diff --git a/forgetest/forgetest/manifest.py b/forgetest/forgetest/manifest.py index 8cccdb3..4942ca3 100644 --- a/forgetest/forgetest/manifest.py +++ b/forgetest/forgetest/manifest.py @@ -94,10 +94,27 @@ NON_BEHAVIORAL = [ ("*", ".env.example"), ("forgectrl", "tools/**"), # host-side dev tools (panel dev server) ("forgectrl", "examples/**"), # clients of the remote API, run on another computer + # forgeext's recipe installs the binary and its init script, and nothing of these: the official + # packages carry their own acceptance artifact, and the author's kit and host tools run off the image. + ("forgeext", "packages/**"), + ("forgeext", "sdk/**"), + ("forgeext", "template/**"), + ("forgeext", "tools/**"), +] + + +# Paths the list above would take out that are behavior all the same: forgectrl embeds its advisory +# documents in the binary, serves them, and records the operator's consent to a document by its hash, so +# an edited advisory is a changed consent and must move every fingerprint that covers it. +BEHAVIORAL = [ + ("forgectrl", "docs/advisories/**"), ] def non_behavioral(comp, path, allow=NON_BEHAVIORAL): + for c, pat in BEHAVIORAL: + if c == comp and glob_to_regex(pat).match(path): + return False for c, pat in allow: if c in ("*", comp) and glob_to_regex(pat).match(path): return True diff --git a/forgetest/tests/test_manifest.py b/forgetest/tests/test_manifest.py index 87e9c33..6026a53 100644 --- a/forgetest/tests/test_manifest.py +++ b/forgetest/tests/test_manifest.py @@ -132,6 +132,18 @@ class CoverageReportTests(unittest.TestCase): t.covers)) self.assertTrue(m.non_behavioral("forgectrl", "tools/devserver.py")) self.assertFalse(m.non_behavioral("grblhal-glowforge", "tools/devserver.py")) + # forgeext's image content is its binary and init script: the packages, the kit, the template and + # the host tools are not, and the host's sources are + for path in ("packages/alignment/ui/index.html", "sdk/js/ffx-bridge.js", "template/manifest.json", + "tools/ffx"): + self.assertTrue(m.non_behavioral("forgeext", path), path) + for path in ("src/api.c", "init/forgeext.init", "CMakeLists.txt"): + self.assertFalse(m.non_behavioral("forgeext", path), path) + # an advisory is a document forgectrl serves and records consent to by its hash: behavior, though + # it is Markdown under docs/ + self.assertFalse(m.non_behavioral("forgectrl", "docs/advisories/extensions.md")) + self.assertTrue(m.non_behavioral("forgectrl", "docs/SERVICES.md")) + self.assertTrue(m.non_behavioral("grblhal-glowforge", "docs/advisories/x.md")) def test_an_entry_that_selects_nothing_is_reported(self): man = helpers.make_manifest()