Repository navigation
chore: fold darnit-example's test fixtures into darnit-testchecks and remove it (#487 part 3) - #570
Merged
Conversation
…via importlib.resources The framework TOML sat beside src/, so a wheel did not contain it, and get_framework_path() climbed out of the package with Path(__file__) (feature 021). It now lives in src/darnit_testchecks/ and resolves with importlib.resources. The two legacy remediation tables (handler = "create_readme" / "create_gitignore") named handlers that do not exist and the executor never ran them; they are removed. Refs darnitdevorg#487 Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…nit-testchecks (darnitdevorg#487) darnit-testchecks gains a second framework, testchecks-steps, and the implementation that registers its three step types in register_handlers() (testchecks_readme_description, testchecks_readme_quality, testchecks_ci_config, moved from darnit-example's handlers.py and renamed so they cannot collide with a real plugin's names). The trivial testchecks framework is unchanged, so the CLI and harness tests that audit it keep their results. Both TOMLs ship inside src/darnit_testchecks/ (feature 021). The core tests that used darnit-example as the plugin with custom step types (strict loading, expr references, registry metadata, the fresh registry load, composition, protocol naming) now use testchecks-steps. The handler tests move to tests/darnit_testchecks/. testchecks is now an implementation package, so the module-path policy test uses yaml as the installed package that is not one. Refs darnitdevorg#487 Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
darnit-hello is the plugin template and darnit-testchecks the test plugin. darnit-example was neither a working template (its TOML sat outside src/ and was resolved with Path(__file__), so a wheel would not contain it, and its seven remediations used a legacy table format the executor never ran) nor published. Its step-type fixtures moved to darnit-testchecks in the previous commit. Removed with it: tests/darnit_example (the remediation-action and MCP-tool tests exercised only the package's dead code) and scripts/create-example-test-repo.py, which only built repositories for the example-hygiene MCP server. Refs darnitdevorg#487 Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…arnitdevorg#487) The implementation and handler-authoring guides, packaging-plugins, and the darnit-hello README now name darnit-hello as the template and darnit-reproducibility / darnit-gittuf as plugins with custom step types. darnit-testchecks describes itself as the test-only plugin. The example-plugin architecture page described only darnit-example and is removed. Threat-model files note the removed files without regenerating. Refs darnitdevorg#487 Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
Marc-cn
approved these changes
Oct 9, 2026
Marc-cn
left a comment
Collaborator
There was a problem hiding this comment.
Verified on a clean RHEL 10 box at d902ed3.
- Full suite: 5138 passed, 26 skipped (matches).
- ruff and validate_sync pass.
- darnit list: testchecks (12 controls) and testchecks-steps (2), nothing named example; same 8 frameworks / 6 implementations as main, with testchecks-steps in place of example-hygiene.
- darnit audit . -f testchecks exits 0; testchecks-steps gives 2/2 WARN (manual), as intended with no ceiling.
- Built wheel contains both TOMLs and the frameworks/implementations entry points.
- Remaining darnit-example references are specs/ history or annotated threat-model notes.
Not run here: darnit plan/validate on the two TOMLs, and the integration suite with Actions env vars.
Open
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Part 3 of #487, the last one.
darnit-exampleis removed, and the custom step types core tests used from it now live indarnit-testchecks. That leaves one plugin template (darnit-hello) and one test-only plugin (darnit-testchecks).Why remove
darnit-example:packaging/README.mdlists it as internal).src/and was resolved viaPath(__file__), against feature 021, so a wheel would not include it.remediation/actions.pywere only exercised by its own tests.What moved:
testchecks-steps. It has its own TOML insidesrc/darnit_testchecks/and its own implementation. It holds the three custom step types, renamedtestchecks_readme_description,testchecks_readme_qualityandtestchecks_ci_configso a test plugin doesn't take generic names. They register throughregister_handlers()with their settings and no ceiling, so their results are evidence only. Two controls use them:TCS-DOC-01andTCS-CI-01.testchecks. A control that only reaches manual review would change their pass counts and exit codes, sotestcheckskeeps its 12 controls unchanged.testchecks-steps: strict loading, expression references, registry metadata, handler-registration protocol, composition, and factory. The example's handler tests moved totests/darnit_testchecks/(git mv), and there are new implementation tests.testchecks.tomlmoved intosrc/darnit_testchecks/and resolves viaimportlib.resources. The built wheel contains both TOMLs. Its two legacy remediation tables, which never ran, are gone.Deleted:
packages/darnit-example, and the tests that only covered its dead code: remediation actions, MCP tool registration, example-only implementation tests;scripts/create-example-test-repo.py, which only built repositories for the example framework;docs/architecture/example-plugin.md.The docs now point plugin authors at
darnit-hello, and the CHANGELOG notes the removal. It isn't marked BREAKING, since the package was internal.uv.lockonly dropsdarnit-example.framework-design.mdhad no references to it, so there's no spec change.With parts 1 (#566) and 2 (#569), every item in #487 is done.
Closes #487
Type of Change
Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changed (no reference to change)uv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5138 passed, 26 skipped (main: 5150)uv run ruff check .)The net change of −12 tests:
example-plugin.md.Also run:
darnit listshowstestchecksandtestchecks-stepsand nothing named example;darnit audit . -f testchecksexits 0;darnit plananddarnit validatework on both testchecks TOMLs;uv build --package darnit-testchecks: the wheel contains both TOMLs and the entry points.AI assistance
Claude (Claude Code, claude-opus-5-5) made this change: fixture move, removals, tests and docs. This description was also drafted with Claude. Commits carry an
Assisted-by: Claude:claude-opus-5-5trailer.Additional Notes
Follow-ups found across #487 but outside its scope:
adapters_used: ["builtin"]. Consumers can see that field, so changing it is a spec change.EffectiveControl.remediation_handlerandremediation_config.core/plugin.pycomment listsget_check_handlers,get_context_handlersandget_remediation_handlers, which nothing calls.server/factory.pyhas its own copy of the handler-registration helper; it could delegate.darnit-helloresolves its TOML withPath(__file__)instead ofimportlib.resources.docs/threatmodel/raw-findings.jsonstill names deleted files. The rendered threat-model docs have removal notes.🤖 Generated with Claude Code