CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Medium

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

test_verify_authority.shskills/herdr-foreman/tests/

#!/usr/bin/env bash
# Outcome-based tests for skills/herdr-foreman/verify-authority.sh.
#
# Every case points GH_BIN at a fake this harness writes, replaying payloads
# built in the test (rules/testing-standards.md Fixtures — no network, no real
# GitHub session, no binary fixtures).
#
# The harness drops `set -e` to aggregate results, so every fixture-setup
# command is checked explicitly and aborts with a fatal diagnostic on failure
# (rules/error-handling.md aggregate-reporting carve-out).
#
# Covers:
#   1. Own user repo     -> namespace_owner + authorized true.
#   2. Case-folded login -> logins compare case-insensitively.
#   3. Write collaborator-> permission write, authorized FALSE (not ownership).
#   4. Admin collaborator-> permission admin on someone else's repo, still false.
#   5. Org admin         -> authorized true through org membership.
#   6. Org member        -> role member is not ownership.
#   7. Org 404           -> not a member, not an owner, still a verdict, and
#                          SILENT: a non-member is the ordinary case.
#  7b. Org fault         -> a non-404 membership failure is exit 2 and NO
#                          verdict; a fault is not a denial.
#   8. Usage / bad slug  -> exit 1, no verdict.
#   9. gh absent         -> exit 1.
#  9b. gh not logged in  -> exit 1 naming `gh auth login`, before any API call.
#  10. API failure       -> exit 2, never a verdict.
#
# Run: bash skills/herdr-foreman/tests/test_verify_authority.sh
set -uo pipefail

die() { echo "fatal: $*" >&2; exit 2; }
cleanup() { [[ -n "${TMP:-}" ]] && ! rm -rf "$TMP" && echo "warn: could not remove $TMP" >&2; return 0; }
pass() { PASS=$((PASS+1)); }
fail() { FAIL=$((FAIL+1)); echo "  ✗ FAIL: $1" >&2; }

mk_fake_gh() { # <path>
  cat > "$1" <<'FAKE' || die "could not write the fake gh"
#!/usr/bin/env bash
set -uo pipefail
if [[ "${1:-} ${2:-}" == "auth status" ]]; then
  [[ -n "${FAKE_AUTH_ERR:-}" ]] && { printf 'You are not logged into any GitHub hosts.\n' >&2; exit 1; }
  printf 'Logged in to github.com\n'; exit 0
fi
[[ "${1:-}" == "api" ]] || { echo '{"error":"unsupported"}' >&2; exit 2; }
[[ -n "${FAKE_ARGV_FILE:-}" ]] && printf '%s\n' "$*" >> "$FAKE_ARGV_FILE"
case "${2:-}" in
  user)
    [[ -n "${FAKE_USER_ERR:-}" ]] && { printf 'gh: auth required\n' >&2; exit 1; }
    printf '{"login":"%s"}\n' "${FAKE_VIEWER:-jbaruch}"
    ;;
  repos/*)
    [[ -n "${FAKE_REPO_ERR:-}" ]] && { printf 'gh: HTTP 404\n' >&2; exit 1; }
    printf '{"owner":{"login":"%s","type":"%s"},"permissions":{"admin":%s,"maintain":false,"push":%s,"triage":false,"pull":true}}\n' \
      "${FAKE_OWNER:-jbaruch}" "${FAKE_OWNER_TYPE:-User}" "${FAKE_ADMIN:-true}" "${FAKE_PUSH:-true}"
    ;;
  orgs/*/memberships/*)
    [[ -n "${FAKE_ORG_404:-}" ]] && { printf 'gh: HTTP 404: Not Found\n' >&2; exit 1; }
    [[ -n "${FAKE_ORG_FAULT:-}" ]] && { printf 'gh: HTTP 500: server error\n' >&2; exit 1; }
    printf '%s\n' "${FAKE_ORG_ROLE:-member}"
    ;;
  *) echo '{"error":"unsupported path"}' >&2; exit 2 ;;
esac
exit 0
FAKE
  chmod +x "$1" || die "could not chmod the fake gh"
}

run() { # [env...] -- <slug>
  local slug="${!#}"
  RUN_SEQ=$((RUN_SEQ+1))
  OUT="$(env GH_BIN="$FAKE" "${@:1:$#-1}" bash "$SCRIPT" "$slug" 2>"$TMP/err.$RUN_SEQ")"
  RC=$?
  ERRTEXT="$(cat "$TMP/err.$RUN_SEQ")"
}

main() {
  SCRIPT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/verify-authority.sh"
  [[ -f "$SCRIPT" && -r "$SCRIPT" ]] || die "verify-authority.sh not found at $SCRIPT"
  command -v jq >/dev/null 2>&1 || die "jq required for these tests"
  TMP="$(mktemp -d -t foreman-authority-test.XXXXXX)" || die "mktemp failed"
  trap cleanup EXIT
  FAKE="$TMP/gh"; mk_fake_gh "$FAKE"
  FAIL=0; PASS=0; RUN_SEQ=0

  # 1. The operator's own repo.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=jbaruch jbaruch/coding-policy
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '
      .authorized == true and .namespace_owner == true
      and .repo == "jbaruch/coding-policy" and .viewer_permission == "admin"' >/dev/null 2>&1; then
    pass; else fail "own repo: expected authorized true, got RC=$RC OUT=$OUT"; fi

  # 2. GitHub logins are case-insensitive.
  run FAKE_VIEWER=JBaruch FAKE_OWNER=jbaruch jbaruch/coding-policy
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '.authorized == true' >/dev/null 2>&1; then
    pass; else fail "case folding: expected authorized true, got OUT=$OUT"; fi

  # 3. Write access is not ownership (rules/external-repo-contributions.md).
  run FAKE_VIEWER=jbaruch FAKE_OWNER=someoneelse FAKE_ADMIN=false FAKE_PUSH=true someoneelse/thing
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '
      .authorized == false and .viewer_permission == "write"' >/dev/null 2>&1; then
    pass; else fail "collaborator: expected authorized false with write, got OUT=$OUT"; fi

  # 4. Even admin permission on somebody else's repo is not ownership.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=someoneelse FAKE_ADMIN=true someoneelse/thing
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '
      .authorized == false and .viewer_permission == "admin"' >/dev/null 2>&1; then
    pass; else fail "admin collaborator: expected authorized false, got OUT=$OUT"; fi

  # 5. An org the operator administers IS their namespace.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=acme FAKE_OWNER_TYPE=Organization FAKE_ORG_ROLE=admin acme/thing
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '.authorized == true and .owner_type == "Organization"' >/dev/null 2>&1; then
    pass; else fail "org admin: expected authorized true, got OUT=$OUT"; fi

  # 6. Org membership alone is not administering it.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=acme FAKE_OWNER_TYPE=Organization FAKE_ORG_ROLE=member acme/thing
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '.authorized == false' >/dev/null 2>&1; then
    pass; else fail "org member: expected authorized false, got OUT=$OUT"; fi

  # 7. A 404 on the membership endpoint is "not a member", not a failure.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=acme FAKE_OWNER_TYPE=Organization FAKE_ORG_404=1 acme/thing
  if [[ $RC -eq 0 ]] && printf '%s' "$OUT" | jq -e '.authorized == false' >/dev/null 2>&1; then
    pass; else fail "org 404: expected a false verdict, got RC=$RC OUT=$OUT"; fi
  # Not being in an org is the ordinary case, so it must not warn — a warning
  # on every run is one nobody reads by the time it matters.
  if [[ -z "$ERRTEXT" ]]; then
    pass; else fail "org 404: expected no warning, got ERR=$ERRTEXT"; fi

  # 7b. A membership call that fails for any other reason is an unanswered
  # question: exit 2, nothing on stdout, and the diagnostic names the fix.
  run FAKE_VIEWER=jbaruch FAKE_OWNER=acme FAKE_OWNER_TYPE=Organization FAKE_ORG_FAULT=1 acme/thing
  if [[ $RC -eq 2 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "could not read org membership"; then
    pass; else fail "org fault: expected exit 2 and no verdict, got RC=$RC OUT=$OUT ERR=$ERRTEXT"; fi

  # 8. A bare name is not a slug.
  run FAKE_VIEWER=jbaruch coding-policy
  if [[ $RC -eq 1 && -z "$OUT" ]] && printf '%s' "$ERRTEXT" | grep -q "owner"; then
    pass; else fail "bad slug: expected exit 1, got RC=$RC OUT=$OUT"; fi

  # 8b. No argument at all.
  OUT="$(env GH_BIN="$FAKE" bash "$SCRIPT" 2>"$TMP/e8b")"; RC=$?
  if [[ $RC -eq 1 && -z "$OUT" ]] && grep -q "usage:" "$TMP/e8b"; then
    pass; else fail "usage: expected exit 1 with a usage line, got RC=$RC"; fi

  # 9. gh absent.
  OUT="$(env GH_BIN="$TMP/no-such-gh" bash "$SCRIPT" jbaruch/coding-policy 2>"$TMP/e9")"; RC=$?
  if [[ $RC -eq 1 && -z "$OUT" ]] && grep -q "no-such-gh" "$TMP/e9"; then
    pass; else fail "gh absent: expected exit 1 naming it, got RC=$RC"; fi

  # 9b. Not logged in is a precondition (exit 1) with the fix named, and no
  #     API call is made — it must not surface as exit 2 "could not answer".
  ARGVLOG="$TMP/argv.9b"; : > "$ARGVLOG" || die "could not create $ARGVLOG"
  OUT="$(env GH_BIN="$FAKE" FAKE_AUTH_ERR=1 FAKE_ARGV_FILE="$ARGVLOG" bash "$SCRIPT" jbaruch/coding-policy 2>"$TMP/e9b")"; RC=$?
  if [[ $RC -eq 1 && -z "$OUT" && ! -s "$ARGVLOG" ]] && grep -q "auth login" "$TMP/e9b"; then
    pass; else fail "not logged in: expected exit 1 naming gh auth login and no api call, got RC=$RC OUT=$OUT ERR=$(cat "$TMP/e9b") CALLS=$(cat "$ARGVLOG")"; fi

  # 10. An API failure is never a verdict — an unanswerable question must not
  #     read as "not authorized" OR as "authorized".
  run FAKE_REPO_ERR=1 jbaruch/coding-policy
  if [[ $RC -eq 2 && -z "$OUT" ]]; then
    pass; else fail "api failure: expected exit 2 + empty stdout, got RC=$RC OUT=$OUT"; fi

  # 10b. Same for the viewer lookup.
  run FAKE_USER_ERR=1 jbaruch/coding-policy
  if [[ $RC -eq 2 && -z "$OUT" ]]; then
    pass; else fail "user lookup failure: expected exit 2, got RC=$RC OUT=$OUT"; fi

  echo "─────────────────────────────────────────────" >&2
  if [[ $FAIL -gt 0 ]]; then echo "FAILED: ${FAIL} failed, ${PASS} passed" >&2; exit 1; fi
  echo "PASSED: all ${PASS} checks" >&2
}

if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then
  main "$@"
fi

skills

herdr-foreman

tests

__init__.py

fakes.py

test_assign.py

test_attention.py

test_billing.py

test_bounded_run.sh

test_capabilities.py

test_capability_routing.py

test_chronology.py

test_churn.py

test_classify.sh

test_claude_native.py

test_cli.py

test_compose_briefs.sh

test_composer.py

test_composition.py

test_config.py

test_continuity_cli.py

test_cost_report.py

test_diagnostics.py

test_engagement.py

test_entrypoints.py

test_foreman_launcher.sh

test_foreman_queue.py

test_foreman_reset.py

test_foreman_seat.py

test_foreman_tier_check.py

test_freeze.py

test_herdr.py

test_historical.py

test_home.py

test_label_workspaces.sh

test_launch.py

test_legacy_recovery.py

test_lifecycle.py

test_load_set.py

test_measure.py

test_members.py

test_memory.py

test_minimum_adequate.py

test_oracle.py

test_parsers.py

test_partition.py

test_planner.py

test_probe.py

test_provision_worktree.sh

test_prune_remote_branches.sh

test_prune_report_caches.py

test_prune_result.py

test_prune_worktrees.sh

test_recovery_cli.py

test_recovery.py

test_renderable.py

test_report_contract.py

test_report_delivery.py

test_report_gates.py

test_report_verdict.py

test_reset_input_hook.py

test_resolve_gates.sh

test_resolve_policy_paths.py

test_restoration.py

test_retrospective_runtime.py

test_retrospective.py

test_review_package.py

test_role_clear.py

test_roster.sh

test_round_preflight.sh

test_runnable.py

test_scoring.py

test_script_dir_newline.sh

test_seat_holds.py

test_selection.py

test_skill_invocations.sh

test_slice_scope_parity.py

test_specialist_cli.py

test_specialist_delivery.py

test_specialist_recovery.py

test_specialist_retention.py

test_stale_grok_delivery.py

test_start_judge_worker.py

test_state.py

test_successors.py

test_supervision_cli.py

test_supervision_diagnostics.py

test_supervision_gate.py

test_supervision_replay.py

test_supervision.py

test_sweep_worktrees.sh

test_tier_integration.py

test_tiers.py

test_triggers.py

test_typesafe_client.py

test_verdict_gates.py

test_verify_authority.sh

test_wait_report.sh

tier_fixture.py

bounded-run.sh

compose-briefs.sh

config.example.json

foreman-tier-check.py

foreman.sh

label-workspaces.sh

provision-worktree.sh

prune-remote-branches.sh

prune-report-caches.py

prune-worktrees.sh

resolve-gates.sh

resolve-policy-paths.sh

review-package.sh

roster.sh

round-preflight.sh

SKILL.md

start-judge-worker.sh

state-schema.md

sweep-worktrees.sh

verify-authority.sh

wait-report.sh

README.md

tile.json