"""Frozen action packet safety; requires the governed secrets-engine sibling.""" import importlib.util from pathlib import Path import shutil import pytest pytest.importorskip("secrets_engine") ROOT = Path(__file__).resolve().parents[1] SOURCE = ROOT.parent / "secrets-engine/docs/proposals/glas-metered-tool-renewal-20260927" spec = importlib.util.spec_from_file_location("metered_native", ROOT / "scripts/metered-native-owner.py") native = importlib.util.module_from_spec(spec) spec.loader.exec_module(native) @pytest.fixture def bundle(tmp_path): path = tmp_path / "bundle" shutil.copytree(SOURCE, path) return path def test_all_six_action_bindings_match(bundle, tmp_path): private = tmp_path / "private" private.mkdir() configs, entries = native.prepare_configs(bundle, private) assert len(entries) == 6 for (lane, action), entry in entries.items(): assert entry.approval["authorization_id"] == native.IDS[lane][action] assert configs["exec"].clock_trust_file is None # validation is backend-free @pytest.mark.parametrize("lane", [native.PROVIDER, native.WORKER]) def test_recipient_drift_refused_before_auth(bundle, tmp_path, lane): path = bundle / "catalog" / (lane + ".yaml") path.write_text(path.read_text().replace("token_max_ttl: 15m", "token_max_ttl: 16m")) private = tmp_path / "private" private.mkdir() with pytest.raises(ValueError, match="frozen_action_request_drift"): native.prepare_configs(bundle, private) def test_changed_packet_refused(bundle, tmp_path): path = bundle / "native-pdp-inputs.json" path.write_bytes(path.read_bytes() + b"\n") with pytest.raises(ValueError, match="frozen_packet_drift"): native.prepare_configs(bundle, tmp_path) def test_execution_never_replays_prior_attempt(bundle): (bundle / "execution.json").write_text('{"phase":"one_exec_started"}') with pytest.raises(ValueError, match="prior_attempt_requires_reconciliation"): native.execute(bundle)