no-mistakes(review): Fix report-only gate, dedupe list, correct fleet map
This commit is contained in:
@@ -78,12 +78,40 @@ def test_agent_name_alone_does_not_gate_a_guest(tmp_path):
|
||||
assert plan and plan[0]["action"] == "gc-executor"
|
||||
|
||||
|
||||
def test_contract_carries_the_guest_keyed_exclusion(tmp_path):
|
||||
"""The authoritative gate must exist and identify CT 111 by guest/host."""
|
||||
plan = _plan([{"id": 111, "usage_pct": 95}], tmp_path)
|
||||
reason = _actions_for(plan, 111)[0]["reason"]
|
||||
assert reason, "the exclusion must carry a reason for the alert"
|
||||
contract = (ROOT / "disk-gc-threat-response.prose.md").read_text()
|
||||
assert "report_only_guests:" in contract
|
||||
assert "192.168.68.129" in contract
|
||||
assert "tdunna" in contract
|
||||
def _plan_with_contract(scan, contract_text, tmp_path, name):
|
||||
contract = tmp_path / name
|
||||
contract.write_text(contract_text)
|
||||
scan_file = tmp_path / f"scan-{name}.json"
|
||||
scan_file.write_text(json.dumps(scan))
|
||||
proc = subprocess.run(
|
||||
[sys.executable, str(PLAN), "--scan", str(scan_file),
|
||||
"--contract", str(contract), "--json"],
|
||||
capture_output=True, text=True,
|
||||
)
|
||||
assert proc.returncode == 0, proc.stderr
|
||||
return json.loads(proc.stdout)
|
||||
|
||||
|
||||
def test_gate_is_read_from_the_contract_block(tmp_path):
|
||||
"""The gate is data-driven by the contract block: the planner excludes the guest
|
||||
when the block names it and acts on it when the block does not. Executes the real
|
||||
planner interface against both fixtures so the behaviour change is observable."""
|
||||
scan = [{"id": 111, "hostname": "tdunna", "ip": "192.168.68.129", "usage_pct": 95}]
|
||||
with_gate = (
|
||||
"```yaml\n"
|
||||
"report_only_guests:\n"
|
||||
" - guest: 111\n"
|
||||
" hostname: tdunna\n"
|
||||
" ip: 192.168.68.129\n"
|
||||
" reason: \"fixture reason\"\n"
|
||||
"```\n"
|
||||
)
|
||||
without_gate = "```yaml\nreport_only_guests: []\n```\n"
|
||||
|
||||
gated = _plan_with_contract(scan, with_gate, tmp_path, "gated.prose.md")
|
||||
assert gated[0]["action"] == "report-only", gated
|
||||
assert gated[0]["reason"] == "fixture reason", gated
|
||||
|
||||
ungated = _plan_with_contract(scan, without_gate, tmp_path, "ungated.prose.md")
|
||||
assert ungated[0]["action"] == "gc-executor", ungated
|
||||
assert ungated[0]["action"] != gated[0]["action"]
|
||||
|
||||
Reference in New Issue
Block a user