This commit is contained in:
@@ -0,0 +1,132 @@
|
||||
#!/usr/bin/env python3
|
||||
# SPDX-License-Identifier: GPL-3.0-or-later
|
||||
"""Mutation guardrails for Phase-1.0S shsrv/hbldr provenance."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import importlib.util
|
||||
from pathlib import Path
|
||||
import sys
|
||||
|
||||
|
||||
def load(path: Path):
|
||||
spec = importlib.util.spec_from_file_location("phase10s", path)
|
||||
assert spec and spec.loader
|
||||
module = importlib.util.module_from_spec(spec)
|
||||
sys.modules[spec.name] = module
|
||||
spec.loader.exec_module(module)
|
||||
return module
|
||||
|
||||
|
||||
def require(value: bool, message: str) -> None:
|
||||
if not value:
|
||||
raise RuntimeError(message)
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser()
|
||||
parser.add_argument("--root", type=Path, required=True)
|
||||
args = parser.parse_args()
|
||||
root = args.root.resolve()
|
||||
validator = load(root / "tools/validate_retroarch_phase10s.py")
|
||||
record = validator.load_json(
|
||||
root / "manifests/retroarch/phase-1.0s-launcher-provenance.json")
|
||||
cases = []
|
||||
|
||||
def case(name):
|
||||
def register(function):
|
||||
cases.append((name, function))
|
||||
return function
|
||||
return register
|
||||
|
||||
@case("01 authorizations remain false")
|
||||
def _(): require(validator.all_false(record["authorizations"], validator.AUTHORIZATION_FIELDS), "authority active")
|
||||
|
||||
@case("02 target build authorization fails")
|
||||
def _():
|
||||
value = dict(record["authorizations"]); value["target_build_authorized"] = True
|
||||
require(not validator.all_false(value, validator.AUTHORIZATION_FIELDS), "target build allowed")
|
||||
|
||||
@case("03 device and remount authorization fail")
|
||||
def _():
|
||||
value = dict(record["authorizations"]); value["system_remount_authorized"] = True
|
||||
require(not validator.all_false(value, validator.AUTHORIZATION_FIELDS), "remount allowed")
|
||||
|
||||
@case("04 source acquisition remains official and static")
|
||||
def _(): require(validator.acquisition_is_bounded(record["source_acquisition"]), "scope rejected")
|
||||
|
||||
@case("05 executed upstream source fails")
|
||||
def _():
|
||||
value = dict(record["source_acquisition"]); value["downloaded_code_executed"] = True
|
||||
require(not validator.acquisition_is_bounded(value), "execution accepted")
|
||||
|
||||
@case("06 deployed identity remains unproven")
|
||||
def _(): require(validator.deployed_identity_is_unproven(record["deployed_identity"]), "identity promoted")
|
||||
|
||||
@case("07 official upstream is not deployed identity")
|
||||
def _():
|
||||
value = dict(record["deployed_identity"]); value["classification"] = "EXACT_USED"
|
||||
require(not validator.deployed_identity_is_unproven(value), "upstream promoted")
|
||||
|
||||
@case("08 launch callgraph is exact")
|
||||
def _(): require(validator.callgraph_is_exact(record["launch_callgraph"]), "callgraph rejected")
|
||||
|
||||
@case("09 BigApp context difference is source proven")
|
||||
def _(): require(validator.context_difference_is_source_only(record["launch_context"]), "context rejected")
|
||||
|
||||
@case("10 VideoOut permission cannot be promoted")
|
||||
def _():
|
||||
value = dict(record["launch_context"]); value["videoout_permission_proven"] = True
|
||||
require(not validator.context_difference_is_source_only(value), "VideoOut promoted")
|
||||
|
||||
@case("11 firmware runtime cannot be promoted")
|
||||
def _():
|
||||
value = dict(record["launch_context"]); value["firmware_9_60_runtime_proven"] = True
|
||||
require(not validator.context_difference_is_source_only(value), "runtime promoted")
|
||||
|
||||
@case("12 target ELF requires a device path")
|
||||
def _(): require(record["effects"]["target_elf_must_exist_on_device"] is True, "staging hidden")
|
||||
|
||||
@case("13 current system-ex mutation remains blocker")
|
||||
def _(): require(validator.effects_block_device_use(record["effects"]), "effects rejected")
|
||||
|
||||
@case("14 fake-app write cannot be suppressed")
|
||||
def _():
|
||||
value = dict(record["effects"]); value["v019_persistent_fakeapp_creation_possible"] = False
|
||||
require(not validator.effects_block_device_use(value), "persistent write hidden")
|
||||
|
||||
@case("15 BigApp termination remains visible")
|
||||
def _(): require(record["effects"]["running_bigapp_may_be_killed"] is True, "termination hidden")
|
||||
|
||||
@case("16 hard deadline remains absent")
|
||||
def _(): require(record["effects"]["hard_deadline_present"] is False, "deadline invented")
|
||||
|
||||
@case("17 root cause remains a candidate only")
|
||||
def _(): require(record["decision"]["root_cause_resolved"] is False, "root cause invented")
|
||||
|
||||
@case("18 existing hbldr route remains blocked")
|
||||
def _(): require(validator.decision_is_blocked(record["decision"]), "decision rejected")
|
||||
|
||||
@case("19 no target or device action occurred")
|
||||
def _(): require(all(value is False for value in record["performed_actions"].values()), "action occurred")
|
||||
|
||||
@case("20 host source audit is not hardware proof")
|
||||
def _(): require(record["tests"]["hardware_claim_from_host_test"] is False, "host audit promoted")
|
||||
|
||||
failures = []
|
||||
for name, function in cases:
|
||||
try:
|
||||
function()
|
||||
print(f"PASS {name}")
|
||||
except Exception as error: # noqa: BLE001 - mutation harness
|
||||
failures.append(f"{name}: {error}")
|
||||
print(f"FAIL {name}: {error}")
|
||||
if failures:
|
||||
return 1
|
||||
print(f"Phase-1.0S guardrails passed: {len(cases)}")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Reference in New Issue
Block a user