The playbook detector is the estate reference (021 §3). Add its one addition to the reference and the checker: any v?N.N in a standard: or companion: value is a pin. The prose-citation note moves from pending to not reached (021 §1, A12 r3), and intent_version is noted as a key that must not be flagged. VALIDATED_AGAINST keeps accepted v0.7 and adds GH-DEC-2026-021 at gate-house@39d9287. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
319 lines
14 KiB
Python
319 lines
14 KiB
Python
"""Layer-model conformance (security-layer-model_v0.4 §5, §11).
|
|
|
|
Two things are checked here. §11 makes one of them mechanical: every direct
|
|
Tooling client maps to a declared shape. §5.2 asks for the other: the conduit's
|
|
supplied-authority property covered by a test.
|
|
|
|
Deliberately absent: any assertion on a §5.3 review date. A date-triggered
|
|
failure breaks the build on a calendar day with no code change, punishing
|
|
whoever commits next rather than whoever owns the gap — the same reasoning
|
|
recorded in WARDEN-WP-0033-T05 for blocker staleness.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
import subprocess
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
import yaml
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
|
|
|
|
def _decl() -> dict:
|
|
return yaml.safe_load((ROOT / "layer.yaml").read_text())
|
|
|
|
|
|
def _intent_frontmatter() -> dict:
|
|
lines = (ROOT / "INTENT.md").read_text().splitlines()
|
|
assert lines[0].strip() == "---", "INTENT.md must carry frontmatter — it is the declaration"
|
|
end = next(i for i, ln in enumerate(lines[1:], 1) if ln.strip() == "---")
|
|
return yaml.safe_load("\n".join(lines[1:end]))
|
|
|
|
|
|
def _checker():
|
|
import importlib.util
|
|
|
|
spec = importlib.util.spec_from_file_location(
|
|
"check_layer_conformance", ROOT / "scripts" / "check_layer_conformance.py"
|
|
)
|
|
module = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(module)
|
|
return module
|
|
|
|
|
|
def _fold(value: str) -> str:
|
|
return str(value).strip().encode("ascii", "ignore").decode().lower()
|
|
|
|
|
|
class TestDeclaration:
|
|
def test_declares_staff_layer_in_its_own_voice(self):
|
|
d = _decl()
|
|
assert d["repository"] == "ops-warden"
|
|
assert _fold(d["layer"]) == "staff"
|
|
# §11: "only the repository's own file, in its own voice, conforms."
|
|
assert d["declared_by"] == "docs/adr/ADR-0010"
|
|
|
|
def test_intent_md_carries_the_governing_declaration(self):
|
|
"""GH-DEC-2026-017 §1 / A11: INTENT.md's frontmatter is the declaration."""
|
|
assert _fold(_intent_frontmatter()["layer"]) == "staff"
|
|
|
|
def test_sidecar_is_marked_derived_and_names_its_source(self):
|
|
"""§11's derived-artifact rule, applied to the layer sidecar."""
|
|
d = _decl()
|
|
assert d["derived"] is True
|
|
assert d["derived_from"] == "INTENT.md"
|
|
|
|
def test_the_two_forms_agree_once_case_is_folded(self):
|
|
"""A11: the derived form must agree; A9: comparison folds case.
|
|
|
|
`Staff` in INTENT.md and `staff` in layer.yaml are the SAME value. This
|
|
test is deliberately a fold rather than an equality: the ruling asked
|
|
nobody to re-spell anything, and an equality assertion here would be this
|
|
repository quietly doing the re-spelling the ruling declined to order.
|
|
The next *real* divergence — a different layer — still fails.
|
|
"""
|
|
assert _fold(_decl()["layer"]) == _fold(_intent_frontmatter()["layer"])
|
|
|
|
def test_layer_is_in_section_3_closed_vocabulary(self):
|
|
"""A9: {Taxonomy, Tooling, Engine, Staff}, closed, case-insensitive."""
|
|
vocabulary = {"taxonomy", "tooling", "engine", "staff"}
|
|
assert _fold(_intent_frontmatter()["layer"]) in vocabulary
|
|
assert _fold(_decl()["layer"]) in vocabulary
|
|
|
|
def test_no_declaration_carries_a_standard_version(self):
|
|
"""GH-DEC-2026-017 §5 / A12 — and the regression guard on its return.
|
|
|
|
The field was removed from the estate's reference form, not just from
|
|
this file. A field that is present will be branched on, so absence is
|
|
asserted rather than trusted.
|
|
"""
|
|
assert "standard_version" not in _decl()
|
|
assert "standard_version" not in _intent_frontmatter()
|
|
|
|
def test_no_version_anywhere_in_either_declaration(self):
|
|
"""A12 r2 / GH-DEC-2026-020 §1-§2: content, not a key name.
|
|
|
|
A versioned `standard:` path or a `companion_version` is the same pin as
|
|
`standard_version`, so the guard walks every key and value of both forms.
|
|
"""
|
|
checker = _checker()
|
|
assert checker.find_version_pins(_intent_frontmatter()) == []
|
|
assert checker.find_version_pins(_decl()) == []
|
|
assert not str(_intent_frontmatter()["standard"]).endswith(".md")
|
|
|
|
def test_checker_catches_a_versioned_standard_path(self):
|
|
checker = _checker()
|
|
pins = checker.find_version_pins(
|
|
{"layer": "Staff", "standard": "net-kingdom/canon/standards/security-layer-model_v0.7.md"}
|
|
)
|
|
assert pins and pins[0].startswith("standard")
|
|
|
|
def test_checker_catches_a_companion_version(self):
|
|
checker = _checker()
|
|
assert checker.find_version_pins({"layer": "Staff", "companion_version": "0.2"})
|
|
assert checker.find_version_pins({"nested": {"standard_version": "0.7"}})
|
|
|
|
def test_version_token_in_identity_value_is_a_pin(self):
|
|
"""GH-DEC-2026-021 §3: any `v?N.N` in a standard:/companion: value is a pin."""
|
|
checker = _checker()
|
|
pins = checker.find_version_pins({"standard": "security-layer-model v0.7"})
|
|
assert pins and pins[0].startswith("standard")
|
|
assert checker.find_version_pins({"companion": "SECURITY-COMPANION 0.2"})
|
|
assert checker.find_version_pins({"nested": {"standard": ["security-layer-model v0.8"]}})
|
|
|
|
def test_prose_citation_and_intent_version_are_not_reached(self):
|
|
"""GH-DEC-2026-021 §1 (A12 r3): prose provenance and `intent_version` pass."""
|
|
checker = _checker()
|
|
assert checker.find_version_pins(
|
|
{"layer": "Staff", "note": "Outside §5 by the v0.5 scope rule", "intent_version": "0.1.0"}
|
|
) == []
|
|
|
|
def test_schema_version_is_not_reached(self):
|
|
assert _checker().find_version_pins({"schema_version": "0.2", "layer": "Staff"}) == []
|
|
|
|
def test_stance_map_is_outside_the_run(self):
|
|
"""GH-DEC-2026-020 §3: a stance map keeps its version; the run must not read it."""
|
|
stance = yaml.safe_load((ROOT / "pep-stance.yaml").read_text())
|
|
assert "standard_version" in stance, "pep-stance.yaml keeps its clause-scoped version"
|
|
assert "pep-stance" not in _checker().SCOPE
|
|
|
|
def test_every_run_states_version_and_scope(self):
|
|
"""GH-DEC-2026-020 §4: the version belongs to the run, printed every time."""
|
|
checker = _checker()
|
|
out = subprocess.run(
|
|
[sys.executable, str(ROOT / "scripts" / "check_layer_conformance.py")],
|
|
capture_output=True,
|
|
text=True,
|
|
).stdout
|
|
assert f"validated against: {checker.VALIDATED_AGAINST}" in out
|
|
assert f"scope: {checker.SCOPE}" in out
|
|
pass_line = next(ln for ln in out.splitlines() if ln.startswith("PASS"))
|
|
assert checker.VALIDATED_AGAINST in pass_line
|
|
|
|
def test_every_tooling_contact_maps_to_a_declared_shape(self):
|
|
"""§11 mechanical check — the guard against a new undeclared client."""
|
|
result = subprocess.run(
|
|
[sys.executable, str(ROOT / "scripts" / "check_layer_conformance.py")],
|
|
capture_output=True,
|
|
text=True,
|
|
)
|
|
assert result.returncode == 0, (
|
|
f"undeclared Tooling contact — a finding under §11, not a tracked gap:\n"
|
|
f"{result.stdout}{result.stderr}"
|
|
)
|
|
|
|
def test_declared_gaps_carry_all_four_fields(self):
|
|
"""§5.3 is machine-readable or it is prose wearing a schema."""
|
|
for c in _decl()["tooling_contacts"]:
|
|
if c["shape"] == "5.3":
|
|
for field in ("capability", "intended_owner", "blocked_on", "review"):
|
|
assert c.get(field), f"{c['id']} missing {field}"
|
|
|
|
def test_gaps_are_not_counted_as_conformance(self):
|
|
"""§11: a declared gap is tracked non-conformance. Keep that visible."""
|
|
text = (ROOT / "layer.yaml").read_text()
|
|
assert "TRACKED NON-CONFORMANCE" in text.upper()
|
|
|
|
|
|
class TestConduitSuppliesNoAuthority:
|
|
"""§5.2: 'MUST NOT present its own credential, MUST NOT widen what the
|
|
caller could already do.' The standard says this SHOULD be covered by a
|
|
test; this is that test."""
|
|
|
|
def test_conduit_supplies_no_authority_of_its_own(self, monkeypatch):
|
|
from warden import proxy
|
|
|
|
monkeypatch.setenv("VAULT_TOKEN", "caller-own-token")
|
|
monkeypatch.setenv("HOME", "/home/nobody")
|
|
before = dict(os.environ)
|
|
|
|
env = proxy._caller_env()
|
|
|
|
# The child environment IS the caller's environment — nothing added,
|
|
# nothing removed, no ops-warden credential injected.
|
|
assert env == before, (
|
|
"conduit altered the caller's environment; §5.2 requires it to "
|
|
"supply no authority of its own"
|
|
)
|
|
assert env["VAULT_TOKEN"] == "caller-own-token"
|
|
|
|
def test_conduit_declares_supplied_authority_none(self):
|
|
conduits = [c for c in _decl()["tooling_contacts"] if c["shape"] == "5.2"]
|
|
assert conduits, "no §5.2 conduit declared — proxy.py is one"
|
|
for c in conduits:
|
|
assert c["supplied_authority"] == "none"
|
|
|
|
def test_proxy_holds_no_credential_constant(self):
|
|
"""A conduit that presents its own token is not a conduit (§5.2)."""
|
|
src = (ROOT / "src" / "warden" / "proxy.py").read_text()
|
|
# It may name token ENV VARS to detect caller auth; it must not carry a
|
|
# token value or mint one.
|
|
for forbidden in ("X-Vault-Token", "auth/approle/login", "token create"):
|
|
assert forbidden not in src, (
|
|
f"proxy.py references {forbidden!r} — that is presenting or "
|
|
f"minting authority, not conducting the caller's"
|
|
)
|
|
|
|
|
|
class TestPepStanceMap:
|
|
"""§6.4: every PEP-shaped consumer MUST publish its unreachable-engine
|
|
stance map, total and per zone, 'published rather than held in code'.
|
|
ADR-0009 is named as the reference shape, so it should actually hold."""
|
|
|
|
def _stance(self) -> dict:
|
|
return yaml.safe_load((ROOT / "pep-stance.yaml").read_text())
|
|
|
|
def test_published_map_equals_shipped_behaviour(self):
|
|
"""The whole point. A published map that may drift from the code is
|
|
worse than none, because it invites reliance it cannot support."""
|
|
from warden.config import PolicyConfig
|
|
|
|
assert self._stance()["stance"] == PolicyConfig().failure_modes
|
|
|
|
def test_stance_is_total_over_the_zone_model(self):
|
|
"""§6.4 obligation 3: total, no implicit default."""
|
|
stance = self._stance()["stance"]
|
|
required = {
|
|
"z0-experimental", "z1-operational", "z2-protected",
|
|
"z2-continuity", "z3-critical", "unknown", "not-applicable",
|
|
}
|
|
assert required <= set(stance), f"stance not total; missing {required - set(stance)}"
|
|
assert set(stance.values()) <= {"fail_open", "fail_closed"}
|
|
|
|
def test_critical_zone_fails_closed(self):
|
|
"""ADR-0009's one non-negotiable row."""
|
|
assert self._stance()["stance"]["z3-critical"] == "fail_closed"
|
|
|
|
def test_verdict_is_never_cached(self):
|
|
"""§6.4 obligation 2: caching an input claim is permitted; caching the
|
|
answer is a second decision point deciding early (§6.1)."""
|
|
assert self._stance()["verdict_caching"] == "none"
|
|
|
|
def test_revocation_visibility_deadline_equals_enforced_ttl_policy(self):
|
|
"""§9.7.2: a published replay window must not drift from issuance."""
|
|
from warden.models import ActorType, MAX_TTL_HOURS
|
|
|
|
published = self._stance()["revocation_visibility"]
|
|
expected = {actor.value: MAX_TTL_HOURS[actor] for actor in ActorType}
|
|
assert published["deadline_hours"] == expected
|
|
assert published["mechanism"] == "ttl_expiry"
|
|
assert published["revocation_channel"] == "none"
|
|
|
|
def test_attributive_emission_cadence_deferral_carries_measurement(self):
|
|
cadence = self._stance()["emission_cadence"]
|
|
assert cadence["classification"] == "attributive"
|
|
assert cadence["status"] == "deferred"
|
|
assert cadence["observed_window"]["signature_records"] == 3
|
|
assert cadence["observed_window"]["active_signature_days"] == 2
|
|
assert cadence["reason"]
|
|
|
|
|
|
# --- classification coverage (v0.8 §6.4 obligation 3) -------------------------
|
|
|
|
def test_published_coverage_equals_measured_coverage():
|
|
"""The published figure must equal what the repo actually measures.
|
|
|
|
ops-warden asked gate-house for §13.1's Coverage column and its figures are
|
|
that column's first entries, so their accuracy is ours to hold. The register
|
|
explicitly does not compute anyone's coverage, and a stale number beside a
|
|
marked cell is worse than a blank -- a blank at least reads as "not reported".
|
|
|
|
This is the same property that makes the stance map worth publishing (the map
|
|
equals PolicyConfig.failure_modes by test), applied one level up.
|
|
"""
|
|
import importlib.util
|
|
|
|
repo = Path(__file__).resolve().parents[1]
|
|
spec = importlib.util.spec_from_file_location(
|
|
"report_coverage", repo / "scripts" / "report_coverage.py"
|
|
)
|
|
module = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(module)
|
|
|
|
published = yaml.safe_load((repo / "pep-stance.yaml").read_text())[
|
|
"classification_coverage"
|
|
]
|
|
measured = module.measure()
|
|
|
|
for population in ("signing_targets", "routing_lanes"):
|
|
assert published[population] == measured[population], population
|
|
|
|
|
|
def test_the_unknown_cell_is_marked_as_a_declared_gap():
|
|
"""A non-conformant cell must say so where it is declared, not only in a review.
|
|
|
|
§11's marking obligation, which ops-warden argued for in the v0.6 round and
|
|
then acquired a marked cell under. If the cell is ever flipped to fail_closed
|
|
this test fails, which is the correct time to remove the marking.
|
|
"""
|
|
repo = Path(__file__).resolve().parents[1]
|
|
text = (repo / "pep-stance.yaml").read_text()
|
|
stance = yaml.safe_load(text)["stance"]
|
|
|
|
if stance["unknown"] == "fail_open":
|
|
assert "DECLARED GAP" in text
|
|
assert "WARDEN-WP-0040" in text
|
|
else:
|
|
assert stance["unknown"] == "fail_closed"
|