#!/usr/bin/env bash set -uo pipefail # CASAN WP-S8 — one-command security gate. # Runs the security-relevant harness checks and prints a single aggregate # verdict. Live-model checks SKIP (not fail) when the Ollama tunnel is down. # Exit: 0 all required gates green, 1 a required gate failed. SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "$SCRIPT_DIR/casan-paths.sh" ROOT="$CASAN_APP_ROOT" PASS=0; FAIL=0; SKIP=0 run() { # local name="$1"; shift if "$@" >/dev/null 2>&1; then echo " GATE PASS $name"; PASS=$((PASS+1)); else echo " GATE FAIL $name"; FAIL=$((FAIL+1)); fi } echo "== CASAN security gate ==" run "run-casan4 harness suite" bash "$CASAN_HARNESS_ROOT/tests/run-casan4-harness-tests.sh" run "adversarial suite" bash "$CASAN_HARNESS_ROOT/tests/adversarial-harness-tests.sh" # Wave 5: sign audit head via Vault KMS (or local fallback) before verifying. # This changes verify output from anchor=unsigned to anchor=signed when Vault is configured. run "sign audit-chain head (KMS)" bash "$CASAN_HARNESS_ROOT/scripts/bash/sign-audit-head.sh" run "audit hash-chain (signed)" bash "$CASAN_HARNESS_ROOT/scripts/bash/verify-audit-chain.sh" run "tool-call audit (signed)" bash "$CASAN_HARNESS_ROOT/scripts/bash/verify-tool-audit.sh" # Wave 3 additions run "secrets scan (WP-S4)" bash "$CASAN_HARNESS_ROOT/scripts/bash/secrets-scan.sh" run "no-bypass + circuit breaker" bash "$CASAN_HARNESS_ROOT/scripts/bash/circuit-breaker-check.sh" if curl -sS -m 5 http://127.0.0.1:11434/api/tags >/dev/null 2>&1; then run "model router tests" bash "$CASAN_HARNESS_ROOT/tests/phase3-model-router-tests.sh" run "red-team H4 metrics (30 samples)" bash "$CASAN_HARNESS_ROOT/tests/phase3-redteam-metrics.sh" run "judge gate tests (WP-B)" bash "$CASAN_HARNESS_ROOT/tests/phase3-judge-gate-tests.sh" else echo " GATE SKIP model router + red-team + judge-gate (Ollama tunnel down)"; SKIP=$((SKIP+1)) fi # Wave 4 additions FNM_NODE_DIR="$HOME/AppData/Roaming/fnm/node-versions" if [[ -d "$FNM_NODE_DIR" ]]; then NODE_BIN=$(find "$FNM_NODE_DIR" -name "node.exe" -maxdepth 4 2>/dev/null | sort -V | tail -1) [[ -n "$NODE_BIN" ]] && export PATH="$(dirname "$NODE_BIN"):$PATH" fi if command -v node >/dev/null 2>&1; then if [[ ! -f "$ROOT/node_modules/.bin/vitest" ]]; then echo " installing frontend deps (vitest not found)..." npm ci -w frontend --prefix "$ROOT" >/dev/null 2>&1 || true fi run "frontend runtime tests (WV4-A)" bash -c "cd '$ROOT' && npm test -w frontend" else echo " GATE SKIP frontend runtime tests (node not in PATH)"; SKIP=$((SKIP+1)) fi echo "== verdict: PASS=$PASS FAIL=$FAIL SKIP=$SKIP ==" [[ "$FAIL" -eq 0 ]] || exit 1