b5843ab43f
Both arity assertions matched on `jq) returned N field(s)` — a needle that starts in the middle of the script's `(parser name)` parenthetical. On a real failure the harness prints `missing <needle>`, so the line came out as: FAIL: empty parser output count: missing jq) returned 0 field(s) which reads as if the script's own message had an unbalanced paren. It does not; the needle was just sliced. Matching on `policy parser (jq) returned N field(s)` makes the failure readable and also pins that the refusal names the parser it used, which the narrower needle did not. make_jq() PATH-prefixes a fake jq, so `_PARSER_NAME` is deterministically "jq" in both tests; the wider needle cannot flake on a host without jq. Re-proved on this revision, because a disproof is about a revision and not a file: * suite exit 0, "PASS: probe member credentials guards" * bash -n rc=0 on the test under /bin/bash 3.2.57 and bash 5.3.9 * dropping the empty-parse special case -> FAIL: empty parser output count: missing policy parser (jq) returned 0 field(s) * arity threshold 5 -> 0 -> FAIL: short parser output status * script restored byte-identical after each, green control after both
110 lines
3.3 KiB
Bash
Executable File
110 lines
3.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Self-contained checks for the policy parsing guards in probe-member-credentials.sh.
|
|
|
|
set -euo pipefail
|
|
|
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
PROBE="$ROOT/scripts/probe-member-credentials.sh"
|
|
TMP="$(mktemp -d "$ROOT/.probe-member-credentials-test.XXXXXX")"
|
|
trap 'rm -rf "$TMP"' EXIT
|
|
|
|
# The SOURCED guard exposes this pure parser without contacting POLICY_URL.
|
|
source "$PROBE"
|
|
|
|
fail() {
|
|
printf 'FAIL: %s\n' "$*" >&2
|
|
return 1
|
|
}
|
|
|
|
assert_equals() {
|
|
local expected="$1" actual="$2" description="$3"
|
|
[ "$expected" = "$actual" ] || fail "$description: expected $expected, got $actual"
|
|
}
|
|
|
|
assert_contains() {
|
|
local needle="$1" text="$2" description="$3"
|
|
printf '%s' "$text" | grep -qF "$needle" || fail "$description: missing $needle"
|
|
}
|
|
|
|
make_jq() {
|
|
local body="$1"
|
|
mkdir -p "$TMP/bin"
|
|
printf '%s\n' '#!/usr/bin/env bash' "$body" > "$TMP/bin/jq"
|
|
chmod +x "$TMP/bin/jq"
|
|
}
|
|
|
|
run_parser() {
|
|
local output rc=0
|
|
POLICY_JSON="$(< "$TMP/policy.json")"
|
|
POLICY_URL="fixture://member-credentials"
|
|
output="$(PATH="$TMP/bin:$PATH" parse_policy_fields 2>&1)" || rc=$?
|
|
PARSER_OUTPUT="$output"
|
|
PARSER_RC="$rc"
|
|
}
|
|
|
|
test_bash_older_than_four_refuses() {
|
|
local output rc=0 version
|
|
version="$(/bin/bash -c 'printf %s "$BASH_VERSION"')"
|
|
output="$(/bin/bash "$PROBE" 2>&1)" || rc=$?
|
|
assert_equals 3 "$rc" "bash 3 refusal status"
|
|
assert_contains 'This shell is bash' "$output" "bash 3 refusal"
|
|
assert_contains "$version" "$output" "bash 3 refusal version"
|
|
}
|
|
|
|
test_parser_non_zero_refuses() {
|
|
make_jq 'exit 17'
|
|
run_parser
|
|
assert_equals 4 "$PARSER_RC" "parser failure status"
|
|
assert_contains 'jq exited non-zero (status 17)' "$PARSER_OUTPUT" "parser failure message"
|
|
}
|
|
|
|
test_short_parser_output_refuses() {
|
|
make_jq "printf '%s\\n' true enforce 3 2"
|
|
run_parser
|
|
assert_equals 5 "$PARSER_RC" "short parser output status"
|
|
assert_contains 'policy parser (jq) returned 4 field(s)' "$PARSER_OUTPUT" "short parser output count"
|
|
}
|
|
|
|
test_empty_parser_output_reports_zero_fields() {
|
|
make_jq ':'
|
|
run_parser
|
|
assert_equals 5 "$PARSER_RC" "empty parser output status"
|
|
assert_contains 'policy parser (jq) returned 0 field(s)' "$PARSER_OUTPUT" "empty parser output count"
|
|
}
|
|
|
|
test_well_formed_policy_prints_name_table() {
|
|
local output rc=0
|
|
make_jq "cat '$TMP/policy.fields'"
|
|
# Shell functions cannot be passed in an environment assignment. Run the executable through bash.
|
|
output="$(BRIDGED_MEMBER=1 FIXTURE="$TMP/policy.json" PROBE="$PROBE" PATH="$TMP/bin:$PATH" bash -c '
|
|
curl() { cat "$FIXTURE"; }
|
|
export -f curl
|
|
exec "$PROBE"
|
|
' 2>&1)" || rc=$?
|
|
assert_equals 0 "$rc" "well-formed policy status"
|
|
assert_contains 'ALPHA_TOKEN' "$output" "name table"
|
|
assert_contains 'BETA_TOKEN' "$output" "name table"
|
|
assert_contains 'GAMMA_TOKEN' "$output" "name table"
|
|
}
|
|
|
|
cat > "$TMP/policy.json" <<'JSON'
|
|
{"present":true,"policy":"enforce","knownCount":3,"allowedCount":2,"blockedCount":1,"known":["ALPHA_TOKEN","BETA_TOKEN","GAMMA_TOKEN"]}
|
|
JSON
|
|
cat > "$TMP/policy.fields" <<'FIELDS'
|
|
true
|
|
enforce
|
|
3
|
|
2
|
|
1
|
|
ALPHA_TOKEN
|
|
BETA_TOKEN
|
|
GAMMA_TOKEN
|
|
FIELDS
|
|
|
|
test_bash_older_than_four_refuses
|
|
test_parser_non_zero_refuses
|
|
test_short_parser_output_refuses
|
|
test_empty_parser_output_reports_zero_fields
|
|
test_well_formed_policy_prints_name_table
|
|
printf 'PASS: probe member credentials guards\n'
|