ops-warden/tests
tegwick baf53602ca Revert the npm field, re-measure coverage, and hold the layer divergence
Five inbox items worked, none of which changed a credential value or moved a
secret.

whynot-design-npm-publish: field reverted npm_token -> NPM_AUTH_TOKEN and the
path confirmed, on railiance-platform's attended, read-only, no-value field
enumeration (their docs/evidence/2026-09-10-npm-lane-field-resolution.json).
Exactly one field is present at the governed path. The 2026-09-09 change was
adopted from a coordination message and would have failed at the WP-0037-T03
rotation. The ungoverned second location is recorded as an explicit non-lane,
not deleted and not tidied away.

pep-stance coverage: published figures were stale by eight lanes (unknown
18->20, not_applicable 12->15) while resolved stayed at 3 — the denominator
moved, the classification did not. Caught by the test that asserts the published
block equals what report_coverage.py measures. tests/test_workload_join.py held
the same stale counts; both now measure the same populations.

rapp-qonto-keycape-client: blocker character updated — authority exists and is
unexercised by owner decision ("not yet", offer open), which is not the same as
no authority existing. Reopen triggers are events, never elapsed time.

flex-auth -> access-engine rename (WARDEN-IN-0003): access-engine added to the
policy-check lane's keywords so routing resolves under both names from today.
owner_repo deliberately not flipped — policy.py sends it as resource.system on
every /v1/check, and FLEX-DEC-2026-013 keeps runtime names as flex-auth.

layer declaration: INTENT.md says Staff, layer.yaml says staff, section 11 does
not say which governs. Neither changed; gate-house holds the ruling. Position in
docs/layer-declaration-precedence.md, wait in WARDEN-WP-0034-T06, and a comment
in layer.yaml telling the next session not to "fix" it — the divergence is the
evidence the ruling is made against.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:16:33 +02:00
..
__init__.py Initial Commit 2026-03-28 00:45:43 +00:00
conftest.py Implement WARDEN-WP-0024 experiential memory and agent sessions. 2026-07-02 23:40:45 +02:00
test_access.py feat: complete local layer model v0.7 conformance work 2026-09-05 01:19:48 +02:00
test_agent_read_boundary_check.py WARDEN-WP-0033-T03: emit the high-risk data-path artifact 2026-08-21 08:38:13 +02:00
test_audit.py Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
test_ca.py feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
test_cli.py feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
test_config.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
test_desk.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
test_doubles.py Fix warden access proxy for catalog fetch commands with shell pipes. 2026-07-07 16:42:26 +02:00
test_flex_auth_registry.py feat: assert flex-auth ceiling keys are declared, not assumed 2026-09-09 14:40:05 +02:00
test_integration.py feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
test_inventory.py feat(bootstrap): WARDEN-WP-0001 initial implementation — 42 tests passing 2026-05-15 13:27:49 +02:00
test_layer_conformance.py docs: mark the unknown cell, measure the coverage we asked to publish 2026-09-10 08:02:10 +02:00
test_mask.py WARDEN-WP-0026 T03: masking display filter (defense-in-depth) 2026-07-16 14:54:55 +02:00
test_memory.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
test_models.py Initial Commit 2026-03-28 00:45:43 +00:00
test_plan.py feat: refuse to answer a write with a read (WARDEN-WP-0038) 2026-09-10 08:02:10 +02:00
test_policy.py feat: assert flex-auth ceiling keys are declared, not assumed 2026-09-09 14:40:05 +02:00
test_policy_http_refusal.py Refuse explicit policy authentication and binding denials before side effects 2026-09-08 16:46:00 +02:00
test_posture.py WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
test_posture_conformance.py feat(WARDEN-WP-0015): T3 conformance checker + T4 dev-tier contract doubles 2026-06-27 19:30:30 +02:00
test_principals_drift.py feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
test_proxy.py Refuse explicit policy authentication and binding denials before side effects 2026-09-08 16:46:00 +02:00
test_routing.py docs: narrow qonto blocker, record key-cape lane ownership 2026-09-08 14:55:02 +02:00
test_scorecard.py WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
test_taint.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
test_tunnel_cert_readiness.py feat(WARDEN-WP-0016): ops-bridge cert_command readiness gate + handoff 2026-06-27 19:50:28 +02:00
test_vault.py Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
test_worker.py feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
test_workload_join.py Revert the npm field, re-measure coverage, and hold the layer divergence 2026-09-21 02:16:33 +02:00