From b7e7c0fb2c6e63075f1f8ce39002e0865831b5f2 Mon Sep 17 00:00:00 2001 From: ScottW514 Date: Tue, 22 Sep 2026 21:41:30 -0400 Subject: [PATCH] Manifest: the advisories are behavior, and forgeext's kit and packages are not forgectrl embeds its advisory documents in the binary, serves them, and records the operator's consent to one by its hash, so an edited advisory is a changed consent. They are Markdown under docs/, which the non-behavioral list takes out of every fingerprint, and that left setup.extensions-consent's covers entry for docs/advisories/extensions.md selecting nothing: the enforced coverage lint fails on it (exit 1 on the dev image's manifest of 20260922225653), and an edited advisory moved no fingerprint at all. A BEHAVIORAL list now keeps forgectrl's docs/advisories/** in, ahead of the non-behavioral one. forgeext's recipe installs the binary and its init script and nothing else, so packages/ (the official packages, which carry their own acceptance artifact), sdk/ (the author's kit), template/ and tools/ are non-behavioral for the image: without that, an edit to the alignment page or the kit would make every exthost test stale on the next image. Proof: test_manifest passes its 25 cases, the new ones among them; the enforced coverage lint on the dev image's manifest of 20260922225653 exits 0 with no empty entry and nothing uncovered, where it exited 1 before. The whole forgetest suite ran its 451 tests; one, test_cloud_suite's test_pause_resume_passes_on_the_machines_lines, errored under the suite's load and passes 16 runs of 16 alone, at HEAD and on this tree alike: it replays a print against timed hooks. --- forgetest/forgetest/manifest.py | 17 +++++++++++++++++ forgetest/tests/test_manifest.py | 12 ++++++++++++ 2 files changed, 29 insertions(+) diff --git a/forgetest/forgetest/manifest.py b/forgetest/forgetest/manifest.py index 8cccdb3..4942ca3 100644 --- a/forgetest/forgetest/manifest.py +++ b/forgetest/forgetest/manifest.py @@ -94,10 +94,27 @@ NON_BEHAVIORAL = [ ("*", ".env.example"), ("forgectrl", "tools/**"), # host-side dev tools (panel dev server) ("forgectrl", "examples/**"), # clients of the remote API, run on another computer + # forgeext's recipe installs the binary and its init script, and nothing of these: the official + # packages carry their own acceptance artifact, and the author's kit and host tools run off the image. + ("forgeext", "packages/**"), + ("forgeext", "sdk/**"), + ("forgeext", "template/**"), + ("forgeext", "tools/**"), +] + + +# Paths the list above would take out that are behavior all the same: forgectrl embeds its advisory +# documents in the binary, serves them, and records the operator's consent to a document by its hash, so +# an edited advisory is a changed consent and must move every fingerprint that covers it. +BEHAVIORAL = [ + ("forgectrl", "docs/advisories/**"), ] def non_behavioral(comp, path, allow=NON_BEHAVIORAL): + for c, pat in BEHAVIORAL: + if c == comp and glob_to_regex(pat).match(path): + return False for c, pat in allow: if c in ("*", comp) and glob_to_regex(pat).match(path): return True diff --git a/forgetest/tests/test_manifest.py b/forgetest/tests/test_manifest.py index 87e9c33..6026a53 100644 --- a/forgetest/tests/test_manifest.py +++ b/forgetest/tests/test_manifest.py @@ -132,6 +132,18 @@ class CoverageReportTests(unittest.TestCase): t.covers)) self.assertTrue(m.non_behavioral("forgectrl", "tools/devserver.py")) self.assertFalse(m.non_behavioral("grblhal-glowforge", "tools/devserver.py")) + # forgeext's image content is its binary and init script: the packages, the kit, the template and + # the host tools are not, and the host's sources are + for path in ("packages/alignment/ui/index.html", "sdk/js/ffx-bridge.js", "template/manifest.json", + "tools/ffx"): + self.assertTrue(m.non_behavioral("forgeext", path), path) + for path in ("src/api.c", "init/forgeext.init", "CMakeLists.txt"): + self.assertFalse(m.non_behavioral("forgeext", path), path) + # an advisory is a document forgectrl serves and records consent to by its hash: behavior, though + # it is Markdown under docs/ + self.assertFalse(m.non_behavioral("forgectrl", "docs/advisories/extensions.md")) + self.assertTrue(m.non_behavioral("forgectrl", "docs/SERVICES.md")) + self.assertTrue(m.non_behavioral("grblhal-glowforge", "docs/advisories/x.md")) def test_an_entry_that_selects_nothing_is_reported(self): man = helpers.make_manifest()