"""Pure helper checks: no containers, services, credentials, or PostgreSQL.""" import ast from contextlib import ExitStack import copy import hashlib import importlib.util import io import json import os from pathlib import Path import stat import sys import tempfile from types import SimpleNamespace import unittest from unittest import mock PATH = Path(__file__).with_name('container_e2e.py') SPEC = importlib.util.spec_from_file_location('container_e2e_helpers', PATH) e2e = importlib.util.module_from_spec(SPEC) SPEC.loader.exec_module(e2e) class ContainerE2EHelperTests(unittest.TestCase): def test_environment_is_rebuilt_from_allowlist_before_application_imports(self): def normalized(environment): if os.name == 'nt': return {name.upper(): value for name, value in environment.items()} return dict(environment) poison = { 'DATABASE_URL': 'postgresql://production.invalid/truf', 'PGPASSWORD': 'production-secret', 'MiXeD_Proxy': 'http://proxy.invalid', 'AWS_SECRET_ACCESS_KEY': 'production-secret', } with mock.patch.dict(os.environ, poison, clear=True): e2e.neutralize_environment('prepare') self.assertEqual(normalized(os.environ), normalized(e2e.BASE_ENVIRONMENT)) child = {name: 'fixture-' + str(index) for index, name in enumerate(sorted(e2e.KEYCHECK_CHILD_ENVIRONMENT))} with mock.patch.dict(os.environ, {**poison, **child}, clear=True): e2e.neutralize_environment('_keycheck-child') self.assertEqual({name: os.environ[name] for name in child}, child) actual_names = set(normalized(os.environ)) self.assertFalse((set(normalized(poison)) - set(normalized(child))) & actual_names) self.assertEqual(actual_names, set(normalized(e2e.BASE_ENVIRONMENT)) | set(normalized(child))) def test_canary_matches_existing_known_fake_without_importing_scanner(self): tree = ast.parse(PATH.with_name('test_synthetic_llm_pipeline.py').read_text(encoding='utf-8')) functions = [node for node in tree.body if isinstance(node, ast.FunctionDef) and node.name in ('synthetic_material', 'synthetic_llm_tokens')] namespace = {'hashlib': hashlib} exec(compile(ast.Module(body=functions, type_ignores=[]), '', 'exec'), namespace) expected = namespace['synthetic_llm_tokens']()['openai'] self.assertEqual(e2e.digest(e2e.synthetic_openai_token().encode()), e2e.digest(expected.encode())) def test_fixture_config_preserves_profile_without_activating_other_sources(self): base = { 'global': {'safety_limit': 123, 'result_bundle_max_event_bytes': 201326592}, 'supervisor': { 'defaults': {'enabled': True}, 'sources': { 'github': {}, 'gitlab': {'once': False}, 'dockerhub': {}, 'huggingface': {}, }, 'result_ingester': {'lease_seconds': 300}, 'jsonl_projector': {}, 'janitor': {}, 'docker_shadow': {}, 'dashboard': {}, }, 'sources': { 'github': {'max_depth': 100, 'auth_pool': 'legacy'}, 'gitlab': {'enabled': True, 'auth_pool': 'gitlab'}, 'dockerhub': {'enabled': True, 'auth_pool': 'docker'}, 'huggingface': {'enabled': True, 'auth_pool': 'hf'}, }, 'keychecks': {'enabled': True}, 'query_policy': {'rejected': []}, } original = copy.deepcopy(base) config = e2e.fixture_config(base) self.assertEqual(base, original) self.assertEqual(config['global']['safety_limit'], 123) self.assertEqual(config['global']['result_bundle_max_event_bytes'], 201326592) self.assertEqual(config['supervisor']['result_ingester']['lease_seconds'], 300) self.assertEqual(config['supervisor']['enabled_sources'], list(e2e.CORE_SOURCES)) self.assertEqual( [name for name, value in config['sources'].items() if value['enabled']], list(e2e.CORE_SOURCES), ) source = config['sources']['gitlab'] self.assertEqual(source['target_file'], '/data/runtime-linux/queues/e2e-targets.txt') self.assertEqual(source['queries'], ['e2e']) self.assertEqual(source['mode'], 'custom') self.assertEqual((source['workers'], source['timeout']), (1, 60)) self.assertFalse(source['exact_git_planning_enabled']) self.assertEqual(source['max_commit_age_days'], 0) self.assertEqual(config['global']['opportunistic_scan_slots'], 0) self.assertEqual(config['supervisor']['postgres_stable_ready_sec'], 2) self.assertFalse(config['global']['api_proxy_enabled']) self.assertFalse(config['keychecks']['enabled']) self.assertTrue(config['supervisor']['sources']['gitlab']['once']) self.assertEqual( [config['supervisor']['defaults'][name] for name in ('enabled', 'repeat', 'restart')], [False, False, False], ) self.assertEqual(source['auth_pool'], '') self.assertTrue(all(value.get('auth_pool', '') == '' for value in config['sources'].values())) self.assertFalse(config['keychecks']['autostart']) self.assertFalse(config['supervisor']['dashboard']['enabled']) self.assertTrue(e2e.TARGET.startswith('https://gitlab.com/')) git_env = config['supervisor']['sources']['gitlab']['env'] self.assertEqual(git_env['GIT_CONFIG_COUNT'], '2') self.assertEqual(git_env['GIT_CONFIG_VALUE_0'], e2e.TARGET) self.assertEqual( git_env['GIT_CONFIG_KEY_0'], 'url.' + e2e.FIXTURE_REPOSITORY + '.insteadOf', ) self.assertEqual(git_env['GIT_CONFIG_VALUE_1'], e2e.REMOTE_TARGET) def projection_fixture(self): payload = b'{"fixture":1}\n' job = {'id': 3, 'event_id': 'a' * 32, 'event_hash': 'b' * 64} append = { 'id': 4, 'job_id': 3, 'stream_name': 'found_secrets', 'state': 'appended', 'event_id': job['event_id'], 'event_hash': job['event_hash'], 'generation': 0, 'byte_offset': 0, 'byte_length': len(payload), 'payload_sha256': e2e.digest(payload), 'record_count': 1, } state = { 'stream_name': 'found_secrets', 'generation': 0, 'current_generation': 0, 'committed_offset': len(payload), 'last_append_id': 4, 'last_job_id': 3, 'last_event_id': job['event_id'], 'last_event_hash': job['event_hash'], } return payload, append, state, job def test_projection_requires_exact_bytes_offsets_hash_and_event(self): payload, append, state, job = self.projection_fixture() e2e.verify_projection(payload, payload, append, state, job, 1) mutations = [ ('append', 'byte_offset', 1), ('append', 'byte_length', len(payload) + 1), ('append', 'payload_sha256', '0' * 64), ('append', 'record_count', 2), ('append', 'state', 'prepared'), ('append', 'event_hash', '0' * 64), ('append', 'event_id', 'c' * 32), ('append', 'job_id', 99), ('state', 'generation', 1), ('state', 'current_generation', 1), ('state', 'committed_offset', len(payload) + 1), ('state', 'last_append_id', 99), ('state', 'last_job_id', 99), ('state', 'last_event_hash', '0' * 64), ] for location, name, value in mutations: with self.subTest(location=location, field=name): changed_append, changed_state = copy.deepcopy(append), copy.deepcopy(state) (changed_append if location == 'append' else changed_state)[name] = value with self.assertRaises(e2e.E2EFailure): e2e.verify_projection(payload, payload, changed_append, changed_state, job, 1) with self.assertRaises(e2e.E2EFailure): e2e.verify_projection(payload * 2, payload, append, state, job, 1) with self.assertRaises(e2e.E2EFailure): e2e.verify_projection(b'{"fixture":2}\n', payload, append, state, job, 1) def test_projection_region_requires_exact_lineage_and_current_cursor(self): expected = b'{"remote":1}\n' prefix = b'{"local":1}\n' payload = prefix + expected job = {'id': 7, 'event_id': 'c' * 32, 'event_hash': 'd' * 64} append = { 'id': 8, 'job_id': 7, 'stream_name': 'scan_results', 'state': 'appended', 'event_id': job['event_id'], 'event_hash': job['event_hash'], 'generation': 0, 'byte_offset': len(prefix), 'byte_length': len(expected), 'payload_sha256': e2e.digest(expected), 'record_count': 1, } state = { 'stream_name': 'scan_results', 'generation': 0, 'current_generation': 0, 'committed_offset': len(payload), 'last_append_id': 8, 'last_job_id': 7, 'last_event_id': job['event_id'], 'last_event_hash': job['event_hash'], } e2e.verify_projection_region(payload, expected, append, state, job, 1) for field, value in ( ('byte_offset', 0), ('byte_length', len(expected) - 1), ('payload_sha256', '0' * 64), ('event_id', 'e' * 32), ): changed = copy.deepcopy(append) changed[field] = value with self.subTest(field=field), self.assertRaises(e2e.E2EFailure): e2e.verify_projection_region( payload, expected, changed, state, job, 1, ) def test_persistence_ignores_only_ephemeral_supervisor_identity(self): before = { 'schema': 1, 'checked': 0, 'counts': {'findings': 1}, 'hashes': {'scan_sha256': 'a' * 64}, 'ids': {'scan_id': 1}, 'origin_instance_sha256': 'b' * 64, } after = copy.deepcopy(before) after['origin_instance_sha256'] = 'c' * 64 e2e.compare_persisted(before, after, require_restart=True) with self.assertRaisesRegex(e2e.E2EFailure, 'recreation_required'): e2e.compare_persisted(before, before, require_restart=True) for field in ('counts', 'hashes', 'ids', 'checked'): changed = copy.deepcopy(after) changed[field] = {} if field != 'checked' else 1 with self.subTest(field=field), self.assertRaises(e2e.E2EFailure): e2e.compare_persisted(before, changed) def test_poll_is_bounded_and_only_retries_not_ready(self): with mock.patch.object(e2e, 'pipeline_snapshot', side_effect=e2e.NotReady('waiting')), \ mock.patch.object(e2e.time, 'monotonic', side_effect=[0, 0, 1, 2, 3]), \ mock.patch.object(e2e.time, 'sleep'): with self.assertRaisesRegex(e2e.E2EFailure, 'timeout_waiting'): e2e.wait_for_pipeline({}, {}, '', 0, 2) with mock.patch.object(e2e, 'pipeline_snapshot', side_effect=e2e.E2EFailure('duplicate')), \ mock.patch.object(e2e.time, 'sleep') as sleep: with self.assertRaisesRegex(e2e.E2EFailure, '^duplicate$'): e2e.wait_for_pipeline({}, {}, '', 0, 2) sleep.assert_not_called() def test_failures_and_arguments_do_not_print_credentials_or_exceptions(self): for error in (RuntimeError(e2e.synthetic_openai_token()), e2e.E2EFailure(e2e.synthetic_openai_token()), e2e.E2EFailure('fresh_volume_required')): output = io.StringIO() with mock.patch.object(e2e, 'require_container', side_effect=error), \ mock.patch.object(sys, 'stdout', output): code = e2e.main(['prepare']) self.assertEqual(code, 1) summary = json.loads(output.getvalue()) self.assertEqual(set(summary), {'counts', 'hashes'}) self.assertEqual(summary['counts']['ok'], 0) self.assertTrue(all(type(value) is int for value in summary['counts'].values())) self.assertFalse(e2e.synthetic_openai_token() in output.getvalue()) output = io.StringIO() with mock.patch.object(sys, 'stdout', output): self.assertEqual(e2e.main([e2e.synthetic_openai_token()]), 1) self.assertEqual(json.loads(output.getvalue())['counts']['invalid_arguments'], 1) def test_no_assertion_sql_can_mutate_database(self): database = mock.Mock() with self.assertRaises(e2e.E2EFailure): e2e.rows(database, 'UPDATE target_queue SET status = 1') database.conn.execute.assert_not_called() tree = ast.parse(PATH.read_text(encoding='utf-8')) forbidden = {'record_final_cutover', 'initialize_schema', 'record_target_result', 'ingest_result_bundle', 'complete_keycheck_candidate', 'claim_keycheck_candidate'} calls = {node.func.attr for node in ast.walk(tree) if isinstance(node, ast.Call) and isinstance(node.func, ast.Attribute)} self.assertFalse(calls & forbidden) def test_remote_full_harness_selects_real_boundaries_and_only_controls_time(self): tree = ast.parse(PATH.read_text(encoding='utf-8')) functions = { node.name: node for node in tree.body if isinstance(node, ast.FunctionDef) } selected = ast.Module(body=[functions[name] for name in ( 'remote_worker_service', 'execute_fixture_assignment', 'prepare_remote_full_race', 'remote_full_snapshot', '_finish_remote_full_race', 'finish_remote_full_race', )], type_ignores=[]) calls = { node.func.attr if isinstance(node.func, ast.Attribute) else node.func.id for node in ast.walk(selected) if isinstance(node, ast.Call) and isinstance(node.func, (ast.Attribute, ast.Name)) } self.assertTrue({ 'RemoteGitAssignmentBuilder', 'WorkerService', 'execute_planned_claim', 'scan_target_result', 'invoke_worker_claim', 'invoke_bundle_upload', 'admin_remote_worker_snapshot', } <= calls) controls = [] for node in ast.walk(functions['prepare_remote_full_race']): if not isinstance(node, ast.Call) or not isinstance(node.func, ast.Attribute): continue if node.func.attr != 'patch' and node.func.attr != 'object': continue controls.append(ast.unparse(node)) source = ast.unparse(selected) self.assertNotIn("patch.object(scanner, 'scan_target_result'", source) self.assertNotIn("patch.object(scan_execution, 'execute_planned_claim'", source) self.assertIn("mock.patch.object(worker_api, 'utc_now_iso'", source) self.assertIn("mock.patch.object(scanner_db, 'utc_now_iso'", source) self.assertIn('asyncio.Barrier(2)', source) def test_remote_source_selection_is_bounded_without_admission_widening(self): args = e2e.remote_source_args({ 'sources': {'gitlab': {'timeout': 60}}, }) self.assertEqual(args.platform, 'gitlab') self.assertTrue(args.exact_git_planning_enabled) self.assertTrue(args.external_trufflehog_lifecycle) self.assertEqual(args.result_bundle_max_event_bytes, e2e.MAX_BYTES) self.assertEqual(args.max_active_scans, 1) self.assertEqual(args.keycheck_candidates_per_event, 8) self.assertEqual(args.projection_backlog_max_bytes, 8 * e2e.MAX_BYTES) self.assertEqual(args.target_claim_order, 'oldest') def test_dockerhub_canary_configuration_has_exact_test_only_bounds(self): import yaml app = PATH.parents[1] / 'app' config = e2e.fixture_config(yaml.safe_load( (app / 'config.linux.yaml').read_text(encoding='utf-8') )) original = copy.deepcopy(config) with mock.patch.object(sys, 'path', [str(app), *sys.path]): discovery = e2e.dockerhub_canary_args(config, discovery=True) assignment = e2e.dockerhub_canary_args(config, discovery=False) self.assertEqual(config, original) for args in (discovery, assignment): self.assertEqual(args.platform, 'docker') self.assertEqual(args.mode, 'search') self.assertEqual(args.configured_queries, (e2e.DOCKERHUB_CANARY_QUERY,)) self.assertEqual(args.query, e2e.DOCKERHUB_CANARY_QUERY) self.assertEqual(args.pages, 1) self.assertEqual(args.per_page, 4) self.assertEqual(args.workers, 1) self.assertEqual(args.max_active_scans, 1) self.assertEqual(args.max_targets, 4) self.assertEqual(args.tag_fetch_workers, 1) self.assertEqual(args.tag_retry_count, 1) self.assertEqual(args.tag_retry_delay, 1) self.assertEqual(args.tag_resolve_limit, 4) self.assertEqual(args.docker_images_per_repository, 1) self.assertEqual(args.result_bundle_max_items, 1) self.assertEqual(args.projection_backlog_max_items, 1) self.assertEqual(args.projection_backlog_max_bytes, 4 * e2e.MAX_BYTES) self.assertEqual(args.projection_backlog_headroom_bytes, 2 * e2e.MAX_BYTES) self.assertEqual(args.keycheck_candidates_per_event, 1) self.assertEqual(args.keycheck_candidate_bytes_per_event, 1024) self.assertEqual(discovery.token, e2e.DOCKERHUB_CANARY_DISCOVERY_TOKEN) self.assertEqual( (assignment.token, assignment.docker_username, assignment.docker_token, assignment.auth_name), ('', '', '', None), ) self.assertEqual(len(e2e.DOCKERHUB_CANARY_REPOSITORIES), 4) self.assertEqual(len(set(e2e.DOCKERHUB_CANARY_TARGETS)), 4) self.assertTrue(all('@sha256:' in target for target in e2e.DOCKERHUB_CANARY_TARGETS)) def test_dockerhub_canary_transport_substitution_is_exact_and_bounded(self): search, tags, calls = e2e.dockerhub_canary_transport() page = search( e2e.DOCKERHUB_CANARY_QUERY, 1, per_page=4, sort_by='updated_at', sort_order='desc', request_timeout=15, ) self.assertEqual(page['page'], 1) self.assertEqual(page['total_count'], 4) self.assertEqual( [item['repo_name'] for item in page['repositories']], list(e2e.DOCKERHUB_CANARY_REPOSITORIES), ) for repository, target in zip( e2e.DOCKERHUB_CANARY_REPOSITORIES, e2e.DOCKERHUB_CANARY_TARGETS, ): outcome = tags( repository, None, 1, 1, 1, True, 'linux', 'amd64', 4, return_outcome=True, ) self.assertEqual(outcome.tags, (target,)) self.assertEqual(outcome.status, 'ok') self.assertEqual(len(calls['search']), 1) self.assertEqual(calls['tags'], list(e2e.DOCKERHUB_CANARY_REPOSITORIES)) invalid_search, invalid_tags, _ = e2e.dockerhub_canary_transport() with self.assertRaisesRegex(e2e.E2EFailure, '^dockerhub_canary_search_bound$'): invalid_search( e2e.DOCKERHUB_CANARY_QUERY, 2, per_page=4, sort_by='updated_at', sort_order='desc', request_timeout=15, ) with self.assertRaisesRegex(e2e.E2EFailure, '^dockerhub_canary_tag_bound$'): invalid_tags( e2e.DOCKERHUB_CANARY_REPOSITORIES[0], None, 2, 0, 0, True, 'linux', 'amd64', 4, return_outcome=True, ) def test_dockerhub_canary_uses_real_boundaries_without_probe_or_proof_machinery(self): tree = ast.parse(PATH.read_text(encoding='utf-8')) functions = { node.name: node for node in tree.body if isinstance(node, ast.FunctionDef) } selected = ast.Module(body=[functions[name] for name in ( 'dockerhub_canary_service', 'stage_dockerhub_canary_result', 'dockerhub_canary_result_snapshot', 'prepare_dockerhub_canary', 'finish_dockerhub_canary', )], type_ignores=[]) calls = { node.func.attr if isinstance(node.func, ast.Attribute) else node.func.id for node in ast.walk(selected) if isinstance(node, ast.Call) and isinstance(node.func, (ast.Attribute, ast.Name)) } self.assertTrue({ 'RemoteAssignmentBuilder', 'WorkerService', 'run_discovery_cycle', 'resolve_due_docker_queue_targets', 'invoke_worker_claim', 'client_scan_launch_authority', 'client_scan_execution_policy', 'stage_scan_result_in_scope', 'apply_trufflehog_diagnostics', 'invoke_bundle_upload', 'reap', 'reconcile_runtime_drain', 'verify_projection_region', } <= calls) self.assertFalse({ 'dockerhub_search_response', 'dockerhub_tags_response', 'resolve_docker_content_manifest', 'docker_registry_bearer_token', 'bind_docker_layer_plan', 'record_final_cutover', 'initialize_schema', } & calls) patched = [] for node in ast.walk(selected): if not isinstance(node, ast.Call) or not isinstance(node.func, ast.Attribute): continue if node.func.attr != 'object' or len(node.args) < 2: continue if isinstance(node.args[1], ast.Constant) and isinstance(node.args[1].value, str): patched.append(node.args[1].value) self.assertEqual( set(patched), {'fetch_dockerhub_search_page', 'fetch_dockerhub_tags', 'utc_now_iso'}, ) self.assertFalse({ 'stage_scan_result_in_scope', 'apply_trufflehog_diagnostics', 'ingest_result_bundle', 'claim_projection_job', } & set(patched)) production = '\n'.join( (PATH.parents[1] / 'app' / name).read_text(encoding='utf-8') for name in ( 'worker_assignment.py', 'worker_api.py', 'scanner_db.py', 'scan_execution.py', ) ).lower() for forbidden in ( 'access_probe', 'public_access_proof', 'proof_freshness', ): self.assertNotIn(forbidden, production) def test_dockerhub_canary_modes_wrap_existing_runtime_restart(self): driver = PATH.read_text(encoding='utf-8') verifier = (PATH.parents[1] / 'docker' / 'verify.py').read_text(encoding='utf-8') for mode in ('prepare-dockerhub-canary', 'finish-dockerhub-canary'): self.assertIn("'" + mode + "'", driver) prepare = verifier.index("'prepare-dockerhub-canary'") remote_prepare = verifier.index("'prepare-remote-full-race'") second_stop = verifier.index("verifier.stop(second, 'second_stop')") third_start = verifier.index("third = verifier.start('third_start'") remote_finish = verifier.index("'finish-remote-full-race'") finish = verifier.index("'finish-dockerhub-canary'") third_stop = verifier.index("verifier.stop(third, 'third_stop')") self.assertLess(prepare, remote_prepare) self.assertLess(remote_prepare, second_stop) self.assertLess(second_stop, third_start) self.assertLess(third_start, remote_finish) self.assertLess(remote_finish, finish) self.assertLess(finish, third_stop) def test_local_pipeline_cycle_precedes_pipeline_assertion(self): driver = PATH.read_text(encoding='utf-8') verifier = (PATH.parents[1] / 'docker' / 'verify.py').read_text(encoding='utf-8') self.assertIn("'run-local-pipeline'", driver) self.assertIn('supervised_child_environment(metadata, url, \'scanner\')', driver) self.assertIn('os.environ.pop(name, None)', driver) self.assertLess( verifier.index("'run-local-pipeline'"), verifier.index("'assert-pipeline'"), ) def test_full_linux_profile_and_candidate_api_contract(self): import yaml app = PATH.parents[1] / 'app' config = e2e.fixture_config(yaml.safe_load((app / 'config.linux.yaml').read_text(encoding='utf-8'))) policy_spec = importlib.util.spec_from_file_location('e2e_query_policy', app / 'query_policy.py') policy = importlib.util.module_from_spec(policy_spec) policy_spec.loader.exec_module(policy) policy.validate_rejected_query_policy(config) self.assertEqual(config['global']['runtime_dir'], '/data/runtime-linux') self.assertEqual(config['global']['postgres_data_dir'], '/data/postgres-linux') self.assertEqual(config['global']['postgres_bin_dir'], '/usr/lib/postgresql/16/bin') self.assertEqual(config['global']['result_bundle_dir'], '/data/scanner-result-bundles') self.assertEqual(config['global']['control_dir'], '/run/truf/control') candidate_spec = importlib.util.spec_from_file_location('e2e_candidate_contract', app / 'keycheck_candidates.py') candidates = importlib.util.module_from_spec(candidate_spec) with mock.patch.dict(sys.modules, {candidate_spec.name: candidates}): candidate_spec.loader.exec_module(candidates) material = e2e.synthetic_openai_token() specs = list(candidates.extract_candidates({'DetectorName': 'OpenAI', 'Raw': material})) self.assertEqual(len(specs), 1) self.assertEqual(specs[0].service, 'openai') self.assertEqual(specs[0].provider_key_hash, e2e.digest(material.encode())) self.assertEqual(specs[0].credential_hash, e2e.digest(('truf-credential-v2|openai|' + material).encode())) def test_transport_allows_only_one_fenced_fake_models_request(self): import requests active = {'id': 17, 'lease_token': 'test-only-fence'} common = SimpleNamespace(_ACTIVE_DB_CANDIDATE=active) headers = {'Authorization': 'Bearer ' + e2e.synthetic_openai_token()} calls = [] request = e2e.fixture_transport(17, calls) with mock.patch.dict(sys.modules, {'keycheck_common': common}), \ mock.patch.object(requests.Session, 'request', new=request): response = requests.get('https://api.openai.com/v1/models', headers=headers, proxies=None, timeout=15) self.assertEqual(response.status_code, 401) self.assertEqual(response.json()['error']['code'], 'invalid_api_key') self.assertEqual(calls, [1]) with self.assertRaises(e2e.E2EFailure): request(None, 'GET', 'https://api.openai.com/v1/models', headers=headers) for method, url, kwargs in ( ('POST', 'https://api.openai.com/v1/models', {'headers': headers}), ('GET', 'https://api.openai.com/v1/chat/completions', {'headers': headers}), ('GET', 'https://example.invalid/v1/models', {'headers': headers}), ('GET', 'https://api.openai.com/v1/models', {'headers': {'Authorization': 'Bearer not-the-fixture'}}), ('GET', 'https://api.openai.com/v1/models', {'headers': headers, 'proxies': {'https': 'http://proxy.invalid'}}), ('GET', 'https://api.openai.com/v1/models', {'headers': headers, 'params': {'unexpected': 1}}), ('GET', 'https://api.openai.com/v1/models', {'headers': headers, 'auth': ('unexpected', 'credential')}), ): with self.subTest(method=method, url=url), mock.patch.dict(sys.modules, {'keycheck_common': common}): calls = [] with self.assertRaises(e2e.E2EFailure): e2e.fixture_transport(17, calls)(None, method, url, **kwargs) self.assertEqual(calls, []) for active in (None, {'id': 18, 'lease_token': 'test-only-fence'}, {'id': 17}, {'id': 17, 'lease_token': 'test-only-fence', '_completed': True}): with mock.patch.dict(sys.modules, {'keycheck_common': SimpleNamespace(_ACTIVE_DB_CANDIDATE=active)}): with self.assertRaises(e2e.E2EFailure): e2e.fixture_transport(17, [])(None, 'GET', 'https://api.openai.com/v1/models', headers=headers) class ContainerE2EFreshVolumeTests(unittest.TestCase): def setUp(self): self.stack = ExitStack() self.addCleanup(self.stack.close) self.data = Path(self.stack.enter_context(tempfile.TemporaryDirectory(prefix='truf-e2e-proxy-'))) self.runtime = self.data / 'runtime-linux' self.runtime.mkdir() self.proxy = self.runtime / 'proxy.txt' self.private_directory = mock.Mock() self.stack.enter_context(mock.patch.dict(sys.modules, { 'runtime_security': SimpleNamespace(require_private_directory=self.private_directory), })) self.stack.enter_context(mock.patch.multiple( e2e, DATA=self.data, RUNTIME=self.runtime, PG_DATA=self.data / 'postgres-linux', BUNDLES=self.data / 'scanner-result-bundles', FIXTURE=self.data / 'fixture', )) @staticmethod def proxy_stat(**overrides): # Host tests simulate POSIX ownership/mode without changing host ACLs. details = dict(st_mode=stat.S_IFREG | 0o600, st_uid=10001, st_gid=10001, st_size=0, st_nlink=1) details.update(overrides) return SimpleNamespace(**details) def test_fresh_volume_accepts_empty_tree_and_exact_proxy_without_writes(self): e2e.require_fresh_volume() self.proxy.touch() before = self.proxy.stat() with mock.patch.object(Path, 'lstat', return_value=self.proxy_stat()) as inspect: e2e.require_fresh_volume() inspect.assert_called_once_with() self.assertEqual(self.proxy.stat(), before) self.assertEqual(self.proxy.read_bytes(), b'') self.assertTrue(all(call.kwargs == {'create': False} for call in self.private_directory.call_args_list)) def test_fresh_volume_rejects_nonempty_proxy_without_clearing_it(self): self.proxy.write_bytes(b'not an empty provisioned file\n') before = self.proxy.read_bytes() with mock.patch.object(Path, 'lstat', return_value=self.proxy_stat(st_size=len(before))): with self.assertRaisesRegex(e2e.E2EFailure, '^fresh_volume_required$'): e2e.require_fresh_volume() self.assertEqual(self.proxy.read_bytes(), before) def test_fresh_volume_rejects_wrong_proxy_owner_group_and_modes(self): self.proxy.touch() before = self.proxy.stat() for overrides in ( {'st_uid': 0}, {'st_gid': 0}, {'st_uid': 10002}, {'st_gid': 10002}, *({'st_mode': stat.S_IFREG | mode} for mode in (0o400, 0o640, 0o644, 0o700, 0o4600)), ): with self.subTest(metadata=overrides), \ mock.patch.object(Path, 'lstat', return_value=self.proxy_stat(**overrides)): with self.assertRaisesRegex(e2e.E2EFailure, '^fresh_volume_required$'): e2e.require_fresh_volume() self.assertEqual(self.proxy.stat(), before) def test_fresh_volume_rejects_symlink_nonregular_and_hardlinked_proxy(self): self.proxy.touch() for overrides in ( *({'st_mode': kind | 0o600} for kind in (stat.S_IFLNK, stat.S_IFIFO, stat.S_IFSOCK, stat.S_IFDIR)), {'st_nlink': 2}, {'st_nlink': 0}, ): with self.subTest(metadata=overrides), \ mock.patch.object(Path, 'lstat', return_value=self.proxy_stat(**overrides)) as inspect: with self.assertRaisesRegex(e2e.E2EFailure, '^fresh_volume_required$'): e2e.require_fresh_volume() inspect.assert_called_once_with() self.assertEqual(self.proxy.read_bytes(), b'') def test_fresh_volume_rejects_other_files_even_with_valid_proxy_metadata(self): self.proxy.touch() for relative in ( 'runtime-linux/other.txt', 'runtime-linux/nested/proxy.txt', 'postgres-linux/proxy.txt', 'scanner-result-bundles/proxy.txt', 'scanner-work/proxy.txt', 'fixture/proxy.txt', ): unexpected = self.data / relative unexpected.parent.mkdir(parents=True, exist_ok=True) unexpected.touch() try: with self.subTest(path=relative), \ mock.patch.object(Path, 'lstat', return_value=self.proxy_stat()): with self.assertRaisesRegex(e2e.E2EFailure, '^fresh_volume_required$'): e2e.require_fresh_volume() self.assertTrue(unexpected.is_file()) self.assertEqual(self.proxy.read_bytes(), b'') finally: unexpected.unlink() def test_fresh_volume_rejects_directory_at_proxy_path(self): self.proxy.mkdir() with self.assertRaisesRegex(e2e.E2EFailure, '^fresh_volume_required$'): e2e.require_fresh_volume() self.assertTrue(self.proxy.is_dir()) if __name__ == '__main__': unittest.main()