None:
"""THE FASIT NEVER COMES FROM THE READER IT JUDGES -- including this route.
The conversion route reads two digests out of the bundle. Before this
guard it read them out of ANY text in it, so a document could write the
sentence itself and the judge would believe it: measured by PM 2026-09-19,
a BMP declaring 50 000 x 50 000 that was refused `asset_too_large` and
never carried gave `asset_holds = True`, both through an image's alt text
and through ordinary body text. The route the judge had before the
conversion landed hashed the source file and nothing else, so no document
could reach it; this round opened a way IN for content this repository
does not trust.
A claim counts only where THIS CODE put it: inside a pointer block, tied
to the asset that block names. Every arm below carries a source that was
never carried, and a bundle holding one unrelated REAL asset -- so the
digest the forgery names really is in `assets/`, which is what made the
measured forgeries work.
"""
never_carried = tmp_path / "figur.bmp"
never_carried.write_bytes(_huge_bmp())
real = tmp_path / "ekte.png"
real.write_bytes(_png_bytes(b"\x10\x20\x30"))
before = gate._sha256(never_carried)
after = gate._sha256(real)
assets = {f"{after[:12]}-ekte.png": after}
clause = f"converted from image/bmp sha256:{before} to image/png sha256:{after}"
pointer = f"\nImage: ekte.png (1x1 px)"
arms = {
"plain body text": f"{pointer}\n\nProsess 84. {clause}. Se figuren over.\n",
"a table cell": f"{pointer}\n\n| Krav | Kilde |\n| --- | --- |\n| 84-1 | {clause} |\n",
"a pointer block naming another asset": (
f"\nImage: annen.png (1x1 px) -- {clause}\n"
f"{pointer}\n"
),
}
for label, text in arms.items():
build = _build(assets=assets, bundle_text=text)
assert gate.asset_holds(build, never_carried) is False, (
f"{label}: a document talked the judge into a carry that never happened"
)
# KNOWN-POSITIVE on the same bytes: the clause where the code writes it,
# in the pointer block for the asset it names. Without this the arms above
# would pass on a route that had simply stopped working.
honest_text = (
f"\nImage: figur.bmp (1x1 px) -- {clause}\n"
)
honest = _build(assets=assets, bundle_text=honest_text)
assert gate.asset_holds(honest, never_carried) is True
def test_the_build_never_writes_a_claim_the_document_supplied(tmp_path: Path) -> None:
"""PM's measured path, end to end through the real `okf build`.
The judge reading only pointer blocks is half of it. The other half is
that an image's own LABEL is document text written INSIDE a pointer
block, so the door that puts it there must not let it emit the grammar
the judge reads. This builds the forgery PM measured: a BMP that is
refused and never carried, a real PNG that is, and an `alt` attribute
claiming the first became the second.
"""
pytest.importorskip("llm_ingestion_guard")
corpus = tmp_path / "inbox"
(corpus / "graphics").mkdir(parents=True)
never_carried = corpus / "graphics" / "figur.bmp"
never_carried.write_bytes(_huge_bmp())
real = corpus / "graphics" / "ekte.png"
real.write_bytes(_png_bytes(b"\x10\x20\x30"))
before = gate._sha256(never_carried)
after = gate._sha256(real)
clause = f"converted from image/bmp sha256:{before} to image/png sha256:{after}"
(corpus / "prosess.html").write_text(
"\nProsess 84\n\n"
"84 Konstruksjoner av betong
\n"
"Toleranseklassene staar i figuren under.
\n"
f'
\n'
"Og den store figuren:
\n"
'
\n'
f"{clause}
\n"
"\n",
encoding="utf-8",
)
build = gate.run_build(corpus, tmp_path / "work", door=False)
assert build.exit_code == 0, build.log
assert any(name.startswith(after[:12]) for name in build.assets), build.assets
assert not any(name.startswith(before[:12]) for name in build.assets), (
"the 50 000 x 50 000 BMP was carried; the arm measures nothing"
)
assert gate.asset_holds(build, never_carried) is False, (
"a document's own alt text talked the judge into a carry that never happened"
)
def test_the_judge_proves_carriage_and_says_it_does_not_prove_fidelity(tmp_path: Path) -> None:
"""The limit, MEASURED here rather than trusted to the prose beside it.
PM's M10 2026-09-19: a mutated converter that writes a BLANK PNG gives
`asset_holds = True`. The bundle is internally consistent -- the digest it
claims to have written really is the asset's digest -- and the judge has
no opinion about whether those bytes hold the source's picture. The suite
fells that mutant (`test_the_carried_png_holds_the_source_pixels_exactly`
decodes both sides); this gate cannot, and the docstring's "a bundle
claiming a conversion it did not perform still fails" reads wider than
the route reaches.
So the limit is asserted in BOTH directions: it is real (the blank PNG is
accepted) and it is stated (the docstring names it). Teaching the judge
pixels is a different job; leaving a reader to infer the gap is not.
"""
source = tmp_path / "figur.bmp"
source.write_bytes(_huge_bmp())
blank = tmp_path / "blank.png"
blank.write_bytes(_png_bytes(b"\xff\xff\xff"))
before = gate._sha256(source)
after = gate._sha256(blank)
text = (
f"\n"
f"Image: figur.bmp (8x4 px) -- converted from image/bmp sha256:{before} "
f"to image/png sha256:{after}\n"
)
build = _build(assets={f"{after[:12]}-figur.png": after}, bundle_text=text)
assert gate.asset_holds(build, source) is True
doc = gate.asset_holds.__doc__ or ""
lowered = doc.lower()
assert "fidelity" in lowered, "the judge does not say what its second route cannot see"
assert "pixel" in lowered, "the limit is stated without naming what is not checked"
def _declared(heading: int = 2, image: int = 1, fate: str = "rejected") -> dict[str, Any]:
return {
"accounting_version": 1,
"documents": [
{
"source_file": "a.md",
"status": "persisted",
"code": None,
"inventory": {"heading": 2, "image": 1},
"fates": {
"heading": {"carried": heading},
"image": {"pointer": image},
},
}
],
"files": [{"source_file": "graphics/x.png", "fate": fate, "code": "extractor_unknown"}],
}
def _corpus(tmp_path: Path) -> Path:
(tmp_path / "graphics").mkdir()
(tmp_path / "graphics" / "x.png").write_bytes(b"png bytes")
return tmp_path
def test_row1_is_green_when_every_type_has_a_fasit() -> None:
inventory = {
"documents": {f"f{s}": {"suffix": s, "elements": {}} for s in TABLE},
"files": {},
}
row = gate.row1(TABLE, inventory, inventory)
assert (row.k, row.m, row.status) == (13, 13, gate.GREEN)
def test_row1_is_red_when_one_type_lacks_a_fasit() -> None:
inventory = {
"documents": {f"f{s}": {"suffix": s, "elements": {}} for s in TABLE[:-1]},
"files": {},
}
row = gate.row1(TABLE, inventory, inventory)
assert (row.k, row.m, row.status) == (12, 13, gate.RED)
def test_row1_is_red_when_the_committed_fasit_is_stale() -> None:
inventory = {"documents": {"f.md": {"suffix": ".md", "elements": {"heading": 1}}}}
fresh = {"documents": {"f.md": {"suffix": ".md", "elements": {"heading": 2}}}}
row = gate.row1([".md"], inventory, fresh)
assert (row.k, row.status) == (0, gate.RED)
def test_row2_is_red_without_the_door() -> None:
row = gate.row2([".md"], _inventory(), _build(), door=False)
assert (row.k, row.m, row.status) == (0, 1, gate.RED)
def test_row2_is_green_when_the_declared_inventory_equals_the_witness() -> None:
row = gate.row2([".md"], _inventory(), _build(accounting=_declared()), door=True)
assert (row.k, row.m, row.status) == (1, 1, gate.GREEN)
def test_row2_is_red_when_the_declared_inventory_is_one_off() -> None:
declared = _declared()
declared["documents"][0]["inventory"]["heading"] = 3
row = gate.row2([".md"], _inventory(), _build(accounting=declared), door=True)
assert (row.k, row.status) == (0, gate.RED)
def test_row3_is_green_when_every_element_and_file_has_one_fate(tmp_path: Path) -> None:
units = gate.account(_inventory(), _build(accounting=_declared()), _corpus(tmp_path))
row = gate.row3(units, door=True)
assert (row.k, row.m, row.status) == (2, 2, gate.GREEN)
@pytest.mark.parametrize(("heading", "u", "d"), [(1, 1, 0), (3, 0, 1)])
def test_row3_is_red_one_element_either_side(tmp_path: Path, heading: int, u: int, d: int) -> None:
units = gate.account(
_inventory(), _build(accounting=_declared(heading=heading)), _corpus(tmp_path)
)
document = units[0]
assert (document.unaccounted, document.double) == (u, d)
assert gate.row3(units, door=True).status == gate.RED
def test_row3_is_red_when_no_fate_is_declared(tmp_path: Path) -> None:
units = gate.account(_inventory(), _build(), _corpus(tmp_path))
assert units[0].unaccounted == 3
assert gate.row3(units, door=False).status == gate.RED
def test_row3_says_how_many_documents_were_refused_whole_and_what_they_cost() -> None:
"""P11 and P12, PM 2026-09-19: row 3's own summary of a refusal, and the
`refused=` column on its detail line, could each be deleted with this file
staying green at 106 passed. The LOSS is held -- `Unit.refused` keeps the
unit unclean and the note names the source and its code -- but what the
ROW says about it was decoration nothing pinned, and the row is what a
reader of the gate's output actually sees.
R, D and the element total are counted HERE, over the units this test
built, never read back off the row. The known-negative is the same units
without a refusal: the sentence has to change with them, or it is a
constant that happens to read true."""
refused_note = "refused whole: 17 element(s) declared rejected `fail_secure`"
units = [
gate.Unit("a.xml", "document", 0, 0, refused=17, notes=[refused_note]),
gate.Unit("b.json", "document", 0, 0, refused=4, notes=["refused whole: 4 element(s)"]),
gate.Unit("c.md", "document", 0, 0, verified=9),
gate.Unit("d.png", "file", 0, 0),
]
documents = [u for u in units if u.kind == "document"]
refused_docs = [u for u in documents if u.refused]
elements = sum(u.refused for u in units)
assert (len(refused_docs), len(documents), elements) == (2, 3, 21)
row = gate.row3(units, door=True)
assert row.status == gate.RED
assert (
f"{elements} element(s) lost with "
f"{len(refused_docs)} of {len(documents)} document(s) refused whole"
) in row.reason
for unit in refused_docs:
assert any(
unit.name in detail and f"refused={unit.refused}" in detail for detail in row.details
), unit.name
clean = [gate.Unit(u.name, u.kind, 0, 0, verified=9) for u in units]
assert (
"0 element(s) lost with 0 of 3 document(s) refused whole"
in gate.row3(clean, door=True).reason
)
def test_a_file_carried_through_a_document_and_rejected_is_double_booked(tmp_path: Path) -> None:
corpus = _corpus(tmp_path)
carried = _assets(corpus / "graphics" / "x.png")
units = gate.account(_inventory(), _build(accounting=_declared(), assets=carried), corpus)
assert (units[1].unaccounted, units[1].double) == (0, 1)
def test_a_file_carried_through_a_document_and_declared_carried_is_clean(tmp_path: Path) -> None:
corpus = _corpus(tmp_path)
carried = _assets(corpus / "graphics" / "x.png")
build = _build(accounting=_declared(fate="carried"), assets=carried)
assert gate.account(_inventory(), build, corpus)[1].clean
def test_a_file_declared_carried_without_its_bytes_is_unaccounted(tmp_path: Path) -> None:
build = _build(accounting=_declared(fate="carried"))
unit = gate.account(_inventory(), build, _corpus(tmp_path))[1]
assert (unit.unaccounted, unit.double) == (1, 0)
def test_an_unpointed_file_sharing_bytes_with_a_carried_one_is_not_carried(
tmp_path: Path,
) -> None:
corpus = _corpus(tmp_path)
(corpus / "graphics" / "twin.png").write_bytes(b"png bytes")
inventory = _inventory()
inventory["files"]["graphics/twin.png"] = {"pointed_at_by": []}
carried = _assets(corpus / "graphics" / "x.png")
units = gate.account(inventory, _build(assets=carried), corpus)
assert [(u.name, u.double) for u in units[1:]] == [
("graphics/twin.png", 0),
("graphics/x.png", 1),
]
def test_without_the_door_double_booking_is_derived_from_conservation(tmp_path: Path) -> None:
corpus = _corpus(tmp_path)
carried = _assets(corpus / "graphics" / "x.png")
assert gate.account(_inventory(), _build(assets=carried), corpus)[1].double == 1
assert gate.account(_inventory(), _build(), corpus)[1].clean
# --- B-1: the judge opens the bundle itself ----------------------------------
#
# Written RED 2026-09-18 against the hardening order. At 864570b the gate
# compared BOOKED NUMBERS with the witness's counts and never opened a concept
# file, so a report that booked every element of every document as carried was
# `GATE GREEN` over a bundle holding nothing (independent review, B-1).
def _all_carried(headings: int = 2, images: int = 1) -> dict[str, Any]:
"""A report that books everything as carried, the cheat's shape."""
return {
"accounting_version": 1,
"documents": [
{
"source_file": "a.md",
"status": "persisted",
"code": None,
"inventory": {"heading": 2, "image": 1},
"fates": {
"heading": {"carried": headings},
"image": {"carried": images},
},
}
],
"files": [
{"source_file": "graphics/x.png", "fate": "rejected", "code": "extractor_unknown"}
],
}
def test_carried_text_the_bundle_does_not_hold_is_unverified(tmp_path: Path) -> None:
build = _build(accounting=_all_carried(images=0), bundle_text="")
unit = gate.account(_inventory(), build, _corpus(tmp_path))[0]
assert unit.unverified == 2
assert not unit.clean
def test_carried_text_the_bundle_holds_verifies(tmp_path: Path) -> None:
corpus = _corpus(tmp_path)
build = _build(accounting=_all_carried(images=0), assets=_assets(corpus / "graphics" / "x.png"))
unit = gate.account(_inventory(), build, corpus)[0]
assert (unit.unverified, unit.verified) == (0, 2)
def test_one_heading_carried_of_two_in_the_bundle_is_unverified(tmp_path: Path) -> None:
build = _build(accounting=_all_carried(images=0), bundle_text="# Foerste overskrift\n")
unit = gate.account(_inventory(), build, _corpus(tmp_path))[0]
assert unit.unverified == 1
def test_an_image_booked_carried_without_its_bytes_is_unverified(tmp_path: Path) -> None:
"""The image element has no text of its own, so the only proof it was
carried is the asset. Without it the booking is not verifiable, and an
unverifiable booking is never clean."""
unit = gate.account(_inventory(), _build(accounting=_all_carried()), _corpus(tmp_path))[0]
assert unit.unverified >= 1
assert not unit.clean
def test_a_negative_booking_is_never_clean(tmp_path: Path) -> None:
declared = _all_carried()
declared["documents"][0]["fates"]["heading"] = {
"carried": 25,
"rejected": {"extractor_unknown": -15},
}
unit = gate.account(_inventory(), _build(accounting=declared), _corpus(tmp_path))[0]
assert unit.invalid >= 1
assert not unit.clean
# 25 + (-15) = 10 booked against a source holding 2, so eight are booked
# twice. Absorbing the sign would read 40 and report thirty-eight.
assert unit.double == 8
def test_a_document_declared_persisted_that_is_not_in_the_bundle_is_never_clean(
tmp_path: Path,
) -> None:
build = _build(accounting=_all_carried(), sources=set())
unit = gate.account(_inventory(), build, _corpus(tmp_path))[0]
assert unit.invalid >= 1
def test_everything_rejected_is_never_clean_for_a_document_the_build_persisted(
tmp_path: Path,
) -> None:
declared = _all_carried()
declared["documents"][0]["fates"] = {
"heading": {"rejected": {"fail_secure": 2}},
"image": {"rejected": {"fail_secure": 1}},
}
unit = gate.account(_inventory(), _build(accounting=declared), _corpus(tmp_path))[0]
assert unit.invalid >= 1
assert "persisted" in "; ".join(unit.notes)
def test_a_document_refused_whole_is_never_clean(tmp_path: Path) -> None:
"""H1, measured by PM 2026-09-18: a document the build refused books every
element as a coded rejection, so u = 0 and d = 0 and the unit read CLEAN.
The fate is honest and the content is gone; the gate has to say both."""
declared = _all_carried()
declared["documents"][0]["status"] = "rejected"
declared["documents"][0]["code"] = "fail_secure"
declared["documents"][0]["fates"] = {
"heading": {"rejected": {"fail_secure": 2}},
"image": {"rejected": {"fail_secure": 1}},
}
unit = gate.account(
_inventory(), _build(accounting=declared, sources=set()), _corpus(tmp_path)
)[0]
assert not unit.clean
assert unit.refused == 3
assert "fail_secure" in "; ".join(unit.notes)
def test_a_document_refused_whole_is_not_made_clean_by_the_neighbour(tmp_path: Path) -> None:
"""H1 in the shape the po scenario meets it: ONE refused source beside an
accepted one. `refused_whole` asks its question only when the corpus
persisted NOTHING, so the partial case reached row 3 as `clean = 4 of 4`
with `okf build` exiting 0 and three elements gone unseen."""
inventory = _inventory()
inventory["documents"]["b.md"] = {
"suffix": ".md",
"elements": {"heading": 1},
"texts": {"heading": [["Refused"]]},
"images": [],
}
declared = _all_carried()
declared["documents"].append(
{
"source_file": "b.md",
"status": "rejected",
"code": "fail_secure",
"inventory": {"heading": 1},
"fates": {"heading": {"rejected": {"fail_secure": 1}}},
}
)
declared["files"][0]["fate"] = "carried"
build = _build(
accounting=declared,
sources={"a.md"},
assets=_assets(_corpus(tmp_path) / "graphics" / "x.png"),
)
units = gate.account(inventory, build, tmp_path)
refused = next(u for u in units if u.name == "b.md")
assert gate.refused_whole(inventory["documents"], build) is None, "the corpus is not refused"
assert not refused.clean
assert (refused.name, refused.refused) == ("b.md", 1)
row = gate.row3(units, door=True)
assert row.status == gate.RED
assert any("b.md" in detail and "fail_secure" in detail for detail in row.details)
def test_a_document_declared_rejected_that_the_bundle_holds_is_never_clean(
tmp_path: Path,
) -> None:
"""H2 / mutant X2: the mirror of
`test_a_document_declared_persisted_that_is_not_in_the_bundle_is_never_clean`,
and the only one of B-1's six refusals no test drove. A report claiming a
document was refused while a concept in the bundle names it is the shape
that hides a persist gate that did not fire.
The known-negative on the same declaration: with no concept naming it,
the refusal is honest and the only finding is H1's own column."""
declared = _all_carried()
declared["documents"][0]["status"] = "rejected"
declared["documents"][0]["code"] = "fail_secure"
declared["files"][0]["fate"] = "carried"
corpus = _corpus(tmp_path)
assets = _assets(corpus / "graphics" / "x.png")
held = gate.account(
_inventory(), _build(accounting=declared, sources={"a.md"}, assets=assets), corpus
)[0]
assert held.invalid >= 1
assert "declared rejected" in "; ".join(held.notes)
honest = _all_carried()
honest["documents"][0]["status"] = "rejected"
honest["documents"][0]["code"] = "fail_secure"
honest["documents"][0]["fates"] = {
"heading": {"rejected": {"fail_secure": 2}},
"image": {"rejected": {"fail_secure": 1}},
}
honest["files"][0]["fate"] = "carried"
absent = gate.account(
_inventory(), _build(accounting=honest, sources=set(), assets=assets), corpus
)[0]
assert absent.invalid == 0
assert absent.refused == 3
def test_a_rejection_code_outside_the_closed_list_is_never_clean(tmp_path: Path) -> None:
declared = _all_carried()
declared["documents"][0]["status"] = "rejected"
declared["documents"][0]["code"] = "because_i_said_so"
declared["documents"][0]["fates"] = {
"heading": {"rejected": {"because_i_said_so": 2}},
"image": {"rejected": {"because_i_said_so": 1}},
}
unit = gate.account(
_inventory(), _build(accounting=declared, sources=set()), _corpus(tmp_path)
)[0]
assert unit.invalid >= 1
def test_an_accounting_version_the_gate_does_not_read_is_never_clean(tmp_path: Path) -> None:
declared = _all_carried()
declared["accounting_version"] = 2
units = gate.account(_inventory(), _build(accounting=declared), _corpus(tmp_path))
assert not any(u.clean for u in units)
def test_an_asset_with_the_right_name_and_the_wrong_bytes_is_not_carried(tmp_path: Path) -> None:
"""m-1: the check was a NAME check, so a zero-byte file called
`-x.png` proved a carry."""
corpus = _corpus(tmp_path)
source = corpus / "graphics" / "x.png"
lying = {f"{gate._sha12(source)}-x.png": gate._sha256_bytes(b"")}
build = _build(accounting=_declared(fate="carried"), assets=lying)
assert gate.account(_inventory(), build, corpus)[1].unaccounted == 1
def test_an_asset_under_a_reduced_name_still_proves_the_carry(tmp_path: Path) -> None:
"""The build lowercases and folds the source's basename and sniffs the
suffix from the bytes. Measured on R761, a judge checking the FULL name
called 50 of 50 carried images missing -- the judge's defect, not the
build's, so the content address is the check and the readable tail is not.
"""
corpus = _corpus(tmp_path)
source = corpus / "graphics" / "x.png"
digest = gate._sha256(source)
reduced = {f"{digest[:12]}-25-0143-tabeller-r761-r762.jpeg": digest}
build = _build(accounting=_declared(fate="carried"), assets=reduced)
assert gate.account(_inventory(), build, corpus)[1].clean
def test_an_asset_holding_the_bytes_under_a_foreign_address_is_not_a_carry(
tmp_path: Path,
) -> None:
corpus = _corpus(tmp_path)
source = corpus / "graphics" / "x.png"
build = _build(accounting=_declared(fate="carried"), assets={"x.png": gate._sha256(source)})
assert gate.account(_inventory(), build, corpus)[1].unaccounted == 1
def test_the_cheat_that_books_everything_carried_makes_row3_red(tmp_path: Path) -> None:
"""The review's `MODE=carried`: a report that changes not one byte of the
bundle and books every element as carried."""
units = gate.account(
_inventory(), _build(accounting=_all_carried(), bundle_text=""), _corpus(tmp_path)
)
assert gate.row3(units, door=True).status == gate.RED
_HONEST_LOG = (
"* **Images**: 0 carried of 1 found, written to `assets/`.\n"
"* a.md: 3 elements found in the source, 0 carried: document rejected `fail_secure`\n"
)
def _rejected_inventory() -> dict[str, Any]:
inventory = _inventory()
inventory["documents"]["a.md"]["images"] = [{"kind": "local"}]
return inventory
def test_row4_is_green_when_the_log_names_what_the_rejected_document_held() -> None:
row = gate.row4(_rejected_inventory(), _build(sources=set(), log=_HONEST_LOG))
assert (row.k, row.m, row.status) == (1, 1, gate.GREEN)
@pytest.mark.parametrize(
"log",
[
_HONEST_LOG.replace("0 carried of 1 found", "0 carried of 0 found"),
_HONEST_LOG.replace("3 elements", "2 elements"),
_HONEST_LOG.replace(" `fail_secure`", ""),
],
)
def test_row4_is_red_when_the_log_understates_the_rejected_document(log: str) -> None:
row = gate.row4(_rejected_inventory(), _build(sources=set(), log=log))
assert (row.k, row.status) == (0, gate.RED)
def test_row4_cannot_be_green_when_nothing_was_rejected() -> None:
row = gate.row4(_rejected_inventory(), _build(log=_HONEST_LOG))
assert (row.m, row.status) == (0, gate.RED)
def test_row5_is_green_when_the_witnesses_agree() -> None:
row = gate.row5([("pair", gate.compare({"p": 3}, {"p": 3}))], [])
assert (row.k, row.m, row.status) == (1, 1, gate.GREEN)
def test_row5_is_red_with_both_numbers_when_they_disagree_by_one() -> None:
row = gate.row5([("pair", gate.compare({"p": 3}, {"p": 4}))], [])
assert row.status == gate.RED
assert row.details == ["pair: p: 3 vs 4"]
def test_row5_is_red_when_a_witness_is_missing() -> None:
assert gate.row5([("pair", gate.compare({"p": 3}, None))], []).status == gate.RED
def test_row6_without_its_source_is_red_locally_and_skipped_in_ci(tmp_path: Path) -> None:
missing = tmp_path / "absent"
local = gate.row6(missing, None, ci=False)
ci = gate.row6(missing, None, ci=True)
assert (local.status, local.fails) == (gate.RED, True)
assert (ci.status, ci.fails) == (gate.SKIPPED, False)
assert "source missing" in ci.reason
def test_a_skipped_row_never_leaves_the_verdict_unqualified() -> None:
"""m-2: `CI=1` with a missing source printed `GATE GREEN` with nothing
beside it, so the one line most readers stop at said the corpus passed."""
skipped = gate.Row(6, "real corpora", 0, 0, gate.SKIPPED, "not measured, source missing: x")
rendered = gate.render([skipped])
assert "GATE GREEN (row 6 not run: not measured, source missing: x)" in rendered
def test_a_corpus_refused_whole_under_the_default_gate_is_red(tmp_path: Path) -> None:
"""Row 6 was GREEN with R761 100 % rejected: every element booked as a
coded rejection satisfies u = 0 and d = 0. The build order asked for an
honest red there, so the row says this on its own."""
inventory = {
"documents": {
"a.md": {
"suffix": ".md",
"elements": {"heading": 2},
"texts": {"heading": [["A"], ["B"]]},
"images": [],
}
},
"files": {},
}
declared = {
"accounting_version": 1,
"documents": [
{
"source_file": "a.md",
"status": "rejected",
"code": "fail_secure",
"inventory": {"heading": 2},
"fates": {"heading": {"rejected": {"fail_secure": 2}}},
}
],
"files": [],
}
build = _build(accounting=declared, sources=set(), exit_code=1)
units = gate.account(inventory, build, tmp_path)
# The NUMBERS still balance -- that is what made the row green, and since
# H1 the loss has its own column instead of hiding behind them.
assert all((u.unaccounted, u.double) == (0, 0) for u in units)
assert not any(u.clean for u in units)
assert gate.refused_whole(inventory["documents"], build) is not None
def test_a_corpus_whose_every_document_has_no_declared_fate_says_so() -> None:
"""H6: N200 contributes one blank red. `okf build` proposes 0 plans on it
and FAILS (exit 2) before the accounting door is reached -- reproduced
2026-09-19: no accounting file is written at all -- so all 16 549 elements
land as `u` with `no declared fates` and the corpus measures none of the
classes it was brought in for. The row has to say that instead of showing
a number that looks like a finding about the build."""
blank = [
gate.Unit("a.json", "document", 9, 0, notes=["no declared fates"]),
gate.Unit("b.json", "document", 7, 0, notes=["no declared fates"]),
]
said = gate.measures_no_class(blank)
assert said is not None
assert "2 of 2" in said and "no declared fate" in said
def test_a_corpus_with_one_declared_document_is_not_called_blank() -> None:
"""The known-negative: one document with a fate is a corpus that measures
something, however badly the rest went."""
mixed = [
gate.Unit("a.json", "document", 9, 0, notes=["no declared fates"]),
gate.Unit("b.xml", "document", 0, 0, verified=3),
]
assert gate.measures_no_class(mixed) is None
assert gate.measures_no_class([]) is None
def test_the_two_real_corpora_are_named_and_the_second_is_not_r761() -> None:
"""R761 holds 0 `fig`, 0 formulas and 0 references, so the gate's only
real corpus could not see the hole in the STS role map."""
corpora = gate.real_corpora(Path("/r761"), Path("/n200.json"))
assert [c.label.split()[0] for c in corpora] == ["R761", "N200"]
def test_a_unit_clean_in_only_one_of_the_two_builds_is_not_clean() -> None:
"""M13: the two gates see different things, so either build could cover
for the other."""
clean = gate.Unit("a", "document", 0, 0)
dirty = gate.Unit("a", "document", 1, 0)
assert gate.clean_in_every_run([[clean], [clean]]) == 1
assert gate.clean_in_every_run([[clean], [dirty]]) == 0
def test_a_row_skipped_while_the_default_source_exists_exits_one(
tmp_path: Path, monkeypatch: pytest.MonkeyPatch, capsys: pytest.CaptureFixture[str]
) -> None:
"""H5: the guard asked whether the corpora named by the ARGUMENTS are
available -- and row 6 is SKIPPED precisely when none of them is, so the
branch could never fire and no test covered it. The question it meant to
ask is about the machine: a corpus that is HERE and was pointed away from
is a row that did not run, and `CI=1` then printed a qualified GREEN and
exited 0.
Measured against its own known-negative below, so a guard that fires on
everything would not pass either."""
present = tmp_path / "corpus.json"
present.write_text("{}", encoding="utf-8")
skipped = gate.Row(6, "real corpora", 0, 0, gate.SKIPPED, "not measured, source missing: x")
monkeypatch.setattr(gate, "N200_DEFAULT", present)
monkeypatch.setattr(gate, "evaluate", lambda **kwargs: [skipped])
code = gate.main(["--r761", str(tmp_path / "absent"), "--n200", str(tmp_path / "absent.json")])
assert code == 1
assert "row 6 was skipped while its source exists" in capsys.readouterr().err
def test_a_row_skipped_with_no_source_on_the_machine_exits_zero(
tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
"""The known-negative: nothing to measure is not a row that did not run."""
skipped = gate.Row(6, "real corpora", 0, 0, gate.SKIPPED, "not measured, source missing: x")
monkeypatch.setattr(gate, "R761_DEFAULT", tmp_path / "absent")
monkeypatch.setattr(gate, "N200_DEFAULT", tmp_path / "absent.json")
monkeypatch.setattr(gate, "evaluate", lambda **kwargs: [skipped])
assert gate.main([]) == 0
def test_a_surviving_mutant_is_not_exit_zero() -> None:
"""H4: the mutation harness returned `2 if errors else 0`, so a run that
printed `killed 0 of 1` and named the survivor exited 0. PM measured it on
a copy carrying only the X2 mutant. A harness nothing can fail is a report,
not a gate."""
import okf_gate_mutants as mutants
assert mutants.verdict(survived=[], errors=[]) == 0
assert mutants.verdict(survived=["X2"], errors=[]) == 1
assert mutants.verdict(survived=[], errors=["not applied"]) == 2
assert mutants.verdict(survived=["X2"], errors=["not applied"]) == 2
def test_the_gate_exits_one_when_a_row_is_red(monkeypatch: pytest.MonkeyPatch) -> None:
"""M14: nothing checked the real command's exit code, so `main` could
return 0 over a red table and no test would notice."""
pytest.importorskip("pdfplumber")
pytest.importorskip("pypandoc")
monkeypatch.delenv("CI", raising=False)
code = gate.main(["--r761", "/no/such/corpus", "--n200", "/no/such/file.json"])
assert code == 1
def test_a_file_with_no_declaration_is_unaccounted_when_conservation_failed(
tmp_path: Path,
) -> None:
"""M17: without the door, a file that is not merged counts as a coded
rejection ONLY because the build's own conservation identity held. A run
that exited non-zero has not earned that inference."""
corpus = _corpus(tmp_path)
failed = _build(exit_code=1, log="K1b FAILED")
assert gate.account(_inventory(), failed, corpus)[1].unaccounted == 1
assert gate.account(_inventory(), _build(), corpus)[1].clean
def test_a_merged_file_declared_carried_without_its_bytes_is_still_a_false_claim(
tmp_path: Path,
) -> None:
"""M05: with `fates` summing to one anyway, the false claim is the only
thing that can see it."""
corpus = _corpus(tmp_path)
build = _build(accounting=_declared(fate="carried"), sources={"a.md", "graphics/x.png"})
unit = gate.account(_inventory(), build, corpus)[1]
assert (unit.unaccounted, unit.clean) == (1, False)
def test_a_rejection_code_inside_an_element_fate_must_also_be_known(tmp_path: Path) -> None:
"""M24: the document's own `code` was checked and the per-element ones
were not, so a report could name any reason it liked for an element."""
declared = _all_carried()
declared["documents"][0]["fates"]["heading"] = {"rejected": {"because_i_said_so": 2}}
unit = gate.account(_inventory(), _build(accounting=declared), _corpus(tmp_path))[0]
assert unit.invalid >= 1
assert "because_i_said_so" in "; ".join(unit.notes)
def test_the_json_twin_is_read_with_the_json_role_map(tmp_path: Path) -> None:
"""M-2, measured on R761 2026-09-18: the XML delivery places a section's
label at `sec/label` (7 714, and 0 inside a title); the JSON delivery puts
2 760 of them inside the title. Read with the XML map, the twin loses
every one of those."""
twin = gate.FIXTURES / "witness" / "sts-label-in-title.twin.json"
assert witness.count_sts_json(twin.read_bytes()).counts["section_label"] == 1
assert witness._sts_role_xml("label", "title", "sec") is None
assert witness._sts_role_json("label", "title", "sec") == "section_label"
def test_an_approved_exception_is_read_and_says_what_it_does() -> None:
"""m-3: `APPROVED_EXCEPTIONS` was read by no row, so approving one changed
nothing and the list could have said anything."""
for suffix, element in gate.APPROVED_EXCEPTIONS:
assert "no denominator moves" in gate.exception_effect(suffix, element)
assert "WARNING" in gate.exception_effect(".pdf", "page")
assert "names nothing" in gate.exception_effect(".doc", "heading")
rendered = gate.render([])
assert "no denominator moves" in rendered
def test_the_gate_states_its_own_limits() -> None:
rendered = gate.render([])
assert "what this gate cannot check" in rendered
assert len(gate.LIMITS) >= 5
def test_every_witnessed_type_has_a_vocabulary() -> None:
assert set(gate.FORMAT_VOCABULARY) == set(witness.WITNESSED_SUFFIXES)
def test_the_proposed_exceptions_are_not_applied() -> None:
assert "NOT APPROVED" in gate.render([])
assert not {suffix for suffix, _ in gate.APPROVED_EXCEPTIONS} & {
item["suffix"] for item in gate.PROPOSED_EXCEPTIONS
}, "an exception cannot be both proposed and approved"
def test_the_operator_approved_the_pdf_exception_and_nothing_else() -> None:
"""Operator 2026-09-17, answering the gate's three proposals: the PDF one
only. It moves no number -- no witness counts a heading in a PDF -- so what
it changes is that the gap is a stated limit rather than an open question.
"""
assert gate.APPROVED_EXCEPTIONS == frozenset(
{(".pdf", "heading"), (".pdf", "paragraph"), (".pdf", "table")}
)
assert [item["suffix"] for item in gate.PROPOSED_EXCEPTIONS] == [
".xlsx",
".md .txt .csv .json .odt .rtf",
]
assert gate.APPROVED_ON in gate.render([])
def test_bad_usage_exits_two() -> None:
with pytest.raises(SystemExit) as exc:
gate.main(["--no-such-flag"])
assert exc.value.code == 2
# --- 3. the real build at this commit ----------------------------------------
@pytest.fixture(scope="module")
def real_rows() -> list[gate.Row]:
pytest.importorskip("pdfplumber")
pytest.importorskip("pypandoc")
return gate.evaluate(r761=None, n200=None, ci=True, consume=False)
def _cheating_report(inventory: dict[str, Any], mode: str) -> dict[str, Any]:
"""The review's `cheat.py`, as data: a report that changes not one byte of
the bundle and books every element as carried (or as rejected)."""
documents = []
for name, entry in inventory["documents"].items():
if mode == "carried":
fates = {kind: {"carried": n} for kind, n in entry["elements"].items()}
else:
fates = {
kind: {"rejected": {"extractor_unknown": n}} if n else {"rejected": {}}
for kind, n in entry["elements"].items()
}
documents.append(
{
"source_file": name,
"status": "persisted",
"code": None,
"inventory": dict(entry["elements"]),
"fates": fates,
}
)
files = [{"source_file": name, "fate": "carried", "code": None} for name in inventory["files"]]
return {"accounting_version": 1, "documents": documents, "files": files}
@pytest.mark.parametrize("mode", ["carried", "empty"])
def test_a_report_the_build_did_not_write_cannot_make_row3_green(mode: str) -> None:
"""B-1, end to end on the real fixture bundle. Until 2026-09-18 both modes
gave `GATE GREEN`, exit 0: the gate compared the report's numbers with the
witness's and never opened a concept file."""
pytest.importorskip("pdfplumber")
pytest.importorskip("pypandoc")
inventory = gate.load_inventory(gate.INVENTORY)
with tempfile.TemporaryDirectory() as tmp:
build = gate.run_build(gate.CORPUS, Path(tmp), door=True)
build.accounting = _cheating_report(inventory, mode)
units = gate.account(inventory, build, gate.CORPUS)
assert gate.row3(units, door=True).status == gate.RED
def test_the_door_exists() -> None:
assert gate.door_available()
def test_the_real_gate_names_what_the_build_does_not_account_for(
real_rows: list[gate.Row],
) -> None:
"""Rows 1-5 against the real `okf build`; row 6 needs R761 and is skipped
here.
Rows 2 and 3 were GREEN at `864570b` and are RED now, and that is the
hardening working rather than a regression: the witness counts thirteen
classes of content it could not see before, the build accounts for none
of them, and a number nobody counts is a loss nobody can report. The
named classes are the raw material for the next capability order.
"""
assert [(r.number, r.status) for r in real_rows] == [
(1, gate.GREEN),
(2, gate.RED),
(3, gate.RED),
(4, gate.GREEN),
(5, gate.GREEN),
(6, gate.SKIPPED),
]
unaccounted = " ".join(real_rows[2].details)
for element in (
"annotation",
"citation",
"comment",
"endnote",
"figure",
"figure_caption",
"formula",
"header_footer",
"hidden_sheet",
"hidden_slide",
"math",
"note",
"text_box",
):
assert f"{element}: 0 booked of" in unaccounted, element
# And no false red from the gate's own reading: every element the build
# DOES book as carried was found in the bundle.
assert "0 claimed and not found" in real_rows[2].details[0]