Repository navigation
fix: align behavioral tests with current workspace layout and policy format - #850
Merged
sonupreetam merged 2 commits intoSep 15, 2026
Conversation
gxmiranda
previously approved these changes
Sep 11, 2026
gxmiranda
left a comment
Contributor
There was a problem hiding this comment.
Clean test infrastructure fix that correctly aligns behavioral tests with the XDG workspace migration and Gemara policy format evolution. All CI checks pass. One non-blocking DRY suggestion below.
This review was generated by /review-pr (AI-assisted).
marcusburghardt
added a commit
to marcusburghardt/complyctl
that referenced
this pull request
Sep 14, 2026
Extract the repeated config directory creation + path resolution pattern (6 occurrences across 4 files) into a shared ensureConfigPath helper in reusable_steps.go per CS-004 DRY principle. Addresses PR complytime#850 review feedback from @gxmiranda. Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
…format The behavioral assessment tests were failing due to test infrastructure drift from three product changes: 1. Mock registry policy format: The mock OCI registry served policy content as a YAML sequence, but the policy resolver now expects a gemara.Policy mapping with adherence.assessment-plans. Updated to a valid Gemara Policy document with proper metadata, contacts, scope, imports, and assessment plans using evaluator ID 'test'. 2. Config file path: Tests wrote complytime.yaml to the workspace root, but the workspace restructuring (XDG migration) expects the config at .complytime/complytime.yaml. Updated all 6 occurrences across reusable_steps.go, transport_security.go, credential_protection.go, and log_security.go to use complytime.WorkspaceDir and complytime.WorkspaceConfigFile constants. 3. Log file path: The CTRL09 log redaction test looked for complytime.log at the workspace root, but the log is now written to .complytime/complyctl.log. Updated to use complytime.LogFileName constant. Additionally, filter Passed evaluations from the SARIF output in the behavioral report generator. Passed controls were appearing as 'note' level alerts in GitHub Code Scanning, creating noise. The full EvaluationLog YAML retains all results for audit completeness. These changes resolve behavioral assessment failures for CTRL03, CTRL04, CTRL05, CTRL06, and CTRL09, and eliminate 6 informational code scanning alerts from passed controls. Signed-off-by: Marcus Burghardt <maburgha@redhat.com> Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
Extract the repeated config directory creation + path resolution pattern (6 occurrences across 4 files) into a shared ensureConfigPath helper in reusable_steps.go per CS-004 DRY principle. Addresses PR complytime#850 review feedback from @gxmiranda. Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
marcusburghardt
force-pushed
the
fix/behavioral-test-infrastructure
branch
from
September 14, 2026 13:59
37eada6 to
83cb421
Compare
sonupreetam
approved these changes
Sep 15, 2026
sonupreetam
left a comment
Member
There was a problem hiding this comment.
All outputs are structurally correct, content-complete, and the behavioral changes are working as designed. Everything checks out.
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The behavioral assessment tests were failing due to test infrastructure
drift from product changes (XDG workspace migration, Gemara policy format
evolution). This PR fixes the test infrastructure to align with the current
codebase without modifying any product code.
Changes
1. Mock registry policy format (
tests/behavioral/registry.go)The mock OCI registry served policy content as a YAML sequence:
The policy resolver now expects a
gemara.Policymapping withadherence.assessment-plans. Updated to a valid Gemara Policy documentwith proper metadata, contacts, scope, imports, and assessment plans
using evaluator ID
test.Resolves: CTRL04.AR01 (#80), CTRL06.AR01 (#84), CTRL06.AR02 (#85)
and unblocks CTRL04.AR02 (#81), CTRL07.AR01 (#86)
2. Config file path (6 occurrences across 4 files)
Tests wrote
complytime.yamlto the workspace root, but the workspacerestructuring expects
<workspace>/.complytime/complytime.yaml. Updatedall occurrences to use
complytime.WorkspaceDirandcomplytime.WorkspaceConfigFileconstants withos.MkdirAllfor the.complytime/directory.Files:
reusable_steps.go,transport_security.go,credential_protection.go,log_security.go3. Log file path (
tests/behavioral/log_security.go)The CTRL09 log redaction test looked for
complytime.logat the workspaceroot. The log file is now written to
.complytime/complyctl.log. Updatedto use
complytime.LogFileNameconstant.Resolves: CTRL09.AR01 (#88)
4. Filter Passed evaluations from SARIF (
cmd/behavioral-report/main.go)Passed controls were appearing as
note-level alerts in GitHub CodeScanning, creating noise. Added
filterNonPassed()to exclude Passedevaluations from the SARIF output. The full EvaluationLog YAML retains
all results for audit completeness.
Resolves: CTRL02.AR01 (#76), CTRL02.AR02 (#77), CTRL03.AR01 (#78),
CTRL03.AR02 (#79), CTRL05.AR01 (#82), CTRL05.AR02 (#83)
Expected Impact
Remaining alerts (genuine gaps, not addressable by test fixes):
Validation
make lint— 0 issuesmake test-unit— all tests passgo vet ./tests/behavioral/... ./cmd/behavioral-report/...— clean