diff --git a/src/wardline/install/block.py b/src/wardline/install/block.py index fa250bf4..655b363e 100644 --- a/src/wardline/install/block.py +++ b/src/wardline/install/block.py @@ -31,6 +31,7 @@ _BLOCK_VERSION = "1" + def _compose_body(grant_suffix: str = "", grant_sentence: str = "") -> str: return ( "This project uses **wardline** as its trust-boundary gate. Before handing " @@ -81,6 +82,7 @@ def _pack_guidance(project_root: Path) -> tuple[str, str]: ) return suffix, sentence + _OWN_NS = "wardline" _END_MARKER = f"" _WRITER_MARKER = f"" diff --git a/src/wardline/mcp/server.py b/src/wardline/mcp/server.py index 07fa0c62..a9bbe42c 100644 --- a/src/wardline/mcp/server.py +++ b/src/wardline/mcp/server.py @@ -5103,9 +5103,7 @@ def _grants_merged_arguments(self, arguments: dict[str, Any]) -> dict[str, Any]: if caller_packs is None or ( isinstance(caller_packs, list) and all(isinstance(p, str) for p in caller_packs) ): - merged["trust_packs"] = list( - dict.fromkeys([*(caller_packs or []), *self._default_trusted_packs]) - ) + merged["trust_packs"] = list(dict.fromkeys([*(caller_packs or []), *self._default_trusted_packs])) if self._default_trust_local_packs: caller_local = merged.get("trust_local_packs") # Identity checks, not equality: 0 == False, and masking a caller's diff --git a/src/wardline/scanner/taint/variable_level.py b/src/wardline/scanner/taint/variable_level.py index 3190e60c..45b8685d 100644 --- a/src/wardline/scanner/taint/variable_level.py +++ b/src/wardline/scanner/taint/variable_level.py @@ -67,6 +67,12 @@ "tomllib.load", "tomli_w.dumps", "tomli_w.dump", + "shelve.open", + "dill.load", + "dill.loads", + "jsonpickle.decode", + "joblib.load", + "torch.load", } ) diff --git a/tests/unit/install/test_doctor_pack_grants.py b/tests/unit/install/test_doctor_pack_grants.py index 8061c8b8..c39f0e51 100644 --- a/tests/unit/install/test_doctor_pack_grants.py +++ b/tests/unit/install/test_doctor_pack_grants.py @@ -66,9 +66,7 @@ def test_project_mcp_check_accepts_grant_flags(tmp_path: Path, monkeypatch: pyte assert check.ok, check.message -def test_project_mcp_check_names_divergence_not_missing( - tmp_path: Path, monkeypatch: pytest.MonkeyPatch -) -> None: +def test_project_mcp_check_names_divergence_not_missing(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None: # A present-but-noncanonical entry is a different failure than an absent one; # "missing wardline server" for a visibly present entry sent the operator # chasing the wrong problem. diff --git a/tests/unit/install/test_mcp_json.py b/tests/unit/install/test_mcp_json.py index c59dbc67..1ccaa6d9 100644 --- a/tests/unit/install/test_mcp_json.py +++ b/tests/unit/install/test_mcp_json.py @@ -549,9 +549,7 @@ def test_repair_preserves_trust_pack_grant_flags(tmp_path: Path, monkeypatch: py "--allow-custom-packs", ] (tmp_path / ".mcp.json").write_text( - json.dumps( - {"mcpServers": {"wardline": {"type": "stdio", "command": "/bin/wardline", "args": list(args)}}} - ), + json.dumps({"mcpServers": {"wardline": {"type": "stdio", "command": "/bin/wardline", "args": list(args)}}}), encoding="utf-8", ) assert merge_mcp_entry(tmp_path) == "unchanged" @@ -581,9 +579,7 @@ def test_repair_preserves_repeated_trust_pack_grants(tmp_path: Path, monkeypatch assert merge_mcp_entry(tmp_path) == "unchanged" -def test_repair_drops_dangling_trust_pack_but_keeps_bare_grant( - tmp_path: Path, monkeypatch: pytest.MonkeyPatch -) -> None: +def test_repair_drops_dangling_trust_pack_but_keeps_bare_grant(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None: # A --trust-pack with a missing or flag-shaped value is malformed: it must be # dropped cleanly, and must never swallow the following --allow-custom-packs. monkeypatch.setattr("wardline.install.mcp_json._find_wardline_command", lambda: "/bin/wardline") diff --git a/tests/unit/mcp/test_server_trust_grants.py b/tests/unit/mcp/test_server_trust_grants.py index bbaa9652..59c8bf7c 100644 --- a/tests/unit/mcp/test_server_trust_grants.py +++ b/tests/unit/mcp/test_server_trust_grants.py @@ -24,9 +24,7 @@ def _pack_project(tmp_path: Path) -> Path: proj = tmp_path / "proj" (proj / "scripts").mkdir(parents=True) - (proj / "scripts" / "grantpack.py").write_text( - 'config = {"exclude": ["skipped_by_pack.py"]}\n', encoding="utf-8" - ) + (proj / "scripts" / "grantpack.py").write_text('config = {"exclude": ["skipped_by_pack.py"]}\n', encoding="utf-8") (proj / "weft.toml").write_text(f'[wardline]\npacks = ["{PACK_NAME}"]\n', encoding="utf-8") (proj / "kept.py").write_text("def kept():\n return 1\n", encoding="utf-8") (proj / "skipped_by_pack.py").write_text("def skipped():\n return 1\n", encoding="utf-8")