yaml").read_text() # Namespaces audit-core is permitted to egress to, by name. for namespace, expected in [("databases", "platform-pg"), ("kube-system", None)]: assert f"kubernetes.io/metadata.name: {namespace}" in policies if expected: assert expected in _listed() # The attest job's API-server reach is real infrastructure and is declared. assert "port: 6443" in policies assert "kube-apiserver" in _listed() def test_the_registry_pinned_in_deploy_is_declared(): manifests = "".join( path.read_text() for path in (ROOT / "deploy").glob("*.yaml") ) for row in LAYER["uncatalogued_infrastructure"]: if row["id"] == "forgejo.coulomb.social": break else: pytest.fail("registry not declared") assert "forgejo.coulomb.social" in manifests # Pinned by digest, never by tag: a mutable tag makes the registry able to # change what runs without any change here. images = [ line.strip() for line in manifests.splitlines() if line.strip().startswith("image:") ] assert images assert all("@sha256:" in image for image in images) assert not any(":latest" in image for image in images) def test_the_receiver_has_no_api_server_egress(): """The separation T02 depends on, asserted rather than assumed.""" documents = (ROOT / "deploy" / "networkpolicies.yaml").read_text().split("\n---\n") receiver = next(d for d in documents if "name: audit-core-egress" in d) assert "component: receiver" in receiver assert "6443" not in receiver attest = next(d for d in documents if "name: audit-core-attest-egress" in d) assert "component: attest" in attest assert "6443" in attest assert "443" in attest assert "6443" not in receiver assert "443" not in receiver # AUDIT-IN-0005 — §11's emission-guarantee check, made mechanical for audit-core's # own declaration. The ruling itself lives in docs/section-4-source-of-evidence.md; # these assert that the declaration keeps saying what the ruling says. def test_audit_core_declines_the_source_of_evidence_role(): """The archive is not the source. AUDIT-IN-0001, AUDIT-IN-0005.""" assert LAYER["source_of_evidence"] is False note = LAYER["source_of_evidence_note"].lower() assert "non-production" in note assert "sender" in note def test_the_attestation_emission_is_declared_and_not_rate_monitored(): """A rare load-bearing class may not rest on rate monitoring (§11).""" rows = {row["id"]: row for row in LAYER["emission_guarantee"]} attestation = rows["chain-head-attestation"] assert attestation["class"] == "load-bearing" assert attestation["rarity"] == "rare" assert attestation["rate_monitoring"] == "forbidden" # All three things §11 asks a source to state. assert attestation["cadence"]["interval"] == "daily" assert attestation["detection_surface"]["form"] == "freshness-window" def test_the_declared_cadence_matches_the_deployed_schedule(): """Declared against the manifest, so drift fails here rather than at review.""" cronjob = (ROOT / "deploy" / "attest-cronjob.yaml").read_text() declared = next( row for row in LAYER["emission_guarantee"] if row["id"] == "chain-head-attestation" )["cadence"] assert declared["schedule"] in cronjob assert declared["published_to"].split()[-1] in cronjob def test_the_declared_freshness_window_matches_the_contract(): surface = next( row for row in LAYER["emission_guarantee"] if row["id"] == "chain-head-attestation" )["detection_surface"] assert surface["window_hours"] == 168 contract = (ROOT / surface["contract"]).read_text() assert "168 hours" in contract