Apply GH-DEC-2026-020: the checker prints its version and scope, and detects a version anywhere

check_layer_conformance.py now carries VALIDATED_AGAINST and SCOPE and prints
both on every run, the OK line included (kings-guard's pattern, ruling §4).
A12 detection widens from the key `standard_version` to any version in any key
or value of the INTENT.md frontmatter and layer.yaml: a *version* key, a
version-bearing path, or a version in standard/companion/framework
(ruling §1-§2). schema_version, comments and stance/claims files are not
reached (§1, §3). The declaration itself was already conforming; unchanged.

Tests fail if a versioned `standard:` path or a companion_version comes back.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 09:37:43 +02:00
parent 3d71ceecd4
commit 2ef97c87a0
2 changed files with 135 additions and 16 deletions

View file

@ -112,3 +112,51 @@ def test_checker_catches_an_openbao_client(tmp_path, monkeypatch):
hits = module.scan()
assert hits
assert hits[0][1] == "hvac"
def _checker():
import importlib.util
spec = importlib.util.spec_from_file_location("check_layer_conformance_v", SCRIPT)
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)
return module
def test_every_run_prints_the_version_and_scope():
"""GH-DEC-2026-020 §4: the version belongs to the run, OK line included."""
module = _checker()
for args in ((), ("--report",)):
out = _run(*args).stdout
assert module.VALIDATED_AGAINST in out
assert module.SCOPE in out
ok = [line for line in _run().stdout.splitlines() if line.startswith("OK:")]
assert ok and module.VALIDATED_AGAINST in ok[0] and module.SCOPE in ok[0]
def test_no_version_anywhere_in_either_declaration():
"""A12 r2: no standard or companion version in any key or value."""
module = _checker()
assert module.version_findings(_intent_frontmatter(), "INTENT.md") == []
assert module.version_findings(yaml.safe_load(DECL.read_text()), "layer.yaml") == []
@pytest.mark.parametrize(
"declaration",
[
{"standard": "net-kingdom/canon/standards/security-layer-model_v0.7.md"},
{"companion": "net-kingdom/v0.2/SECURITY-COMPANION.md"},
{"companion_version": "0.2"},
{"standard_version": "0.7"},
{"framework": "netkingdom-security-layer-model 0.8"},
],
)
def test_checker_catches_a_version_beyond_the_key_name(declaration):
"""Fails if a versioned `standard:` path or a companion_version comes back."""
assert _checker().version_findings(declaration, "x")
def test_schema_version_and_prose_are_not_reached():
module = _checker()
assert module.version_findings({"schema_version": "0.1"}, "x") == []
assert module.version_findings({"note": "Outside §5 by the v0.5 scope rule"}, "x") == []