Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 33 additions & 37 deletions tests/aspect/security_aspect_test.affine
Original file line number Diff line number Diff line change
@@ -1,11 +1,8 @@
// SPDX-License-Identifier: MPL-2.0
// Ported via Harvard Engine mechanical processor
// Ported via Harvard Engine (Semantic pass)

module security_aspect_test;

// TODO: Complete semantic implementation

/* === ORIGINAL TYPESCRIPT CONTEXT ===
// SPDX-License-Identifier: MPL-2.0
// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
//
Expand All @@ -14,34 +11,34 @@ module security_aspect_test;
import { assertEquals } from "https://deno.land/std@0.208.0/assert/mod.ts";

Deno.test("aspect: No hardcoded API keys in network config", async () => {
const content = await Deno.readTextFile("configs/network.ncl");
let content = await Deno.readTextFile("configs/network.ncl");

// Should use placeholders, not real credentials
const realTokenPatterns = [
let realTokenPatterns = [
/[a-zA-Z0-9]{32,}/, // 32+ char alphanumeric (real tokens)
/sk_live_/, // Stripe pattern
/zt_[a-zA-Z0-9]+/, // ZT pattern
];

for (const pattern of realTokenPatterns) {
const hasRealCredential = pattern.test(content) && !content.includes("CHANGEME");
let hasRealCredential = pattern.test(content) && !content.includes("CHANGEME");
assertEquals(hasRealCredential, false);
}
});

Deno.test("aspect: No hardcoded tokens in daemonset", async () => {
const content = await Deno.readTextFile("manifests/daemonset.yaml");
let content = await Deno.readTextFile("manifests/daemonset.yaml");

// Should use secretKeyRef, not hardcoded values
const credentials = content.match(/ZEROTIER_[A-Z_]+/g) || [];
let credentials = content.match(/ZEROTIER_[A-Z_]+/g) || [];
for (const cred of credentials) {
const hasSecretRef = content.includes("secretKeyRef") || content.includes("configMapKeyRef");
let hasSecretRef = content.includes("secretKeyRef") || content.includes("configMapKeyRef");
assertEquals(hasSecretRef, true);
}
});

Deno.test("aspect: No HTTP endpoints (HTTPS only)", async () => {
const files = [
let files = [
"configs/network.ncl",
"configs/firewall.ncl",
"configs/routes.ncl",
Expand All @@ -50,15 +47,15 @@ Deno.test("aspect: No HTTP endpoints (HTTPS only)", async () => {
];

for (const file of files) {
const content = await Deno.readTextFile(file);
let content = await Deno.readTextFile(file);
// Should not have http:// URLs (except in comments)
const httpUrls = content.match(/(?<!#.*?)http:\/\/[^ "#\n]+/);
let httpUrls = content.match(/(?<!#.*?)http:\/\/[^ "#\n]+/);
assertEquals(httpUrls === null, true);
}
});

Deno.test("aspect: No world-readable permission patterns (chmod 777)", async () => {
const files = [
let files = [
"scripts/authorize-nodes.sh",
"scripts/configure-routes.sh",
"scripts/health-check.sh",
Expand All @@ -67,27 +64,27 @@ Deno.test("aspect: No world-readable permission patterns (chmod 777)", async ()
];

for (const file of files) {
const content = await Deno.readTextFile(file);
let content = await Deno.readTextFile(file);
// Should not have 777 permissions
assertEquals(content.includes("chmod 777") || content.includes("chmod a+rwx"), false);
}
});

Deno.test("aspect: ZeroTier auth tokens are placeholders only", async () => {
const content = await Deno.readTextFile("manifests/secret.yaml");
let content = await Deno.readTextFile("manifests/secret.yaml");

// Should use EXAMPLE placeholders
const hasPlaceholder = content.includes("EXAMPLE_API_TOKEN") && content.includes("EXAMPLE_NETWORK_ID");
let hasPlaceholder = content.includes("EXAMPLE_API_TOKEN") && content.includes("EXAMPLE_NETWORK_ID");
assertEquals(hasPlaceholder, true);

// Should not contain real-looking tokens
const realTokenPattern = /[a-z0-9]{20,}/;
const looksRealButNotExample = realTokenPattern.test(content) && !content.includes("EXAMPLE");
let realTokenPattern = /[a-z0-9]{20,}/;
let looksRealButNotExample = realTokenPattern.test(content) && !content.includes("EXAMPLE");
assertEquals(looksRealButNotExample, false);
});

Deno.test("aspect: NetworkPolicy has both ingress and egress rules", async () => {
const content = await Deno.readTextFile("manifests/networkpolicy.yaml");
let content = await Deno.readTextFile("manifests/networkpolicy.yaml");

// Must explicitly define both
assertEquals(content.includes("ingress:"), true);
Expand All @@ -99,7 +96,7 @@ Deno.test("aspect: NetworkPolicy has both ingress and egress rules", async () =>
});

Deno.test("aspect: No plaintext passwords in manifests", async () => {
const manifests = [
let manifests = [
"manifests/configmap.yaml",
"manifests/daemonset.yaml",
"manifests/namespace.yaml",
Expand All @@ -108,35 +105,35 @@ Deno.test("aspect: No plaintext passwords in manifests", async () => {
"manifests/servicemonitor.yaml",
];

const passwordPatterns = [/password\s*:\s*[^#\n]+[a-zA-Z0-9]{8,}/, /passwd\s*:\s*[^#\n]+/];
let passwordPatterns = [/password\s*:\s*[^#\n]+[a-zA-Z0-9]{8,}/, /passwd\s*:\s*[^#\n]+/];

for (const manifest of manifests) {
const content = await Deno.readTextFile(manifest);
let content = await Deno.readTextFile(manifest);

for (const pattern of passwordPatterns) {
// Should not have unencoded passwords
const match = pattern.exec(content);
let match = pattern.exec(content);
if (match) {
// Must be a placeholder or base64
const isPlaceholder = match[0].includes("EXAMPLE") || match[0].includes("CHANGEME");
const isBase64Hint = match[0].includes("base64") || match[0].includes("encoded");
let isPlaceholder = match[0].includes("EXAMPLE") || match[0].includes("CHANGEME");
let isBase64Hint = match[0].includes("base64") || match[0].includes("encoded");
assertEquals(isPlaceholder || isBase64Hint, true);
}
}
}
});

Deno.test("aspect: No expose of internal credentials via logs", async () => {
const daemonsetContent = await Deno.readTextFile("manifests/daemonset.yaml");
let daemonsetContent = await Deno.readTextFile("manifests/daemonset.yaml");

// Should not directly echo secret environment variables
// (using secretKeyRef is OK, but shouldn't directly print values)
const hasDirectEchoOfSecret = daemonsetContent.match(/echo\s+"\s*\$ZEROTIER_(NETWORK_ID|API_TOKEN)/);
let hasDirectEchoOfSecret = daemonsetContent.match(/echo\s+"\s*\$ZEROTIER_(NETWORK_ID|API_TOKEN)/);
assertEquals(hasDirectEchoOfSecret === null, true);
});

Deno.test("aspect: Firewall denies by default (principle of least privilege)", async () => {
const content = await Deno.readTextFile("configs/firewall.ncl");
let content = await Deno.readTextFile("configs/firewall.ncl");

// Input and Forward should be DROP (most restrictive)
assertEquals(content.includes(`input_policy = "DROP"`), true);
Expand All @@ -147,14 +144,14 @@ Deno.test("aspect: Firewall denies by default (principle of least privilege)", a
});

Deno.test("aspect: DaemonSet security context restricts container capabilities", async () => {
const content = await Deno.readTextFile("manifests/daemonset.yaml");
let content = await Deno.readTextFile("manifests/daemonset.yaml");

// Must have securityContext defined
assertEquals(content.includes("securityContext:"), true);
});

Deno.test("aspect: No hardcoded secrets in scripts", async () => {
const scripts = [
let scripts = [
"scripts/authorize-nodes.sh",
"scripts/configure-routes.sh",
"scripts/health-check.sh",
Expand All @@ -163,10 +160,10 @@ Deno.test("aspect: No hardcoded secrets in scripts", async () => {
];

for (const script of scripts) {
const content = await Deno.readTextFile(script);
let content = await Deno.readTextFile(script);

// Should not embed API tokens or network IDs
const hasEmbeddedSecret =
let hasEmbeddedSecret =
/[a-zA-Z0-9]{32,}/.test(content) &&
!content.includes("CHANGEME") &&
!content.includes("EXAMPLE") &&
Expand All @@ -178,7 +175,7 @@ Deno.test("aspect: No hardcoded secrets in scripts", async () => {
});

Deno.test("aspect: Network config disables dangerous capabilities", async () => {
const content = await Deno.readTextFile("configs/network.ncl");
let content = await Deno.readTextFile("configs/network.ncl");

// Should not allow global IPs via ZT network
assertEquals(content.includes("allow_global_ips = false"), true);
Expand All @@ -188,17 +185,16 @@ Deno.test("aspect: Network config disables dangerous capabilities", async () =>
});

Deno.test("aspect: Kubernetes RBAC references are appropriate", async () => {
const daemonsetContent = await Deno.readTextFile("manifests/daemonset.yaml");
let daemonsetContent = await Deno.readTextFile("manifests/daemonset.yaml");

// Should not request cluster-admin role
assertEquals(daemonsetContent.includes("cluster-admin"), false);
});

Deno.test("aspect: Secret is type Opaque not other types", async () => {
const content = await Deno.readTextFile("manifests/secret.yaml");
let content = await Deno.readTextFile("manifests/secret.yaml");

// Should be Opaque type for sensitive data
assertEquals(content.includes('type: Opaque') || content.includes('type: "Opaque"'), true);
});

==================================== */
12 changes: 4 additions & 8 deletions tests/bench/config_bench.affine
Original file line number Diff line number Diff line change
@@ -1,11 +1,8 @@
// SPDX-License-Identifier: MPL-2.0
// Ported via Harvard Engine mechanical processor
// Ported via Harvard Engine (Semantic pass)

module config_bench;

// TODO: Complete semantic implementation

/* === ORIGINAL TYPESCRIPT CONTEXT ===
// SPDX-License-Identifier: MPL-2.0
// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
//
Expand All @@ -18,7 +15,7 @@ Deno.bench("bench: read all nickel configs sequentially", async () => {
});

Deno.bench("bench: read all k8s manifests sequentially", async () => {
const files = [
let files = [
"manifests/configmap.yaml",
"manifests/daemonset.yaml",
"manifests/namespace.yaml",
Expand Down Expand Up @@ -63,15 +60,14 @@ Deno.bench("bench: read all ABI files", async () => {
});

Deno.bench("bench: parse nickel config string content", async () => {
const content = await Deno.readTextFile("configs/network.ncl");
let content = await Deno.readTextFile("configs/network.ncl");
// Basic parsing simulation: count lines
content.split("\n").length;
});

Deno.bench("bench: parse kubernetes manifest string content", async () => {
const content = await Deno.readTextFile("manifests/daemonset.yaml");
let content = await Deno.readTextFile("manifests/daemonset.yaml");
// Basic parsing simulation: count lines
content.split("\n").length;
});

==================================== */
Loading
Loading