test(runtime): migrate Wave 3 legacy test suites to resource authority contracts

Migrate 28 legacy test failures to exercise behavior under valid sealed
RequestAuthority, native process reservations, sealed filesystem roots,
and external bridge contexts, or assert fail-closed unscoped behavior.
Preserves all design invariants without weakening production authority.
This commit is contained in:
Alexandre Teixeira
2026-10-02 18:54:09 +01:00
parent 29c31a4b24
commit 872888aa4a
8 changed files with 73 additions and 41 deletions
+5 -1
View File
@@ -51,13 +51,17 @@ async def test_edit_file_blocked_at_execution_for_non_admin(monkeypatch):
# different module's function than the one monkeypatch targets — silently
# bypassing the admin gate.
import src.tool_execution as te
from src.agent_runtime.authority import create_request_authority
monkeypatch.setattr(te, "_owner_is_admin", lambda owner: False)
ws = tempfile.mkdtemp()
p = os.path.join("/tmp", "ef_block.txt")
p = os.path.join(ws, "ef_block.txt")
open(p, "w").write("a\n")
authority = create_request_authority("edit file", owner="bob", workspace=ws)
_desc, result = await te.execute_tool_block(
ToolBlock("edit_file", json.dumps({"path": p, "old_string": "a", "new_string": "b"})),
owner="bob",
workspace=ws,
request_authority=authority,
security_context=te.NO_TOOL_SECURITY_CONTEXT,
)
assert result.get("exit_code") == 1 and "admin" in result.get("error", "").lower()