ci(coverage): enforce the critical core contract
This commit is contained in:
+8
-8
@@ -20,10 +20,10 @@ cd "$(dirname "$0")/.."
|
||||
|
||||
PY="${PYTHON:-python3}"
|
||||
|
||||
# Critical security/logic core held to the high bar by ADR 0004. The list
|
||||
# lives in one place (scripts/critical-modules.txt) so this report and the
|
||||
# README "core coverage" badge can't drift; comma-join it for --include.
|
||||
CRITICAL=$(grep -vE '^[[:space:]]*(#|$)' scripts/critical-modules.txt | paste -sd, -)
|
||||
# Critical security/logic core held to the high bar by ADR 0004. The helper
|
||||
# fails before coverage when a curated path was renamed or removed; Coverage.py
|
||||
# itself would silently ignore that stale include and inflate the score.
|
||||
CRITICAL=$("$PY" scripts/critical_modules.py)
|
||||
|
||||
if [ "${1:-}" = "aggregate" ]; then
|
||||
# Aggregate mode: combine .coverage.* artifacts already in the workspace.
|
||||
@@ -34,8 +34,8 @@ if [ "${1:-}" = "aggregate" ]; then
|
||||
"$PY" -m coverage report -m
|
||||
|
||||
if [ "${2:-}" = "critical" ]; then
|
||||
echo "== critical modules (ADR 0004 target: 90%) ==" >&2
|
||||
"$PY" -m coverage report --include="$CRITICAL"
|
||||
echo "== critical modules (ADR 0004 minimum: 90%) ==" >&2
|
||||
"$PY" -m coverage report --include="$CRITICAL" --fail-under=90
|
||||
fi
|
||||
exit 0
|
||||
fi
|
||||
@@ -55,6 +55,6 @@ echo "== combined report ==" >&2
|
||||
"$PY" -m coverage report -m
|
||||
|
||||
if [ "${1:-}" = "critical" ]; then
|
||||
echo "== critical modules (ADR 0004 target: 90%) ==" >&2
|
||||
"$PY" -m coverage report --include="$CRITICAL"
|
||||
echo "== critical modules (ADR 0004 minimum: 90%) ==" >&2
|
||||
"$PY" -m coverage report --include="$CRITICAL" --fail-under=90
|
||||
fi
|
||||
|
||||
@@ -7,19 +7,48 @@
|
||||
# number that silently stops measuring a module is worse than no badge.
|
||||
#
|
||||
# One module path per line, relative to the repo root. Blank lines and
|
||||
# `#` comments are ignored.
|
||||
# `#` comments are ignored. scripts/critical_modules.py rejects missing,
|
||||
# duplicate, non-Python, and out-of-repository entries before coverage runs.
|
||||
|
||||
# Host-side egress planning and secret preparation.
|
||||
bot_bottle/egress/plan.py
|
||||
bot_bottle/egress/service.py
|
||||
|
||||
# Gateway egress policy, matching, and DLP enforcement.
|
||||
bot_bottle/gateway/egress/addon.py
|
||||
bot_bottle/gateway/egress/addon_core.py
|
||||
bot_bottle/gateway/egress/context.py
|
||||
bot_bottle/gateway/egress/dlp.py
|
||||
bot_bottle/gateway/egress/dlp_config.py
|
||||
bot_bottle/gateway/egress/dlp_detectors.py
|
||||
bot_bottle/egress.py
|
||||
bot_bottle/manifest.py
|
||||
bot_bottle/manifest_egress.py
|
||||
bot_bottle/manifest_agent.py
|
||||
bot_bottle/manifest_schema.py
|
||||
bot_bottle/git_gate.py
|
||||
bot_bottle/gateway/egress/matching.py
|
||||
bot_bottle/gateway/egress/schema.py
|
||||
bot_bottle/gateway/egress/types.py
|
||||
|
||||
# Manifest trust boundary and schema.
|
||||
bot_bottle/manifest/agent.py
|
||||
bot_bottle/manifest/bottle.py
|
||||
bot_bottle/manifest/egress.py
|
||||
bot_bottle/manifest/extends.py
|
||||
bot_bottle/manifest/git.py
|
||||
bot_bottle/manifest/index.py
|
||||
bot_bottle/manifest/loader.py
|
||||
bot_bottle/manifest/schema.py
|
||||
bot_bottle/manifest/util.py
|
||||
|
||||
# Host-side and gateway-side git policy enforcement.
|
||||
bot_bottle/git_gate/host_key.py
|
||||
bot_bottle/git_gate/plan.py
|
||||
bot_bottle/git_gate/provision.py
|
||||
bot_bottle/git_gate/service.py
|
||||
bot_bottle/gateway/git_gate/render.py
|
||||
bot_bottle/git_gate_provision.py
|
||||
bot_bottle/gateway/git_gate/http_backend.py
|
||||
bot_bottle/supervise.py
|
||||
|
||||
# Supervise proposal protocol and data plane.
|
||||
bot_bottle/supervisor/plan.py
|
||||
bot_bottle/supervisor/types.py
|
||||
bot_bottle/gateway/supervisor/server.py
|
||||
|
||||
# Shared parsers and state validation.
|
||||
bot_bottle/yaml_subset.py
|
||||
bot_bottle/bottle_state.py
|
||||
|
||||
@@ -0,0 +1,101 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Validate and render the critical-module coverage manifest.
|
||||
|
||||
Coverage.py silently ignores an ``--include`` path that does not exist. That
|
||||
is useful for broad globs, but dangerous for bot-bottle's curated security
|
||||
core: a rename could otherwise improve the reported percentage by removing a
|
||||
module from the measurement. Keep the validation in one small stdlib helper
|
||||
and make every coverage consumer call it.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
REPO_ROOT = Path(__file__).resolve().parents[1]
|
||||
DEFAULT_MANIFEST = REPO_ROOT / "scripts" / "critical-modules.txt"
|
||||
|
||||
|
||||
class CriticalModulesError(ValueError):
|
||||
"""The critical-module manifest is empty, ambiguous, or stale."""
|
||||
|
||||
|
||||
def load_critical_modules(manifest: Path, *, root: Path) -> list[str]:
|
||||
"""Return validated module paths relative to *root*.
|
||||
|
||||
Entries must be unique, concrete Python files inside the repository.
|
||||
Globs are deliberately rejected by the file check: each rename must update
|
||||
this explicit security review surface.
|
||||
"""
|
||||
|
||||
root = root.resolve()
|
||||
try:
|
||||
lines = manifest.read_text(encoding="utf-8").splitlines()
|
||||
except OSError as exc:
|
||||
raise CriticalModulesError(
|
||||
f"cannot read critical-module manifest {manifest}: {exc}"
|
||||
) from exc
|
||||
|
||||
modules: list[str] = []
|
||||
seen: set[str] = set()
|
||||
errors: list[str] = []
|
||||
for line_number, raw in enumerate(lines, start=1):
|
||||
entry = raw.strip()
|
||||
if not entry or entry.startswith("#"):
|
||||
continue
|
||||
path = Path(entry)
|
||||
prefix = f"{manifest}:{line_number}: {entry!r}"
|
||||
if path.is_absolute():
|
||||
errors.append(f"{prefix} must be relative to the repository root")
|
||||
continue
|
||||
try:
|
||||
resolved = (root / path).resolve()
|
||||
resolved.relative_to(root)
|
||||
except ValueError:
|
||||
errors.append(f"{prefix} escapes the repository root")
|
||||
continue
|
||||
if entry in seen:
|
||||
errors.append(f"{prefix} is duplicated")
|
||||
continue
|
||||
seen.add(entry)
|
||||
if path.suffix != ".py":
|
||||
errors.append(f"{prefix} is not a Python module")
|
||||
continue
|
||||
if not resolved.is_file():
|
||||
errors.append(f"{prefix} does not exist")
|
||||
continue
|
||||
modules.append(path.as_posix())
|
||||
|
||||
if not modules and not errors:
|
||||
errors.append(f"{manifest}: contains no critical modules")
|
||||
if errors:
|
||||
raise CriticalModulesError("\n".join(errors))
|
||||
return modules
|
||||
|
||||
|
||||
def main(argv: list[str] | None = None) -> int:
|
||||
parser = argparse.ArgumentParser(
|
||||
description="validate and print the critical coverage include list"
|
||||
)
|
||||
parser.add_argument("--manifest", type=Path, default=DEFAULT_MANIFEST)
|
||||
parser.add_argument("--root", type=Path, default=REPO_ROOT)
|
||||
parser.add_argument(
|
||||
"--check", action="store_true",
|
||||
help="validate only; do not print the comma-separated include list",
|
||||
)
|
||||
args = parser.parse_args(argv)
|
||||
try:
|
||||
modules = load_critical_modules(args.manifest, root=args.root)
|
||||
except CriticalModulesError as exc:
|
||||
print(f"critical-modules: {exc}", file=sys.stderr)
|
||||
return 1
|
||||
if not args.check:
|
||||
print(",".join(modules))
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Reference in New Issue
Block a user