test: gate releases on enforced conformance and installed package checks
Some checks failed
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / pytest-smoke (push) Failing after 5s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:26:40 +02:00
parent a15fe032b0
commit 1ece969f59
6 changed files with 206 additions and 17 deletions

View file

@ -46,3 +46,27 @@ absorption slices that are not part of the T04 minimal vertical. Tenant
isolation also remains open because the 0.1 runtime has no tenant identity or
authorization context yet. These gaps must not be interpreted as passing; the
harness reports only the implemented profile above.
## Access enforcement and CI gates
`make ci-check` runs the test suite, checks the reviewed access inventory for
source drift, builds distributions and validates an installed wheel outside the
checkout's import path. Forgejo runs these gates for `main` pushes and manual
runs, using the full commit SHA and a unique temporary checkout. CI installs the
locked development and runtime dependencies first. Individual gates are
`make test`, `make inventory-check` and `make package-check`.
`tests/test_enforced_conformance.py` runs all twelve existing Tier 2/3 checks
through an explicitly enforced runtime using a real signed IAM JWT and synthetic
owner facts, policy and audit. It verifies event attribution against authorization
records. Additional journeys establish valid state, deny both reads and writes
for anonymous/invalid credentials, revoked entitlement, policy denial and
policy/audit outages, then independently read back unchanged stored messages.
These tests run in the ordinary suite; they need no external owner checkout.
The installed-wheel gate validates runtime/security imports, packaged action and
browser route coverage, contract fixtures/schemas and the migration template.
It makes no owner requests and starts no service. The separate optional Audit
Core interoperability suite still requires `HUB_CORE_AUDIT_CORE_SOURCE` and is
not silently represented as covered by ordinary CI. Local CI-equivalent success
is not a deployed Forgejo receipt or live owner/platform acceptance.