no-mistakes(review): Harden GC gate key aliases, fail closed, fix baseline

This commit is contained in:
root
2026-09-12 18:42:36 +00:00
parent 4ea2d0309f
commit de1428b4ae
3 changed files with 31 additions and 8 deletions
+11 -1
View File
@@ -51,8 +51,10 @@ def test_excluded_guest_never_gets_gc_at_any_level(tmp_path):
def test_exclusion_matches_on_any_identity_key(tmp_path):
"""The gate is keyed on guest/host, so id, hostname or IP all match."""
"""The gate is keyed on guest/host, so id, ct, ctid, hostname or IP all match."""
for entry in ({"id": 111, "usage_pct": 95},
{"ct": 111, "usage_pct": 95},
{"ctid": 111, "usage_pct": 95},
{"hostname": "tdunna", "usage_pct": 95},
{"ip": "192.168.68.129", "usage_pct": 95}):
plan = _plan([entry], tmp_path)
@@ -78,6 +80,14 @@ def test_agent_name_alone_does_not_gate_a_guest(tmp_path):
assert plan and plan[0]["action"] == "gc-executor"
def test_unidentified_threat_fails_closed(tmp_path):
"""A threshold-crossing entry with no recognized identity must not schedule GC."""
plan = _plan([{"usage_pct": 97}], tmp_path)
assert plan, "an unidentified threat must still be reported"
assert plan[0]["action"] == "report-only", plan
assert plan[0]["reason"], plan
def _plan_with_contract(scan, contract_text, tmp_path, name):
contract = tmp_path / name
contract.write_text(contract_text)