verify(P5): review fixes — wire Step 5c meta-policies + fix smoke policy (P1-1, P1-2, P1-3)
P1-1 (correctness): run_platform.sh Step 5c now invokes the meta-policies
(block-on-any-critical, tagging-rules-agree) over the merged PCR list after
Step 5b, appending the meta-PCRs to pcr.json before the confidence signal
runs. Closes the D-118/D-119 declarative-critical-block gap (the
confidence_signal.py hard-override stays as defense-in-depth).
P1-2 (testing): test_meta_policies.py behavioral assertions strengthened —
test_no_critical_passes asserts no fails, test_critical_fail_present asserts
a non-pass result, test_pcrs_validate_against_schema validates output.
P1-3 (correctness): _smoke.json assertion rewritten from malformed
'{{ to_string(@) }}' to valid JMESPath '(regex_match(...))'.
---ci---
project: acdl
phase: 5
milestone: v1.25
status: execute
phase_role: final
---/ci---
This commit is contained in:
@@ -27,6 +27,11 @@ class TestStep5bKyvernoJsonWiring:
|
||||
assert "Step 5b: kyverno-json plan-JSON policies" in s, \
|
||||
"run_platform.sh must have a Step 5b kyverno-json block (REQ-301)"
|
||||
|
||||
def test_step_5c_meta_block_present(self):
|
||||
s = _read_script()
|
||||
assert "Step 5c: kyverno-json meta-policies over the merged PCR list" in s, \
|
||||
"run_platform.sh must have a Step 5c meta-policy block (REQ-303, P1-1 fix)"
|
||||
|
||||
def test_kj_scan_invocation_present(self):
|
||||
s = _read_script()
|
||||
assert "adapters/kyverno-json/policies/plan-json" in s, \
|
||||
|
||||
Reference in New Issue
Block a user