Skip to content

fix: align behavioral tests with current workspace layout and policy format - #850

Merged
sonupreetam merged 2 commits into
complytime:mainfrom
marcusburghardt:fix/behavioral-test-infrastructure
Sep 15, 2026
Merged

sonupreetam merged 2 commits into
complytime:mainfrom
marcusburghardt:fix/behavioral-test-infrastructure

Conversation

@marcusburghardt

Copy link
Copy Markdown
Member

Summary

The behavioral assessment tests were failing due to test infrastructure
drift from product changes (XDG workspace migration, Gemara policy format
evolution). This PR fixes the test infrastructure to align with the current
codebase without modifying any product code.

Changes

1. Mock registry policy format (tests/behavioral/registry.go)

The mock OCI registry served policy content as a YAML sequence:

- id: AC-1-impl
  evaluator_id: test

The policy resolver now expects a gemara.Policy mapping with
adherence.assessment-plans. Updated to a valid Gemara Policy document
with proper metadata, contacts, scope, imports, and assessment plans
using evaluator ID test.

Resolves: CTRL04.AR01 (#80), CTRL06.AR01 (#84), CTRL06.AR02 (#85)
and unblocks CTRL04.AR02 (#81), CTRL07.AR01 (#86)

2. Config file path (6 occurrences across 4 files)

Tests wrote complytime.yaml to the workspace root, but the workspace
restructuring expects <workspace>/.complytime/complytime.yaml. Updated
all occurrences to use complytime.WorkspaceDir and
complytime.WorkspaceConfigFile constants with os.MkdirAll for the
.complytime/ directory.

Files: reusable_steps.go, transport_security.go,
credential_protection.go, log_security.go

3. Log file path (tests/behavioral/log_security.go)

The CTRL09 log redaction test looked for complytime.log at the workspace
root. The log file is now written to .complytime/complyctl.log. Updated
to use complytime.LogFileName constant.

Resolves: CTRL09.AR01 (#88)

4. Filter Passed evaluations from SARIF (cmd/behavioral-report/main.go)

Passed controls were appearing as note-level alerts in GitHub Code
Scanning, creating noise. Added filterNonPassed() to exclude Passed
evaluations from the SARIF output. The full EvaluationLog YAML retains
all results for audit completeness.

Resolves: CTRL02.AR01 (#76), CTRL02.AR02 (#77), CTRL03.AR01 (#78),
CTRL03.AR02 (#79), CTRL05.AR01 (#82), CTRL05.AR02 (#83)

Expected Impact

Category Before After
Behavioral code scanning alerts 14 3
Passing controls shown as alerts 6 0
Test infrastructure failures 5 0
Genuine gaps (NOT IMPLEMENTED) 3 3

Remaining alerts (genuine gaps, not addressable by test fixes):

Validation

  • make lint — 0 issues
  • make test-unit — all tests pass
  • go vet ./tests/behavioral/... ./cmd/behavioral-report/... — clean

gxmiranda
gxmiranda previously approved these changes Sep 11, 2026

@gxmiranda gxmiranda left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean test infrastructure fix that correctly aligns behavioral tests with the XDG workspace migration and Gemara policy format evolution. All CI checks pass. One non-blocking DRY suggestion below.

This review was generated by /review-pr (AI-assisted).

Comment thread tests/behavioral/credential_protection.go Outdated
marcusburghardt added a commit to marcusburghardt/complyctl that referenced this pull request Sep 14, 2026
Extract the repeated config directory creation + path resolution
pattern (6 occurrences across 4 files) into a shared ensureConfigPath
helper in reusable_steps.go per CS-004 DRY principle.

Addresses PR complytime#850 review feedback from @gxmiranda.

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
…format

The behavioral assessment tests were failing due to test infrastructure
drift from three product changes:

1. Mock registry policy format: The mock OCI registry served policy
   content as a YAML sequence, but the policy resolver now expects a
   gemara.Policy mapping with adherence.assessment-plans. Updated to
   a valid Gemara Policy document with proper metadata, contacts,
   scope, imports, and assessment plans using evaluator ID 'test'.

2. Config file path: Tests wrote complytime.yaml to the workspace root,
   but the workspace restructuring (XDG migration) expects the config
   at .complytime/complytime.yaml. Updated all 6 occurrences across
   reusable_steps.go, transport_security.go, credential_protection.go,
   and log_security.go to use complytime.WorkspaceDir and
   complytime.WorkspaceConfigFile constants.

3. Log file path: The CTRL09 log redaction test looked for
   complytime.log at the workspace root, but the log is now written
   to .complytime/complyctl.log. Updated to use complytime.LogFileName
   constant.

Additionally, filter Passed evaluations from the SARIF output in the
behavioral report generator. Passed controls were appearing as 'note'
level alerts in GitHub Code Scanning, creating noise. The full
EvaluationLog YAML retains all results for audit completeness.

These changes resolve behavioral assessment failures for CTRL03, CTRL04,
CTRL05, CTRL06, and CTRL09, and eliminate 6 informational code scanning
alerts from passed controls.

Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
Extract the repeated config directory creation + path resolution
pattern (6 occurrences across 4 files) into a shared ensureConfigPath
helper in reusable_steps.go per CS-004 DRY principle.

Addresses PR complytime#850 review feedback from @gxmiranda.

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
@marcusburghardt
marcusburghardt force-pushed the fix/behavioral-test-infrastructure branch from 37eada6 to 83cb421 Compare September 14, 2026 13:59

@gxmiranda gxmiranda left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sonupreetam sonupreetam left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All outputs are structurally correct, content-complete, and the behavioral changes are working as designed. Everything checks out.

@sonupreetam
sonupreetam merged commit bf774c0 into complytime:main Sep 15, 2026
32 checks passed
@github-project-automation github-project-automation Bot moved this from Ready for Review 👀 to Done ✔️ in ComplyTime planning Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Done ✔️

Development

Successfully merging this pull request may close these issues.

4 participants