fix: complete evidence documentation contract

This commit is contained in:
2026-08-09 20:47:30 +02:00
parent d77c08884b
commit d7264b843d
3 changed files with 69 additions and 13 deletions
+20 -3
View File
@@ -348,6 +348,18 @@ for phrase in required_contract_phrases:
if phrase not in contract:
raise SystemExit(f"workspace Evidence contract lacks required rule: {phrase}")
mode_rules = {
"missing public HTTP mode": "Public HTTP (`authentication: none`) uses the declared query-free\nURIs directly and requires no Evidence credential file.",
"missing ambient S3 mode": "Ambient S3\n(`credentials: ambient`) uses the runtime provider chain and requires no Evidence credential file.",
}
for error, phrase in mode_rules.items():
if phrase not in contract:
raise SystemExit(error)
if "positive safe integers" not in contract or "nonnegative safe integer" not in contract or "9007199254740991" not in contract:
raise SystemExit("missing strict Evidence numeric domains")
if "Endpoint-policy flags cannot be enabled without `endpoint_url`." not in contract:
raise SystemExit("missing S3 endpoint policy without endpoint invariant")
# The canonical one-repository tree is exact, including generated docs outside workspaces/.
legacy_docs = re.compile(r"workspaces/(?:<[^>]+>|[^\s`/]+)\.(?:env\.example|md)")
all_public = "\n".join(path.read_text() for path in paths)
@@ -396,17 +408,22 @@ if no_scope not in contract or re.search(r"P1\s+(?:materializes|extracts|indexes
installation_rows = {row[0]: row[1:] for row in table_for("Installation files")}
http_row = " ".join(installation_rows.get("Signed HTTP", []))
if "THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE" not in http_row or not all(
token in http_row for token in ("nonempty JSON string array", "declared-URI order", "query-stripped identities")
token in http_row for token in (
"1048576 bytes", "nonempty UTF-8 JSON string array", "declared-URI order",
"query-stripped identities", "one-to-one",
)
):
raise SystemExit("missing signed HTTP file boundary")
s3_pair = " ".join(installation_rows.get("Static S3 pair", []))
if not all(token in s3_pair for token in (
"THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE",
"THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE", "Required together",
"THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE", "Required together", "65536 bytes",
)):
raise SystemExit("missing static S3 file boundary")
s3_token = " ".join(installation_rows.get("Static S3 session", []))
if "THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE" not in s3_token or "Optional" not in s3_token:
if not all(token in s3_token for token in (
"THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE", "Optional", "65536 bytes",
)):
raise SystemExit("missing static S3 session-token boundary")
if "tht config check -c <path>" not in contract: