Enforce companion-only credential delivery and refresh activation handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 7s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 15:58:53 +02:00
parent 303cbf652b
commit 5c6f2b319d
8 changed files with 150 additions and 24 deletions

View file

@ -179,3 +179,47 @@ def test_unresolvable_companion_refuses_before_any_gate(bound, monkeypatch, tmp_
command = data["delivery_config"]["exec_owner"]["command"]
with pytest.raises(DeliveryError, match="unavailable"):
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=command, mode="exec-env"))
def test_companion_only_lane_refuses_standalone_exec_before_gate(monkeypatch, tmp_path):
lane = validate_entry(_companion())
monkeypatch.setattr(cli, "get_entry", lambda *a: lane)
monkeypatch.setattr(cli, "_require_lane_approval", lambda *a, **k: pytest.fail("no gate"))
monkeypatch.setattr(cli, "_open_backend", lambda *a, **k: pytest.fail("no backend"))
with pytest.raises(DeliveryError, match="companion-only"):
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(
field=None, catalog=lane.id, command=["/bin/sh"], mode="exec-env",
))
def test_companion_only_lane_refuses_direct_delivery_before_read(monkeypatch):
lane = validate_entry(_companion())
monkeypatch.setattr(exec_delivery, "_fetch_value", lambda *a, **k: pytest.fail("no read"))
with pytest.raises(DeliveryError, match="companion-only"):
exec_delivery.exec_with_secret(object(), lane, "worker_token", ["/bin/sh"])
@pytest.mark.parametrize("change", ["missing", "extra", "env", "field", "lane", "consent", "stage"])
def test_delivery_rechecks_companion_contract_before_any_read(bound, monkeypatch, change):
data, _, _ = bound
entry = validate_entry(_with_companion(data))
lane_data = _companion()
if change == "consent":
lane_data["delivery_config"] = {}
elif change == "stage":
lane_data.update(stage="build", path="build/team/worker")
elif change == "lane":
lane_data["id"] = "another-worker"
lane = validate_entry(lane_data)
companions = [(lane, "worker_token", "WORKER_TOKEN")]
if change == "missing": companions = []
elif change == "extra": companions *= 2
elif change == "env": companions = [(lane, "worker_token", "API_TOKEN")]
elif change == "field": companions = [(lane, "other_field", "WORKER_TOKEN")]
monkeypatch.setattr(exec_delivery, "_fetch_value", lambda *a, **k: pytest.fail("no read"))
monkeypatch.setattr(exec_delivery, "_spawn", lambda *a, **k: pytest.fail("no child"))
with pytest.raises(DeliveryError, match="companion"):
exec_delivery.exec_with_secret(
object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"],
companions=companions,
)