Skip to content

Evidence: unit tests for task grant matching and V1-I07 traceability #1032

Description

@jeremi

Follow-up to #1029.

  • Add unit tests for task_grant_matches in crates/registry-evidence/src/selector.rs. It is covered today only through tests/selector_conformance.rs.
  • V1-I07 in products/evidence/contracts/security-invariant-matrix.yaml now lists the full grant binding set (agent kind, principal, client, resource, trusted source issuer, deadline, authority, purpose, requirement bound). Task grants: remove the registry_grant_authority claim #1039 removes authority from this set and aligns V1-I07; land it first so the tests register against the set it leaves. In security-test-traceability.yaml, sec-caller-grant-reference-rejected still maps only to request_rejects_query_material_and_unknown_fields. Register task_grant_context_is_bound_before_selector_or_source_access for it as well.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyReady for an implementation agent.area:evidenceEvidence ownership.criticality:p3Priority/criticality P3.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions