no-mistakes(review): Fail closed on empty report-only exclusion list

This commit is contained in:
root
2026-09-12 18:55:34 +00:00
parent 4bd6132cf5
commit 6272d29978
2 changed files with 28 additions and 1 deletions
+23 -1
View File
@@ -124,6 +124,22 @@ def test_exclusion_entry_without_identity_fails_closed(tmp_path):
assert "identity" in proc.stderr.lower(), proc.stderr
def test_empty_exclusion_block_fails_closed(tmp_path):
"""An emptied report_only_guests list must break the run, not disable the gate."""
contract = tmp_path / "empty.prose.md"
contract.write_text("```yaml\nreport_only_guests: []\n```\n")
scan_file = tmp_path / "scan.json"
scan_file.write_text(json.dumps([{"ct": 111, "usage_pct": 97}]))
proc = subprocess.run(
[sys.executable, str(PLAN), "--scan", str(scan_file),
"--contract", str(contract), "--json"],
capture_output=True, text=True,
)
assert proc.returncode != 0, proc.stdout
assert "gc-executor" not in proc.stdout
assert "report-only gate" in proc.stderr.lower(), proc.stderr
def _plan_with_contract(scan, contract_text, tmp_path, name):
contract = tmp_path / name
contract.write_text(contract_text)
@@ -152,7 +168,13 @@ def test_gate_is_read_from_the_contract_block(tmp_path):
" reason: \"fixture reason\"\n"
"```\n"
)
without_gate = "```yaml\nreport_only_guests: []\n```\n"
without_gate = (
"```yaml\n"
"report_only_guests:\n"
" - guest: 999\n"
" reason: \"fixture excludes a different guest\"\n"
"```\n"
)
gated = _plan_with_contract(scan, with_gate, tmp_path, "gated.prose.md")
assert gated[0]["action"] == "report-only", gated