Repository navigation
Expand file tree
/
Copy pathtest_testing_gates.py
More file actions
437 lines (359 loc) · 15.6 KB
/
Copy pathtest_testing_gates.py
File metadata and controls
437 lines (359 loc) · 15.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
"""Production must never honour a test-only hook.
Every variable exercised here replaces evidence the kit would otherwise gather
from the machine: which platform this is, whether a provider process really
started, which sessions the provider reports, whether an install should abort.
Setting an environment variable is not a privilege, so each hook is armed only
when ``SESSION_KIT_TESTING=1`` is also set. These tests assert both directions
-- ignored without the gate, honoured with it -- because a gate that is only
tested in its armed state is a gate nobody has proven closed.
"""
from __future__ import annotations
import os
import platform
import subprocess
import sys
import tempfile
import unittest
from pathlib import Path
from tests.support import REPO, run
sys.path.insert(0, os.fspath(REPO / "lib"))
from sessionkit_inventory import common as inventory_common # noqa: E402
COMMON = REPO / "bin" / "session_kit_common"
LIFECYCLE = REPO / "lib" / "sh" / "session_kit_lifecycle.sh"
COMMANDS = REPO / "lib" / "sh" / "sp_commands.sh"
# A PID that exists (this process) paired with start ticks that cannot be its
# own, so the real evidence path always answers "not present". Only the
# override can turn this into a success, which is exactly what makes it a
# usable probe for whether the override was honoured.
UNPROVABLE_START_TICKS = "999999999999"
def sandbox_env(**extra: str) -> dict[str, str]:
environment = {
"PATH": os.environ.get("PATH", "/usr/bin:/bin"),
"HOME": os.environ.get("HOME", "/tmp"),
"PYTHONDONTWRITEBYTECODE": "1",
}
environment.update(extra)
return environment
class ProviderPresenceOverrideGateTests(unittest.TestCase):
"""`sk_provider_process_present` is the entire proof that a launch worked."""
def presence(self, **extra: str) -> subprocess.CompletedProcess[str]:
return run(
[
"bash",
"-c",
'source "$1"; '
f'sk_provider_process_present "$$" {UNPROVABLE_START_TICKS} codex',
"presence-gate-test",
COMMON,
],
env=sandbox_env(**extra),
check=False,
)
def test_override_is_ignored_without_the_testing_gate(self) -> None:
result = self.presence(SESSION_KIT_PROVIDER_PRESENCE_OVERRIDE="present")
self.assertNotEqual(0, result.returncode)
self.assertIn(
"ignoring SESSION_KIT_PROVIDER_PRESENCE_OVERRIDE", result.stderr
)
self.assertIn("reserved for isolated tests", result.stderr)
def test_override_is_honoured_under_the_testing_gate(self) -> None:
result = self.presence(
SESSION_KIT_TESTING="1",
SESSION_KIT_PROVIDER_PRESENCE_OVERRIDE="present",
)
self.assertEqual(0, result.returncode, result.stderr)
self.assertNotIn("ignoring", result.stderr)
def test_an_absent_override_still_refuses_under_the_gate(self) -> None:
"""The gate decides whether the hook is read, not what it may say."""
result = self.presence(
SESSION_KIT_TESTING="1",
SESSION_KIT_PROVIDER_PRESENCE_OVERRIDE="absent",
)
self.assertNotEqual(0, result.returncode)
def test_an_unset_override_never_notes_anything(self) -> None:
result = self.presence()
self.assertNotEqual(0, result.returncode)
self.assertEqual("", result.stderr)
class PlatformOverrideGateTests(unittest.TestCase):
def platform_of(self, **extra: str) -> subprocess.CompletedProcess[str]:
return run(
["bash", "-c", 'source "$1"; sk_platform', "platform-gate-test", COMMON],
env=sandbox_env(**extra),
check=False,
)
def test_platform_override_is_ignored_without_the_testing_gate(self) -> None:
result = self.platform_of(SESSION_KIT_TEST_PLATFORM="Darwin")
self.assertEqual(platform.system(), result.stdout.strip())
self.assertIn("ignoring SESSION_KIT_TEST_PLATFORM", result.stderr)
def test_platform_override_is_honoured_under_the_testing_gate(self) -> None:
result = self.platform_of(
SESSION_KIT_TESTING="1", SESSION_KIT_TEST_PLATFORM="Darwin"
)
self.assertEqual("Darwin", result.stdout.strip())
self.assertEqual("", result.stderr)
class LifecycleFailpointGateTests(unittest.TestCase):
"""An ungated failpoint lets any process abort every install."""
def failpoint(self, name: str, **extra: str) -> subprocess.CompletedProcess[str]:
return run(
[
"bash",
"-c",
'die() { printf "die: %s\\n" "$*" >&2; exit 9; }; '
'source "$1"; lifecycle_failpoint "$2"; echo SURVIVED',
"failpoint-gate-test",
LIFECYCLE,
name,
],
env=sandbox_env(**extra),
check=False,
)
def test_failpoint_is_ignored_without_the_testing_gate(self) -> None:
result = self.failpoint("themes", SESSION_KIT_TEST_FAILPOINT="themes")
self.assertEqual(0, result.returncode, result.stderr)
self.assertIn("SURVIVED", result.stdout)
def test_kill_mode_is_ignored_without_the_testing_gate(self) -> None:
result = self.failpoint(
"themes",
SESSION_KIT_TEST_FAILPOINT="themes",
SESSION_KIT_TEST_FAILPOINT_MODE="kill",
)
self.assertEqual(0, result.returncode, result.stderr)
self.assertIn("SURVIVED", result.stdout)
def test_failpoint_is_honoured_under_the_testing_gate(self) -> None:
result = self.failpoint(
"themes", SESSION_KIT_TESTING="1", SESSION_KIT_TEST_FAILPOINT="themes"
)
self.assertEqual(9, result.returncode)
self.assertIn("isolated test failpoint after themes", result.stderr)
self.assertNotIn("SURVIVED", result.stdout)
def test_a_different_failpoint_name_never_fires(self) -> None:
result = self.failpoint(
"themes",
SESSION_KIT_TESTING="1",
SESSION_KIT_TEST_FAILPOINT="theme-copy",
)
self.assertEqual(0, result.returncode, result.stderr)
self.assertIn("SURVIVED", result.stdout)
def test_the_theme_copy_failpoint_shares_the_one_gate(self) -> None:
"""`session_kit_install.sh` asks the same helper, so it cannot drift."""
source = (REPO / "lib/sh/session_kit_install.sh").read_text(encoding="utf-8")
theme_copy = source.split("install_codex_themes() {", 1)[1].split(
"install_codex_terminal_title() {", 1
)[0]
self.assertIn("lifecycle_failpoint_armed theme-copy", theme_copy)
self.assertNotIn("SESSION_KIT_TEST_FAILPOINT", theme_copy)
class ProviderSnapshotFixtureGateTests(unittest.TestCase):
"""The fixture hooks replace the provider's own answer about what exists."""
def setUp(self) -> None:
self.temporary = tempfile.TemporaryDirectory()
self.fixture = Path(self.temporary.name) / "agents.json"
self.fixture.write_text(
'[{"sessionId": "00000000-0000-4000-8000-000000000001"}]',
encoding="utf-8",
)
def tearDown(self) -> None:
self.temporary.cleanup()
def command_json(self, environ: dict[str, str]) -> object:
called: list[list[str]] = []
def runner(argv, timeout): # noqa: ANN001 - mirrors the injected Runner
called.append(list(argv))
return "[]"
payload = inventory_common._command_json(
fixture_env="SESSION_KIT_CLAUDE_JSON_FILE",
command_env="SESSION_KIT_CLAUDE_CMD",
default_command=("claude", "agents", "--json"),
runner=runner,
timeout=1.0,
environ=environ,
load_json_file=lambda path: {"fixture": str(path)},
command_from_env=lambda name, default: [
*environ.get(name, default).split()
],
)
return payload, called
def test_snapshot_fixture_is_ignored_without_the_testing_gate(self) -> None:
payload, called = self.command_json(
{"SESSION_KIT_CLAUDE_JSON_FILE": str(self.fixture)}
)
self.assertEqual([], payload)
self.assertEqual([["claude", "agents", "--json"]], called)
def test_snapshot_fixture_is_honoured_under_the_testing_gate(self) -> None:
payload, called = self.command_json(
{
"SESSION_KIT_TESTING": "1",
"SESSION_KIT_CLAUDE_JSON_FILE": str(self.fixture),
}
)
self.assertEqual({"fixture": str(self.fixture)}, payload)
self.assertEqual([], called)
class ProcRootGateTests(unittest.TestCase):
"""`/proc` is where every identity proof in the kit gets its answer."""
def setUp(self) -> None:
self.temporary = tempfile.TemporaryDirectory()
self.fake_proc = Path(self.temporary.name) / "proc"
self.fake_proc.mkdir()
def tearDown(self) -> None:
self.temporary.cleanup()
def test_fixture_root_is_ignored_without_the_testing_gate(self) -> None:
chosen = inventory_common.proc_root(
{"SESSION_KIT_PROC_ROOT": os.fspath(self.fake_proc)}
)
self.assertEqual(Path("/proc"), chosen)
def test_fixture_root_is_honoured_under_the_testing_gate(self) -> None:
chosen = inventory_common.proc_root(
{
"SESSION_KIT_TESTING": "1",
"SESSION_KIT_PROC_ROOT": os.fspath(self.fake_proc),
}
)
self.assertEqual(self.fake_proc, chosen)
def test_an_unset_fixture_root_is_the_real_one(self) -> None:
self.assertEqual(Path("/proc"), inventory_common.proc_root({}))
self.assertEqual(
Path("/proc"), inventory_common.proc_root({"SESSION_KIT_TESTING": "1"})
)
def test_the_reaper_reads_the_real_proc_without_the_gate(self) -> None:
result = run(
[
"bash",
"-c",
'set -a; source /dev/stdin <<<"$(sed -n "1,/^SENTINEL=/p" "$1")"; '
'printf "%s\\n" "$PROC_ROOT"',
"reaper-proc-root-test",
REPO / "bin" / "shpool_reaper",
],
env=sandbox_env(SESSION_KIT_PROC_ROOT=os.fspath(self.fake_proc)),
check=False,
)
self.assertEqual("/proc", result.stdout.strip(), result.stderr)
def test_the_reaper_reads_the_fixture_proc_under_the_gate(self) -> None:
result = run(
[
"bash",
"-c",
'set -a; source /dev/stdin <<<"$(sed -n "1,/^SENTINEL=/p" "$1")"; '
'printf "%s\\n" "$PROC_ROOT"',
"reaper-proc-root-test",
REPO / "bin" / "shpool_reaper",
],
env=sandbox_env(
SESSION_KIT_TESTING="1",
SESSION_KIT_PROC_ROOT=os.fspath(self.fake_proc),
),
check=False,
)
self.assertEqual(os.fspath(self.fake_proc), result.stdout.strip(), result.stderr)
class HistoryExecutableOverrideGateTests(unittest.TestCase):
"""History tool substitutions are isolated-test hooks, never production input."""
OVERRIDES = (
"SESSION_KIT_JOURNAL_RENDER_TOOL",
"SESSION_KIT_TRANSCRIPT_TEXT_TOOL",
"SESSION_KIT_HISTORY_SEARCH_TOOL",
)
def selected_path(
self, name: str, **extra: str
) -> subprocess.CompletedProcess[str]:
return run(
[
"bash",
"-c",
'source "$1"; source "$2"; sk_history_tool_path "$3" /trusted/tool',
"history-tool-gate-test",
COMMON,
COMMANDS,
name,
],
env=sandbox_env(**{name: "/untrusted/tool"}, **extra),
check=False,
)
def test_overrides_are_ignored_without_the_testing_gate(self) -> None:
for name in self.OVERRIDES:
with self.subTest(name=name):
result = self.selected_path(name)
self.assertEqual("/trusted/tool", result.stdout.strip())
self.assertIn(f"ignoring {name}", result.stderr)
self.assertIn("reserved for isolated tests", result.stderr)
def test_overrides_are_honoured_under_the_testing_gate(self) -> None:
for name in self.OVERRIDES:
with self.subTest(name=name):
result = self.selected_path(name, SESSION_KIT_TESTING="1")
self.assertEqual("/untrusted/tool", result.stdout.strip())
self.assertEqual("", result.stderr)
class NoUngatedTestHookRemainsTests(unittest.TestCase):
"""A regression net: a new ungated hook fails here, not in production."""
HOOKS = (
"SESSION_KIT_PROVIDER_PRESENCE_OVERRIDE",
"SESSION_KIT_TEST_FAILPOINT",
"SESSION_KIT_TEST_FAILPOINT_MODE",
"SESSION_KIT_TEST_MONOTONIC_NS",
"SESSION_KIT_TEST_PLATFORM",
"SESSION_KIT_PROC_ROOT",
"SESSION_KIT_SHPOOL_JSON_FILE",
"SESSION_KIT_CLAUDE_JSON_FILE",
"SESSION_KIT_JOURNAL_RENDER_TOOL",
"SESSION_KIT_TRANSCRIPT_TEXT_TOOL",
"SESSION_KIT_HISTORY_SEARCH_TOOL",
)
# The files that own a gate. Every other reader has to sit beside one.
GATEKEEPERS = {
"bin/session_kit_common",
"bin/shpool_reaper",
"lib/sh/session_kit_lifecycle.sh",
"lib/sessionkit_inventory/common.py",
}
def production_files(self) -> list[Path]:
listed = subprocess.run(
["git", "ls-files"],
cwd=REPO,
text=True,
stdout=subprocess.PIPE,
check=True,
).stdout.split()
keep = []
for name in listed:
if name.startswith(("tests/", "docs/", ".github/")):
continue
path = REPO / name
if path.suffix in {".md", ".json", ".txt", ".patch", ".tmTheme"}:
continue
if path.is_file():
keep.append(path)
return keep
def test_every_test_hook_read_sits_next_to_the_testing_gate(self) -> None:
offenders = []
for path in self.production_files():
relative = path.relative_to(REPO).as_posix()
if relative in self.GATEKEEPERS:
continue
try:
lines = path.read_text(encoding="utf-8").splitlines()
except (OSError, UnicodeDecodeError):
continue
for number, line in enumerate(lines, 1):
if not any(hook in line for hook in self.HOOKS):
continue
# The gate may sit on this line or within six lines either
# side, which covers the longest multi-line condition in the
# tree while still requiring the hook and gate to be adjacent.
window = "\n".join(lines[max(0, number - 7) : number + 6])
if "SESSION_KIT_TESTING" in window:
continue
if any(
marker in line
for marker in (
"sk_test_hook",
"sk_history_tool_path",
"failpoint_armed",
"proc_root(",
# Names the variable for `_command_json`, which is
# where that hook's gate lives.
"fixture_env=",
)
):
continue
if line.lstrip().startswith(("#", "``", '"')):
continue
offenders.append(f"{relative}:{number}: {line.strip()}")
self.assertEqual([], offenders)
if __name__ == "__main__":
unittest.main()