Skip to content
This repository was archived by the owner on Sep 28, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
94 changes: 94 additions & 0 deletions tests/unit/test_clean_room_automation_contract.sh
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,20 @@ def main() -> None:
raise SystemExit("readiness must not treat generic python3 as the Ansible interpreter")
print("PASS: readiness requires python3.12")

if "clean_room_has_angle_placeholders" not in lib:
raise SystemExit("shared placeholder detector is missing from the helper")
if re.search(r"grep -Eq '<|>'", lib):
raise SystemExit("placeholder detector must not scan comment-only angle brackets")
if "clean_room_has_angle_placeholders" not in deploy:
raise SystemExit("deploy must use the shared placeholder detector")
if "clean_room_has_angle_placeholders" not in verify:
raise SystemExit("verify must use the shared placeholder detector")
if "clean_room_has_angle_placeholders" not in readiness:
raise SystemExit("readiness must use the shared placeholder detector")
if re.search(r"grep -Eq '<|>'", readiness):
raise SystemExit("readiness must not duplicate whole-file angle-bracket grep")
print("PASS: placeholder detection ignores comment-only angle brackets")

if "-auto-approve" in deploy:
raise SystemExit("deploy-clean-room must not use -auto-approve")
if not re.search(r"-e\s+scratch_storage_allow_format=true", deploy):
Expand Down Expand Up @@ -266,6 +280,83 @@ else
fi

TMP_ROOT="$(mktemp -d "${TMPDIR:-/tmp}/clean-room-automation.XXXXXX")"
PH_DIR="${TMP_ROOT}/placeholders"
mkdir -p "$PH_DIR"

cat >"${PH_DIR}/active.hcl" <<'EOF'
oci_region = "<oci-region>"
EOF
if clean_room_has_angle_placeholders "${PH_DIR}/active.hcl"; then
pass "active HCL placeholder is rejected"
else
fail "active HCL placeholder is rejected"
fi

cat >"${PH_DIR}/active.yml" <<'EOF'
private_runtime_config_vault_id: "<vault-ocid>"
EOF
if clean_room_has_angle_placeholders "${PH_DIR}/active.yml"; then
pass "active YAML placeholder is rejected"
else
fail "active YAML placeholder is rejected"
fi

cat >"${PH_DIR}/comment-only.tfvars" <<'EOF'
# curl -s checkip.dyndns.org | sed -e 's/.*Current IP Address: //' -e 's/<.*$//'
ssh_ingress_cidr = "203.0.113.10/32"
EOF
if clean_room_has_angle_placeholders "${PH_DIR}/comment-only.tfvars"; then
fail "comment-only angle bracket is accepted"
else
pass "comment-only angle bracket is accepted"
fi

cat >"${PH_DIR}/ws-comment.tfvars" <<'EOF'
# curl -s checkip.dyndns.org | sed -e 's/.*Current IP Address: //' -e 's/<.*$//'
ssh_ingress_cidr = "203.0.113.10/32"
EOF
if clean_room_has_angle_placeholders "${PH_DIR}/ws-comment.tfvars"; then
fail "leading-whitespace comment-only angle bracket is accepted"
else
pass "leading-whitespace comment-only angle bracket is accepted"
fi

python3 - "${ROOT}/terraform/terraform.tfvars.example" "${PH_DIR}/populated.tfvars" <<'PY'
from pathlib import Path
import sys

src = Path(sys.argv[1]).read_text(encoding="utf-8")
replacements = {
"<oci-region>": "eu-frankfurt-1",
"<compartment-ocid>": "ocid1.compartment.oc1..example",
"<tenancy-ocid>": "ocid1.tenancy.oc1..example",
"<vault-ocid>": "ocid1.vault.oc1..example",
"<vault-compartment-ocid>": "ocid1.compartment.oc1..vault-example",
"<cloud-shell-or-operator-cidr>": "203.0.113.10/32",
"<contents-of-~/.ssh/tradingchassis.pub>": (
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA "
"contract-test@example.invalid"
),
}
for old, new in replacements.items():
src = src.replace(old, new)
Path(sys.argv[2]).write_text(src, encoding="utf-8")
PY
if grep -Fq "s/<.*\$//" "${PH_DIR}/populated.tfvars" \
&& ! clean_room_has_angle_placeholders "${PH_DIR}/populated.tfvars"; then
pass "populated terraform.tfvars-style fixture with curl/sed comment is accepted"
else
fail "populated terraform.tfvars-style fixture with curl/sed comment is accepted"
fi

if clean_room_has_angle_placeholders "${ROOT}/terraform/terraform.tfvars.example" \
&& clean_room_has_angle_placeholders "${ROOT}/terraform/backend.hcl.example" \
&& clean_room_has_angle_placeholders "${ROOT}/ansible/extra-vars/private-runtime.yml.example"; then
pass "committed example files still fail placeholder checks"
else
fail "committed example files still fail placeholder checks"
fi

HELPER_DIR="${TMP_ROOT}/helper"
mkdir -p "$HELPER_DIR"

Expand Down Expand Up @@ -585,6 +676,9 @@ oci_compartment_id = "ocid1.compartment.oc1..example"
oci_tenancy_id = "ocid1.tenancy.oc1..example"
oci_vault_id = "ocid1.vault.oc1..example"
oci_vault_compartment_id = "ocid1.compartment.oc1..vault-example"
# Cloud Shell public egress IP is dynamic across sessions.
# Example discovery (Cloud Shell docs):
# curl -s checkip.dyndns.org | sed -e 's/.*Current IP Address: //' -e 's/<.*$//'
ssh_ingress_cidr = "203.0.113.10/32"
ssh_public_key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA contract-test@example.invalid"
EOF
Expand Down
2 changes: 2 additions & 0 deletions tests/unit/test_cloud_shell_execution_contracts.sh
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,8 @@ def main() -> None:
content = content.replace(old, new)
if ssh_public_key_uses_function(content):
raise SystemExit("sanitized temp tfvars unexpectedly contains functions")
if "s/<.*$//" not in content:
raise SystemExit("sanitized tfvars must retain the documented curl/sed comment")
sanitized.write_text(content, encoding="utf-8")
print("PASS: sanitized temp var-file keeps literal ssh_public_key")

Expand Down
14 changes: 10 additions & 4 deletions tools/check-cloud-shell-readiness
Original file line number Diff line number Diff line change
@@ -1,9 +1,15 @@
#!/usr/bin/env bash
# shellcheck shell=bash
# Local/static Cloud Shell execution-readiness checks.
# Does not create buckets, mutate IAM, terraform init/plan/apply, SSH, or Ansible.
set -euo pipefail

ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
ROOT="$(cd "${SCRIPT_DIR}/.." && pwd)"
# shellcheck source=lib/clean-room-common.sh
# Dynamic SCRIPT_DIR path is not followed without shellcheck -x; the helper is linted separately.
# shellcheck disable=SC1091
source "${SCRIPT_DIR}/lib/clean-room-common.sh"
STRICT=0
failures=0

Expand Down Expand Up @@ -176,7 +182,7 @@ check_file "${ROOT}/docs/V2_CLEAN_ROOM_DEPLOYMENT.md" "clean-room runbook"

if [[ -f "${ROOT}/terraform/backend.hcl" ]]; then
pass "operator backend.hcl present"
if grep -Eq '<|>' "${ROOT}/terraform/backend.hcl"; then
if clean_room_has_angle_placeholders "${ROOT}/terraform/backend.hcl"; then
placeholder_issue "terraform/backend.hcl"
else
pass "terraform/backend.hcl has no angle-bracket placeholders"
Expand All @@ -201,7 +207,7 @@ fi

if [[ -f "${ROOT}/terraform/terraform.tfvars" ]]; then
pass "operator terraform.tfvars present"
if grep -Eq '<|>' "${ROOT}/terraform/terraform.tfvars"; then
if clean_room_has_angle_placeholders "${ROOT}/terraform/terraform.tfvars"; then
placeholder_issue "terraform/terraform.tfvars"
else
pass "terraform.tfvars has no angle-bracket placeholders"
Expand All @@ -221,7 +227,7 @@ fi

if [[ -f "${ROOT}/ansible/extra-vars/private-runtime.yml" ]]; then
pass "operator private-runtime.yml present"
if grep -Eq '<|>' "${ROOT}/ansible/extra-vars/private-runtime.yml"; then
if clean_room_has_angle_placeholders "${ROOT}/ansible/extra-vars/private-runtime.yml"; then
placeholder_issue "ansible/extra-vars/private-runtime.yml"
else
pass "private-runtime.yml has no angle-bracket placeholders"
Expand Down
4 changes: 3 additions & 1 deletion tools/lib/clean-room-common.sh
Original file line number Diff line number Diff line change
Expand Up @@ -89,9 +89,11 @@ sys.exit(0 if ok else 1)
PY
}

# True when an active (non-comment, non-blank) line contains < or >.
# Full-line comments such as sed 's/<.*$//' are documentation, not placeholders.
clean_room_has_angle_placeholders() {
local path="$1"
grep -Eq '<|>' "$path"
grep -Eq '^[[:space:]]*[^#[:space:]].*[<>]' "$path"
}

clean_room_require_exact_input() {
Expand Down
Loading