test_legacy_identifiers.py (6406B)
1 from __future__ import annotations 2 3 import copy 4 import json 5 import plistlib 6 import sys 7 import tempfile 8 import unittest 9 from pathlib import Path 10 11 SCRIPTS = Path(__file__).resolve().parent 12 if str(SCRIPTS) not in sys.path: 13 sys.path.insert(0, str(SCRIPTS)) 14 15 import legacy_identifiers as legacy # noqa: E402 16 import package_contract as contract # noqa: E402 17 18 19 class LegacyIdentifierTests(unittest.TestCase): 20 def setUp(self) -> None: 21 self.path = "Tera/Runtime/TeraExample.swift" 22 self.sources = { 23 self.path: 'import RadrootsKit\nlet oldKey = "radroots.mobile.settings.v1"\n' 24 } 25 self.policy = { 26 "schema": "tera.legacy-identifiers.v1", 27 "baseline_commit": "a" * 40, 28 "categories": { 29 "synthetic": { 30 "owner": "synthetic public producer", 31 "reason": "synthetic shared API and persisted reader", 32 "reader": "synthetic app consumer", 33 "removal_condition": "explicit versioned reader migration", 34 } 35 }, 36 "entries": [ 37 { 38 "identifier": identifier, 39 "category": "synthetic", 40 "occurrences": [{"path": self.path, "count": 1}], 41 } 42 for identifier in ("RadrootsKit", "radroots.mobile.settings.v1") 43 ], 44 } 45 46 def test_shared_and_persisted_names_are_exact_exceptions(self) -> None: 47 self.assertEqual(legacy.validate(self.policy, self.sources)["identifiers"], 2) 48 49 def test_kotlin_binding_harness_keeps_exact_naming_boundaries(self) -> None: 50 for extension in ("kt", "kts"): 51 path = f"scripts/kotlin_smoke/source.{extension}" 52 self.assertTrue(legacy.selected(path)) 53 policy = copy.deepcopy(self.policy) 54 entry = next( 55 e for e in policy["entries"] if e["identifier"] == "RadrootsKit" 56 ) 57 entry["occurrences"].append({"path": path, "count": 1}) 58 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "declaration"): 59 legacy.validate(policy, {**self.sources, path: "fun RadrootsKit() {}"}) 60 61 def test_unknown_identifier_is_rejected_even_in_an_allowed_file(self) -> None: 62 sources = { 63 self.path: self.sources[self.path] + 'let old = "radroots.unapproved.v1"\n' 64 } 65 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "unapproved"): 66 legacy.validate(self.policy, sources) 67 68 def test_known_identifier_cannot_expand_to_another_file(self) -> None: 69 sources = {**self.sources, "Tera/New.swift": "import RadrootsKit\n"} 70 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "unapproved"): 71 legacy.validate(self.policy, sources) 72 73 def test_removed_or_duplicated_occurrences_require_review(self) -> None: 74 for text in ("", self.sources[self.path] * 2): 75 with self.subTest(text=text): 76 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "stale"): 77 legacy.validate(self.policy, {self.path: text}) 78 79 def test_shared_name_exception_cannot_authorize_an_app_declaration(self) -> None: 80 for declaration in ( 81 "struct RadrootsKit {}", 82 "public actor RadrootsKit {}", 83 "pub struct RadrootsKit;", 84 "private func RadrootsKit() {}", 85 "private static var RadrootsKit: Int { 0 }", 86 ): 87 with self.subTest(declaration=declaration): 88 with self.assertRaisesRegex( 89 legacy.LegacyIdentifierError, "declaration" 90 ): 91 legacy.validate(self.policy, {self.path: declaration}) 92 93 def test_missing_owner_reader_or_removal_condition_is_rejected(self) -> None: 94 for field in legacy.CATEGORY_FIELDS: 95 with self.subTest(field=field): 96 policy = copy.deepcopy(self.policy) 97 policy["categories"]["synthetic"][field] = "" 98 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "absent"): 99 legacy.validate(policy, self.sources) 100 101 def test_wildcard_and_traversal_exceptions_are_rejected(self) -> None: 102 for path in ("Tera/*.swift", "../Tera/Runtime/TeraExample.swift"): 103 with self.subTest(path=path): 104 policy = copy.deepcopy(self.policy) 105 policy["entries"][0]["occurrences"][0]["path"] = path 106 with self.assertRaises(legacy.LegacyIdentifierError): 107 legacy.validate(policy, self.sources) 108 109 def test_duplicate_policy_fields_and_rows_are_rejected(self) -> None: 110 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "duplicated"): 111 json.loads( 112 '{"schema": 1, "schema": 2}', object_pairs_hook=legacy.unique_object 113 ) 114 policy = copy.deepcopy(self.policy) 115 policy["entries"].append(policy["entries"][0]) 116 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "duplicated"): 117 legacy.validate(policy, self.sources) 118 119 def test_source_parent_symlinks_and_oversized_files_fail_closed(self) -> None: 120 with tempfile.TemporaryDirectory() as temporary: 121 root = Path(temporary) 122 (root / "outside").mkdir() 123 (root / "Tera").symlink_to(root / "outside", target_is_directory=True) 124 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "symlink"): 125 legacy.read_regular(root, "Tera/Example.swift") 126 (root / "large").write_bytes(b"x" * (legacy.MAX_BYTES + 1)) 127 with self.assertRaisesRegex(legacy.LegacyIdentifierError, "byte bound"): 128 legacy.read_regular(root, "large") 129 130 def test_display_name_is_independent_of_legacy_namespace_exceptions(self) -> None: 131 document = plistlib.loads((SCRIPTS.parent / "Tera/Info.plist").read_bytes()) 132 document["CFBundleDisplayName"] = "Radroots" 133 with self.assertRaisesRegex(contract.PackageContractError, "display name"): 134 contract._validate_app_plist(document) 135 136 def test_current_source_has_only_reviewed_legacy_occurrences(self) -> None: 137 result = legacy.verify(SCRIPTS.parent) 138 self.assertGreater(result["identifiers"], 0) 139 140 141 if __name__ == "__main__": 142 unittest.main()