import re import unittest from pathlib import Path ROOT = Path(__file__).resolve().parents[1] class ReleaseHygieneTests(unittest.TestCase): allowed_large_files = { Path("approach/ovod/APE/ape_d_model_final.pth"), } def test_release_policies_exclude_generated_python_state(self): gitignore = (ROOT / ".gitignore").read_text(encoding="utf-8") release_excludes = (ROOT / "docs" / "RELEASE_EXCLUDES.txt").read_text(encoding="utf-8") self.assertIn("__pycache__/", gitignore) self.assertIn("*.py[cod]", gitignore) self.assertIn(".pytest_cache/", gitignore) self.assertIn("**/__pycache__/", release_excludes) self.assertIn("**/*.pyc", release_excludes) self.assertIn("**/.pytest_cache/", release_excludes) def test_release_does_not_reference_private_relays_or_source_machines(self): forbidden = ( "chat" + "anywhere", "aigpt" + "x.top", "/home/" + "sqli/", "/research/d4/gds/" + "sqli21", "10.249." + "190.53", "/Users" + "/", "/users/" + "prannay", ) violations = [] for path in ROOT.rglob("*"): if not path.is_file() or ".git" in path.parts: continue try: text = path.read_text(encoding="utf-8") except (UnicodeDecodeError, OSError): continue for needle in forbidden: if needle in text: violations.append(f"{path.relative_to(ROOT)}: {needle}") self.assertEqual(violations, []) def test_release_excludes_generated_results_and_local_git_state(self): forbidden_parts = { ".git", "__pycache__", ".pytest_cache", "outputs", "output", "runs", "wandb", "results", "eval_results", "validation", } violations = [] for path in ROOT.rglob("*"): rel = path.relative_to(ROOT) if any(part in forbidden_parts for part in rel.parts): violations.append(str(rel)) self.assertEqual(violations, []) self.assertFalse( (ROOT / "data").exists(), "Top-level data/ must remain an external mount, not release content", ) explicitly_forbidden = ( Path("docs/EVALUATION_VALIDATION.md"), Path("evaluation/validation"), Path("approach/ovod/APE/test_output.png"), Path("baselines/claude-4.5-sonnet-e2e/claude-4.5-sonnet-tiny.json"), ) self.assertEqual([str(path) for path in explicitly_forbidden if (ROOT / path).exists()], []) forbidden_suffixes = (".log", ".pyc", ".pyo", ".nfs") unexpected = [] for path in ROOT.rglob("*"): if not path.is_file(): continue if path.name.startswith(".nfs") or path.name.endswith(forbidden_suffixes): unexpected.append(str(path.relative_to(ROOT))) self.assertEqual(unexpected, []) def test_release_has_no_credential_material(self): forbidden_files = [] for path in ROOT.rglob("*"): if not path.is_file(): continue rel = path.relative_to(ROOT) if path.name == ".env" or ( path.name.startswith(".env.") and path.name != ".env.example" ): forbidden_files.append(str(rel)) if path.suffix.lower() in {".pem", ".key"}: forbidden_files.append(str(rel)) self.assertEqual(forbidden_files, []) secret_patterns = ( re.compile(r"sk-or-v1-[A-Za-z0-9_-]{20,}"), re.compile(r"olp_[A-Za-z0-9_-]{12,}"), re.compile(r"AIza[0-9A-Za-z_-]{20,}"), re.compile(r"gh[pousr]_[0-9A-Za-z]{20,}"), re.compile(r"hf_[0-9A-Za-z]{20,}"), re.compile(r"AKIA[0-9A-Z]{16}"), re.compile(r"BEGIN (?:RSA |OPENSSH |EC )?PRIVATE KEY"), ) violations = [] for path in ROOT.rglob("*"): if not path.is_file() or path.suffix.lower() == ".pth": continue try: text = path.read_text(encoding="utf-8") except (UnicodeDecodeError, OSError): continue if any(pattern.search(text) for pattern in secret_patterns): violations.append(str(path.relative_to(ROOT))) self.assertEqual(violations, []) def test_large_binary_files_are_limited_to_bundled_main_checkpoint(self): threshold = 20 * 1024 * 1024 violations = [] for path in ROOT.rglob("*"): if not path.is_file(): continue rel = path.relative_to(ROOT) if path.stat().st_size > threshold and rel not in self.allowed_large_files: violations.append(str(rel)) self.assertEqual(violations, []) def test_model_manifest_matches_bundled_checkpoint_policy(self): manifest = (ROOT / "docs" / "MODEL_MANIFEST.md").read_text(encoding="utf-8") checkpoint = ROOT / "approach" / "ovod" / "APE" / "ape_d_model_final.pth" self.assertIn("3548f41a3238148180e08fd4b16c71f4abc3ac3caf9c8434444462d1bdb7f965", manifest) self.assertTrue(checkpoint.is_file()) self.assertEqual(checkpoint.stat().st_size, 5_956_547_279) attributes = (ROOT / ".gitattributes").read_text(encoding="utf-8") self.assertIn( "approach/ovod/APE/ape_d_model_final.pth filter=lfs diff=lfs merge=lfs -text", attributes, ) if __name__ == "__main__": unittest.main()