test(policy): expect advisor overlay for new binary

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This commit is contained in:
Drew Newberry
2026-09-23 02:38:21 -07:00
parent 2a9ad0383a
commit e391bee5cd
2 changed files with 7 additions and 4 deletions
+4 -3
View File
@@ -297,9 +297,10 @@ through the proposal loop instead of treating the denial as terminal.
2. **Build and validate the candidate.** The gateway first canonicalizes a
mechanistic proposal against the live effective policy. If an endpoint is
already governed by an inspected or provider-owned contract, the candidate
preserves that contract and adds only the proposed sandbox binary. Provider
rules are immutable inputs; the sandbox contribution is stored as an
overlay. The gateway then performs the same merge, policy validation,
preserves that contract and adds only the proposed sandbox binary. A new
binary gets a separate overlay rule, leaving the existing sandbox or
provider rule intact. The gateway then performs the same merge, policy
validation,
provider composition, credential preflight, and prover evaluation that the
candidate would encounter when applied. Each chunk stores the resulting
effective candidate, its hashes, any application error, and a review token
@@ -72,7 +72,7 @@ done
printf '%s\n' "$RULE_OUTPUT"
grep -q "Status: approved" <<<"$RULE_OUTPUT"
grep -q "Rule: cargo_registry" <<<"$RULE_OUTPUT"
grep -q "Rule: allow_index_crates_io_443" <<<"$RULE_OUTPUT"
grep -q "Prover: prover: no new findings" <<<"$RULE_OUTPUT"
if grep -q "Application:" <<<"$RULE_OUTPUT"; then
echo "auto-approved chunk unexpectedly retained an application error" >&2
@@ -80,6 +80,8 @@ if grep -q "Application:" <<<"$RULE_OUTPUT"; then
fi
POLICY_OUTPUT="$($OPENSHELL_BIN policy get "$SANDBOX" --full 2>&1 | strip_ansi)"
grep -q '^ allow_index_crates_io_443:' <<<"$POLICY_OUTPUT"
grep -q '^ cargo_registry:' <<<"$POLICY_OUTPUT"
grep -q "protocol: rest" <<<"$POLICY_OUTPUT"
grep -q "access: read-only" <<<"$POLICY_OUTPUT"
grep -q "/usr/bin/cargo" <<<"$POLICY_OUTPUT"