Repository navigation
feat: enforce the published JSON Schemas in the runner and CI - #7
Merged
Merged
Conversation
The schemas under schemas/ were published but never applied: the runner used a hand-rolled required-field check that required three fewer fields than the test-case schema, adapter payloads were never validated, and the registry was never checked against the taxonomy schema. A malformed adapter payload could also raise an uncaught KeyError from Event.from_dict. Add caap_benchmark.schemas, which loads the schemas bundled with the package and validates against them with the optional jsonschema package (new schema extra, installed in CI). Without it the loader applies a structural subset that reads its required-field list and safety keys from the schema itself, so the two can no longer diverge. The HTTP and command adapters validate every payload against the adapter-response schema and return test_error for a malformed one. Repository validation checks the registry and all 200 cases against the schemas when jsonschema is available. caap validate reports which validator ran. The generator copies the schemas into the package data and validation checks those copies match. The release workflow installed only build and then ran the unit tests without the package importable; it now installs the dev extra and runs ruff before the checks. Tests cover every schema-required field through the fallback, the three previously missing fields through validate_test_case, a constraint only the full schema catches, the registry, a written report, the mock adapter's response, and six malformed adapter payloads becoming test_error. Verified with jsonschema installed (41 tests) and with its import blocked (37 tests, 4 skipped). Signed-off-by: requie <tarique.smith@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The four schemas under
schemas/were published but never applied. The runner used a hand-rolled required-field check that required three fewer fields than the test-case schema (pattern_version,target_profile,expected_secure_behavior), adapter payloads were never validated, and the registry was never checked against the taxonomy schema. A malformed adapter payload could also raise an uncaughtKeyErrorfromEvent.from_dict.The schemas are now enforced. Full validation uses the optional
jsonschemapackage through a newschemaextra that CI installs. Without it, a structural fallback reads its required fields and safety keys from the schema itself, so the two can no longer diverge.Pattern or implementation impact
Technical review. No taxonomy, case, or schema content changes; all 200 cases and the registry already validated under the published schemas, so this adds enforcement only.
src/caap_benchmark/schemas.py: new. Loads the bundled schemas, reports whetherjsonschemais available, and returns schema violations with JSON paths.src/caap_benchmark/loaders.py:validate_test_caseuses the test-case schema;structural_test_case_errorsis the dependency-free fallback driven by the schema'srequiredlist,pattern_idpattern, and safety keys.src/caap_benchmark/adapters/http.py:_normalize(shared with the command adapter) validates every payload against the adapter-response schema and returnstest_errorfor a malformed one instead of raising.src/caap_benchmark/cli.py:caap validatereports which validator ran.scripts/generate_catalog.py: copies the schemas into the package data.scripts/validate_repository.py: checks those copies match, and validates the registry and all 200 cases against the schemas whenjsonschemais available (prints a note otherwise).pyproject.toml:schemaextra;devextra now includes PyYAML and jsonschema; schemas added to package data..github/workflows/ci.yml: installs[yaml,schema]..github/workflows/release.yml: previously installed onlybuildand then ran the unit tests without the package importable, so it would have failed on the first tag; it now installs[dev]and runs ruff before the checks.tests/test_schemas.py: new, 13 tests. Docs:docs/CONFORMANCE.md(schema enforcement section),README.md(extras),CHANGELOG.md.Safety impact
Not applicable. No fixture, capability, sink, network boundary, persistence boundary, or public procedure changes. The change makes the runner stricter about what it accepts: a malformed adapter payload yields
test_error, neverpass.Validation
jsonschemais blockedjsonschemainstalled, 37 plus 4 skipped with its import blockedcaap validateon a case missingtarget_profilewith an invalid severity rating reports both violations with their JSON pathsruff check src tests scripts examplesis clean