fix: complete evidence documentation contract
This commit is contained in:
@@ -486,21 +486,40 @@ elif mutation == "wrong-docs-directory":
|
||||
"workspaces/<id>.env.example\nworkspaces/<id>.md",
|
||||
1,
|
||||
)
|
||||
elif mutation == "public-http-mode-omitted":
|
||||
changed = original.replace(
|
||||
"Public HTTP (`authentication: none`) uses the declared query-free\nURIs directly and requires no Evidence credential file.",
|
||||
"",
|
||||
1,
|
||||
)
|
||||
elif mutation == "ambient-s3-mode-omitted":
|
||||
changed = original.replace(
|
||||
"Ambient S3\n(`credentials: ambient`) uses the runtime provider chain and requires no Evidence credential file.",
|
||||
"",
|
||||
1,
|
||||
)
|
||||
elif mutation == "numeric-domains-omitted":
|
||||
changed = original.replace("positive safe integers", "positive integers", 1)
|
||||
changed = changed.replace("nonnegative safe integer", "nonnegative integer", 1)
|
||||
elif mutation == "endpoint-without-url-invariant-omitted":
|
||||
changed = original.replace(
|
||||
"Endpoint-policy flags cannot be enabled without `endpoint_url`.", "", 1
|
||||
)
|
||||
elif mutation == "http-file-boundary-omitted":
|
||||
changed = original.replace(
|
||||
"| Signed HTTP | `THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE` | Required for `signed_urls_file`; nonempty JSON string array in declared-URI order; query-stripped identities must match `uris`. |\n",
|
||||
"| Signed HTTP | `THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE` | Required for `signed_urls_file`; at most 1048576 bytes; nonempty UTF-8 JSON string array in declared-URI order; query-stripped identities must match `uris` one-to-one. |\n",
|
||||
"",
|
||||
1,
|
||||
)
|
||||
elif mutation == "s3-pair-boundary-omitted":
|
||||
changed = original.replace(
|
||||
"| Static S3 pair | `THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE` and `THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE` | Required together for `static_files`. |\n",
|
||||
"| Static S3 pair | `THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE` and `THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE` | Required together for `static_files`; each file is at most 65536 bytes. |\n",
|
||||
"",
|
||||
1,
|
||||
)
|
||||
elif mutation == "s3-token-boundary-omitted":
|
||||
changed = original.replace(
|
||||
"| Static S3 session | `THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE` | Optional, and valid only with the required access/secret pair. |\n",
|
||||
"| Static S3 session | `THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE` | Optional, valid only with the required access/secret pair, and at most 65536 bytes. |\n",
|
||||
"",
|
||||
1,
|
||||
)
|
||||
@@ -920,6 +939,18 @@ expect_evidence_fixture_rejected \
|
||||
expect_evidence_fixture_rejected \
|
||||
"generated docs in wrong directory" docs/contracts/workspace-evidence-v3.md wrong-docs-directory \
|
||||
"generated docs path invalid"
|
||||
expect_evidence_fixture_rejected \
|
||||
"public HTTP mode omitted" docs/contracts/workspace-evidence-v3.md public-http-mode-omitted \
|
||||
"missing public HTTP mode"
|
||||
expect_evidence_fixture_rejected \
|
||||
"ambient S3 mode omitted" docs/contracts/workspace-evidence-v3.md ambient-s3-mode-omitted \
|
||||
"missing ambient S3 mode"
|
||||
expect_evidence_fixture_rejected \
|
||||
"strict Evidence numeric domains omitted" docs/contracts/workspace-evidence-v3.md numeric-domains-omitted \
|
||||
"missing strict Evidence numeric domains"
|
||||
expect_evidence_fixture_rejected \
|
||||
"S3 endpoint policy without endpoint invariant omitted" docs/contracts/workspace-evidence-v3.md endpoint-without-url-invariant-omitted \
|
||||
"missing S3 endpoint policy without endpoint invariant"
|
||||
expect_evidence_fixture_rejected \
|
||||
"signed HTTP file boundary omitted" docs/contracts/workspace-evidence-v3.md http-file-boundary-omitted \
|
||||
"missing signed HTTP file boundary"
|
||||
|
||||
@@ -348,6 +348,18 @@ for phrase in required_contract_phrases:
|
||||
if phrase not in contract:
|
||||
raise SystemExit(f"workspace Evidence contract lacks required rule: {phrase}")
|
||||
|
||||
mode_rules = {
|
||||
"missing public HTTP mode": "Public HTTP (`authentication: none`) uses the declared query-free\nURIs directly and requires no Evidence credential file.",
|
||||
"missing ambient S3 mode": "Ambient S3\n(`credentials: ambient`) uses the runtime provider chain and requires no Evidence credential file.",
|
||||
}
|
||||
for error, phrase in mode_rules.items():
|
||||
if phrase not in contract:
|
||||
raise SystemExit(error)
|
||||
if "positive safe integers" not in contract or "nonnegative safe integer" not in contract or "9007199254740991" not in contract:
|
||||
raise SystemExit("missing strict Evidence numeric domains")
|
||||
if "Endpoint-policy flags cannot be enabled without `endpoint_url`." not in contract:
|
||||
raise SystemExit("missing S3 endpoint policy without endpoint invariant")
|
||||
|
||||
# The canonical one-repository tree is exact, including generated docs outside workspaces/.
|
||||
legacy_docs = re.compile(r"workspaces/(?:<[^>]+>|[^\s`/]+)\.(?:env\.example|md)")
|
||||
all_public = "\n".join(path.read_text() for path in paths)
|
||||
@@ -396,17 +408,22 @@ if no_scope not in contract or re.search(r"P1\s+(?:materializes|extracts|indexes
|
||||
installation_rows = {row[0]: row[1:] for row in table_for("Installation files")}
|
||||
http_row = " ".join(installation_rows.get("Signed HTTP", []))
|
||||
if "THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE" not in http_row or not all(
|
||||
token in http_row for token in ("nonempty JSON string array", "declared-URI order", "query-stripped identities")
|
||||
token in http_row for token in (
|
||||
"1048576 bytes", "nonempty UTF-8 JSON string array", "declared-URI order",
|
||||
"query-stripped identities", "one-to-one",
|
||||
)
|
||||
):
|
||||
raise SystemExit("missing signed HTTP file boundary")
|
||||
s3_pair = " ".join(installation_rows.get("Static S3 pair", []))
|
||||
if not all(token in s3_pair for token in (
|
||||
"THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE",
|
||||
"THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE", "Required together",
|
||||
"THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE", "Required together", "65536 bytes",
|
||||
)):
|
||||
raise SystemExit("missing static S3 file boundary")
|
||||
s3_token = " ".join(installation_rows.get("Static S3 session", []))
|
||||
if "THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE" not in s3_token or "Optional" not in s3_token:
|
||||
if not all(token in s3_token for token in (
|
||||
"THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE", "Optional", "65536 bytes",
|
||||
)):
|
||||
raise SystemExit("missing static S3 session-token boundary")
|
||||
|
||||
if "tht config check -c <path>" not in contract:
|
||||
|
||||
Reference in New Issue
Block a user