Repository navigation
test: tripwire for a contextScope that changes across REST versions - #131
Merged
juemerson-at-purestorage merged 1 commit intoAug 20, 2026
Conversation
…mann000#112) contextScope is one value per endpoint, computed last-seen-wins across the whole spec set, with no version dimension. Issue dmann000#112 records that as a deliberate decision resting on a premise: a resource does not migrate between the fleet database and an individual array, so scope is a property of the resource rather than of the API version. Nothing tested the premise. If it stopped holding, the map would silently record the newest reading, the runtime gates would apply it to an array running an older REST version, and no existing test could see it -- the drift suite compares the shipped artifact against generator output, and both sides would agree. Adds three cross-version assertions over every cached spec, plus a fourth that needs only a single version: ValueChange an endpoint declares a different scope in a later version KindGained an endpoint gains an ADDITIONAL kind (FLEET -> FLEET|REALM), which one scalar scope cannot represent and which the generator's FLEET-wins rule would quietly resolve Withdrawn a later spec still has the operation but drops its override, so last-seen-wins reverts it to the array default vocabulary the declared domain set is still exactly ARRAY and FLEET The vocabulary assertion is the one most likely to fire first, and the reason it is separate: Build-PfbCapabilityMap.ps1 sends an unrecognised token to scope 'unknown', and 'unknown' suppresses the kind-vs-scope gate in Private/Assert-PfbContextSupported.ps1 -- so a new domain would not fail loudly, it would stop validating. Set-PfbContext -Kind already accepts TopologyGroup with no spec vocabulary behind it. Two things this deliberately does NOT assume. The real-spec assertions are vacuously green today: all five endpoints that declare an override declare it only in fb2.28, so there are no cross-version pairs to compare. A tripwire nobody has seen trip is indistinguishable from one that cannot, so the comparison is a separate function driven by synthetic declarations in its own ungated Describe, which runs on both editions and proves each finding fires. And an empty walk is inconclusive rather than negative -- the 2.17 $ref restructuring makes a walk that silently returns nothing easy to write -- so a positive control asserts the scan saw the API surface (>500 endpoints, at least one declaration) before any "no findings" assertion is believed. Spec files are iterated by filename, never by numeric version literal: the literal 2.20 is the number 2.2, which opens fb2.2.json, a real file. coverage-baseline.psd1: winps51 MaxSkipped 268 -> 273 for the 5 PS7-gated It blocks, keeping the same +16 headroom, and both new Describes added to RequiredDescribes -- load-bearing here, because a vacuously-green block is exactly what a skip ceiling cannot distinguish from one that stopped running. Verified under both editions (pwsh 7: 84 passed / 0 failed; WinPS 5.1: 17 passed / 0 failed / 67 skipped, container ok on both) across this file, Build-PfbCapabilityMap.Tests.ps1 and PfbSpecTools.ContextScope.Tests.ps1. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
juemerson-at-purestorage
deleted the
test/issue-112-contextscope-version-tripwire
branch
August 25, 2026 20:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
contextScopeis one value per endpoint inData/PfbCapabilityMap.json, computed last-seen-winsacross the whole 2.0-2.28 spec set, with no version dimension. #112 records that as a deliberate
decision resting on a premise: a resource does not migrate between the fleet database and an
individual array, so scope is a property of the resource rather than of the API version.
Nothing tested the premise. If it ever stopped holding, the generator would silently record the
newest reading, the runtime gates would apply it to an array running an older REST version, and no
existing test could see it — the drift suite compares the shipped artifact against generator output,
and both sides would agree.
This adds three cross-version assertions over every cached spec, plus a fourth that needs only a
single version:
ValueChangeKindGainedFLEET→FLEET|REALM)Withdrawnarraydefault, changing what the runtime gates enforceARRAY/FLEETThe vocabulary assertion is the one most likely to fire first, and the reason it is separate rather
than folded into the others: it needs a single version to declare an unfamiliar token, not two
versions to disagree.
tools/Build-PfbCapabilityMap.ps1sends an unrecognised token toscope: unknown, andunknownsuppresses the kind-vs-scope gate inPrivate/Assert-PfbContextSupported.ps1— so a new domain would not fail loudly, it would stopvalidating those endpoints.
Set-PfbContext -Kindalready acceptsTopologyGroupwith no specvocabulary behind it, so the client half of that gap exists today.
What it does not claim
The real-spec assertions are vacuously green today. All five endpoints that declare an override
— the
/presets/workloadverbs — declare it only in fb2.28, so there are zero cross-version pairs tocompare. Only the vocabulary assertion has live data behind it.
That is the point of a tripwire, but it creates a problem: a tripwire nobody has seen trip is
indistinguishable from one that cannot. So the comparison is a separate function driven by synthetic
declarations in its own ungated
Describe— seven cases proving each finding fires, and proving twonear-misses do not: an operation leaving the API entirely is not a withdrawal, and a version outside
the scanned range is ignored rather than mis-ranked as earliest.
An empty walk is inconclusive, never negative. The 2.17
$refrestructuring makes a walk thatsilently returns nothing easy to write, and an empty result reads as "nothing is affected". A
positive control therefore asserts the scan saw the API surface — more than 500 endpoints, at least
one declaration — before any "no findings" assertion is believed. Bounds rather than exact counts, so
a new spec version does not red the file.
Spec files are iterated by filename, never by numeric version literal. The literal
2.20is thenumber
2.2, which opensfb2.2.json— a real file — so a cross-version claim can silently cover aversion it never read.
This does not add the version dimension #112 describes as missing. The omission stands exactly as
recorded; it is now self-monitoring rather than resting on an argument nobody re-examines.
Coverage baseline
winps51 MaxSkipped268 → 273 for the 5 PS7-gatedItblocks, keeping the same +16 headroom thefile's convention uses. Both new
Describes added toRequiredDescribes— load-bearing here,because a vacuously-green block is exactly what a skip ceiling cannot distinguish from one that
stopped running. The synthetic block is listed under both editions (it reads no spec and uses no
PS7-only syntax); the real-spec block under
pwsh7alone.Verification
Both editions, across this file plus its two neighbours (
Build-PfbCapabilityMap.Tests.ps1,PfbSpecTools.ContextScope.Tests.ps1):Test-only: no runtime change, no generator change, no derived-report regeneration, no version bump.
Refs #112 — merging this makes #112 closable as the recorded decision it is, with the tripwire as the
reopen trigger its own text asks for. Left for you to close rather than auto-closing, since the
disposition is separable from whether this test is wanted.
🤖 Generated with Claude Code