#!/usr/bin/env python3 # -*- coding: utf-8 -*- """Decoys for scripts/iso_bootstrap_gate.py (R-502). DOCKER-FREE — runs on the CI runner (BusyBox + python3 + git) and on DooPlex alike, and never reaches the real docker. HOW. The gate finds docker with shutil.which, so every case runs the REAL gate as a subprocess with PATH set to ONE temp directory: empty (no docker), or holding a FAKE `docker` written in python with an absolute shebang (so it needs nothing else on PATH — /usr/bin, where the real docker lives on DooPlex, is never on it). The fake answers `image inspect` and `run` per FAKE_DOCKER_MODE, and for `run` reads the STAGED felhom-bootstrap.sh from the `-v :/src:ro` mount, so it can tell the genuine run from the gate's built-in banner decoy. What the fake cannot do is run the harness — that needs root and the image. The harness's power to see a broken banner is proven by the gate itself, in the real container, on every full run (its built-in decoy). This file proves the gate's verdicts: that a blind harness, a failing harness, a harness that checked nothing, and an unrun harness can never read as green. Run: python3 scripts/test_iso_bootstrap_gate.py """ import os import shutil import subprocess import sys import tempfile import unittest HERE = os.path.dirname(os.path.abspath(__file__)) ROOT = os.path.dirname(HERE) GATE = os.path.join(HERE, "iso_bootstrap_gate.py") sys.path.insert(0, HERE) import iso_bootstrap_gate as g # noqa: E402 import repo_gates # noqa: E402 FAKE = r'''#!%(py)s import os, re, sys mode = os.environ.get("FAKE_DOCKER_MODE", "genuine") a = sys.argv[1:] log = os.environ.get("FAKE_DOCKER_LOG") if log: open(log, "a").write(" ".join(a) + "\n") if a[:2] == ["image", "inspect"]: sys.exit(1 if mode == "no-image" else 0) if a[:1] == ["rm"]: sys.exit(0) if a[:1] != ["run"]: sys.exit(3) if mode == "daemon-error": print("docker: Error response from daemon: something broke."); sys.exit(125) src = [x for x in a if x.endswith(":/src:ro")][0][:-len(":/src:ro")] mutant = "R-502 planted decoy" in open(os.path.join(src, "felhom-bootstrap.sh"), encoding="utf-8").read() oks = "".join(" ok: check %%d\n" %% i for i in range(60)) if mode == "fails" or (mutant and mode != "blind"): print(oks + " FAIL: R-496: banner painted to the console seam\nSOME TESTS FAILED"); sys.exit(1) if mode == "hollow": print("ALL BOOTSTRAP-MODE TESTS PASSED"); sys.exit(0) print(oks + "ALL BOOTSTRAP-MODE TESTS PASSED"); sys.exit(0) ''' def run_gate(mode=None): """Run the real gate. mode None = no docker on PATH at all.""" d = tempfile.mkdtemp(prefix="iso-gate-test-") try: log = os.path.join(d, "calls.log") if mode is not None: p = os.path.join(d, "docker") with open(p, "w") as f: f.write(FAKE % {"py": sys.executable}) os.chmod(p, 0o755) env = {"PATH": d, "FAKE_DOCKER_MODE": mode or "", "FAKE_DOCKER_LOG": log, "HOME": d, "PYTHONDONTWRITEBYTECODE": "1"} r = subprocess.run([sys.executable, GATE], cwd=ROOT, env=env, stdout=subprocess.PIPE, stderr=subprocess.STDOUT) calls = "" if os.path.exists(log): with open(log) as f: calls = f.read() return r.returncode, r.stdout.decode("utf-8", "replace"), calls finally: shutil.rmtree(d, ignore_errors=True) class IsoBootstrapGateTest(unittest.TestCase): def test_genuine_passes_and_runs_the_decoy_too(self): rc, out, calls = run_gate("genuine") self.assertEqual(rc, 0, out) self.assertIn("built-in decoy convicted", out) self.assertEqual(calls.count("run "), 2, "want the genuine run AND the decoy run:\n" + calls) self.assertIn("--network none", calls) def test_blind_harness_convicts(self): # The harness passes a bootstrap whose banner never paints: the R-496 shape. Must be 1. rc, out, _ = run_gate("blind") self.assertEqual(rc, 1, out) self.assertIn("instrument is blind", out) def test_failing_harness_convicts(self): rc, out, calls = run_gate("fails") self.assertEqual(rc, 1, out) self.assertIn("FAIL: R-496: banner painted", out) self.assertEqual(calls.count("run "), 1) def test_pass_line_without_checks_convicts(self): rc, out, _ = run_gate("hollow") self.assertEqual(rc, 1, out) self.assertIn("proved nothing", out) def test_no_docker_is_not_checked(self): rc, out, _ = run_gate(None) self.assertEqual(rc, 2, out) self.assertIn("NOT CHECKED", out) def test_no_image_is_not_checked(self): rc, out, calls = run_gate("no-image") self.assertEqual(rc, 2, out) self.assertIn("NOT CHECKED", out) self.assertNotIn("run ", calls) def test_docker_error_is_not_checked(self): rc, out, _ = run_gate("daemon-error") self.assertEqual(rc, 2, out) def test_decoy_plants_on_the_real_bootstrap(self): # The built-in decoy's anchor must exist ONCE in the real script, and the plant must apply. d = tempfile.mkdtemp() try: self.assertIsNone(g.stage(d, mutate=True)) with open(os.path.join(d, "felhom-bootstrap.sh"), encoding="utf-8") as f: text = f.read() self.assertIn("R-502 planted decoy", text) for _src, rel in g.INPUTS: self.assertTrue(os.path.exists(os.path.join(d, rel)), rel) finally: shutil.rmtree(d, ignore_errors=True) def test_registered_full_runs_only(self): # Decision 147: never in --fast (pre-push hook and CI both run --fast; CI has no docker). rows = [r for r in repo_gates.GATES if r[0] == "iso-bootstrap"] self.assertEqual(len(rows), 1, "iso-bootstrap must be registered once in repo_gates.GATES") self.assertTrue(rows[0][1].endswith("iso_bootstrap_gate.py")) self.assertIs(rows[0][3], False, "iso-bootstrap must be fast=False (full runs only)") self.assertIs(rows[0][4], False, "iso-bootstrap must not be exemptible") if __name__ == "__main__": unittest.main(verbosity=2)