Bind qualification to the complete current filesystem source

Exact-source validation found two unbound compiled packages after composing the retained notes repair with current main. Include both in the source manifest and report the whole dependency closure without weakening the check.

Change-source: pulse-maintainer
This commit is contained in:
pulse-triage[bot] 2026-10-01 07:33:49 +01:00
parent d012113e92
commit 0aaf639b5a
4 changed files with 24 additions and 4 deletions

View file

@ -1024,6 +1024,9 @@ Companion drill:
`go test ./scripts/installtests -run 'TestStablePatchReleaseNotes' -count=1`
`cd scripts/release_control && python3 -m unittest render_release_body_test`
`cd scripts/release_control && python3 -m unittest secure_runtime_rootful_attestation_v1_test release_note_visuals_test documentation_currentness_test`
- The rootful source-closure test must cover the current filesystem probe and
shared filesystem evidence packages as well as the compiled harness. Its
complete missing-package list is a failed boundary check, not qualification.
`cd scripts/release_control && python3 -m unittest resolve_release_promotion_test release_promotion_policy_test`
`go test ./scripts/installtests -run 'Test(Demo|DeployDemo|UpdateDemo|Release)' -count=1`
- Manual scenario:

View file

@ -6136,3 +6136,13 @@ rewriting the author's instructions or selecting another rollback version.
distant-scope rejection, and valid generated and inline ownership conditions.
This changes publication validation, not installer behaviour, immutable release
contents or proof of an installed upgrade/rollback.
## Rootful qualification source closure (1 October 2026)
The rootful source manifest includes `internal/filesystemprobe` and
`pkg/agents/filesystem`: both are compiled dependencies of the current collector
and qualification harness. Omitting them would leave the attested packet
unbound to filesystem-observation code that it actually executes. The closure
test enumerates all repository-local dependencies of the install-test binary,
collector and helper and reports every missing package together. No qualification
gate, source exclusion or production permission is relaxed by this correction.

View file

@ -508,6 +508,7 @@ if module.MAX_RECEIPT_BYTES <= 0:
}
self.assertTrue(compiled_test_inputs.issubset(manifest["exact_paths"]))
recursive_roots = set(manifest["recursive_roots"])
unbound_dependencies = set()
for target, include_tests in (
("./scripts/installtests", True),
("./cmd/pulse-agent", False),
@ -529,12 +530,16 @@ if module.MAX_RECEIPT_BYTES <= 0:
if not raw_directory or directory == repo_root / "scripts" / "installtests":
continue
relative = directory.relative_to(repo_root).as_posix()
self.assertTrue(
any(relative == root or relative.startswith(root + "/") for root in recursive_roots),
f"compiled dependency for {target} is outside the source manifest: {relative}",
)
if not any(relative == root or relative.startswith(root + "/") for root in recursive_roots):
unbound_dependencies.add(f"{target}: {relative}")
self.assertFalse(
unbound_dependencies,
"compiled dependencies outside the source manifest: " + ", ".join(sorted(unbound_dependencies)),
)
self.assertIn("internal/agenthelper", manifest["recursive_roots"])
self.assertIn("pkg/auth", manifest["recursive_roots"])
self.assertIn("internal/filesystemprobe", manifest["recursive_roots"])
self.assertIn("pkg/agents/filesystem", manifest["recursive_roots"])
if __name__ == "__main__":

View file

@ -63,6 +63,7 @@
"internal/config",
"internal/crypto",
"internal/dockeragent",
"internal/filesystemprobe",
"internal/hostagent",
"internal/hostmetrics",
"internal/kubernetesagent",
@ -92,6 +93,7 @@
"internal/vmware",
"pkg/auth",
"pkg/agents/docker",
"pkg/agents/filesystem",
"pkg/agents/host",
"pkg/agents/kubernetes",
"pkg/aicontracts",