fleetd #519: test policy probe guards #523

Merged
ltms merged 3 commits from worker/519-probe-test-harness-d25ab8-4 into main 2026-09-12 06:59:02 +02:00
Member

Adds scripts/test-probe-member-credentials.sh and a source guard with a pure policy parser. Empty parser output now reports 0 fields.

Checks run:

  • bash scripts/test-probe-member-credentials.sh: PASS. It defines 5 test functions and invokes 5.
  • /bin/bash -n scripts/probe-member-credentials.sh: passed (3.2.57).
  • env bash -n scripts/probe-member-credentials.sh: passed (5.3.9).
  • mvn clean install in fleetd: BUILD SUCCESS; Tests run: 1696, Failures: 0, Errors: 0, Skipped: 0.

Mutation proof: each mutation was present while original text was absent. Then the suite failed, and restoration matched the edited-script SHA-256.

  • bash gate < 3: FAIL: bash 3 refusal status: expected 3, got 1; exit 1.
  • parser return 9: FAIL: parser failure status: expected 4, got 9; exit 1.
  • field minimum 4: FAIL: short parser output status: expected 5, got 0; exit 1.
  • empty fields as one empty value: FAIL: empty parser output count: missing jq) returned 0 field(s); exit 1.
  • empty name table: FAIL: well-formed policy status: expected 0, got 1; exit 1.
    All restores matched SHA-256 0e243e0351c7ee7f60d1cc0d8d8a28dfba26bb511d80f7958b58914664ce6cb1 before the final indentation-only edit. The final script SHA-256 is 099b2ecfe78f736ca2f5ba3f62a2a700973822445846e8716fbb90fb959a57d8. git show HEAD:scripts/probe-member-credentials.sh | shasum -a 256 matched the required pristine SHA-256 408b68fdcd81e2109af8712d689d00fa8a260311094ec7a2233dd1b493b9c8b7.

Caveat: the new harness does not cover the non-member, missing-parser, curl-fetch, known-count, or hash-tool fallback paths; those still need hand-run checks.

Adds scripts/test-probe-member-credentials.sh and a source guard with a pure policy parser. Empty parser output now reports 0 fields. Checks run: - bash scripts/test-probe-member-credentials.sh: PASS. It defines 5 test functions and invokes 5. - /bin/bash -n scripts/probe-member-credentials.sh: passed (3.2.57). - env bash -n scripts/probe-member-credentials.sh: passed (5.3.9). - mvn clean install in fleetd: BUILD SUCCESS; Tests run: 1696, Failures: 0, Errors: 0, Skipped: 0. Mutation proof: each mutation was present while original text was absent. Then the suite failed, and restoration matched the edited-script SHA-256. - bash gate < 3: FAIL: bash 3 refusal status: expected 3, got 1; exit 1. - parser return 9: FAIL: parser failure status: expected 4, got 9; exit 1. - field minimum 4: FAIL: short parser output status: expected 5, got 0; exit 1. - empty fields as one empty value: FAIL: empty parser output count: missing jq) returned 0 field(s); exit 1. - empty name table: FAIL: well-formed policy status: expected 0, got 1; exit 1. All restores matched SHA-256 0e243e0351c7ee7f60d1cc0d8d8a28dfba26bb511d80f7958b58914664ce6cb1 before the final indentation-only edit. The final script SHA-256 is 099b2ecfe78f736ca2f5ba3f62a2a700973822445846e8716fbb90fb959a57d8. git show HEAD:scripts/probe-member-credentials.sh | shasum -a 256 matched the required pristine SHA-256 408b68fdcd81e2109af8712d689d00fa8a260311094ec7a2233dd1b493b9c8b7. Caveat: the new harness does not cover the non-member, missing-parser, curl-fetch, known-count, or hash-tool fallback paths; those still need hand-run checks.
agent added 1 commit 2026-09-12 06:31:39 +02:00
fleetd #519: test policy probe guards
CI / contract (pull_request) Successful in 1m24s
CI / build (pull_request) Successful in 1m51s
a5ad7c6561
agent added 1 commit 2026-09-12 06:47:37 +02:00
fleetd #519 review fix: move the parser comments with the code they explain
CI / contract (pull_request) Successful in 50s
CI / build (pull_request) Successful in 2m2s
5b1e13ca3d
PR #523 extracted parse_policy_fields() but left about 25 lines of
explanatory comments at the old parse site in main(). That is the same
defect class as fleetd #500 itself — a stated fact that no longer
matches the code next to it — in the very file whose ticket history is
about it.

Three blocks moved, no code touched:

* "One parse pass" + the mapfile/process-substitution reasoning now sits
  above parse_policy_fields(), which is what it describes.
* The arity-check block now sits inside the function, directly above
  `if (( ${#_FIELDS[@]} < 5 ))`. At the old site it said "the slice just
  below this" and "every line below this expects", both pointing at a
  function call rather than the check. Reworded to name main() and its
  slice explicitly.
* The pipefail note said the parser failure was "handled below"; the
  handling is now above it, in the function.

The call site keeps a three-line pointer saying where the reasoning went.

Checked myself, on this revision:

* suite exit 0, "PASS: probe member credentials guards"
* bash -n rc=0 under /bin/bash 3.2.57 and bash 5.3.9
* two mutations killed, each proven applied two ways (mutant present AND
  original gone), restored byte-identical, green control after each:
  - dropping the empty-parse special case -> FAIL: empty parser output
    count
  - arity threshold 5 -> 0 -> FAIL: short parser output status
agent added 1 commit 2026-09-12 06:50:15 +02:00
fleetd #519 review fix: widen two needles to the whole parenthetical
CI / contract (pull_request) Successful in 51s
CI / build (pull_request) Successful in 2m5s
b5843ab43f
Both arity assertions matched on `jq) returned N field(s)` — a needle
that starts in the middle of the script's `(parser name)` parenthetical.
On a real failure the harness prints `missing <needle>`, so the line
came out as:

  FAIL: empty parser output count: missing jq) returned 0 field(s)

which reads as if the script's own message had an unbalanced paren. It
does not; the needle was just sliced. Matching on
`policy parser (jq) returned N field(s)` makes the failure readable and
also pins that the refusal names the parser it used, which the narrower
needle did not.

make_jq() PATH-prefixes a fake jq, so `_PARSER_NAME` is deterministically
"jq" in both tests; the wider needle cannot flake on a host without jq.

Re-proved on this revision, because a disproof is about a revision and
not a file:

* suite exit 0, "PASS: probe member credentials guards"
* bash -n rc=0 on the test under /bin/bash 3.2.57 and bash 5.3.9
* dropping the empty-parse special case -> FAIL: empty parser output
  count: missing policy parser (jq) returned 0 field(s)
* arity threshold 5 -> 0 -> FAIL: short parser output status
* script restored byte-identical after each, green control after both
ltms merged commit 01adc841fa into main 2026-09-12 06:59:02 +02:00
Sign in to join this conversation.