Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
53 lines
2 KiB
Python
53 lines
2 KiB
Python
"""Frozen action packet safety; requires the governed secrets-engine sibling."""
|
|
import importlib.util
|
|
from pathlib import Path
|
|
import shutil
|
|
|
|
import pytest
|
|
|
|
pytest.importorskip("secrets_engine")
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
SOURCE = ROOT.parent / "secrets-engine/docs/proposals/glas-metered-tool-renewal-20260927"
|
|
spec = importlib.util.spec_from_file_location("metered_native", ROOT / "scripts/metered-native-owner.py")
|
|
native = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(native)
|
|
|
|
|
|
@pytest.fixture
|
|
def bundle(tmp_path):
|
|
path = tmp_path / "bundle"
|
|
shutil.copytree(SOURCE, path)
|
|
return path
|
|
|
|
|
|
def test_all_six_action_bindings_match(bundle, tmp_path):
|
|
private = tmp_path / "private"
|
|
private.mkdir()
|
|
configs, entries = native.prepare_configs(bundle, private)
|
|
assert len(entries) == 6
|
|
for (lane, action), entry in entries.items():
|
|
assert entry.approval["authorization_id"] == native.IDS[lane][action]
|
|
assert configs["exec"].clock_trust_file is None # validation is backend-free
|
|
|
|
|
|
@pytest.mark.parametrize("lane", [native.PROVIDER, native.WORKER])
|
|
def test_recipient_drift_refused_before_auth(bundle, tmp_path, lane):
|
|
path = bundle / "catalog" / (lane + ".yaml")
|
|
path.write_text(path.read_text().replace("token_max_ttl: 15m", "token_max_ttl: 16m"))
|
|
private = tmp_path / "private"
|
|
private.mkdir()
|
|
with pytest.raises(ValueError, match="frozen_action_request_drift"):
|
|
native.prepare_configs(bundle, private)
|
|
|
|
|
|
def test_changed_packet_refused(bundle, tmp_path):
|
|
path = bundle / "native-pdp-inputs.json"
|
|
path.write_bytes(path.read_bytes() + b"\n")
|
|
with pytest.raises(ValueError, match="frozen_packet_drift"):
|
|
native.prepare_configs(bundle, tmp_path)
|
|
|
|
|
|
def test_execution_never_replays_prior_attempt(bundle):
|
|
(bundle / "execution.json").write_text('{"phase":"one_exec_started"}')
|
|
with pytest.raises(ValueError, match="prior_attempt_requires_reconciliation"):
|
|
native.execute(bundle)
|