fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
parent
4e666d6fa3
commit
43e621439a
26 changed files with 1367 additions and 3 deletions
|
|
@ -42,6 +42,10 @@ def prepared(ledger, tmp_path, monkeypatch):
|
|||
runtime = tmp_path / "runtime"
|
||||
(runtime / "bin").mkdir(parents=True)
|
||||
(runtime / "bin/python3").write_bytes(b"not executed; fixture runtime structure")
|
||||
for name in ("rein-aharness", "glas-harness"):
|
||||
executable = runtime / "bin" / name
|
||||
executable.write_text("#!/opt/sandboxer/runtime/bin/python3\n# fixture only\n")
|
||||
executable.chmod(0o755)
|
||||
(runtime / "pyvenv.cfg").write_text("fixture only")
|
||||
messages = MessagesPolicy("fixture:upper-rate", profile.model.model, 1000, 1000, 1000, 1000)
|
||||
data = {"version": "1", "authority_ref": policy.authority_ref,
|
||||
|
|
@ -62,7 +66,8 @@ def test_prepare_pins_without_key_or_claim(prepared, monkeypatch):
|
|||
|
||||
|
||||
@pytest.mark.parametrize("case", ["authority", "policy_digest", "model", "version", "unknown_field",
|
||||
"duplicate", "public", "runtime_changed", "schema_missing"])
|
||||
"duplicate", "public", "runtime_changed", "schema_missing",
|
||||
"build_host_launcher", "missing_launcher", "nonexecutable_launcher"])
|
||||
def test_bad_bootstrap_refuses_before_claim(prepared, monkeypatch, capsys, case):
|
||||
path, config, data, runtime = prepared
|
||||
if case == "authority": data["authority_ref"] = "unrelated"
|
||||
|
|
@ -71,6 +76,16 @@ def test_bad_bootstrap_refuses_before_claim(prepared, monkeypatch, capsys, case)
|
|||
elif case == "version": data["version"] = "2"
|
||||
elif case == "unknown_field": data["upstream_url"] = "https://not-admitted.invalid"
|
||||
elif case == "runtime_changed": (runtime / "added-file").write_text("changed")
|
||||
elif case in {"build_host_launcher", "missing_launcher", "nonexecutable_launcher"}:
|
||||
executable = runtime / "bin/rein-aharness"
|
||||
if case == "build_host_launcher":
|
||||
executable.write_text("#!/bin/sh\nexec /old-build/bin/python3\n")
|
||||
elif case == "missing_launcher":
|
||||
executable.unlink()
|
||||
else:
|
||||
executable.chmod(0o644)
|
||||
# Even a correctly pinned malformed runtime must fail before claim.
|
||||
data["runtime"]["sha256"] = runtime_digest(runtime)
|
||||
elif case == "schema_missing":
|
||||
import sqlite3
|
||||
with sqlite3.connect(config.spend_ledger_path) as db: db.execute("DROP TABLE request_routes")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue