Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -102,8 +102,9 @@ def test_binding_changed_after_approval_refuses_before_fetch(bound, monkeypatch)
exec_delivery.exec_with_secret(object(), entry, "api_token", data["delivery_config"]["exec_owner"]["command"], expected_owner_digest=expected)
def test_pending_real_catalog_refuses_before_approval_and_backend(tmp_path, monkeypatch):
def test_pending_owner_refuses_before_approval_and_backend(tmp_path, monkeypatch):
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
for name in ["_require_lane_approval", "_open_backend"]:
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
@ -160,8 +161,35 @@ def test_invalid_binding_is_not_a_catalog_fallback(bound, change):
def test_pending_owner_never_advertises_ready(tmp_path, monkeypatch):
from secrets_engine import routing
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
entry.delivery_config["exec_owner"] = {"status": "pending", "owner": "fixture", "reason": "not admitted"}
monkeypatch.setattr(routing, "resolve_decision", lambda **k: SimpleNamespace(status="approved", review_url="", is_approved=lambda: True))
client = SimpleNamespace(is_reachable=lambda: True, read_policy=lambda p: "policy", approle_exists=lambda r: True, kv_fields_present=lambda *a: {"ANTHROPIC_API_KEY": True})
result = routing.route_lane(entry, hub_url="", repo_root=tmp_path, client=client)
assert not result.ready and "exec owner" in result.missing
assert "<command" not in result.next_command
def test_configured_glas_catalog_refuses_arbitrary_child_before_gate(tmp_path, monkeypatch):
entry = load_entry(Path(__file__).resolve().parents[1] / "catalog/glas-claude-agent-dev-anthropic.yaml")
assert entry.delivery_config["exec_owner"]["status"] == "configured"
monkeypatch.setattr(cli, "get_entry", lambda *a: entry)
for name in ["_require_lane_approval", "_open_backend"]:
monkeypatch.setattr(cli, name, lambda *a, **k: pytest.fail("no approval consume or backend"))
with pytest.raises(DeliveryError, match="catalog-bound"):
cli.cmd_exec(_cfg(tmp_path), SimpleNamespace(field=None, catalog=entry.id, command=["/bin/echo"], mode="exec-env"))
def test_configured_glas_companion_matches_worker_and_pins_spend_policy():
from secrets_engine.exec_owner import resolve_companions
root = Path(__file__).resolve().parents[1] / "catalog"
entry = load_entry(root / "glas-claude-agent-dev-anthropic.yaml")
binding = entry.delivery_config["exec_owner"]
companions = resolve_companions(entry, lambda cid: load_entry(root / (cid + ".yaml")))
assert [(lane.id, field, env) for lane, field, env in companions] == [
("activity-core-metered-worker-token", "token", "ACTIVITY_CORE_WORKER_TOKEN")
]
assert binding["environment"]["AGENT_HARNESS_WORKER_ID"] == "rein-aharness-metered@railiance01"
assert binding["environment"]["AGENT_HARNESS_OPS_LABELS"] == "hfact-metered"
assert binding["files"][binding["environment"]["AGENT_HARNESS_SPEND_POLICY"]]["private"] is True
request = build_action_request(entry, "exec", subject_id="agent:fixture", subject_type="Agent", purpose="owner-proof", fields=entry.fields)
assert request["context"]["exec_owner_sha256"] == owner_digest(entry)