no-mistakes(review): Fix report-only gate, dedupe list, correct fleet map

This commit is contained in:
root
2026-09-12 18:38:19 +00:00
parent 7b8cc5f9ac
commit 4ea2d0309f
5 changed files with 85 additions and 76 deletions
+37 -9
View File
@@ -78,12 +78,40 @@ def test_agent_name_alone_does_not_gate_a_guest(tmp_path):
assert plan and plan[0]["action"] == "gc-executor"
def test_contract_carries_the_guest_keyed_exclusion(tmp_path):
"""The authoritative gate must exist and identify CT 111 by guest/host."""
plan = _plan([{"id": 111, "usage_pct": 95}], tmp_path)
reason = _actions_for(plan, 111)[0]["reason"]
assert reason, "the exclusion must carry a reason for the alert"
contract = (ROOT / "disk-gc-threat-response.prose.md").read_text()
assert "report_only_guests:" in contract
assert "192.168.68.129" in contract
assert "tdunna" in contract
def _plan_with_contract(scan, contract_text, tmp_path, name):
contract = tmp_path / name
contract.write_text(contract_text)
scan_file = tmp_path / f"scan-{name}.json"
scan_file.write_text(json.dumps(scan))
proc = subprocess.run(
[sys.executable, str(PLAN), "--scan", str(scan_file),
"--contract", str(contract), "--json"],
capture_output=True, text=True,
)
assert proc.returncode == 0, proc.stderr
return json.loads(proc.stdout)
def test_gate_is_read_from_the_contract_block(tmp_path):
"""The gate is data-driven by the contract block: the planner excludes the guest
when the block names it and acts on it when the block does not. Executes the real
planner interface against both fixtures so the behaviour change is observable."""
scan = [{"id": 111, "hostname": "tdunna", "ip": "192.168.68.129", "usage_pct": 95}]
with_gate = (
"```yaml\n"
"report_only_guests:\n"
" - guest: 111\n"
" hostname: tdunna\n"
" ip: 192.168.68.129\n"
" reason: \"fixture reason\"\n"
"```\n"
)
without_gate = "```yaml\nreport_only_guests: []\n```\n"
gated = _plan_with_contract(scan, with_gate, tmp_path, "gated.prose.md")
assert gated[0]["action"] == "report-only", gated
assert gated[0]["reason"] == "fixture reason", gated
ungated = _plan_with_contract(scan, without_gate, tmp_path, "ungated.prose.md")
assert ungated[0]["action"] == "gc-executor", ungated
assert ungated[0]["action"] != gated[0]["action"]