approval-engine suggested a conformance check after the examples-contradict- prose class hit a third repository -- theirs. Fifteen lines, they said, and it would have caught our caring fixture and our provenance omission. Worth stealing, so we stole it. internal/schemaguard validates published examples against published schemas. It implements only the JSON Schema subset these schemas use, and the property that makes it trustworthy is that an unrecognised keyword FAILS rather than skips: a validator that silently approves what it does not understand invites reliance it cannot support. It found three things on first run. ONE, AND THE LARGEST: check_request.schema.json pointed subject.type at CARING's subject_type enum (Human, Service, ...), and no consumer sends that vocabulary. user-engine sends human, tenant-engine and secrets-engine send service, and ops-warden sends adm/agt/atm -- an actor-type vocabulary CARING does not model at all. Our published schema declared three live integrations non-conformant. A rule that outlaws shipped correct behaviour is the rule that is wrong, so the $ref is replaced with an opaque non-empty string and a description saying why. CARING's enum remains correct where it belongs: the registry's subject_manifest.yaml, where Service is right. TWO: policy_package_note, which this session added to the caring example's decision provenance, is undeclared under additionalProperties:false. Our own annotation broke the conformance it was annotating. Moved to the envelope's outer provenance. THREE: the secrets-engine fixtures carried partial approval-claims, missing binding, freshness and validity. A partial claim in a fixture is how a consumer learns the wrong shape -- the same mechanism that produced the destroy defect. They are now complete and valid against approval-engine's schema, including the now-required binding.pdp_digest, and a test validates them against that schema when the sibling repo is present. The destroy replay fixture is regenerated accordingly and the replay README's pinned digests updated, since a stale digest table is the same defect wearing a different hat. Closed the binding-mapping open item. approval-engine declined to publish a vocabulary mapping and their reasoning is better than the request: a PIP asserting secrets.kv.destroy MEANS destroy would author semantics over two vocabularies it owns neither of, and a wrong mapping silently accepts a claim approved for a different action. pdp_digest is the mapping precisely because it does not translate. It is now always present and nullable, so the destroy gate is pdp_digest non-null and equal, enforced at the PEP. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB Assistant: claude-code Assistant-Model: opus Assistant-Process: 412054@bnt-lap001 Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
125 lines
4 KiB
Go
125 lines
4 KiB
Go
package schemaguard
|
|
|
|
import (
|
|
"encoding/json"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
// repoRoot walks up from the package directory to the module root.
|
|
func repoRoot(t *testing.T) string {
|
|
t.Helper()
|
|
return filepath.Join("..", "..")
|
|
}
|
|
|
|
// TestPublishedExamplesMatchTheirSchemas is the check approval-engine suggested
|
|
// after the same defect class hit three repositories: a published example that
|
|
// contradicts the schema it claims gets implemented in preference to the prose.
|
|
func TestPublishedExamplesMatchTheirSchemas(t *testing.T) {
|
|
root := repoRoot(t)
|
|
cases := []struct {
|
|
schema string
|
|
example string
|
|
}{
|
|
{"schemas/decision_envelope.schema.json", "examples/caring/decision_envelope.json"},
|
|
{"schemas/decision_envelope.schema.json", "examples/secrets-engine/replay/decision_rotate.json"},
|
|
{"schemas/decision_envelope.schema.json", "examples/secrets-engine/replay/decision_destroy_dual_control.json"},
|
|
{"schemas/action_authorization.schema.json", "examples/caring/action_authorization.json"},
|
|
}
|
|
for _, tc := range cases {
|
|
t.Run(tc.example, func(t *testing.T) {
|
|
s, err := Load(filepath.Join(root, tc.schema))
|
|
if err != nil {
|
|
t.Fatalf("load schema: %v", err)
|
|
}
|
|
problems, err := s.ValidateFile(filepath.Join(root, tc.example))
|
|
if err != nil {
|
|
t.Fatalf("read example: %v", err)
|
|
}
|
|
for _, p := range problems {
|
|
t.Errorf("%s: %s", tc.example, p)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestEveryAllowExampleStatesItsLifetime pins the §9.7.1 obligation that
|
|
// FLEX-WP-0019 closed. An allow without a lifetime is the gap G3 named, and an
|
|
// example missing it teaches consumers the pre-WP-0019 shape.
|
|
func TestEveryAllowExampleStatesItsLifetime(t *testing.T) {
|
|
root := repoRoot(t)
|
|
matches, err := filepath.Glob(filepath.Join(root, "examples", "*", "replay", "*.json"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
extra := filepath.Join(root, "examples", "caring", "decision_envelope.json")
|
|
if _, err := os.Stat(extra); err == nil {
|
|
matches = append(matches, extra)
|
|
}
|
|
if len(matches) == 0 {
|
|
t.Fatal("no decision examples found — this test would pass vacuously")
|
|
}
|
|
for _, path := range matches {
|
|
raw, err := os.ReadFile(path)
|
|
if err != nil {
|
|
t.Fatalf("%s: %v", path, err)
|
|
}
|
|
var doc map[string]any
|
|
if err := json.Unmarshal(raw, &doc); err != nil {
|
|
t.Fatalf("%s: %v", path, err)
|
|
}
|
|
if doc["effect"] != "allow" {
|
|
continue
|
|
}
|
|
if _, ok := doc["lifetime"].(map[string]any); !ok {
|
|
t.Errorf("%s: allow carries no lifetime (security-layer-model v0.7 §9.7.1)", path)
|
|
}
|
|
}
|
|
}
|
|
|
|
// TestApprovalClaimsInFixturesAreComplete validates the approval-claims embedded
|
|
// in this repo's check requests against approval-engine's published schema.
|
|
//
|
|
// It is skipped when the sibling repository is not checked out, because a
|
|
// cross-repo path is not a dependency this module can assert. It is worth
|
|
// running where it can: the destroy rule was first written against an invented
|
|
// claim shape, and a partial claim in a fixture is how a consumer learns one.
|
|
func TestApprovalClaimsInFixturesAreComplete(t *testing.T) {
|
|
schemaPath := filepath.Join(os.Getenv("HOME"), "approval-engine", "schemas", "approval_claim.schema.json")
|
|
if _, err := os.Stat(schemaPath); err != nil {
|
|
t.Skipf("approval-engine not checked out at %s", schemaPath)
|
|
}
|
|
s, err := Load(schemaPath)
|
|
if err != nil {
|
|
t.Fatalf("load claim schema: %v", err)
|
|
}
|
|
root := repoRoot(t)
|
|
matches, err := filepath.Glob(filepath.Join(root, "examples", "*", "check_request_*.json"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
checked := 0
|
|
for _, path := range matches {
|
|
raw, err := os.ReadFile(path)
|
|
if err != nil {
|
|
t.Fatalf("%s: %v", path, err)
|
|
}
|
|
var doc map[string]any
|
|
if err := json.Unmarshal(raw, &doc); err != nil {
|
|
t.Fatalf("%s: %v", path, err)
|
|
}
|
|
ctx, _ := doc["context"].(map[string]any)
|
|
claim, ok := ctx["approval"]
|
|
if !ok {
|
|
continue
|
|
}
|
|
checked++
|
|
for _, p := range s.Validate(claim) {
|
|
t.Errorf("%s: context.approval: %s", path, p)
|
|
}
|
|
}
|
|
if checked == 0 {
|
|
t.Skip("no check request carries context.approval")
|
|
}
|
|
}
|