test: gate releases on enforced conformance and installed package checks
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
a15fe032b0
commit
1ece969f59
6 changed files with 206 additions and 17 deletions
|
|
@ -46,3 +46,27 @@ absorption slices that are not part of the T04 minimal vertical. Tenant
|
|||
isolation also remains open because the 0.1 runtime has no tenant identity or
|
||||
authorization context yet. These gaps must not be interpreted as passing; the
|
||||
harness reports only the implemented profile above.
|
||||
|
||||
## Access enforcement and CI gates
|
||||
|
||||
`make ci-check` runs the test suite, checks the reviewed access inventory for
|
||||
source drift, builds distributions and validates an installed wheel outside the
|
||||
checkout's import path. Forgejo runs these gates for `main` pushes and manual
|
||||
runs, using the full commit SHA and a unique temporary checkout. CI installs the
|
||||
locked development and runtime dependencies first. Individual gates are
|
||||
`make test`, `make inventory-check` and `make package-check`.
|
||||
|
||||
`tests/test_enforced_conformance.py` runs all twelve existing Tier 2/3 checks
|
||||
through an explicitly enforced runtime using a real signed IAM JWT and synthetic
|
||||
owner facts, policy and audit. It verifies event attribution against authorization
|
||||
records. Additional journeys establish valid state, deny both reads and writes
|
||||
for anonymous/invalid credentials, revoked entitlement, policy denial and
|
||||
policy/audit outages, then independently read back unchanged stored messages.
|
||||
These tests run in the ordinary suite; they need no external owner checkout.
|
||||
|
||||
The installed-wheel gate validates runtime/security imports, packaged action and
|
||||
browser route coverage, contract fixtures/schemas and the migration template.
|
||||
It makes no owner requests and starts no service. The separate optional Audit
|
||||
Core interoperability suite still requires `HUB_CORE_AUDIT_CORE_SOURCE` and is
|
||||
not silently represented as covered by ordinary CI. Local CI-equivalent success
|
||||
is not a deployed Forgejo receipt or live owner/platform acceptance.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue