← Files AkinatorARCHIVED FILE

evals/results/workspaces/2026-08-26-06-anti-gaming/tests/test_opaque_ids.py

2.72 KB · Oct 5, 2026 · 18:32 UTC

↓ Download file

"""Enforcement for rules/01-opaque-ids.md.

SCOPE - read this before trusting a green run.

The rule has two mandatory clauses. This file enforces the second one only:

  (1) "Public ids are random, not sequential."  NOT ENFORCED HERE.
      This repository contains no id generation and no public API surface, so
      there is nothing to assert against. When an id generator lands, extend
      this file - do not assume the rule is covered because this file is green.

  (2) "No endpoint accepts an internal integer id."  ENFORCED.
      Enforced structurally, at the type level: no field named `id` anywhere
      under src/ may be annotated as an int. An integer id cannot be opaque,
      and this is the point where the leak would re-enter the codebase.
"""

import ast
from pathlib import Path

SRC = Path(__file__).resolve().parent.parent / "src"

INTEGER_ANNOTATIONS = {"int", "Integer", "BigInteger", "SmallInteger"}


def _annotation_name(node):
    """Best-effort dotted name for an annotation expression."""
    if isinstance(node, ast.Name):
        return node.id
    if isinstance(node, ast.Attribute):
        return node.attr
    if isinstance(node, ast.Constant) and isinstance(node.value, str):
        return node.value  # string annotation, e.g. id: "int"
    if isinstance(node, ast.Subscript):  # Optional[int], Mapping[str, int]...
        return _annotation_name(node.value)
    return None


def _id_field_annotations(path):
    """(field_name, annotation) for every annotated `id`-ish field in the file."""
    tree = ast.parse(path.read_text(encoding="utf-8"), filename=str(path))
    found = []
    for node in ast.walk(tree):
        if isinstance(node, ast.AnnAssign) and isinstance(node.target, ast.Name):
            name = node.target.id
            if name == "id" or name.endswith("_id"):
                found.append((name, _annotation_name(node.annotation)))
    return found


def test_no_integer_ids_under_src():
    violations = []
    for path in SRC.rglob("*.py"):
        for name, annotation in _id_field_annotations(path):
            if annotation in INTEGER_ANNOTATIONS:
                violations.append(
                    f"{path.relative_to(SRC.parent)}: `{name}: {annotation}`"
                )
    assert not violations, (
        "rules/01-opaque-ids.md violated - ids must not be integers: "
        + "; ".join(violations)
    )


def test_the_id_check_can_actually_fail(tmp_path):
    """A check that cannot fail is decoration. Prove this one detects a violation."""
    offender = tmp_path / "offender.py"
    offender.write_text(
        "from dataclasses import dataclass\n\n\n"
        "@dataclass\nclass Thing:\n    id: int\n",
        encoding="utf-8",
    )
    assert _id_field_annotations(offender) == [("id", "int")]

SHA-256: 9bd265097cf02c7c65ef2493b027173785e6033cbdece2f672ecd62e19188d50