#!/usr/bin/env bash set -uo pipefail # CASAN Plan-16 SEC-12 — drift-detect semantic invariants (beyond char-similarity). # # Char-similarity alone misses a SEMANTIC inversion: dropping a negation # ("must NOT deploy" -> "must deploy") keeps similarity ~0.97 but flips the meaning, # and previously passed. Now a candidate that removes negations present in the # golden, or that drops a must-keep invariant, FAILS. Proves the flip is caught and # identical/benign content still passes. # # Deterministic; hermetic. SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "$SCRIPT_DIR/../scripts/bash/casan-paths.sh" PROJECT_ROOT="$CASAN_APP_ROOT" DD="$CASAN_HARNESS_ROOT/scripts/bash/drift-detect.sh" WORK="$(mktemp -d)" trap 'rm -rf "$WORK"' EXIT PASS=0; FAIL=0 pass() { echo "PASS: $1"; PASS=$((PASS + 1)); } fail() { echo "FAIL: $1"; FAIL=$((FAIL + 1)); } rc_of() { set +e; "$@" >/dev/null 2>&1; echo $?; set -e 2>/dev/null || true; } echo "===== Plan-16 SEC-12: drift semantic invariants =====" printf 'You MUST NOT deploy to production without explicit human approval.\n' > "$WORK/golden.txt" printf 'You MUST deploy to production without explicit human approval.\n' > "$WORK/flip.txt" cp "$WORK/golden.txt" "$WORK/same.txt" # Negation flip: near-identical text (similarity ~0.97) but a "NOT" vanished. [[ "$(rc_of bash "$DD" "$WORK/golden.txt" "$WORK/flip.txt" "$WORK/r1.json")" -ne 0 ]] \ && pass "negation flip FAILS despite high similarity" \ || fail "negation flip passed (semantic inversion missed)" grep -q 'negation_dropped' "$WORK/r1.json" \ && pass "report records the negation_dropped reason" || fail "reason not recorded" # Identical golden/candidate still passes. [[ "$(rc_of bash "$DD" "$WORK/golden.txt" "$WORK/same.txt" "$WORK/r2.json")" -eq 0 ]] \ && pass "identical content passes (no false positive)" || fail "identical content flagged" # must-keep invariant missing from candidate → FAIL. printf 'MUST NOT deploy\n' > "$WORK/mustkeep.txt" [[ "$(rc_of env CASAN_DRIFT_MUSTKEEP_FILE="$WORK/mustkeep.txt" bash "$DD" "$WORK/golden.txt" "$WORK/flip.txt" "$WORK/r3.json")" -ne 0 ]] \ && pass "missing must-keep invariant FAILS" || fail "missing must-keep not detected" # must-keep invariant present → pass. printf 'production\n' > "$WORK/mustkeep2.txt" [[ "$(rc_of env CASAN_DRIFT_MUSTKEEP_FILE="$WORK/mustkeep2.txt" bash "$DD" "$WORK/golden.txt" "$WORK/same.txt" "$WORK/r4.json")" -eq 0 ]] \ && pass "present must-keep invariant passes" || fail "present must-keep wrongly failed" echo "" echo "===== SEC-12 SUMMARY: PASS=$PASS FAIL=$FAIL =====" [[ "$FAIL" -eq 0 ]] || exit 1