hub-core/tests/test_conformance.py

73 lines
2.5 KiB
Python
Raw Normal View History

from __future__ import annotations
from fastapi.testclient import TestClient
from hub_core.conformance import ConformanceHarness, find_secret_violations
from hub_core.runtime.app import create_app
from hub_core.runtime.cli import build_parser
from hub_core.runtime.config import RuntimeSettings
from hub_core.runtime.store import InMemoryPortStore
def isolated_target() -> TestClient:
settings = RuntimeSettings(environment="test", backend="memory", allow_ephemeral=True)
return TestClient(create_app(settings=settings, port_store=InMemoryPortStore()))
def test_implemented_tier_2_and_3_profile_passes_reference_runtime() -> None:
report = ConformanceHarness(isolated_target()).run()
assert report.passed
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
assert report.passed_count == 12
assert {check.check_id for check in report.checks} == {
"C1",
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
"C2",
"C3",
"C4",
"C5",
"C6",
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
"C7",
"C8",
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
"C9",
"C10",
"F2",
"F3",
}
assert all(check.status == "pass" for check in report.checks)
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
assert report.to_dict()["summary"] == {"passed": 12, "total": 12}
def test_projection_rebuild_scenario_leaves_separate_provenance_bearing_views() -> None:
target = isolated_target()
assert ConformanceHarness(target).run().passed
progress = target.get("/ports/projections/progress_events").json()
interaction = target.get("/ports/projections/interaction_events").json()
assert progress["data"]["rebuild_from"] == ["progress_events"]
assert interaction["data"]["rebuild_from"] == ["interaction_events"]
assert {item["family"] for item in progress["data"]["items"]} == {"progress"}
assert {item["family"] for item in interaction["data"]["items"]} == {"interaction"}
assert progress["provenance"]["content_hash"]
assert interaction["provenance"]["content_hash"]
def test_secret_heuristic_reports_paths_without_echoing_values() -> None:
value = {
"nested": {"api_token": "do-not-echo"},
"database": "postgresql://runtime:do-not-echo@example.invalid/hub",
"safe": "https://ops-hub.example.invalid/docs",
}
assert find_secret_violations(value) == ["$.nested.api_token", "$.database"]
def test_cli_exposes_remote_conformance_runner() -> None:
args = build_parser(RuntimeSettings()).parse_args(
["conformance", "--base-url", "http://runtime.invalid", "--json"]
)
assert args.command == "conformance"
assert args.base_url == "http://runtime.invalid"
assert args.as_json is True