"""AUDIT-WP-0009-T10. Make the §5 conformance check total rather than vacuous. `layer.yaml` declares `tooling_contacts: []`, which is true under §5 as written — audit-core is an Engine and holds no key-cape or OpenBao client. The companion asks that uncatalogued infrastructure be listed anyway, and a list nobody checks decays into a list nobody updates. These tests make the claim of totality mechanical. """ from pathlib import Path import pytest yaml = pytest.importorskip("yaml") ROOT = Path(__file__).parents[1] LAYER = yaml.safe_load((ROOT / "layer.yaml").read_text()) def _listed() -> set[str]: return {row["id"] for row in LAYER.get("uncatalogued_infrastructure", [])} def test_the_declaration_states_the_layer_and_role(): assert LAYER["layer"] == "engine" assert LAYER["role"] == "evidence" assert LAYER["decision_surfaces_exposed"] == "none" # §9.4, normative and permanent. assert LAYER["approval_validity_query"] == "forbidden" def test_the_evidence_bound_never_claims_occurrence(): bound = LAYER["evidence_bound"] does_not = " ".join(bound["does_not_prove"]).lower() assert "ever sent" in does_not assert "non-occurrence" in does_not proves = " ".join(bound["proves"]).lower() # The archive's claim is about records it holds, never about the world. assert "altered" in proves and "truncated" in proves assert set(bound["not_claimed"]) >= {"WORM", "object-lock", "archival-custody"} def test_every_infrastructure_contact_is_listed(): """The totality claim, checked rather than asserted. Each probe below names a contact that exists in `deploy/`. When a new one appears, this fails and the list gets a row — which is the whole point of the companion's carve-out being total. """ listed = _listed() assert "platform-pg" in listed assert "state-hub" in listed assert "kube-apiserver" in listed assert "forgejo.coulomb.social" in listed def test_a_new_egress_destination_must_appear_in_the_declaration(): """Derived from the manifests, so drift fails here rather than at review.""" policies = (ROOT / "deploy" / "networkpolicies.yaml").read_text() # Namespaces audit-core is permitted to egress to, by name. for namespace, expected in [("databases", "platform-pg"), ("kube-system", None)]: assert f"kubernetes.io/metadata.name: {namespace}" in policies if expected: assert expected in _listed() # The attest job's API-server reach is real infrastructure and is declared. assert "port: 6443" in policies assert "kube-apiserver" in _listed() def test_the_registry_pinned_in_deploy_is_declared(): manifests = "".join( path.read_text() for path in (ROOT / "deploy").glob("*.yaml") ) for row in LAYER["uncatalogued_infrastructure"]: if row["id"] == "forgejo.coulomb.social": break else: pytest.fail("registry not declared") assert "forgejo.coulomb.social" in manifests # Pinned by digest, never by tag: a mutable tag makes the registry able to # change what runs without any change here. images = [ line.strip() for line in manifests.splitlines() if line.strip().startswith("image:") ] assert images assert all("@sha256:" in image for image in images) assert not any(":latest" in image for image in images) def test_the_receiver_has_no_api_server_egress(): """The separation T02 depends on, asserted rather than assumed.""" documents = (ROOT / "deploy" / "networkpolicies.yaml").read_text().split("\n---\n") receiver = next(d for d in documents if "name: audit-core-egress" in d) assert "component: receiver" in receiver assert "6443" not in receiver attest = next(d for d in documents if "name: audit-core-attest-egress" in d) assert "component: attest" in attest assert "6443" in attest