mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 04:38:48 +00:00
Bind qualification to the complete current filesystem source
Exact-source validation found two unbound compiled packages after composing the retained notes repair with current main. Include both in the source manifest and report the whole dependency closure without weakening the check. Change-source: pulse-maintainer
This commit is contained in:
parent
d012113e92
commit
0aaf639b5a
4 changed files with 24 additions and 4 deletions
|
|
@ -1024,6 +1024,9 @@ Companion drill:
|
|||
`go test ./scripts/installtests -run 'TestStablePatchReleaseNotes' -count=1`
|
||||
`cd scripts/release_control && python3 -m unittest render_release_body_test`
|
||||
`cd scripts/release_control && python3 -m unittest secure_runtime_rootful_attestation_v1_test release_note_visuals_test documentation_currentness_test`
|
||||
- The rootful source-closure test must cover the current filesystem probe and
|
||||
shared filesystem evidence packages as well as the compiled harness. Its
|
||||
complete missing-package list is a failed boundary check, not qualification.
|
||||
`cd scripts/release_control && python3 -m unittest resolve_release_promotion_test release_promotion_policy_test`
|
||||
`go test ./scripts/installtests -run 'Test(Demo|DeployDemo|UpdateDemo|Release)' -count=1`
|
||||
- Manual scenario:
|
||||
|
|
|
|||
|
|
@ -6136,3 +6136,13 @@ rewriting the author's instructions or selecting another rollback version.
|
|||
distant-scope rejection, and valid generated and inline ownership conditions.
|
||||
This changes publication validation, not installer behaviour, immutable release
|
||||
contents or proof of an installed upgrade/rollback.
|
||||
|
||||
## Rootful qualification source closure (1 October 2026)
|
||||
|
||||
The rootful source manifest includes `internal/filesystemprobe` and
|
||||
`pkg/agents/filesystem`: both are compiled dependencies of the current collector
|
||||
and qualification harness. Omitting them would leave the attested packet
|
||||
unbound to filesystem-observation code that it actually executes. The closure
|
||||
test enumerates all repository-local dependencies of the install-test binary,
|
||||
collector and helper and reports every missing package together. No qualification
|
||||
gate, source exclusion or production permission is relaxed by this correction.
|
||||
|
|
|
|||
|
|
@ -508,6 +508,7 @@ if module.MAX_RECEIPT_BYTES <= 0:
|
|||
}
|
||||
self.assertTrue(compiled_test_inputs.issubset(manifest["exact_paths"]))
|
||||
recursive_roots = set(manifest["recursive_roots"])
|
||||
unbound_dependencies = set()
|
||||
for target, include_tests in (
|
||||
("./scripts/installtests", True),
|
||||
("./cmd/pulse-agent", False),
|
||||
|
|
@ -529,12 +530,16 @@ if module.MAX_RECEIPT_BYTES <= 0:
|
|||
if not raw_directory or directory == repo_root / "scripts" / "installtests":
|
||||
continue
|
||||
relative = directory.relative_to(repo_root).as_posix()
|
||||
self.assertTrue(
|
||||
any(relative == root or relative.startswith(root + "/") for root in recursive_roots),
|
||||
f"compiled dependency for {target} is outside the source manifest: {relative}",
|
||||
)
|
||||
if not any(relative == root or relative.startswith(root + "/") for root in recursive_roots):
|
||||
unbound_dependencies.add(f"{target}: {relative}")
|
||||
self.assertFalse(
|
||||
unbound_dependencies,
|
||||
"compiled dependencies outside the source manifest: " + ", ".join(sorted(unbound_dependencies)),
|
||||
)
|
||||
self.assertIn("internal/agenthelper", manifest["recursive_roots"])
|
||||
self.assertIn("pkg/auth", manifest["recursive_roots"])
|
||||
self.assertIn("internal/filesystemprobe", manifest["recursive_roots"])
|
||||
self.assertIn("pkg/agents/filesystem", manifest["recursive_roots"])
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
|
|
|||
|
|
@ -63,6 +63,7 @@
|
|||
"internal/config",
|
||||
"internal/crypto",
|
||||
"internal/dockeragent",
|
||||
"internal/filesystemprobe",
|
||||
"internal/hostagent",
|
||||
"internal/hostmetrics",
|
||||
"internal/kubernetesagent",
|
||||
|
|
@ -92,6 +93,7 @@
|
|||
"internal/vmware",
|
||||
"pkg/auth",
|
||||
"pkg/agents/docker",
|
||||
"pkg/agents/filesystem",
|
||||
"pkg/agents/host",
|
||||
"pkg/agents/kubernetes",
|
||||
"pkg/aicontracts",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue