Enforce companion-only credential delivery and refresh activation handoff
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
303cbf652b
commit
5c6f2b319d
8 changed files with 150 additions and 24 deletions
|
|
@ -179,3 +179,47 @@ def test_unresolvable_companion_refuses_before_any_gate(bound, monkeypatch, tmp_
|
|||
command = data["delivery_config"]["exec_owner"]["command"]
|
||||
with pytest.raises(DeliveryError, match="unavailable"):
|
||||
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=command, mode="exec-env"))
|
||||
|
||||
|
||||
def test_companion_only_lane_refuses_standalone_exec_before_gate(monkeypatch, tmp_path):
|
||||
lane = validate_entry(_companion())
|
||||
monkeypatch.setattr(cli, "get_entry", lambda *a: lane)
|
||||
monkeypatch.setattr(cli, "_require_lane_approval", lambda *a, **k: pytest.fail("no gate"))
|
||||
monkeypatch.setattr(cli, "_open_backend", lambda *a, **k: pytest.fail("no backend"))
|
||||
with pytest.raises(DeliveryError, match="companion-only"):
|
||||
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(
|
||||
field=None, catalog=lane.id, command=["/bin/sh"], mode="exec-env",
|
||||
))
|
||||
|
||||
|
||||
def test_companion_only_lane_refuses_direct_delivery_before_read(monkeypatch):
|
||||
lane = validate_entry(_companion())
|
||||
monkeypatch.setattr(exec_delivery, "_fetch_value", lambda *a, **k: pytest.fail("no read"))
|
||||
with pytest.raises(DeliveryError, match="companion-only"):
|
||||
exec_delivery.exec_with_secret(object(), lane, "worker_token", ["/bin/sh"])
|
||||
|
||||
|
||||
@pytest.mark.parametrize("change", ["missing", "extra", "env", "field", "lane", "consent", "stage"])
|
||||
def test_delivery_rechecks_companion_contract_before_any_read(bound, monkeypatch, change):
|
||||
data, _, _ = bound
|
||||
entry = validate_entry(_with_companion(data))
|
||||
lane_data = _companion()
|
||||
if change == "consent":
|
||||
lane_data["delivery_config"] = {}
|
||||
elif change == "stage":
|
||||
lane_data.update(stage="build", path="build/team/worker")
|
||||
elif change == "lane":
|
||||
lane_data["id"] = "another-worker"
|
||||
lane = validate_entry(lane_data)
|
||||
companions = [(lane, "worker_token", "WORKER_TOKEN")]
|
||||
if change == "missing": companions = []
|
||||
elif change == "extra": companions *= 2
|
||||
elif change == "env": companions = [(lane, "worker_token", "API_TOKEN")]
|
||||
elif change == "field": companions = [(lane, "other_field", "WORKER_TOKEN")]
|
||||
monkeypatch.setattr(exec_delivery, "_fetch_value", lambda *a, **k: pytest.fail("no read"))
|
||||
monkeypatch.setattr(exec_delivery, "_spawn", lambda *a, **k: pytest.fail("no child"))
|
||||
with pytest.raises(DeliveryError, match="companion"):
|
||||
exec_delivery.exec_with_secret(
|
||||
object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"],
|
||||
companions=companions,
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue