fix(work): import hashlib and wire heal subparser into main CLI

This commit is contained in:
operator
2026-10-09 23:13:43 +00:00
parent c3b4b1cd28
commit f75977ca6e
202 changed files with 4185 additions and 4142 deletions
+69 -7
View File
@@ -33,6 +33,7 @@ def _load(name, relpath):
exec_constrained = _load("exec_constrained_read", "bin/exec-constrained.py")
super_cli = _load("super_cli_read", "bin/super-cli.py")
box_ctl = _load("box_ctl_readtest", "bin/box-ctl.py")
def _box_ctl(*args):
@@ -41,6 +42,33 @@ def _box_ctl(*args):
capture_output=True, text=True, timeout=60)
class _InProcResult:
"""Minimal CompletedProcess stand-in (returncode/stdout/stderr)."""
def __init__(self, returncode, stdout, stderr=""):
self.returncode = returncode
self.stdout = stdout
self.stderr = stderr
def _box_ctl_inproc(*args):
"""In-process _box_ctl for dry-run/read-only verbs (quality-validate,
dm-log success paths).
Calls the real main(argv) -- identical argv parsing, dispatch, audit,
and stdout JSON -- with stdio captured, amortizing the ~80ms
per-spawn interpreter + module-exec cost over one import.
"""
from contextlib import redirect_stderr
out, err = io.StringIO(), io.StringIO()
returncode = 0
with redirect_stdout(out), redirect_stderr(err):
try:
box_ctl.main(["box-ctl.py", *args])
except SystemExit as e:
returncode = e.code if isinstance(e.code, int) else 1
return _InProcResult(returncode, out.getvalue(), err.getvalue())
class ExecReadOpsTests(unittest.TestCase):
def test_ops_registered_and_read_only(self):
self.assertIn("fleet.unread", exec_constrained.OPS)
@@ -97,8 +125,10 @@ class ExecReadOpsTests(unittest.TestCase):
spec = exec_constrained.OPS["dm.log"]
clean = spec["validate"]({"limit": 2})
argv = spec["build"](clean)
argv[0] = sys.executable # hermetic interpreter, same script + args
r = subprocess.run(argv, capture_output=True, text=True, timeout=60)
# In-process dispatch of the op-built argv (minus interpreter and
# script: argv is [python, box-ctl.py, action, ...]): same argv
# parsing, dispatch, and stdout JSON, without respawn.
r = _box_ctl_inproc(*argv[2:])
self.assertEqual(r.returncode, 0, r.stderr)
data = json.loads(r.stdout)
self.assertTrue(data["ok"])
@@ -131,23 +161,55 @@ class BoxCtlReadVerbsTests(unittest.TestCase):
self.assertEqual(json.loads(r.stdout)["code"], "BAD_ARGS")
def test_dm_log_back_compat_limit_only(self):
r = _box_ctl("dm-log", "2")
r = _box_ctl_inproc("dm-log", "2")
self.assertEqual(r.returncode, 0, r.stderr)
data = json.loads(r.stdout)
self.assertTrue(data["ok"])
self.assertEqual(len(data["entries"]), 2)
def test_quality_validate_new_verbs(self):
r = _box_ctl("quality-validate", "unread", "--agent", "pip")
# In-process dry-runs: same main(argv) path and stdout JSON as
# subprocess calls. Assertions below are unchanged.
r = _box_ctl_inproc("quality-validate", "unread", "--agent", "pip")
data = json.loads(r.stdout)
self.assertTrue(data["valid"], r.stdout)
r = _box_ctl("quality-validate", "dm-log", "5", "--agent", "opm")
r = _box_ctl_inproc("quality-validate", "dm-log", "5", "--agent", "opm")
self.assertTrue(json.loads(r.stdout)["valid"], r.stdout)
r = _box_ctl("quality-validate", "unread", "--agent", "nope")
r = _box_ctl_inproc("quality-validate", "unread", "--agent", "nope")
self.assertFalse(json.loads(r.stdout)["valid"], r.stdout)
r = _box_ctl("quality-validate", "unread", "extra-positional")
r = _box_ctl_inproc("quality-validate", "unread", "extra-positional")
self.assertFalse(json.loads(r.stdout)["valid"], r.stdout)
def test_policy_verbs_live_schema(self):
r = _box_ctl_inproc("policy")
self.assertEqual(r.returncode, 0, r.stderr)
data = json.loads(r.stdout)
self.assertTrue(data["ok"])
self.assertIn("agents", data)
self.assertIn("totals", data)
self.assertIn(data["status"], ("clean", "violations found"))
r = _box_ctl_inproc("policy", "check", "opm")
self.assertEqual(r.returncode, 0, r.stderr)
data = json.loads(r.stdout)
self.assertTrue(data["ok"])
self.assertEqual(data["agent"], "opm")
for k in ("blocked", "authorized_main", "violations", "total_sends"):
self.assertIn(k, data)
def test_policy_scan_parses_each_line_once(self):
import shutil
import tempfile
with tempfile.TemporaryDirectory() as td:
frozen = Path(td) / "dm-log.jsonl"
shutil.copyfile(box_ctl.DM_LOG, frozen)
expect = sum(1 for ln in frozen.read_text().splitlines() if ln.strip())
real_loads = json.loads
with mock.patch.object(box_ctl, "DM_LOG", frozen):
with mock.patch.object(json, "loads", wraps=real_loads) as spy:
per_agent, meta = box_ctl._policy_scan()
self.assertIsNotNone(per_agent)
self.assertEqual(spy.call_count, expect)
class SuperCliUnreadTests(unittest.TestCase):
def test_lookup_dispatches_unread(self):