Implements the four residual conformance checks left open by the T04
minimal vertical:
- C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404),
ambiguous (shared reuse_surface_id across hub_slugs), and stale
(deprecated/retired descriptor) registrations; a new .../audit route
exposes queryable registration history from the existing in-memory
history and the PostgreSQL runtime_audit_ledger.
- C7: harness proof that disabled compatibility groups deny access
(404) with no fixture credentials involved, matching the existing
fail-closed compat router behavior.
- C9: harness proof plus a dedicated test that /readyz degrades only on
an unavailable configured dependency while unrelated disabled
projections stay non-blocking.
- C10: ContractValidator now negotiates contract_version_min/max against
the runtime's contract version and rejects incompatible or inverted
ranges with an explicit 422 instead of silently accepting them.
HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open
task (T06) has no remaining hub-core code path and waits on an external
Forgejo identity/production deployment gate. HUB-WP-0011 is marked
blocked: T02/T03 already waited on external credential/deployment
review, and T01 needs a source/destination ownership and retention
decision against live message data before it can be implemented safely.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 310936@bnt-lap001
Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
72 lines
2.5 KiB
Python
72 lines
2.5 KiB
Python
from __future__ import annotations
|
|
|
|
from fastapi.testclient import TestClient
|
|
|
|
from hub_core.conformance import ConformanceHarness, find_secret_violations
|
|
from hub_core.runtime.app import create_app
|
|
from hub_core.runtime.cli import build_parser
|
|
from hub_core.runtime.config import RuntimeSettings
|
|
from hub_core.runtime.store import InMemoryPortStore
|
|
|
|
|
|
def isolated_target() -> TestClient:
|
|
settings = RuntimeSettings(environment="test", backend="memory", allow_ephemeral=True)
|
|
return TestClient(create_app(settings=settings, port_store=InMemoryPortStore()))
|
|
|
|
|
|
def test_implemented_tier_2_and_3_profile_passes_reference_runtime() -> None:
|
|
report = ConformanceHarness(isolated_target()).run()
|
|
|
|
assert report.passed
|
|
assert report.passed_count == 12
|
|
assert {check.check_id for check in report.checks} == {
|
|
"C1",
|
|
"C2",
|
|
"C3",
|
|
"C4",
|
|
"C5",
|
|
"C6",
|
|
"C7",
|
|
"C8",
|
|
"C9",
|
|
"C10",
|
|
"F2",
|
|
"F3",
|
|
}
|
|
assert all(check.status == "pass" for check in report.checks)
|
|
assert report.to_dict()["summary"] == {"passed": 12, "total": 12}
|
|
|
|
|
|
def test_projection_rebuild_scenario_leaves_separate_provenance_bearing_views() -> None:
|
|
target = isolated_target()
|
|
assert ConformanceHarness(target).run().passed
|
|
|
|
progress = target.get("/ports/projections/progress_events").json()
|
|
interaction = target.get("/ports/projections/interaction_events").json()
|
|
|
|
assert progress["data"]["rebuild_from"] == ["progress_events"]
|
|
assert interaction["data"]["rebuild_from"] == ["interaction_events"]
|
|
assert {item["family"] for item in progress["data"]["items"]} == {"progress"}
|
|
assert {item["family"] for item in interaction["data"]["items"]} == {"interaction"}
|
|
assert progress["provenance"]["content_hash"]
|
|
assert interaction["provenance"]["content_hash"]
|
|
|
|
|
|
def test_secret_heuristic_reports_paths_without_echoing_values() -> None:
|
|
value = {
|
|
"nested": {"api_token": "do-not-echo"},
|
|
"database": "postgresql://runtime:do-not-echo@example.invalid/hub",
|
|
"safe": "https://ops-hub.example.invalid/docs",
|
|
}
|
|
|
|
assert find_secret_violations(value) == ["$.nested.api_token", "$.database"]
|
|
|
|
|
|
def test_cli_exposes_remote_conformance_runner() -> None:
|
|
args = build_parser(RuntimeSettings()).parse_args(
|
|
["conformance", "--base-url", "http://runtime.invalid", "--json"]
|
|
)
|
|
|
|
assert args.command == "conformance"
|
|
assert args.base_url == "http://runtime.invalid"
|
|
assert args.as_json is True
|