Files
cleveragents-core/features/plugins_loader_coverage.feature
HAL9000 5b6224daa8 fix(plugins): prevent arbitrary code execution in PluginLoader.validate_protocol()
- Add guard in TypeError fallback path: raise ProtocolMismatchError when
  issubclass raises TypeError and protocol has no inspectable members,
  preventing silent True return for unverifiable protocols
- Update test scenario descriptions to accurately reflect the new
  implementation (no instantiation occurs at any point)
- Update step definition comments to remove references to old
  instantiation-based code paths

ISSUES CLOSED: #7418
2026-05-08 09:32:29 +00:00

50 lines
2.7 KiB
Gherkin

Feature: Plugin Loader Coverage Boost
Scenarios targeting uncovered lines in the PluginLoader class:
- Lines 203-209: entry point load failure exception handler
- validate_protocol: issubclass succeeds (class satisfies protocol structurally)
- validate_protocol: issubclass raises TypeError with unverifiable protocol
- validate_protocol: issubclass returns False (class missing required members)
Background:
Given the plugin loader module is imported
# -----------------------------------------------------------------------
# Entry-point discovery: failure path (lines 203-209)
# -----------------------------------------------------------------------
Scenario: Entry point that fails to load is skipped with a warning
Given the entry points are mocked with one that raises on load
When I call load_from_entry_points
Then the plugin result should be an empty descriptor list
And the failed entry point should have been logged as a warning
# -----------------------------------------------------------------------
# validate_protocol: issubclass succeeds for class satisfying protocol
# -----------------------------------------------------------------------
Scenario: validate_protocol returns True when class satisfies protocol via issubclass
Given I have a class that requires constructor arguments
And I have a runtime checkable protocol the class satisfies via issubclass
When I call validate_protocol with the non-instantiable class and protocol
Then validate_protocol should return True
# -----------------------------------------------------------------------
# validate_protocol: issubclass raises TypeError for unverifiable protocol
# -----------------------------------------------------------------------
Scenario: validate_protocol raises ProtocolMismatchError when issubclass raises TypeError
Given I have a class that cannot be instantiated without arguments
And I have a protocol-like object that causes issubclass to raise TypeError
When I call validate_protocol expecting a mismatch error
Then a plugin-loader ProtocolMismatchError should be raised
# -----------------------------------------------------------------------
# validate_protocol: issubclass returns False (class missing required members)
# -----------------------------------------------------------------------
Scenario: validate_protocol raises ProtocolMismatchError when issubclass returns False
Given I have a class that cannot be instantiated without arguments
And I have a runtime checkable protocol the class does not satisfy
When I call validate_protocol expecting a mismatch error
Then a plugin-loader ProtocolMismatchError should be raised