test: add unit tests for 6 previously-untested packages (R7)
Added pure unit tests for all packages that had 0% coverage. Where pure logic was entangled with DB calls, extracted testable helpers first. internal/domain (0% -> 100%): - TestIsNil, TestCanTransition (all 30 state transitions), TestSentinelErrors, TestSignalTransitionsComplete internal/learning (0% -> 26.2%): - Refactored processGroup to extract 4 pure helpers: countOutcomes, computeConfidence, shouldValidate, shouldQuarantine - TestWilsonLowerBound (monotonicity, edge cases, sample-size cap) - TestCountOutcomes, TestComputeConfidence, TestShouldValidate, TestShouldQuarantine (table-driven) - Remaining gap: extractPatterns/processGroup DB calls need make test-db internal/policy (39% -> 50%): - Extracted determineRoute from ClassifySignal (pure route logic) - TestDetermineRoute (7 cases covering global/entity kill-switches, approval) - Remaining gap: ClassifySignal/computeBlastRadius need DB mock internal/knowledge (0% -> 14.2%): - TestContentHash, TestStr, TestStrSlice, TestMapVal, TestToPGArray - Documented latent bug: toPGArray doesn't escape " or \\ in tags - Remaining gap: ingest* functions need make test-db internal/actuator (0% -> 14.7%): - TestSSHErrorClassString, TestClassifySSHError (11 cases incl. net.Error mock) - TestParseProcedure, TestSetDefaultSSHTimeout - Circuit breaker full state-machine test (open/close/reset/per-target) - Remaining gap: ExecuteProcedure/ProvisionLXC need SSH+DB fixtures internal/scheduler (0% -> 7.3%): - TestParsePingLatency (Linux/macOS formats), TestAllowlistedScript - TestEvaluateSeverity (threshold logic, crit:0 skip, signalKind fallback) - Remaining gap: checkHTTP/checkTCP need httptest; runCheckPass needs DB internal/notifier (0% -> 6.4%): - TestHashToken, TestGenerateApprovalToken (HMAC re-derivation) - Remaining gap: checkReaction/sendMatrixAlert need httptest; DB funcs need make test-db All tests pass with -race. domain hits its 60% gate at 100%. The remaining packages need integration tests (make test-db) and/or httptest-based tests to reach their coverage gates — tracked as follow-up.
This commit is contained in:
@@ -92,21 +92,7 @@ func (c *Classifier) ClassifySignal(ctx context.Context, signalEntityID, targetE
|
||||
}
|
||||
|
||||
// Determine route
|
||||
route := "escalate"
|
||||
autonomyCheck := ""
|
||||
|
||||
if globalAutoAct == "off" || globalAutoAct == "false" {
|
||||
route = "escalate"
|
||||
autonomyCheck = "blocked: global auto_act disabled"
|
||||
} else if entityAutoAct == "true" {
|
||||
route = "escalate"
|
||||
autonomyCheck = "blocked: per-entity kill-switch"
|
||||
} else if approvalRequired == "none" {
|
||||
route = "auto-act"
|
||||
autonomyCheck = "allowed"
|
||||
} else {
|
||||
autonomyCheck = "requires approval: " + approvalRequired
|
||||
}
|
||||
route, autonomyCheck := determineRoute(globalAutoAct, entityAutoAct, approvalRequired)
|
||||
|
||||
// Compute blast radius
|
||||
blastRadius := computeBlastRadius(ctx, c.DB, targetEntityID)
|
||||
@@ -136,6 +122,21 @@ func (c *Classifier) ClassifySignal(ctx context.Context, signalEntityID, targetE
|
||||
}, nil
|
||||
}
|
||||
|
||||
// determineRoute evaluates autonomy settings and approval requirements to
|
||||
// decide whether a signal should auto-act, escalate, or hold for approval.
|
||||
func determineRoute(globalAutoAct, entityAutoAct, approvalRequired string) (route, autonomyCheck string) {
|
||||
if globalAutoAct == "off" || globalAutoAct == "false" {
|
||||
return "escalate", "blocked: global auto_act disabled"
|
||||
}
|
||||
if entityAutoAct == "true" {
|
||||
return "escalate", "blocked: per-entity kill-switch"
|
||||
}
|
||||
if approvalRequired == "none" {
|
||||
return "auto-act", "allowed"
|
||||
}
|
||||
return "escalate", "requires approval: " + approvalRequired
|
||||
}
|
||||
|
||||
// computeBlastRadius traverses relationships to find affected entities.
|
||||
func computeBlastRadius(ctx context.Context, dbc interface {
|
||||
Query(ctx context.Context, sql string, args ...any) (pgx.Rows, error)
|
||||
|
||||
62
internal/policy/classify_test.go
Normal file
62
internal/policy/classify_test.go
Normal file
@@ -0,0 +1,62 @@
|
||||
package policy
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestDetermineRoute(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
globalAutoAct string
|
||||
entityAutoAct string
|
||||
approvalRequired string
|
||||
wantRoute string
|
||||
wantCheck string
|
||||
}{
|
||||
{
|
||||
"global auto_act off blocks everything",
|
||||
"off", "", "none",
|
||||
"escalate", "blocked: global auto_act disabled",
|
||||
},
|
||||
{
|
||||
"global auto_act false blocks everything",
|
||||
"false", "", "none",
|
||||
"escalate", "blocked: global auto_act disabled",
|
||||
},
|
||||
{
|
||||
"per-entity kill-switch blocks",
|
||||
"on", "true", "none",
|
||||
"escalate", "blocked: per-entity kill-switch",
|
||||
},
|
||||
{
|
||||
"approval none auto-acts",
|
||||
"on", "", "none",
|
||||
"auto-act", "allowed",
|
||||
},
|
||||
{
|
||||
"approval required escalates",
|
||||
"on", "", "operator",
|
||||
"escalate", "requires approval: operator",
|
||||
},
|
||||
{
|
||||
"approval none with empty global defaults to auto-act",
|
||||
"", "", "none",
|
||||
"auto-act", "allowed",
|
||||
},
|
||||
{
|
||||
"global on, no entity kill, approval confirmation",
|
||||
"on", "", "confirmation",
|
||||
"escalate", "requires approval: confirmation",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
route, check := determineRoute(tt.globalAutoAct, tt.entityAutoAct, tt.approvalRequired)
|
||||
if route != tt.wantRoute {
|
||||
t.Errorf("route = %q, want %q", route, tt.wantRoute)
|
||||
}
|
||||
if check != tt.wantCheck {
|
||||
t.Errorf("autonomyCheck = %q, want %q", check, tt.wantCheck)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user