"""Inventory failures must not be reported as a healthy empty store.""" import importlib.util from pathlib import Path from types import SimpleNamespace import pytest spec = importlib.util.spec_from_file_location("inventory", Path(__file__).parents[1] / "scripts/custody-inventory.py") inventory = importlib.util.module_from_spec(spec) spec.loader.exec_module(inventory) def test_no_scoped_grant_refuses_instead_of_using_operator_token(monkeypatch): monkeypatch.delenv("BAO_TOKEN", raising=False) monkeypatch.setattr(inventory.os.path, "exists", lambda _: False) with pytest.raises(inventory.InventoryError, match="No scoped"): inventory.walk("operators") @pytest.mark.parametrize("rc,output", [(1, ""), (0, "not-json"), (0, '{}')]) def test_listing_errors_never_become_empty_success(monkeypatch, rc, output): monkeypatch.setenv("BAO_TOKEN", "synthetic-token") monkeypatch.setattr(inventory.subprocess, "run", lambda *a, **kw: SimpleNamespace(returncode=rc, stdout=output)) with pytest.raises(inventory.InventoryError): inventory.walk("operators") def test_inventory_reads_only_metadata_and_reports_incomplete(monkeypatch, capsys): calls = [] responses = {("kv", "list", "operators"): ["example/"], ("kv", "list", "operators/example"): ["admin"], ("kv", "metadata", "get", "operators/example/admin"): {"data": {"custom_metadata": {}}}} def bao(*args): calls.append(args) return responses[args] monkeypatch.setattr(inventory, "bao", bao) monkeypatch.setattr(inventory.sys, "argv", ["inventory", "operators", "--undescribed"]) assert inventory.main() == 1 assert "1 credential path(s), 1 missing" in capsys.readouterr().out assert all(c[:2] == ("kv", "list") or c[:3] == ("kv", "metadata", "get") for c in calls)