no-mistakes(review): Gate wrapper checks on executed infisical; scope liveness guide

This commit is contained in:
2026-09-10 01:46:06 +00:00
parent c59c9fb174
commit 1974959cc9
4 changed files with 35 additions and 11 deletions
+14
View File
@@ -231,6 +231,20 @@ def test_comment_mentioning_removed_infisical_path_is_not_failed(ahc, monkeypatc
assert "wrapper infisical path OK" in out
def test_comment_only_infisical_mention_does_not_reach_path_check(ahc, monkeypatch, capsys):
# A comment-only mention of a removed infisical path on a healthy .env-based
# wrapper is not an invocation: it must not fall through to the `command -v`
# PATH check and false-FAIL `wrapper-no-infisical`.
_stub_wrapper_ssh(ahc, monkeypatch,
"#!/bin/bash\n# migrated from /usr/local/bin/infisical\n"
"source ~/.hermes/.env\nexec hermes-real \"$@\"\n",
test_x_result="MISS", command_v=None)
ahc.check_wrapper_integrity()
out = capsys.readouterr().out
assert ahc.FAIL == []
assert "wrapper resolves creds without infisical" in out
# ── item 4: prose-lint enforces report provenance (real consumer) ─────
GOOD_CONTRACT = textwrap.dedent("""\