Advance supervised agent records and close verified Secret annotation guard
This commit is contained in:
parent
b2f6713721
commit
db91818e84
44 changed files with 6868 additions and 54 deletions
57
tests/test_agent_supervision.py
Normal file
57
tests/test_agent_supervision.py
Normal file
|
|
@ -0,0 +1,57 @@
|
|||
import importlib.util
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
spec = importlib.util.spec_from_file_location("supervision", Path(__file__).resolve().parents[1] / "scripts/summarize_agent_supervision.py")
|
||||
module = importlib.util.module_from_spec(spec)
|
||||
spec.loader.exec_module(module)
|
||||
|
||||
|
||||
def record(*proposals):
|
||||
return {"agent_id": "fixture", "scope": "synthetic", "mode": "supervised", "proposals": list(proposals)}
|
||||
|
||||
|
||||
def proposal(identity, disposition="accepted_unchanged", outcome="succeeded", refinement=False):
|
||||
approved = "original" if disposition == "accepted_unchanged" else "revised"
|
||||
return dict(proposal_id=identity, disposition=disposition, outcome=outcome,
|
||||
original_digest="original", approved_digest=approved, executed_digest=approved,
|
||||
approval_ref="synthetic-approval", verification_ref="synthetic-verification",
|
||||
refinement_or_rescue=refinement)
|
||||
|
||||
|
||||
def test_no_sample_is_unknown_and_cannot_grant_authority():
|
||||
report = module.summarize(record())
|
||||
assert report["unchanged_acceptance_rate"] is None
|
||||
assert report["unchanged_execution_success_rate"] is None
|
||||
assert report["authority_granted"] is False
|
||||
|
||||
|
||||
def test_revisions_rejections_and_rescue_do_not_earn_unchanged_success():
|
||||
report = module.summarize(record(proposal("one"), proposal("two", "accepted_revised"),
|
||||
proposal("three", refinement=True), proposal("four", "rejected", "not_executed")))
|
||||
assert report["unchanged_acceptance_rate"] == 2 / 4
|
||||
assert report["unchanged_execution_success_rate"] == 1 / 3
|
||||
|
||||
|
||||
def test_approval_alone_is_not_execution_success():
|
||||
report = module.summarize(record(proposal("one", outcome="not_executed")))
|
||||
assert report["unchanged_acceptance_rate"] == 1
|
||||
assert report["unchanged_execution_success_rate"] is None
|
||||
|
||||
|
||||
def test_duplicate_trials_and_unapproved_revisions_are_rejected():
|
||||
with pytest.raises(ValueError):
|
||||
module.summarize(record(proposal("same"), proposal("same")))
|
||||
wrong = proposal("one"); wrong["executed_digest"] = "unapproved"
|
||||
with pytest.raises(ValueError):
|
||||
module.summarize(record(wrong))
|
||||
|
||||
|
||||
def test_unscored_history_remains_visible_without_manufacturing_a_rate():
|
||||
report = module.summarize(record(proposal("historic", "unscored", "failed", True)))
|
||||
assert report["counts"]["unscored"] == 1
|
||||
assert report["counts"]["outcome_failed"] == 1
|
||||
assert report["counts"]["refinement_or_rescue"] == 1
|
||||
assert report["unchanged_acceptance_rate"] is None
|
||||
assert report["unchanged_execution_success_rate"] is None
|
||||
61
tests/test_secret_annotation_maintenance.py
Normal file
61
tests/test_secret_annotation_maintenance.py
Normal file
|
|
@ -0,0 +1,61 @@
|
|||
"""Ensure maintenance cannot echo credentials or change Secret data."""
|
||||
import importlib.util
|
||||
import json
|
||||
import subprocess
|
||||
from pathlib import Path
|
||||
from unittest.mock import patch
|
||||
|
||||
PATH = Path(__file__).resolve().parents[1] / "docs/changes/CUST-WP-0073/secret_annotation_maintenance.py"
|
||||
spec = importlib.util.spec_from_file_location("maintenance", PATH)
|
||||
maintenance = importlib.util.module_from_spec(spec)
|
||||
spec.loader.exec_module(maintenance)
|
||||
|
||||
|
||||
def test_failure_does_not_return_raw_secret_output():
|
||||
responses = [subprocess.CompletedProcess([], 0, "sso example\n", ""),
|
||||
subprocess.CompletedProcess([], 0, "namespace/sso\n", ""),
|
||||
subprocess.CompletedProcess([], 1, "SENSITIVE-STDOUT", "SENSITIVE-STDERR")]
|
||||
with patch.object(maintenance.subprocess, "run", side_effect=responses):
|
||||
report = maintenance.maintain()
|
||||
assert report["complete"] is False
|
||||
assert "SENSITIVE" not in json.dumps(report)
|
||||
|
||||
|
||||
def test_clean_only_removes_annotation_and_checks_result():
|
||||
responses = ["sso example", "namespace/sso", "HAS-ANNOTATION", "secret/example patched", "clean"]
|
||||
calls = []
|
||||
def fake(args):
|
||||
calls.append(args)
|
||||
return responses.pop(0)
|
||||
with patch.object(maintenance, "run", side_effect=fake):
|
||||
report = maintenance.maintain(clean=True)
|
||||
assert report["complete"] and report["cleaned"] == ["sso/example"]
|
||||
operation = json.loads(calls[3][-1])
|
||||
assert operation == [{"op": "remove", "path": "/metadata/annotations/kubectl.kubernetes.io~1last-applied-configuration"}]
|
||||
assert calls[2] == calls[4]
|
||||
|
||||
|
||||
def test_inspect_never_patches_and_rejects_unexpected_template_output():
|
||||
with patch.object(maintenance, "run", side_effect=["sso example", "namespace/sso", "SENSITIVE-DUMP"]):
|
||||
report = maintenance.maintain()
|
||||
assert not report["complete"]
|
||||
assert "SENSITIVE" not in json.dumps(report)
|
||||
|
||||
|
||||
def test_inventory_rejects_untrusted_arguments():
|
||||
with patch.object(maintenance, "run", return_value="sso --help"):
|
||||
try:
|
||||
maintenance.maintain(clean=True)
|
||||
except RuntimeError:
|
||||
pass
|
||||
else:
|
||||
raise AssertionError("unsafe identity accepted")
|
||||
|
||||
|
||||
def test_orphan_namespace_is_explicit_and_never_deleted_or_claimed_clean():
|
||||
with patch.object(maintenance, "run", side_effect=["gone orphan\nsso normal", "namespace/sso", "clean"]) as mocked:
|
||||
report = maintenance.maintain(clean=True)
|
||||
assert report["orphaned_namespace"] == ["gone/orphan"]
|
||||
assert not report["complete"]
|
||||
assert report["active_namespace_scan_complete"]
|
||||
assert mocked.call_count == 3
|
||||
Loading…
Add table
Add a link
Reference in a new issue