"""Fail-closed unit tests for Outcome OS release artifact binding.""" from __future__ import annotations import importlib.util import unittest from pathlib import Path CHECKER_PATH = Path(__file__).with_name("check-outcome-os-release-manifest.py") def load_checker(): spec = importlib.util.spec_from_file_location( "check_outcome_os_release_manifest", CHECKER_PATH, ) if spec is None or spec.loader is None: raise RuntimeError("release manifest checker could not be loaded") module = importlib.util.module_from_spec(spec) spec.loader.exec_module(module) return module class ReleaseManifestArtifactBindingTests(unittest.TestCase): @classmethod def setUpClass(cls) -> None: cls.checker = load_checker() def test_counts_each_git_file_section(self) -> None: patch = ( b"diff --git a/one.txt b/one.txt\n" b"--- a/one.txt\n+++ b/one.txt\n" b"diff --git a/two.txt b/two.txt\n" b"--- a/two.txt\n+++ b/two.txt\n" ) self.assertEqual(2, self.checker.count_patch_files(patch)) def test_satisfied_gate_rejects_stale_patch_sha(self) -> None: current_sha = "a" * 64 stale_sha = "b" * 64 errors: list[str] = [] self.checker.validate_satisfied_gate_evidence( { "mixed-files-cleared": { "evidence": f"SHA-256 {stale_sha}; clean apply passed", }, }, {"patch_sha256": current_sha}, errors, ) self.assertEqual( [ "release gate mixed-files-cleared evidence does not reference " "the current release_assembly.patch_sha256" ], errors, ) def test_satisfied_gate_accepts_current_patch_sha(self) -> None: current_sha = "c" * 64 errors: list[str] = [] self.checker.validate_satisfied_gate_evidence( { "mixed-files-cleared": { "evidence": f"SHA-256 {current_sha}; clean apply passed", }, }, {"patch_sha256": current_sha}, errors, ) self.assertEqual([], errors) def test_public_gates_require_evidence(self) -> None: self.assertEqual( { "mixed-files-cleared": "satisfied-by-verified-release-patch", "g8-agentic-runtime-promotion": "satisfied-by-isolated-nas-release", "g8-public-proof": "satisfied-by-public-release", "aos-011-public-deployment-proof": "satisfied-by-public-release", "aos-012-final-ssot-sync": "satisfied-by-final-checkers", }, self.checker.REQUIRED_SATISFIED_GATES, ) self.assertEqual("g7-external-proof", self.checker.G7_GATE_ID) self.assertEqual( {"blocked", "satisfied-by-validated-g7-proof"}, self.checker.G7_ALLOWED_STATUSES, ) if __name__ == "__main__": unittest.main()