fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
tegwick 2026-09-27 23:19:50 +02:00
parent 4e666d6fa3
commit 43e621439a
26 changed files with 1367 additions and 3 deletions

View file

@ -0,0 +1,53 @@
"""Frozen action packet safety; requires the governed secrets-engine sibling."""
import importlib.util
from pathlib import Path
import shutil
import pytest
pytest.importorskip("secrets_engine")
ROOT = Path(__file__).resolve().parents[1]
SOURCE = ROOT.parent / "secrets-engine/docs/proposals/glas-metered-tool-renewal-20260927"
spec = importlib.util.spec_from_file_location("metered_native", ROOT / "scripts/metered-native-owner.py")
native = importlib.util.module_from_spec(spec)
spec.loader.exec_module(native)
@pytest.fixture
def bundle(tmp_path):
path = tmp_path / "bundle"
shutil.copytree(SOURCE, path)
return path
def test_all_six_action_bindings_match(bundle, tmp_path):
private = tmp_path / "private"
private.mkdir()
configs, entries = native.prepare_configs(bundle, private)
assert len(entries) == 6
for (lane, action), entry in entries.items():
assert entry.approval["authorization_id"] == native.IDS[lane][action]
assert configs["exec"].clock_trust_file is None # validation is backend-free
@pytest.mark.parametrize("lane", [native.PROVIDER, native.WORKER])
def test_recipient_drift_refused_before_auth(bundle, tmp_path, lane):
path = bundle / "catalog" / (lane + ".yaml")
path.write_text(path.read_text().replace("token_max_ttl: 15m", "token_max_ttl: 16m"))
private = tmp_path / "private"
private.mkdir()
with pytest.raises(ValueError, match="frozen_action_request_drift"):
native.prepare_configs(bundle, private)
def test_changed_packet_refused(bundle, tmp_path):
path = bundle / "native-pdp-inputs.json"
path.write_bytes(path.read_bytes() + b"\n")
with pytest.raises(ValueError, match="frozen_packet_drift"):
native.prepare_configs(bundle, tmp_path)
def test_execution_never_replays_prior_attempt(bundle):
(bundle / "execution.json").write_text('{"phase":"one_exec_started"}')
with pytest.raises(ValueError, match="prior_attempt_requires_reconciliation"):
native.execute(bundle)