Skip to content

test: pin RunResult's fields so a new one forces a redaction audit - #92

Merged
lesnik512 merged 1 commit into
mainfrom
test/run-result-redaction-invariant
Oct 3, 2026
Merged

lesnik512 merged 1 commit into
mainfrom
test/run-result-redaction-invariant

Conversation

@lesnik512

Copy link
Copy Markdown
Member

Closes #61.

JsonOutput.emit writes the RunResult envelope to stdout without passing it through redact, unlike every RichOutput path. Triage traced each field and found no way to leak a token today:

  • schema_version, status and reason are fixed strings (module constants or a strategy's no_bump_reason ClassVar).
  • strategy is a registered strategy name.
  • bump is a Bump value.
  • commit is a commit sha.
  • tag is a version semvertag computed or an existing repository tag name.

So the gap is structural, and this PR takes outcome 1 from the issue: write the invariant down as a named test instead of adding redaction. test_no_run_result_field_carries_user_supplied_text asserts RunResult's field set equals the audited set. When it breaks, its message explains why emit is unredacted, says to audit the changed field, and warns that any redaction has to be per field because redact() would also mask the 40-hex commit.

test_emit_envelope_order_matches_dataclass_declaration would already catch a new field, but as a wire-shape failure that says nothing about redaction. The new test exists to carry that reason.

No production code changes.

Verified with just lint-ci, just test-ci (481 passed, 100% coverage) and just adr-check. I also temporarily added a message field to RunResult and confirmed the test fails with Added: ['message'], then reverted it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decide whether JsonOutput.emit should redact the result envelope

1 participant