Skip to content

test: add missing coverage for council/paths.py - #8

Merged
wikithoughts merged 1 commit into
mainfrom
test/paths-coverage
Aug 30, 2026
Merged

wikithoughts merged 1 commit into
mainfrom
test/paths-coverage

Conversation

@wikithoughts

Copy link
Copy Markdown
Owner

Why

council/paths.py is the single source of truth for ~/.passiveworkers layout, and AGENTS.md
explicitly calls out write_private_json as load-bearing/security-sensitive:

Any 0600-mode credential write (council/paths.py:write_private_json, ...) — these hold
signing keys and node/asker secrets. A write path that skips the owner-only permission window
is a real vulnerability, not a style nit.

Despite that, the module had no dedicated test file — it was only exercised incidentally through
other tests (e.g. tests/test_doctor.py pins coordinator_entries() indirectly via
council.doctor). This closes that coverage gap directly.

What this adds

New tests/test_paths.py, covering all four public functions:

  • home() — default resolves to ~/.passiveworkers; PW_HOME override works; an empty-string
    PW_HOME is treated as unset (guards the or fallback in the implementation).
  • reports_dir() — default resolves under home(); PW_REPORTS_DIR override wins even when
    PW_HOME is also set.
  • write_private_json() (the load-bearing one):
    • Written file is mode 0600 (fresh write, overwrite, and after mkdir(parents=True)).
    • Content round-trips through json.load().
    • Missing parent directories are created.
    • Source-inspection regression guard: confirms the implementation opens the fd via
      os.open(..., 0o600) directly rather than open() + a separate os.chmod() call — the
      exact pattern that would reopen a world-readable window.
  • coordinator_entries() — the join.json/asker.json "default" sentinel bug this function
    exists to prevent (see tests/test_doctor.py's docstring for the original incident): excludes
    "default", excludes any non-dict value defensively, returns the right dict-valued entries
    otherwise, handles the empty-state case, and doesn't mutate its input.

No production code changed — council/paths.py itself is untouched.

Verification

All run from a fresh venv against this branch:

  • python -m py_compile tests/test_paths.py — clean
  • ruff check . — all checks passed
  • pytest tests/ -q — full suite green: 524 collected (523 passed, 1 pre-existing unrelated
    skip)
    , up from a 508-test baseline (524 − 16 new tests in this file). Zero failures, zero
    regressions.

🤖 Generated with Claude Code

@wikithoughts
wikithoughts merged commit 545ddc3 into main Aug 30, 2026
5 of 9 checks passed
@wikithoughts
wikithoughts deleted the test/paths-coverage branch August 31, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant