audit-core/tests/test_layer_conformance.py
tegwick 3b7bedc8e0
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Apply GH-DEC-2026-020: de-version the INTENT.md standard: path.
A12 r2 reaches every key and value of the declaration, so the _v0.7
inside the standard: path is a standard version. The path is now
canon/standards/security-layer-model. Comments and schema_version are
not reached and are left as they were.

The conformance test now fails on a version anywhere in either form of
the declaration, including a versioned standard: path and
companion_version, and carries a self-test that it catches those forms.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 09:36:37 +02:00

236 lines
9.1 KiB
Python

"""AUDIT-WP-0009-T10. Make the §5 conformance check total rather than vacuous.
`layer.yaml` declares `tooling_contacts: []`, which is true under §5 as
written — audit-core is an Engine and holds no key-cape or OpenBao client. The
companion asks that uncatalogued infrastructure be listed anyway, and a list
nobody checks decays into a list nobody updates. These tests make the claim of
totality mechanical.
"""
import re
from pathlib import Path
import pytest
yaml = pytest.importorskip("yaml")
ROOT = Path(__file__).parents[1]
LAYER = yaml.safe_load((ROOT / "layer.yaml").read_text())
def _listed() -> set[str]:
return {row["id"] for row in LAYER.get("uncatalogued_infrastructure", [])}
def test_the_declaration_states_the_layer_and_role():
assert LAYER["layer"] == "engine"
assert LAYER["role"] == "evidence"
assert LAYER["decision_surfaces_exposed"] == "none"
# §9.4, normative and permanent.
assert LAYER["approval_validity_query"] == "forbidden"
def test_the_evidence_bound_never_claims_occurrence():
bound = LAYER["evidence_bound"]
does_not = " ".join(bound["does_not_prove"]).lower()
assert "ever sent" in does_not
assert "non-occurrence" in does_not
proves = " ".join(bound["proves"]).lower()
# The archive's claim is about records it holds, never about the world.
assert "altered" in proves and "truncated" in proves
assert set(bound["not_claimed"]) >= {"WORM", "object-lock", "archival-custody"}
def test_every_infrastructure_contact_is_listed():
"""The totality claim, checked rather than asserted.
Each probe below names a contact that exists in `deploy/`. When a new one
appears, this fails and the list gets a row — which is the whole point of
the companion's carve-out being total.
"""
listed = _listed()
assert "platform-pg" in listed
assert "state-hub" in listed
assert "kube-apiserver" in listed
assert "forgejo.coulomb.social" in listed
def test_a_new_egress_destination_must_appear_in_the_declaration():
"""Derived from the manifests, so drift fails here rather than at review."""
policies = (ROOT / "deploy" / "networkpolicies.yaml").read_text()
# Namespaces audit-core is permitted to egress to, by name.
for namespace, expected in [("databases", "platform-pg"), ("kube-system", None)]:
assert f"kubernetes.io/metadata.name: {namespace}" in policies
if expected:
assert expected in _listed()
# The attest job's API-server reach is real infrastructure and is declared.
assert "port: 6443" in policies
assert "kube-apiserver" in _listed()
def test_the_registry_pinned_in_deploy_is_declared():
manifests = "".join(
path.read_text() for path in (ROOT / "deploy").glob("*.yaml")
)
for row in LAYER["uncatalogued_infrastructure"]:
if row["id"] == "forgejo.coulomb.social":
break
else:
pytest.fail("registry not declared")
assert "forgejo.coulomb.social" in manifests
# Pinned by digest, never by tag: a mutable tag makes the registry able to
# change what runs without any change here.
images = [
line.strip() for line in manifests.splitlines()
if line.strip().startswith("image:")
]
assert images
assert all("@sha256:" in image for image in images)
assert not any(":latest" in image for image in images)
def test_the_receiver_has_no_api_server_egress():
"""The separation T02 depends on, asserted rather than assumed."""
documents = (ROOT / "deploy" / "networkpolicies.yaml").read_text().split("\n---\n")
receiver = next(d for d in documents if "name: audit-core-egress" in d)
assert "component: receiver" in receiver
assert "6443" not in receiver
attest = next(d for d in documents if "name: audit-core-attest-egress" in d)
assert "component: attest" in attest
assert "6443" in attest
assert "443" in attest
assert "6443" not in receiver
assert "443" not in receiver
# AUDIT-IN-0005 — §11's emission-guarantee check, made mechanical for audit-core's
# own declaration. The ruling itself lives in docs/section-4-source-of-evidence.md;
# these assert that the declaration keeps saying what the ruling says.
def test_audit_core_declines_the_source_of_evidence_role():
"""The archive is not the source. AUDIT-IN-0001, AUDIT-IN-0005."""
assert LAYER["source_of_evidence"] is False
note = LAYER["source_of_evidence_note"].lower()
assert "non-production" in note
assert "sender" in note
def test_the_attestation_emission_is_declared_and_not_rate_monitored():
"""A rare load-bearing class may not rest on rate monitoring (§11)."""
rows = {row["id"]: row for row in LAYER["emission_guarantee"]}
attestation = rows["chain-head-attestation"]
assert attestation["class"] == "load-bearing"
assert attestation["rarity"] == "rare"
assert attestation["rate_monitoring"] == "forbidden"
# All three things §11 asks a source to state.
assert attestation["cadence"]["interval"] == "daily"
assert attestation["detection_surface"]["form"] == "freshness-window"
def test_the_declared_cadence_matches_the_deployed_schedule():
"""Declared against the manifest, so drift fails here rather than at review."""
cronjob = (ROOT / "deploy" / "attest-cronjob.yaml").read_text()
declared = next(
row for row in LAYER["emission_guarantee"]
if row["id"] == "chain-head-attestation"
)["cadence"]
assert declared["schedule"] in cronjob
assert declared["published_to"].split()[-1] in cronjob
def test_the_declared_freshness_window_matches_the_contract():
surface = next(
row for row in LAYER["emission_guarantee"]
if row["id"] == "chain-head-attestation"
)["detection_surface"]
assert surface["window_hours"] == 168
contract = (ROOT / surface["contract"]).read_text()
assert "168 hours" in contract
# GH-DEC-2026-017 (amendments A9, A11, A12): INTENT.md governs, layer.yaml is
# derived from it, the §3 vocabulary is closed at four tokens compared after an
# ASCII case fold, and a declaration carries no standard version.
VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
def _intent_frontmatter() -> dict:
text = (ROOT / "INTENT.md").read_text()
assert text.startswith("---\n"), "INTENT.md must carry frontmatter"
return yaml.safe_load(text.split("---\n", 2)[1])
def _fold(value: str) -> str:
return value.encode("ascii").lower().decode("ascii")
def test_layer_yaml_is_marked_derived_from_intent():
assert LAYER["derived"] is True
assert LAYER["derived_from"] == "INTENT.md"
def test_the_two_forms_agree_after_folding_and_nobody_re_spells():
intent_layer = _intent_frontmatter()["layer"]
assert _fold(intent_layer) in VOCABULARY
assert _fold(LAYER["layer"]) in VOCABULARY
# Assert the fold, not equality: a casing difference is conforming, a
# layer divergence that survives folding is a finding and must fail.
assert _fold(intent_layer) == _fold(LAYER["layer"])
def test_no_standard_version_in_either_form():
assert "standard_version" not in LAYER
assert "standard_version" not in _intent_frontmatter()
# GH-DEC-2026-020 (A12 r2): A12 reaches every key and value of the declaration,
# so a version inside the `standard:` path counts, and so does
# `companion_version`. Comments and `schema_version` are not reached. Stance,
# claims and classification maps are not declaration files and are not checked.
_VERSION = re.compile(r"(?i)(?:_v|\bv)\d+(?:\.\d+)+|\b\d+\.\d+(?:\.\d+)?\b")
_NOT_REACHED = {"schema_version"}
def _walk(node, path=""):
if isinstance(node, dict):
for key, value in node.items():
if key in _NOT_REACHED:
continue
yield f"{path}.{key}", str(key)
yield from _walk(value, f"{path}.{key}")
elif isinstance(node, list):
for i, value in enumerate(node):
yield from _walk(value, f"{path}[{i}]")
elif isinstance(node, str):
yield path, node
def _standard_versions(declaration: dict) -> list[str]:
found = [p for p, text in _walk(declaration) if _VERSION.search(text)]
if "companion_version" in declaration:
found.append(".companion_version")
return found
@pytest.mark.parametrize("form", ["INTENT.md", "layer.yaml"])
def test_no_version_anywhere_in_the_declaration(form):
declaration = _intent_frontmatter() if form == "INTENT.md" else LAYER
assert "companion_version" not in declaration
standard = declaration.get("standard")
if standard is not None:
assert not _VERSION.search(str(standard)), standard
assert _standard_versions(declaration) == []
def test_the_version_check_catches_what_a12_r2_rules():
"""The check must fail on the forms GH-DEC-2026-020 names, not only on a
key literally named `standard_version`."""
assert _standard_versions(
{"standard": "canon/standards/security-layer-model_v0.7.md"}
)
assert _standard_versions({"companion_version": "0.3"})
assert _standard_versions({"standard_version": "0.8"})
assert not _standard_versions(
{"standard": "canon/standards/security-layer-model", "schema_version": "0.1"}
)