R-426: image-resolvable decoys, end to end through a PATH-stub docker
The gate's unit tests inject `resolver`, so docker_resolver - where both live traps sit - never ran under test. test_gate_decoys.py now copies the working-tree gate into a scratch catalog and runs it with PATH = ONLY a stub docker (the real runtime acts on DooPlex and cannot be reached; no network). 9 cases: a `manifest unknown` pin is convicted naming the app; rc=0 carrying a throttle or any error text, a docker that resolves the .invalid canary too, no docker, nothing to judge are INCONCLUSIVE or HARNESS REFUSED, never 0; a throttle or unrecognised error on rc=1 is never an accusation. COVERS gains "image-resolvable". check-image-resolvable.py: the "same shape as check-image-pins.py" comment was made false by the image-pins fix; it now says why the narrower regex is safe. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -32,7 +32,9 @@ import subprocess
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
IMAGE_RE = re.compile(r"^\s*image:\s*[\"']?([^\s\"'#]+)") # same shape as check-image-pins.py
|
||||
# Narrower than check-image-pins.py since R-426: that gate also reads a QUOTED `"image":` key (and refuses an
|
||||
# interpolated ref), so neither shape can reach a published template for this one to miss.
|
||||
IMAGE_RE = re.compile(r"^\s*image:\s*[\"']?([^\s\"'#]+)")
|
||||
|
||||
# A ref that must never resolve, for self-testing the resolver end of the gate. `.invalid` is
|
||||
# reserved by RFC 2606 and can never be a real registry.
|
||||
|
||||
Reference in New Issue
Block a user