use crate::provider_v3::ComponentKind;
use serde_json::Value;
use crate::harness_runtime::facts::Harness;
pub const BLOCK: &str = "native_surfaces";
const SHAPES: [&str; 2] = ["file", "directory"];
fn credentials_are_disclaimed(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
let mut named = Vec::new();
for block in ["surfaces", "declined"] {
let Some(rows) = baseline
.get(BLOCK)
.and_then(|found| found.get(block))
.and_then(Value::as_array)
else {
continue;
};
for row in rows {
let Some(path) = row.get("path").and_then(Value::as_str) else {
continue;
};
let lowered = path.to_lowercase();
if ["credential", "auth.json", "oauth", "token"]
.iter()
.any(|tell| lowered.contains(tell))
{
named.push(path.to_owned());
}
}
}
for path in named {
let leaf = path.rsplit('/').next().unwrap_or(&path);
if !harness.never_touch.contains(&leaf) {
found.push(format!(
"{path:?} reads as a credentials file and {} does not disclaim it. \
never_captured is the control directory plus never_touch, and a slot \
holding a product's credentials would put them on disk in a second \
place. Add {leaf:?} to never_touch, or say in the row why it is not one.",
harness.provider_id
));
}
}
}
fn never_touch_is_disclaimed(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
let empty = Vec::new();
for entry in baseline
.get("never_touch")
.and_then(Value::as_array)
.unwrap_or(&empty)
{
let Some(name) = entry.as_str() else {
found.push(format!("never_touch member {entry} is not a string"));
continue;
};
if harness.native_namespaces.contains(&name) {
found.push(format!(
"{name:?} is marked never_touch by the baseline but claimed as ours"
));
}
if !harness.never_touch.contains(&name) {
found.push(format!(
"{name:?} is marked never_touch by the baseline and {} does not \
disclaim it",
harness.provider_id
));
}
}
for name in harness.never_touch {
if harness.native_namespaces.contains(name) {
found.push(format!("{name:?} is claimed and disclaimed"));
}
}
}
fn the_measured_format_names_an_owned_file(
harness: &Harness,
block: &serde_json::Map<String, Value>,
found: &mut Vec<String>,
) {
let Some(format) = block.get("configuration_format") else {
found.push(format!(
"{BLOCK} records no configuration_format, so what a file at the owned \
configuration path *is* -- its grammar, whether it takes comments, whether a \
vendor publishes a schema -- is a measurement nobody kept"
));
return;
};
let Some(named) = format.get("file").and_then(Value::as_str) else {
found.push(format!("{BLOCK}.configuration_format names no file"));
return;
};
if !harness.native_namespaces.contains(&named) {
found.push(format!(
"{BLOCK}.configuration_format measures {named:?}, which is not in \
native_namespaces -- a grammar recorded for a file this build does not own is a \
measurement about somebody else's"
));
}
for key in ["grammar", "note"] {
if format
.get(key)
.and_then(Value::as_str)
.is_none_or(str::is_empty)
{
found.push(format!("{BLOCK}.configuration_format has no {key}"));
}
}
if format
.get("accepts_comments")
.and_then(Value::as_bool)
.is_none()
{
found.push(format!(
"{BLOCK}.configuration_format does not say whether the parser accepts comments, \
and absent is not the same answer as false"
));
}
}
fn owned_paths_fold_together(harness: &Harness, found: &mut Vec<String>) {
let mut folded: std::collections::BTreeMap<String, &str> = std::collections::BTreeMap::new();
let owned = harness.native_namespaces.iter().copied().chain(
harness
.scoped_projections
.iter()
.flat_map(|scope| scope.native_namespaces.iter().copied()),
);
for name in owned {
if let Some(other) = folded.insert(name.to_lowercase(), name)
&& other != name
{
found.push(format!(
"{name:?} and {other:?} are both owned and differ only in case, so they are one \
path on macOS and Windows and two on Linux"
));
}
}
}
fn a_scope_is_distinguishable_from_the_global_target(harness: &Harness, found: &mut Vec<String>) {
for scoped in harness.scoped_projections {
let same = scoped.native_namespaces.len() == harness.native_namespaces.len()
&& scoped
.native_namespaces
.iter()
.all(|name| harness.native_namespaces.contains(name));
if same {
found.push(format!(
"the {} scope owns exactly the namespaces the global target owns, so a managed global target reads back as scoped and `status` answers about the wrong inventory. Declare what the scope's own root holds.",
scoped.target_scope.as_str()
));
}
}
}
fn policy_is_not_owned(harness: &Harness, found: &mut Vec<String>) {
let owned: Vec<&str> = harness
.native_namespaces
.iter()
.copied()
.chain(
harness
.scoped_projections
.iter()
.flat_map(|scope| scope.native_namespaces.iter().copied()),
)
.collect();
for name in owned {
let leaf = name.rsplit('/').next().unwrap_or(name);
if leaf.starts_with("managed") || leaf.ends_with(".sig.json") {
found.push(format!(
"{name:?} is declared in native_namespaces and reads as an \
administrator's policy or the signature over one; owning it \
means `remove` deletes it, which on a managed machine leaves \
a signature with nothing to verify"
));
}
}
}
fn owned_rows<'a>(
harness: &Harness,
block: &'a Value,
) -> Vec<(&'a Value, &'static [&'static str])> {
let mut rows: Vec<(&Value, &'static [&'static str])> = Vec::new();
if let Some(global) = block.get("surfaces").and_then(Value::as_array) {
rows.extend(global.iter().map(|row| (row, harness.native_namespaces)));
}
for scope in block
.get("scoped")
.and_then(Value::as_array)
.map_or(&[][..], Vec::as_slice)
{
let Some(named) = scope.get("target_scope").and_then(Value::as_str) else {
continue;
};
let Some(declared) = harness
.scoped_projections
.iter()
.find(|scoped| scoped.target_scope.as_str() == named)
else {
continue;
};
if let Some(entries) = scope.get("surfaces").and_then(Value::as_array) {
rows.extend(entries.iter().map(|row| (row, declared.native_namespaces)));
}
}
rows
}
fn silent_about_routing_nothing(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
let Some(block) = baseline.get(BLOCK) else {
return;
};
for (row, owned) in owned_rows(harness, block) {
let Some(path) = row.get("path").and_then(Value::as_str) else {
continue;
};
if !owned.contains(&path) {
continue;
}
let routes = row
.get("kinds")
.and_then(Value::as_array)
.is_some_and(|kinds| !kinds.is_empty());
let explained = ["note", "reason"].iter().any(|key| {
row.get(*key)
.and_then(Value::as_str)
.is_some_and(|text| !text.trim().is_empty())
});
if !routes && !explained {
found.push(format!(
"{path:?} is owned and routes no kind, and the row says nothing about why. \
That is allowed -- being silent about it is not, because the next reader \
re-derives the answer, and the consumer has already asked about two of \
these. Add a note."
));
}
}
}
fn the_home_and_what_moves_it(
harness: &Harness,
block: &serde_json::Map<String, Value>,
found: &mut Vec<String>,
) {
match block.get("config_home_env").and_then(Value::as_str) {
Some(name) if name == harness.config_home_env => {}
Some(name) => found.push(format!(
"{BLOCK}.config_home_env is {name:?} and the declaration says {:?}",
harness.config_home_env
)),
None => found.push(format!(
"{BLOCK} records no config_home_env, so the variable this build sets \
on a launched product is a value nothing checks"
)),
}
match block.get("config_home_env_note").and_then(Value::as_str) {
Some(note) if !note.is_empty() => {}
_ => found.push(format!(
"{BLOCK}.config_home_env carries no note saying how it was \
established; a variable name is a claim about a product"
)),
}
match (
harness.config_home_note,
block.get("config_home_note").and_then(Value::as_str),
) {
("", None) => {}
(declared, Some(recorded)) if declared == recorded => {}
("", Some(recorded)) => found.push(format!(
"{BLOCK}.config_home_note records {recorded:?} and the declaration \
carries none, so a condition a person is told about is one this \
build does not state"
)),
(declared, None) => found.push(format!(
"the declaration says the home is conditional ({declared:?}) and \
{BLOCK} records no config_home_note saying how that was measured"
)),
(declared, Some(recorded)) => found.push(format!(
"{BLOCK}.config_home_note is {recorded:?} and the declaration says \
{declared:?}"
)),
}
match block.get("config_home").and_then(Value::as_str) {
Some(home) if home == harness.documented_config_home => {}
Some(home) => found.push(format!(
"{BLOCK}.config_home is {home:?} and the declaration says {:?}",
harness.documented_config_home
)),
None => found.push(format!("{BLOCK}.config_home is missing")),
}
}
struct Owned<'a> {
path: &'a str,
kinds: Vec<&'a str>,
}
fn owned_surfaces<'a>(rows: &'a [Value], found: &mut Vec<String>) -> Vec<Owned<'a>> {
let mut owned: Vec<Owned<'a>> = Vec::new();
for (index, row) in rows.iter().enumerate() {
let Some(path) = row.get("path").and_then(Value::as_str) else {
found.push(format!("{BLOCK}.surfaces[{index}] has no path"));
continue;
};
if owned.iter().any(|seen| seen.path == path) {
found.push(format!("{path} is listed twice among the owned surfaces"));
}
match row.get("source").and_then(Value::as_str) {
Some(source) if !source.is_empty() => {}
_ => found.push(format!(
"{path} is owned and cites no source; a surface nobody can \
source is not owned"
)),
}
match row.get("shape").and_then(Value::as_str) {
Some(shape) if SHAPES.contains(&shape) => {}
other => found.push(format!(
"{path} has shape {other:?}, which is not one of {SHAPES:?}"
)),
}
let Some(rows) = row.get("kinds").and_then(Value::as_array) else {
found.push(format!(
"{path} has no kinds array; a surface that routes no component \
kind says so with an empty one"
));
continue;
};
let mut kinds = Vec::new();
for kind in rows {
let Some(kind) = kind.as_str() else {
found.push(format!("{path} names a kind that is not a string"));
continue;
};
if ComponentKind::parse(kind).is_none() {
found.push(format!(
"{path} names {kind:?}, which is not a component kind"
));
continue;
}
kinds.push(kind);
}
owned.push(Owned { path, kinds });
}
owned
}
fn every_projection_names_where_it_lands(
harness: &Harness,
block: &serde_json::Map<String, Value>,
owned: &[Owned<'_>],
found: &mut Vec<String>,
) {
let basis = block.get("projection_basis").and_then(Value::as_object);
let declared: Vec<&str> = harness
.projection_kinds
.iter()
.map(|kind| kind.as_str())
.filter(|kind| *kind != "native_files")
.collect();
let Some(basis) = basis else {
if !declared.is_empty() {
found.push(format!(
"{} declares {declared:?} and {BLOCK} has no projection_basis, so \
nothing says where a package of that family would land",
harness.provider_id
));
}
return;
};
for kind in &declared {
let Some(path) = basis.get(*kind).and_then(Value::as_str) else {
found.push(format!(
"{kind} is a declared projection and projection_basis names no surface \
for it; a package family with nowhere to unpack is a promise nothing \
can keep"
));
continue;
};
if !owned.iter().any(|surface| surface.path == path) {
found.push(format!(
"{kind} is declared to land in {path:?}, which this harness does not own"
));
}
}
for (kind, _) in basis {
if !declared.contains(&kind.as_str()) {
found.push(format!(
"projection_basis names {kind} and the declaration does not, so the \
basis is describing a family this provider does not offer"
));
}
}
}
fn against_declaration(harness: &Harness, owned: &[Owned<'_>], found: &mut Vec<String>) {
for namespace in harness.native_namespaces {
if !owned.iter().any(|surface| surface.path == *namespace) {
found.push(format!(
"{namespace} is declared in native_namespaces and is not in {BLOCK}; \
either the vendor documents it and the baseline should say where, \
or nothing does and it should not be owned"
));
}
}
for surface in owned {
if !harness.native_namespaces.contains(&surface.path) {
found.push(format!(
"{} is a documented surface and is not declared in native_namespaces",
surface.path
));
}
}
let mut routed: Vec<&str> = Vec::new();
for surface in owned {
for kind in &surface.kinds {
if routed.contains(kind) {
found.push(format!(
"{kind} is routed by more than one surface, the second being {}",
surface.path
));
}
routed.push(kind);
}
}
for kind in harness.component_kinds {
if !routed.contains(&kind.as_str()) {
found.push(format!(
"{} is declared and no owned surface routes it; a declared kind is \
a promise of a rollback",
kind.as_str()
));
}
}
for kind in &routed {
if !harness
.component_kinds
.iter()
.any(|declared| declared.as_str() == *kind)
{
found.push(format!(
"{kind} has an owned surface and is not declared, so a consumer \
that compiles one is refused"
));
}
}
}
fn against_scope(
declared: &crate::harness_runtime::facts::Scoped,
owned: &[Owned<'_>],
named: &str,
found: &mut Vec<String>,
) {
for namespace in declared.native_namespaces {
if !owned.iter().any(|surface| surface.path == *namespace) {
found.push(format!(
"{namespace} is declared for the {named} scope and is not in {BLOCK}"
));
}
}
let mut routed: Vec<&str> = Vec::new();
for surface in owned {
if !declared.native_namespaces.contains(&surface.path) {
found.push(format!(
"{} is sourced for the {named} scope and is not declared",
surface.path
));
}
for kind in &surface.kinds {
routed.push(kind);
}
}
for kind in declared.component_kinds {
if !routed.contains(&kind.as_str()) {
found.push(format!(
"{} is declared for the {named} scope and no owned surface routes it",
kind.as_str()
));
}
}
for kind in &routed {
if !declared
.component_kinds
.iter()
.any(|held| held.as_str() == *kind)
{
found.push(format!(
"{kind} has a surface in the {named} scope and is not declared there"
));
}
}
}
fn declined_rows(harness: &Harness, rows: &[Value], owned: &[Owned<'_>], found: &mut Vec<String>) {
declined_rows_in(harness.native_namespaces, rows, owned, found);
}
fn declined_rows_in(
namespaces: &[&str],
rows: &[Value],
owned: &[Owned<'_>],
found: &mut Vec<String>,
) {
for (index, row) in rows.iter().enumerate() {
let Some(path) = row.get("path").and_then(Value::as_str) else {
found.push(format!("{BLOCK}.declined[{index}] has no path"));
continue;
};
if namespaces.contains(&path) {
found.push(format!("{path} is declined and owned at the same time"));
}
if owned.iter().any(|surface| surface.path == path) {
found.push(format!("{path} is in both surfaces and declined"));
}
for key in ["reason", "source"] {
match row.get(key).and_then(Value::as_str) {
Some(text) if !text.is_empty() => {}
_ => found.push(format!("{path} is declined and carries no {key}")),
}
}
}
}
fn control_state_is_recorded(harness: &Harness, rows: &[Value], found: &mut Vec<String>) {
for own in [harness.control_directory, harness.state_file] {
if !rows
.iter()
.any(|row| row.get("path").and_then(Value::as_str) == Some(own))
{
found.push(format!(
"{own} is this provider's own control state and {BLOCK}.declined \
does not record it, so a reader has to open the file to learn \
it is not a surface"
));
}
}
}
fn rooted_elsewhere(baseline: &Value, found: &mut Vec<String>) {
let mut check = |path: &str, whose: &str| {
if path.starts_with('~') || path.starts_with('/') {
found.push(format!(
"{whose} records {path:?}, which is relative to a root this \
provider never evaluates against; every recorded path \
is relative to the target"
));
}
};
if let Some(names) = baseline.get("never_touch").and_then(Value::as_array) {
for name in names.iter().filter_map(Value::as_str) {
check(name, "never_touch");
}
}
let Some(block) = baseline.get(BLOCK).and_then(Value::as_object) else {
return;
};
for list in ["surfaces", "declined"] {
let Some(rows) = block.get(list).and_then(Value::as_array) else {
continue;
};
for row in rows {
if let Some(path) = row.get("path").and_then(Value::as_str) {
check(path, &format!("{BLOCK}.{list}"));
}
}
}
}
fn shares_a_name_with_the_protocol(baseline: &Value, found: &mut Vec<String>) {
const SCHEMA: &str = include_str!("../../provider-kit/v3/provider-info.schema.json");
let Ok(schema) = serde_json::from_str::<Value>(SCHEMA) else {
found.push(
"the kit's provider-info schema is unreadable, so no baseline name could be \
checked against it -- this guard measured nothing"
.to_owned(),
);
return;
};
let Some(properties) = schema.get("properties").and_then(Value::as_object) else {
found.push(
"the kit's provider-info schema has no properties object, so no name could be \
checked against it -- this guard measured nothing"
.to_owned(),
);
return;
};
let Some(keys) = baseline.as_object() else {
found.push("the baseline is not an object, so its keys could not be read".to_owned());
return;
};
for name in keys.keys() {
if properties.contains_key(name) {
found.push(format!(
"the baseline key {name:?} is also a provider-info field. A baseline records \
what the vendor does and provider-info declares what this provider does, so \
one word on two axes will be bound together by somebody. Rename the baseline \
key -- product_{name} reads correctly -- rather than documenting the \
collision."
));
}
}
}
fn writes_where_nothing_is_routed(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
let Some(rows) = baseline
.get(BLOCK)
.and_then(|block| block.get("surfaces"))
.and_then(Value::as_array)
else {
return;
};
for (embedded, _) in harness.embedded_setups {
let Some((_, relative)) = embedded.split_once("/home/") else {
continue;
};
let mut owner: Option<(&str, usize)> = None;
for row in rows {
let Some(path) = row.get("path").and_then(Value::as_str) else {
continue;
};
let covered = relative == path
|| relative
.strip_prefix(path)
.is_some_and(|rest| rest.starts_with('/'));
if covered && owner.is_none_or(|(_, len)| path.len() > len) {
owner = Some((path, path.len()));
}
}
let Some((path, _)) = owner else {
found.push(format!(
"the setup file {relative:?} lands on no surface {BLOCK} records, so \
nothing says what it is or where it was read from"
));
continue;
};
let routes = rows
.iter()
.find(|row| row.get("path").and_then(Value::as_str) == Some(path))
.and_then(|row| row.get("kinds"))
.and_then(Value::as_array)
.is_some_and(|kinds| !kinds.is_empty());
if routes {
continue;
}
let reached_by = rows
.iter()
.find(|row| row.get("path").and_then(Value::as_str) == Some(path))
.and_then(|row| row.get("reached_by"))
.and_then(Value::as_str);
let Some(pointer) = reached_by else {
found.push(format!(
"the setup file {relative:?} lands in {path:?}, which routes no kind. Either \
the kind belongs on this row rather than on a neighbour, or these bytes are \
being written somewhere the product reads nothing from."
));
continue;
};
let setup = embedded.split_once("/home/").map_or("", |(id, _)| id);
let wanted = format!("{setup}/home/{pointer}");
let points_at_it = harness
.embedded_setups
.iter()
.find(|(name, _)| *name == wanted)
.is_some_and(|(_, body)| String::from_utf8_lossy(body).contains(relative));
if !points_at_it {
found.push(format!(
"{path:?} says it is reached by {pointer:?}, and the setup file \
{relative:?} is not named in it. A surface that routes no kind is read \
only through the pointer that names it, so a pointer that is claimed \
and missing leaves these bytes inert while the row reads as routed."
));
}
}
}
fn evidence_is_recorded(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
const ALLOWED: [&str; 3] = ["ran", "bytes", "page"];
let Some(block) = baseline.get(BLOCK) else {
return;
};
for (row, owned) in owned_rows(harness, block) {
let Some(path) = row.get("path").and_then(Value::as_str) else {
continue;
};
if !owned.contains(&path) {
continue;
}
match row.get("evidence").and_then(Value::as_str) {
Some(value) if ALLOWED.contains(&value) => {}
Some(value) => found.push(format!(
"{path:?} records evidence {value:?}, which is not one of \
`ran`, `bytes` or `page`"
)),
None => found.push(format!(
"{path:?} is owned and does not say what exercised it. Add \
`evidence`: `ran` if the product was run and the behaviour \
observed, `bytes` if its own shipped bytes were read, `page` \
if a vendor page is all there is. A citation is not a \
measurement, and the weakest of the three is the one a reader \
mistakes for the strongest."
)),
}
}
}
fn an_absence_is_not_recorded_beside_the_thing(baseline: &Value, found: &mut Vec<String>) {
let claims_absent = baseline.get("second_pin_absent").is_some();
let carries_one = baseline
.get("previous_software_artifacts")
.and_then(|previous| previous.get("version"))
.and_then(Value::as_str)
.is_some_and(|version| !version.is_empty());
if claims_absent && carries_one {
found.push(
"second_pin_absent records that there is no second release to cross, and \
previous_software_artifacts names one. The gap it describes has closed: \
remove the block rather than editing it, because what it says was true and \
is now a statement about a different day."
.to_owned(),
);
}
}
fn custody_is_what_nothing_can_fill(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
let Some(rows) = baseline
.get(BLOCK)
.and_then(|block| block.get("surfaces"))
.and_then(Value::as_array)
else {
return;
};
if harness.embedded_setups.is_empty() {
return;
}
let under = |namespace: &str, relative: &str| {
relative == namespace
|| relative
.strip_prefix(namespace)
.is_some_and(|rest| rest.starts_with('/'))
};
for namespace in harness.native_namespaces {
let routes = rows.iter().any(|row| {
row.get("path").and_then(Value::as_str) == Some(*namespace)
&& row
.get("kinds")
.and_then(Value::as_array)
.is_some_and(|kinds| !kinds.is_empty())
});
let filled = harness.embedded_setups.iter().any(|(embedded, _)| {
embedded
.split_once("/home/")
.is_some_and(|(_, relative)| under(namespace, relative))
});
let listed = harness.custody_namespaces.contains(namespace);
if listed && (routes || filled) {
found.push(format!(
"{namespace:?} is declared as custody and something can fill it: \
{}. A posture is entitled to say a fillable namespace is empty.",
if routes {
"a kind routes there"
} else {
"a setup carries files there"
}
));
}
if !listed && !routes && !filled {
found.push(format!(
"{namespace:?} is owned, routes no kind and no setup fills it, and is \
not declared as custody -- so selecting any posture empties it, and \
the only thing ever in it is somebody else's"
));
}
}
for namespace in harness.custody_namespaces {
if !harness.native_namespaces.contains(namespace) {
found.push(format!(
"{namespace:?} is declared as custody and is not owned at all"
));
}
}
}
fn the_switch_it_sets_was_measured(harness: &Harness, baseline: &Value, found: &mut Vec<String>) {
if harness.updates_off_env.is_empty() {
return;
}
let measured = baseline
.get("source_verified_runtime_flags")
.and_then(Value::as_array)
.map(|flags| {
flags
.iter()
.filter_map(Value::as_str)
.any(|flag| flag == harness.updates_off_env)
});
match measured {
Some(true) => {}
Some(false) => found.push(format!(
"launch sets {} and the baseline's measured runtime flags do not name it",
harness.updates_off_env
)),
None => found.push(format!(
"launch sets {} and this baseline records no source-verified runtime flags at all",
harness.updates_off_env
)),
}
}
#[must_use]
pub fn disagreements(harness: &Harness, baseline: &Value) -> Vec<String> {
let mut found = Vec::new();
rooted_elsewhere(baseline, &mut found);
shares_a_name_with_the_protocol(baseline, &mut found);
credentials_are_disclaimed(harness, baseline, &mut found);
never_touch_is_disclaimed(harness, baseline, &mut found);
policy_is_not_owned(harness, &mut found);
a_scope_is_distinguishable_from_the_global_target(harness, &mut found);
owned_paths_fold_together(harness, &mut found);
silent_about_routing_nothing(harness, baseline, &mut found);
writes_where_nothing_is_routed(harness, baseline, &mut found);
custody_is_what_nothing_can_fill(harness, baseline, &mut found);
the_switch_it_sets_was_measured(harness, baseline, &mut found);
evidence_is_recorded(harness, baseline, &mut found);
an_absence_is_not_recorded_beside_the_thing(baseline, &mut found);
let Some(block) = baseline.get(BLOCK).and_then(Value::as_object) else {
found.push(format!(
"{} has no {BLOCK} object, so nothing this harness claims to own is sourced",
harness.provider_id
));
return found;
};
the_home_and_what_moves_it(harness, block, &mut found);
the_measured_format_names_an_owned_file(harness, block, &mut found);
let Some(surfaces) = block.get("surfaces").and_then(Value::as_array) else {
found.push(format!("{BLOCK}.surfaces is missing or not an array"));
return found;
};
let owned = owned_surfaces(surfaces, &mut found);
against_declaration(harness, &owned, &mut found);
every_projection_names_where_it_lands(harness, block, &owned, &mut found);
let scoped_blocks = block
.get("scoped")
.and_then(Value::as_array)
.cloned()
.unwrap_or_default();
for (index, entry) in scoped_blocks.iter().enumerate() {
let Some(named) = entry.get("target_scope").and_then(Value::as_str) else {
found.push(format!("{BLOCK}.scoped[{index}] names no target_scope"));
continue;
};
let Some(declared) = harness
.scoped_projections
.iter()
.find(|scoped| scoped.target_scope.as_str() == named)
else {
found.push(format!(
"{named} is sourced in {BLOCK} and this harness declares no such scope"
));
continue;
};
let Some(rows) = entry.get("surfaces").and_then(Value::as_array) else {
found.push(format!("{BLOCK}.scoped[{index}].surfaces is missing"));
continue;
};
let owned = owned_surfaces(rows, &mut found);
against_scope(declared, &owned, named, &mut found);
let empty = Vec::new();
let rows = entry
.get("declined")
.and_then(Value::as_array)
.unwrap_or(&empty);
declined_rows_in(declared.native_namespaces, rows, &owned, &mut found);
}
for declared in harness.scoped_projections {
let named = declared.target_scope.as_str();
let sourced = scoped_blocks
.iter()
.any(|entry| entry.get("target_scope").and_then(Value::as_str) == Some(named));
if !sourced {
found.push(format!(
"this harness declares the {named} scope and {BLOCK} sources none"
));
}
}
let Some(declined) = block.get("declined").and_then(Value::as_array) else {
found.push(format!(
"{BLOCK}.declined is missing or not an array; a harness that declined \
nothing says so with an empty one"
));
return found;
};
declined_rows(harness, declined, &owned, &mut found);
control_state_is_recorded(harness, declined, &mut found);
found
}
#[cfg(test)]
mod tests {
#![allow(clippy::unwrap_used, clippy::panic)]
use serde_json::json;
use super::*;
use crate::harness_runtime::wire::tests_support::TEST;
fn agreeing() -> Value {
let surfaces: Vec<Value> = TEST
.native_namespaces
.iter()
.enumerate()
.map(|(index, path)| {
let kinds: Vec<&str> = if index == 0 {
TEST.component_kinds
.iter()
.map(|kind| kind.as_str())
.collect()
} else {
Vec::new()
};
json!({
"path": path,
"kinds": kinds,
"shape": "file",
"source": "https://example.invalid/docs",
"evidence": "page",
"note": if kinds.is_empty() {
"owned so a backup returns it; no kind describes it"
} else {
"routes the kinds this fixture declares"
},
})
})
.collect();
json!({
BLOCK: {
"verified_at": "2026-08-27",
"config_home": TEST.documented_config_home,
"config_home_env": TEST.config_home_env,
"config_home_env_note": "measured against the product",
"configuration_format": {
"file": TEST.native_namespaces[0],
"grammar": "json",
"accepts_comments": false,
"note": "measured by reading the product",
},
"surfaces": surfaces,
"scoped": [
{
"target_scope": "user_root",
"root": "~/.agents",
"surfaces": [
{
"path": "shared",
"kinds": ["skill"],
"shape": "directory",
"source": "this fixture's own contract",
"evidence": "page",
"note": "the scoped namespace, relative to the scope's own root",
},
],
"declined": [],
},
],
"declined": [
{
"path": TEST.state_file,
"reason": "this provider's own state file",
"source": "this provider's own contract",
},
{
"path": TEST.control_directory,
"reason": "this provider's own control directory",
"source": "this provider's own contract",
},
],
}
})
}
#[test]
fn a_declaration_that_matches_its_baseline_has_nothing_to_say() {
assert_eq!(disagreements(&TEST, &agreeing()), Vec::<String>::new());
}
#[test]
fn a_never_touch_the_baseline_marks_is_disclaimed_here() {
let mut baseline = agreeing();
baseline["never_touch"] = json!(["person-data.json"]);
let agreed = disagreements(&TEST, &baseline);
assert!(
agreed.iter().any(|line| line.contains("person-data.json")),
"an undisclaimed never_touch name passed: {agreed:?}"
);
baseline["never_touch"] = json!([TEST.native_namespaces[0]]);
let owned = disagreements(&TEST, &baseline);
assert!(
owned.iter().any(|line| line.contains("claimed as ours")),
"an owned never_touch name passed: {owned:?}"
);
}
#[test]
fn a_missing_block_is_reported_rather_than_passing_silently() {
let problems = disagreements(&TEST, &json!({}));
assert_eq!(problems.len(), 1);
assert!(problems[0].contains("no native_surfaces"));
}
#[test]
fn an_owned_namespace_the_baseline_does_not_source_is_named() {
let mut baseline = agreeing();
let surfaces = baseline[BLOCK]["surfaces"].as_array_mut().unwrap();
let dropped = surfaces.pop().unwrap();
let path = dropped["path"].as_str().unwrap().to_owned();
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.starts_with(&path)
&& line.contains("is declared in native_namespaces")),
"{problems:?}"
);
}
#[test]
fn a_documented_surface_the_declaration_omits_is_named() {
let mut baseline = agreeing();
baseline[BLOCK]["surfaces"]
.as_array_mut()
.unwrap()
.push(json!({
"path": "a-surface-nobody-declared",
"kinds": [],
"shape": "directory",
"source": "https://example.invalid/docs",
}));
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.contains("is not declared in native_namespaces")),
"{problems:?}"
);
}
#[test]
fn a_path_recorded_against_another_root_is_refused() {
for (field, mutate) in [
(
"never_touch",
Box::new(|b: &mut Value| b["never_touch"] = json!(["~/.thing.json"]))
as Box<dyn Fn(&mut Value)>,
),
(
"surfaces",
Box::new(|b: &mut Value| b[BLOCK]["surfaces"][0]["path"] = json!("/etc/thing")),
),
(
"declined",
Box::new(|b: &mut Value| {
b[BLOCK]["declined"] = json!([{
"path": "~/thing",
"reason": "measured, and recorded against the wrong root",
"source": "https://example.invalid/docs",
}]);
}),
),
] {
let mut baseline = agreeing();
mutate(&mut baseline);
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.contains("relative to a root this provider never")),
"{field}: {problems:?}"
);
}
}
#[test]
fn a_surface_with_no_source_is_not_owned() {
let mut baseline = agreeing();
baseline[BLOCK]["surfaces"][0]["source"] = json!("");
let problems = disagreements(&TEST, &baseline);
assert!(
problems.iter().any(|line| line.contains("cites no source")),
"{problems:?}"
);
}
#[test]
fn a_declared_kind_no_surface_routes_is_named() {
let mut baseline = agreeing();
baseline[BLOCK]["surfaces"][0]["kinds"] = json!([]);
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.contains("promise of a rollback")),
"{problems:?}"
);
}
#[test]
fn a_routed_kind_the_declaration_omits_is_named() {
let mut baseline = agreeing();
let absent = ComponentKind::ALL
.iter()
.find(|kind| !TEST.component_kinds.contains(kind))
.unwrap();
baseline[BLOCK]["surfaces"][0]["kinds"]
.as_array_mut()
.unwrap()
.push(json!(absent.as_str()));
let problems = disagreements(&TEST, &baseline);
assert!(
problems.iter().any(|line| line.contains("is refused")),
"{problems:?}"
);
}
#[test]
fn a_path_that_is_owned_and_declined_at_once_is_named() {
let mut baseline = agreeing();
baseline[BLOCK]["declined"] = json!([{
"path": TEST.native_namespaces[0],
"reason": "a reason",
"source": "https://example.invalid/docs",
}]);
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.contains("declined and owned at the same time")),
"{problems:?}"
);
}
#[test]
fn a_declined_path_with_no_reason_is_named() {
let mut baseline = agreeing();
baseline[BLOCK]["declined"] = json!([{
"path": "something-considered",
"source": "https://example.invalid/docs",
}]);
let problems = disagreements(&TEST, &baseline);
assert!(
problems
.iter()
.any(|line| line.contains("carries no reason")),
"{problems:?}"
);
}
#[test]
fn a_config_home_that_drifted_from_the_declaration_is_named() {
let mut baseline = agreeing();
baseline[BLOCK]["config_home"] = json!("~/somewhere-else");
let problems = disagreements(&TEST, &baseline);
assert!(
problems.iter().any(|line| line.contains("config_home")),
"{problems:?}"
);
}
#[test]
fn an_administrators_policy_in_the_owned_set_is_refused() {
let mut found = Vec::new();
let mut harness = TEST;
harness.native_namespaces = &["settings.json", "managed_config.toml"];
policy_is_not_owned(&harness, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("managed_config.toml"), "{found:?}");
assert!(found[0].contains("signature"), "{found:?}");
for owned in [
&["settings.json", "managed_identity.sig.json"][..],
&["settings.json", "policy.sig.json"][..],
&["settings.json", "config/managed_config_cache.json"][..],
] {
let mut nested = Vec::new();
let mut probe = TEST;
probe.native_namespaces = owned;
policy_is_not_owned(&probe, &mut nested);
assert_eq!(nested.len(), 1, "{owned:?} -> {nested:?}");
}
let mut kept = Vec::new();
let mut ordinary = TEST;
ordinary.native_namespaces = &["settings.json", "manage.json", "signals.json"];
policy_is_not_owned(&ordinary, &mut kept);
assert!(kept.is_empty(), "{kept:?}");
}
#[test]
fn a_scope_that_owns_the_global_set_is_refused() {
let mut clean = Vec::new();
a_scope_is_distinguishable_from_the_global_target(&TEST, &mut clean);
assert_eq!(clean, Vec::<String>::new(), "{clean:?}");
let mut harness = TEST;
harness.scoped_projections = &[crate::harness_runtime::facts::Scoped {
target_scope: crate::provider_v3::TargetScope::UserRoot,
profile_id: "test/native-files/user-root/1",
component_kinds: &[],
projection_kinds: &[],
native_namespaces: &["skills", "AGENTS.md", "settings.json"],
}];
let mut found = Vec::new();
a_scope_is_distinguishable_from_the_global_target(&harness, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("reads back as scoped"), "{found:?}");
}
#[test]
fn two_owned_paths_that_fold_together_are_refused() {
let mut found = Vec::new();
let mut harness = TEST;
harness.native_namespaces = &["settings.json", "skills", "Skills"];
owned_paths_fold_together(&harness, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("Skills"), "{found:?}");
let mut across = Vec::new();
let mut scoped = TEST;
scoped.native_namespaces = &["skills"];
scoped.scoped_projections = &[crate::harness_runtime::facts::Scoped {
target_scope: crate::provider_v3::TargetScope::Project,
profile_id: "test/native-files/project/1",
component_kinds: &[],
projection_kinds: &[],
native_namespaces: &["SKILLS"],
}];
owned_paths_fold_together(&scoped, &mut across);
assert_eq!(across.len(), 1, "{across:?}");
let mut kept = Vec::new();
let mut ordinary = TEST;
ordinary.native_namespaces = &["skills", "skills-extra", "agents"];
owned_paths_fold_together(&ordinary, &mut kept);
assert!(kept.is_empty(), "{kept:?}");
}
#[test]
fn a_claimed_pointer_that_names_nothing_is_refused() {
const NAMES_IT: &[(&str, &[u8])] = &[
("kit/home/skills/role.toml", b"the layer"),
("kit/home/AGENTS.md", b"config_file = \"skills/role.toml\""),
];
const NAMES_NOTHING: &[(&str, &[u8])] = &[
("kit/home/skills/role.toml", b"the layer"),
(
"kit/home/AGENTS.md",
b"a settings file that forgot to point",
),
];
let mut baseline = agreeing();
let rows = baseline["native_surfaces"]["surfaces"]
.as_array_mut()
.unwrap();
for row in rows.iter_mut() {
if row["path"] == "skills" {
row["reached_by"] = json!("AGENTS.md");
}
}
let mut pointing = TEST;
pointing.embedded_setups = NAMES_IT;
let mut found = Vec::new();
writes_where_nothing_is_routed(&pointing, &baseline, &mut found);
assert!(
found.is_empty(),
"a pointer that names it is allowed: {found:?}"
);
let mut blind = TEST;
blind.embedded_setups = NAMES_NOTHING;
let mut found = Vec::new();
writes_where_nothing_is_routed(&blind, &baseline, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("is not named in it"), "{found:?}");
let mut plain = agreeing();
let rows = plain["native_surfaces"]["surfaces"].as_array_mut().unwrap();
for row in rows.iter_mut() {
if row["path"] == "skills" {
row.as_object_mut().unwrap().remove("reached_by");
}
}
let mut found = Vec::new();
writes_where_nothing_is_routed(&blind, &plain, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("routes no kind"), "{found:?}");
}
#[test]
fn an_owned_row_that_does_not_say_what_exercised_it_is_refused() {
let mut baseline = agreeing();
baseline["native_surfaces"]["surfaces"][0]
.as_object_mut()
.unwrap()
.remove("evidence");
let mut found = Vec::new();
evidence_is_recorded(&TEST, &baseline, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("what exercised it"), "{found:?}");
let mut baseline = agreeing();
baseline["native_surfaces"]["scoped"][0]["surfaces"][0]
.as_object_mut()
.unwrap()
.remove("evidence");
let mut found = Vec::new();
evidence_is_recorded(&TEST, &baseline, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("\"shared\""), "{found:?}");
let mut baseline = agreeing();
baseline["native_surfaces"]["surfaces"][0]["evidence"] = json!("documented");
let mut found = Vec::new();
evidence_is_recorded(&TEST, &baseline, &mut found);
assert_eq!(found.len(), 1, "{found:?}");
assert!(found[0].contains("not one of"), "{found:?}");
let mut found = Vec::new();
evidence_is_recorded(&TEST, &agreeing(), &mut found);
assert!(found.is_empty(), "{found:?}");
}
}