BE-M0-27 · Acceptance: the delivered M0's 44 checks, each mapped to a rule and its tests
ID BE-M0-27 · Level L0 · Pack Pack E · Logins, types and the acceptance check · Run order row 22 · Issue #14
After a fresh reset, every pgTAP test passes (275 in 13 files) and the rule check is clean. Through the table below, 43 of the delivered M0's 44 checks are proved by the tests of the rule each one maps to (D25, D27). Check 7 waits for VEH open 1. This step changes no file.
Before
Section titled “Before”- BE-M0-26 is Done. You are on the branch tools/e2e-types-reference in ~/opleet-v2/opleet,
git status --shortprints nothing, and the stack is running.
1 · Rebuild the local database from nothing, then run every test
Section titled “1 · Rebuild the local database from nothing, then run every test”pnpm supabase db resetpnpm supabase test db2 · Run the rule check
Section titled “2 · Run the rule check”pnpm docs:rules3 · List, for each rule the 44 checks map to, the test files that cite it
Section titled “3 · List, for each rule the 44 checks map to, the test files that cite it”for id in R-ACC-02 R-ACC-03 R-ACC-04 R-ACC-05 R-ACC-06 R-ACC-09 R-ACC-10 R-ACC-27 R-AUD-03 R-AUD-06 R-AUD-08 R-MON-07 R-MON-11 R-MON-15 R-MON-17 R-MON-18 R-MON-20 R-MON-29 R-NUM-01 R-NUM-02 R-NUM-03 R-NUM-08 R-NUM-09 R-RNT-01 R-RNT-02 R-RNT-03 R-RNT-04 R-SET-01 R-TEN-02 R-TEN-03 R-VEH-06 R-VEH-07 R-VEH-08; do echo "$id $(grep -l "'$id: " supabase/tests/database/*.sql | xargs -n1 basename | sed 's/.test.sql//' | tr '\n' ' ')"; doneExpect
Section titled “Expect”- Block 1: “Finished supabase db reset”, then “All tests successful.”, “Files=13, Tests=275” and “Result: PASS”.
- Block 2: one “Rules: …” line and nothing under it.
- Block 3: 33 lines, each a rule ID followed by at least one file name, as in the table below.
git status --shortPrints nothing: the acceptance check changes no file. The run log on #14 is the record.
If it fails
Section titled “If it fails”- test db prints “not ok”: paste every “not ok” line and the lines under it, and say which check in the table it belongs to if the rule ID shows one.
- Block 3 prints a rule ID with no file after it: a test lost its rule ID. Paste the line.
Nothing to undo: the step only reads.
Not run yet. Log each run as a comment on #14.
The 44 checks
Section titled “The 44 checks”The delivered M0 ran 44 checks in one SQL file on a plain-Postgres stub; their names are its output, in order. v2 proves each one through the rule it maps to: the table names that rule and the test files that cite it. DOC pack A's “Coverage: the 44 M0 checks” gives the same mapping by topic.
| # | Check in the delivered M0 | Rule | Tests that cite it |
|---|---|---|---|
| 1 | checker has inspection:write in pool A only | R-ACC-03 | 13_tenancy_access |
| 2 | checker sees only the pool A car | R-ACC-09 | 21_rls |
| 3 | the car checker sees is E2E0001A | R-ACC-09 | 21_rls |
| 4 | grant override: checker reads pool A drivers only | R-ACC-05 | 13_tenancy_access |
| 5 | checker has no vehicle:write | R-ACC-27 | 22_seed_system |
| 6 | checker update without vehicle:write changes nothing | R-ACC-10 | 21_rls |
| 7 | satpam in pool B sees only the pool B car | none yet: VEH open 1 | none; fails today |
| 8 | satpam cannot read charges | R-MON-29 | 21_rls |
| 9 | finance reads payments in both pools | R-ACC-04 | 13_tenancy_access |
| 10 | deny wins: finance approves in pool A only | R-ACC-06 | 13_tenancy_access, 21_rls |
| 11 | other tenant sees no E2E vehicles | R-TEN-02 | 21_rls |
| 12 | other tenant sees no E2E drivers | R-TEN-02 | 21_rls |
| 13 | other tenant sees only its own pool | R-TEN-02 | 21_rls |
| 14 | system lead sources are visible to every tenant | R-TEN-03 | 21_rls |
| 15 | anon cannot read drivers | R-ACC-02 | 12_foundation, 13_tenancy_access, 21_rls |
| 16 | rental takes the car's pool | R-RNT-03 | 17_rentals |
| 17 | one live rental per driver | R-RNT-02 | 17_rentals |
| 18 | cross-pool booking refused (transfer first) | R-RNT-04 | 17_rentals |
| 19 | a booked car cannot be booked twice | R-RNT-01 | 17_rentals |
| 20 | direct vehicles.status update refused | R-VEH-06 | 15_vehicles |
| 21 | set_vehicle_status changes the status | R-VEH-06 | 15_vehicles |
| 22 | ... and writes the history row | R-VEH-07 | 15_vehicles |
| 23 | first contract number of entity E2E is 1 | R-NUM-02 | 13_tenancy_access |
| 24 | second is 2 | R-NUM-01 | 13_tenancy_access |
| 25 | another legal entity counts on its own | R-NUM-02 | 13_tenancy_access |
| 26 | organization-wide counter starts at 1 | R-NUM-03 | 13_tenancy_access |
| 27 | organization-wide counter continues (nulls not distinct) | R-NUM-03 | 13_tenancy_access |
| 28 | staff cannot read the counters directly | R-NUM-08 | 21_rls |
| 29 | other tenants cannot take numbers | R-NUM-09 | 13_tenancy_access |
| 30 | cannot allocate more than the open balance | R-MON-15 | 19_money |
| 31 | charge is partially paid | R-MON-11 | 19_money |
| 32 | payment to entity E2E for a charge of E2F is flagged cross_entity | R-MON-17 | 19_money |
| 33 | driver balance is 80,000 | R-MON-07 | 20_views_audit |
| 34 | voiding the payment reopens the charge | R-MON-20 | 19_money |
| 35 | cross-entity payments can be switched off | R-MON-18 | 19_money |
| 36 | phone is masked in the audit log | R-AUD-06 | 20_views_audit |
| 37 | only the changed field is listed (updated_at ignored) | R-AUD-03 | 20_views_audit |
| 38 | checker in pool A cannot read pool B history | R-AUD-08 | 21_rls |
| 39 | checker in pool A reads pool A history | R-AUD-08 | 21_rls |
| 40 | pool B overrides the checkpoint interval | R-SET-01 | 13_tenancy_access |
| 41 | pool A uses the organization value | R-SET-01 | 13_tenancy_access |
| 42 | 11 system roles seeded | R-ACC-27 | 22_seed_system |
| 43 | satpam has exactly gate:read and audit_log:read, as in v1 | R-ACC-27 | 22_seed_system |
| 44 | satpam cannot change a vehicle status | R-VEH-08 | 15_vehicles |
Two notes on the mapping:
- Check 24 proves that the second number is 2, which R-NUM-01's test also proves. R-NUM-01 itself (two saves at the same moment never get the same number) stays planned until a test can run two sessions at once.
- Check 37 listed only the changed field, with updated_at ignored. R-AUD-03 keeps that. Since R-AUD-01, an update that moves only updated_at is now logged too, with no changed field (DOC-Q3).
Check 7 waits for VEH open 1
Section titled “Check 7 waits for VEH open 1”In the delivered M0, satpam could read the car of its own pool, because gate:read read vehicles there. In v2, R-VEH-14 lets vehicle:read read a car and no rule yet gives that to gate:read. VEH open 1 asks which other permissions read vehicles. So satpam, which holds only gate:read and audit_log:read (R-ACC-27), reads no car today, and check 7 fails as written. If VEH open 1 gives car reads to gate:read, the vehicles entry in tools/db/gen_rls.py gets that permission, a test citing the new rule follows, and check 7 passes.