#!/usr/bin/env python3 # -*- coding: utf-8 -*- """test_golden_currency_gate.py — R-410's red-proof, shipped as a test. WHAT IT PINS. Until 2026-09-01 `golden_currency_gate.py` matched `EVIDENCE_RE` against `os.listdir` and read nothing inside the directory, so mkdir documentation/tests/golden-9.9.9-2026-01-01 turned the gate GREEN with no bake behind it. That was noticed while the 0.230.0 bake was running — the evidence directory was created BEFORE the bake finished, and the gate would have passed at that moment. **A directory name is a label; `GOLDEN_SHA256=<64 hex>` is a fact only a completed publish produces.** This is the gate's own instrument check: an empty directory must FAIL, a real bake log must PASS, and a log with no sha line must FAIL. Without the last two, "it fails on an empty directory" would be satisfied by a gate that fails on everything. Run: python3 scripts/test_golden_currency_gate.py Exit 0 all pass · 1 a case failed. """ import io import os import shutil import subprocess import sys import tempfile ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__))) GATE = os.path.join(ROOT, "scripts", "golden_currency_gate.py") EVIDENCE_DIR = os.path.join(ROOT, "documentation", "tests") REAL_SHA = "9287f7cef5f13166276e8406005e3f28004004510c5184f1c1c7377f7aafad2e" def run_gate(): p = subprocess.run([sys.executable, GATE], capture_output=True, text=True) return p.returncode, p.stdout + p.stderr def with_dir(name, files): """Context: create documentation/tests// holding `files` (name -> contents), then remove it.""" class _C(object): def __enter__(self): self.path = os.path.join(EVIDENCE_DIR, name) if os.path.exists(self.path): raise SystemExit("refusing to overwrite an existing %s" % self.path) os.makedirs(self.path) for fn, body in files.items(): with io.open(os.path.join(self.path, fn), "w", encoding="utf-8") as fh: fh.write(body) return self.path def __exit__(self, *a): shutil.rmtree(self.path, ignore_errors=True) return False return _C() def main(): if not os.path.isfile(GATE): print("FAIL: the gate script is missing — that is a failure, never a skip") return 1 fails = [] # --- BASELINE: what does the gate say with the tree as it is? ------------------------------ base_rc, base_out = run_gate() print("baseline: gate exit %d" % base_rc) # --- CASE 1: an EMPTY directory with a perfect name must NOT count as a bake ---------------- # Version 9.9.9 is far above any real release, so if it counted, the gate would go GREEN. with with_dir("golden-9.9.9-2026-01-01", {}): rc, out = run_gate() counted = "9.9.9" in out and "NOT counted" not in out.split("9.9.9")[0][-200:] if "newest golden baked : 9.9.9" in out: fails.append("CASE 1: an EMPTY directory was counted as a bake — this is R-410 exactly") elif "NOT counted as bakes" not in out: fails.append("CASE 1: the empty directory was neither counted nor reported; a half-finished " "bake must be VISIBLE, not silently ignored") else: print("CASE 1 ok: an empty golden-9.9.9-2026-01-01/ is rejected and named") _ = counted # --- CASE 2: a directory whose log has NO sha line must NOT count --------------------------- with with_dir("golden-9.9.8-2026-01-01", {"bake.log": "[golden] starting\n[golden] it all went wrong\n"}): rc, out = run_gate() if "newest golden baked : 9.9.8" in out: fails.append("CASE 2: a bake log with no GOLDEN_SHA256 line was counted as a bake") else: print("CASE 2 ok: a log with no GOLDEN_SHA256 line is rejected") # --- CASE 3: a REAL bake log must count, and the gate must read its sha --------------------- # The positive control. Without it, cases 1 and 2 are satisfied by a gate that rejects everything. with with_dir("golden-9.9.7-2026-01-01", {"bake.log": "[golden] upload OK (HTTP 201)\nGOLDEN_VERSION=9.9.7\nGOLDEN_SHA256=%s\n" % REAL_SHA}): rc, out = run_gate() if "newest golden baked : 9.9.7" not in out: fails.append("CASE 3 (POSITIVE CONTROL): a real bake log was NOT counted — the gate now " "rejects everything, which would make cases 1 and 2 meaningless") elif REAL_SHA[:12] not in out: fails.append("CASE 3: the gate counted the bake but did not read its sha") else: print("CASE 3 ok: a real bake log counts, and its sha is read and shown") # --- CASE 4: the tree is left exactly as found ---------------------------------------------- post_rc, _ = run_gate() if post_rc != base_rc: fails.append("CASE 4: the gate's verdict changed after the test cleaned up (%d -> %d) — a test " "that leaves the tree different is not a test" % (base_rc, post_rc)) else: print("CASE 4 ok: the tree is unchanged; the gate's verdict is the same as the baseline") if fails: print() for f in fails: print("FAIL: %s" % f) return 1 print("\ngolden-currency gate self-test OK — a directory name alone cannot satisfy it (R-410)") return 0 sys.exit(main())