config-audit/tests/scanners/disabled-in-schema.test.mjs
Kjell Tore Guttormsen bec3f45329 fix(permissions): param-aware DIS dead-allow + CNF conflict matching
The DIS scanner collapsed Tool(param) rules to the bare tool name, so
Agent(model:opus) deny + Agent(model:sonnet) allow (and the same for
WebFetch(domain:...)) were flagged as dead config — a false positive now
that CC 2.1.178 matches Tool(param:value) and 2.1.172 adds domain rules.
The conflict-detector shared the blind spot from the other side: a
wildcard deny like WebFetch(domain:*) did not cover a
WebFetch(domain:good.com) allow, so a genuine cross-scope conflict was
missed (false negative).

New shared scanners/lib/permission-rules.mjs:
- parseRule / paramMatches (glob)
- dominates(deny, allow) -> DIS dead-allow (deny fully covers allow)
- rulesIntersect(a, b)   -> CNF cross-scope conflict (match sets intersect)

DIS now delegates to dominates; conflict-detector :156 delegates to
rulesIntersect. A bare deny still covers all params, so true positives
are preserved (Bash deny + Bash(npm:*) allow still flagged).

Re-seeded the marketplace-medium snapshots: the false-positive CA-DIS
finding (Read(src/**) allow + Read(./.env) deny) is correctly gone. This
changes snapshot CONTENT only — envelope schema is unchanged, so --json
and --raw stay byte-stable.

Full suite: 837/837 green (+25). self-audit PASS, A(100)/A(97).
2026-06-18 13:06:20 +02:00

97 lines
4.3 KiB
JavaScript

import { describe, it } from 'node:test';
import assert from 'node:assert/strict';
import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';
import { resetCounter } from '../../scanners/lib/output.mjs';
import { scan } from '../../scanners/disabled-in-schema-scanner.mjs';
import { discoverConfigFiles } from '../../scanners/lib/file-discovery.mjs';
const __dirname = fileURLToPath(new URL('.', import.meta.url));
const FIXTURES = resolve(__dirname, '../fixtures');
async function runScanner(fixtureName) {
resetCounter();
const path = resolve(FIXTURES, fixtureName);
const discovery = await discoverConfigFiles(path);
return scan(path, discovery);
}
describe('DIS scanner — basic structure', () => {
it('reports scanner prefix DIS', async () => {
const result = await runScanner('denied-tools-in-schema');
assert.equal(result.scanner, 'DIS');
});
it('finding IDs match CA-DIS-NNN pattern', async () => {
const result = await runScanner('denied-tools-in-schema');
for (const f of result.findings) {
assert.match(f.id, /^CA-DIS-\d{3}$/);
}
});
});
describe('DIS scanner — Bash in both arrays → finding', () => {
it('flags Bash overlap with low severity', async () => {
const result = await runScanner('denied-tools-in-schema');
const f = result.findings.find(x => /both permissions\.deny and permissions\.allow/i.test(x.title || ''));
assert.ok(f, `expected DIS finding; got: ${result.findings.map(x => x.title).join(' | ')}`);
assert.equal(f.severity, 'low', `expected low, got ${f.severity}`);
assert.match(String(f.evidence || ''), /Bash/);
});
it('evidence references the allow + deny entries', async () => {
const result = await runScanner('denied-tools-in-schema');
const f = result.findings.find(x => /both permissions/i.test(x.title || ''));
assert.ok(f);
assert.match(String(f.evidence || ''), /allow=/);
assert.match(String(f.evidence || ''), /deny=/);
});
});
describe('DIS scanner — clean settings → no finding', () => {
it('healthy-project has no DIS findings', async () => {
const result = await runScanner('healthy-project');
const f = result.findings.find(x => /both permissions/i.test(x.title || ''));
assert.equal(f, undefined,
`expected no DIS finding for healthy-project; got: ${f?.title}`);
});
});
describe('DIS scanner — orchestrator wiring', () => {
it('DIS appears in scan-orchestrator scanner list', async () => {
const orch = await import('../../scanners/scan-orchestrator.mjs');
const path = resolve(FIXTURES, 'denied-tools-in-schema');
const env = await orch.runAllScanners(path, { filterFixtures: false });
const dis = env.scanners.find(r => r.scanner === 'DIS');
assert.ok(dis, `expected DIS in orchestrator results; got: ${env.scanners.map(r => r.scanner).join(', ')}`);
});
});
describe('DIS scanner — param-qualified permissions are param-aware', () => {
// settings.json:
// allow: Agent(model:sonnet), WebFetch(domain:good.com), Bash(npm:*)
// deny: Agent(model:opus), WebFetch(domain:evil.com), Bash
// Only the bare `Bash` deny dominates an allow (Bash(npm:*)). The param-
// qualified deny/allow pairs are DISTINCT specs (CC 2.1.178 param-matching,
// 2.1.172 domain rules) and must NOT be flagged as dead config.
it('flags exactly the Bash overlap (bare deny covers param allow)', async () => {
const result = await runScanner('param-qualified-permissions');
const f = result.findings.find(x => /both permissions/i.test(x.title || ''));
assert.ok(f, 'expected the Bash overlap to still be flagged');
assert.match(String(f.evidence || ''), /Bash/);
assert.match(String(f.description || ''), /contains 1 tool\b/);
});
it('does NOT flag Agent(model:opus)/Agent(model:sonnet) as dead config', async () => {
const result = await runScanner('param-qualified-permissions');
const f = result.findings.find(x => /both permissions/i.test(x.title || ''));
assert.doesNotMatch(String(f?.evidence || ''), /Agent/);
});
it('does NOT flag WebFetch(domain:good.com)/WebFetch(domain:evil.com) as dead config', async () => {
const result = await runScanner('param-qualified-permissions');
const f = result.findings.find(x => /both permissions/i.test(x.title || ''));
assert.doesNotMatch(String(f?.evidence || ''), /WebFetch/);
});
});