feat(guard): read the Zerto task, and ask before guarding unknown tools (#6)

This commit was merged in pull request #6.
This commit is contained in:
2026-09-21 15:07:43 -04:00
parent 5039f7378d
commit 1d53029038
10 changed files with 359 additions and 22 deletions
+19
View File
@@ -50,3 +50,22 @@ def test_example_config_covers_windows_and_linux():
# every entry must name the arg holding the VM, or the guard cannot resolve one
for entry in cat.list():
assert entry.vm_arg, f"{entry.server}/{entry.tool} has no vm_arg"
def test_classify_three_way():
data = {
"mutating_tools": [{"server": "winrm", "tool": "run_ps", "vm_arg": "host"}],
"read_only_tools": [{"server": "ssh", "tool": "read_file"}],
}
cat = MutatingCatalog.from_config(data)
assert cat.classify("winrm", "run_ps") == "mutating"
assert cat.classify("SSH", "Read_File") == "read_only"
# unknown is not safe; it means nobody classified it
assert cat.classify("anything", "else") == "unknown"
def test_read_only_entries_need_no_vm_arg():
data = {"read_only_tools": [{"server": "ssh", "tool": "stat"}]}
cat = MutatingCatalog.from_config(data)
assert cat.classify("ssh", "stat") == "read_only"
assert [e.tool for e in cat.read_only()] == ["stat"]